Data Processing Agreement

This Data Processing Agreement (“DPA”) forms part of the agreement between the customer (“Controller”) and YOYABA GmbH, Barmbekerstraße 6a, 22303 Hamburg, Germany, operating the Nimblet service (“Processor”), and governs the processing of personal data by the Processor on behalf of the Controller under Art. 28 GDPR. A countersignable copy is available on request at info@yoyaba.com.

This page reproduces the DPA terms for transparency. For a binding engagement, the executed DPA (or the Controller’s own DPA where agreed) prevails.

1. Subject matter and duration

The Processor processes personal data solely to provide the Nimblet service - creative-first analytics for paid advertising - as described in the agreement. Processing continues for the term of the agreement and ends in accordance with Section 9 (Deletion and return).

2. Nature and purpose of processing

The Processor ingests advertising data from the Controller’s connected ad accounts (Meta, LinkedIn), stores creative media, computes performance and creative analytics, and - where the Controller enables it with its own AI key - performs AI-assisted creative analysis and generation. Processing operations include collection, storage, organization, structuring, analysis, retrieval, and erasure.

3. Categories of data subjects

The Controller’s authorized users; and individuals whose data may appear in the Controller’s advertising data. Nimblet ingests conversion and pixel data at aggregate level only (per-ad, per-day counts and values) and does not ingest lead-level identifiers such as names or email addresses of ad audiences.

4. Categories of personal data

Authorized-user account data (name, email, profile picture); ad-account structure and creative content (campaigns, ads, creative copy and media, targeting configuration); and aggregate performance and conversion metrics. Special categories of data (Art. 9 GDPR) are not intentionally processed and must not be introduced into the service by the Controller.

5. Obligations of the Processor

  • Process personal data only on documented instructions from the Controller, including regarding international transfers, unless required by EU or Member State law.
  • Ensure persons authorized to process the data are bound by confidentiality.
  • Implement the technical and organizational measures set out in Annex 2 (Art. 32 GDPR).
  • Assist the Controller, taking into account the nature of processing, in responding to data-subject requests (Art. 12–23) and in meeting its obligations under Art. 32–36.
  • Make available all information necessary to demonstrate compliance and allow for and contribute to audits (Section 8).

6. Sub-processors

The Controller grants general authorization for the Processor to engage the sub-processors listed at nimblet.yoyaba.com/subprocessors (Annex 3). The Processor imposes data-protection obligations on each sub-processor equivalent to those in this DPA and remains fully liable for their performance. The Processor will inform the Controller of intended additions or replacements of sub-processors, giving the Controller the opportunity to object on reasonable data-protection grounds.

7. International transfers

Where processing involves a transfer of personal data outside the EU/EEA (see the sub-processor list), the transfer is safeguarded by EU Standard Contractual Clauses or another mechanism recognized under Art. 46 GDPR. Application data is hosted in the EU (Google Cloud region europe-west1).

8. Audit rights

The Processor makes available information necessary to demonstrate compliance with Art. 28 GDPR and permits audits, including inspections, by the Controller or an auditor it mandates, on reasonable prior notice and no more than once per year absent a specific cause (e.g. a security incident).

9. Deletion and return

On termination of the agreement, and at the Controller’s choice, the Processor deletes or returns the personal data and deletes existing copies, unless EU or Member State law requires storage. Standard retention periods are set out in the Privacy Policy. Disconnecting an ad account or deleting a workspace triggers deletion of the associated data within the stated periods.

10. Personal data breaches

The Processor notifies the Controller without undue delay after becoming aware of a personal data breach affecting the Controller’s data, providing the information the Controller needs to meet its Art. 33/34 obligations.

11. Liability and governing law

Liability under this DPA follows the liability provisions of the main agreement. This DPA is governed by German law; the place of jurisdiction is Hamburg, Germany.

Annex 1 - Processing details

Subject matter, nature, purpose, data subjects and data categories: as set out in Sections 1–4 above.

Annex 2 - Technical and organizational measures (Art. 32)

  • Confidentiality: role- and workspace-scoped access control enforced on every request; access to production restricted to authorized personnel; passwords stored with Argon2id; no public user registration.
  • Encryption: TLS in transit; connected ad-account OAuth tokens encrypted at rest; secrets held in Google Secret Manager.
  • Integrity: parameterized database access; strict host allow-listing on outbound media fetches; audit logging of key operations.
  • Availability & resilience: managed, EU-region cloud infrastructure with automated database backups.
  • Tenant isolation: each workspace’s data is logically segregated and access is verified against the requesting user’s membership.
  • Pseudonymization & minimization: conversion data is processed in aggregate only; lead-level identifiers are not ingested.
  • Review: measures are reviewed periodically and after material changes to processing.

Annex 3 - Approved sub-processors

The current list is published at nimblet.yoyaba.com/subprocessors.

Last updated: 2026-07-08