Adhook Back to the homepage

Data Processing Agreement

Version 5 September 2026

This agreement governs our processing of personal data contained in the content you submit, where you are the controller and Simon Košir s.p. ("Adhook") is the processor. It forms part of our Terms of Service and applies automatically to content that contains personal data. A signed copy is available on request from privacy@theadhook.com.

1. Subject matter and duration. We process personal data in your submitted content only to provide the ad-generation service, for as long as you use it and until the data is deleted or returned as set out below.

2. Nature and purpose. Generating ad creatives and copy from the product and service data, page data, and images you submit.

3. Types of data and data subjects. The categories of personal data and data subjects are those contained in the content you choose to submit. Adhook is designed for your own product and service information and does not require special-category data.

4. Our obligations as processor. We will: process the data only on your documented instructions; ensure persons authorized to process it are bound by confidentiality; apply appropriate technical and organizational security measures; assist you, taking account of the nature of processing, with data-subject requests and with your security, breach-notification, and impact-assessment obligations; and notify you without undue delay after becoming aware of a personal data breach.

5. Sub-processors. You authorize the sub-processors listed at /legal/subprocessors. We impose data protection terms on each and remain responsible for their performance, and we will inform you of intended changes so you can object.

6. International transfers. Where a sub-processor is outside the EU, transfers are made under the EU Standard Contractual Clauses (Module 2 or 3, as applicable) or, where the provider is certified, the EU-US Data Privacy Framework; the basis per provider is on the sub-processor list.

7. Deletion and return. On termination, or on your request, we delete or return the personal data in the submitted content within 30 days, except where retention is required by law; backups expire within a further 30 days. Uploaded reference images are deleted as soon as each generation job finishes.

8. Audits. We make available the information reasonably necessary to demonstrate compliance with this agreement and allow for reasonable audits on request: once per year on 30 days' notice, or without delay after a personal data breach affecting your data.

9. Technical and organisational measures. Hosting on EU infrastructure (Hetzner, Finland) with TLS in transit; passwords hashed with argon2 and email verification; per-tenant isolation enforced in the application and by Postgres row-level security; private object storage served only through short-lived signed URLs; two-factor authentication and audit logging for every administrative action; rate limiting and CSRF protection on all forms; secrets kept outside the code repository; error monitoring with personal data removed before storage; daily encrypted-at-rest database backups kept up to 30 days; content moderation before any generation step; customer content accessible only to authorized persons bound by confidentiality, with access logging.

This is our standard Data Processing Agreement. To put a signed copy in place, contact privacy@theadhook.com; the signed version takes precedence.

Back to the homepage