DATA PROCESSING ADDENDUM

Customer data processing terms

This DPA framework applies where WESTCAST-24, LLC processes Personal Data on behalf of a business customer in connection with MediaBrain services and applicable data-protection law requires processor terms.

1. Roles and instructions

Customer acts as controller or processor, as applicable, and MediaBrain acts as processor or subprocessor for Customer Personal Data. MediaBrain will process Customer Personal Data only on documented instructions from Customer, including the instructions embodied in the Agreement and Customer's use of the Services, unless otherwise required by law.

2. Scope of processing

Processing may include hosting, storage, organization, retrieval, analysis, generation, transmission, security monitoring, support and deletion of Customer Personal Data. Categories may include account information, business contact data, prompts, uploaded documents and other content selected by Customer.

3. Confidentiality

Personnel authorized to process Customer Personal Data are subject to appropriate confidentiality obligations.

4. Security measures

MediaBrain will maintain technical and organizational safeguards appropriate to the risk and the Services. Current controls and limitations are described at Security. Security commitments do not include certifications or controls not expressly published or agreed in writing.

5. Subprocessors

Customer authorizes MediaBrain to engage subprocessors needed to provide the Services. MediaBrain remains responsible for imposing data-protection obligations appropriate to the services performed. The production register is published at Subprocessors.

6. International transfers

Where required by applicable law, transfers of Customer Personal Data outside the EEA, UK or Switzerland will be supported by an applicable lawful transfer mechanism, which may include Standard Contractual Clauses and supplementary safeguards.

7. Data subject requests

Taking into account the nature of the processing, MediaBrain will provide commercially reasonable assistance to Customer with data-subject requests where Customer cannot reasonably fulfill the request using the Services.

8. Security incidents

MediaBrain will notify Customer without undue delay after becoming aware of a confirmed Personal Data Breach affecting Customer Personal Data, as required by applicable law, and will provide information reasonably available to support Customer's response obligations.

9. DPIAs and regulator cooperation

Taking into account the nature of processing and information available to MediaBrain, MediaBrain will provide reasonable assistance with data-protection impact assessments and regulator consultations where required by law and related to the Services.

10. Return and deletion

Upon termination, Customer Personal Data will be returned or deleted in accordance with the applicable Agreement, product capabilities, backup lifecycle and legal-retention requirements. Specific deletion periods may be established in an Order Form or enterprise agreement.

11. Audit information

MediaBrain will make available information reasonably necessary to demonstrate compliance with applicable processor obligations. Any audit rights will be exercised in a manner that protects other customers, security and confidential information and avoids unreasonable disruption.

12. Precedence

If this DPA conflicts with the Agreement regarding processing of Personal Data, this DPA controls for that subject matter. Customer-specific signed DPAs or enterprise terms may replace this public framework.

This public DPA is a framework for launch and enterprise contracting. Customers requiring executed SCCs, jurisdiction-specific addenda or negotiated security schedules should use the commercial contracting process.