Legal

Agreement

Data Processing
Agreement.

Effective 27 August 2026Version 1.0

This Data Processing Agreement ("DPA") forms part of the Terms of Service (the "Agreement") between the person or entity accepting the Agreement (the "Customer") and Reasonable Limited, a company incorporated in England and Wales under company number 17388534, with its registered office at Unit 82a James Carter Road, Bury St. Edmunds, IP28 7DE, United Kingdom, trading as Adalyst ("Adalyst"), governing Adalyst's Processing of Personal Data on the Customer's behalf in connection with the Customer's use of the Services.

Capitalised terms used and not defined in this DPA have the meanings given in the Agreement. In the event of any conflict between this DPA and the Agreement, this DPA prevails with respect to the subject-matter of data protection.

Section 1

Definitions

Capitalised terms not defined here have the meaning given in the Agreement. For this DPA:

  • "Agreement" means the Terms of Service between the Customer and Reasonable Limited, trading as Adalyst, that governs the Customer's use of the Services.
  • "Applicable Data Protection Law" means UK GDPR, the EU GDPR, the Data Protection Act 2018, and any other data-protection law applicable to the Processing of Personal Data under this DPA.
  • "Customer Data" means any Personal Data that Adalyst processes on the Customer's behalf in connection with the Customer's use of the Services.
  • "Data Subject" has the meaning given in Applicable Data Protection Law.
  • "Personal Data" has the meaning given in Applicable Data Protection Law.
  • "Processing" (and its derivatives) has the meaning given in Applicable Data Protection Law.
  • "Standard Contractual Clauses" or "SCCs" means (a) for transfers out of the EEA, the clauses approved by the European Commission in Commission Implementing Decision (EU) 2021/914, and (b) for transfers out of the UK, the International Data Transfer Addendum issued by the ICO under s.119A of the Data Protection Act 2018.
  • "Sub-processor" means any third party engaged by Adalyst to Process Customer Data.

Section 2

Roles and scope of Processing

In relation to Customer Data, the Customer is the Controller and Adalyst is the Processor. Adalyst Processes Customer Data only on the Customer's documented instructions, including as set out in the Agreement and this DPA, unless required to do otherwise by law.

The subject-matter, duration, nature, and purpose of the Processing, the types of Personal Data, and the categories of Data Subjects are set out in Exhibit A.

Section 3

Customer instructions

Adalyst will:

  • Process Customer Data only on the Customer's documented instructions, including with regard to transfers of Personal Data outside the UK or EEA, unless required to do so by law. Where such a requirement applies, Adalyst will inform the Customer of that legal requirement before Processing, unless the law prohibits this on important grounds of public interest.
  • Immediately inform the Customer if, in Adalyst's opinion, an instruction infringes Applicable Data Protection Law.

The Customer's configuration and use of the Services, including connecting data sources, submitting prompts and files, authorising users or MCP clients, and requesting analysis or campaign operations, constitutes documented instructions for the purposes of this DPA.

Section 4

Aggregated and de-identified data

The Customer acknowledges and agrees that Adalyst may create, compile, and use aggregated, anonymised, and de-identified data derived from the Customer's use of the Services ("Aggregated Data") for the purposes of:

  1. improving, securing and developing the Services and operating statistical models that benefit Adalyst customers;
  2. generating anonymised benchmarks, percentiles, and cohort statistics that may be surfaced to other Adalyst customers alongside their own data, provided such benchmarks are computed over a cohort of no fewer than five (5) distinct customer workspaces and contain no information by which any individual customer, Data Subject, or account can be identified;
  3. producing industry reports, whitepapers, and public-facing insights, provided all such outputs are irreversibly de-identified; and
  4. internal research and analysis.

Adalyst will not disclose any Aggregated Data in a form that identifies, or could reasonably be used to identify, the Customer, any end user, or any Data Subject. For the avoidance of doubt, Aggregated Data does not constitute Personal Data once the irreversible de-identification process described in Exhibit C has been applied, and the storage-limitation and retention provisions of this DPA do not apply to Aggregated Data.

The Customer may request that its data be excluded from the generation of new Aggregated Data by contacting privacy@adalyst.app. Such exclusion is prospective only; Aggregated Data already generated prior to the date of exclusion may continue to be used.

Section 5

Confidentiality

Adalyst will ensure that persons authorised to Process Customer Data are bound by written confidentiality obligations or are under an appropriate statutory obligation of confidentiality.

Section 6

Security of Processing

Adalyst will implement the technical and organisational measures set out in Exhibit C to protect Customer Data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure, or unauthorised access.

Adalyst will review and, where necessary, update these measures from time to time to address evolving risks and the state of the art.

Section 7

Sub-processors

The Customer provides Adalyst with general written authorisation to engage Sub-processors for the Processing of Customer Data. The current list of Sub-processors is published at https://adalyst.app/sub-processors.

Adalyst will:

  • enter into a written agreement with each Sub-processor imposing data-protection obligations substantially equivalent to those in this DPA;
  • remain liable to the Customer for the acts and omissions of any Sub-processor to the same extent Adalyst would be liable if it were performing the services of the Sub-processor directly;
  • make changes to the public Sub-processor list available to Customers and, where a Customer has subscribed to change notifications, provide advance notice where reasonably practicable.

A Customer may object to a new Sub-processor on reasonable data-protection grounds by contacting privacy@adalyst.app. The parties will work in good faith to address the objection. If no reasonable resolution is available, the Customer may stop using the affected Services and terminate the affected subscription.

Section 8

Assistance with Data Subject rights

Adalyst will, taking into account the nature of the Processing, assist the Customer by appropriate technical and organisational measures, insofar as this is possible, in responding to requests from Data Subjects exercising their rights under Applicable Data Protection Law. The Services provide self-service mechanisms for access, export, rectification, and deletion of Customer Data; where a request cannot be satisfied through these mechanisms, Adalyst will provide reasonable assistance on request.

Adalyst will not respond to Data Subject requests directly, except on the Customer's documented instructions or as required by law. Where Adalyst receives a Data Subject request relating to Customer Data, it will promptly forward the request to the Customer.

Section 9

Assistance with impact assessments and prior consultations

Adalyst will provide reasonable assistance to the Customer with any data-protection impact assessments and prior consultations with supervisory authorities that the Customer is required to carry out under Applicable Data Protection Law, taking into account the nature of the Processing and the information available to Adalyst.

Section 10

Personal Data Breach

Adalyst will notify the Customer without undue delay after becoming aware of a Personal Data Breach affecting Customer Data and will provide the information reasonably required for the Customer to meet its own notification obligations, to the extent known at the time.

Adalyst will cooperate with the Customer and provide reasonable assistance in investigating, mitigating, and remediating the Personal Data Breach.

Section 11

Audits and inspections

Adalyst will make available to the Customer all information reasonably necessary to demonstrate compliance with its obligations under this DPA and Article 28 of the UK GDPR / EU GDPR.

On reasonable prior written notice and no more than once in any twelve-month period (except where required by a supervisory authority), the Customer or an independent auditor mandated by the Customer may inspect the parts of Adalyst's operations relevant to the Processing of the Customer's Personal Data. Audits will be conducted during normal business hours, subject to reasonable confidentiality obligations, and must not unreasonably interfere with Adalyst's business operations.

The Customer will first use information and documentation supplied by Adalyst to establish compliance. Any inspection must be proportionate to the processing risk and subject to appropriate security and confidentiality restrictions.

Section 12

International data transfers

Where Adalyst transfers Customer Data originating in the EEA, the UK, or Switzerland to a country that is not recognised as providing an adequate level of protection, the transfer is made subject to the Standard Contractual Clauses, which are incorporated into this DPA by reference. The parties agree to Module Two (Controller to Processor) of the SCCs, and to the UK International Data Transfer Addendum where applicable.

Details of the transfer and the applicable docking clauses are set out in Exhibit B.

Section 13

Return or deletion of Customer Data

On termination or expiry of the Agreement, Adalyst will, at the Customer's election, delete or return Customer Data and delete existing copies, unless retention is required by law. The Customer may request an export by contacting privacy@adalyst.app and may request deletion through the available account settings or by contacting privacy@adalyst.app.

On workspace deletion, Adalyst's hard-delete sweep destroys the workspace's audit data-encryption key, rendering any residual encrypted audit content unrecoverable.

Section 14

Order of precedence

In the event of any conflict between the SCCs, this DPA, and the Agreement, the following order of precedence applies, from highest to lowest: (i) the SCCs; (ii) this DPA; (iii) the Agreement. Nothing in this DPA reduces Adalyst's obligations under Applicable Data Protection Law.

Section 15

Execution

This DPA is incorporated into the Agreement by reference. The Customer's acceptance of the Agreement — through account creation, ongoing use of the Services, or a signed order form — constitutes the Customer's acceptance of this DPA. No separate signature is required; both parties are deemed to have executed this DPA as of the Effective Date or the date the Customer accepts the Agreement, whichever is later.

Exhibit A

Details of Processing

Subject-matter: provision of the Services to the Customer under the Agreement.

Duration: the term of the Agreement and the limited retention period described in the Privacy Policy, unless applicable law requires longer retention.

Nature and purpose: Processing Customer Data to connect to the Customer's authorised advertising, CRM and analytics platforms; provide the AI assistant, analysis, findings, briefings and recommended actions; operate authorised MCP tools; prepare and, following confirmation, execute supported campaign operations; store customer-supplied assets; secure and support the Services; and send transactional notifications.

Categories of Data Subjects may include: the Customer's end users and employees who interact with the Services; the Customer's marketing contacts and leads surfaced through connected CRM and analytics integrations; individuals represented in the Customer's ad-platform audience data.

Categories of Personal Data may include: names, business email addresses, employer and job-title data, ad-engagement identifiers, session and device identifiers, IP addresses, and any Personal Data contained in free-text fields the Customer's systems expose through their integrations.

Special categories of data: none are intentionally collected. The Customer undertakes not to instruct Adalyst to Process Special Categories of Data under Article 9 UK/EU GDPR through the Services without Adalyst's prior written agreement.

Exhibit B

Parties and transfer details

Data Exporter: the Customer, acting as Controller under Applicable Data Protection Law.

Data Importer: Reasonable Limited (company number 17388534), trading as Adalyst, Unit 82a James Carter Road, Bury St. Edmunds, IP28 7DE, United Kingdom, acting as Processor. Contact for data-protection matters: privacy@adalyst.app.

Frequency of transfer: continuous, as necessary to deliver the Services.

Nature of transfer: Processing of Customer Data by Adalyst and its Sub-processors.

Competent supervisory authority: the Information Commissioner's Office (ICO) for UK data exporters; the supervisory authority of the EEA Member State of the data exporter's establishment for EEA data exporters.

Sub-processors: published at https://adalyst.app/sub-processors and maintained continuously.

Signature: this DPA is executed by acceptance of the Agreement; no counter-signature is required.

Exhibit C

Technical and organisational measures

Adalyst implements the following technical and organisational measures. A current list and detail is maintained at https://adalyst.app/security:

  • Encryption in transit: TLS 1.2 or higher for all connections.
  • Encryption at rest: AES-256-GCM authenticated encryption for OAuth tokens, LLM prompt/response audit records, and customer-supplied cloud credentials. Each workspace has its own data-encryption key, wrapped by an environment-level key-encryption-key.
  • Access controls: role-based access control within workspaces; least-privilege within Adalyst's internal systems; all authentication events and privileged actions are logged.
  • Authentication: password login with bcrypt hashing and single sign-on via Google and Microsoft. Session tokens are signed JWTs delivered as HTTP-only, secure, SameSite cookies.
  • Audit logging: every LLM call made on a workspace's behalf is logged with metadata; prompt and response bodies are stored encrypted with the workspace's own data-encryption key, subject to a configurable retention window.
  • Outbound data protection: prompts sent to an upstream language-model provider are subject to automated controls designed to detect and reduce disclosure of sensitive content.
  • De-identification for aggregate data: rollups are computed at segment level (vertical × deal-size bucket × platform) with a minimum cohort size of five (5) organisations; outputs never include customer names, identifiers, or segmented rows that could reconstruct a single customer's data.
  • Deletion: workspace deletion uses a limited soft-delete period followed by removal from primary storage and deletion or destruction of applicable encryption keys, subject to backup cycles and legal retention requirements described in the Privacy Policy.
  • Personnel: persons authorised to access Customer Data are subject to confidentiality obligations and access is limited according to role and operational need.
  • Incident response: documented procedures support investigation, mitigation and notification of Personal Data Breaches; security concerns can be reported to security@adalyst.app.

Questions, requests, or a counter-signed copy on letterhead: legal@adalyst.app.