DATA PROTECTION ADDENDUM – INDEPENDENT CONTROLLERS

D-block (“D-block”) and the counterparty (“Company”), having agreed to this Data Protection Addendum (the “Addendum”), have entered into an agreement for the provision of Services, as amended from time to time (the “Agreement”). This Addendum sets forth the relationship and obligations of the Parties concerning personal data processed in connection with the services provided to the Company under the Agreement (the “Services”). D-block and the Company are each referred to individually as a “Party” and collectively as the “Parties.” Capitalized terms used but not defined in this Addendum have the meanings assigned to them in the Agreement.

1. Definitions

a. “Applicable Data Protection Law” means all applicable data protection and privacy laws, regulations, and self-regulatory codes related to the relevant personal data, including, where applicable, CCPA, CPA, CTDPA, UCPA, VCDPA, European Data Protection Laws, LGPD, as well as all related regulations and binding guidelines, decisions, orders, and interpretations of the United States Federal Trade Commission (FTC) and any other applicable data privacy laws and regulations, including but not limited to Industry Regulations.

b. “CCPA” refers to the California Consumer Privacy Act, Cal. Civ. Code §§ 1798.100 et seq., as amended, including without limitation any related implementing regulations. “CPA” refers to the Colorado Privacy Act, Senate Bill 21-190 (2021), as amended. “CTDPA” refers to the Connecticut Data Protection Act, Senate Bill 6 (2022), as amended. “UCPA” refers to the Utah Consumer Privacy Act, Senate Bill 227 (2022), as amended. “VCDPA” refers to the Virginia Consumer Data Protection Act, Va. Code §§ 59.1-575 et seq., as amended.

c. “European Data Protection Laws” means (i) the EU General Data Protection Regulation 2016/679 (“EU GDPR”); (ii) the EU ePrivacy Directive (Directive 2002/58/EC); (iii) the UK GDPR; (iv) the Swiss Federal Act on Data Protection of 1992 (“Swiss FADP”); and (v) applicable national laws enacted under (i), (ii), (iii), and (iv), each as amended or replaced from time to time.

d. “Industry Regulations” means all applicable industry self-regulatory rules, codes, and guidelines in effect regarding online behavioral targeting and data privacy compliance.

e. “LGPD” refers to the Lei Geral de Proteção de Dados (Law No. 13,709/2018), as amended, including related implementing regulations.

f. “Restricted Transfer” means (i) a transfer of personal data from the EEA to a non-EEA country not covered by a European Commission adequacy decision; (ii) a transfer of personal data from the UK to any other country not covered by a UK adequacy regulation; (iii) a transfer of personal data from Switzerland to a country not offering adequate data protection under Swiss law.

g. “Security Incident” refers to any accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to personal data. Any data breach is a Security Incident.

h. “SCCs” refers to the Standard Contractual Clauses: (i) when the EU GDPR or Swiss FADP applies, the EU SCCs of June 4, 2021; (ii) when the UK GDPR applies, the UK SCCs; and (iii) as mandated by other applicable laws.

i. Terms such as “business,” “consumer,” “controller,” “processor,” “data subject,” “processing,” “recipient,” “sale,” “sensitive data,” “service provider,” “share,” and “third party” are defined per the Applicable Data Protection Law.

j. “Personal Data” means any information constituting “personal information,” “personal data,” or similar under the Applicable Data Protection Law.

2. Terms

a. Purpose: Each Party shall disclose or make available personal data to the other Party only for the purpose outlined in Schedule 1 of this Annex (the “Purpose”). The Parties act as separate and independent controllers and not as joint controllers or as controller and processor.

b. Privacy Policy: Each Party shall maintain a privacy notice and, where applicable, a cookie policy that complies with the Applicable Data Protection Law. This policy shall, to the extent required by the Applicable Data Protection Law, (i) disclose any collection, sharing, and/or use of personal data related to the Agreement; (ii) inform data subjects of all types of processing activities, including processing for targeted and behavioral advertising; and (iii) provide data subjects with an option to opt out of these processing activities, including global privacy controls when required. D-block shall provide the Company with any information it reasonably requests concerning D-block’s cookies to ensure this information is included in the notice. Each Party shall collect, disclose, and/or use personal data in accordance with its published privacy policy and the Applicable Data Protection Law, including obtaining all necessary permissions required to collect, use, transfer, or otherwise process data using cookies or other identifiers as applicable.

c. User Consent: The Company shall not use any means to induce, encourage, or mislead a data subject into clicking on an ad or consenting to the placement of cookies on a browser or any other personal data collection. If a data subject opts out of such processing activities, the Company shall transmit an opt-out signal to D-block in compliance with industry standards (e.g., an IAB-approved opt-out signal transmitted through the IAB OpenRTB specification). If a site is a mobile application, the Company shall provide the above-mentioned notices, disclosures, and options where the mobile application is available, either near each ad, within the app (e.g., via a link from “settings”), or on the landing page of each ad. D-block shall accept, respect, and promptly comply with any instruction, opt-out option, privacy choice, or consent signal transmitted by the Company in connection with personal data, including without limitation the OpenRTB guidelines or signals from the IAB framework. D-block shall not use cookies to collect personal data from a data subject who has opted out of receiving D-block’s cookies.

d. Other Measures: Each Party is individually and separately responsible for complying with its obligations under the Applicable Data Protection Law. Without limiting the foregoing, each Party shall (i) conduct and document a data protection assessment that meets the requirements of the Applicable Data Protection Law; and (ii) implement and maintain appropriate technical and organizational measures to protect the processing of personal data, which are tailored to the risk and designed to be sufficient under the Applicable Data Protection Law.

e. COPPA Compliance: Each Party shall comply with the Children’s Online Privacy Protection Act (COPPA) and other relevant laws concerning the collection, use, and other processing of children’s data, as defined by the applicable jurisdiction’s law, as it applies to the activities of that Party. Neither Party shall sell personal data of a consumer if it is aware that the consumer is under 16 years of age unless the consumer (if at least 13 years old) or the parent or guardian of the consumer (if under 13 years old) has expressly authorized the sale of such personal data.

f. Ownership: Nothing in this Annex shall be interpreted as conferring any ownership interest or license in the personal data that contradicts the ownership interests and licenses set forth in the Agreement.

g. Regulatory Matters: Each Party agrees to (i) promptly notify the other Party in writing of any question, complaint, investigation, request, warrant, subpoena, or proceeding from or initiated by any public, governmental, or judicial agency or authority (each, a “Regulatory Request”) that (A) relates to the processing of personal data by that other Party in connection with the Services, or (B) may indicate either Party’s inability to comply with the Applicable Data Protection Law; and (ii) comply with any written request to suspend litigation, document preservation notice, or other similar request required by the other Party in connection with any Regulatory Request, litigation, or other claim, except to the extent required by applicable law.

h. Security Incidents: If either Party experiences a confirmed Security Incident involving personal data disclosed by the other Party, that Party shall notify the other Party without undue delay, and the Parties shall cooperate in good faith to agree upon and implement any necessary measures to mitigate or remedy the effects of the Security Incident.

3. Restricted Transfers

The Parties agree that when the transfer of personal data under the Agreement constitutes a Restricted Transfer, the SCCs shall be incorporated into this Annex by reference and shall apply to this Restricted Transfer, with each Party deemed to have concluded the SCCs as follows:

a. Standard Contractual Clauses (EU SCCs)

Regarding personal data protected by the EU GDPR, the EU SCCs shall apply as follows: (i) Module One applies; (ii) the Company must provide all information required by Section II, Clause 8.2(a) of the EU SCCs as well as a copy of the SCCs to all data subjects; (iii) Clause 7 (Docking Clause) does not apply; (iv) Clause 11 (optional language) does not apply; (v) Clause 17 is governed by Irish law; (vi) disputes are resolved in the Irish courts; (vii) Annex I is supplemented with the information defined in Schedule 1 of this Addendum; (viii) Annex II is supplemented with the information defined in Schedule 2.

b. Standard Contractual Clauses for the United Kingdom (UK SCCs)

For data protected by the UK’s GDPR, the UK SCCs shall apply as follows: (i) the EU SCCs are amended in accordance with the UK’s International Data Transfer Addendum; (ii) Tables 1 to 3 in Part 1 of the UK Addendum are completed with information from Section 3.a and Schedules 1 and 2; (iii) Table 4 in Part 1 is completed by selecting “neither party.”

c. Swiss Standard Contractual Clauses (Swiss SCCs)

For data protected by Swiss data protection law, the EU SCCs shall apply with the following amendments: (i) references to “Regulation (EU) 2016/679” will be interpreted as references to Swiss law; (ii) specific articles of the GDPR will be replaced with equivalent articles of Swiss law; (iii) “EU,” “Union,” and “Member State” will be replaced by “Switzerland”; (iv) the competent authority is the Federal Data Protection and Information Commissioner; (v) disputes will be resolved in competent Swiss courts.

d. Other Jurisdictions

The Parties agree that the SCCs automatically apply for transfers of personal data to D-block in accordance with the relevant jurisdiction’s legislation.

4. LGPD (Brazil)

For data subjects whose data is processed in Brazil, the Company shall provide notifications in accordance with the LGPD, including those required by Article 18 of the LGPD.

5. United States

If a Party collects or shares the personal data of California residents, it will be considered a business or third party under the CCPA.

Each Party will only process personal data within the scope of the specified purpose, comply with the CCPA, and enable the other Party to ensure CCPA obligations are met.

SCHEDULE 1: DESCRIPTION OF DATA AND PARTIES

A. List of Parties

  • Data Exporter:
    Name of exporter, address, contact name, and contact details: Company, as defined in the Agreement.
    Relevant activities: Facilitation of ad sales, ad placement, marketing performance measurement and optimization.
    Role: Independent Controller.
  • Data Importer:
    Name of importer, address, contact name, and contact details: D-block, as defined in the Agreement.
    Relevant activities: Facilitation of ad sales, ad placement, and performance optimization.
    Role: Independent Controller.

B. Description of Transfer

  • Categories of Data Subjects: End users of websites.
  • Categories of Personal Data Transferred: Online identifiers, IP addresses, cookie IDs, etc.
  • Sensitive Data Transferred: None.
  • Frequency of Transfer: Daily.
  • Nature of Processing: Provision of the described services.
  • Data Retention Period: Duration of the Agreement or 12 months, whichever is longer.

C. Competent Supervisory Authority

  • Irish Data Protection Commission.

SCHEDULE II

Technical and Organizational Measures

Each Party is responsible for implementing appropriate measures to ensure GDPR compliance, considering the nature, scope, context, and purposes of the processing as well as risks to the rights and freedoms of data subjects. These measures include:

  • Pseudonymization and Encryption: Pseudonymize personal data if possible.
  • Confidentiality, Integrity, and Availability: Develop systems that meet industry standards.
  • Data Restoration: Incident response plans for physical or technical incidents.
  • Regular Assessment: Periodic reviews of measures by security teams.
  • User Identification and Authorization: Limit access to authorized persons only.
  • Data Storage Security: Minimize data and comply with retention periods.
  • Physical Security: Restrict facility access.
  • System Configuration: Use configuration management tools.
  • IT Governance: Appoint security officers.
  • Process Certification: Implement appropriate controls.
  • Data Minimization: Exclude special categories of data.
  • Data Retention: Enforce retention and destruction policies.
  • Accountability: Review data protection policies.
  • Portability and Erasure: Procedures to respond to data subjects’ requests.