This Data Processing Agreement ("DPA") forms part of the Terms of Service (the "Agreement") between the person or entity accepting the Agreement (the "Customer") and Reasonable Limited, a company incorporated in England and Wales under company number 17388534, with its registered office at Unit 82a James Carter Road, Bury St. Edmunds, IP28 7DE, United Kingdom, trading as Adalyst ("Adalyst"), governing Adalyst's Processing of Personal Data on the Customer's behalf in connection with the Customer's use of the Services.
Capitalised terms used and not defined in this DPA have the meanings given in the Agreement. In the event of any conflict between this DPA and the Agreement, this DPA prevails with respect to the subject-matter of data protection.
Section 1
Capitalised terms not defined here have the meaning given in the Agreement. For this DPA:
Section 2
In relation to Customer Data, the Customer is the Controller and Adalyst is the Processor. Adalyst Processes Customer Data only on the Customer's documented instructions, including as set out in the Agreement and this DPA, unless required to do otherwise by law.
The subject-matter, duration, nature, and purpose of the Processing, the types of Personal Data, and the categories of Data Subjects are set out in Exhibit A.
Section 3
Adalyst will:
The Customer's configuration and use of the Services, including connecting data sources, submitting prompts and files, authorising users or MCP clients, and requesting analysis or campaign operations, constitutes documented instructions for the purposes of this DPA.
Section 4
The Customer acknowledges and agrees that Adalyst may create, compile, and use aggregated, anonymised, and de-identified data derived from the Customer's use of the Services ("Aggregated Data") for the purposes of:
Adalyst will not disclose any Aggregated Data in a form that identifies, or could reasonably be used to identify, the Customer, any end user, or any Data Subject. For the avoidance of doubt, Aggregated Data does not constitute Personal Data once the irreversible de-identification process described in Exhibit C has been applied, and the storage-limitation and retention provisions of this DPA do not apply to Aggregated Data.
The Customer may request that its data be excluded from the generation of new Aggregated Data by contacting privacy@adalyst.app. Such exclusion is prospective only; Aggregated Data already generated prior to the date of exclusion may continue to be used.
Section 5
Adalyst will ensure that persons authorised to Process Customer Data are bound by written confidentiality obligations or are under an appropriate statutory obligation of confidentiality.
Section 6
Adalyst will implement the technical and organisational measures set out in Exhibit C to protect Customer Data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure, or unauthorised access.
Adalyst will review and, where necessary, update these measures from time to time to address evolving risks and the state of the art.
Section 7
The Customer provides Adalyst with general written authorisation to engage Sub-processors for the Processing of Customer Data. The current list of Sub-processors is published at https://adalyst.app/sub-processors.
Adalyst will:
A Customer may object to a new Sub-processor on reasonable data-protection grounds by contacting privacy@adalyst.app. The parties will work in good faith to address the objection. If no reasonable resolution is available, the Customer may stop using the affected Services and terminate the affected subscription.
Section 8
Adalyst will, taking into account the nature of the Processing, assist the Customer by appropriate technical and organisational measures, insofar as this is possible, in responding to requests from Data Subjects exercising their rights under Applicable Data Protection Law. The Services provide self-service mechanisms for access, export, rectification, and deletion of Customer Data; where a request cannot be satisfied through these mechanisms, Adalyst will provide reasonable assistance on request.
Adalyst will not respond to Data Subject requests directly, except on the Customer's documented instructions or as required by law. Where Adalyst receives a Data Subject request relating to Customer Data, it will promptly forward the request to the Customer.
Section 9
Adalyst will provide reasonable assistance to the Customer with any data-protection impact assessments and prior consultations with supervisory authorities that the Customer is required to carry out under Applicable Data Protection Law, taking into account the nature of the Processing and the information available to Adalyst.
Section 10
Adalyst will notify the Customer without undue delay after becoming aware of a Personal Data Breach affecting Customer Data and will provide the information reasonably required for the Customer to meet its own notification obligations, to the extent known at the time.
Adalyst will cooperate with the Customer and provide reasonable assistance in investigating, mitigating, and remediating the Personal Data Breach.
Section 11
Adalyst will make available to the Customer all information reasonably necessary to demonstrate compliance with its obligations under this DPA and Article 28 of the UK GDPR / EU GDPR.
On reasonable prior written notice and no more than once in any twelve-month period (except where required by a supervisory authority), the Customer or an independent auditor mandated by the Customer may inspect the parts of Adalyst's operations relevant to the Processing of the Customer's Personal Data. Audits will be conducted during normal business hours, subject to reasonable confidentiality obligations, and must not unreasonably interfere with Adalyst's business operations.
The Customer will first use information and documentation supplied by Adalyst to establish compliance. Any inspection must be proportionate to the processing risk and subject to appropriate security and confidentiality restrictions.
Section 12
Where Adalyst transfers Customer Data originating in the EEA, the UK, or Switzerland to a country that is not recognised as providing an adequate level of protection, the transfer is made subject to the Standard Contractual Clauses, which are incorporated into this DPA by reference. The parties agree to Module Two (Controller to Processor) of the SCCs, and to the UK International Data Transfer Addendum where applicable.
Details of the transfer and the applicable docking clauses are set out in Exhibit B.
Section 13
On termination or expiry of the Agreement, Adalyst will, at the Customer's election, delete or return Customer Data and delete existing copies, unless retention is required by law. The Customer may request an export by contacting privacy@adalyst.app and may request deletion through the available account settings or by contacting privacy@adalyst.app.
On workspace deletion, Adalyst's hard-delete sweep destroys the workspace's audit data-encryption key, rendering any residual encrypted audit content unrecoverable.
Section 14
In the event of any conflict between the SCCs, this DPA, and the Agreement, the following order of precedence applies, from highest to lowest: (i) the SCCs; (ii) this DPA; (iii) the Agreement. Nothing in this DPA reduces Adalyst's obligations under Applicable Data Protection Law.
Section 15
This DPA is incorporated into the Agreement by reference. The Customer's acceptance of the Agreement — through account creation, ongoing use of the Services, or a signed order form — constitutes the Customer's acceptance of this DPA. No separate signature is required; both parties are deemed to have executed this DPA as of the Effective Date or the date the Customer accepts the Agreement, whichever is later.
Exhibit A
Subject-matter: provision of the Services to the Customer under the Agreement.
Duration: the term of the Agreement and the limited retention period described in the Privacy Policy, unless applicable law requires longer retention.
Nature and purpose: Processing Customer Data to connect to the Customer's authorised advertising, CRM and analytics platforms; provide the AI assistant, analysis, findings, briefings and recommended actions; operate authorised MCP tools; prepare and, following confirmation, execute supported campaign operations; store customer-supplied assets; secure and support the Services; and send transactional notifications.
Categories of Data Subjects may include: the Customer's end users and employees who interact with the Services; the Customer's marketing contacts and leads surfaced through connected CRM and analytics integrations; individuals represented in the Customer's ad-platform audience data.
Categories of Personal Data may include: names, business email addresses, employer and job-title data, ad-engagement identifiers, session and device identifiers, IP addresses, and any Personal Data contained in free-text fields the Customer's systems expose through their integrations.
Special categories of data: none are intentionally collected. The Customer undertakes not to instruct Adalyst to Process Special Categories of Data under Article 9 UK/EU GDPR through the Services without Adalyst's prior written agreement.
Exhibit B
Data Exporter: the Customer, acting as Controller under Applicable Data Protection Law.
Data Importer: Reasonable Limited (company number 17388534), trading as Adalyst, Unit 82a James Carter Road, Bury St. Edmunds, IP28 7DE, United Kingdom, acting as Processor. Contact for data-protection matters: privacy@adalyst.app.
Frequency of transfer: continuous, as necessary to deliver the Services.
Nature of transfer: Processing of Customer Data by Adalyst and its Sub-processors.
Competent supervisory authority: the Information Commissioner's Office (ICO) for UK data exporters; the supervisory authority of the EEA Member State of the data exporter's establishment for EEA data exporters.
Sub-processors: published at https://adalyst.app/sub-processors and maintained continuously.
Signature: this DPA is executed by acceptance of the Agreement; no counter-signature is required.
Exhibit C
Adalyst implements the following technical and organisational measures. A current list and detail is maintained at https://adalyst.app/security:
Questions, requests, or a counter-signed copy on letterhead: legal@adalyst.app.