After the body tag (Desktop)

Data Protection Addendum


Last Updated 04/13/2026

This Data Protection Addendum (“DPA”) is entered into by and between MV Digital Group LLC (“Company”) and the customer identified on the applicable order form (“Customer”). This DPA forms part of and is incorporated into the Terms of Use, order form(s), or other governing agreement between the parties (the “Agreement”). Capitalized terms not defined in this DPA have the meanings set forth in the Agreement. In the event of conflict between this DPA and the Agreement, this DPA controls. 

  1. Definitions
    1. “Applicable Privacy Laws” means all applicable U.S. federal, state, and local privacy, data protection, and data security laws, rules, and regulations, including without limitation the California Consumer Privacy Act (“CCPA”), and other comprehensive state privacy laws, as amended and applicable, as well as all applicable industry self-regulatory principles.
    2. “Audience Segments” means Company’s marketing and advertising segments and related outputs made available to Customer under the Agreement, including associated attributes, scores, and inferences.
    3. “Automated Decisionmaking” and “Automated Decisionmaking Technology” have the meanings assigned to such terms under Applicable Privacy Laws.
    4. “Business Purpose(s),” “Business,” “Commercial Purpose(s),” “Consumer(s),” “Controller,” “Contractor,” “Cross-context Behavioral Advertising,” “Person(s),” “Processor,” “Profiling,” “Sale” (including “Sell”), “Service Provider,” “Share,” and “Targeted Advertising” have the meanings assigned under Applicable Privacy Laws.
    5. “Deidentified Data” means data that cannot reasonably be used to infer information about, or otherwise be linked to, a particular consumer, household, or device, and that qualifies as “deidentified” (or equivalent) under Applicable Privacy Laws. Pseudonymous data is not Deidentified Data.
    6. “Personal Data” means any information made available by Company to Customer that constitutes “personal information,” “personal data,” or a similar term under Applicable Privacy Laws. For the avoidance of doubt, Personal Data includes the Audience Segments, as well as Sensitive Personal Data, including any categories of sensitive personal data as defined under the DOJ Rule Terms.
    7. “Privacy Signal” means end users’ privacy preferences regarding the processing of Personal Information, including without limitation, a signal indicating that a Consumer and/or Data Subject, as such terms are defined by Applicable Law, has: (i) opted out of the Sale, Share, Processing of their Personal Data for purposes of Targeted Advertising, and/or Cross-context Behavioral Advertising; (ii) opted out of Profiling, as such term is defined by Applicable Law; (iii) opted out of Automated Decisionmaking, as such term is defined by Applicable Law; and/or (iv) submitted a request for, access, correction, and/or deletion
    8. “Security Incident” means any actual or reasonably suspected (a) unauthorized access to, acquisition of, disclosure of, or use of Personal Data; (b) compromise of the confidentiality, integrity, or availability of Personal Data in Customer’s possession or control; or (c) breach of Customer’s security resulting in the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to Personal Data. Security Incident excludes unsuccessful attempts that do not result in unauthorized access.
    9. “DOJ Rule Terms” means Executive Order 14117 and the regulations promulgated thereunder by the U.S. Department of Justice, codified at 28 C.F.R. Part 202, as amended from time to time, including the definitions of “Countries of Concern,” “Covered Data Transactions,” “Restricted Person,” “Prohibited Person,” and any other defined terms set forth therein.
    10. “PADFAA” means the Protecting Americans’ Data from Foreign Adversaries Act.
  2. Roles
    1. Company is a “Business” under CCPA and a Controller under other Applicable Privacy Laws.
    2. Customer is a “Third Party” under CCPA and an independent Controller under other Applicable Privacy Laws.
  3. Limited and Specified Purpose
    1. The limited and specified purpose(s) for which Company makes Personal Data available to Customer, and the categories of Personal Data disclosed, are set forth in Exhibit A (Processing Details), which is incorporated herein.
    2. Company makes Personal Data available only for the limited and specified purpose(s) set forth in Exhibit A, and Customer shall process Personal Data only for such purpose(s).
    3. Customer shall not retain, use, or disclose Personal Data outside the direct business relationship between the parties.
    4. Customer shall not reidentify Deidentified Data or attempt to link Deidentified Data to a consumer, household, or device.
  4. Data Minimization and Use Restrictions
        Customer shall
    1. Use Personal Data solely for the Exhibit A purpose(s).
    2. Not combine Personal Data with other datasets for unrelated profiling or commercialization.
    3. Not license or resell the Personal Data, or create derivative segments of Personal Data for resale or onward commercialization.
    4. Not benchmark, reverse engineer, decompile, disassemble, reconstruct, or otherwise derive Company datasets or methodologies.
    5. Retain Personal Data only as reasonably necessary for the Exhibit A purpose(s).
    6. Apply suppression files and deletion lists provided by Company, as applicable.
    7. Not circumvent Privacy Signals, opt-outs, or statutory restrictions.
    8. Maintain reasonable internal access controls and safeguards.
    9. Not use Personal Data (or enable such Personal Data to be used) for the preparation of a Consumer Report (as such term is defined in the Fair Credit Reporting Act, or “FCRA”), including, without limitation, for any purpose enumerated in Section 1681b(a)(3) of FCRA.
  5. Compliance and Regulatory Obligations
    1. Customer Obligations
      1. Customer shall
        1. comply with Applicable Privacy Laws in its processing of Personal Data, including but not limited to, ensuring it has provided legally sufficient consumer notice and choice mechanisms;
        2. provide the same level of privacy protection required of businesses under Applicable Privacy Laws and its implementing regulations with respect to Personal Data made available by Company;
        3. honor Privacy Signals and applicable consumer rights requests communicated via Company and/or within its role as an independent Controller, including the right to correct, delete, and access/know Personal Data, where required by Applicable Privacy Laws; and
        4. notify Company promptly if Customer determines that it can no longer meet its obligations under Applicable Privacy Laws or this DPA with respect to Personal Data made available by Company.
    2. Company Overs
      1. With respect to Personal Data made available under the Agreement, Company retains the right to take reasonable and appropriate steps to ensure that Customer uses such Personal Data in a manner consistent with Company’s obligations under Applicable Privacy Laws. Without limiting the foregoing, Company may:
        1. require written certifications, attestations, or other documentation reasonably necessary to demonstrate Customer’s compliance with this DPA;
        2. request annual compliance certifications confirming that Customer is processing Personal Data in accordance with the limited and specified purpose(s) set forth in Attachment A and this DPA;
        3. upon reasonable notice and during normal business hours, conduct reasonable audits or assessments of Customer’s compliance, not more than annually absent reasonable suspicion of material noncompliance, subject to appropriate confidentiality safeguards;
        4. take reasonable and appropriate steps, upon notice, to stop and remediate any unauthorized use or disclosure of Personal Data, including requiring Customer to provide documentation verifying that it has ceased retention, use, or disclosure inconsistent with this DPA;
        5. suspend further disclosures of Personal Data if Company reasonably determines that Customer is in material breach of this DPA; and
        6. terminate the Agreement upon reasonable written notice if material noncompliance is not cured within a commercially reasonable cure period, unless the breach is incapable of cure.
  6. AI and Automated Decisionmaking
    1. Customer shall not use Personal Data or derived segments for artificial intelligence or machine learning training, development, fine-tuning, or model improvement without Company’s prior written authorization.
    2. Customer shall not use Personal Data to engage in Automated Decisionmaking without prior written authorization.
  7. Security Measures
    1. Customer shall implement and maintain administrative, technical, and organizational safeguards appropriate to the nature and volume of Personal Data, including at a mini
      1. Encryption in transit using TLS 1.2+ / HTTPS;
      2. Encryption at rest using AES-256 or an industry-equivalent standard;
      3. Role-based access controls;
      4. Multi-factor authentication for systems containing Personal Data;
      5. Protections against malicious code and unauthorized system access;
      6. Vulnerability management and patching practices consistent with industry standards.
  8. Security Incidents
    1. Customer shall notify Company without undue delay upon becoming aware of a Security Incident.
    2. Customer shall cooperate in investigation, mitigation, and legally required notification.
    3. Customer is responsible for costs and liabilities arising from incidents attributable to its breach or failure to maintain reasonable safeguards.
  9. Subprocessors
    1. Customer shall not disclose or make Personal Data available to any affiliate, contractor, service provider, or other third party (each, a “Subprocessor”) unless (i) such disclosure is necessary for the limited and specified purpose(s) set forth in Attachment A, and (ii) Customer has entered into a written agreement with the Subprocessor that imposes data protection, confidentiality, security, use restriction, and retention obligations no less protective than those set forth in this DPA. Customer shall remain fully liable for the acts and omissions of its Subprocessors relating to the processing of Personal Data and shall be responsible for ensuring their compliance with the terms of this DPA.
  10. Cross-Border Transfers
    1. Customer shall not, without Company’s prior written authorization and including through its affiliates, subprocessors, contractors, or technical infrastructure, transfer, store, or process Personal Data outside of the United States or otherwise make Personal Data accessible from outside of the United States. In the event that Company authorizes any such cross-border transfer, Customer shall enter into a data processing agreement with any applicable receiving party that incorporates restrictions regarding Personal Data that are substantially similar to those contained within this DPA.
    2. Customer is expressly prohibited from selling, licensing access to, reselling, sublicensing, leasing, transferring for valuable consideration, data brokerage, or engaging in any similar commercial transaction involving Personal Data, or otherwise making Personal Data available through any vendor agreement, employment arrangement, investment agreement or infrastructure access, directly or indirectly, to any country, government, entity, or individual designated or classified as: (i) a country of concern or covered person under the DOJ Rule Terms; (ii) a foreign adversary country or an entity controlled by a foreign adversary PADFAA; or (iii) falling within any substantially similar category under any other U.S. law or regulation of similar purpose. Customer shall promptly notify Company in writing if it becomes aware of any actual or reasonably suspected access to Personal Data by any such restricted party, including, without limitation, if Customer undergoes a change of control.
    3. Customer represents, warrants, and certifies that it is not a covered person, it is not owned or controlled by a country of concern, covered person, or foreign adversary, and that it is currently, and shall remain for the duration of this Agreement, in full compliance with, as applicable: (i) Executive Order 14117; (ii) the DOJ Rule Terms; (iii) PADFAA; and (iv) any other U.S. law or regulation of similar purpose that restricts access to U.S. personal or sensitive data by foreign adversaries or similarly designated entities or individuals, as such laws or regulations may be amended or implemented from time to time.
  11. Retention and Deletion
    1. Termination or Expiration. Upon termination or expiration of the Agreement for any reason, Customer shall, within thirty (30) days (or such shorter period as Company may reasonably request in writing), permanently and securely delete or return all Personal Data in its possession or control, including Personal Data held by its affiliates and subprocessors, except to the extent retention is required by Applicable Privacy Laws.
    2. Legal Retention Exception. If Customer is required by Applicable Privacy Laws to retain any Personal Data, Customer shall (i) retain such Personal Data solely for the purpose and duration required by law, (ii) continue to protect such Personal Data in accordance with this DPA, (iii) not use or disclose such Personal Data for any other purpose, and (iv) notify Company of such retention.
    3. Certification. Upon Company’s written request, Customer shall provide a written certification, signed by an authorized representative, confirming that deletion or return has been completed in accordance with this Section.
  12. Insurance
    1. Customer shall maintain, during the term of the Agreement, commercially reasonable cybersecurity and professional liability insurance covering data security, privacy liability, and unauthorized use or disclosure of Personal Data, in amounts appropriate to the nature and scale of Customer’s operations. Upon reasonable written request, Customer shall provide a certificate of insurance evidencing such coverage.
  13. Indemnification
    1. Customer shall indemnify, defend, and hold harmless Company, its data suppliers, and its affiliates, and their respective officers, directors, and employees, from and against any third-party claims or governmental enforcement actions, including any resulting damages, settlements, judgments, fines, penalties, and reasonable attorneys’ fees, to the extent arising out of or relating to Customer’s material breach of this DPA, Customer’s violation of Applicable Privacy Laws in connection with its processing of Personal Data, any Security Incident caused by Customer’s failure to implement the safeguards required under this DPA, the DOJ Rule Terms, PADFAA, or other applicable national security restrictions. Customer’s obligations apply only to the extent such claims or liabilities result from Customer’s acts or omissions and are subject to the limitations of liability set forth in the Agreement.
  14. Suspension for Non-Compliance
    1. In the event that Customer breaches or is unable to meet its obligations under this DPA, Company shall have the right to suspend the Agreement without penalty or further payment until such time as Company reasonably believes the non-compliance has been cured.
  15. Conflict of Terms
    1. With regards to any conflicts with this DPA and the Agreement, this DPA shall prevail.
  16. Legal Authority
    1. Each of Customer and Company mutually represent and warrant that: (i) the person executing this DPA on its respective behalf has the legal authority to bind such party, and (ii) it has right, power, and authority to (a) enter into this DPA, (b) make the representations and warranties contained herein, and (c) commit to and perform the respective duties, obligations, and covenants set forth hereunder.
  17. Severability
    1. The invalidity in whole or in part of any provision of this DPA shall not affect the validity of other provisions.

Exhibit A

Processing Details
Purpose of Processing: Audience Segments and Personal Data may be used for ad targeting, analytics, and reporting purposes.

Types of Personal Information Processed: Personal Information processed under this DPA may include, depending on the services and campaign configurations selected by Customer:

  • Pseudonymous identifiers and online or device identifiers (e.g., mobile advertising IDs, IP addresses, and similar persistent identifiers);
  • Direct identifiers (e.g., name, address, email address, and phone number);
  • Internet or electronic network activity information used for audience analytics and the development of audience insights and audience segments;
  • General location information (e.g., city, state, or DMA); and
  • Audience attributes, demographic information, and inferred or modelled interests used for audience segmentation, analytics, and reporting.

Duration of Processing: During the term of the Agreement.

 

One World Trade Center
New York, NY 10007 

Use of and/or registration on any portion of this site constitutes acceptance of our User Agreement (updated 4/29/2024), and acknowledgement of our Privacy Policy, Your Privacy Choices and Rights, and Products Privacy Policy (each updated 1/31/2026).

© 2025 CinqDI
The material on this site may not be reproduced, distributed, transmitted, cached or otherwise used, except with the prior written permission of CinqDI.