AI Revenue Engine for Media
Data Processing Addendum | ePublishing
Legal

Data Processing Addendum

This Addendum forms part of the Agreement between Licensee and ePublishing, LLC, governing the processing of personal data under applicable data protection laws.

Last reviewed 2025
This Attachment, Data Processing Addendum, including its exhibits (collectively, "DPA"), forms part of the Agreement. To the extent Licensor acts as a Processor of any Personal Data on behalf of Licensee under or in connection with the Agreement, Licensor agrees to comply with all provisions of this Attachment. If Licensor processes any Licensee Data that is not Personal Data, or processes Personal Data in its capacity as a Controller, Licensor still agrees to comply with all applicable provisions of this Attachment.
1
Definitions
1.1 — "Licensee Data"
All data or information, electronic or otherwise, submitted or made available by Licensee, its agents, customers, suppliers and contractors to Licensor, including any confidential or sensitive data and any Personal Data that Licensor processes on behalf of Licensee.
1.2 — "Controller"
The entity that determines the purposes and means of the processing of Personal Data.
1.3 — "Data Breach"
A breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, Licensee Data transmitted, stored or otherwise processed.
1.4 — "Data Protection Laws"
All applicable laws and regulations related to the protection of personal data, including Regulation (EU) 2016/679, the General Data Protection Regulation (GDPR), as amended from time to time.
1.5 — "Data Subject"
An identified or identifiable natural person to whom the Personal Data refers.
1.6 — "Data Subject Rights"
The rights of a Data Subject in relation to their Personal Data as set out in the GDPR including the rights of access, rectification, restriction, objection, erasure, portability, and objection to automatic individual decision-making.
1.7 — "Personal Data"
A subset of Licensee Data — any information relating to an identified or identifiable natural person, to the extent protected under applicable Data Protection Laws and submitted to Licensor under or in connection with the Agreement.
1.8 — "Process" (and derivatives)
Any operation performed upon Licensee Data, whether or not by automatic means — including collection, recording, organization, storage, adaptation, retrieval, use, disclosure by transmission, dissemination, alignment, blocking, erasure or destruction.
1.9 — "Processor"
The entity that processes the Personal Data on behalf of the Controller.
1.10 — "Subprocessor"
Any third-party entity engaged by Licensor to process Personal Data in connection with the Services.

All capitalized terms not defined in this DPA shall have the meaning set forth in the Agreement.

2
General
2.1 — Ownership of Data
Unless otherwise agreed, all Licensee Data is and shall remain the exclusive property of Licensee.
2.2 — Use of Licensee Data
Licensor may only collect, use, access, maintain, disclose or share Licensee Data for the benefit of Licensee, and only to the extent strictly necessary to perform its obligations under the Agreement. Unless otherwise agreed in writing, Licensor may not modify, merge, commercially exploit, or transfer Licensee Data in any way that adversely affects its integrity, security or confidentiality.
2.3 — Access to Licensee Data
Licensor will take reasonable steps to ensure the integrity of employees and authorized subcontractors with access to Licensee Data. Access is granted only to personnel who require it for Service delivery, and only to the least amount required, subject to binding confidentiality obligations.
3
Processing of Personal Data
3.1 — Roles
For purposes of this DPA, Licensee is the Controller and Licensor (and any authorized Subprocessors) are the Processors in relation to the processing of Personal Data.
3.2 — Processing
Licensor shall process Personal Data only as instructed in writing by Licensee, and only to the extent strictly necessary to perform its obligations under the Agreement, in accordance with applicable Data Protection Laws at all times.
3.3 — Details of Processing
The purpose, duration, types of Personal Data, and categories of Data Subjects are detailed in Exhibit A ("Data Processing Details"). Licensee may update Exhibit A as requirements change, subject to written agreement with Licensor.
3.4 — Access to Personal Data
Licensor will: (i) maintain separation of duties to prevent unauthorized end-to-end control; (ii) log all access to systems containing Personal Data and provide access reports upon request; and (iii) maintain a prompt employee termination process addressing logical and physical access revocation.
4
Data Security
4.1 — Appropriate Measures
Licensor will implement and maintain current and appropriate technical and organizational measures to protect the security, confidentiality and integrity of Licensee Data against unauthorized or unlawful processing and accidental loss, destruction, damage, alteration or disclosure. Specific measures are set out in Exhibit B ("Data Security Obligations").
4.2 — Third-Party Certification
Where Licensor adheres to an approved code of conduct or certification mechanism recognized under applicable Data Protection Laws, Licensee will accept such adherence as evidence of Licensor's compliance with the security obligations in this DPA.
5
Subprocessors

Licensor will not engage any Subprocessor without first obtaining Licensee's written consent. Licensor's engagement of any authorized Subprocessor is conditional on Licensor and Subprocessor entering a data processing agreement containing obligations that provide at least the same level of protection to the Personal Data as those in this DPA.

Licensor will ensure each Subprocessor complies with its data processing obligations and Licensor will remain liable for the acts and omissions of its Subprocessors as if they were its own.

6
Transfers
6.1 — Data within the European Economic Area (EEA)
Where Personal Data is located within the EEA, Licensor may not transfer such data outside the EEA without Licensee's prior written consent unless: (i) there has been an EC finding of adequacy pursuant to applicable Data Protection Laws; or (ii) appropriate safeguards (including Standard Contractual Clauses approved by the EC) are in place.
6.2 — Data in Other Locations
Where Personal Data is in a non-EEA jurisdiction with Data Protection Laws restricting transfers, Licensor may not transfer Personal Data to any other country without Licensee's prior written consent. Licensor shall cooperate with Licensee to implement all measures required to comply with applicable laws.
7
Data Subject Rights

Licensor will promptly notify Licensee if it receives a request from a Data Subject to exercise their Data Subject Rights, or receives a complaint relating to Licensee's obligations under applicable Data Protection Laws.

To the extent Licensor is a Processor, Licensor will provide full cooperation and assistance in relation to any such request or complaint, including: (i) providing full details of the complaint or request; (ii) complying with Data Subject requests within applicable timescales, strictly in accordance with Licensee's instructions; (iii) providing any Personal Data held in relation to a Data Subject; and (iv) providing any other information reasonably requested by Licensee.

8
Assistance

In fulfilling its role as Processor, Licensor will (at Licensee's reasonable request and expense, except where the request results from Licensor's own violation of this DPA): (i) assist Licensee with fulfilling obligations to respond to Data Subject rights requests; and (ii) provide assistance in complying with GDPR Articles 32–36, covering security, breach notifications, data protection impact assessments, and prior consultation.

Licensor will immediately inform Licensee if, in its opinion, any instruction relating to processing could infringe applicable Data Protection Laws.
9
Data Retention

On termination of the Agreement, or earlier if processing is no longer required, Licensor will (and will procure that authorized subcontractors will), at Licensee's option and expense: (a) return all Licensee Data in an agreed format; or (b) securely dispose of all Licensee Data and copies, ensuring the data is unrecoverable.

Licensor will ensure that any storage media containing Licensee Data is securely erased or destroyed before repurposing or disposal. An encrypted archival copy shall be retained by Licensor for not less than one year, unless otherwise agreed in writing.

10
Auditing

Licensor will keep, and provide to Licensee on request, a record of its use of Licensee Data and processing activities. Licensor will make available all information necessary to demonstrate compliance with this DPA.

Subject to reasonable notice, Licensor will allow for and contribute to audits and inspections conducted by Licensee or a third-party auditor acting on behalf of Licensee, to be carried out at mutually agreed times during regular business hours, no more than twice per year. Audit costs are borne by Licensee unless the audit results from a violation of this DPA or a data breach caused by Licensor.

11
Data Breach

Licensor shall promptly notify Licensee upon becoming aware of any actual or potential Data Breach by Licensor or any of its subcontractors or Subprocessors. Notification shall include:

(a) The nature of the Data Breach
(b) The date and time upon which the Data Breach took place and was discovered
(c) The number of Data Subjects affected
(d) The categories of Personal Data involved
(e) Technical and organizational measures taken to address the incident, including mitigation steps
(f) Whether proposed measures would result in disproportionate effort given the nature of the incident
(g) The name and contact details of the relevant data protection officer or other contact
(h) A description of the likely consequences of the Data Breach

In the event of a Data Breach, Licensor will conduct a thorough investigation, document remediation steps, provide results to Licensee promptly, and implement required remediation on timescales specified by Licensee. Licensor shall bear all costs Licensee incurs arising from a breach caused by Licensor's failure to meet its obligations under this DPA.

12
Severability

Any provision of this DPA that is prohibited or unenforceable in any jurisdiction shall, as to such jurisdiction, be ineffective to the extent of such prohibition or unenforceability without invalidating the remaining provisions. The parties will attempt in good faith to agree upon a valid and enforceable substitute provision to be incorporated into this Agreement.

13
Entire Agreement; Conflict

This DPA supersedes and replaces all prior representations, understandings, agreements or communications between Licensee and Licensor regarding the subject matter of this DPA, including any prior data processing addenda entered into under Directive 95/46/EC.

Except as amended by this DPA, the Agreement will remain in full force and effect. In the event of any conflict between any other agreement (including the Agreement) and this DPA, the terms of this DPA will control.

Questions about your data?

Our privacy team is available to address any questions or concerns regarding this DPA or your data rights.

Contact Privacy Team