This Data Processing Agreement ("DPA") forms part of the agreement between Yes, Please! Ltd (company no. 514444561), Arye Shenkar St 1, Herzliya, Israel, operating the "Keyword Ninja" service ("Processor", "we", "us"), and the customer that has accepted our Terms of Service ("Customer", "Controller", "you"). It governs our processing of personal data on your behalf when you use the Service. Where this DPA conflicts with the Terms of Service on the subject of data protection, this DPA prevails. This DPA takes effect on the date you accept the Terms of Service or countersign this document.
This is a template. It is provided for review and is not a substitute for legal advice. Have it reviewed by qualified counsel before you rely on it.
1. Definitions
"Data Protection Law" means all laws applicable to the processing of personal data under this DPA, including the EU General Data Protection Regulation 2016/679 ("GDPR"), the UK GDPR, and Israel's Protection of Privacy Law, 5741-1981 and its regulations. "Controller", "Processor", "Data Subject", "Personal Data", "Processing", and "Personal Data Breach" have the meanings given in the GDPR. "Subprocessor" means any third party engaged by us to process Personal Data on your behalf.
2. Roles of the Parties
For Personal Data that we process on your behalf in providing the Service — including the Google Ads data you connect and any personal data contained within it — you are the Controller and we are the Processor. For account, authentication, and billing data that we determine the purposes and means of processing, we act as an independent Controller as described in our Privacy Policy. Each party will comply with its obligations under Data Protection Law.
3. Scope and Instructions
We will process Personal Data only: (a) to provide, maintain, secure, and support the Service; (b) in accordance with your documented instructions, including as set out in this DPA, the Terms of Service, and your use of the Service's features; and (c) as required by applicable law, in which case we will inform you unless legally prohibited. If we believe an instruction infringes Data Protection Law, we will notify you. The subject matter, nature, purpose, duration, categories of Data Subjects, and types of Personal Data are described in Annex I.
4. Confidentiality
We ensure that personnel authorized to process Personal Data are bound by appropriate confidentiality obligations and process the data only as necessary to provide the Service.
5. Security
We implement and maintain appropriate technical and organizational measures to protect Personal Data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure, or access, taking into account the state of the art, the costs of implementation, and the nature, scope, and purposes of processing. Our measures are described in Annex II.
6. Subprocessors
You grant us general authorization to engage Subprocessors to process Personal Data in providing the Service. Our current Subprocessors are listed at keywordninja.com/subprocessors. We will impose data-protection obligations on each Subprocessor that are no less protective than those in this DPA, and we remain responsible for their performance. We will update the Subprocessor list before authorizing a new Subprocessor and, on request, provide a mechanism to notify you in advance so that you may object on reasonable data-protection grounds. If you reasonably object and we cannot accommodate the objection, you may terminate the affected part of the Service.
7. Data Subject Requests
Taking into account the nature of the processing, we will assist you by appropriate technical and organizational measures, insofar as possible, to respond to requests from Data Subjects exercising their rights. The Service also provides self-service tools to access, export, and delete data. If we receive a request directly from your Data Subject, we will not respond except on your instruction or as legally required, and will forward the request to you where identifiable.
8. Personal Data Breach
We will notify you without undue delay after becoming aware of a Personal Data Breach affecting Personal Data we process on your behalf, and will provide information reasonably available to us to help you meet your notification obligations under Data Protection Law.
9. Data Protection Impact Assessment
Taking into account the nature of the processing and information available to us, we will provide reasonable assistance with data protection impact assessments and prior consultations with supervisory authorities.
10. Return and Deletion
On termination of the Service, and at your choice, we will delete or return Personal Data processed on your behalf and delete existing copies, unless applicable law requires continued storage. Data associated with a deleted account is removed as described in our Privacy Policy.
11. Audits
We will make available information reasonably necessary to demonstrate compliance with this DPA and allow for and contribute to audits, including inspections, conducted by you or an auditor you mandate. Audits will be conducted on reasonable prior notice, no more than once per year (except where required by a supervisory authority or following a Personal Data Breach), during business hours, and subject to confidentiality, in a manner that does not disrupt our operations or compromise the data of other customers.
12. International Transfers
We and our Subprocessors may process Personal Data in countries outside your own, including the United States. Where such transfers occur, we rely on an appropriate transfer mechanism under Data Protection Law, such as the European Commission's Standard Contractual Clauses (and the UK Addendum where applicable), which are incorporated by reference where required.
13. Liability
Each party's liability under or in connection with this DPA is subject to the limitations and exclusions of liability set out in the Terms of Service.
14. Term
This DPA remains in effect for as long as we process Personal Data on your behalf. Provisions that by their nature should survive termination will survive.
Annex I — Description of Processing
- Data exporter (Controller): the Customer identified in the account and, where executed, on the signature block below.
- Data importer (Processor): Yes, Please! Ltd, operating Keyword Ninja.
- Categories of Data Subjects: the Customer's authorized users; and individuals whose data appears within the Customer's Google Ads account (e.g. as reflected in search terms and performance data).
- Categories of Personal Data: account identifiers (name, email, profile); Google Ads campaign, ad group, keyword, ad, and search-term data and performance metrics; usage, device, and IP data; and, where paid billing is enabled, billing details.
- Special categories of data: none intended; the Service is not designed to process special-category data.
- Nature and purpose: hosting, analysis, optimization insights, automations, reporting, and support, as described in the Terms of Service.
- Duration: for the term of the account and the retention periods described in the Privacy Policy.
- Subprocessors: as listed at keywordninja.com/subprocessors.
Annex II — Technical and Organizational Measures
- Encryption of data in transit using TLS;
- OAuth 2.0 authentication for Google Ads API access, with access tokens handled securely;
- Role-based access controls and restricted employee access to Personal Data on a need-to-know basis;
- Logical separation of customer data and access scoping within the application;
- Network and edge protections, including a reverse proxy / web application firewall and bot protection;
- Logging and monitoring for security and troubleshooting;
- Regular review of security practices and prompt remediation of identified issues.
[Confirm and expand these measures to match your production environment before signing — e.g. encryption at rest, backup practices, and hosting-provider certifications.]
Annex III — Approved Subprocessors
The list of approved Subprocessors is maintained at keywordninja.com/subprocessors and forms part of this DPA.
Signature
To execute this DPA, an authorized representative of each party may sign below, or you may accept it electronically as part of your subscription. For a countersigned copy, contact [email protected].
Processor: Yes, Please! Ltd — Name: ____________________ Title: ____________________ Date: ____________________
Controller (Customer): ____________________ — Name: ____________________ Title: ____________________ Date: ____________________