a. Compliance with Laws. Within the scope of the Agreement and in its use of the services, the Customer will be responsible for complying with all requirements that apply to it under applicable Data Protection Laws with respect to its Processing of Personal Data and the Instructions it issues to Brij. In particular, but without prejudice to the generality of the foregoing, the Customer acknowledges and agrees that it will be solely responsible for: (i) the accuracy, quality, and legality of Customer Data and the means by which it acquired Personal Data; (ii) complying with all necessary transparency and lawfulness requirements under applicable Data Protection Laws for the collection and use of the Personal Data, including obtaining any necessary consents and authorizations (particularly for use by the Customer for marketing purposes); (iii) ensuring it has the right to transfer, or provide access to, the Personal Data to Brij for Processing in accordance with the terms of the Agreement (including this DPA); (iv) ensuring that its Instructions to Brij regarding the Processing of Personal Data comply with applicable laws, including Data Protection Laws; and (v) complying with all laws (including Data Protection Laws) applicable to any emails or other content created, sent, or managed through the services, including those relating to obtaining consents (where required) to send emails, the content of the emails, and its email deployment practices. The Customer will inform Brij without undue delay if it is not able to comply with its responsibilities under this ‘Compliance with Laws’ section or applicable Data Protection Laws.
b. Controller Instructions. The parties agree that the Agreement (including this DPA), together with the Customer’s use of the services in accordance with the Agreement, constitute the Customer's complete Instructions to Brij in relation to the Processing of Personal Data, so long as the Customer may provide additional instructions during the Subscription Term that are consistent with the Agreement, the nature, and lawful use of the services.
c. Security. The Customer is responsible for independently determining whether the data security provided for in the services adequately meets its obligations under applicable Data Protection Laws. The Customer is also responsible for its secure use of the services, including protecting the security of Personal Data in transit to and from the services (including securely backing up or encrypting any such Personal Data).
d. Signal Notice, Consent, and Ad Platform Terms. With respect to Conversion Data, the Customer (i) instructs Brij to transmit Conversion Data to the Ad Platform Recipients identified in Annex 3 solely for attribution, measurement, and related advertising purposes on the Customer’s behalf; (ii) is responsible, as the Business with respect to its consumers, for the content of its privacy policy and for any notices and consents required of the Customer under applicable Data Protection Laws; and (iii) will expressly accept, and maintain in effect, the applicable data or business-tools terms of each Ad Platform Recipient it enables (including Meta’s Business Tools Terms), including where the Ad Platform requires acceptance directly from the Customer as the advertiser of record, and will not rely on implicit or assumed acceptance. The Customer will not enable Signal for any Restricted Category Product unless the parties have agreed in writing to the additional safeguards required by applicable Data Protection Laws; will identify all Restricted Category Products to Brij in writing and recertify that identification at least annually and upon material catalog changes; will promptly notify Brij if it acquires actual knowledge that consumers registering its products are under 16 years of age; and will not circumvent, disable, or interfere with any consent, opt-out, suppression, or preference-signal mechanism Brij operates, nor attempt to re-identify any hashed identifier contained in Conversion Data.
a. Compliance with Instructions. Brij will only Process Personal Data for the purposes described in this DPA or as otherwise agreed within the scope of the Customer’s lawful Instructions, except where and to the extent otherwise required by applicable law. Brij is not responsible for compliance with any Data Protection Laws applicable to the Customer or its industry that are not generally applicable to Brij.
b. Conflict of Laws. If Brij becomes aware that it cannot Process Personal Data in accordance with the Customer’s Instructions due to a legal requirement under any applicable law, Brij will (i) promptly notify the Customer of that legal requirement to the extent permitted by the applicable law; and (ii) where necessary, cease all Processing (other than merely storing and maintaining the security of the affected Personal Data) until such time as the Customer issues new Instructions with which Brij is able to comply. If this provision is invoked, Brij will not be liable to the Customer under the Agreement for any failure to perform the applicable services until such time as the Customer issues new lawful Instructions with regard to the Processing.
c. Security. Brij will implement and maintain appropriate technical and organizational measures to protect Personal Data from Personal Data Breaches, as described in Annex 2 to this DPA (“Security Measures”). Notwithstanding any provision to the contrary, Brij may modify or update the Security Measures at its discretion provided that such modification or update does not result in a material degradation in the protection offered by the Security Measures.
d. Confidentiality. Brij will ensure that any personnel whom Brij authorizes to Process Personal Data on its behalf is subject to appropriate confidentiality obligations (whether a contractual or statutory duty) with respect to that Personal Data.
e. Personal Data Breaches. Brij will notify the Customer without undue delay after becoming aware of any Personal Data Breach and will provide timely information relating to the Personal Data Breach as it becomes known or reasonably requested by the Customer. At the Customer’s request, Brij will promptly provide the Customer with such reasonable assistance as necessary to enable the Customer to notify relevant Personal Data Breaches to competent authorities and/or affected Data Subjects, if the Customer is required to do so under Data Protection Laws.
f. Deletion or Return of Personal Data. Brij will delete or return all Customer Data, including Personal Data (including copies thereof) Processed pursuant to this DPA, on termination or expiration of the Customer’s use of the services in accordance with the procedures set out in Annex 1. This term will apply except where Brij is required by applicable law to retain some or all of the Customer Data, or where Brij has archived Customer Data on backup systems, which data Brij will securely isolate and protect from any further Processing and delete in accordance with Brij’s deletion practices.
g. Signal Operational Commitments. With respect to Conversion Data, Brij will make available tools and functionality that enable the Customer to: (i) present, on Brij-hosted registration flows configured by the Customer, a notice at collection and an opt-out mechanism covering the transmission of Conversion Data to Ad Platform Recipients, and to suppress transmission of Conversion Data for a consumer who has affirmatively opted out of that transmission; (ii) provide consumers a mechanism to opt out of the Sale or Sharing of their personal information, process opt-out preference signals (including the Global Privacy Control) as valid opt-out requests, and apply suppression logic so that no Conversion Data is transmitted for an opted-out consumer; (iii) hash consumer identifiers using SHA-256 (or a successor standard) prior to transmission and limit unhashed fields to those strictly required by the applicable Ad Platform interface; and (iv) enable Limited Data Use or equivalent restricted-processing designations offered by an Ad Platform. The Customer is solely responsible for configuring, enabling, and maintaining these mechanisms within its data capture flows, and for determining the notices, consents, and opt-out treatments required for its collection and use of Conversion Data. Brij will (v) make available records of consumer consent states, opt-outs, and suppression events sufficient to reflect the operation of the mechanisms described in this Section 3(g).
The services provide the Customer with a number of controls that the Customer can use to retrieve, correct, delete, or restrict Personal Data, which the Customer can use to assist in connection with its obligations under Data Protection Laws, including its obligations relating to responding to requests from Data Subjects to exercise their rights under applicable Data Protection Laws (“Data Subject Requests”).
To the extent that the Customer is unable to independently address a Data Subject Request through the services, then upon the Customer’s written request, Brij will provide reasonable assistance to the Customer to respond to any Data Subject Requests or requests from data protection authorities relating to the Processing of Personal Data under the Agreement. The Customer will reimburse Brij for the commercially reasonable costs arising from this assistance.
If a Data Subject Request or other communication regarding the Processing of Personal Data under the Agreement is made directly to Brij, Brij will promptly inform the Customer and will advise the Data Subject to submit their request to the Customer. The Customer will be solely responsible for responding substantively to any such Data Subject Requests or communications involving Personal Data.
With respect to Conversion Data, upon receiving a verifiable deletion request (directly or from the Customer), Brij will (i) delete the associated registration data from Brij systems within the timeframes required by applicable Data Protection Laws; (ii) cease all future transmission of Conversion Data for that consumer; and (iii) submit deletion requests to each applicable Ad Platform Recipient through the mechanisms such platform provides. The parties acknowledge that Brij cannot itself delete data from an Ad Platform Recipient’s systems, and Brij’s obligation is limited to ceasing transmission and submitting such requests. A Data Subject may also direct requests concerning Conversion Data already received by an Ad Platform Recipient to that recipient under its own privacy policy and consumer-rights process.
The Customer agrees that Brij may engage Sub-Processors to Process Personal Data on the Customer’s behalf. Brij will ensure that any Sub-Processor it engages to Process Personal Data on the Customer’s behalf provides at least the same level of data protection as required by this DPA.
Brij will make available to the Customer a current list of Sub-Processors upon request.
The Customer may object to the engagement of a new Sub-Processor on reasonable grounds relating to the protection of Personal Data within 30 days of being notified. If the Customer does notify Brij of such an objection, the parties will discuss the Customer’s concerns in good faith with a view to achieving a commercially reasonable resolution. If no such resolution can be reached, Brij will, at its discretion, either not appoint the new Sub-Processor or permit the Customer to suspend or terminate the affected services in accordance with the termination provisions of the Agreement without liability to either party (but without prejudice to any fees incurred by the Customer prior to suspension or termination).
Where Brij engages Sub-Processors, Brij will impose data protection terms on the Sub-Processors that provide at least the same level of protection for Personal Data as those in this DPA, to the extent applicable to the nature of the services provided by such Sub-Processors. Brij will remain responsible for each Sub-Processor’s compliance with the obligations of this DPA and for any acts or omissions of such Sub-Processor that cause Brij to breach any of its obligations under this DPA.
For clarity, Ad Platform Recipients are not Sub-Processors and are not subject to the notice, objection, or flow-down provisions of this Section 5; the transmission of Conversion Data to Ad Platform Recipients is governed exclusively by Sections 2(d), 3(g), 9(g), and Annex 3.
The Customer acknowledges and agrees that Brij may access and Process Personal Data on a global basis as necessary to provide the services in accordance with the Agreement, and in particular that Personal Data may be transferred to and Processed by Brij, Inc. in the United States and to other jurisdictions where Brij Affiliates and Sub-Processors have operations. Wherever Personal Data is transferred outside its country of origin, each party will ensure such transfers are made in compliance with the requirements of Data Protection Laws.
Brij will make all information reasonably necessary to demonstrate compliance with this DPA available to the Customer and allow for and contribute to audits, including inspections conducted by the Customer or the Customer’s auditor in order to assess compliance with this DPA, where required by applicable law. The Customer acknowledges and agrees that it will exercise its audit rights under this DPA by instructing Brij to comply with the audit measures described in this ‘Demonstration of Compliance’ section.
a. Scope. This ‘Additional Provisions for European Data’ section will apply only with respect to European Data.
b. Roles of the Parties. When Processing European Data in accordance with the Customer’s Instructions, the parties acknowledge and agree that the Customer is acting as the Controller of European Data (either as the Controller or as a Processor on behalf of another Controller) and Brij is the Processor under the Agreement.
c. Instructions. If Brij believes that the Customer’s Instruction infringes European Data Protection Laws (where applicable), Brij will inform the Customer without delay.
d. Data Protection Impact Assessments and Consultation with Supervisory Authorities. To the extent that the required information is reasonably available to Brij, and the Customer does not otherwise have access to the required information, Brij will provide reasonable assistance to the Customer with any data protection impact assessments and prior consultations with supervisory authorities to the extent required by European Data Protection Laws.
e. Transfer Mechanisms for Data Transfers. Brij will not transfer European Data to any country or recipient not recognized as providing an adequate level of protection for Personal Data (within the meaning of applicable European Data Protection Laws), unless it first takes all such measures as are necessary to ensure the transfer is in compliance with applicable European Data Protection Laws. Such measures may include (without limitation) (i) transferring such data to a recipient that is covered by a suitable framework or other legally adequate transfer mechanism recognized by the relevant authorities or courts as providing an adequate level of protection for Personal Data; (ii) to a recipient that has achieved binding corporate rules authorization in accordance with European Data Protection Laws; or (iii) to a recipient that has executed the Standard Contractual Clauses in each case as adopted or approved in accordance with applicable European Data Protection Laws.
a. Scope. The ‘Additional Provisions for California Personal Information’ section of the DPA will apply only with respect to California Personal Information.
b. Roles of the Parties. When processing California Personal Information in accordance with the Customer’s Instructions, the parties acknowledge and agree that the Customer is a Business and Brij is a Service Provider for the purposes of the CCPA.
c. Responsibilities. Brij certifies that it will Process California Personal Information as a Service Provider strictly for the purpose of performing the services under the Agreement (the “Business Purpose”) or as otherwise permitted by the CCPA, including as described in the ‘Usage Data’ section of Brij’s Privacy Policy. Brij further certifies it (i) will not Sell or Share California Personal Information, except as and to the extent expressly set forth in Section 9(g) (Ad Platform Disclosures) with respect to Conversion Data transmitted to Ad Platform Recipients at the Customer’s direction; (ii) will not Process California Personal Information outside the direct business relationship between the parties, unless required by applicable law; and (iii) will not combine the California Personal Information included in Customer Data with personal information that Brij collects or receives from another source (other than information Brij receives from another source in connection with its obligations as a Service Provider under the Agreement).
d. Compliance. Brij will (i) comply with obligations applicable to it as a Service Provider under the CCPA and (ii) provide California Personal Information with the same level of privacy protection as is required by the CCPA. Brij will notify the Customer if Brij determines that it can no longer meet its obligations as a Service Provider under the CCPA.
e. CCPA Audits. The Customer will have the right to take reasonable and appropriate steps to help ensure that Brij uses California Personal Information in a manner consistent with the Customer’s obligations under the CCPA. Upon notice, the Customer will have the right to take reasonable and appropriate steps in accordance with the Agreement to stop and remediate unauthorized use of California Personal Information.
f. Not a Sale. The parties acknowledge and agree that the disclosure of California Personal Information by the Customer to Brij does not form part of any monetary or other valuable consideration exchanged between the parties.
g. Ad Platform Disclosures. The parties acknowledge that transmitting Conversion Data to an Ad Platform Recipient for cross-context behavioral advertising may constitute a “Sale” or “Share” under the CCPA. With respect to any such transmission: (i) the Customer, as the Business, is responsible for the required disclosures in its privacy policy and for honoring consumer rights directed to it; (ii) Brij will perform the operational commitments in Section 3(g), including notice and consent at the Brij-hosted point of collection, opt-out and Global Privacy Control processing, suppression, hashing, and Limited Data Use designations; (iii) Brij may add additional Ad Platform Recipients from time to time by updating Annex 3, and will use commercially reasonable efforts to make such updates available to the Customer (e.g., via Brij’s Trust Center or upon request); if the Customer does not wish to enable a newly added Ad Platform Recipient for a particular Brand, the Customer may disable that recipient for that Brand through the Services or by written notice to Brij; and (iv) each party will promptly inform the other of any consumer request, regulatory inquiry, or complaint concerning Conversion Data.
a. Amendments. Notwithstanding anything else to the contrary in the Agreement and without prejudice to the ‘Compliance with Instructions’ or ‘Security’ sections of this DPA, Brij reserves the right to make any updates and changes to this DPA, and the terms that apply in the ‘Amendment; No Waiver’ section of the Agreement will apply.
b. Severability. If any individual provisions of this DPA are determined to be invalid or unenforceable, the validity and enforceability of the other provisions of this DPA will not be affected.
c. Limitation of Liability. Each party and each of their Affiliates' liability, taken in aggregate, arising out of or related to this DPA (including any other DPAs between the parties) and the Standard Contractual Clauses, where applicable, whether in contract, tort, or under any other theory of liability, will be subject to the limitations and exclusions of liability set out in the Agreement. For the avoidance of doubt, if Brij, Inc. is not a party to the Agreement, the ‘Limitation of Liability’ section of the Agreement will apply as between the Customer and Brij, Inc., and in such respect, any references to ‘Brij’, ‘we’, ‘us’, or ‘our’ will include both Brij, Inc. and the Brij entity that is a party to the Agreement. In no event will either party's liability be limited with respect to any individual's data protection rights under this DPA (including any other DPAs between the parties and the Standard Contractual Clauses, where applicable) or otherwise.
d. Governing Law. This DPA will be governed by and construed in accordance with the ‘Governing Law’ section of the Agreement, unless required otherwise by Data Protection Laws.
a. Permitted Affiliates. By signing the Agreement, the Customer enters into this DPA (including, where applicable, the Standard Contractual Clauses) on behalf of itself and in the name and on behalf of its Permitted Affiliates. For the purposes of this DPA only, and except where indicated otherwise, the terms “Customer”, “you”, and “your” will include the Customer and such Permitted Affiliates.
b. Authorization. The legal entity agreeing to this DPA as the Customer represents that it is authorized to agree to and enter into this DPA for and on behalf of itself and, as applicable, each of its Permitted Affiliates.
c. Remedies. The parties agree that (i) solely the Customer entity that is the contracting party to the Agreement will exercise any right or seek any remedy any Permitted Affiliate may have under this DPA on behalf of its Affiliates, and (ii) the Customer entity that is the contracting party to the Agreement will exercise any such rights under this DPA not separately for each Permitted Affiliate individually but in a combined manner for itself and all of its Permitted Affiliates together. The Customer entity that is the contracting entity is responsible for coordinating all Instructions, authorizations, and communications with Brij under the DPA and will be entitled to make and receive any communications related to this DPA on behalf of its Permitted Affiliates.
d. Other Rights. The parties agree that the Customer will, when reviewing Brij’s compliance with this DPA pursuant to the ‘Demonstration of Compliance’ section, take all reasonable measures to limit any impact on Brij and its Affiliates by combining several audit requests carried out on behalf of the Customer entity that is the contracting party to the Agreement and all of its Permitted Affiliates in one single audit.
a. Description of Transfer
a. Information Security Policy
b. Access Control
c. Incident Management, Logging, and Monitoring
d. Availability Control
e. Vulnerability Management Program
f. Personnel Management
List of Sub-Processors: Brij engages Sub-Processors to assist with its data processing activities.
As of the Effective Date, Brij’s Sub-Processors include, without limitation, Amazon Web Services, Twilio, PayPal, MongoDB Inc., Google LLC, Zendesk, and Alloy Automation. This list is illustrative and not exhaustive. Brij’s current, complete list of Sub-Processors is available at Brij’s Trust Center and/or upon written request, and will be updated from time to time in accordance with Section 5 above. Updates to this list made in accordance with Section 5 do not require a formal amendment to this DPA.
Ad Platform Recipients (not Sub-Processors; see Sections 5 and 9(g)): Meta Platforms, Inc. (Meta Conversions API); Google LLC (Google Ads offline conversion import / enhanced conversions); TikTok Inc. (TikTok Events API). Each Ad Platform Recipient’s own privacy policy and data-use terms govern its handling of Conversion Data after receipt. Additional Ad Platform Recipients may be added in accordance with Section 9(g).