DATA PROCESSING ADDENDUM

This Data Processing Addendum (“DPA”) is entered into by and between Pipeline360, Inc., a Delaware corporation (“Pipeline360”), and the Company specified below, on behalf of which Pipeline360 is processing Personal Data in connection with services provided under the applicable Master Services Agreement or Media Sales and Delivery Agreement (the “Agreement”) between the Parties. This DPA is incorporated into and forms part of the Agreement. 

THIS DPA is made as of the date last signed between: 

[Name], with a principal place of business at [Address], and its Affiliates (“Company” or “Controller”); and 

Pipeline360, Inc., with a principal place of business at 2345 E Thomas Rd, Ste 100 #955, Phoenix, AZ 85016 (“Pipeline360”).

1. DEFINITIONS

All capitalised terms defined in this DPA have the meanings given here. Capitalised terms not defined here have the meanings given in the Agreement or applicable Data Protection Law.

  • “Affiliate” means any entity that directly or indirectly controls, is controlled by, or is under common control with another entity through majority ownership.
  • “Agreement” means this DPA and all agreements between Pipeline360 and Company, including any statements of work or orders entered pursuant to them.
  • “Approved Consent Language” means the consent language reviewed and approved by the Controller prior to deployment by a Strategic Data Partner in connection with a Campaign.
  • “Campaign” means a lead generation campaign operated by a Strategic Data Partner on behalf of the Controller, in connection with which Pipeline360 processes Personal Data under this DPA.
  • “CCPA” means the California Consumer Privacy Act of 2018, as amended by the California Privacy Rights Act (Cal. Civ. Code §§ 1798.100–1798.199), and all regulations adopted under it.
  • “Controller” means the entity which, alone or jointly with others, determines the purposes and means of the Processing of Personal Data. “Controller” also encompasses the term “business” as used in the CCPA.
  • “Data Breach” means a breach of security leading to accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, Personal Data transmitted, stored, or otherwise processed.
  • “Data Exporter” means the Controller.
  • “Data Importer” means Pipeline360.
  • “Data Privacy Framework” (“DPF”) means the EU-U.S. Data Privacy Framework, the UK Extension to the EU-U.S. Data Privacy Framework, and the Swiss-U.S. Data Privacy Framework self-certification programs operated by the U.S. Department of Commerce.
  • “Data Privacy Principles” means the Data Privacy Framework Principles as supplemented by the Supplemental Principles.
  • “Data Protection Law” means any and all data protection laws and regulations applicable to the Processing of Personal Data by either Party, or their respective subprocessors, under this DPA, including without limitation EU GDPR, UK GDPR, the Swiss Federal Act on Data Protection, and the CCPA.
  • “Data Subject” means an identified or identifiable natural person who can be identified, directly or indirectly, by reference to an identifier such as a name, identification number, location data, online identifier, or factors specific to the physical, physiological, genetic, mental, economic, cultural, or social identity of that person.
  • “EEA” means the European Economic Area.
  • “EU SCCs” means the Standard Contractual Clauses adopted by Commission Implementing Decision (EU) 2021/915 of 4 June 2021, as updated from time to time.
  • “GDPR” means collectively EU General Data Protection Regulation 2016/679 and the United Kingdom General Data Protection Regulation.
  • “Personal Data” means any information that identifies, describes, relates to, or can be linked, directly or indirectly, to a Data Subject, or is otherwise deemed “personal data” or “personal information” under applicable Data Protection Law.
  • “Platform” means the software applications, tools, APIs, connectors, programs, networks, and equipment Pipeline360 makes available to its customers.
  • “Process” or “Processing” means any operation or set of operations performed on Personal Data, whether or not by automatic means, including collection, recording, organisation, structuring, storage, adaptation, retrieval, consultation, disclosure, dissemination, alignment, combination, restriction, erasure, or destruction.
  • “Processor” has the meaning given under GDPR and includes “Service Provider” as used in the CCPA.
  • “Regulator” means any data protection authority or regulatory, governmental, or supervisory authority with investigatory powers under applicable Data Protection Law.
  • “Restricted Transfer” means:
    1. under GDPR, a transfer of Personal Data from the EEA to a country outside the EEA not subject to an adequacy determination by the European Commission;
    2. under UK GDPR, a transfer of Personal Data from the UK to any country not subject to adequacy regulations under Section 17A of the UK Data Protection Act 2018; and
    3. under the Swiss DPA, a transfer of Personal Data to a country not on the list of adequate jurisdictions published by the Swiss Federal Data Protection and Information Commissioner.
  • “Sell” has the meaning given under the CCPA and any other applicable state privacy law.
  • “Strategic Data Partner” (“SDP”) means a third-party source engaged to collect consent from Data Subjects and supply resulting lead data to Pipeline360 in connection with a Campaign.
  • “Subprocessor” means any person (including any third party or Affiliate but excluding a Pipeline360 employee) appointed by or on behalf of Pipeline360 to process Personal Data in connection with the Agreement.
  • “UK Addendum” means the International Data Transfer Addendum issued by the ICO to the EU Commission’s Standard Contractual Clauses, Version B1.0, in force 21 March 2022.

2. SCOPE

  1. The Parties agree to process Personal Data in accordance with this DPA and their respective obligations under applicable Data Protection Law.
  2. Where any term of this DPA conflicts with the Agreement, this DPA prevails. Where any term of this DPA conflicts with the EU SCCs or UK Addendum, the EU SCCs or UK Addendum (as applicable) prevail.
  3. Pipeline360 processes Personal Data only on documented instructions from the Controller, as set out in this DPA and Annex I.B, unless required otherwise by applicable law, in which case Pipeline360 will notify the Controller before processing unless prohibited from doing so by law.

3. CONTROLLER WARRANTIES AND OBLIGATIONS

  1. Consent Language Warranty. The Controller warrants that:
    1. all Approved Consent Language provided to Pipeline360 in connection with any Campaign complies with Article 7 GDPR and UK GDPR;
    2. all Approved Consent Language discloses the identity of the Controller and the purposes for which the Personal Data will be used;
    3. the Controller maintains and can demonstrate records of consent in accordance with Article 7(1) GDPR for all Personal Data it receives from Pipeline360 in connection with any Campaign; and
    4. the Controller has lawful authority under applicable Data Protection Law to instruct Pipeline360 to process the Personal Data described in Annex I.B.

4. PIPELINE360 OBLIGATIONS

  1. Pipeline360 shall immediately inform the Controller if it is unable to follow the Controller’s instructions.
  2. Pipeline360 shall implement and maintain the technical and organisational measures set out in Annex II.
  3. Pipeline360 shall ensure that all personnel authorised to process Personal Data are bound by enforceable confidentiality obligations.
  4. Pipeline360 shall cooperate with and assist the Controller to enable the Controller to comply with its obligations under applicable Data Protection Law.
  5. Pipeline360 shall provide all information reasonably necessary to demonstrate compliance with this DPA and shall allow for and participate in audits requested by the Controller or a Regulator, subject to reasonable notice and confidentiality protections.
  6. Pipeline360 shall ensure that each Subprocessor complies with obligations equivalent to those imposed on Pipeline360 under this DPA.
  7. Pipeline360 shall assist the Controller in responding to Data Subject rights requests under applicable Data Protection Law, including requests to access, rectify, erase, restrict, or port Personal Data. Pipeline360 shall action the Controller’s written instruction in relation to any such request within 5 business days of receipt.

5. DATA BREACH NOTIFICATION

  1. Pipeline360 shall notify the Controller within 48 hours of becoming aware of a Data Breach affecting Personal Data processed under this DPA. The initial notification shall include, to the extent then available:
    1. a description of the nature of the Data Breach, including the categories and approximate number of Data Subjects and Personal Data records affected;
    2. the name and contact details of Pipeline360’s data protection officer or designated privacy contact;
    3. the likely consequences of the Data Breach; and
    4. the measures taken or proposed to address the Data Breach and mitigate its effects.
  2. Where all information is not available at the time of initial notification, Pipeline360 shall provide further updates without undue delay as information becomes available.
  3. Pipeline360 shall cooperate fully with the Controller in connection with any notification to a Regulator or affected Data Subjects required by applicable Data Protection Law.
  4. Upon the Controller’s written request, Pipeline360 shall promptly delete or return Personal Data from its systems (and if requested, certify such deletion in writing). Where Pipeline360 is unable to delete Personal Data for legal reasons, it shall:
    1. cease any further use or disclosure;
    2. maintain security over the data; and
    3. delete it as soon as the legal obligation permits.
  5. Pipeline360 shall ensure that any deletion obligation under this Clause flows down to Subprocessors within a timeframe that allows Pipeline360 to certify deletion to the Controller within 30 days of receiving the Controller’s deletion request.

6. SECURITY

Both Parties shall implement and maintain appropriate administrative, technical, and physical security measures against unauthorised access to, alteration of, disclosure of, or destruction of Personal Data and against all other unlawful forms of processing. Such measures shall be at minimum at the level each Party applies to its own comparable data. The measures required of Pipeline360 are set out in Annex II.

7. CROSS-BORDER TRANSFERS

  1. Except through approved Subprocessors, neither Party shall transfer Personal Data across borders except as permitted under applicable Data Protection Law.
  2. Pipeline360 shall not disclose, share, or otherwise process Personal Data except as permitted by this DPA.
  3. Business contact information of each Party’s employees may be stored and processed anywhere either Party does business solely for the purposes of this DPA and the delivery of services under the Agreement.
  4. Where Personal Data is transferred from the EEA, UK, or Switzerland to a country not providing adequate protection under applicable Data Protection Law, the transfer mechanisms in Clause 8 apply.

8. TRANSFER MECHANISMS

  1. Data Privacy Framework. Pipeline360 is self-certified under the EU-U.S. Data Privacy Framework, the UK Extension, and the Swiss-U.S. Data Privacy Framework. Pipeline360 represents that it complies with the Data Privacy Principles when processing EEA, UK, and Swiss Personal Data and will provide at least the same level of protection as required by those Principles.
  2. EU SCCs. Where the Controller requires Pipeline360 to process Personal Data from the EEA in a country without adequacy standing, the Parties agree to Module Two (Controller to Processor) of the EU SCCs published https://commission.europa.eu/law/law-topic/data-protection/international-dimension-data-protection/standard-contractual-clauses-scc_en, as further detailed in Annex I.
  3. UK Addendum. For Personal Data originating from the UK to be processed outside the UK, the Parties shall comply with the UK Addendum published by the ICO https://ico.org.uk/media2/migrated/4019539/international-data-transfer-addendum.pdf.
  4. Swiss Modifications. Where Personal Data protected by the Swiss Federal Act on Data Protection is transferred to a country not on the FDPIC’s list of adequate jurisdictions, the EU SCCs apply with the following modifications:
    1. the competent supervisory authority under Clause 13 is the Swiss Federal Data Protection and Information Commissioner;
    2. references to “Member State” mean Switzerland; and
    3. references to “GDPR” and “Regulation 2016/679” mean the Swiss Federal Act on Data Protection.
Standard Contractual Clauses UK SCCs EU SCCs
Docking Clause (Clause 7): This optional clause shall not apply.  
Sub-processor authorization (Clause 9(a)): The Parties agree that Option 2 General Written Authorization will apply with the specified time-period of ten (10) business days.  
Redress (Clause 11(a)): The option shall not apply.  
Supervision (Clause 13(a): N/A. The competent supervisory authority is the Data Protection Commission (Ireland); which is where the Pipeline360 EU GDPR Article 27 representative is established.
Governing law (clause 17) /Choice of forum and jurisdiction (clause 18) (both as amended by the UK SCCs): England and Wales. Clause 17 – Republic of Ireland. Clause 18(b) – Republic of Ireland.
Table 4: Ending this Addendum when the Approved Addendum changes (UK SCCs only): Neither party. N/A.

9. LATIN AMERICAN DATA

For any Personal Data collected, processed, or transferred from any Latin American country, the terms of the Latin American Data Processing Rider attached as Exhibit D apply.

10. CCPA AND CPRA

Pipeline360 acts as a Service Provider under the CCPA and CPRA and confirms that it:

  1. does not collect, retain, use, disclose, or otherwise process Personal Data for any purpose other than performing its obligations under this DPA;
  2. does not sell or share the Controller’s Personal Data;
  3. does not combine the Controller’s Personal Data with data from other sources except as permitted by the CCPA;
  4. does not use the Controller’s Personal Data to provide services to a different business; and
  5. will provide the same level of privacy protection as required by the CCPA.

11. SUBPROCESSORS

  1. Pipeline360 shall use only Subprocessors that provide sufficient guarantees to implement appropriate technical and organisational measures meeting the standards required under this DPA.
  2. Pipeline360 shall impose on each Subprocessor data protection obligations equivalent to those imposed on Pipeline360 under this DPA, including cross-border transfer obligations.
  3. Pipeline360 shall ensure that each Subprocessor processes Personal Data only on Pipeline360’s instructions, except where required by applicable law.
  4. The Controller authorizes Pipeline360 to appoint the Subprocessors listed at https://www.pipeline-360.com/subprocessors (“Subprocessor List”), which includes each Subprocessors name, location and description of processing. Pipeline360 will update the Subprocessor List and provide written notice to the Controller before adding any new Subprocessor.
  5. The Controller may object to a new Subprocessor within 10 business days of notice by sending written notice to privacy@pipeline-360.com stating the data protection basis for its objection. Objections must not be unreasonably made. If no objection is received within 10 business days, the Controller is deemed to have approved the appointment.
  6. If the Controller raises a reasonable objection, Pipeline360 will cease using that Subprocessor for the Controller’s Personal Data and will propose an alternative. If no alternative is agreed within 30 days, the Controller may terminate this DPA on written notice.
  7. In an emergency requiring immediate replacement of a Subprocessor, Pipeline360 shall notify the Controller as soon as practicable, and the Controller retains the right to object under Clause 13.5.
  8. Pipeline360 remains fully liable to the Controller for the performance of any Subprocessor’s obligations under this DPA.

12. DATA RETENTION

  1. Pipeline360 shall not retain Personal Data for longer than either Controller remains a client or Controller request the data be deleted.
  2. On termination of this DPA, or on written request from the Controller, Pipeline360 shall cease processing Personal Data and shall securely delete or return all Personal Data within 30 days, unless applicable law requires retention, in which case Pipeline360 shall notify the Controller and apply the obligations in Clause 6.3.

13. RECORDS OF PROCESSING

Pipeline360 shall maintain records of processing activities carried out on behalf of the Controller as required under Article 30(2) GDPR and shall make those records available to the Controller or a Regulator on request.

14. TERMINATION

This DPA terminates when Pipeline360 ceases to process Personal Data for the Controller, unless otherwise agreed in writing.

15. AMENDMENTS

Pipeline360 may amend this DPA to reflect changes required by applicable Data Protection Law by providing the Controller with 30 days’ written notice. Amendments take effect only on the Controller’s written acceptance. Where the Controller does not respond within 30 days, Pipeline360 may suspend processing until written acceptance is received. Deemed acceptance by continued business conduct does not apply.

16. LIMITATION OF LIABILITY

Pipeline360’s maximum aggregate liability arising out of this DPA shall not exceed the greater of (a) US$100,000, or (b) three times the fees paid by the Controller to Pipeline360 under the affected order in the 12 months immediately preceding the Controller’s first assertion of its claim. This limitation does not apply to: (i) Pipeline360’s indemnification obligations under this DPA; or (ii) the third-party rights available to EEA and UK Data Subjects under the SCCs.

ANNEX I

A. LIST OF PARTIES

Data Exporter (Controller): 

Name: 

Address: 

Contact / DPO: Email: Activities: 

Controller determines the purposes and means of processing Personal Data in connection with B2B marketing campaigns and receives consent-based lead data processed by Pipeline360 on its behalf. 

Role: Controller 

Data Importer (Processor): 

Name: Pipeline360, Inc. 

Address: 2345 E Thomas Rd, Ste 100 #955, Phoenix, AZ 85016 

Contact: Lindsay O’Neill, Director of Legal, Privacy and Compliance 

Email: privacy@pipeline-360.com 

Activities: Receiving consent-based lead data from Strategic Data Partners, processing it through Pipeline360’s lead management platform and subprocessors, and delivering validated lead data to the Controller for use in B2B marketing campaigns. 

Role: Processor

B. DESCRIPTION OF TRANSFER

Categories of data subjects: Business professionals in the UK and EEA who have provided explicit consent, collected by Strategic Data Partners using Approved Consent Language, for their contact information to be used for B2B marketing communications by the Controller. 

Categories of personal data: First name, last name, business email address, business telephone number, job title, employer name, business address, and other professional contact details as specified per Campaign by the Controller. 

Sensitive data: None. The Parties agree that no special category data under Article 9 GDPR will be transferred under this DPA. If the Controller requires transfer of any special category data, this must be agreed in a separate written amendment to this Annex prior to any such transfer. 

Frequency: Continuous for the duration of each Campaign, for the duration of this DPA. 

Nature of processing: Receipt of consent-based lead data from Strategic Data Partners; processing, validation, and formatting through Pipeline360’s lead management platform and Subprocessors; and delivery of validated lead data to the Controller. 

Purpose: To enable the Controller to receive validated, consent-based lead data of business professionals who have agreed to receive B2B marketing communications from the Controller, for use in targeted B2B marketing campaigns. 

Subprocessor processing: Pipeline360 processes Personal Data through Subprocessors listed at https://www.pipeline-360.com/subprocessors. 

Retention period: Personal Data will be retained for no longer than 12 months from the date of collection unless the Controller specifies a shorter period or applicable law requires earlier deletion.

C. COMPETENT SUPERVISORY AUTHORITY

For EEA transfers: Data Protection Commission of Ireland (DPC), as Pipeline360’s EU Article 27 representative is established in Ireland. 

For UK transfers: Information Commissioner’s Office (ICO). 

For Swiss transfers: Swiss Federal Data Protection and Information Commissioner (FDPIC).

ANNEX II – TECHNICAL AND ORGANISATIONAL MEASURES

Pipeline360 shall maintain and implement the following technical and organisational measures as a minimum standard. These measures are reviewed at least annually and updated following any material change to processing activities or applicable risk. 

Information Security Program: Pipeline360 maintains a written Information Security Programme designating responsible personnel, identifying and assessing internal and external risks, implementing safeguards proportionate to those risks, and requiring ongoing employee training and confidentiality obligations. 

Access Controls: Role-based access restrictions limiting Personal Data access to personnel who require it for their job function; unique user credentials that are not vendor-supplied defaults; multi-factor authentication for systems processing Personal Data; immediate revocation of access on termination of employment or contract. 

Encryption: Encryption of Personal Data in transit over public networks using TLS 1.2 or higher; encryption of Personal Data at rest on portable devices and cloud storage; encrypted backup with the same access controls as original data. 

Network Security: Regularly updated firewall protection and operating system security patches; up-to-date malware protection with current virus definitions; intrusion detection and prevention systems with logging and alerting; network segmentation ensuring logical or physical separation of Personal Data from other customer data. 

Physical Security: Controlled physical access to areas where Personal Data is stored or processed, using individually identifiable entry controls providing an audit trail. 

Incident Management: Documented incident response procedure covering detection, containment, assessment, notification (including the 48-hour notification obligation to the Controller under Clause 5), and post-incident review; evidence preservation procedures. 

Cloud and Remote Storage: All cloud storage of Personal Data in environments meeting ISO 27001 and 27002 or equivalent standards; logical or physical data segregation per customer; no reduction in security standards without prior written approval from the Controller; audit rights extended to the Controller as third-party beneficiary for cloud environments. 

Sub-Processor Security: Pipeline360 imposes security obligations at least equivalent to those in this Annex II on each Subprocessor through written contract.

EXHIBIT D – LATIN AMERICAN DATA PROCESSING RIDER

This Rider applies to all Personal Data collected, processed, or transferred from any Latin American country under this DPA. The Parties shall observe the following principles when processing such Personal Data:

  1. Purpose: Processing for legitimate, specific, explicit, and informed purposes only.
  2. Adequacy: Compatibility of processing with the purposes disclosed to the Data Subject.
  3. Necessity: Processing limited to the minimum necessary for the stated purpose.
  4. Free Access: Data Subjects shall have free and easy consultation rights.
  5. Data Quality: Personal Data shall be accurate, clear, relevant, and kept up to date.
  6. Transparency: Clear, accurate, and accessible information provided to Data Subjects about processing activities.
  7. Security: Technical and administrative measures protecting against unauthorized access, destruction, loss, alteration, or unlawful processing.
  8. Prevention: Proactive measures to prevent harm from processing.
  9. Non-discrimination: No processing for illicit or abusive discriminatory purposes.
  10. Accountability: Maintenance of effective measures demonstrating compliance with applicable data protection rules.