First 200 users get the Growth plan for $19/mo.

Claim
Legal

Data Processing Agreement

For customers with GDPR or CCPA obligations who need a signed agreement on file.

A Data Processing Agreement (DPA) governs how overads, as a data processor, handles personal data that you, as data controller, entrust to us when you use our service. It sits alongside our Terms of Service and Privacy Policy rather than replacing them.

Our Terms of Service do not currently incorporate a DPA by reference. If you need one in place, it has to be requested and signed as a separate document. The subprocessor list below is maintained here and is accurate to what the service actually calls today.

Request a signed DPA

Email dpa@overads.io with your legal entity name, workspace name, and the signatory email, and we will send back a countersigned copy.

dpa@overads.io

Subprocessors

A subprocessor is a third party we send data to in order to deliver part of the service. We group the list, because the distinction matters: vendors we choose and send your data to, vendors that only receive data once you turn a feature on, public sources we query on your behalf, and platforms you connect with your own account. Where we cannot state a processing region from our own configuration, we say so instead of guessing.

Core subprocessors

In the path for every workspace. We send data to these on our own initiative to run the service.

NamePurposeRegion
Amazon Web ServicesKey management for encrypting connected-platform tokens, and file storage for uploaded mediaUnited States, us-east-1 by default
Google (Gemini API)AI text and image generation behind the assistant, creative, CRM, and Signals featuresSee provider documentation
Google AnalyticsMarketing-site analytics. Only loads after you accept analytics cookies; denied by defaultSee provider documentation
StripeSubscription billing and payment processingSee provider documentation
CloudflareTurnstile bot protection on public forms. Required in productionSee provider documentation
Email delivery providerTransactional email such as sign-in codes and invites. Sent through AWS SES or an SMTP provider, depending on how the deployment is configuredSee provider documentation
VercelFrontend hostingSee provider documentation

Feature-dependent subprocessors

Called only when the matching feature is enabled and its credentials are configured. If the credential is absent, the feature degrades and no data is sent.

NamePurposeRegion
DataForSEOKeyword, SERP, domain, and backlink data for SignalsSee provider documentation
OpenAIImage generation for creatives. It also receives the prompt and any reference images you attach on the automatic route, not only when you pick a GPT Image modelSee provider documentation
ApifyAI brand monitoring and social profile scrapingSee provider documentation
PerplexityAI search visibility scansSee provider documentation
Google PageSpeed InsightsSite audit scoresSee provider documentation
TwilioWhatsApp one-time passcodesSee provider documentation

Public sources we query for you

No account and no credential is involved here. We read public endpoints on your behalf, so the search terms we send them, usually your brand, domain, or competitor names, do reach these sites.

NamePurposeRegion
Reddit, Hacker News, GitHub, dev.toMention and discussion search behind brand monitoring and Signals researchSee provider documentation
Trustpilot, Product Hunt, Google NewsReview, launch, and news search for the Signals brand auditSee provider documentation
Google autocompleteKeyword suggestion lookups for the keyword toolsSee provider documentation

Platforms you connect yourself

We do not treat these as our subprocessors. You hold the account, you grant the access, and you can revoke it at any time. We list them because data still moves between overads and these platforms on your instruction.

NamePurposeRegion
MetaFacebook and Instagram ad reporting, page engagement, and lead forms. If you connect WhatsApp, we also send contact phone numbers and message content through the WhatsApp Cloud API on your own credentialsSee provider documentation
Google AdsAd account, campaign, and performance reportingSee provider documentation
Google Search ConsoleSearch performance reporting and URL inspectionSee provider documentation
Google (Gmail)Mailbox connection for CRM email. Connecting asks Google for read and send access to your mailbox, and we store the resulting refresh token encrypted. Message syncing is not built yet, so no mail is read todaySee provider documentation
LinkedIn, X, SnapchatAd account and campaign reporting for each connected platformSee provider documentation
Slack, Discord, Microsoft Teams, TelegramNotification destinations you configure with your own webhook URL or bot tokenSee provider documentation