Data Processing Addendum
Last updated 8 August 2026
The terms under which Lemmonite LLC processes end-user personal data on behalf of Adback customers.
1. Parties, scope, and incorporation
This Data Processing Addendum ("DPA") forms part of the agreement between Lemmonite LLC("Adback", "processor") and the customer accepting our Terms of Service("Customer", "controller" or "processor", as applicable). It applies whenever Adback processes personal data subject to the EU GDPR or UK GDPR on Customer's behalf through the Adback website, dashboard, APIs, and SDKs (the "Service"). If this DPA conflicts with the Terms, this DPA prevails for that processing. For questions about executing or countersigning this DPA, contact [email protected].
2. Definitions
"Personal data", "processing", "controller", "processor", "data subject", and "personal data breach" have the meanings given in the GDPR. "SCCs" means the Standard Contractual Clauses approved by the European Commission decision 2021/914. "UK Addendum" means the UK ICO's international data transfer addendum to the SCCs.
3. Processing on documented instructions
Adback processes Customer end-user data only on Customer's documented instructions, including with regard to international transfers, unless required to do otherwise by law that applies to Adback; in that case Adback informs Customer of the legal requirement before processing, unless the law prohibits this. The Terms, this DPA, and the settings Customer configures in the Service — signal links, SDK integration, event mapping, and connected advertising-network and revenue integrations — are Customer's complete documented instructions. Adback will inform Customer if, in its opinion, an instruction infringes the GDPR.
4. Details of processing
- Subject matter:mobile install attribution, event measurement, and forwarding of conversion signals for Customer's apps.
- Duration: the term of the agreement, plus the deletion period in Section 11.
- Frequency: continuous or intermittent, as Customer and its end users use the Service during the agreement.
- Nature and purpose:collecting clicks on Customer's signal links; receiving install, event, and revenue data from Customer's apps and connected sources; matching installs and events to clicks; reporting; and sending conversion signals to advertising networks Customer connects (TikTok is the supported postback network today).
- Categories of data subjects:end users of Customer's apps and people who click Customer's signal links.
- Categories of personal data: online identifiers and measurement data — advertising click IDs captured from the network URL; coarse device, locale, and campaign context; install and in-app events; connected subscription and purchase events; and the raw client IP address plus a coarse network prefix stored on new click and install records for matching and attribution debugging. Raw IP values are kept out of logs, metrics, event snapshots, and remote error responses. Adback does not collect IDFA, GAID/AAID, Android ID, OAID, IMEI/MEID, MAC address, installed-app lists, or precise location.
- Special categories: none. Customer must not submit special categories of data or data relating to criminal convictions.
5. Confidentiality
Adback ensures that persons authorised to process Customer end-user data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality, and that access is limited to what their role requires.
6. Security (Article 32)
Adback implements and maintains technical and organisational measures appropriate to the risk, including:
- Encryption of data in transit.
- Encryption of stored advertising-network credentials.
- Access controls, least-privilege internal access, and isolation of each customer's data by tenant.
- Exclusion of raw IP addresses from logs, metrics, event snapshots, and remote error responses.
- Monitoring, incident response procedures, and operational hardening of the production infrastructure.
Adback may update these measures over time, provided the update does not materially lower the level of protection.
7. Sub-processors
Customer gives Adback general written authorisation to engage sub-processors to run the Service. The core sub-processors that can process Customer end-user data are Hetzner Online GmbH for hosting, Cloudflare, Inc. for edge link delivery and queues, and Functional Software, Inc. for Sentry error monitoring. Adback keeps raw IP values out of Sentry reports. Request the current list at [email protected]. Adback will:
- Give Customer notice of intended additions or replacements, giving Customer the opportunity to object on reasonable data-protection grounds before the change takes effect.
- Impose data-protection obligations on each sub-processor that are materially equivalent to this DPA.
- Remain fully liable to Customer for the performance of each sub-processor's obligations.
8. Assistance
Taking into account the nature of the processing, Adback assists Customer with appropriate technical and organisational measures, insofar as this is possible, in fulfilling Customer's obligations to respond to data subject requests (access, rectification, erasure, restriction, portability, objection). Adback also assists Customer in ensuring compliance with Articles 32 to 36 — security, breach notification, data protection impact assessments, and prior consultation — taking into account the information available to Adback. Requests go to [email protected].
9. Personal data breach notice
Adback notifies Customer without undue delay after becoming aware of a personal data breach affecting Customer end-user data, and provides the information reasonably available to Adback about the nature of the breach, the categories and approximate number of data subjects and records concerned, the likely consequences, and the measures taken or proposed. Adback's notice is not an admission of fault.
10. Audits
Adback makes available to Customer the information necessary to demonstrate compliance with Article 28 and allows for and contributes to audits, including inspections, conducted by Customer or an auditor mandated by Customer. Audits require reasonable prior notice, run during normal business hours, occur no more than once per year unless a supervisory authority requires otherwise or a breach has occurred, respect confidentiality, and must not compromise other customers' data. Adback may first satisfy an audit request with relevant documentation of its measures.
11. Deletion and return
At the end of the Service, Adback deletes or returns Customer end-user data, at Customer's choice, and deletes existing copies unless law applicable to Adback requires further storage. Customer can request deletion earlier at [email protected].
12. International transfers
Lemmonite LLC is established in the United States. Where Customer transfers personal data subject to the EU GDPR to Adback, the SCCs are incorporated into this DPA by reference. Module Two applies when Customer is a controller. Module Three applies when Customer is a processor. Customer is the data exporter and Adback is the data importer. Sections 4, 6, and 7 populate the SCC annexes. Where the UK GDPR applies, the UK Addendum is incorporated on the same basis. Adback imposes equivalent transfer safeguards on sub-processors where required.
13. Customer duties
- Establish a lawful basis for the processing Customer configures, including conversion-signal forwarding to connected advertising networks, and provide any notices and obtain any consents required by law.
- Issue only lawful instructions, and keep configuration accurate.
- Do not submit special categories of data, criminal-offence data, or data of children knowingly directed to the Service.
- Respond to data subjects and supervisory authorities for Customer's own controller obligations.
14. Contact and execution
Questions about this DPA, requests for the current sub-processor list, or execution and countersignature requests go to [email protected].