DATA PROCESSING ADDENDUM
Customer data processing terms
This DPA framework applies where WESTCAST-24, LLC processes Personal Data on behalf of a business customer in connection with MediaBrain services and applicable data-protection law requires processor terms.
1. Roles and instructions
Customer acts as controller or processor, as applicable, and MediaBrain acts as processor or subprocessor for Customer Personal Data. MediaBrain will process Customer Personal Data only on documented instructions from Customer, including the instructions embodied in the Agreement and Customer's use of the Services, unless otherwise required by law.
2. Scope of processing
Processing may include hosting, storage, organization, retrieval, analysis, generation, transmission, security monitoring, support and deletion of Customer Personal Data. Categories may include account information, business contact data, prompts, uploaded documents and other content selected by Customer.
3. Confidentiality
Personnel authorized to process Customer Personal Data are subject to appropriate confidentiality obligations.
4. Security measures
MediaBrain will maintain technical and organizational safeguards appropriate to the risk and the Services. Current controls and limitations are described at Security. Security commitments do not include certifications or controls not expressly published or agreed in writing.
5. Subprocessors
Customer authorizes MediaBrain to engage subprocessors needed to provide the Services. MediaBrain remains responsible for imposing data-protection obligations appropriate to the services performed. The production register is published at Subprocessors.
6. International transfers
Where required by applicable law, transfers of Customer Personal Data outside the EEA, UK or Switzerland will be supported by an applicable lawful transfer mechanism, which may include Standard Contractual Clauses and supplementary safeguards.
7. Data subject requests
Taking into account the nature of the processing, MediaBrain will provide commercially reasonable assistance to Customer with data-subject requests where Customer cannot reasonably fulfill the request using the Services.
8. Security incidents
MediaBrain will notify Customer without undue delay after becoming aware of a confirmed Personal Data Breach affecting Customer Personal Data, as required by applicable law, and will provide information reasonably available to support Customer's response obligations.
9. DPIAs and regulator cooperation
Taking into account the nature of processing and information available to MediaBrain, MediaBrain will provide reasonable assistance with data-protection impact assessments and regulator consultations where required by law and related to the Services.
10. Return and deletion
Upon termination, Customer Personal Data will be returned or deleted in accordance with the applicable Agreement, product capabilities, backup lifecycle and legal-retention requirements. Specific deletion periods may be established in an Order Form or enterprise agreement.
11. Audit information
MediaBrain will make available information reasonably necessary to demonstrate compliance with applicable processor obligations. Any audit rights will be exercised in a manner that protects other customers, security and confidential information and avoids unreasonable disruption.
12. Precedence
If this DPA conflicts with the Agreement regarding processing of Personal Data, this DPA controls for that subject matter. Customer-specific signed DPAs or enterprise terms may replace this public framework.
This public DPA is a framework for launch and enterprise contracting. Customers requiring executed SCCs, jurisdiction-specific addenda or negotiated security schedules should use the commercial contracting process.