e Find eFind Ads
Why eFind Ads
Solutions expand_more
Leads Display Search Video Affiliates Earn With Ads
Resources expand_more
All docs For advertisers For publishers Support center
FAQ Contact
1-214-444-8126 Sign in Start now
Why eFind Ads chevron_right
Leads Display Search Video Affiliates Earn With Ads
All docs For advertisers For publishers Support center
FAQ chevron_right Contact chevron_right
Start now Sign in phone 1-214-444-8126
Trust Framework

Data Processing Addendum

This Data Processing Addendum governs how eFind handles Personal Information when we act on your behalf as a business customer. It attaches to your Advertiser Agreement or Publisher Agreement, sets out each party’s data-protection role, and commits eFind to concrete obligations covering security, Sub-processors, international transfers, and breach response.

Purpose

This Data Processing Addendum, which we call the DPA, exists to describe, in one place, the terms that apply whenever eFind LLC (“eFind”) Processes Personal Information on behalf of a business customer. Modern advertising involves the movement of data between many parties, and data-protection laws require the party that decides how and why Personal Information is used to put a written arrangement in place with the party that carries out the Processing. This DPA is that arrangement. It records the instructions eFind follows, the safeguards eFind maintains, and the rights and remedies each party can rely on. It is written to satisfy the requirements of the GDPR, the UK GDPR, the CCPA, the CPRA, and comparable data-protection laws, while remaining readable for the business owners who have to work with it.

Scope

This DPA applies only to Processing that eFind performs as a Processor on behalf of a customer, meaning Processing of Personal Information that the customer controls and that eFind handles under the customer’s instructions in the course of providing the Services. It does not govern Processing for which eFind is itself the Controller, such as the Personal Information eFind collects to run its business, to secure and improve the Services, to meet its own legal obligations, and to bill and support its customers. That independent Controller Processing is described in the Privacy Policy and, where relevant, the GDPR Privacy Notice and the California Privacy Notice. Where a single flow of data involves both roles, this DPA applies to the part of the flow in which eFind acts as a Processor, and the Privacy Policy applies to the part in which eFind acts as a Controller.

Who It Applies To

This DPA applies to any business customer that has entered into an Advertiser Agreement or a Publisher Agreement with eFind and that provides, makes available, or directs the Processing of Personal Information through the Services. It also applies for the benefit of the Data Subjects whose Personal Information is Processed, to the extent Applicable Law gives them enforceable rights under an arrangement of this kind. It does not create a direct contract between eFind and any Data Subject, and it does not apply to individuals who use the Services purely in a personal capacity outside a business relationship.

Definitions

Capitalized terms used in this DPA, such as Advertiser, Publisher, Personal Information, Processing, Controller, Processor, Sub-processor, Data Subject, and Standard Contractual Clauses, have the meanings given in the Master Definitions. This DPA builds on those meanings by describing how each data-protection role works in practice.

Data-Protection Roles

A Controller is the party that decides why and how Personal Information is Processed. In this DPA the customer is normally the Controller, because the customer chooses which Campaigns to run, which audiences to reach, which measurement to enable, and which data to send to eFind. Under the CCPA and CPRA, the Controller occupies the role that those laws call the “business.”

A Processor is the party that Processes Personal Information on behalf of, and under the documented instructions of, a Controller. In this DPA eFind is normally the Processor. Under the CCPA and CPRA, the Processor occupies the role that those laws call the “service provider.”

A Data Subject is the identified or identifiable individual to whom Personal Information relates, referred to as a “consumer” under the CCPA and CPRA. A Data Subject may be a User who sees or interacts with an Advertisement, a visitor to a Publisher Property, or any other individual whose Personal Information the customer provides or directs eFind to Process.

A Sub-processor is a third party that eFind engages to Process Personal Information in the course of providing the Services on behalf of the customer, such as a hosting provider, a specialized measurement vendor, or a support tool. A Sub-processor is distinct from an independent third party to whom the customer separately chooses to send data.

Note

The words “personal data” and “processing” used in the GDPR carry the same meaning here as Personal Information and Processing. We use the Trust Framework terms throughout so that this DPA reads consistently with every other eFind document.

Incorporation and When This DPA Applies

This DPA forms part of, and is incorporated by reference into, the Advertiser Agreement and the Publisher Agreement. It takes effect automatically, without the need for a separate signature, when a customer accepts an Agreement that references it, provided the customer is a business that provides or directs the Processing of Personal Information through the Services. A customer that requires a countersigned copy for its records may request one through support@efind.com, and eFind will make a signature version available where reasonable.

This DPA applies for the entire period during which eFind Processes Personal Information on behalf of the customer, which begins when the customer first submits or directs the Processing of Personal Information through the Services and continues until eFind has deleted or returned that Personal Information in accordance with the section on deletion and return below. Termination of the underlying Agreement does not by itself terminate the obligations in this DPA that are meant to survive, such as confidentiality, security during any wind-down period, and deletion or return.

Roles of the Parties

Customer as Controller, eFind as Processor

For the Processing that is the subject of this DPA, the customer acts as the Controller and eFind acts as the Processor. The customer is responsible for establishing a lawful basis for the Processing, for providing any notices and obtaining any Consents that Applicable Law requires from Data Subjects, and for ensuring that its instructions to eFind are lawful. eFind is responsible for Processing that Personal Information only as this DPA and the customer’s documented instructions permit, and for maintaining the safeguards described below.

The customer confirms that, in providing Personal Information to eFind or directing its Processing, the customer has the authority to do so and has met its own obligations as a Controller. eFind relies on that confirmation and is not responsible for verifying the accuracy of the customer’s legal basis, although eFind will tell the customer if, in eFind’s reasonable opinion, an instruction appears to breach Applicable Law, and eFind may decline to act on an instruction that it reasonably believes is unlawful.

Where the Customer Is a Processor for Another Controller

Some customers are themselves Processors acting for their own clients. If a customer provides Personal Information to eFind in its capacity as a Processor for a third-party Controller, then eFind acts as a Sub-processor to that customer, and the customer confirms that it has the authority from the ultimate Controller to appoint eFind and to bind the ultimate Controller to terms at least as protective as this DPA. The customer remains responsible to eFind for the acts and instructions of the ultimate Controller as though they were the customer’s own.

Where eFind Is an Independent Controller

eFind acts as an independent Controller, not as a Processor, for certain Processing that it carries out for its own purposes even while providing the Services. This includes Processing Personal Information to detect and prevent Fraud and Invalid Traffic across the platform, to secure and monitor the integrity of the Services, to bill and collect Payment, to comply with legal and regulatory obligations, to produce Aggregated Data and de-identified analytics, and to develop and improve the Services in ways that do not depend on any individual customer’s instructions. When eFind acts as an independent Controller, it does so under the Privacy Policy rather than under this DPA, and each party is independently responsible for its own compliance for that Processing. The two parties are not joint Controllers unless they agree so in writing for a specific activity.

eFind’s Obligations as Processor

Processing Only on Documented Instructions

eFind Processes Personal Information only on the customer’s documented instructions, including with respect to International Transfers, unless Applicable Law requires eFind to Process it otherwise. The customer’s complete and final instructions are set out in this DPA, in the Advertiser Agreement or Publisher Agreement, in the settings and configurations the customer selects within the Services, and in any written instructions the customer later gives that eFind agrees to follow. Using the Services in accordance with their Documentation is itself an instruction. If Applicable Law requires eFind to Process Personal Information beyond the customer’s instructions, eFind will, unless the law forbids it, inform the customer of that requirement before Processing.

Confidentiality of Personnel

eFind ensures that the personnel it authorizes to Process Personal Information are bound by appropriate obligations of confidentiality, whether by contract or by a statutory duty, and receive training on their data-protection responsibilities. eFind limits access to Personal Information to those personnel who need it to provide, secure, or support the Services, and it removes access promptly when it is no longer needed.

Security Measures

eFind implements and maintains appropriate technical and organizational measures to protect Personal Information against accidental or unlawful destruction, loss, alteration, unauthorized disclosure, or access. These measures take into account the state of the art, the costs of implementation, and the nature, scope, context, and purposes of the Processing, as well as the risks to Data Subjects. A summary of the current measures appears in Annex B below, and the broader program is described in the Security Policy. eFind may update its measures over time, provided that the level of protection is not materially reduced.

Assistance with Data Subject Rights

eFind assists the customer, by appropriate technical and organizational measures and so far as is reasonably possible, in responding to requests from Data Subjects to exercise their rights, such as the rights of access, correction, deletion, restriction, portability, and objection, and the rights to opt out of sale, sharing, or targeted advertising where Applicable Law provides them. If eFind receives a request directly from a Data Subject that relates to Personal Information eFind Processes on the customer’s behalf, eFind will not respond to the request itself, except to confirm that the request has been received or to direct the Data Subject to the customer, and will promptly forward the request to the customer unless Applicable Law directs otherwise.

Assistance with Security, Breach Notification, and Impact Assessments

eFind assists the customer, taking into account the nature of the Processing and the information available to eFind, in meeting the customer’s obligations to keep Personal Information secure, to notify a Personal Data breach to a supervisory authority and to affected Data Subjects, to carry out a data-protection impact assessment (a DPIA) where one is required, and to consult a supervisory authority in advance where the law requires it. This assistance is limited to Processing that eFind performs as a Processor and to information that is within eFind’s reasonable control.

Sub-processors

General Authorization

The customer gives eFind a general authorization to engage Sub-processors to Process Personal Information in connection with the Services. eFind uses Sub-processors to provide the infrastructure and specialized capabilities that the Services depend on, such as cloud hosting and storage, content delivery, measurement and analytics, communications, and customer support tooling. eFind remains responsible to the customer for the performance of each Sub-processor’s obligations under this DPA.

Sub-processor List and Notice of Changes

eFind maintains an up-to-date list of the Sub-processors it engages for the Processing covered by this DPA, together with a description of what each one does and the country in which it operates. eFind makes that list available to customers on request and, where a customer subscribes to notifications, provides advance notice before adding a new Sub-processor or replacing an existing one for the covered Processing. eFind provides that notice at least thirty days before the new Sub-processor begins Processing Personal Information, except where a shorter period is necessary to address a security, legal, or continuity risk.

Right to Object

If a customer has a reasonable, data-protection-related objection to a new Sub-processor, the customer may notify eFind in writing within the notice period, explaining the grounds for the objection. The parties will then work together in good faith to find a solution, which may include eFind offering an alternative arrangement, adjusting the configuration of the Services for that customer, or the customer choosing not to use the feature that requires the Sub-processor. If no reasonable solution can be found and eFind proceeds with the Sub-processor, the customer may, as its sole remedy, terminate the affected part of the Services by giving written notice, and eFind will refund any prepaid fees for the terminated part covering the period after termination.

Flow-Down Obligations and Liability

Before a Sub-processor begins Processing Personal Information, eFind enters into a written contract with it that imposes data-protection obligations no less protective than those in this DPA, appropriate to the nature of the Processing the Sub-processor performs. Where the Sub-processor is located outside the region from which the Personal Information originates, eFind puts a lawful transfer mechanism in place as described below. eFind remains fully liable to the customer for the acts and omissions of its Sub-processors to the same extent eFind would be liable if it performed the Processing itself.

International Data Transfers

eFind and its Sub-processors may Process Personal Information in the United States and in other countries where eFind or its Sub-processors operate. Where this involves an International Transfer of Personal Information from the EEA, the United Kingdom, Switzerland, or another jurisdiction that restricts cross-border transfers, eFind puts an appropriate transfer mechanism in place so that the Personal Information continues to receive an essentially equivalent level of protection.

Standard Contractual Clauses

For transfers of Personal Information subject to the GDPR to a country that does not benefit from an adequacy determination, the parties incorporate the Standard Contractual Clauses approved by the European Commission by this reference, completed as follows: the module that applies is the one that matches the parties’ roles, meaning Controller-to-Processor where the customer is a Controller, or Processor-to-Processor where the customer is a Processor and eFind acts as a Sub-processor; the customer is the data exporter and eFind is the data importer; the optional docking clause applies; the governing law and the forum for disputes are those of the Republic of Ireland unless another EEA jurisdiction is required; and Annex A and Annex B of this DPA supply the descriptions of the Processing and of the security measures that the Standard Contractual Clauses call for. Where the Standard Contractual Clauses conflict with the rest of this DPA in respect of a transfer they govern, the Standard Contractual Clauses control for that transfer.

UK Addendum and Swiss Transfers

For transfers of Personal Information subject to the UK GDPR, the parties incorporate the International Data Transfer Addendum issued by the United Kingdom Information Commissioner, which sits alongside the Standard Contractual Clauses and modifies them as needed for the United Kingdom. For that Addendum, the parties are those identified in this DPA, the tables are completed using the information in this DPA and its Annexes, and the customer may terminate the transfer where the Addendum permits following a change in United Kingdom law that reduces protection. For transfers subject to Swiss data-protection law, the Standard Contractual Clauses apply with the adjustments the Swiss Federal Data Protection and Information Commissioner requires, including that references to the GDPR are read as references to the Swiss regime and that the Swiss authority and Swiss law govern where appropriate.

Transfer Safeguards and Government Access

eFind assesses the risks associated with International Transfers and applies supplementary measures where they are needed to protect Personal Information, such as encryption in transit and at rest, access controls, and internal policies for handling requests from public authorities. If eFind receives a legally binding request from a government or law-enforcement body for Personal Information it Processes on the customer’s behalf, eFind will, unless legally prohibited, notify the customer, challenge requests that appear unlawful or overbroad, and disclose only the minimum that is legally required.

Personal Data Breach Notification

eFind maintains procedures to detect, investigate, contain, and remediate a Personal Data breach affecting Personal Information it Processes on the customer’s behalf. A Personal Data breach means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to that Personal Information.

Timing

eFind notifies the customer without undue delay, and in any event within seventy-two hours, after eFind becomes aware of a Personal Data breach affecting the customer’s Personal Information. Because eFind is a Processor for this Processing, it is the customer, as Controller, who decides whether and how to notify a supervisory authority and affected Data Subjects, and this DPA does not shift that decision to eFind.

Content of the Notice

eFind’s breach notice describes, to the extent known at the time and updated as more becomes known, the nature of the breach, including the categories and approximate number of Data Subjects and records affected; the likely consequences of the breach; the measures eFind has taken or proposes to take to address the breach and to reduce its effects; and a point of contact from whom the customer can obtain further information. Where eFind cannot provide all of this information at once, it provides it in phases without further undue delay.

Important

A notice from eFind about a Personal Data breach is not, and should not be read as, an admission of fault or liability by eFind. Its purpose is to give the customer the information the customer needs to meet its own legal obligations quickly.

Audits and Compliance

eFind makes available to the customer the information reasonably necessary to demonstrate compliance with this DPA and, where Applicable Law requires it, allows for and contributes to audits, including inspections, of the Processing covered by this DPA. To make this practical for both parties and to protect the security of the Services and the Personal Information of other customers, audits are conducted as follows. First, eFind responds to a reasonable request for information by providing its current certifications, third-party audit reports, security summaries, and answers to a reasonable security questionnaire. Second, if that information does not reasonably resolve the customer’s concern, the customer may request an audit, on at least thirty days’ written notice, no more than once in any twelve-month period unless Applicable Law or a supervisory authority requires more, conducted during normal business hours, without disrupting eFind’s operations, and subject to confidentiality obligations. The audit does not extend to eFind’s Confidential Information that is unrelated to the covered Processing, to Personal Information of other customers, or to systems that would compromise the security of other customers. The customer bears the cost of any audit it requests, except where the audit reveals a material breach of this DPA by eFind, in which case eFind bears its own reasonable costs of supporting that audit.

Deletion or Return of Personal Information

On termination or expiry of the Services to which the Processing relates, and at the customer’s choice, eFind deletes or returns the Personal Information it Processes on the customer’s behalf and deletes existing copies, unless Applicable Law requires eFind to retain some or all of it. If the customer does not make a choice within thirty days after termination, eFind deletes the Personal Information. Deletion is carried out within a commercially reasonable period, generally within ninety days, after which the Personal Information is no longer accessible in eFind’s production systems, subject to routine backup cycles that expire on their normal schedule and to any Personal Information that eFind retains as an independent Controller for the purposes described in this DPA. On request, eFind confirms in writing that it has completed the deletion or return. Personal Information that eFind is required to retain remains subject to the confidentiality and security obligations of this DPA for as long as eFind holds it.

CCPA and CPRA Service-Provider Terms

To the extent eFind Processes Personal Information of California residents on the customer’s behalf, eFind acts as a “service provider” and the customer acts as a “business,” as those terms are used in the CCPA and CPRA. For that Processing, eFind commits to the following.

  • eFind Processes the Personal Information only to perform the Services specified in the Agreement and for the business purposes set out in this DPA, and not for any other purpose.
  • eFind does not sell or share the Personal Information within the meaning of the CCPA and CPRA.
  • eFind does not retain, use, or disclose the Personal Information outside the direct business relationship with the customer, except as the CCPA and CPRA permit a service provider to do.
  • eFind does not combine the Personal Information it receives from or on behalf of the customer with Personal Information it receives from other sources, except as the CCPA and CPRA permit a service provider to do.
  • eFind complies with the applicable obligations of the CCPA and CPRA and provides the Personal Information the same level of protection those laws require.
  • eFind notifies the customer if it determines that it can no longer meet these obligations, and the customer may take reasonable and appropriate steps to stop and remediate any unauthorized use of Personal Information.
  • eFind grants the customer the right, on notice, to take reasonable and appropriate steps to help ensure that eFind uses the Personal Information in a manner consistent with the customer’s obligations under the CCPA and CPRA.

The customer confirms that it discloses Personal Information to eFind only for the limited and specified purposes described in this DPA. Nothing in this section prevents eFind from Processing Personal Information as an independent Controller for the limited purposes that the CCPA and CPRA allow a service provider to pursue, such as detecting security incidents and protecting against Fraud, or as required by law.

Liability and Order of Precedence

Each party’s liability arising out of or related to this DPA is subject to the limitations and exclusions of liability set out in the Advertiser Agreement or Publisher Agreement, and any reference in those Agreements to the liability of a party means the aggregate liability of that party across the Agreement and this DPA together. This does not limit any liability that cannot be limited under Applicable Law, including certain liability to Data Subjects under the Standard Contractual Clauses.

If there is a conflict between the documents that make up the relationship, the following order of precedence applies for the matter in conflict, from highest to lowest: first, the Standard Contractual Clauses and the UK Addendum, for the International Transfers they govern; second, this DPA; third, the Advertiser Agreement or Publisher Agreement; and fourth, any other document, including the Policies. This order applies only to a genuine conflict about the Processing of Personal Information and does not override a more specific provision that clearly states it controls.

Annex A: Details of Processing

This Annex describes the Processing that eFind carries out as a Processor on behalf of the customer. Where the Standard Contractual Clauses or the UK Addendum require a description of the Processing, this Annex supplies it.

ItemDescription
Subject matter eFind’s Processing of Personal Information as necessary to provide the Advertising Services and Publisher Network services to the customer under the Agreement, including delivering, targeting, measuring, and supporting Campaigns and inventory.
Duration For the term of the Agreement, plus the period until eFind deletes or returns the Personal Information as described in this DPA, plus any period during which Applicable Law requires retention.
Nature of the Processing Collection, receipt, storage, organization, use, analysis, disclosure to authorized Sub-processors, transfer, restriction, deletion, and other operations needed to operate the Services and to comply with the customer’s instructions.
Purpose of the Processing To plan, create, target, deliver, optimize, measure, and report on Advertisements; to attribute Conversions; to detect and prevent Invalid Traffic and Fraud in connection with the customer’s activity; to provide support; and to perform the parties’ obligations under the Agreement.
Categories of Data Subjects Users who view or interact with Advertisements; visitors to Publisher Properties; the customer’s prospects, customers, and audience members whose data the customer provides or directs eFind to Process; and the customer’s Authorized Users to the extent their Personal Information is involved.
Categories of Personal Information Online identifiers such as Cookie and Device identifiers and IP addresses; approximate location derived from an IP address; browser, Device, and technical information; interaction data such as Clicks, Impressions, and Conversions; audience and segment attributes the customer supplies or selects; and, where the customer provides it, contact identifiers used for audience matching in hashed or pseudonymized form.
Sensitive Personal Information The Services are not designed to Process Sensitive Personal Information on the customer’s behalf, and the customer agrees not to provide or direct the Processing of Sensitive Personal Information except where the Services expressly support it and the customer has a lawful basis. Any such Processing is subject to the additional protections Applicable Law requires.
Frequency of the transfer Continuous, for as long as the customer uses the Services.
Recipients eFind personnel who need access to provide, secure, and support the Services, and the authorized Sub-processors described in this DPA and eFind’s Sub-processor list.

Annex B: Security Measures

This Annex summarizes the technical and organizational measures eFind maintains to protect Personal Information it Processes as a Processor. Where the Standard Contractual Clauses or the UK Addendum require a description of the security measures, this Annex supplies it. The full program is described in the Security Policy, which eFind may update as its practices and the threat landscape evolve, provided the level of protection is not materially reduced.

AreaMeasures
Access control Role-based access limited to personnel with a need to know; unique accounts; multi-factor authentication for administrative and remote access; and periodic review and prompt removal of access that is no longer needed.
Encryption Encryption of Personal Information in transit using current transport-layer protocols and encryption of Personal Information at rest in production data stores, together with managed handling of encryption keys.
Network and system security Segmentation of networks, firewalls and access restrictions, hardening of systems, timely patching, and monitoring and logging designed to detect and alert on suspicious activity.
Pseudonymization and minimization Use of identifiers rather than direct contact details where possible, hashing of contact identifiers used for audience matching, and configuration of the Services to collect and retain only what is needed for the stated purposes.
Resilience and recovery Backups, redundancy, and documented business-continuity and disaster-recovery plans designed to restore availability and access to Personal Information in a timely manner after an incident.
Incident management A documented incident-response process covering detection, triage, containment, remediation, and notification, including the breach-notification commitments in this DPA.
Vendor and Sub-processor management Due diligence before engaging Sub-processors, written contracts imposing protective obligations, and ongoing oversight appropriate to the Processing each Sub-processor performs.
Personnel and governance Confidentiality obligations for personnel, security and privacy training, background checks where lawful and appropriate, written security policies, and regular testing and assessment of the effectiveness of the measures.
Physical security Reliance on data-center facilities that maintain physical access controls, environmental protections, and monitoring appropriate to hosting Personal Information.

How to Contact Us

Questions about this DPA, requests for a signature version, requests for eFind’s Sub-processor list or security documentation, and data-protection notices may be sent to the eFind Office of Trust and Legal at support@efind.com or by telephone at 1-214-444-8126. Written notices may be sent to eFind LLC at 2451 West Grapevine Mills Circle, Suite 324, Grapevine, TX 76051, United States.

Related Documents

  • Privacy Policy
  • GDPR Privacy Notice
  • California Privacy Notice
  • Security Policy
  • Advertiser Agreement
  • Publisher Agreement
  • Master Definitions

Building Technology People Can Trust.

© 2026 eFind. All rights reserved.

eFind

About Contact Careers Mission Technology Trademarks

Advertising

eFind Ads eFind TV Earn with Ads Affiliates Countries Resources FAQ

Data

GDPR Policies Privacy Terms Equal Opportunity

Products

Search AI Search Mail Maps eTube News Weather
eFind
About Contact Careers Mission Technology Trademarks
Advertising
eFind Ads eFind TV Earn with Ads Affiliates Countries Support
Data
GDPR Policies Privacy Terms
Products
Search AI Search Mail Maps eTube News Weather
© 2026 eFind. All rights reserved. Made in the USA.