Skip to main content
CyberLab.Team

Data Processing Agreement (DPA) and Subprocessors

Last updated: 23 September 2026

This document applies to all Clients (specifically B2B) using my.cyberlab.team where CyberLab.Team OÜ acts as a Data Processor on their behalf under the GDPR.

1. DPA Overview

By using the Platform, the Client (acting as the Data Controller) appoints CyberLab.Team OÜ (acting as the Data Processor) to process personal data strictly for the purpose of providing the Service (e.g., managing marketing campaigns, analyzing performance data). We process personal data only on documented instructions from the Client, including to provide the Platform's core features. We process data in full compliance with the GDPR. We ensure all staff are subject to strict confidentiality obligations.

2. Processor Obligations (GDPR Article 28)

2.1. Security Measures. We implement appropriate technical and organizational measures to ensure a level of security appropriate to the risk, including encryption of OAuth tokens at rest and access controls.

2.2. Data Breach Notification. In the event of a personal data breach affecting the Client's data, we shall notify the Client without undue delay after becoming aware of it.

2.3. Assistance. We will assist the Client, insofar as possible, in fulfilling their obligations to respond to requests for exercising data subjects' rights (e.g., if an end user requests data deletion) and in conducting Data Protection Impact Assessments (DPIAs) if required.

2.4. Audit Rights. As required by GDPR Article 28(3)(h), we shall make available to the Client information necessary to demonstrate compliance. This audit right is primarily satisfied by CyberLab.Team OÜ providing written responses to reasonable security questionnaires. To protect the security and confidentiality of our secure Client Cabinet infrastructure, physical access to our servers or direct technical penetration testing by the Client is strictly prohibited.

2.5. Deletion upon Termination. Upon termination of the Service or account deletion, we shall, at the Client's choice, delete or return all personal data, unless EU or Estonian law requires continued storage (GDPR Article 28(3)(g)).

2.6. Lawfulness of Instructions and Indemnification. The Client expressly warrants that all personal data provided to the Processor has been collected lawfully and that the Client has the legal right to instruct the Processor to process it. The Client shall fully indemnify, defend, and hold CyberLab.Team OÜ harmless against any claims, fines, regulatory actions, or damages arising from the Client's unlawful processing instructions or failure to obtain legally valid end-user consent.

2.7. Account Suspensions (Google Policy Violations). CyberLab.Team OÜ acts solely as a data processor and management interface. We bear no financial or legal liability for any suspensions, bans, or penalties imposed by Google (or other platforms) on the Client's advertising accounts or business profiles, provided such actions result from the nature of the Client's business, the quality of their website, manual interventions by the Client, or the Client's direct violations of Google's advertising policies.

2.8. Client's Website Compliance (e.g., Consent Mode). The Client bears sole and absolute responsibility for ensuring their own websites and web properties comply with all applicable data protection laws (including the GDPR and ePrivacy Directive) and Google's specific technical requirements (including, but not limited to, the correct implementation of Google Consent Mode v2 and valid cookie banners). CyberLab.Team OÜ's data processing obligations are strictly limited to the Client Cabinet platform (my.cyberlab.team). We accept no liability for any Google Ads account suspensions, data loss, or regulatory fines caused by the Client's failure to legally collect user consent on their own web properties.

3. Approved Subprocessors

To deliver a reliable and secure Service, CyberLab.Team OÜ utilizes the following third-party subprocessors. By agreeing to our Terms of Service, you authorize the use of these subprocessors:

  1. Google Cloud / Google Ireland Ltd.: cloud infrastructure, database hosting, and Google API integrations.
  2. Cloudflare, Inc.: CDN, DNS, Web Application Firewall (WAF), and security edge routing.
  3. Stripe, Inc.: secure payment processing and subscription management.
  4. Resend, Inc.: transactional and service email delivery (e.g., password resets, notifications).
  5. CRM and support providers (e.g., HubSpot, Pipedrive): used strictly for managing client relationships, support tickets, and sales inquiries from the Website.
  6. AI service providers (e.g., Google Cloud Gemini, OpenAI): AI models are utilized strictly for zero-day content generation (e.g., ad copy ideas). Under no circumstances are Google API tokens, Google user data, location details, or advertising metrics transmitted to OpenAI or Google Gemini. AI generation operates completely independently of the Google API data pipeline. We strictly guarantee that no Google API User Data is ever transferred to these services for the purpose of training generalized AI/ML foundational models (in full compliance with the Google API Limited Use policy).
  7. Technical logging and monitoring providers (e.g., Sentry): used strictly for application error tracking and stability. We implement strict data scrubbing to ensure no Personally Identifiable Information (PII) or Google API User Data is ever transmitted to these logging services.

Note: banking institutions and financial service providers (e.g., Revolut, Wise) used for receiving SEPA/SWIFT wire transfers operate as highly regulated Independent Data Controllers under financial laws, not as our subprocessors.

3.1. Google as an Independent Controller. When our Platform transmits data (e.g., location structures, budgets, or ad campaign settings) into the Google Ads or Google Business Profile networks via API, Google Ireland Ltd. / Google LLC processes that data within its advertising ecosystem as an Independent Data Controller according to its own Terms of Service. CyberLab.Team OÜ acts solely as a Processor (a transport layer and management interface) and disclaims liability for how Google utilizes that data within its own proprietary systems.

3.2. Subprocessor Liability Limitation. While we enter into strict agreements with our subprocessors, CyberLab.Team OÜ shall not be held financially or legally liable for security breaches, service outages, or data losses that occur exclusively within the isolated infrastructure of a Tier-1 subprocessor (e.g., Google Cloud, Cloudflare, Stripe), provided we have not acted with gross negligence in their configuration or selection.

4. Adding New Subprocessors

If we plan to add or replace any subprocessors, we will notify you at least 14 days in advance via the Platform or email. The Client has the right to object to the new subprocessor. If an objection is made and a reasonable resolution cannot be found, the Client has the right to terminate the agreement and cease using the Service without penalty.

5. International Data Transfers

Where personal data is transferred outside the European Economic Area (EEA) to our subprocessors (e.g., infrastructure located in the US), we ensure such transfers are subject to appropriate legal safeguards as required by Chapter V of the GDPR. This includes relying on the EU-US Data Privacy Framework (DPF) adequacy decision, or implementing Standard Contractual Clauses (SCCs) approved by the European Commission.

6. Limitation of Liability under this DPA

Any claims, damages, or disputes arising out of or in connection with this DPA shall be strictly subject to the limitations of liability and indemnification clauses set forth in the main Terms of Service. The aggregate cumulative liability of CyberLab.Team OÜ for any and all breaches of this DPA shall not exceed the financial cap established in the Terms of Service.