Data Processing Agreement
This Data Processing Agreement (“DPA”) is entered into between AiDigital Operating, LLC (“AiDigital”) and the customer or other entity that has entered into the Agreement with AiDigital (“Company”) and is effective as of the effective date of the first Agreement between the parties that incorporates this DPA by reference (the “DPA Effective Date”). This DPA forms part of the services agreement between the parties, including the applicable Order and either the Terms and Conditions or Online Non-Media Services Terms (the Order, Terms and Conditions, and Online Non-Media Services Terms, as applicable, collectively, the “Agreement”). This DPA applies to the Processing of Company Personal Information pursuant to the Agreement.
In the event of any conflict between any of this DPA and the Agreement, the terms of this DPA will control with respect to the subject matter hereof.
- Definitions
Any capitalized terms not defined herein shall have the meaning given to them in the Agreement.
1.1. “Controller” means the entity that determines the purposes and means of Processing Company Personal Information.
1.2. “Company Personal Information” means any information received by AiDigital from or on behalf of Company under the Agreement that identifies, relates to, describes, or can be reasonably linked to a natural person or household.
1.3. “Compliance Metadata” means flags, labels, restrictions, opt-out indicators, do-not-sell or do-not-share indicators, or similar metadata associated with Company Personal Information.
1.4. “Data Protection Laws” means all applicable data protection, privacy, marketing, and related laws, rules, and regulations applicable to the processing of Company Personal Information including any amending or replacement legislation, such as, to the extent applicable, the California Consumer Privacy Act (the CCPA), EU GDPR, UK GDPR, the Federal Data Protection Act of 19 June 1992 (Switzerland) and PIPEDA.
1.5. “EU GDPR” means Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data.
1.6. “Minor Personal Information” means Company Personal Information from or belonging to an individual that the Controller has actual knowledge, or knowledge fairly implied on the basis of objective circumstances, is under the age of eighteen.
1.7. “Privacy Rights Request” means a request from an individual to exercise control or choice over the Processing of their Company Personal Information, pursuant to a Data Protection Law (including requests to access, delete, correct, know, opt-out, restrict, and portability).
1.8. “Process” or “Processing” means any operation or set of operations which is performed on Company Personal Information or on sets of Company Personal Information, whether or not by automated means, such as collection, recording, organization, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction.
1.9. “Processor” means an entity that Processes Company Personal Information on behalf of a Controller.
1.10. “Restricted Transfer” means any transfer of Company Personal Information that would be prohibited under Data Protection Laws in the absence of relevant safeguards, such as Standard Contractual Clauses.
1.11. “Security Incident” means any unauthorized or unlawful use, damage to, loss, misuse, destruction, alteration, acquisition of, access to, or disclosure of Company Personal Information.
1.12. “Sell” means disclose, transfer, or otherwise make available Company Personal Information to another person for monetary or other valuable consideration.
1.13. “Sensitive Personal Information” means Company Personal Information that reveals: (1) a social security, driver’s license, state identification card, or passport number; account log-in, financial account, debit card, or credit card number; precise geolocation information (data that identifies an individual’s location within 2,000 feet); an individual’s racial or ethnic origin, citizenship or immigration status, religious or philosophical beliefs, or union membership; (2) the contents of an individual’s mail, email, or text message; (3) genetic data; (4) neural data; (5) biometric information; (6) information concerning an individual’s health or medical condition or current, present or future health status; or (7) information about an individual’s sex life or sexual orientation.
1.14. “Sub-Processor” means a person appointed by AiDigital to Process Company Personal Information on behalf of the Controller in order to assist AiDigital in fulfilling its obligations under the Agreement.
1.15. “Share” means disclose, transfer, or otherwise make available Company Personal Information to another person for cross-contextual behavioral advertising, whether or not for monetary or other valuable consideration.
1.16. “UK GDPR” means the EU GDPR as amended and incorporated into UK law under the UK European Union (Withdrawal) Act 2018, and applicable secondary legislation made under that Act.
- General Provisions
2.1. With regard to the Processing of Company Personal Information under the Agreement, Company is the Controller or, if Company is a Processor, Company warrants that any instructions it provides to AiDigital are made on behalf of and authorized by the ultimate Controller. AiDigital will only Process Company Personal Information on behalf of Company based on Company’s instructions, as set forth below.
2.2 The Parties shall comply with all Data Protection Laws. AiDigital will promptly notify Company if AiDigital determines that it cannot comply with Data Protection Laws or this DPA or if, in its opinion, Company’s instruction infringes Data Protection Laws. In the event AiDigital is unable to meet its obligations under Data Protection Laws, Company will have such rights as set forth in the Agreement, to the extent applicable.
2.3. Details regarding the Processing of Company Personal Information under the Agreement are set forth in Appendix A. AiDigital shall Process Company Personal Information in accordance with Company’s written instructions as set forth in any applicable Order and this DPA, including Appendix A. Company specifically instructs AiDigital to Process Company Personal Information on behalf of Company as may be necessary and proportionate to perform the Services, and to: (i) verify and maintain the quality or safety of the Services; (ii) undertake activities to improve, upgrade, or enhance the Services; (iii) detect Security Incidents and other security events and protect against malicious, fraudulent, or illegal activity; and (iv) comply with Data Protection Laws.
- Company Requirements
3.1. Company shall obtain all necessary consents and provide all required notices (or, if Company is a Processor, ensure that all such consents are obtained and notices provided) for the Processing of Company Personal Information under the Agreement, to the extent required under Data Protection Laws.
3.2. Company is prohibited from disclosing, transferring or providing Sensitive Personal Information or Minor Personal Information to AiDigital for Processing through the Services without AiDigital’s prior, express, written consent.
3.3. Company is prohibited from using the Services to geofence an entity or location that provides in-person health care services or reproductive care services.
3.4. Company is responsible for ensuring that any Privacy Rights Request to opt-out of targeted advertising or sharing for cross-context behavioral advertising using Company Personal Information is communicated to AiDigital through Compliance Metadata as specified by AiDigital in applicable documentation.
- AiDigital Restrictions on Use
4.1. AiDigital is expressly prohibited from: (i) Selling or Sharing Company Personal Information; (ii) retaining, using or disclosing Company Personal Information for any purpose other than as set forth in Section 2.3 or as required by law; (iii) using Company Personal Information for AiDigital’s own commercial purposes; and (iv) except as necessary and proportionate to provide the Services, combining Company Personal Information with data relating to an identified or identifiable natural person received from another entity or collected by AiDigital for its own commercial or business purposes.
4.2. Unless separately agreed to by the Parties, AiDigital will store and Process Company Personal Information in the United States. In the event of a Restricted Transfer of Company Personal Information from the European Economic Area, United Kingdom or Switzerland by Company to AiDigital, the Parties agree to the Standard Contractual Clauses described in Appendix B, which are deemed signed and incorporated herein, as well as, where applicable, the Supplemental Clauses contained in Appendix C. For Restricted Transfers from a jurisdiction other than the European Economic Area, United Kingdom or Switzerland, the Parties will cooperate in good faith to enter into any required safeguards for the transfer of Company Personal Information.
- Privacy Rights and Compliance Obligations
5.1. Taking into account the nature of the Processing of Company Personal Information, AiDigital will assist Company through appropriate technical and organizational measures, insofar as this is possible, for the fulfilment of Company’s obligation to respond to Privacy Rights Requests, including by deleting, correcting or providing access to Company Personal Information where requested by Company (in the case of access, provided such Company Personal Information is not otherwise available to Company).
- Information Security
5.2. AiDigital shall reasonably ensure that all persons authorized to process Company Personal Information have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality.
7.1. AiDigital shall implement and maintain reasonable security measures, documented in writing. Such measures shall be appropriate, taking into account the nature and volume of Company Personal Information as well as the scope, context and purpose of Processing under the Agreement.
6.3. AiDigital will impose on any Sub-Processor, in writing, data protection obligations that are at least as restrictive as the terms of this DPA. AiDigital will be responsible for the acts and omissions of any Sub-Processor in relation to Data Protection Laws and this DPA.
8.3. Upon Company’s request, no more than once per year and provided an appropriate non-disclosure agreement is in place, AiDigital will supply Company with documentation prepared by AiDigital, such as its then applicable SOC 2 Report, reflecting the controls in place for the protection of Company Personal Information in compliance with this DPA and Data Protection Laws. Only in the event such documentation is not reasonably sufficient to satisfy Company’s obligations under Data Protection Laws, Company, or a third-party on Company’s behalf mutually agreed to by the Parties, may conduct an additional review of evidence reflecting compliance, the scope of which will be agreed to by the Parties in advance, including as to the start date, duration, and systems and documentation under review. In no event will the scope of such review extend beyond information applicable to Company. Such additional reviews will be conducted no more than once per year during regular business hours with no less than thirty days’ advanced notice. Company will take appropriate measures to limit unnecessary impact on AiDigital as a result of any such review and will agree to appropriate confidentiality terms in advance. Company, or the third party acting on Company’s behalf, will be subject to security restrictions required by AiDigital.
7.2. In the event of a Security Incident, AiDigital will notify Company promptly (and in any event within seventy-two (72) hours), and AiDigital will provide reasonable assistance in remediating and responding to the Security Incident. Where reasonably available, any such notice shall include details of the Security Incident, including the nature of the Security Incident, the type and volume of Company Personal Information impacted, and steps taken to remediate. Where requested by Company, AiDigital will assist in providing any legally required notice to individuals, regulators or other third parties at Company’s cost. AiDigital will not make any public disclosures about a Security Incident, except where required by law or, if the Security Incident involves other customers of AiDigital, by ensuring that Company cannot be identified in any such disclosure.
5.3. Upon termination of the Agreement, AiDigital will either return or delete, at Company’s election, all Company Personal Information Processed in relation to the Services within 45 days, unless ongoing retention is required by law in which case the terms of this DPA will continue to apply until such Company Personal Information is finally returned or deleted.
6.2. Before engaging any new Sub-Processor, AiDigital will notify Company no less than 30 days in advance. If within ten (10) calendar days of receipt of that notice, Company objects, the Parties will work in good faith to resolve the objection. In the event any objection cannot be resolved in good faith, AiDigital reserves the right to discontinue providing the relevant part of the Services that rely on the Sub-Processor.
8.2. AiDigital will adhere to reasonable requests from Company to ensure Company is satisfying its obligations under Data Protection Laws. AiDigital may charge appropriate fees for assistance that materially exceeds the standard of support included in the Agreement.
- Assessments and Audits
- Sub-Processors
6.1. Company grants AiDigital general authorization to appoint Sub-Processors to perform specific Processing activities on its behalf. A list of AiDigital’s current, approved Sub-Processors will be made available upon request.
8.1. AiDigital will assist Company in conducting any legally required data protection impact assessments and prior consultations with data protection authorities. Such assistance may take the form of providing applicable documentation, such as security reports prepared by AiDigital.