AdCharter is operated by [to be provided: company legal name] ("Programz"). To run AdCharter we rely on a small number of third-party providers. This page lists them: it is the list of Approved Subprocessors referred to in our Data Processing Agreement (DPA), which forms part of our Terms of Service.
A sub-processor is a company that processes personal data on our behalf when we process Customer Personal Data for our customers. Customer Personal Data is the content that customers and their users put into AdCharter, such as briefs, comments, approvals and uploaded files. We have a written agreement with each sub-processor that requires it to protect that data and to use it only to provide its services to us, and we share only the data each provider needs. The terms of our DPA apply to all processing on this list.
Some providers also process data for which Programz is the controller, such as account, billing and server log data; our Privacy Policy describes that processing. Stripe also acts as an independent controller for fraud prevention and legal compliance.
The providers under "Integrations you choose to connect" are used only when a customer or user chooses to connect them. When you connect one, we send data to it on your instruction, and the provider also processes that data under your own agreement with it (for example, Meta's terms for advertisers or Slack's customer terms). You can stop these transfers at any time by disconnecting the integration.
Infrastructure and service providers
DigitalOcean
- Entity: DigitalOcean, LLC (United States).
- Purpose: cloud hosting of the AdCharter application and database, and storage of encrypted database backups (DigitalOcean Droplets and Spaces).
- Data processed: all Customer Personal Data held in the AdCharter database and its backups, and server logs.
- Location: [to be provided: hosting location].
- Transfer safeguard: Standard Contractual Clauses and, where the provider is certified, the EU-US Data Privacy Framework (with its UK Extension).
BuildCharter Assets (bcassets)
- Entity: [to be provided: operator of BuildCharter Assets], part of the Programz group.
- Purpose: storage and delivery of uploaded files, such as creatives, creator footage, images, product images and logos. The files themselves are stored on DigitalOcean Spaces.
- Data processed: uploaded files, which may show people, and file details such as file names, sizes and folder paths.
- Location: [to be provided: file storage location].
- Transfer safeguard: a written agreement within the Programz group, with Standard Contractual Clauses where a transfer outside the EEA or the UK requires them.
Stripe
- Entity: Stripe, Inc. (United States) and Stripe Payments Europe, Limited (Ireland).
- Purpose: subscription payments, invoices and tax calculation (Stripe Checkout, Customer Portal, Stripe Tax and Stripe invoices).
- Data processed: billing data only: billing contact name and email address, company name, address, VAT or tax ID, and payment details. Payment card details are entered directly with Stripe and never reach AdCharter. Stripe does not receive briefs, files or other customer content.
- Location: United States and European Union (Ireland).
- Transfer safeguard: Standard Contractual Clauses and, where the provider is certified, the EU-US Data Privacy Framework (with its UK Extension).
Resend
- Entity: Plus Five Five, Inc., doing business as Resend (United States).
- Purpose: delivery of transactional email: invitations, task links, email confirmation, password resets, notifications when Slack is not available, and alerts to the platform operator. We do not send marketing email.
- Data processed: recipient names and email addresses, and email content, which may include brief names, comments, the people involved and links to tasks.
- Location: United States.
- Transfer safeguard: Standard Contractual Clauses and, where the provider is certified, the EU-US Data Privacy Framework (with its UK Extension).
Integrations you choose to connect
These providers are used only when a customer or user chooses to connect them.
Slack
- Entity: Slack Technologies, LLC (United States).
- Purpose: only when a customer connects a Slack workspace to a brand: posting updates to the chosen channel, and direct messages about task assignments, @mentions and Meta ad disapprovals.
- Data processed: the Slack bot token (stored encrypted by AdCharter), the channel ID, Slack user IDs matched by email address, and message content such as brief names, states, the people involved and links. When the Slack app is removed, this data is deleted from AdCharter within 14 business days.
- Location: United States.
- Transfer safeguard: Standard Contractual Clauses and, where the provider is certified, the EU-US Data Privacy Framework (with its UK Extension).
Meta
- Entity: Meta Platforms, Inc. (United States) and Meta Platforms Ireland Limited (Ireland).
- Purpose: only when a brand connects Meta through Facebook Login for Business: launching ads and reading ad performance in the customer's own ad accounts.
- Data processed: creatives and ad copy sent for launch (which may show people), ad, ad set and campaign names, Meta business asset IDs (such as ad accounts, Pages, Instagram accounts and pixels), the access token (stored encrypted by AdCharter), and aggregated ad performance metrics received from Meta.
- Location: United States and Ireland.
- Transfer safeguard: Standard Contractual Clauses and, where the provider is certified, the EU-US Data Privacy Framework (with its UK Extension).
- Entity: Google LLC (United States).
- Purpose: only for users who choose "Sign in with Google": authentication.
- Data processed: name, email address, profile picture URL and Google account ID, received from Google with the openid, email and profile scopes only.
- Location: United States.
- Transfer safeguard: Standard Contractual Clauses and, where the provider is certified, the EU-US Data Privacy Framework (with its UK Extension).
Changes to this list
We tell customers at least 30 days before a new sub-processor starts processing Customer Personal Data, by email to each organisation's admins and by updating this page; the date at the top of the page shows when the list last changed. If you have reasonable data protection concerns about a new sub-processor, you can object within 30 days of our notice by writing to [to be provided: privacy email address]. We will work with you in good faith to resolve the objection, and if we cannot, you may end your agreement as set out in Section 2.6 of the DPA.
Contact
Questions about our sub-processors or data protection: [to be provided: privacy email address].