Scope and roles
This Data Processing Addendum (“DPA”) forms part of the Master Services Agreement between Nasrev LLC and the Partner and applies to all processing of Personal Data under it.
The Parties acknowledge that in respect of data processed through the advertising exchange, each Party acts as an independent controller determining its own purposes and means. Where Nasrev processes Personal Data solely on the documented instructions of the Partner, Nasrev acts as a processor and sections 4 to 9 apply.
Subject matter and duration
| Item | Detail |
|---|---|
| Subject matter | Provision of real-time bidding advertising services |
| Duration | The term of the Master Services Agreement, plus any retention period in section 9 |
| Nature and purpose | Transmission and receipt of bid requests, auction execution, frequency capping, fraud detection, measurement and reporting |
| Categories of data subject | End users of the Properties on which advertising is served |
| Categories of Personal Data | Online identifiers, IP address, device and browser identifiers, mobile advertising IDs, approximate location, user agent, consent strings, interaction events |
| Special categories | None. Neither Party shall transmit special category data through the exchange |
Independent controller obligations
Where the Parties act as independent controllers, each shall:
- Establish and maintain a lawful basis for its own processing, including obtaining valid consent where required;
- Provide clear and accurate information to data subjects about its processing;
- Transmit and honour consent and privacy signals accurately, including IAB TCF, Global Privacy Platform and Global Privacy Control;
- Respond to data subject requests it receives in respect of its own processing, and pass on requests properly directed at the other Party;
- Not transmit Personal Data of any individual known or reasonably suspected to be under 16;
- Notify the other Party without undue delay of any regulatory action or data subject complaint that materially affects the other.
Processor obligations
Where Nasrev acts as a processor, Nasrev shall:
- Process Personal Data only on the Partner’s documented instructions, unless required otherwise by law;
- Ensure personnel authorised to process the data are bound by confidentiality;
- Implement the technical and organisational measures set out in section 6;
- Not engage a sub-processor without prior general written authorisation, and give at least thirty (30) days’ notice of any intended change, during which the Partner may object on reasonable data protection grounds;
- Assist the Partner, taking account of the nature of processing, with data subject requests, impact assessments and consultations with supervisory authorities;
- Make available all information necessary to demonstrate compliance and allow for audits under section 8;
- At the Partner’s election, delete or return Personal Data at the end of the relationship, subject to legal retention obligations.
Sub-processors
Nasrev engages sub-processors for cloud hosting, data storage, analytics and fraud verification. A current list is available on request from [email protected]. Nasrev imposes data protection obligations on each sub-processor no less protective than those in this DPA and remains liable for their performance.
Security measures
Nasrev maintains technical and organisational measures including:
- Encryption of Personal Data in transit using TLS 1.2 or above
- Access control on a least-privilege basis with multi-factor authentication for administrative access
- Network segregation between production and non-production environments
- Logging and monitoring of access to systems containing Personal Data
- Regular patching and vulnerability management
- Background-checked personnel bound by written confidentiality obligations
- A documented incident response procedure, tested periodically
- Business continuity and backup procedures
Personal data breach
Each Party shall notify the other without undue delay, and in any event within forty-eight (48) hours, of becoming aware of a Personal Data breach affecting data processed under the Agreement. The notification shall describe the nature of the breach, the categories and approximate number of data subjects and records affected, the likely consequences, and the measures taken or proposed. The Parties shall cooperate in good faith on remediation and on any required notification to authorities or data subjects.
Audit
The Partner may, on thirty (30) days’ written notice and no more than once in any twelve-month period, audit Nasrev’s compliance with this DPA, either by reviewing documentation Nasrev provides or, where reasonably necessary, by an independent auditor bound by confidentiality. Audits shall be conducted during business hours, shall not unreasonably disrupt operations, and shall be at the Partner’s cost unless a material non-compliance is found.
International transfers
Where this DPA involves transferring Personal Data out of the European Economic Area, the United Kingdom or Switzerland to a country without an adequacy decision, the Parties agree that the European Commission’s Standard Contractual Clauses (Decision 2021/914) are incorporated by reference and apply, with Module One (controller to controller) or Module Two (controller to processor) as applicable. For UK transfers, the ICO’s International Data Transfer Addendum applies. The Parties shall complete the annexes using the information in section 2 of this DPA.
Retention and deletion
Nasrev retains bid request and auction logs for no longer than thirteen (13) months, after which they are deleted or irreversibly aggregated. Aggregated reporting data containing no identifiers may be retained for up to twenty-four (24) months. Data required for fraud investigation, billing or legal defence may be retained for as long as necessary for that purpose.
US state privacy laws
For the purposes of the California Consumer Privacy Act as amended, and equivalent laws in Virginia, Colorado, Connecticut, Utah, Texas and other states, each Party is a “business” or “controller” in respect of its own processing. Nasrev does not sell Personal Information and does not share it for cross-context behavioural advertising other than as necessary to run the auction the user’s publisher has enabled. Where Nasrev acts as a “service provider” it shall not retain, use or disclose Personal Information for any purpose other than performing the services, and certifies that it understands and will comply with this restriction.
Order of precedence and contact
In the event of conflict, this DPA prevails over the Master Services Agreement in respect of data protection matters. Where the Standard Contractual Clauses apply, they prevail over this DPA.
Nasrev LLC, 8 Holmes Ave, Apt 2, Jersey City, New Jersey, 07306, USA. Email [email protected].