Legal
Data Processing Agreement
Last updated: August 17, 2026
This page summarizes the standard data processing terms for customers using Amazon Ads Optimizer. A signed DPA can be requested at info@baoks.de.
1. Scope of Processing
Baoks UG (haftungsbeschränkt) processes customer account data, Amazon Advertising data, billing data, and service metadata solely for the provision of the software service, support, security, and legal compliance.
2. Categories of Data
- Account data such as name, email address, and authentication metadata
- Amazon Data synced through the Amazon Ads API
- Billing and subscription records
- Support and operational logs required to secure and operate the service
3. Subprocessors
We engage carefully selected subprocessors in the following categories to operate the service: cloud hosting and application infrastructure; database and authentication services; payment processing services; and security and operational support services.
Amazon Data is disclosed only to subprocessors permitted under the applicable Amazon Ads policies and solely for operating the service. Payment providers process billing data only and do not receive Amazon Data. The Amazon Ads API is the source of Amazon Data and is not a subprocessor of Baoks UG.
A current list of subprocessors is provided with a signed DPA and is otherwise available to customers upon request at info@baoks.de.
4. Technical and Organizational Measures
- Encryption of Amazon refresh tokens at rest using AES-256-GCM
- Access control based on least privilege
- Tenant isolation enforced at the database level
- Logging, rate limiting, and monitoring for abuse prevention and incident response
- Secure deployment infrastructure and authenticated access to administrative systems
5. Breach Notification
We maintain a documented process for security incident response, reviewed at least every six months. As your processor, we notify you as the controller without undue delay after becoming aware of a personal data breach (GDPR Art. 33(2)) so that you can meet your own obligations towards supervisory authorities and data subjects (GDPR Art. 33(1), Art. 34). If an actual or suspected security incident involves Amazon Data, we additionally notify Amazon within 24 hours as required by the Amazon Ads API Data Protection Policy and coordinate the content of notices concerning Amazon Data with Amazon, unless the law requires otherwise.
6. Audit and Cooperation
Upon reasonable request, we provide information necessary to demonstrate compliance with our data protection obligations and cooperate with customer privacy inquiries related to the services covered by this agreement.
7. Deletion of Amazon Data
Upon termination of the account or receipt of a deletion request, we immediately discontinue all processing and syncing of Amazon Data. Amazon Data in active production systems is deleted without undue delay. Residual encrypted backup copies are deleted automatically within a maximum of 30 days.