Last updated: 13 August 2026
Vargas Digital SRL · Sat Vălișoara, Județul Cluj, Romania · CUI 41265668 · Reg. Com. J2019002466127 · EUID ROONRC.J2019002466127
For personal data contained in Connected Accounts and collected via the Tracking module, the Controller determines the purposes and means of processing and the Processor processes such data only to provide the Service and on the Controller's documented instructions (including via the App's configuration). For the Processor's own account, billing and security data, the Processor acts as an independent controller under its Privacy Policy.
The Processor will promptly notify the Controller of any request received directly from a data subject relating to the Controller's data and will not respond except on the Controller's instruction or as legally required. The Processor will notify the Controller without undue delay after becoming aware of a personal‑data breach affecting the Controller's data, with the information reasonably available to assist the Controller's own notification obligations.
The Controller provides general authorization for the Processor to engage sub‑processors. The Processor imposes data‑protection obligations on each sub‑processor equivalent to those in this DPA and remains liable for their performance. Current sub‑processors (Annex III):
| Sub‑processor | Service | Processing location | Transfer safeguard |
|---|---|---|---|
| Hostinger International Ltd. | Application hosting & database | European Union (Frankfurt, Germany) | Within EEA |
| Stripe Payments Europe, Limited (with Stripe, Inc.) | Subscription billing & payment processing | EU / United States | SCCs / EU‑US DPF |
| Anthropic, PBC | AI‑assisted analysis of performance data | United States | SCCs |
| Google LLC | Google Ads / Analytics / Data Manager APIs you connect | United States / global | SCCs / EU‑US DPF |
| Meta Platforms, Inc. | Meta Marketing APIs you connect | United States / global | SCCs / EU‑US DPF |
| TikTok / LinkedIn / Microsoft | Respective advertising APIs you connect | United States / global | SCCs / EU‑US DPF |
We will give the Controller advance notice of changes to sub‑processors (via the App or email) and an opportunity to object on reasonable data‑protection grounds.
Where processing involves transfer of personal data outside the EEA, the parties rely on an adequacy decision, the European Commission's Standard Contractual Clauses (which are incorporated by reference and completed by the details in the Annexes), and/or the EU‑US Data Privacy Framework, with supplementary measures where appropriate.
The Processor will make available information reasonably necessary to demonstrate compliance with Article 28 and allow for audits, including inspections, conducted by the Controller or an auditor it mandates, subject to reasonable notice, confidentiality, and no more than once per year unless required by a supervisory authority or following a breach.
This DPA remains in effect while the Processor processes the Controller's personal data. Each party's liability under this DPA is subject to the limitations in the Terms of Service. This DPA is governed by Romanian law.
This Section applies where the Controller is a "business" and the Processor is a "service provider" as those terms are defined in the California Consumer Privacy Act as amended by the California Privacy Rights Act, and its implementing regulations (together, the "CCPA"). Terms used in this Section have the meanings given to them in the CCPA. This Section is intended to satisfy Cal. Civ. Code §1798.100(d) and 11 CCR §7051.
Nothing in this Section is an admission that either party is subject to the CCPA; it applies only to the extent the CCPA does.
Subject matter & duration: provision of the VGS Hub Service for the term of the Controller's subscription.
Nature & purpose: collection, storage, organization, analysis, and transmission of advertising, analytics and conversion data to provide reporting, measurement, alerting and campaign‑management features; receipt and delivery of the Controller's lead‑form submissions to the destinations the Controller configures; and, where the Controller explicitly enables it, reading and updating the Controller's Merchant Center product listings.
Categories of data subjects: the Controller's personnel; the Controller's customers, leads and website visitors.
Categories of personal data: online identifiers; contact identifiers (email address and phone number), stored encrypted at rest and transmitted to advertising platforms only as SHA‑256 hashes; name and address data (first name, last name or full name, city, state / region, postal code and country), stored encrypted at rest; advertising click IDs; device/IP and event data; conversion and commercial values; lead‑form submissions, comprising the contact details and the full set of answers the data subject provided to the Controller's form; and account, campaign and product‑listing metadata. The parties do not intend for special‑category data to be processed.
As listed in Section 4 above, maintained current as the Service evolves.