This Data Processing Addendum (the “DPA”) forms part of the Client Agreement between Informa TechTarget and its subsidiaries and Affiliates (collectively, “we”, “our”, “us” and “Company”) or any other mutually agreed paperwork (the “Agreement”) entered into by and between Company and the Client identified on the Order Form (“Client”). Capitalized terms not defined in this DPA shall have the meaning set forth in the Agreement. Company and Client are together referred to as the “Parties,” and individually as a “Party.”

  1. Definitions.

Client Personal Data” means personal data provided or made available by Client in connection with the Services and processed by Company or a sub-processor exclusively for Client.

CCPA” means the California Consumer Privacy Act, as amended by the California Privacy Rights Act of 2020, and any implementing regulations.

Data Protection Laws” refers to all applicable data protection and privacy laws and regulations regarding the processing of personal data in connection with this DPA, including but not limited to, European Union or Member State laws with respect to personal data, including GDPR and the CCPA.

EEA” means the member states of the European Union, Iceland, Liechtenstein, and Norway.

GDPR” means the General Data Protection Regulation, or Regulation 2016/679 of the European Parliament and of the Council on the protection of natural persons regarding the processing of personal data and on the free movement of such data and for the purpose of this DPA includes the corresponding laws of the United Kingdom (including the UK GDPR and Data Protection Act 2018); “controller,” “processor,” “sub-processor,” “data subject,” “personal data,” “personal data breach,” “processing,” “process,” and “Supervisory Authority” each will have the meanings given in the GDPR.

Standard Contractual Clauses or SCCs” means the standard contractual clauses prepared in accordance with the European Commission Decision 2021/914 of June 4, 2021.

  1. Roles of the Parties.

The Parties are independent controllers for all personal data processed in connection with the Services unless otherwise specified in writing. Where Client transfers Client Personal Data to Company and Company processes such Client Personal Data solely on behalf of and under the documented instructions of Client, Company shall serve as a data processor. In such cases, Client shall provide prior written notice to Company identifying: (i) the categories of Client Personal Data being transferred; (ii) the processing purpose(s); and (iii) any specific processing instructions. In the absence of such written notice, the Parties acknowledge that they are acting as independent controllers with respect to personal data exchanged in connection with the Services, including personal data contained in Licensed Materials.

  1. Processing Details and Obligations.

(a) General Compliance: Each Party shall comply with all applicable Data Protection Laws with respect to its processing of personal data under this DPA at its own cost and expense.

(b) Where Parties Act as Independent Controllers: Where the Parties process personal data as independent controllers (including with respect to Licensed Materials), each Party shall be independently responsible for responding to data subject requests and regulatory inquiries. Upon reasonable written request, each Party shall provide the other with information reasonably necessary to respond to such requests or inquiries, provided such cooperation does not require disclosure of confidential business information or impose unreasonable burden or expense on the assisting Party.

(c) Where Company Acts as Data Processor: With respect to Client Personal Data processed by Company as a data processor, Company shall: (i) process Client Personal Data only on documented instructions from Client, unless otherwise required by Data Protection Laws, (ii) provide reasonable cooperation and assistance to Client in responding to regulatory inquiries or investigations related to Client Personal Data, and (iii) provide reasonable assistance to Client in responding to data subject requests, including by providing relevant information within Company’s possession or control.

(d) Representations and Warranties – Licensed Materials: With respect to Licensed Materials, Company represents and warrants that: (i) it has a lawful basis under Data Protection Laws to transfer Licensed Materials to Client for the purposes set forth in the Agreement and applicable Order Form, (ii) it has not received any request, notice, or communication from any regulatory authority restricting its processing or transfer of Licensed Materials in the manner contemplated by the Agreement, and (iii) the Licensed Materials have been collected and processed in compliance with applicable Data Protection Laws.

(e) Representations and Warranties – Client Personal Data: With respect to Client Personal Data, Client represents and warrants that: (i) it has a lawful basis under Data Protection Laws to transfer Client Personal Data to Company for the purposes described in the Agreement and applicable Order Form, (ii) where Company acts as a processor, Client has the authority to provide processing instructions to Company as contemplated by this DPA, (iii) it has not received any request, notice, or communication from any regulatory authority restricting its processing or transfer of Client Personal Data in the manner contemplated by the Agreement, and (iv) where required by Data Protection Laws, it has provided appropriate notice to and obtained necessary consents from data subjects whose personal data is transferred to Company.

(f) CCPA: The California Addendum attached as Exhibit C applies only where, and to the extent that, the California Consumer Privacy Act (CCPA) applies to the processing of personal data in connection with the Services.

  1. Data Sharing Terms.

(a) Data Provided: Company will provide Client with the Licensed Materials, generally comprising business contact information and audience intelligence data, as described in the Agreement.

(b) Client’s Use: Client may use Licensed Materials for its own B2B marketing, sales, and business development purposes in accordance with the Agreement and applicable Order Form. Client will not resell, redistribute, or share the Licensed Materials with third parties except with service providers bound by confidentiality obligations.

(c) Data Protection: Each Party will: (i) process the Licensed Materials in compliance with applicable data protection laws; (ii) implement appropriate security measures; (iii) respect data subject rights; and (iv) notify the other Party without undue delay, to the extent required under applicable Data Protection Laws, of any data breach affecting the Licensed Materials. Client is solely responsible for compliance with applicable marketing laws (including CAN-SPAM, GDPR, etc.) in its use of the Licensed Materials.

  1. Confidentiality.

Each Party shall keep personal data confidential and use it only as permitted under this DPA and the Agreement. Personal data may be disclosed only to employees, contractors, and service providers who need access to perform under the Agreement. Each Party shall ensure that personnel with access to personal data: (i) are trained on data protection requirements appropriate to their role; (ii) are bound by confidentiality obligations; and (iii) process personal data only as authorized.

  1. Sub-Processors.

Where Company is processing Client Personal Data, Company shall: (i) maintain a current list of sub-processors at https://www.informatechtarget.com/sub-processor-list/; (ii) enter into written agreements with sub-processors imposing data protection obligations that provide substantially equivalent protection to this DPA; (iii) remain fully liable to Client for sub-processor performance; and (iv) ensure sub-processors implement appropriate technical and organizational security measures. Company will provide at least thirty (30) days‘ advance notice before engaging a new sub-processor or replacing an existing sub-processor. Client may object in writing within fifteen (15) days of such notice if the new sub-processor presents reasonable data protection concerns. If Client objects, then the Parties will discuss the objection in good faith and, if unresolved within fifteen (15) days of receipt of Client’s objection, then Company may, at its election, (A) choose not use the sub-processor for Client Personal Data, (B) implement alternative measures that address Client’s concerns.

  1. Technical and Organizational Measures.

(a) Company shall implement and maintain technical and organizational security measures appropriate to the risk, including those described in Exhibit B. Company will review and test the effectiveness of these measures at least annually.

(b) Company shall notify Client without undue delay, and in any event within seventy-two (72) hours, upon becoming aware of any personal data breach affecting Client Personal Data. Company will provide reasonable information to enable Client to assess the breach and fulfill any notification obligations under Data Protection Laws.

(c) Upon reasonable written request and at least thirty (30) days‘ advance notice, Company will provide Client with information reasonably necessary to demonstrate compliance with this DPA, which may include: (i) providing client with security documentation (no more than once per year); (ii) providing relevant certifications or audit reports; or (iii) permitting a remote documentary audit by Client or Client’s qualified third-party auditor subject to reasonable confidentiality obligations. Audits shall be conducted during business hours in a manner that does not unreasonably disrupt Company’s operations. If Client uses a third-party representative in connection with this Section 7(c), then the representative must: (A) be approved in advance by both Parties in writing; (B) be bound by confidentiality obligations and protect all information and results provided or made available in connection with the audit; (C) not be compensated on a contingency-fee basis; and (D) provide Company with a copy of all audit reports and summaries promptly upon completion. Client shall bear the cost of audits unless the audit reveals material non-compliance with this DPA, in which case Company shall reimburse Client’s reasonable costs.

  1. International Data Transfers.  

(a) To the extent Company transfers Client Personal Data outside the EEA, United Kingdom (UK), or Switzerland to countries not recognized as providing adequate data protection, the Parties shall implement appropriate transfer mechanisms required by Data Protection Laws, which may include: (i) SCCs as approved by the European Commission, (ii) UK International Data Transfer Agreement addendum to the SCCs (“UK Addendum”), (iii) Swiss-approved transfer mechanisms, or (iv) other legally recognized transfer mechanisms, including the EU-U.S. Data Privacy Framework where Company is certified.

(b) Where the SCCs apply, the SCCs are deemed entered into and incorporated into this DPA by reference, and completed as follows:

(1) Module One

i) Module One (Controller to Controller) will apply where Company provides Licensed Materials as a separate and independent controller to Client as described in Section 4 of this DPA.

(ii) Clause Specifications

A. Clause 7 (Docking Clause): The optional docking clause does not apply;

B. Clause 11 (Redress): The optional language regarding independent dispute resolution does not apply;

C. Clause 13 (Supervision): The supervisory authority is the Data Protection Commission of Ireland;

D. Clause 17 (Governing Law): The SCCs are governed by Irish law;

E. Clause 18(b) (Choice of Forum and Jurisdiction): Disputes shall be resolved before the courts of Ireland;

F. Annexes: Annex I and Annex II of the SCCs are set forth in Exhibit A and Exhibit B.

(2) Module Two

(i) Module Two (Controller to Processor) will apply where Company processes Client Personal Data as a processor as described in Section 2 if this DPA.

         (ii) Clause specifications:

A. Clause 7 (Docking Clause): The optional docking clause does not apply;

B. Clause 9 (Use of Sub-Processors): Option 2 applies, and the time period for prior notice of sub-processor changes is thirty (30) days as set forth in Section 6;

C. Clause 11 (Redress): The optional language regarding independent dispute resolution does not apply;

D. Clause 13 (Supervision): The supervisory authority is the Data Protection Commission of Ireland;

F. Clause 18(b) (Choice of Forum and Jurisdiction): Disputes shall be resolved before the courts of Ireland; and

G. Annexes: Annex I and Annex II of the SCCs are set forth in Exhibit A and Exhibit B.

(c) The UK Addendum will apply to Client Personal Data transferred from the United Kingdom, either directly or via onward transfer, to any country or recipient outside the United Kingdom that is not recognized by the competent United Kingdom regulatory authority as providing an adequate level of protection for personal data. The UK Addendum will be deemed entered into and incorporated into this DPA by reference, and completed as follows:

(i) Table 1 of the UK Addendum: The Parties’ details and key contact information are set forth in Exhibit A;

(ii) Table 2 of the UK Addendum: Information about the version of the SCCs, modules, and selected clauses to which the UK Addendum is appended are set forth in this DPA;

(iii) Table 3 of the UK Addendum:

(A) The list of parties is set forth in Exhibit A;

(B) The description of the transfer is set forth in Exhibit A;

(C) Annex II (technical and organizational measures) is set forth in Exhibit B;

(D) The list of sub-processors is set forth in Section 6 and available at https://www.informatechtarget.com/sub-processor-list/ and

(iv) Table 4 of the UK Addendum: Both the Importer and the Exporter may end the UK Addendum in accordance with its terms.

(d) For transfers of Client Personal Data from Switzerland to countries outside Switzerland that are not recognized as providing an adequate level of protection for personal data, the SCCs shall apply as modified by the requirements of the Swiss Federal Data Protection and Information Commissioner (FDPIC). For such transfers: (i) the FDPIC shall act as the competent supervisory authority, (ii) references to “Member State” in the SCCs shall include Switzerland, and (iii) data subjects in Switzerland may pursue their rights in Switzerland in accordance with Clause 18(c) of the SCCs.

(e) Where Company maintains a current certification under the EU-U.S. Data Privacy Framework, UK Extension to the EU-U.S. Data Privacy Framework, or Swiss-U.S. Data Privacy Framework, such certification may serve as an alternative transfer mechanism for transfers to the United States in accordance with applicable Data Protection Laws.

(f) If the SCCs, UK Addendum, or other transfer mechanisms are invalidated, amended, or replaced by competent authorities or applicable Data Protection Laws, the Parties shall promptly implement updated transfer mechanisms to ensure continued compliance with Data Protection Laws.

  1. Data Deletion.

Company will retain Client Personal Data for as long as necessary to provide the Services and fulfill the purposes described in this DPA and the Agreement. Upon termination or expiration of the Agreement, Company will, at Client’s written election, either: (i) return all Client Personal Data to Client in a commonly used, machine-readable format within thirty (30) days of termination, or (ii) securely delete all Client Personal Data within one hundred eighty (180) days of termination. Client Personal Data retained in backup or disaster recovery systems may be retained for up to one hundred eighty (180) days following termination, provided that such data: (a) is securely stored; (b) is not accessed or processed except for backup restoration purposes; and (c) is subject to the same security measures as active data. Company will delete such backup data in accordance with its standard backup retention and deletion practices. Notwithstanding subsections (b) and (c), Company may retain Client Personal Data to the extent and for such period as required by applicable law, regulation, or legal process, provided that Company: (w) promptly notifies Client in writing of such retention requirement (unless legally prohibited from doing so), (x) limits retention to the minimum period required, (y) continues to protect such data in accordance with this DPA, and (z) deletes such data once the legal retention requirement expires. If Client requests deletion of Client Personal Data during the term, Client acknowledges such deletion may impact Company’s ability to provide the Services. Company will not be liable for service interruptions resulting from Client-requested deletion during the term.

  1. Data Protection Impact Assessments, Data Subject Rights and Prior Consultation with Supervisory Authorities.

Upon Client’s written request, Company will provide reasonable assistance to Client in fulfilling Client’s obligations under Data Protection Laws, including assistance with data protection impact assessments, responses to data subject requests relating to Cient Personal Data, and cooperation with supervisory authorities, taking into account the nature of the processing and the information available to Company.

  1. Limitation of Liability.

Each Party’s liability, taken in aggregate, arising out of or related to this DPA and the SCCs, as amended by the UK Addendum, where applicable, whether in contract, tort or under any other theory of liability, will be subject to the limitations and exclusions of liability set out in the Agreement and any reference in such section to the liability of a Party means aggregate liability of that Party under the Agreement (including this DPA). Each Party is independently responsible for its compliance with applicable data protection laws. Company is liable for its collection and provision of Licensed Materials. Client is liable for its use and protection of Licensed Materials.

  1. Government Requests.

If Company receives a legally binding request from a government or law enforcement authority for Client Personal Data, Company will notify Client promptly unless legally prohibited, and will attempt to redirect the government or law enforcement authority to Client. Company will review the legal validity of any such request, challenge requests that appear invalid or overbroad in consultation with the Client, and disclose only the minimum Client Personal Data legally required. Company will not create back doors, weaken encryption, or provide unauthorized access to Client Personal Data for any government or law enforcement authority, except as compelled by a legally binding court order.

13. Miscellaneous.

  1. This DPA supplements the Agreement. If there is any conflict between this DPA and the Agreement regarding the processing of Client Personal Data, this DPA will control.
  2. Company’s obligations under this DPA will survive termination of the Agreement for as long as Company retains or processes Client Personal Data.
  3. If any provision of this DPA is held invalid or unenforceable, the remaining provisions will remain in full force and effect.
  4. This DPA will be governed by the law and venue provisions set forth in the Agreement.
  5. The Parties consent to the use of electronic signatures, which shall have the same force and effect as manual signatures.

EXHIBIT A

ANNEX I

A. LIST OF PARTIES

MODULE ONE: Transfer Controller to Controller

Data Exporter(s):

Name: TechTarget Holdings, Inc. and its subsidiaries and affiliates

Address: 275 Grove Street, Newton, MA 02466, USA

Contact person’s name, position and contact details: Carmen Picillo, Privacy and Data Privacy Officer, [email protected]

Activities relevant to the data transferred under these Clauses:  Data exporter collects, aggregates, and provides business contact information and intent data from data exporter’s proprietary database to data importer as Licensed Materials for data importer’s independent business purposes.

Signature and date: As set forth in this DPA or applicable Order Form agreed to between the Parties

Role (controller/processor):  Controller

Data Importer(s):

Name: Client identified on the applicable Order Form

Address: Client’s address identified on the applicable Order Form

Contact person’s name, position and contact details: Unless otherwise mutually agreed to in writing, the name and contact information of the individual(s) having administrative access or similar permissions set forth in the applicable Services

Activities relevant to the data transferred under these Clauses: Data importer receives Licensed Materials from data exporter and uses such data for data importer’s own sales and marketing activities as an independent controller.

Signature and date: As set forth in this DPA or applicable Order Form agreed to between the Parties.

Role (controller/processor):  Controller

MODULE TWO: Transfer controller to processor

Data exporter(s): 

Name: Client identified on the applicable Order Form

Address: Client’s address identified on the applicable Order Form

Contact person’s name, position and contact details: Unless otherwise mutually agreed to in writing, the name and contact information of the individual(s) having administrative access or similar permissions set forth in the applicable Services

Activities relevant to the data transferred under these Clauses: Transfer of business contact information in connection with Services provided by Importer.

Signature and date: As set forth in this DPA or applicable Order Form agreed to between the Parties.

Role (controller/processor):  Controller

Data importer(s): 

Name: TechTarget Holdings, Inc. and its subsidiaries and affiliates

Address: 275 Grove Street, Newton, MA 02466, USA

Contact person’s name, position and contact details: Carmen Picillo, Privacy and Data Privacy Officer, [email protected]

Activities relevant to the data transferred under these Clauses:  Processing of business contact information on behalf of Exporter, including hosting, storage, and providing access through the Services for Exporter’s sales and marketing purposes

Signature and date: As set forth in this DPA or applicable Order Form agreed to between the Parties

Role (controller/processor):  Processor

B. DESCRIPTION OF TRANSFER

MODULE ONE

Categories of data subjects whose personal data is transferred

Business professionals and employees at companies in data exporter’s database who have engaged with technology-related content or whose business contact information is publicly available

Individuals who have visited data exporter’s websites or content syndication network, attended events, or subscribed to publications

Categories of Personal Data Transferred

The personal data transferred concern the following categories of data:

Contact information: Name, business email, phone, job title, company details, and professional profiles

Online activity:  website visits and content engagement

Intent signals: Content topics viewed, search terms, purchase intent indicators, and engagement patterns

Company data: Technologies used, IT infrastructure, spending patterns, and growth indicators

Sensitive data transferred (if applicable) and applied restrictions or safeguards that fully take into consideration the nature of the data and the risks involved, such as for instance strict purpose limitation, access restrictions (including access only for staff having followed specialised training), keeping a record of access to the data, restrictions for onward transfers or additional security measures.

None

The frequency of the transfer (e.g. whether the data is transferred on a one-off or continuous basis)

Continuous basis during the term of the Agreement.

Nature of the processing

Data importer will process the Licensed Materials as an independent controller for data importer’s own business purposes. 

Purpose(s) of the data transfer and further processing

The Licensed Materials are transferred to enable data importer to identify and engage potential customers showing purchase intent, support targeted account-based marketing campaigns, optimize sales and marketing efforts based on intent signals, and gain market intelligence about industry trends and competitive landscape.

The period for which the personal data will be retained, or, if that is not possible, the criteria used to determine that period

Data exporter retains personal data in its database in accordance with its retention policies. 

For transfers to (sub-)processors, also specify subject matter, nature and duration of the processing

Not Applicable

MODULE TWO

Categories of data subjects whose personal data is transferred

Business contacts: Prospective customers, current customers, business partners, and other professional contacts whose information is provided by Client or processed through the Services

Website visitors: Individuals who visit Client’s website and whose data is collected through Client’s use of the Services

Other individuals: Other individuals whose personal data Client provides to Company or processes through the Services

Categories of Personal Data Transferred

Client employee and user data, target account, and contact lists, CRM integration data, website visitor data, suppression lists, support communications, and other business information provided by Client.

Sensitive data transferred (if applicable) and applied restrictions or safeguards that fully take into consideration the nature of the data and the risks involved, such as for instance strict purpose limitation, access restrictions (including access only for staff having followed specialized training), keeping a record of access to the data, restrictions for onward transfers or additional security measures.

None. Client shall not provide any special categories of personal data (as defined in Article 9 GDPR) or personal data relating to criminal convictions and offences (as defined in Article 10 GDPR) to Company without Company’s prior written consent and implementation of appropriate safeguards.

The frequency of the transfer (e.g., whether the data is transferred on a one-off or continuous basis)

Continuous for the duration of the Agreement.

Nature of the processing

Company will process personal data on behalf of Client by hosting and storing data, providing access through the Services, analyzing data to provide insights and intent signals, enriching data with business intelligence, facilitating CRM and marketing automation integrations, tracking website visitor activity, processing suppression requests, generating reports and analytics, providing customer support, and performing other processing activities as described in the Agreement and as instructed by Client.

Purpose(s) of the data transfer and further processing

Business contact information and other business information will be transferred to Importer to allow Importer to provide its Services and access to its Platforms as described in the Importer’s product descriptions and the Agreement.

The period for which the personal data will be retained, or, if that is not possible, the criteria used to determine that period

Personal Data will be Processed and retained for the duration of the Agreement and subject to Section 9 of the DPA.

For transfers to (sub-) processors, also specify subject matter, nature and duration of the processing

The subject matter, nature, and related information of the Processing undertaken by sub-processors will be set forth in TechTarget’s Sub-Processor List available here: https://www.informatechtarget.com/sub-processor-list/.   

C. COMPETENT SUPERVISORY AUTHORITY

Data Protection Commission (DPC) of Ireland. Under the SCCs entered into by the Parties pursuant to the DPA, Module 2 (Transfer Controller to Processor), the supervisory authority will be the competent supervisory authority that has supervision over the Client Affiliate or other relevant data exporter located in the EEA in accordance with Clause 13 of the Standard Contractual Clauses.

EXHIBIT B

ANNEX II – TECHNICAL AND ORGANISATIONAL MEASURES INCLUDING TECHNICAL AND ORGANISATIONAL MEASURES TO ENSURE THE SECURITY OF THE DATA

MODULE ONE: Transfer Controller to Controller

MODULE TWO: Transfer Controller to Processor

Trust Center: https://www.informatechtarget.com/about-us/privacy-and-security-trust-center/

Control of physical access to premisesTechnical and organizational measures to control physical access to premises and facilities, particularly to identify permitted personnel at entry:

☒ Locked doors on all entrances / exits (e.g., electronic locks; physical locks; etc.)
☒ Presence of security personnel (e.g., security at the front desk).
☒ Access control systems (e.g., biometric security; access card security; etc.)
☒ CCTV systems
☒ Additional physical security measures to protect IT systems (e.g., partitioned server room; etc.) (please specify): Additional swipe system on server room door.  
Control of access to IT systems  Technical and organizational security measures designed to ensure that users with access to the relevant IT systems are identified and authenticated:
☒ IT security systems requiring individual users to log in using unique user names
☒ IT security systems requiring the use of strong / complex passwords
☒ IT security systems requiring the use of multi-factor authentication
☒ Additional system log-in requirements for particular applications
☒ Mandatory password changes at fixed intervals (e.g., every 6 months)
☒ State-of-the art encryption applied to all data ‘in transit’
☒ State-of-the art encryption applied to all data ‘at rest’
☒ Password databases are subject to strong encryption / hashing
☒ Regular audits of security procedures
☒Training for employees regarding access to IT systems  
Control of access to personal dataTechnical and organizational security measures designed to ensure that users with access to the relevant personal data are identified and authenticated:
☒ ‘Read’ rights for systems containing personal data restricted to specified personnel roles
☒ ‘Edit’ rights for systems containing personal data restricted to specified personnel roles or profiles
☒ Logging of all attempts to access systems containing personal data (e.g., recording IP addresses and attempted password and username combinations)
☒ State-of-the art encryption on drives and media containing personal data (e.g., using Sophos SafeGuard; TrueCrypt; etc.)
☒ Training for employees regarding access to personal data  
Control of disclosure of personal data  Technical and organizational measures to securely transfer, transmit and communicate or store data on data media and for subsequent checking:
☒ Secure data networks (e.g., encrypted VPNs)
☒ SSL encryption for all internet access portals
☒ Enforced encryption of all drives that are used to take data off the network  
Control of input mechanisms    Technical and organizational security measures to permit the recording and later analysis of information about when input to data systems (e.g., editing, adding, deleting, etc.) occurred and who was responsible for such input:
☒ Logging of all input actions in systems containing personal data
☒ ‘Edit’ rights for systems containing personal data restricted to specified personnel roles Profiles
☒ Logging of all failed attempts to edit personal data  
Control of workflows between controllers and processors  Technical and organizational measures to segregate the responsibilities between controllers and processors processing the relevant personal data:
☒ Binding agreements in writing governing the appointment and responsibilities of processors with access to the relevant personal data
☒  Training for employees regarding processing of personal data  
Control mechanisms to ensure availability of the relevant personal data  Technical and organizational measures to ensure the physical and electronic availability and accessibility of the relevant personal data:
☒ Documented disaster recovery procedures
☒ Secure backup procedures in place, with full backups run regularly
☒ Multiple backup facilities and locations
☒ Uninterruptible power supplies at backup facilities
☒ Physical security of backup facilities (e.g., secure premises; security personnel).
☒ Security alarm systems at backup facilities
☒ Electronic security of backup facilities (e.g., firewalls; antivirus software; etc.)
☒ Environmental controls at backup facilities (e.g., cooling; humidity controls; etc.)
☒ Fire protection at backup facilities (e.g., sprinkler systems; fireproof doors; etc.)
☒ Secure anonymization or deletion of personal data that are no longer required for lawful processing purposes
☒ Training for employees regarding backups and disaster recovery  
Control mechanisms to ensure separation of the relevant personal data from other data  Technical and organizational measures to ensure that the relevant personal data are stored and processed separately from other data:
☒ Logical separation of live or production data from backup data and development or test data ☒ Logical separation of drives containing relevant personal data from systems containing other data
☒ Separation of personnel processing the relevant personal data from other personnel
☒ Training for employees regarding data separation

EXHIBIT C

California Addendum

Capitalized terms used in this California Addendum that are not otherwise defined in the DPA shall, unless the context clearly provides otherwise, have the same meaning assigned to them in the CCPA.

For purposes of this California Addendum: “Business,” “Service Provider,” “Sale,” “Sell,” “Share” or “Sharing,” and “Consumer” have the meanings assigned to them in the CCPA.

  1. When Company provides Licensed Materials to Client (including business contact data, intent data, and other information from Company’s database), Company acts as a Business and Client acts as a Business receiving personal information from another Business. In such instances, the following provisions apply:
  1. Company is providing, and Client is using, the Licensed Materials for Client’s internal business purposes and business-to-business sales and marketing efforts as provided in the Agreement, the DPA, and this California Addendum.
  1. Client will comply with applicable sections of the CCPA with respect to the Licensed Materials, including without limitation:
  1. Honoring Consumer requests to opt-out of Sale or Sharing when notified by the Consumer or by Company;
  2. Implementing reasonable security procedures and practices appropriate to the nature of the personal information to protect against unauthorized or illegal access, destruction, use, modification, or disclosure;
  3. Providing the same level of privacy protection as required by the CCPA;
  4. Not Selling or Sharing the Licensed Materials; and
  5. Complying with Consumer opt-out preference signals as required by the CCPA.
  1. Company will:
    1. Provide mechanisms for consumers to opt-out of Sale or Sharing of their personal information;
    2. Maintain records of Consumer opt-out requests;
    3. Notify Client of Consumer opt-out requests that affect the Licensed Materials provided to ; and
    4. Comply with its obligations as a Business under the CCPA with respect to the Licensed Materials.


Company shall notify Client of any Consumer request made pursuant to the CCPA that Client must comply with and agrees to provide all information necessary for Client to comply with the request in the periods prescribed under the CCPA.

  1. Client will notify Company within five (5) business days if it makes a determination that it can no longer meet its obligations under the CCPA with respect to the Licensed Materials. Upon receiving notice of Client’s non-compliance, or upon Company’s discovery of Client’s material breach of this California Addendum, Company may:
  1. Require Client to provide written certification of compliance with CCPA obligations;
  2. Require Client to provide documentation verifying that Client has honored Consumer opt-out requests;
  3. Suspend Client’s access to the Licensed Materials until compliance is restored; or
  4. Terminate the Agreement in accordance with its termination provisions.

 

  1. When Company processes Client Personal Data on Client’s behalf (including data Client uploads, integrates from Client’s systems, or collects through Client’s use of tracking technologies), Company acts as a Service Provider and Client acts as a Business. In such instances, the following provisions apply:
  1. Client hereby appoints Company to process Client Personal Data as a Service Provider in accordance with the Agreement, the DPA, and this California Addendum. Company shall remain responsible for complying with its obligations as a Service Provider, and Client shall remain responsible for compliance with its obligations as a Business. Client represents and warrants that it has all necessary rights, permissions, and authorizations under the CCPA for Company to process the Client Personal Data as contemplated by the Agreement.
  1. Company agrees to process Client Personal Data solely for the following limited and specified business purposes:
  1. Providing the Services as described in the Agreement and Order Form;
  2. Facilitating integrations with Client’s CRM and marketing automation systems;
  3. Tracking and analyzing website visitor activity through tracking technologies deployed on Client’s website;
  4. Providing customer support and technical assistance to Client;
  5. Complying with applicable legal obligations; and
  6. Other purposes as directed by Client in writing or through Client’s use and configuration of the Services.
  1. Company agrees that it will not:
  1. Sell or Share Client Personal Data as those terms are defined in the CCPA;
  2. retain, use, or disclose Client Personal Data for any purpose other than: (i) providing the Services as specified in the Agreement and Order Form or (ii) as otherwise permitted by the CCPA or authorized by Client in writing; or
  3. combine Client Personal Data with personal information that Company receives from or on behalf of another person or persons, or collects from its own interaction with consumers, except as permitted under CCPA Section 1798.140(w)(2)(C) and implementing regulations.
  1. Company will implement and maintain reasonable security procedures and practices appropriate to the nature of the Client Personal Data to protect against unauthorized or illegal access, destruction, use, modification, or disclosure, as further described in the DPA and Exhibit B
  1. Company may engage sub-processors to assist in processing Client Personal Data in accordance with Section 6 of the DPA. Company will ensure that each sub-processor is bound by written obligations substantially similar to those in this California Addendum, and Company remains liable for sub-processor compliance with CCPA obligations.
  1. Company will notify Client within five (5) business days if it makes a determination that it can no longer meet its obligations under the CCPA as a Service Provider. Upon receiving notice of Company’s non-compliance, or upon Client’s discovery of Company’s material breach of this California Addendum, Client may:
  1. Require Company to provide written certification of compliance with CCPA obligations;
  2. Require Company to provide documentation verifying compliance with consumer requests;
  3. Suspend Company’s access to Client Personal Data until compliance is restored; or
  4. Terminate the Agreement in accordance with its termination provisions.
  1. Client shall notify Company of any Consumer request made pursuant to the CCPA that Company must comply with and agrees to provide all information necessary for Company to comply with the request in the periods prescribed under the CCPA.

Effective July 1, 2026 

Conversion Pixel