Data Processing Agreement

This Data Processing Agreement (“DPA”) forms part of the Agreement between Omnidex and the Publisher. It applies to the extent either Party Processes Personal Data in connection with the Services. Omnidex may update this DPA in accordance with the change control provisions of the Terms & Conditions; the current version is available at https://www.omni-dex.io/publisherterms/dpa.

1. Definitions

“Data Protection Laws” means all laws applicable to the privacy, protection, or security of Personal Data, including the EU GDPR, UK Data Protection Laws, the Swiss FADP, the ePrivacy Directive and national implementing laws, and applicable U.S. state privacy laws (including the CCPA as amended), in each case as amended or replaced. “Privacy Signals” means consent, objection, and opt-out signals expressed by End Users, including those conveyed under the IAB TCF, the Global Privacy Platform (“GPP”), the U.S. Privacy String, and Global Privacy Control. All other terms have the meanings given in the Agreement or under applicable Data Protection Laws.

2. Role of the Parties

Each Party is an independent Controller in respect of the Personal Data it Processes under the Agreement. Each Party independently determines the purposes and means of its own Processing and does not jointly determine them with the other Party. Nothing in this DPA creates joint controllership, partnership, or agency. For the purposes of US Data Protection Laws, the Publisher is the “Business” and Omnidex is a “Third Party”, save that where Processing is limited to a Restricted Purpose Omnidex may act as a Service Provider or Processor. “Restricted Purpose” means Processing for auditing, security, integrity, debugging, fraud prevention, short term transient use, internal research, contextual or non-targeted advertising, frequency capping, or measurement, and which does not constitute Selling, Sharing, or Targeted Advertising.

3. Description of Processing

The Personal Data Processed is determined by what the Publisher transmits to Omnidex in bid requests and by Omnidex’s own enrichment activities, and comprises online and advertising identifiers, IP address as received, user agent, device and technical data, geolocation data at the level of precision the Publisher transmits, contextual data including domain and page URL, Privacy Signals, and data derived or enriched by Omnidex, including audience segments and inferred interest and demographic attributes, attributes obtained from data partners, survey responses linked to online identifiers, and advertising performance metrics. Data Subjects are End Users of Publisher Properties. Processing is continuous for the duration of the Agreement and thereafter for any period required for reconciliation, fraud prevention, or legal compliance. Omnidex does not knowingly Process Special Categories of Personal Data.

4. Obligations of the Parties

Compliance. Each Party shall comply with applicable Data Protection Laws in respect of its own Processing.

Notice and Consent. The Publisher shall provide all notices and obtain, record, and maintain all consents required under applicable Data Protection Laws before Omnidex’s Services are invoked, including where consent is required to store or access information on a device, and shall transmit accurate Privacy Signals using a compliant consent management platform. The Publisher shall promptly notify Omnidex of any change or revocation. Omnidex shall honour valid Privacy Signals and shall pass them to Advertisers as received, and is not responsible for the accuracy, sufficiency, or lawfulness of signals generated or transmitted by the Publisher.

Restricted Data. The Publisher shall not make available to Omnidex any direct identifier, account credential, financial or health information, biometric identifier, Special Categories of Personal Data, criminal offence data, or Personal Data relating to an End User below the age of digital consent applicable in the relevant jurisdiction, unless Omnidex has approved that Processing in writing. The Publisher shall flag mixed audience Inventory in advance and shall promptly notify Omnidex if such data has been transmitted, whereupon Omnidex shall delete it and shall not Process it further.

Data Subject Rights. Each Party is responsible for responding to requests relating to its own Processing, and shall promptly forward any request clearly intended for the other Party and provide reasonable assistance.

Security and Breach Notification. Each Party shall maintain technical and organisational measures appropriate to the nature, scope, context, and risks of its Processing, including at a minimum access controls on a least privilege basis, encryption in transit and, where appropriate to the risk, at rest, secure storage and secure disposal of media, logging and monitoring to detect unauthorised access, confidentiality obligations and data protection training for personnel with access to Personal Data, documented incident response procedures, and regular security testing with prompt remediation of high risk findings. Each Party shall notify the other without undue delay of any Personal Data Breach affecting the other Party and shall cooperate in mitigation.

Sub-Processors and Recipients. Each Party shall ensure that any processor it engages is bound by obligations consistent with applicable Data Protection Laws. Omnidex engages technology, infrastructure, and data partners in connection with the Services and shall make a current list available to the Publisher on written request.

Use Restrictions. Neither Party acquires ownership of the other Party’s Personal Data, and neither Party shall Process Personal Data received from the other for a purpose incompatible with the Agreement or with the context in which it was collected.

5. US Privacy Laws and Cross-Context Behavioral Advertising

Omnidex engages in Cross-Context Behavioral Advertising as defined under US Data Protection Laws: it may observe End User activity across multiple publisher properties using Omnidex’s services, derive audience segments from that activity, and make those segments available to Advertisers for targeting. Omnidex shall honour all valid opt-out signals received in the bid request, including the U.S. Privacy String, GPP, and Global Privacy Control, and shall not Process an opted-out End User’s Personal Information for Sale, Sharing, Cross-Context Behavioral Advertising, or Targeted Advertising. The Publisher shall ensure that valid opt-out signals are correctly captured at its properties and transmitted to Omnidex. Where Omnidex Processes Personal Information solely for a Restricted Purpose it shall not Sell or Share that Personal Information, shall not retain, use, disclose, or combine it outside the scope of the Agreement except as permitted by law, shall provide the level of privacy protection required of the Publisher, shall notify the Publisher if it can no longer meet those obligations, and certifies that it understands and will comply with the CCPA in respect of such Processing.

6. International Data Transfers

Scope. This Clause applies only where Personal Data is transferred from the European Economic Area, the United Kingdom, or Switzerland to a country or territory that does not, at the relevant time, benefit from an applicable adequacy decision. In this Clause, "SCCs" means the standard contractual clauses for the transfer of personal data to third countries adopted by the European Commission in Implementing Decision (EU) 2021/914, and "UK Addendum" means the International Data Transfer Addendum to those clauses issued by the UK Information Commissioner under section 119A of the Data Protection Act 2018, in each case as amended or replaced. The SCCs and, where applicable, the UK Addendum and the Swiss adaptations below are incorporated into this DPA and completed as set out in this Clause.

Elections. Module One (controller to controller) applies, and no other Module applies, with the Publisher as data exporter and Omnidex as data importer, each acting as an independent Controller. Clause 7 (docking clause) is not used. Clause 9 does not form part of Module One. The optional paragraph of Clause 11(a) is not used, and accordingly Data Subjects have no right under the SCCs to lodge a complaint with an independent dispute resolution body. For the purposes of Clause 13, the competent supervisory authority is the authority of the EU Member State in which the Publisher is established or, where the Publisher is not so established but falls within the scope of Article 3(2) of the GDPR, the authority of the Member State in which its Article 27 representative is established, failing which the Irish Data Protection Commission. Under Clause 17, Option 1 applies and the SCCs are governed by the law of the EU Member State in which the Publisher is established or, failing that, the law of the Republic of Ireland. Under Clause 18(b), the courts of the Republic of Ireland have jurisdiction over any dispute arising from the SCCs. By entering into the Agreement, each Party is deemed to have signed the SCCs, including their Annexes, as of the Effective Date.

Annexes to the SCCs. Annex I.A (List of Parties) is completed by Annex I of this DPA together with the Parties' details in the Order Form. Annex I.B (Description of the transfer) is completed by Clauses 3 and 7 of this DPA, and no sensitive data is transferred. Annex I.C (Competent supervisory authority) is as determined above. Annex II (Technical and organisational measures) is completed by Annex II of this DPA. Annex III (List of sub-processors) is not applicable to Module One.

UK Addendum. Part 2 of the UK Addendum (Mandatory Clauses) applies as published, without amendment. Part 1 is completed as follows. Table 1 (Parties): the start date is the Effective Date, and the Parties, their details and key contacts are as set out in Annex I of this DPA and in the Order Form. Table 2 (Selected SCCs, Modules and Selected Clauses): the Addendum EU SCCs are those adopted in Implementing Decision (EU) 2021/914 as completed by this Clause; Module One is in operation; Clause 7 is not used; the Clause 11 optional paragraph is not used; Clause 9a is not applicable to Module One; and Personal Data received from the importer is not combined with Personal Data collected by the exporter. Table 3 (Appendix Information): as set out above. Table 4 (Ending this Addendum when the Approved Addendum changes): neither Party may end the Addendum.

Swiss adaptations. Where a transfer is subject to the Swiss FADP, references to the GDPR are read as references to the Swiss FADP, and references to "Member State" include Switzerland, with Data Subjects able to enforce their rights in Switzerland. For transfers subject exclusively to the Swiss FADP, the competent supervisory authority is the Swiss Federal Data Protection and Information Commissioner, the SCCs are governed by the law of Switzerland, and the competent courts of Switzerland have jurisdiction. The SCCs also apply to data relating to legal entities, to the extent and for so long as such data is protected under the Swiss FADP.

Transfers to the United States. Each Party shall maintain industry standard technical measures to protect Personal Data in transit and at rest, including encryption and access controls, and shall use reasonable efforts, subject to applicable law, to resist requests for bulk or indiscriminate access to Personal Data by government authorities. A Party receiving a legally binding request from a public authority for Personal Data subject to the SCCs shall, unless legally prohibited, notify the other Party without undue delay and provide reasonable assistance in opposing or limiting the scope of the disclosure.

7. Retention

Each Party shall retain Personal Data only for as long as necessary for the purposes of the Agreement or as required by law, and shall securely delete or return it thereafter. Event-level logs are retained for up to one (1) year for fraud prevention, troubleshooting, billing reconciliation, audit, and operational integrity. Termination of the Agreement does not require deletion of Personal Data that Omnidex Processes lawfully as an independent Controller, and Omnidex may retain aggregated or de-identified information that does not identify an individual.

8. Cooperation

Each Party shall provide reasonable assistance to the other in responding to regulatory inquiries or investigations, in carrying out data protection impact assessments where required by law, and in demonstrating compliance with this DPA.

9. Liability, Governing Law and Precedence

Liability under this DPA is subject to, and not in addition to, the limitation of liability provisions of the Terms & Conditions, and no separate or additional cap applies. This DPA follows the governing law of the Agreement except where the Standard Contractual Clauses require otherwise. This DPA controls over the rest of the Agreement on data protection matters, and the Standard Contractual Clauses control over this DPA in the event of conflict. No Order Form or other document varies this DPA unless expressly agreed in writing and signed by both Parties as an amendment to this DPA.

ANNEX I – DETAILS OF PROCESSING

Data exporter: the Publisher, as identified in the Order Form. Data importer: Omnidex Technologies LTD, 86-90 Paul Street, London, EC2A 4NE, United Kingdom, [email protected]. Roles: both Parties act as independent Controllers. Data Subjects, categories of Personal Data, nature and purpose of Processing, frequency, and retention are as described in Clauses 3 and 7 of this DPA. Competent supervisory authority: the authority of the EU Member State in which the Publisher is established or, failing that, the Irish Data Protection Commission. By entering into the Agreement the Parties are deemed to have signed the Standard Contractual Clauses and their Annexes as of the Effective Date.

ANNEX II – TECHNICAL AND ORGANISATIONAL MEASURES

The technical and organisational measures required under the Standard Contractual Clauses are those set out under “Security and Breach Notification” in Clause 4 of this DPA, which are incorporated into this Annex II.

Bottom Arrow Icon