Yield | Data Processing Agreement
This Data Processing Agreement is between Azerion and you, the Seller, each a “Party” and collectively the “Parties” as specified under the Terms. By receiving CMP Services and/or Pixel Services from Azerion, you agree to the provisions of this DPA.
WHEREAS:
- Seller shall appoint Azerion as a processor for the processing of Processor Data for the provision of the CMP Services and/or Pixel Services and as detailed under Schedule 1.
- In relation to the foregoing, each Party undertakes to comply with the applicable personal data protection legislation as well as any special law concerning the regime of information it processes within its activities.
- All definitions used in Terms and Addendum apply mutatis mutandis to this DPA.
IT IS AGREED AS FOLLOWS:
- Definitions
| CMP Services | Provision of a consent management platform and associated services by Azerion on Properties under the Terms; |
| DPA | Means this Data Processing Agreement; |
| Pixel Services | Provision of Azerion Pixel under the Terms; |
| Processor Purposes | Means the purposes for which Azerion processes Personal Data under this DPA on behalf of Seller as detailed under Schedule 1; |
| Processor Personal Data | Means the Personal Data processed by Azerion under this DPA on behalf of Seller as detailed under Schedule 1; |
| Personal Data | any information relating to a Data Subject; |
| Processing | any operation or set of operations which is performed on Personal Data or on sets of Personal Data, whether or not by automated means, such as collection, recording, organization, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction. References in this Agreement to ‘Process’ and ‘Processed’ shall be construed accordingly; |
| Supervisory Authority | means (a) an independent public authority which is established by a member state pursuant to Article 51 GDPR; and (b) any similar regulatory authority responsible for the enforcement of EU Data Protection Laws. |
- Scope of DPA
- This DPA sets out the framework for Processing of Personal Data in the context of the provision of CMP Services and/or Pixel Services by Azerion. It defines the principles and procedures that Parties shall adhere to and establishes the mutual responsibilities between Parties and towards Data Subjects.
- Seller shall comply with all the obligations imposed on a Controller under the EU Data Protection Laws. Parties acknowledge that certain EU Data Protection Law (such as the GDPR) may apply to Parties regardless of where Parties are established.
- Data Processing Activities
Parties agree that Processor Purposes and the details regarding the means of Processing, the categories of Personal Data, categories of Data Subjects, duration of Processing are laid out in Schedule 1 of this DPA.
- Processing of Processor Data by Azerion
- Seller, as Controller, hereby instructs Azerion, as a Processor to Process the Processor Personal Data on behalf of Seller for Processor Purposes detailed under Schedule 1. The instructions of Seller are described in more detail in this DPA and, in certain cases, additionally in the Terms. Publisher can provide supplementary instructions or changed instructions in writing. Azerion may oppose such instructions of the Publisher if it deems that they are unlawful under the applicable data protection laws, including EU Data Protection Law. In that regard, if Seller disagrees with the opposition of Azerion, Azerion may terminate this DPA as well as the Terms without incurring any liability in connection therewith.
- Azerion provides Seller with information about Processing of Processor Personal Data on behalf of Seller in Schedule 1. Seller affirms that the information provided has been sufficient for it to make an informed decision and determination of the purposes and means with regard to the Processing of Processor Personal Data.
- Seller undertakes to inform Data Subjects about the involvement of Azerion, as a Processor, in Processing of Personal Data, the nature, scope and purposes of Processing of Publisher Personal Data by Parties, as well as all the other required information accurately and pursuant to Articles 13 and 14 GDPR.
- Technical and Organizational Security Measures
Azerion shall implement and maintain the technical and organizational measures required pursuant to Article 32 GDPR in line with its security policy, including all organizational and technical security measures necessary to protect Processor Personal Data against unauthorized or accidental access, loss, alteration, disclosure, or destruction of Processor Personal Data, in particular where Processing involves the transmission of data over a network, and against all other unlawful forms of Processing.
- Sub Processors
- Azerion is authorized to engage sub processors and other third parties for carrying out Processing of Processor Personal Data for Processor Purposes determined under this DPA. Publisher hereby gives its revocable general authorisation to engage such third parties provided that Azerion duly notifies Seller and Seller has the opportunity to object to such changes. If Azerion cannot reasonably be asked to not make such changes, Azerion may terminate Terms without incurring any liability in connection therewith.
- When engaging a sub processor, Azerion will ensure that the same data protection obligations as set out in this Data Processing Agreement and the Terms are imposed on that sub processor, in particular providing sufficient guarantees to implement appropriate technical and organisational measures in such a manner that the Processing will meet the requirements of EU Data Protection Law. For the avoidance of doubt, Azerion is required to impose similar provisions on any sub processors, but is not required to impose the obligations of this DPA verbatim or back-to-back.
- Processing of Processor Personal Data may result in a transfer to a third country or an international organization. Each Party shall not transfer any Personal Data outside of the EEA unless it has a lawful basis for that transfer, including fulfilling any of the following conditions: (i) the transfer is to a country approved by the European Commission as providing adequate protection pursuant to Article 45 GDPR; (ii) there are appropriate safeguards in place pursuant to Article 46 GDPR, including entering into Standard Contractual Clauses in the form approved by the EU Commission; or (iii) one of the derogations for specific situations in Article 49 GDPR applies to the transfer.
- Deletion and Destruction of Processor Personal Data
- On the expiration of the Terms or on the expiration of the applicable term for saving Processor Personal Data (to be determined by Seller), Azerion will, at the option of Seller: (i) delete all the Processor Personal Data from its systems (automated or otherwise) or the systems it uses to store data, or (ii) return the Processor Personal Data, in both cases without keeping any copies of the Processor Personal Data.
- Azerion may derogate from the provisions in the above paragraphs insofar law requires storage of the Processor Personal Data, or as this is necessary in order to prove compliance with its obligations to Controller under this DPA.
- Assistance
- Azerion, taking into account the nature of Processing and the information available to itself, shall make commercially reasonable efforts to assist Seller in ensuring compliance with the obligations of Publisher under EU Data Protection Law vis-à-vis Data Subject such as the right to be provided with information about the Processing, the right of access, the right to rectification, the right to erasure, the right to a restriction of Processing, the right to data portability, or the right to object to automated individual decision making if any.
- In the event a Data Subject directs any of the above requests to Azerion, Azerion shall make commercially reasonable efforts to refer Data Subject to Seller and otherwise not respond itself to the request, except if required by EU Data Protection Law.
- Azerion will, taking into account the nature of Processing and the information available to Azerion, assist Seller in carrying out any data protection impact assessment or prior consultation as required by EU Data Protection Law.
- Azerion can recover its costs, including out-of-pocket costs for assistance from outside advisors and sub processors, incurred in assisting Seller.
- Audit Rights
- To the extent Azerion deems required by EU Data Protection Laws in relation to Processing of Processor Personal Data, Azerion will allow for and contribute to audits, including inspections, conducted by Seller or another auditor mandated by Seller, provided such an audit or inspection can in principle only be done once a year. In that regard, Seller has the right, following an advanced notice of at least 20 (twenty) working days, to arrange to investigate the establishment(s) and/or systems of Azerion. Any mandated auditor should have demonstrable experience in performing such audits or inspections. The investigation shall not extend beyond what is necessary for the purpose as described in this paragraph and does not include systems owned by third-parties or sub processors.
- Each Party shall bear its own costs associated with the investigation as referred to in paragraph 1 of this clause and Seller will bear the costs of the independent auditor if the investigation shows that Azerion has substantially complied with its obligations pursuant to this DPA.
- Azerion will inform Seller if, in its opinion, an instruction in connection with the investigation referred to in this clause infringes EU Data Protection Law, for example if with such audit or inspection Seller or its mandated auditor would gain access to Personal Data other than Processor Personal Data processed on behalf of Seller.
- Parties agree to handle any information related to inspections and requests for information confidential to the extent legally permitted.
- Azerion can recover its costs, including out-of-pocket costs for assistance from outside advisors and sub processors, incurred in assisting Seller.
- Data Breaches
- In the event of a Data Breach, Azerion shall within 48 hours after it becomes aware of Data Breach, inform Seller, further to which Seller will – if necessary – immediately inform the relevant Supervisory Authority and/or Data Subjects.
- Azerion will include in the report of the Data Breach, to the extent required by Art. 33 GDPR. Where certain information is not yet available, Azerion will report the information it has available, and straightaway gather – if reasonably possible – all additional information and provide it to Seller.
- Contact Points
Seller shall submit the notifications due under this Addendum to the email address dpo@azerion.com. Seller shall promptly provide Azerion with the email address where it prefers Azerion to submit its notifications under this Addendum. In case Seller doesn’t provide any address, Azerion shall not be expected to make any notification not it shall be responsible any indirect or direct damages caused by such absence of notification.
- Liability
The limitations of liability in Terms apply in all cases.
- Miscellaneous
- No amendment or modification of any provision of this Appendix 1 shall be effective unless in writing and signed by duly authorized representatives of the Parties.
- In case of a conflict between the clauses of this Addendum and the Terms, the clauses of this Addendum shall prevail.
- This Addendum shall expire simultaneously with the Terms.
- This Addendum is governed by the laws of the Netherlands. Any disputes arising out of or in connection with this Addendum shall be brought exclusively before the competent court of Amsterdam, without prejudice to the possibilities of appeal.
SCHEDULE 1
DETAILS OF DATA PROCESSING
- Service
CMP Services and/or Pixel Services under Terms
- Duration of Processing
Duration of Terms
- Nature and Purposes of processing
- For CMP Services: Storing cookies, device identifiers, or other information as listed below on Data Subject’s device for the provision of a technology to allow Data Subjects to specify their preferences on the activities to be carried out by Parties under Terms
- For Pixel Services: Processing via pixel and similar technologies for the purposes of determining the interest segments of end users based on the pages within Publisher domains visited to be shared with the Buyer partners of Publisher’s choice and providing reports to Publisher on insights of audiences who visit Publisher’s digital properties
- Categories of Data Subjects
End users of the Seller’s Properties
- Types of Personal Data
- For CMP Services: Identification and/or connection data and/or data related to the equipment of the data subjects, and/or any other Personal Data provided by the Seller, at its discretion
- For Pixel Services: Online identifiers Processed pursuant to the Terms (such as IP addresses, user agent, HTTP header data, interest segments)
Annex 2a
US DATA PROTECTION ADDENDUM
This US Data Protection Addendum is between Azerion and you, the Seller, each a “Party” and collectively the “Parties” as specified under the Terms. By sharing any personal data under Annex 2 Data Processing Agreement subject to State Privacy Laws, you agree to comply with this Annex 2a.
IT IS AGREED AS FOLLOWS:
- Definitions
| Addendum | This US Data Protection Addendum; |
| Restricted Processing Signal | Any flag or signal indicating that a Consumer has opted out of the Sale, Sharing, or Processing for purposes of Targeted Advertising of their Personal Data, including without limitation those flags or signals sent through the IAB CCPA Compliance Framework, Global Privacy Platform, or other signaling system agreed to by the Parties; |
| Restricted Purposes | Advertising-related Processing that qualifies as a Business Purpose, including Processing for purposes of auditing; security and integrity; debugging; short term, transient uses; analytics; providing advertising or marketing services that do not include Cross-Contextual Behavioral Advertising, Targeted Advertising, or profiling; internal research; and efforts to improve quality and safety. Restricted Purposes includes first-party advertising, contextual advertising, frequency capping, measurement, fraud detection and prevention, and ensuring and measuring viewability, each only to the extent such activity (i) is permissible for a Processor to perform under the applicable State Privacy Laws; and (ii) does not result in a Sale or Sharing of Personal Data or constitute Processing of Personal Data for Targeted Advertising purposes; and |
| State Privacy Laws | The California Consumer Privacy Act of 2018, the Colorado Privacy Act, the Connecticut Act Concerning Personal Data Privacy and Online Monitoring of 2022, the Indiana Consumer Data Protection Act, the Iowa Act Relating to Consumer Data Protection of 2023, the Montana Consumer Data Privacy Act, the Tennessee Information Protection Act, the Utah Consumer Privacy Act of 2022, the Virginia Consumer Data Protection Act, the Children’s Online Privacy Protection Act (“COPPA”), as well as any other applicable laws under the laws of United States of America, in each case as amended and including any regulations promulgated thereunder. |
“Business”, “Business Purpose”, “Consumer”, “Controller”, “Cross-Context Behavioral Advertising” “Data Breach”, “Personal Data”, “Personal Information,” “Process(-ing)” “Processor,” “Sell”, “Share” “Service Provider”, and “Targeted Advertising” shall have the meanings ascribed to them in State Privacy Laws.
- Roles
2.1. With respect to the Processing of Personal Data/Personal Information by Parties under this Addendum, Parties agree that Azerion is a Service Provider/Processor and Seller is a Business/Controller. In this regard, to the extent it is a Service Provider/Processor, Azerion shall process Personal Data/Personal Information as listed by and for the purposes provided by Schedule 1 of the DPA.
- Obligations of Parties
3.1. Parties shall comply with State Privacy Laws applicable to the Processing of Personal Data/Personal Information carried out by themselves under this Addendum.
3.2. In particular, to the extent acting as a party that discloses Personal Data/Personal Information; each Party will (a) provide all notices and obtain any consents required by State Privacy Laws necessary to permit each Party to Process Personal Data/Personal Information in accordance with this Addendum; and to the extent providing Personal Data/Personal Information originally collected by another Business/Controller, (i) contractually and operationally oblige such Business/Controller to provide all notices and obtain any consents required by State Privacy Laws necessary to permit each Party to Process Personal Data/Personal Information in accordance with this Addendum and (ii) take reasonable steps to ensure compliance with such contractual obligations.
3.3. As a Service Provider/Processor, Azerion shall;
3.3.1. In the presence of a Restricted Processing Signal provided by Seller under this Addendum, only process Personal Data/Personal Information for Restricted Purposes;
3.3.2. Assist Seller in responding to Consumer requests made pursuant to State Privacy Laws, provided that Seller must provide to Azerion all information necessary for it to provide such assistance or respond to a Consumer request when required by State Privacy Laws;
3.3.3. Contribute to data protection impact assessments where required by State Privacy Laws;
3.3.4. Offer reasonable notice and assistance to Seller in the event Seller experiences a Data Breach, including to help Seller satisfy its Data Breach notification obligations under State Privacy Laws;
3.3.5. Implement reasonable security procedures and practices appropriate to the nature of the Personal Data and designed to protect such Personal Data from unauthorized or illegal access, destruction, use, modification, or disclosure in accordance with State Privacy Laws;
3.3.6. Ensure it has in place a written agreement with any further Service Providers it may engage with under this Addendum that obliges those Service Providers to comply with terms at least as strict as the terms set out in this clause 3.3 and to the extent required by State Privacy Laws, provide Seller notice of such engagement with further Service Providers and an opportunity to object;
3.3.7. Delete, return, or de-identify in accordance with State Privacy Laws Personal Data provided to Azerion by Seller, unless retention of the Personal Data is required by applicable law following the termination of the DPA and this Addendum.
3.3.8. Notify Seller if it makes a determination that it can no longer meet its obligations under State Privacy Laws; and
3.3.9. Provide any other information or attestation the Parties agree is reasonably necessary for Seller to verify that Azerion’s Processing is consistent with Seller’s obligations under State Privacy Laws.