Data Processing Addendum (DPA)
This Data Processing Addendum ("DPA") is incorporated into the Terms of Service between Customer ("Controller") and SpotlightIQ, LLC ("Processor").
1. Definitions
Terms like "Personal Data," "Processing," "Sale," "Share," "Targeted Advertising," and "Data Subject" will have the meanings ascribed to them in applicable data protection laws, including the California Consumer Privacy Act ("CCPA").
2. Roles and Scope of Processing
Processor will process Personal Data only on behalf of and in accordance with the documented instructions of the Controller (as detailed in Appendix 1) and as otherwise permitted under applicable data protection laws.
3. Prohibited Uses
To the extent required by applicable data protection laws, Processor will not:
- Sell or Share Personal Data, or process Personal Data for Targeted Advertising or Cross-Context Behavioral Advertising;
- Retain, use, or disclose Personal Data for any purpose other than performing the Services described in the Terms of Service and Appendix 1, or as otherwise permitted by applicable data protection laws;
- Retain, use, or disclose Personal Data outside the direct business relationship between Processor and Controller; or
- Combine Personal Data received from Controller with Personal Data obtained from any other source, except as permitted by applicable data protection laws to perform a business purpose on Controller's behalf.
4. Security Measures
Processor will implement and maintain appropriate technical and organizational security measures to protect Personal Data against accidental or unlawful destruction, loss, alteration, or unauthorized disclosure or access.
5. Subprocessors
Controller provides a general authorization for Processor to engage third-party subprocessors to provide the Services. Processor will maintain a list of subprocessors and provide notice of any new subprocessors.
6. Data Subject Rights
Processor will, to the extent legally permitted, provide reasonable assistance to the Controller to respond to requests from Data Subjects to exercise their rights under applicable data protection laws.
7. Data Breach Notification
Processor will notify Controller without undue delay after becoming aware of a Personal Data breach.
8. Termination and Deletion
Upon termination of the Services, Processor will delete or return all Personal Data as instructed by the Controller within forty-five (45) days, unless retention is required by applicable law.
Appendix 1: Details of Processing
Categories of Data Subjects:
- Employees, agents, and representatives of the Customer who are authorized to use the SpotlightIQ platform.
- Individuals (e.g., business professionals, stakeholders) whose personal data is included in the Customer Content uploaded or synced by the Customer for targeting purposes.
- Visitors to the Customer's websites where a SpotlightIQ measurement pixel is installed.
Categories of Personal Data:
- Customer User Data: Full name, business email address, phone number, job title, company name, and IP address.
- Customer Targeting Data: Personal data contained within Customer Content, which may include names, titles, company names, and business contact information.
- Website Measurement Data: Online identifiers (e.g., cookie IDs), IP addresses, and browsing activity collected via the measurement pixel on Customer's website(s).
Nature and Purpose of Processing:
- To provide the Services as described in the Terms of Service.
- To enable the Customer to create, manage, and measure CTV and other digital video advertising campaigns.
- To process Customer Targeting Data as instructed by the Customer to create target audience segments.
- To analyze campaign performance and generate insights.
- To provide customer support and maintain the platform.