Data processing addendum
Effective 2 October 2026
This addendum forms part of the terms of service between you and Tagan Labs LLC. You accept it when you accept the terms; no separate signature is needed. If you need a signed copy, email support@ultraroas.ai.
1. Scope and roles
This addendum applies when we process personal data on your behalf in providing UltraROAS.ai("customer personal data") and a data protection law applies, such as the EU General Data Protection Regulation (GDPR), the UK GDPR and Data Protection Act 2018, the Swiss Federal Act on Data Protection, or US state privacy laws. You are the controller (or a processor acting for your own controller) and we are your processor (or service provider).
Terms such as "controller", "processor", "personal data" and "personal data breach" have the meaning given in the GDPR. If this addendum conflicts with the terms, this addendum applies to customer personal data.
2. Details of the processing
- Subject matter and purpose: providing the service as described in the terms: importing, reporting on, diagnosing and, on your approval, changing your Google Ads and Merchant Center accounts, answering your questions with AI features, support and security.
- Duration: while you use the service, and until the data is deleted as described in our privacy policy.
- Data subjects: people in your workspace; people whose details appear in your Google accounts or product data, such as in search terms, product data or account contacts; and people who contact you through channels you connect.
- Types of personal data: names, email addresses, roles and activity records of your users; any personal data contained in search terms, product data, account settings and support messages. The service is not designed for special category data, and you should not send it.
- Processing operations: collection through Google's APIs, storage, organisation, analysis, display, transmission to the subprocessors listed, and deletion.
3. Our obligations
- We process customer personal data only on your documented instructions, which are the terms, this addendum and your use of the service's features, unless the law requires otherwise, in which case we tell you first unless the law forbids it. We tell you if we think an instruction breaks data protection law.
- Everyone we authorise to process customer personal data is bound by confidentiality.
- We maintain the technical and organisational measures described below and on our Security page.
- We help you, taking into account the nature of the processing, to respond to requests from data subjects, and with security, breach notification, data protection impact assessments and prior consultation.
- We do not sell customer personal data, or use it for any purpose other than providing the service.
4. Subprocessors
You authorise us to use the subprocessors listed on our subprocessors page. We impose data protection obligations on each of them that are no less protective than this addendum, and we remain responsible for their performance. We will email workspace owners at least 30 days before adding or replacing a subprocessor. If you object on reasonable data protection grounds, tell us within that period; we will try to find a solution, and if we cannot, you may stop using the affected feature or end the terms.
5. International transfers
Customer personal data is processed in the United States. Where a transfer from the European Economic Area, the United Kingdom or Switzerland needs a transfer mechanism, the Standard Contractual Clauses adopted by the European Commission in Decision 2021/914 (Module Two, controller to processor, or Module Three, processor to processor) are incorporated into this addendum, with you as data exporter and us as data importer. For those clauses: the optional docking clause does not apply; option 2 (general authorisation) applies to subprocessors, with the notice period above; the optional redress clause does not apply; they are governed by the law of Ireland and disputes go to the courts of Ireland; and the annexes are completed by this addendum. For UK transfers, the UK International Data Transfer Addendum issued by the Information Commissioner applies, and for Swiss transfers the clauses apply with the Swiss Federal Act on Data Protection in place of the GDPR.
6. Personal data breaches
We will notify the workspace owner without undue delay, and in any case within 72 hours, after becoming aware of a personal data breach affecting customer personal data. We will provide the information you reasonably need to meet your own obligations, as it becomes available, and take reasonable steps to contain the breach.
7. Deletion and return
You can export your workspace data from Settings at any time. When you delete your workspace, or the terms end, we delete customer personal data from our active systems within 30 days, and from backups when they expire, unless the law requires us to keep it.
8. Audits
On request, we will provide the information reasonably needed to show that we meet this addendum, such as written answers to security questionnaires. If that is not enough, or a regulator requires it, you may audit our compliance, at your cost, once a year with at least 30 days' notice, during business hours, under confidentiality, and without access to other customers' data.
9. US state privacy laws
Where US state privacy laws apply, we act as your service provider or processor. We will not sell or share customer personal data, retain, use or disclose it outside our direct business relationship with you or for any purpose other than providing the service, or combine it with personal data from other sources except as those laws allow. We will tell you if we can no longer meet these obligations.
10. Security measures
- Encryption of all data in transit with TLS, and of Google refresh tokens at rest with AES-256-GCM.
- Separation of each workspace's data with row-level security in the database.
- Role-based access inside workspaces, and approval by a person before any change is sent to Google.
- OAuth sign-in with chosen permissions for connected AI tools, which can be revoked at once.
- Audit logs of approvals, changes and AI tool connections.
- Protection against cross-site request forgery, a strict content security policy and rate limits.
- Logs that exclude tokens and the content of AI conversations, and error monitoring.
- Access to production systems limited to the people who run the service.
- Retention limits and deletion of workspace data within 30 days of deletion.
11. Liability and contact
Each party's liability under this addendum is subject to the limits in the terms, except where the law does not allow them. Contact for data protection matters: Tagan Labs LLC, 30 N Gould St, STE R, Sheridan, Wyoming 82801, United States, support@ultraroas.ai.
