Last updated: 4 February 2026
This Data Processing Addendum ("DPA") forms part of the agreement between Adealo OÜ ("Adealo", "Processor") and the customer using the Adealo Service ("Customer", "Controller").
This DPA applies where Adealo processes personal data on behalf of the Customer in connection with the Service.
Processor:
Adealo OÜ
Registry Code: 17305560
Address: Harju maakond, Tallinn, Kesklinna linnaosa, Tornimäe tn 5, 10145
Email: legal@adealo.com
Controller:
The entity identified as the customer in the applicable Adealo account, order, or subscription.
Terms such as "personal data," "processing," "controller," "processor," "data subject" have the meanings given in the EU General Data Protection Regulation (GDPR).
The Customer is the data controller and determines the purposes and means of processing personal data.
Adealo acts as a data processor and processes personal data solely on behalf of and according to the documented instructions of the Customer.
Adealo does not determine the purposes for which Customer Data is processed.
Processing of personal data submitted to the Adealo Service by or on behalf of the Customer.
For the duration of the Customer's use of the Service, plus any limited period required for backup retention or legal obligations.
Processing necessary to:
May include:
Customer's end users
Customer's employees, agents, or representatives
The Customer represents and warrants that it:
The Customer is responsible for responding to data subject requests unless otherwise required by law.
Adealo shall:
Notify the Customer without undue delay upon becoming aware of a personal data breach involving Customer Data.
Delete or return personal data upon termination of the Service, subject to legal retention requirements.
Adealo implements reasonable technical and organizational measures, including:
No system is completely secure, and Adealo does not guarantee absolute security.
The Customer authorizes Adealo to engage sub-processors to assist in providing the Service, including:
Adealo shall:
A list of current sub-processors may be made available upon request.
Where AI features are used:
Where personal data is transferred outside the EEA, Adealo ensures appropriate safeguards are in place, including:
Upon reasonable written request, Adealo shall make available information necessary to demonstrate compliance with this DPA. On-site audits are subject to reasonable limitations, confidentiality, and security requirements.
Liability arising from this DPA is subject to the limitations of liability set forth in the Terms of Service.
To the extent applicable:
This DPA is governed by the laws of Estonia, without regard to conflict-of-law rules.
In the event of conflict, this DPA prevails over the Terms of Service with respect to data protection matters.
Data protection inquiries may be sent to:
📧 legal@adealo.com