Data Processing Agreement
For customers with GDPR or CCPA obligations who need a signed agreement on file.
A Data Processing Agreement (DPA) governs how overads, as a data processor, handles personal data that you, as data controller, entrust to us when you use our service. It sits alongside our Terms of Service and Privacy Policy rather than replacing them.
Our Terms of Service do not currently incorporate a DPA by reference. If you need one in place, it has to be requested and signed as a separate document. The subprocessor list below is maintained here and is accurate to what the service actually calls today.
Request a signed DPA
Email dpa@overads.io with your legal entity name, workspace name, and the signatory email, and we will send back a countersigned copy.
dpa@overads.ioSubprocessors
A subprocessor is a third party we send data to in order to deliver part of the service. We group the list, because the distinction matters: vendors we choose and send your data to, vendors that only receive data once you turn a feature on, public sources we query on your behalf, and platforms you connect with your own account. Where we cannot state a processing region from our own configuration, we say so instead of guessing.
Core subprocessors
In the path for every workspace. We send data to these on our own initiative to run the service.
| Name | Purpose | Region |
|---|---|---|
| Amazon Web Services | Key management for encrypting connected-platform tokens, and file storage for uploaded media | United States, us-east-1 by default |
| Google (Gemini API) | AI text and image generation behind the assistant, creative, CRM, and Signals features | See provider documentation |
| Google Analytics | Marketing-site analytics. Only loads after you accept analytics cookies; denied by default | See provider documentation |
| Stripe | Subscription billing and payment processing | See provider documentation |
| Cloudflare | Turnstile bot protection on public forms. Required in production | See provider documentation |
| Email delivery provider | Transactional email such as sign-in codes and invites. Sent through AWS SES or an SMTP provider, depending on how the deployment is configured | See provider documentation |
| Vercel | Frontend hosting | See provider documentation |
Feature-dependent subprocessors
Called only when the matching feature is enabled and its credentials are configured. If the credential is absent, the feature degrades and no data is sent.
| Name | Purpose | Region |
|---|---|---|
| DataForSEO | Keyword, SERP, domain, and backlink data for Signals | See provider documentation |
| OpenAI | Image generation for creatives. It also receives the prompt and any reference images you attach on the automatic route, not only when you pick a GPT Image model | See provider documentation |
| Apify | AI brand monitoring and social profile scraping | See provider documentation |
| Perplexity | AI search visibility scans | See provider documentation |
| Google PageSpeed Insights | Site audit scores | See provider documentation |
| Twilio | WhatsApp one-time passcodes | See provider documentation |
Public sources we query for you
No account and no credential is involved here. We read public endpoints on your behalf, so the search terms we send them, usually your brand, domain, or competitor names, do reach these sites.
| Name | Purpose | Region |
|---|---|---|
| Reddit, Hacker News, GitHub, dev.to | Mention and discussion search behind brand monitoring and Signals research | See provider documentation |
| Trustpilot, Product Hunt, Google News | Review, launch, and news search for the Signals brand audit | See provider documentation |
| Google autocomplete | Keyword suggestion lookups for the keyword tools | See provider documentation |
Platforms you connect yourself
We do not treat these as our subprocessors. You hold the account, you grant the access, and you can revoke it at any time. We list them because data still moves between overads and these platforms on your instruction.
| Name | Purpose | Region |
|---|---|---|
| Meta | Facebook and Instagram ad reporting, page engagement, and lead forms. If you connect WhatsApp, we also send contact phone numbers and message content through the WhatsApp Cloud API on your own credentials | See provider documentation |
| Google Ads | Ad account, campaign, and performance reporting | See provider documentation |
| Google Search Console | Search performance reporting and URL inspection | See provider documentation |
| Google (Gmail) | Mailbox connection for CRM email. Connecting asks Google for read and send access to your mailbox, and we store the resulting refresh token encrypted. Message syncing is not built yet, so no mail is read today | See provider documentation |
| LinkedIn, X, Snapchat | Ad account and campaign reporting for each connected platform | See provider documentation |
| Slack, Discord, Microsoft Teams, Telegram | Notification destinations you configure with your own webhook URL or bot token | See provider documentation |