Data Processing Agreement

Version 1.0 | Effective March 31, 2026 | Last updated March 31, 2026

This is the current version of the Elemental TV Data Processing Agreement.

Construction. References in this DPA to Sections and Schedules are to Sections and Schedules of this DPA unless otherwise stated. References in this DPA to “the Agreement” are to the Elemental TV Master Services Agreement, Insertion Order, or other applicable agreement to which this DPA relates or into which it is incorporated. For the purposes of this DPA, Elemental TV LLC is the “Service Provider” and the counterparty is the “Customer” (and, where applicable, a “Publisher” or “Data Provider”).

This Data Processing Agreement ("DPA") is made by and between:

(a) The individual or entity indicated on the signature page of the requisite Elemental TV Agreement ("Agreement"), as “Customer”; or

(b) Any publisher, content owner, or distributor that has entered into an Insertion Order, monetization publisher of record agreement, agency of record agreement, or similar advertising or monetization agreement with Elemental TV pursuant to which Elemental TV monetizes, represents, sells, or purchases advertising inventory and processes Personal Information of such entity's users or viewers (each, a "Publisher"); or

(c) Any entity that provides, transmits, or makes available Personal Information to Elemental TV for processing through audience intelligence services or other Elemental TV services (each, a "Data Provider");

(d) Any demand-side platform, advertiser, agency, advertising network, or other buyer that receives bid requests, bid responses, or impression-level data from Elemental TV in order to bid on, purchase, or deliver advertising through Elemental TV's programmatic advertising platform or an Elemental TV RTB Agreement (each, a "Buyer");

(collectively referred to herein as "Customer") and Elemental TV LLC, a Delaware limited liability company ("Elemental TV" or "Service Provider"). Service Provider may perform its obligations under this DPA through its affiliates, and any affiliate so engaged shall be treated as a subprocessor for the purposes of Section 8 (Subcontractors).

The effective date of this DPA is: (i) the Effective Date of the Agreement for parties with an Agreement; (ii) the effective date of the Insertion Order for Publishers; or (iii) the date on which Data Provider first provides Personal Information to Elemental TV.

All defined terms herein shall have the meanings ascribed to them in the Agreement or Insertion Order (as applicable), unless otherwise defined herein. For Data Providers without a governing commercial agreement, terms shall have their commonly understood meaning in the data processing and privacy context.

Recitals

WHEREAS, the Service Provider and Customer entered into the Agreement that may require the Service Provider to process Personal Information provided or collected by the Customer; and

WHEREAS, this DPA sets out the additional terms, requirements, and conditions on which the Service Provider will obtain, handle, process, disclose, transfer, or store Personal Information when providing services under the Agreement.

NOW, THEREFORE, in consideration of the mutual covenants and agreements hereinafter set forth and for other good and valuable consideration, the receipt and sufficiency of which are hereby acknowledged, the parties hereto agree as follows:

1. Definitions and Interpretation

The following definitions and rules of interpretation apply in this DPA.

1.1 "Business Purpose" means:

(a) For parties with an Agreement: the services described in the Agreement;

(b) For Publishers under an Insertion Order: the delivery, targeting, measurement, and reporting of advertising campaigns on Publisher's inventory, including processing of viewer data, device identifiers, IP addresses, and related information necessary to serve, frequency cap, and measure advertising performance;

(c) For Data Providers contributing to Elemental TV audience segments: processing Personal Information to create de-identified audience segments, analytics, and insights as part of Elemental TV's audience intelligence platform; or

(d) For other Data Providers: the specific data processing purposes documented in the applicable data contribution agreement, order form, or statement of work between the parties.

1.2 "Data Subject" means an individual who is the subject of the Personal Information and to whom or about whom the Personal Information relates or identifies, directly or indirectly.

1.3 "Personal Information" means any information the Service Provider processes for the Customer that (a) identifies or relates to an individual who can be identified directly or indirectly from that data alone or in combination with other information in the Service Provider's possession or control or that the Service Provider is likely to have access to, or (b) the relevant Privacy and Data Protection Laws otherwise define as protected personal information.

1.4 "Privacy and Data Protection Laws" means all applicable federal, state, and foreign laws and regulations relating to the processing, protection, or privacy of the Personal Information, including where applicable, the guidance and codes of practice issued by regulatory bodies in any relevant jurisdiction. Such laws include, without limitation, the EU General Data Protection Regulation (Regulation (EU) 2016/679) and the UK GDPR, the Swiss Federal Act on Data Protection, and the California Consumer Privacy Act as amended by the California Privacy Rights Act and other applicable U.S. state privacy laws and, in respect of any Activated Market or other market from which Personal Information originates, the Personal Information Protection and Electronic Documents Act (Canada) and Quebec's Act respecting the protection of personal information in the private sector (Law 25); the Federal Law on Protection of Personal Data Held by Private Parties (Mexico); the Privacy Act 1988 and Australian Privacy Principles (Australia); and the Privacy Act 2020 (New Zealand), in each case as amended.

1.5 "Security Breach" means any act or omission that compromises the security, confidentiality, or integrity of Personal Information. The loss of or unauthorized access, disclosure, or acquisition of Personal Information is a Security Breach whether or not the incident rises to the level of a security breach under the Privacy and Data Protection Laws.

1.6 Incorporation. For parties with an Agreement or Insertion Order, this DPA is subject to the terms of such Agreement or Insertion Order and is incorporated therein. For Data Providers without a governing commercial agreement, this DPA constitutes the complete and exclusive agreement between the parties with respect to the processing of Personal Information. Interpretations and defined terms set forth in any applicable Agreement or Insertion Order apply to the interpretation of this DPA to the extent applicable.

1.7 Conflict. In the case of conflict or ambiguity between any of the provisions of this DPA and the provisions of the Agreement, the provisions of this DPA will prevail in respect of the processing of Personal Information and the parties' respective obligations under Privacy and Data Protection Laws. The provisions of the Agreement will prevail in respect of governing law, forum, term and termination, commercial terms, indemnification, and limitation of liability, other than the governing law and forum of the Standard Contractual Clauses under Section 7.2(a), which are as stated in that Section. For the avoidance of doubt, "Agreement" as used in this Section includes the IAB Standard Terms and Conditions incorporated into the Agreement, and this DPA prevails over Section XII (Non-Disclosure, Data Usage and Ownership, Privacy and Laws) of those IAB Terms in respect of the processing of Personal Information and all data-protection matters.

1.8 Data Providers Without a Governing Commercial Agreement. For Data Providers without a governing commercial agreement, the following additional terms apply. For the avoidance of doubt, this Section does not apply to any Customer, Publisher, or Data Provider that has entered into an Agreement or Insertion Order with Service Provider, and nothing in this Section varies the governing law, forum, or dispute resolution provisions of any such Agreement or Insertion Order:

(a) License Grant. Data Provider grants Service Provider a perpetual, irrevocable, worldwide, royalty-free license to use, process, aggregate, and de-identify Personal Information provided by Data Provider, and to create, own, and commercialize De-Identified Information and Service Provider Models derived therefrom.

(b) Termination. Either party may terminate this DPA upon thirty (30) days written notice. Upon termination, Data Provider shall cease providing Personal Information, but Service Provider may continue to use De-Identified Information and Service Provider Models in accordance with Section 3.5.

(c) No Payment Obligation. Data Provider acknowledges that Service Provider has no obligation to compensate Data Provider for Personal Information provided hereunder.

(d) Governing Law. This DPA shall be governed by the laws of the State of Delaware, without regard to conflicts of law principles.

(e) Dispute Resolution. Any dispute arising from this DPA shall be resolved through binding arbitration in Los Angeles County, California, in accordance with the rules of the American Arbitration Association.

(f) Data Provider Representations and Warranties. Data Provider represents and warrants that: (i) it has all necessary rights, permissions, and legal bases to provide the Personal Information to Service Provider; (ii) the Personal Information was collected and processed in compliance with all applicable Privacy and Data Protection Laws; (iii) the provision of Personal Information to Service Provider does not violate any third party rights or any agreement to which Data Provider is a party; and (iv) Data Provider has provided all required notices and obtained all required consents for the collection and sharing of Personal Information with Service Provider.

2. Personal Information Types and Processing Purposes

2.1 Customer Responsibility. The Customer retains control of the Personal Information and remains responsible for its compliance obligations under the applicable Privacy and Data Protection Laws, including providing any required notices and obtaining any required consents, and for the processing instructions it gives to the Service Provider.

2.2 Limited Disclosure. The Customer discloses Personal Information to the Service Provider only for the limited and specified Business Purposes. The categories of Personal Information and the nature and purpose of processing are further described in Schedule 2.

2.3 Applicability and Relationship Types. This DPA applies to:

(a) Customers who have entered into an Agreement with Elemental TV for services that involve processing of Personal Information;

(b) Publishers who have entered into Insertion Orders or advertising agreements with Elemental TV pursuant to which Elemental TV monetizes, represents, sells, or purchases advertising inventory and processes Personal Information of Publisher's users, viewers, or website visitors;

(c) Publishers, content owners, or distributors who provide Personal Information to Elemental TV for processing through audience intelligence services or similar audience intelligence services;

(d) Data Providers and any other entity that provides, transmits, or makes Personal Information available to Elemental TV for processing in connection with Elemental TV's services; and

(e) Publishers whose inventory is made available through Elemental TV's programmatic advertising platform or RTB Agreement, for the purposes of: (i) facilitating real-time bidding processes and programmatic ad sales; (ii) transmitting bid requests containing Personal Information to potential Buyers; (iii) delivering advertising to targeted audiences using Elemental TV audience segments; and (iv) providing reporting and measurement services related to programmatic campaigns.

(f) Buyers that receive Personal Information from Elemental TV in bid requests, bid responses, or impression-level data in connection with real-time bidding, programmatic purchasing, or the delivery and measurement of advertising.

For Publishers operating under Insertion Orders, the Business Purpose includes all activities necessary to deliver, serve, target, optimize, frequency cap, measure, and report on advertising campaigns placed on Publisher's inventory, including the processing of device identifiers, IP addresses, viewing behavior, and related technical and behavioral data necessary for ad delivery and measurement.

2.4 Roles of the Parties. With respect to each processing activity under this DPA, Service Provider acts as a service provider or processor on behalf of Customer, except where Service Provider independently determines the purposes and means of processing, including the creation, maintenance, and commercialization of De-Identified Information, Aggregated Information, and Service Provider Models under Section 3.5, in which case Service Provider acts as a business or independent controller with respect to that activity. Customer acts as a business or controller with respect to the Personal Information it discloses to Service Provider, or, where applicable, as a processor acting on behalf of a third-party controller. This Section 2.4 is subject to Section 2.5 (Buyers and Demand-Side Counterparties).

2.5 Buyers and Demand-Side Counterparties. The following applies where the Customer is a Buyer:

(a) Application. This Section 2.5 applies to Personal Information that Service Provider transmits to a Buyer, or that a Buyer receives, in a bid request, bid response, or impression-level data feed in connection with an auction conducted on Service Provider's programmatic advertising platform. Where the Customer is a Buyer, this Section 2.5 prevails over Sections 2.1, 2.2, and 2.4 and over any other provision of this DPA that would designate Service Provider as a processor or service provider acting on behalf of the Buyer.

(b) Roles. With respect to Personal Information described in Section 2.5(a), each party acts as an independent business and independent controller and determines the purposes and means of its own processing. Neither party processes that Personal Information on behalf of, or under the documented instructions of, the other. Service Provider is not a processor or service provider to the Buyer, and the Buyer is not a processor or service provider to Service Provider.

(c) Bid Stream Transmission and Privacy Signals. The transmission of device identifiers, IP addresses, approximate geolocation, and related inventory and device metadata in a bid request is an inherent and necessary element of the programmatic advertising services the parties have contracted for, and is made at the direction of the applicable Publisher. Service Provider will pass, and Buyer will receive, honor, and pass to its own downstream recipients, all applicable consent, opt-out, and privacy signals present in or accompanying the bid request, including any IAB Transparency and Consent Framework, Global Privacy Platform, or US Privacy string values, Global Privacy Control (GPC) signals, and any equivalent successor signal. Buyer will not bid on, purchase, or otherwise process Personal Information contrary to those signals.

(d) Buyer Compliance. Buyer is responsible for its own compliance with Privacy and Data Protection Laws with respect to Personal Information it receives, including providing any notices and obtaining any consents or authorizations required for Buyer's own processing, and is responsible for the acts and omissions of its advertisers, clients, and downstream recipients. Service Provider is responsible for obtaining, through its Publishers, the notices and consents required for the transmission of Personal Information in bid requests.

(e) Scope of Obligations. Personal Information described in Section 2.5(a) originates from Service Provider's Publishers and their end users. Nothing in this DPA entitles Buyer to direct the deletion, return, correction, or restriction of Personal Information held by Service Provider or its Publishers, or to audit Service Provider under Section 12 with respect to that Personal Information. Each party will respond to data subject requests relating to Personal Information in its own possession and will provide the other party with reasonable cooperation where a request concerns Personal Information the other party holds.

(f) Personal Information Supplied by Buyer. Where Buyer provides Personal Information to Service Provider, including audience segments, conversion data, or customer lists supplied for targeting, measurement, or attribution, Service Provider acts as Buyer's service provider or processor with respect to that Personal Information, and the remaining provisions of this DPA apply to Service Provider's processing of it.

(g) Relationship to the Agreement. For Buyers, the data provisions of the Agreement, including any Service Data provisions of an Elemental TV RTB Agreement, govern Buyer's permitted use of data received from Service Provider. Section 1.7 does not operate to displace those provisions, and in the case of conflict between this Section 2.5 and the Agreement, this Section 2.5 prevails only as to the allocation of roles under Privacy and Data Protection Laws.

3. Service Provider's Obligations

3.1 Purpose Limitation. The Service Provider will only process, retain, use, or disclose the Personal Information to the extent, and in such a manner, as is necessary for the Business Purposes. The Service Provider will not process, retain, use, or disclose the Personal Information for any other purpose, outside of the parties' business relationship, or in a way that does not comply with this DPA or the Privacy and Data Protection Laws. The Service Provider must promptly notify the Customer if its processing of Personal Information would not comply with the Privacy and Data Protection Laws.

3.2 Customer Instructions; Deletion. The Service Provider must comply with any Customer request or instruction requiring the Service Provider to amend, transfer, or delete the Personal Information within the timeframes required by applicable Privacy and Data Protection Laws, or within forty-five (45) calendar days if no specific timeframe is mandated. For purposes of this DPA, "deletion" means: (a) permanent erasure or destruction of Personal Information such that it cannot be reconstructed or recovered; or (b) de-identification or aggregation of Personal Information in accordance with Section 3.5, such that the resulting data ceases to constitute Personal Information under this DPA and may be retained by Service Provider. For Personal Information subject to GDPR or other laws requiring irreversible deletion, Service Provider shall permanently erase such data without option for de-identification.

3.3 Confidentiality; No Sale. The Service Provider will maintain the confidentiality of all Personal Information, will not sell it to or share it for cross-contextual advertising with anyone, and will not disclose it to third parties unless the Customer or this DPA specifically authorizes the disclosure, or as required by law. This Section 3.3 is subject to Section 2.5 (Buyers and Demand-Side Counterparties) and Section 3.7(d) (Real-Time Bidding Data Flows), under which Service Provider transmits Personal Information to Buyers in bid requests at the direction of, and on behalf of, the applicable Publisher. If a law requires the Service Provider to disclose Personal Information, the Service Provider must first inform the Customer of the legal requirement and give the Customer an opportunity to object or challenge the requirement, unless the law prohibits such notice.

3.4 Assistance. The Service Provider will reasonably assist the Customer with meeting the Customer's compliance obligations under the Privacy and Data Protection Laws, taking into account the nature of the Service Provider's processing and the information available to the Service Provider.

3.5 De-Identification and Aggregation Rights. The following applies to de-identification and aggregation:

(a) Service Provider may de-identify or aggregate Personal Information in accordance with applicable Privacy and Data Protection Laws. Upon proper de-identification or aggregation, such data shall cease to constitute Personal Information under this DPA.

(b) "De-Identified Information" means information that (i) cannot reasonably be used to infer information about, or otherwise be linked to, a particular consumer or household, and (ii) is maintained and used by Service Provider in de-identified form subject to technical safeguards that prohibit re-identification, business processes that specifically prohibit re-identification, and public commitment not to attempt re-identification.

(c) "Aggregated Information" means information relating to a group or category of consumers from which individual consumer identities have been removed and which is not linked or reasonably linkable to any consumer or household.

(d) De-Identified Information and Aggregated Information are not subject to this DPA, and Service Provider’s rights to retain, use, disclose, and commercialize such information, and any audience segments, models, and analytics derived from it, are governed by the Agreement.

(e) Deletion obligations under Section 3.2 and Section 11.1 shall not apply to De-Identified Information, Aggregated Information, or to Service Provider Models, algorithms, or analytics that have been trained on or derived from properly de-identified or aggregated data.

(f) Service Provider Models and Intellectual Property. "Service Provider Models" means Service Provider's proprietary algorithms, machine learning models, audience segments, predictive models, and analytics tools developed by Service Provider. To the extent Service Provider Models have been trained on De-Identified Information or Aggregated Information, deletion requests shall not require modification or destruction of such models, provided that (i) Service Provider implements technical measures to prevent the models from outputting Personal Information that could identify specific consumers subject to deletion requests, and (ii) Service Provider does not use such models to target, profile, or make decisions about consumers who have requested deletion of their Personal Information. Service Provider may continue to use and improve Service Provider Models based on properly de-identified or aggregated insights, even after deletion of underlying Personal Information.

Notwithstanding the foregoing, the rights granted in this Section 3.5 are subject to the limitations in Sections 3.5(g) and 3.5(h).

(g) Viewing Data. De-identification of Viewing Data does not retroactively cure a violation of applicable law that occurred at the time of original disclosure. Service Provider shall not retain de-identified Viewing Data in any form linked to device-level identifiers for more than one (1) year from the date the underlying information is no longer necessary for the purpose for which it was collected.

(h) Third-Party Distribution Platform Restrictions. Service Provider's rights under this Section 3.5 and Section 3.8 to de-identify, aggregate, create audience segments from, or train Service Provider Models on Personal Information are subject to, and shall not exceed, the data-use restrictions in Customer's agreements with the third-party distribution platforms from which the applicable inventory or data originates, in each case to the extent Customer has notified Service Provider in writing of those restrictions. Where such a distribution platform prohibits the creation of audience segments, look-alike models, user profiles, or device graphs, or the combination of its data with other data, Service Provider shall not exercise the rights in this Section 3.5 or Section 3.8 with respect to data originating from that platform's inventory, and such data shall be excluded from Service Provider Models and audience segments.

3.6 Data Retention. The following applies to retention:

3.6.1 Service Provider shall retain Personal Information only for as long as reasonably necessary to fulfill the Business Purposes specified in the Agreement, unless a longer retention period is required or permitted by law.

3.6.2 Service Provider shall establish and maintain documented retention schedules for different categories of Personal Information based on the Business Purposes for which such information is processed.

3.6.3 Upon expiration of the applicable retention period, Service Provider shall either securely delete the Personal Information or convert it to De-Identified Information or Aggregated Information in accordance with Section 3.5.

3.6.4 Retention Backstop. Notwithstanding Section 3.6.1, Service Provider shall, within eighteen (18) months after Personal Information is no longer necessary for the Business Purposes, either securely delete such Personal Information or convert it to De-Identified Information or Aggregated Information in accordance with Section 3.5, except where a longer retention period is required or permitted by law. For the avoidance of doubt, this Section 3.6.4 applies only to Personal Information and does not apply to De-Identified Information, Aggregated Information, or Service Provider Models, which are governed by Section 3.5, nor to Viewing Data, which remains subject to the one-year limitation in Section 3.8(c).

3.7 Service Provider Status Under CCPA. To the extent the California Consumer Privacy Act, as amended by the California Privacy Rights Act ("CCPA"), applies:

(a) Service Provider acknowledges and agrees that it is receiving Personal Information from Customer as a "service provider" as defined in Cal. Civ. Code § 1798.140(ag);

(b) Subject to Section 3.7(d), Service Provider shall not: (i) sell or share Personal Information as those terms are defined in the CCPA; (ii) retain, use, or disclose Personal Information for any purpose other than the Business Purposes specified in this DPA or as otherwise permitted by the CCPA; (iii) retain, use, or disclose Personal Information outside of the direct business relationship between Service Provider and Customer; or (iv) combine Personal Information received from Customer with personal information received from another source, except as permitted by Cal. Civ. Code § 1798.140(ag)(2)(D) for service provider purposes;

(c) Service Provider certifies that it understands the restrictions in this Section 3.7 and will comply with them; and

(d) Real-Time Bidding Data Flows. When Service Provider facilitates real-time bidding or programmatic advertising on behalf of Publishers: (i) Service Provider may transmit Personal Information to Buyers in bid requests as necessary to facilitate ad auctions and delivery, subject to the restrictions in Section 3.8(f); (ii) such transmission constitutes a disclosure of Personal Information on behalf of Publisher, and Publisher is responsible for providing appropriate notice to users and ensuring a valid legal basis (including opt-out mechanisms where required by CCPA or other applicable Privacy and Data Protection Laws) for such disclosure; (iii) Service Provider's role in facilitating such transmission is as a service provider to Publisher, and Service Provider does not independently determine the purposes of such data sharing; (iv) with respect to Elemental TV audience segments used for targeting, (A) segments that meet the definition of De-Identified Information under Section 3.5 are not Personal Information when transmitted to Buyers, and (B) transmission of device-level identifiers alongside such segments remains subject to CCPA opt-out requirements and applicable video-privacy restrictions; (v) Service Provider makes no representation that bid request transmissions constitute a "non-sale" under CCPA, the characterization of such transmissions depends on the specific facts and circumstances of each Publisher's data collection, notice, and consent practices, and Publisher is solely responsible for determining whether its programmatic advertising activities constitute a "sale" or "sharing" under CCPA and for honoring applicable opt-out requests; and (vi) for programmatic transactions subject to U.S. state privacy laws, Elemental TV is a signatory to the IAB Multi-State Privacy Agreement (MSPA) as a Downstream Participant, and, where Customer is also an MSPA signatory, the parties rely on the MSPA and associated IAB privacy-signaling specifications to govern the transmission of privacy signals and their respective roles and obligations for such transactions.

3.8 Video Content Data. The following applies to video content data:

(a) Scope. This Section 3.8 applies to Personal Information associated with video content viewing activity processed through the Services ("Viewing Data").

(b) Permitted Processing. Elemental TV may process Viewing Data, including content metadata (such as program titles, episode information, genre, network, and content ratings), and other Personal Information for the purposes of: (i) creating and activating audience segments based on viewing behavior, content preferences, and programming affinity; (ii) enabling content-level targeting, including but not limited to live sports, specific programming, and genre-based targeting; (iii) providing audience intelligence and analytics to Customers and authorized partners; (iv) measurement, attribution, and reporting; and (v) such other purposes as set forth in the Agreement. The processing described in this Section 3.8(b) is subject to the Third-Party Distribution Platform Restrictions set out in Section 3.5(h).

(c) Data Retention. Elemental TV shall destroy Personal Information relating to video content viewing activity within one (1) year of the date the information is no longer necessary for the purpose for which it was collected, as required by applicable law.

(d) Customer Compliance Obligations. Customer represents and warrants that: (i) Customer has obtained all necessary consents, authorizations, and legal bases required under applicable law, including all applicable video-privacy and data-protection laws, to permit Elemental TV to process Viewing Data as contemplated by this Agreement; (ii) Customer's privacy policy accurately discloses the collection and sharing of video viewing data with third parties for advertising and analytics purposes; and (iii) Customer shall promptly notify Elemental TV of any consumer opt-out requests or legal restrictions that would limit processing of Viewing Data.

(e) Indemnification. Customer's indemnification obligations in respect of Viewing Data are set out in Section 15.1(e), and no separate or additional indemnity arises under this Section 3.8(e).

(f) Limitation. Elemental TV shall not knowingly disclose to any third party the title, description, or subject matter of any specific video content viewed by a specifically identified individual (that is, identified by name, address, or other directly identifying information), except as required by law or as expressly authorized by such individual.

(g) Service Provider Cooperation. Service Provider will reasonably cooperate with Customer in meeting Customer's obligations under applicable video-privacy laws, including by (i) honoring and giving downstream effect to opt-out, consent, and limitation signals communicated to Service Provider by Customer in a commercially reasonable format, (ii) not knowingly processing Viewing Data in a manner contrary to any opt-out or restriction of which Customer has informed Service Provider, and (iii) providing information reasonably necessary for Customer to respond to a Data Subject request or regulatory inquiry relating to Viewing Data. This Section 3.8(g) does not shift to Service Provider the consent, notice, and legal-basis obligations that remain with Customer under Section 3.8(d).

4. Service Provider's Employees

4.1 Access Limitation. The Service Provider will limit Personal Information access to those employees who require Personal Information access to meet the Service Provider's obligations under this DPA and the Agreement.

4.2 Employee Obligations. The Service Provider will ensure that all employees (a) are informed of the Personal Information's confidential nature and use restrictions and are obliged to keep the Personal Information confidential, and (b) are aware of both the Service Provider's duties and their personal duties and obligations under the Privacy and Data Protection Laws and this DPA.

5. Security

5.1 Technical and Organizational Measures. The Service Provider will maintain appropriate technical and organizational measures designed to safeguard Personal Information against unauthorized or unlawful processing, access, copying, modification, storage, reproduction, display, or distribution, and against accidental loss, destruction, unavailability, or damage.

5.2 Security Practices. Service Provider's security measures include, but are not limited to: encryption of Personal Information in transit and at rest, multi-factor authentication for employee access, regular security assessments and penetration testing, and incident response procedures. A more detailed description of Service Provider's security practices is available upon request at [email protected].

6. Security Breaches and Personal Information Loss

6.1 Loss Notification. The Service Provider will promptly notify the Customer if any Personal Information is lost or destroyed or becomes damaged, corrupted, or unusable.

6.2 Breach Notification. The Service Provider will promptly notify the Customer if it becomes aware of (a) any unauthorized or unlawful processing of the Personal Information, or (b) any Security Breach. Such notification shall be in writing and include, to the extent known: (i) a description of the nature of the incident; (ii) the categories of Personal Information affected; and (iii) measures taken or proposed to address the incident.

6.3 Cooperation. Immediately following any unauthorized or unlawful Personal Information processing or Security Breach, the parties will coordinate with each other to investigate the matter. The Service Provider will reasonably cooperate with the Customer in the Customer's handling of the matter, including (a) assisting with any investigation, (b) facilitating interviews with the Service Provider's employees, former employees, and others involved in the matter, and (c) making available all relevant records, logs, files, data reporting, and other materials required to comply with all Privacy and Data Protection Laws.

6.4 No Third-Party Notification. The Service Provider will not inform any third party of a Security Breach without first obtaining the Customer's prior written consent, except when law or regulation requires it.

7. Cross-Border Transfers of Personal Information

7.1 Transfer Conditions. If the Privacy and Data Protection Laws restrict cross-border Personal Information transfers, the Customer will only transfer that Personal Information to the Service Provider under the following conditions: (a) the Service Provider, either through its location or participation in a valid cross-border transfer mechanism under the Privacy and Data Protection Laws, may legally receive that Personal Information, provided that the Service Provider must immediately inform the Customer of any change to that status; (b) the Customer obtained valid Data Subject consent to the transfer under the Privacy and Data Protection Laws; or (c) the transfer otherwise complies with the Privacy and Data Protection Laws.

7.2 Transfer Mechanisms. The following transfer mechanisms apply:

(a) International Data Transfer Mechanisms. Where Personal Information originating in the European Economic Area, the United Kingdom, or Switzerland is transferred to the Service Provider or its subcontractors in a country that has not received an adequacy decision, the parties incorporate by reference and agree to comply with (i) the Standard Contractual Clauses approved by the European Commission in Implementing Decision (EU) 2021/914 (the "EU SCCs"), (ii) the UK International Data Transfer Addendum to the EU SCCs issued by the UK Information Commissioner (the "UK Addendum"), and (iii) for transfers subject to Swiss law, the EU SCCs as adapted under guidance of the Swiss Federal Data Protection and Information Commissioner. For the EU SCCs, Module One (Controller to Controller) applies to restricted transfers of Personal Information for which Elemental TV and the Customer or a Buyer each act as an independent controller under Sections 2.4 and 2.5, Module Two (Controller to Processor) applies where the Customer is a controller and the Service Provider a processor, and Module Three (Processor to Processor) applies where the Customer acts as a processor; the optional docking clause applies; the audit and subprocessor options are governed by Sections 8 and 12 of this DPA; the governing law and forum are those of the Republic of Ireland (or, for the UK Addendum, the courts of England and Wales); and the information required by the Annexes is set out in Schedule 1 (International Data Transfer Details). In the event of any conflict between the SCCs and this DPA with respect to a restricted transfer, the SCCs prevail.

(b) Comparable Protection; Onward Accountability. For any restricted transfer not covered by the Standard Contractual Clauses above, Service Provider undertakes, regardless of the jurisdiction of origin, to (i) maintain protections materially equivalent to those required by the Privacy and Data Protection Laws of the originating jurisdiction, (ii) impose those protections on its subprocessors by written contract, and (iii) provide breach notification and Data Subject-rights assistance in accordance with this DPA. This undertaking is intended to satisfy the accountability and comparable-protection standards of, without limitation, PIPEDA (Canada), APP 8 of the Privacy Act 1988 (Australia), and IPP 12 of the Privacy Act 2020 (New Zealand).

(c) Quebec (Law 25). For Personal Information communicated outside the Province of Quebec, Customer represents that it has, where required, completed a privacy impact assessment under Section 17 of Law 25, and the parties agree that the safeguards in this DPA reflect the mitigation measures identified in any such assessment.

(d) Mexico (LFPDPPP). For Personal Information originating in Mexico, Service Provider (as encargado or transferee, as applicable) assumes the same obligations as the transferring party with respect to such Personal Information, and Customer represents that its privacy notice (aviso de privacidad) discloses the transfer and destination and that any consent required under the LFPDPPP has been obtained.

8. Subcontractors

8.1 Written Contract. The Service Provider may only authorize a third party (subcontractor) to process the Personal Information if the Service Provider enters into a written contract with the subcontractor that contains terms substantially the same as those set out in this DPA.

8.2 Subcontractor Audit. Upon the Customer's written request, the Service Provider will audit a subcontractor's compliance with its obligations regarding the Customer's Personal Information and provide the Customer with the audit results.

8.3 Deletion Cascade. Upon receiving a deletion directive from Customer under Section 3.2, Service Provider shall promptly notify all subprocessors processing the relevant Personal Information and ensure deletion cascades through the entire processing chain within the timeframes specified in Section 3.2.

8.4 Subprocessor List. Service Provider maintains a current list of subprocessors and will provide such list upon written request to [email protected]. Service Provider will notify Customer of any material changes to its subprocessors at least thirty (30) days in advance. "Material changes" include the addition of new subprocessors or changes to existing subprocessors that expand the categories of Personal Information processed or the purposes of processing. Changes to infrastructure providers or service regions that do not affect data processing purposes are not considered material.

9. Complaints, Data Subject Requests, and Third Party Rights

9.1 Complaints. The Service Provider must promptly notify the Customer if it receives any complaint, notice, or communication that directly or indirectly relates to the Personal Information processing or to either party's compliance with the Privacy and Data Protection Laws.

9.2 Data Subject Requests. The Service Provider must promptly notify the Customer if it receives a request from a Data Subject to exercise any rights the individual may have regarding their Personal Information, such as access, correction, deletion, or to opt-out of or limit certain activities like sales, disclosures, or other processing actions.

9.3 Assistance. The Service Provider will cooperate and assist the Customer in responding to any complaint, notice, communication, or Data Subject request within timeframes that enable Customer to meet its obligations under applicable Privacy and Data Protection Laws.

9.4 No Disclosure. The Service Provider must not disclose the Personal Information to any Data Subject or to a third party unless the disclosure is either at the Customer's request or instruction, permitted by this DPA, or is otherwise required by law.

10. Term and Termination

This DPA will remain in full force and effect so long as (a) the Agreement remains in effect, or (b) the Service Provider retains any Personal Information related to the Agreement in its possession or control (the "Term").

11. Data Return and Destruction

11.1 Return or Destruction. On termination of the Agreement for any reason or expiration of its term, Customer may request return of Personal Information within thirty (30) days of termination. Following the retrieval period (or immediately upon termination if no return is requested), the Service Provider will securely destroy and not retain all Personal Information related to this DPA in its possession or control.

11.2 Required Retention. If any law, regulation, or government or regulatory body requires the Service Provider to retain any documents or materials that the Service Provider would otherwise be required to return or destroy, it will notify the Customer in writing of that retention requirement, giving details of the documents or materials that it must retain, the legal basis for retention, and establishing a specific timeline for destruction once the retention requirement ends. The Service Provider may only use this retained Personal Information for the required retention reason or audit purposes.

11.3 De-Identified Information. Upon termination, Service Provider may retain De-Identified Information and Aggregated Information in accordance with Section 3.5, and may continue to use and improve Service Provider Models trained on such data.

12. Audit

Service Provider maintains information security management practices consistent with ISO 27001 or equivalent standards. Upon written request, Service Provider will provide Customer with relevant certifications, audit summaries, or security documentation demonstrating compliance with this DPA. Customer may conduct or commission an independent inspection of Service Provider's data processing facilities and practices once per calendar year, upon thirty (30) days advance written notice. Any such inspection shall be limited to Service Provider's data protection and information security controls relevant to the processing of Customer's Personal Information, and shall not extend to Service Provider's platform technology, source code, commercial terms, or the records or data of other Service Provider counterparties. Customer shall bear the costs of any such inspection. Customer will treat all audit reports and security documentation as Service Provider's confidential information.

13. Notice

Any notice or other communication given to a party under or in connection with this DPA must be in writing and delivered to the designated contact on the cover page of the Agreement.

14. Amendments

14.1 Amendments. The following applies to amendments:

(a) Material Amendments. Material modifications to this DPA require Customer's prior written consent, which may be provided via email, electronic signature, or other documented acceptance. "Material modifications" include changes that: (i) expand Service Provider's rights to process, retain, or disclose Personal Information; (ii) reduce Customer's rights or protections under this DPA; (iii) modify indemnification or liability provisions; or (iv) alter the scope of permitted Business Purposes.

(b) Non-Material Amendments. Service Provider may amend non-material provisions by posting updated terms at https://www.elementaltv.com/data-processing-agreement and providing at least thirty (30) days advance notice to Customer via email to the contact designated in the Agreement. Non-material amendments include: corrections of typographical errors; formatting changes; updates to contact information or URLs; clarifications that do not expand Service Provider's rights or reduce Customer's protections; and addition of examples or illustrations of existing provisions.

(c) Regulatory Amendments. Changes required to comply with Privacy and Data Protection Laws may be implemented with shorter notice or immediately where legally required, with notice provided to Customer as soon as practicable. If the regulatory amendment materially and adversely affects Customer's rights, the parties shall negotiate in good faith an alternative that achieves compliance with the applicable Privacy and Data Protection Laws with the least adverse effect on Customer, and only the changes legally required to achieve compliance shall apply to Customer.

(d) Objection Rights. For any amendment under Section 14.1(b), Customer may object in writing within the notice period. If Customer objects, the parties shall negotiate in good faith to resolve the objection. If the parties cannot reach agreement within thirty (30) days, the amendment shall not apply to Customer and the prior version of this DPA shall continue in effect as between the parties.

15. Indemnification

15.1 Customer Indemnification. Customer shall indemnify, defend, and hold harmless Service Provider, its affiliates, and their respective officers, directors, employees, and agents from and against any and all claims, damages, losses, liabilities, costs, and expenses (including reasonable attorneys' fees) arising from or related to:

(a) Customer's failure to provide required notices or obtain required consents under applicable Privacy and Data Protection Laws;

(b) Customer's breach of Section 2.1 (Customer Responsibility);

(c) Any claim that Personal Information provided by Customer to Service Provider infringes or violates any third party's rights, including intellectual property rights, privacy rights, or contractual rights;

(d) Customer's violation of applicable laws in the collection, use, or disclosure of Personal Information prior to providing it to Service Provider; or

(e) Customer's failure to obtain the consents, authorizations, and legal bases required by Section 3.8(d) with respect to Viewing Data.

15.2 Service Provider Indemnification. Service Provider shall indemnify, defend, and hold harmless Customer from any claims arising from Service Provider's breach of its obligations under Sections 3.1, 3.2, 3.3, or 3.7 (CCPA service provider restrictions), except to the extent such claim results from Customer's breach of this DPA or failure to comply with applicable Privacy and Data Protection Laws.

15.3 Data Provider Indemnification. Data Providers without a governing commercial agreement shall indemnify, defend, and hold harmless Service Provider pursuant to the same terms set forth in Section 15.1, mutatis mutandis.

16. Limitation of Liability

16.1 Precedence Where an Agreement Exists. Where the Customer has entered into an Agreement or Insertion Order with Service Provider, the limitation-of-liability provisions of that Agreement, including all exclusions, carve-outs, caps, and super-caps, govern all liability arising from or related to this DPA, and Sections 16.2, 16.3 and 16.4 do not apply. Sections 16.2 through 16.4 apply only where the Customer has no such Agreement.

16.2 General Limitation. Except as provided in Section 16.3, Service Provider's total liability arising from or related to this DPA shall not exceed the aggregate Gross Revenue actually collected by Service Provider in respect of Customer's inventory or services during the six (6) months immediately preceding the event giving rise to the claim.

16.3 Carve-Outs. The limitation in Section 16.2 shall not apply to: (a) either party's indemnification obligations under Section 15; (b) Service Provider's breach of confidentiality obligations under Section 3.3; (c) either party's gross negligence or willful misconduct; or (d) either party's infringement of the other party's intellectual property rights.

16.4 Super-Cap on Carve-Outs. Notwithstanding Section 16.3, each party's entire liability arising from such party's indemnification obligations under Section 15, or breach of confidentiality obligations under Section 3.3, shall not exceed Five Hundred Thousand Dollars ($500,000) in the aggregate. This limitation shall not apply to liability arising from gross negligence, willful misconduct, or intellectual property infringement.


 

Schedule 1: International Data Transfer Details (Standard Contractual Clauses)

A. List of Parties. Data exporter: the Customer identified in the Agreement or Insertion Order (role: controller or processor, as applicable). Data importer: Elemental TV LLC (Service Provider), acting as processor or subprocessor providing the ad-serving, real-time bidding, targeting, measurement, and reporting Services described in the Agreement. Data importer contact: [email protected].

B. Description of Transfer. The categories of data subjects, categories of Personal Information, and the nature and purpose of processing are as set out in Schedule 2 (Details of Processing), which is controlling. Frequency of transfer: continuous, for the duration of the Services. Special categories of Personal Information and sensitive personal information volunteered by or collected directly from data subjects are not intended to be processed. The Services may create or use inferred or modeled audience attributes associated with devices or households, including attributes that may be treated as sensitive under applicable law; such attributes are processed only where and as permitted by applicable law and subject to the safeguards of this DPA. Retention is as set out in Sections 3.6 and 11 of this DPA and Section 3.6.4.

C. Competent Supervisory Authority. For EU transfers, the supervisory authority of the EU member state in which the Customer (or its EU representative) is established and, absent such establishment, the Irish Data Protection Commission. For UK transfers, the UK Information Commissioner's Office.

D. Technical and Organizational Measures. The security measures set out in Section 5 of this DPA, including encryption of Personal Information in transit and at rest, access controls, and an information-security program consistent with ISO 27001 or equivalent standards, apply as the technical and organizational measures for purposes of the SCCs.


 

Schedule 2: Details of Processing

This Schedule sets out the details of processing required under applicable Privacy and Data Protection Laws (including Article 28(3) of the EU and UK GDPR) and also serves as the description of transfer for the Annexes to the Standard Contractual Clauses referenced in Schedule 1.

A. Categories of Data Subjects. End users, viewers, and visitors of Customer's FAST channels, AVOD content, applications, websites, and connected-television inventory.

B. Categories of Personal Information. Online and device identifiers (including cookie IDs, mobile advertising IDs, and connected-television device advertising identifiers); IP address; approximate (non-precise) geolocation; browser, device, operating-system, and connection data; content and video viewing activity and related metadata; and ad-interaction, measurement, and attribution data. Special categories of Personal Information and sensitive personal information volunteered by or collected directly from data subjects are not intended to be processed. The Services may create or use inferred or modeled audience attributes associated with devices or households, including attributes that may be treated as sensitive under applicable law; such attributes are processed only where and as permitted by applicable law and subject to the safeguards of this DPA.

C. Nature and Purpose of Processing. Ad serving, real-time bidding, programmatic and direct ad sales, audience targeting and segmentation, frequency capping, measurement, attribution, reporting, and the creation of De-Identified Information, Aggregated Information, and Service Provider Models (including market intelligence and benchmarks derived solely from De-Identified Information or Aggregated Information), in each case as described in this DPA and the Agreement.

D. Duration of Processing. For the Term of the Agreement and thereafter only as permitted under Sections 3.6 and 11 of this DPA, subject to the retention backstop in Section 3.6.4.

E. Recipients / Subprocessors. Service Provider's affiliates and the subprocessors maintained under Section 8; a current list is available on request to [email protected].

F. Retention. As set out in Section 3.6 (including the eighteen (18) month backstop in Section 3.6.4) and, for Viewing Data, Section 3.8(c).