Legal
Data Processing Addendum
How AdOps processes Meta ad-account data on a customer's instructions — the roles, the categories of data, the sub-processors involved, and what happens at termination. This page is the current AdOps Data Processing Addendum, effective 1 August 2026 and last updated 1 August 2026. It is a plain-language draft that has not been reviewed by qualified counsel.
Effective Last updated
Template notice. This document is a plain-language draft describing how the AdOps platform processes data on a customer’s behalf. It has not been reviewed by qualified counsel, it is not legal advice, and it is not yet drafted against any specific regime such as Indonesia’s personal data protection law or the GDPR. A lawyer must review, complete and adapt it before it is signed or relied upon.
AdOps processes Meta ad-account data on a customer’s instructions. The customer decides which ad accounts AdOps may act on and writes the rules that decide what happens; AdOps runs those rules, records what happened, and holds the resulting data. This addendum sets out that relationship, the sub-processors involved, and what happens when the relationship ends.
Roles
The customer is the controller of the ad-account data and any personal data contained in it. AdOps is the processor and acts on the customer’s documented instructions.
Where the customer’s own end-customer data appears in a Google Sheet used by a custom metric, the customer remains the controller of that data too. AdOps reads only the columns the custom metric names.
What the processing consists of
| Item | Description |
|---|---|
| Subject matter | Automated management of Meta advertising campaigns according to rules the customer defines |
| Duration | For as long as the customer’s AdOps account exists, plus any period needed to settle billing |
| Nature | Reading advertising metrics from the Meta Graph API; writing status, budget, name and duplication changes back; storing rule definitions and execution records |
| Purpose | Delivering the AdOps service to the customer |
| Types of data | Account and contact details of the customer’s users; Meta profile metadata returned when a token is verified; ad-account identifiers, spend and metrics; rule definitions and execution records; billing records; any values the customer places in a linked Google Sheet |
| Data subjects | The customer’s own staff and any individuals identifiable in the data the customer connects |
The customer’s instructions
The customer instructs AdOps through the product itself. Three actions are the instruction:
- Connecting Meta and supplying an access token authorises AdOps to call the Meta Graph API on the customer’s behalf.
- Activating an ad account brings it into scope. Ad accounts discovered from Meta are stored inactive until the customer activates them.
- Setting a rule live instructs AdOps to evaluate it on the schedule it carries and to execute its actions when its conditions pass.
AdOps will not process the data for any other purpose. If AdOps believes an instruction conflicts with applicable law, it will say so rather than act on it.
Confidentiality
Access to customer data is limited to personnel who need it to operate and support the service, and those personnel are bound by confidentiality obligations.
Security measures
AdOps applies the following technical measures. This list describes what the platform does; it is a description, not a warranty.
- Authentication with a bearer token that expires 24 hours after issue, verified on every request.
- Passwords stored as hashes and subject to a composition requirement of upper case, lower case, a digit and a symbol.
- Meta access tokens stored server-side and used only for the ad accounts the customer has activated.
- Ad accounts stored inactive on discovery, so nothing is acted on without an explicit activation.
- A separation between the dispatcher, which only reads from the Meta Graph API, and the worker, which performs writes.
- An execution record for every campaign a rule touches, including the conditions that were true and the values that changed.
- A deduplicated error log with normalised messages, in which timestamps, identifiers and IP addresses are masked.
No system is free of risk. This addendum makes no guarantee of security, and the measures above may change as the platform changes.
Sub-processors
The customer authorises the following sub-processors.
| Sub-processor | Function | Data involved |
|---|---|---|
| Meta Platforms | The advertising platform being automated | All ad-account reads and writes |
| Reading spreadsheets referenced by custom metrics, through a service account | The columns named by the custom metric | |
| Anthropic | Generating rule drafts from a plain-language goal, when that feature is used | The goal text the user types and the metric catalogue |
| Duitku | Payment processing | Invoice and payment details |
| SMTP email provider | Transactional email delivery | Recipient address, name and message content |
| Infrastructure providers | Hosting, container registries, the MongoDB database and the Redis queue | All platform data at rest and in transit |
Some sub-processors operate outside Indonesia, so processing may take place abroad. AdOps will give notice of a new sub-processor by email before it begins processing, and a customer who objects on reasonable data-protection grounds may terminate the affected service.
Assisting the customer
On written request, AdOps will help the customer respond to access, correction, deletion and portability requests from data subjects, and will provide the information the customer reasonably needs to complete a data protection impact assessment for the processing described here.
Most of this is self-service: rule definitions, execution records, custom metrics and invoices are all visible and exportable inside the product, and deleting a rule deletes its execution records.
Personal data breaches
If AdOps becomes aware of a personal data breach affecting customer data, it will notify the customer without undue delay at the email address on the account, with the facts known at the time, the likely consequences, and the steps taken or proposed.
Deletion and return
On termination, the customer may export the data available in the product. On written request to support@adops.id, AdOps will delete the customer’s account data, rule definitions, execution records, custom metrics and cached spreadsheet rows, retaining only what is required for billing and legal purposes.
Disconnecting Meta before termination is the fastest way to end AdOps’ access: it deletes the ad-account records stored for the account and clears the stored token.
Audit
On reasonable written notice and not more than once a year, AdOps will make available the information needed to demonstrate compliance with this addendum, and will respond to a reasonable security questionnaire. On-site audits are by agreement.
Precedence
Where this addendum conflicts with the Terms of Service on the processing of personal data, this addendum applies.
Requests under this addendum go to admin@adops.id.
Questions about this document
Legal, procurement and data-protection questions go to admin@adops.id. Include your company name and, if the question is about a specific account, the ad account ID.