1. Scope, incorporation and precedence
This Data Processing Addendum (the “DPA”) forms part of the written agreement, order form, insertion order or online terms governing the Services (the “Agreement”) between the Client identified in the Agreement or a customer-specific Schedule 1 (“Client”) and Starti, Inc. (“Starti”). It is effective on the later of the Agreement effective date and the date this DPA is executed (the “DPA Effective Date”). Client and Starti are each a “Party” and together the “Parties”.
1.1 Incorporation. This DPA is incorporated into the Agreement. It applies only to Processing of Personal Data in connection with the Services and only to the extent Applicable Data Protection Laws govern that Processing.
1.2 Activity-specific application. The Processor provisions apply only where Starti Processes Processor Data on Client’s behalf. The independent Controller provisions apply only where Starti determines the purposes and essential means of Processing for an activity. Where Starti receives information rendered anonymous so it no longer constitutes Personal Data, this DPA does not restrict that information except as expressly stated.
1.3 Order of precedence. If there is a conflict, the following order applies solely for privacy and data protection matters: (a) mandatory terms of the EU SCCs or UK Addendum; (b) this DPA; and (c) the Agreement. The Agreement otherwise remains in effect, including commercial terms and limitations of liability.
1.4 No reduction of protection. Starti will not materially reduce the overall protection provided to Processor Data during the term. Changes required by law, regulator guidance, security improvements or replacement transfer mechanisms are permitted if they do not materially diminish protection.
2. Definitions
- Applicable Data Protection Laws
- All privacy, data protection, electronic communications and consumer privacy laws that apply to a Party’s Processing under the Agreement, including, where applicable, the GDPR, UK GDPR, Swiss FADP, CCPA/CPRA and other U.S. state privacy laws.
- Client Personal Data
- Personal Data submitted to, collected for, transmitted to or otherwise Processed by Starti in connection with Client’s use of the Services, excluding data that Starti receives and Processes solely as an independent Controller unless otherwise stated.
- Controller
- The entity that determines the purposes and means of Processing. “Business” has the corresponding meaning under U.S. State Privacy Laws.
- Data Subject
- An identified or identifiable natural person to whom Personal Data relates; “Consumer” has the corresponding meaning under U.S. State Privacy Laws.
- EU SCCs
- The standard contractual clauses adopted by European Commission Implementing Decision (EU) 2021/914, as incorporated and completed by Section 11 and Schedule 4.
- Personal Data
- Any information relating to an identified or identifiable natural person, or information defined as personal data, personal information or a similar term under Applicable Data Protection Laws.
- Processing
- Any operation performed on Personal Data, whether automated or not. “Process”, “Processes” and “Processed” have corresponding meanings.
- Processor
- The entity that Processes Personal Data on behalf of a Controller. “Service Provider” and “Contractor” have corresponding meanings under U.S. State Privacy Laws.
- Processor Data
- The portion of Client Personal Data for which Starti acts as Processor or Service Provider/Contractor for Client, as identified in Schedule 1.
- Prohibited Data
- The data described in Section 4.4, unless expressly authorised in a signed order and supported by agreed safeguards.
- Restricted Transfer
- A disclosure or transfer of Personal Data that requires an adequacy decision, appropriate safeguard or other transfer mechanism under Applicable Data Protection Laws.
- Security Incident
- A confirmed breach of security leading to accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, Processor Data in Starti’s possession or control. It excludes unsuccessful attempts that do not compromise Processor Data.
- Services
- The Starti products and services purchased or used by Client under the Agreement, including applicable advertising, campaign, AI creative, data management, reporting and measurement features.
- Shared Controller Data
- Personal Data disclosed between the Parties in connection with an activity for which each Party acts as an independent Controller.
- Subprocessor
- A third party engaged by Starti to Process Processor Data on Client’s behalf. It excludes a party that receives data solely as an independent Controller.
3. Role allocation, instructions and permitted use
3.1 Roles follow each activity. Schedule 1 describes the intended allocation of roles. Starti may be a Processor for one activity and an independent Controller for another. The Parties will update the Schedule if a material product or data-flow change alters a role.
3.2 Processor role. For Processor Data, Client is the Controller (or a Processor authorised by the relevant Controller), Starti is the Processor (or Subprocessor), and Starti will Process the data only on Client’s documented instructions and as necessary to provide, secure and support the Services.
3.3 Independent Controller role. For Shared Controller Data, each Party acts as an independent Controller and is independently responsible for its Processing, including legal basis, transparency, rights handling and retention.
3.4 Joint controllership. If a competent authority or court determines, or the Parties agree based on the facts, that they jointly determine purposes and means for a specific Processing activity, the Parties will promptly enter an Article 26 arrangement or equivalent allocation required by applicable law.
3.5 Documented instructions. Client’s documented instructions consist of the Agreement, applicable order forms, Client’s configuration and use of the Services, this DPA and additional written instructions accepted by Starti. Starti will notify Client if, in Starti’s reasonable opinion, an instruction infringes Applicable Data Protection Laws.
3.6 Service and optimisation use. Starti may use Processor Data only to provide, maintain, protect, troubleshoot and improve the Services for Client, to comply with documented instructions, and to comply with law. Starti may use Shared Controller Data only for the specific purposes identified in Schedule 1 and its applicable privacy notice.
3.7 AI and model training. Starti will not use Processor Data in identifiable or reasonably re-identifiable form to train or improve a general-purpose model for the benefit of other customers unless Client has expressly opted in through a written instruction. This does not restrict customer-specific Processing required to generate outputs for Client, or use of data that has been rendered anonymous so it is no longer Personal Data.
3.8 Aggregated and de-identified information. Starti may create and use aggregated or de-identified information for analytics, benchmarking, fraud prevention, product improvement and general model improvement if it applies reasonable measures designed to prevent association with a person or Client, does not re-identify the information where prohibited, and requires recipients to maintain the same restrictions.
4. Client obligations
4.1 Lawful collection and disclosure. Client represents that it has all rights, notices, legal bases, consents and permissions needed to provide Client Personal Data to Starti and instruct the Processing. If Client acts as a Processor, Client represents that the relevant Controller has authorised Client to appoint Starti.
4.2 Advertising transparency and choice. For interest-based, cross-context behavioural or targeted advertising, measurement and attribution, Client is responsible for giving legally sufficient notices; obtaining any required consent before storage of or access to information on a device; communicating valid consent, opt-out and limitation signals; and honouring Global Privacy Control or equivalent signals where required. Client will not instruct Starti to override a user’s valid choice.
4.3 Data accuracy and minimisation. Client will limit Client Personal Data to what is adequate, relevant and reasonably necessary for the documented purpose, maintain reasonable accuracy, and avoid including Personal Data in free-text prompts, creative assets or support tickets unless it is needed for the Services and permitted by law.
4.4 Prohibited Data. Unless a signed order expressly identifies the data and the Parties agree appropriate safeguards, Client will not provide or make available: (a) special-category or sensitive Personal Data, including health, biometric templates, precise geolocation, racial or ethnic origin, political or religious beliefs, sexual orientation, union membership or citizenship/immigration status; (b) government identifiers, account credentials, financial-account or payment-card data; (c) data known to relate to children under 16 or a lower age prohibited by applicable law; (d) raw communications content; or (e) data regulated by sector-specific laws such as HIPAA, GLBA or FERPA.
4.5 Data partners. If Client obtains data from a data broker, publisher, measurement provider or other partner, Client will ensure that the partner lawfully collected and disclosed the data, provided required notices and choices, imposed compatible purpose and retention restrictions, and can substantiate consent where required.
4.6 Credentials and configuration. Client is responsible for its users, account permissions, credentials, campaign configuration, targeting selections, uploaded content and use of Service outputs. Client will promptly notify Starti of unauthorised access to Client’s account.
5. Starti obligations as Processor
5.1 Purpose limitation. Starti will Process Processor Data only on documented instructions, including transfers, unless applicable law requires other Processing. If legally permitted, Starti will inform Client before Processing required by law.
5.2 Confidentiality. Starti will ensure that personnel authorised to Process Processor Data are subject to contractual or statutory confidentiality obligations and receive access only as needed for their duties.
5.3 Access controls. Starti will limit access to Processor Data to authorised personnel and Subprocessors with a need to know, apply role-based privileges and review access on a risk-based schedule.
5.4 Compliance assistance. Taking into account the nature of Processing and information available to Starti, Starti will provide reasonable assistance for Client’s obligations relating to security, Security Incident notification, data protection impact assessments, prior consultations, records of Processing and regulator inquiries. Client will reimburse reasonable, pre-approved costs where assistance materially exceeds ordinary Service support, except to the extent caused by Starti’s breach.
5.5 Records and cooperation. Starti will maintain records required for its Processor activities and make available information reasonably necessary to demonstrate compliance with this DPA, subject to confidentiality, security and privilege restrictions.
5.6 No incompatible commercial use. Starti will not sell or share Processor Data, use it for cross-context behavioural advertising, or retain, use or disclose it outside the direct business relationship with Client, except where Client has separately disclosed the same data to Starti for an activity in which Starti acts as an independent Controller and the applicable legal requirements are met.
6. Independent Controller and Controller-to-Controller terms
6.1 Separate compliance. For Shared Controller Data, each Party will comply with Applicable Data Protection Laws for its own Processing, provide an accessible privacy notice, maintain an appropriate legal basis, implement reasonable security, respond to rights requests, and retain data only as long as necessary for disclosed purposes.
6.2 Specific purposes. A recipient may use Shared Controller Data only for the purposes in Schedule 1, to secure and operate the relevant Services, to comply with law, and for other purposes compatible with the notices and choices provided to Data Subjects. A recipient will not re-identify de-identified data or attempt to derive prohibited sensitive characteristics except where expressly authorised by law and the disclosing Party.
6.3 Signals and suppression. Each Party will transmit and honour legally required consent, opt-out, deletion and suppression signals that it receives and can reasonably associate with the relevant identifier. The Parties will cooperate to prevent a person who has validly opted out from being reintroduced through a refreshed audience or identity file.
6.4 Disclosure minimisation. Each Party will disclose only the data reasonably necessary for the activity. Where practical, the Parties will use pseudonymous advertising identifiers, hashing, aggregation, clean-room or similar controls instead of directly identifying information.
6.5 Inability to comply. A Party will notify the other without undue delay if it determines it can no longer meet the protection required for Shared Controller Data. The disclosing Party may take reasonable steps to stop and remediate unauthorised use, including suspending the affected disclosure.
7. U.S. State Privacy Law terms
7.1 Role-specific treatment. This Section applies when U.S. State Privacy Laws require contractual terms between a Business/Controller and a Service Provider, Contractor, Processor or Third Party. The role for each activity is identified in Schedule 1 and follows the facts.
7.2 Service Provider / Processor activities. For Processor Data, Starti will: (a) Process only for the limited and specified business purposes in the Agreement and Schedule 1; (b) provide the same level of privacy protection required of Client for that data; (c) not sell or share the data; (d) not retain, use or disclose it outside those purposes or the direct business relationship, including for Starti’s own cross-context behavioural advertising; and (e) not combine it with Personal Data received from another person or collected from Starti’s own consumer interaction, except as expressly permitted by applicable law.
7.3 Third Party / Controller activities. For Shared Controller Data received as a Third Party, Starti will use the data only for the specific purposes in Schedule 1, provide the level of protection required by applicable law, allow Client to take reasonable and appropriate steps to help ensure compliant use, notify Client if Starti determines it can no longer comply, and permit Client to take reasonable steps to stop and remediate unauthorised use.
7.4 Verification. Upon reasonable request, Starti will provide information sufficient to demonstrate compliance with this Section. Client may monitor compliance through the audit mechanisms in Section 12. Starti may redact information that would expose other customers, privileged information, trade secrets or material security risk.
7.5 Consumer requests. Starti will provide reasonable assistance for verifiable requests involving Processor Data and will independently respond to requests involving data for which Starti is a Business/Controller. The Parties will cooperate where a request spans both roles.
8. Data Subject requests, assessments and regulators
8.1 Processor Data requests. Client is responsible for responding to Data Subject requests concerning Processor Data. Taking into account the nature of Processing, Starti will provide reasonable technical or organisational assistance where Client cannot fulfil a valid request through self-service features. If Starti receives a request that clearly relates to Processor Data, Starti will direct the requester to Client or notify Client and will not substantively respond unless instructed or legally required.
8.2 Controller Data requests. Each Party will respond to requests concerning data for which it acts as Controller. If a Party reasonably believes the other Party is better placed to identify or act on the relevant data, it may refer the request and provide reasonable cooperation, subject to identity verification and legal restrictions.
8.3 DPIAs and consultations. Starti will provide information reasonably available to it that Client needs to conduct a legally required data protection impact assessment or prior consultation relating to the Services. Starti is not required to disclose other customers’ data, privileged advice, source code or information that would create a material security risk.
8.4 Regulatory inquiries. The Parties will cooperate in good faith with competent regulators for Processing under this DPA. Unless prohibited by law, a Party will notify the other before making a disclosure specifically concerning the other Party and will limit the disclosure to what is legally required.
9. Security and Security Incidents
9.1 Security programme. Starti will maintain a written information security programme with technical and organisational measures designed to provide a level of security appropriate to the risk, taking into account the state of the art, implementation cost, nature and scope of Processing, and risks to individuals. The minimum commitments are described in Schedule 2.
9.2 Security Incident notice. Starti will notify Client without undue delay after becoming aware of a Security Incident. Notice may be delivered in stages and will include, to the extent known and reasonably available: the nature of the incident; affected data and Data Subjects; likely consequences; measures taken or proposed; and a contact for follow-up. Starti’s notice is not an admission of fault or liability.
9.3 Containment and investigation. Starti will take reasonable steps to contain, investigate, mitigate and remediate a Security Incident and preserve relevant evidence. Starti will provide reasonable updates until material remediation is complete.
9.4 External notifications. Client determines whether to notify authorities, Data Subjects or other third parties for a Security Incident involving Processor Data, except where Starti is independently required to notify. Starti will not identify Client in a public statement without Client’s consent unless legally required.
9.5 Client security. Client will use reasonable security for its systems, credentials, integrations, audience files and endpoints. Starti is not responsible for an incident caused solely by Client’s systems, instructions or credentials, without limiting Starti’s duties for its own Processing.
10. Subprocessors and advertising ecosystem recipients
10.1 General authorisation. Client generally authorises Starti to appoint Subprocessors listed in Schedule 3 and to replace or add Subprocessors in accordance with this Section.
10.2 Notice of changes. Starti will provide at least 30 days’ prior notice of a new Subprocessor that will Process Processor Data, through the notification method in Schedule 3, except where an urgent change is reasonably necessary to protect the Services or comply with law. In that case, Starti will provide notice as soon as reasonably practicable.
10.3 Objections. Client may object within 15 days after notice, on reasonable and documented data-protection grounds. The Parties will work in good faith to address the objection. If no reasonable solution is available, Client may discontinue the affected feature or terminate the affected Service without penalty, subject to the Agreement, as its sole remedy for the appointment.
10.4 Subprocessor contracts. Starti will conduct proportionate diligence and enter a written agreement requiring each Subprocessor to protect Processor Data to a standard no less protective than the relevant obligations in this DPA. Starti remains responsible to Client for the Subprocessor’s performance of those obligations to the same extent as if Starti performed them itself.
10.5 Independent recipients. An SSP, DSP, ad exchange, publisher, identity provider, measurement provider or other advertising participant is not a Subprocessor merely because it receives data through the Services. If that participant determines its own purposes and essential means, it is an independent Controller and must be identified, categorised or linked in the independent-recipient portion of Schedule 3 where required.
11. International transfers
11.1 Lawful mechanism. A Party will not make a Restricted Transfer unless it uses a lawful transfer mechanism, such as an adequacy regulation/decision, an applicable certification framework, binding corporate rules, the EU SCCs, the UK Addendum, an approved derogation, or another mechanism permitted by Applicable Data Protection Laws.
11.2 EU SCCs. For a Restricted Transfer governed by the GDPR where the EU SCCs are legally appropriate, the EU SCCs are incorporated by reference and completed by Schedule 4. Module 1 applies to Controller-to-Controller transfers, Module 2 to Controller-to-Processor transfers, and Module 3 to Processor-to-Subprocessor transfers, according to the relevant activity.
11.3 Article 3(2) situations. If the data importer’s Processing is directly subject to the GDPR and the EU SCCs are not an appropriate transfer tool for that reason, the Parties will cooperate in good faith to implement another valid safeguard or regulator-approved contractual mechanism without reducing practical protection.
11.4 United Kingdom. For a Restricted Transfer governed by the UK GDPR, the then-current International Data Transfer Addendum to the EU Commission Standard Contractual Clauses issued by the UK Information Commissioner is incorporated by reference and completed by Schedule 4.
11.5 Switzerland. For a Restricted Transfer governed by the Swiss FADP, the EU SCCs apply with the adaptations in Schedule 4, including references to the Swiss FADP and the competent Swiss authority where required.
11.6 Transfer assessment and supplementary measures. Upon reasonable request, each Party will provide information available to it for a transfer impact assessment. The importer will implement supplementary contractual, technical or organisational measures reasonably necessary to address identified risks, taking into account the nature of the data and Processing.
11.7 Government access. To the extent legally permitted, a data importer receiving a binding government demand for transferred Personal Data will notify the exporter, review the demand’s legality, challenge overbroad or unlawful demands where there are reasonable grounds, disclose only what is legally required, and document the response.
11.8 Certification frameworks. Starti may rely on a recognised certification framework only if and while Starti, Inc. is validly certified for the applicable data and activities. Certification status must be confirmed in Schedule 4 before it is represented as a transfer mechanism.
12. Information and audit rights
12.1 Compliance information. On reasonable request, Starti will make available relevant, current information reasonably necessary to demonstrate compliance for Processor Data, which may include completed security questionnaires, summaries of independent assessments, penetration-test summaries, certifications or other third-party assurance materials, if available and within scope.
12.2 Audit sequence. Client will first use the information in Section 12.1. If that information is reasonably insufficient, Client may conduct one audit in any 12-month period, or an additional audit following a material Security Incident, credible evidence of material non-compliance, or a regulator’s binding request.
12.3 Audit safeguards. An audit requires at least 30 days’ notice unless urgent by law, must occur during normal business hours, be limited to systems and records relevant to Processor Data, avoid unreasonable disruption, and be performed by Client or an independent auditor that is not a competitor and is bound by confidentiality. No audit may expose other customers’ data, privileged material, source code, penetration-test exploit details or information that would create a material security risk.
12.4 Costs and findings. Client bears its audit costs and Starti’s reasonable assistance costs, except where the audit identifies Starti’s material breach. The Parties will promptly discuss findings and a reasonable remediation plan. Audit materials are Starti Confidential Information.
13. Retention, return and deletion
13.1 During the term. Starti will retain Processor Data only as needed for the documented purposes, Client’s instructions, security, dispute preservation and legal requirements. Product-specific periods should be stated in Schedule 1 or the Agreement.
13.2 End of Services. At Client’s choice and subject to available product functionality, Starti will return or delete Processor Data after termination of the affected Services. Unless law requires retention, Starti will complete deletion from active systems and ordinary backup rotation no later than 90 days after termination or Client’s valid written request. Data preserved for law or a documented dispute will remain protected and isolated from ordinary use.
13.3 Controller data. Each Party will delete or anonymise Shared Controller Data according to its applicable retention schedule, notices and legal duties. A Party will apply a valid deletion or suppression signal received from the other where required and technically feasible.
13.4 Deletion confirmation. Upon reasonable written request, Starti will confirm completion of deletion of Processor Data, subject to legally required retention and data maintained only in inaccessible backup media pending rotation.
14. Liability
14.1 Agreement allocation. Each Party’s aggregate liability arising out of or relating to this DPA is subject to the exclusions, limitations and remedies in the Agreement. Claims under this DPA and the Agreement are aggregated for purposes of any cap and do not create a separate or additional cap.
14.2 Mandatory rights. Nothing in this DPA limits liability or rights that cannot lawfully be limited, modifies rights of Data Subjects or authorities under Applicable Data Protection Laws, or alters liability allocated directly between the Parties by mandatory terms of the EU SCCs or UK Addendum.
15. General
15.1 Term and survival. This DPA continues while Starti Processes Personal Data subject to it. Duties that by their nature should survive—including confidentiality, purpose limitation, deletion, audit confidentiality and transfer protections—survive termination.
15.2 Notices. Privacy and Security Incident notices must be sent to the contacts in the Agreement or customer-specific Schedule 1, in addition to any notice method required by the Agreement. Each Party will keep its contact details current.
15.3 Legal changes. If a change in law or binding regulator decision requires amendments, the Parties will cooperate in good faith to implement a compliant replacement. Starti may update this DPA to reflect a replacement transfer mechanism or mandatory law, provided it gives reasonable notice and does not materially reduce protection.
15.4 Governing law. Except where the EU SCCs, UK Addendum or mandatory law specify otherwise, the Agreement’s governing law and dispute provisions apply to this DPA.
15.5 Severability and waiver. An invalid provision will be modified to the minimum extent necessary or severed without affecting the remainder. A failure to enforce a provision is not a waiver.
15.6 Counterparts and electronic signatures. This DPA may be signed in counterparts and electronically. Each counterpart is deemed an original and all counterparts together form one instrument.
How this DPA becomes binding
This webpage is the standard form of Starti, Inc.’s Data Processing Addendum. It becomes binding only when it is incorporated by reference into an Agreement, order form or insertion order accepted by the Parties, or when the Parties execute a signed or electronically signed copy that identifies this version. A customer may request a signable copy from contact@starti.ai.
Schedule 1 — Parties, processing details and role map
Part A. Public contracting reference
| Entity detail | Starti information |
|---|---|
| Full legal name | STARTI, INC. |
| Place of registration | Delaware, United States |
| Tax ID | 36-5165033 |
| Registered address | 8 THE GREEN STE A, KENT, DOVER, DELAWARE 19901, UNITED STATES |
| Contact | contact@starti.ai |
Part B. Activity-by-activity role matrix
| Processing activity | Intended role | Data involved | Purpose / limitation |
|---|---|---|---|
| Account, contracting, billing and support administration | Independent Controller Starti | Client business contacts, account identifiers, communications, invoice and transaction metadata (not full payment-card data). | Account administration, security, billing, customer communications, legal compliance and dispute management. |
| AI Studio / creative generation: Client prompts, uploaded brand assets, creative files and generated outputs | Processor Where content contains Personal Data and is processed to serve Client. | User-provided content; business contacts; images, audio or video containing persons; prompt text; metadata. Prohibited Data remains excluded. | Generate, edit, store and deliver Client-requested creative outputs; maintain and troubleshoot the feature. No identifiable general-model training absent written opt-in. |
| AI DAM / asset management | Processor | Uploaded assets, labels, metadata, authorised user identifiers and activity logs. | Store, organise, retrieve, secure and deliver Client assets and associated metadata. |
| Customer-configured first-party audience onboarding, matching, suppression or activation | Processor / split role Unless a specific data source or activation flow requires an independent Controller role. | Hashed or pseudonymised contact identifiers, advertising/device identifiers, IP address, audience membership, suppression flags and match results. | Onboard, match, segment, suppress and activate audiences according to Client’s configuration; provide match and delivery reporting. |
| Campaign settings, insertion orders, budgets, creatives and customer-specific reporting | Processor For Client-supplied and customer-specific data. | Campaign configuration, creative metadata, Client users, conversion events, performance and reporting data. | Set up, operate, optimise and report campaigns according to Client instructions, subject to Controller activities below. |
| Programmatic / CTV ad request handling, bidding, audience segmentation, frequency management, fraud and brand-safety operations | Independent Controller Generally, for ecosystem-level decision-making; validate per integration. | IP address, cookie/device/CTV identifiers, ad request and interaction data, approximate location, browser/device attributes, inferred interests or segments. | Select, deliver and measure ads; optimise bidding; manage frequency; prevent invalid traffic, abuse and security incidents; operate the advertising marketplace. |
| Cross-context behavioural or targeted advertising | Split role Independent Controller where Starti determines targeting purposes or combines ecosystem data; Processor only where acting solely on Client instructions without independent use. | Pseudonymous online identifiers, browsing or app events, ad interactions, inferred interests, approximate location and audience segment membership. | Personalise and target advertising subject to applicable notice, consent and opt-out requirements. |
| OmniTrack / cross-device measurement and attribution | Split role Processor for customer-directed reporting; independent Controller where Starti determines matching methodology or uses Starti/third-party datasets. | Ad exposure, IP/device identifiers, site/app events, visits, installs, registrations, purchases, revenue or conversion value, and attribution outputs. | Connect exposure to outcomes, produce attribution and campaign reports, detect fraud and evaluate performance. Payment credentials and sensitive purchase detail are excluded. |
| Service telemetry, security, abuse prevention and legal compliance | Independent Controller | User/account identifiers, IP address, authentication events, device/browser data, logs, support and security events. | Secure the Services, detect misuse, maintain availability, investigate incidents, enforce terms and comply with law. |
| Aggregated / anonymised analytics, benchmarks and product or general-model improvement | Outside data-protection scope only after effective anonymisation; Starti determines use. | Statistics or datasets rendered anonymous so they are no longer Personal Data and cannot reasonably be linked to Client or an individual. | Benchmarking, analytics, product improvement and model improvement subject to Section 3.8 and no re-identification. |
Part C. Processor Data — Article 28 processing details
| Required detail | Description |
|---|---|
| Subject matter | Provision of the customer-directed elements of the Services described in the Agreement and Part B. |
| Nature of Processing | Collection, receipt, transmission, organisation, structuring, storage, hosting, pseudonymisation, matching, analysis, generation, retrieval, consultation, use, disclosure as instructed, restriction, return and deletion. |
| Purposes | Provide and support Client-selected features; operate campaigns as configured; generate creative; manage assets; onboard/suppress audiences; produce customer-specific reports; maintain security and availability; comply with lawful instructions. |
| Duration | For the Agreement term and the limited return/deletion period in Section 13, unless a shorter product-specific period or legal retention obligation applies. |
| Frequency | Continuous or event-driven, depending on Client’s campaign, asset, audience, reporting and support activity. |
| Data Subjects | Client personnel and authorised users; Client customers and prospects; website/app visitors; ad viewers and responders; individuals represented in Client-provided creative or content; other persons whose data Client lawfully submits. |
| Personal Data categories | Business contact and account data; IP address; cookie, device, mobile-advertising and CTV identifiers; hashed identifiers where enabled; approximate location; online activity and ad interactions; campaign and conversion events; purchase category/value; audience membership; Client content, prompts, assets and related metadata; support and security logs. |
| Sensitive / Prohibited Data | Not permitted unless expressly identified in a signed order with approved safeguards. See Section 4.4. |
| Deletion period | Processor Data is deleted from active systems and ordinary backup rotation no later than 90 days after termination of the affected Services or receipt of a valid deletion request, unless applicable law requires longer retention. Data retained solely for legal compliance or dispute preservation remains protected and is not used for other purposes. |
| Processing / access locations | Processor Data may be hosted, processed or accessed through Amazon Web Services infrastructure in the United States and Southeast Asia and by authorised personnel or service providers in those regions, subject to the transfer safeguards in this DPA. |
Part D. Controller-to-Controller sharing details
| Required detail | Description |
|---|---|
| Data Subjects | Ad viewers/responders; website/app visitors; Client prospects/customers; Client business contacts; persons represented by pseudonymous advertising identifiers. |
| Data categories | Pseudonymous online identifiers; IP address; browser/device/CTV attributes; approximate location; ad request, exposure and interaction events; audience/interest inferences; campaign, conversion and attribution signals; consent and opt-out signals. |
| Starti purposes | Programmatic/CTV ad selection and delivery; bidding and optimisation; frequency management; audience segmentation; cross-context/targeted advertising where permitted; measurement and attribution; fraud, security and marketplace integrity; compliance. |
| Client purposes | Campaign planning and activation; suppression; measurement and reporting; analytics; lawful marketing and customer engagement. |
| Recipients / categories | Publishers, supply-side platforms, ad exchanges, measurement/attribution providers and Client-authorised partners, as completed in Schedule 3. |
| Transfer frequency | Continuous or event-driven during active campaigns and measurement windows. |
| Retention | Starti retains advertising, campaign, measurement and attribution data during the applicable Services only for as long as reasonably necessary for the disclosed purposes. Following termination of the affected Services or a valid deletion request, such data is deleted or anonymised within 90 days, unless a longer period is required by applicable law or necessary for documented dispute preservation. |
Schedule 2 — Minimum technical and organisational measures
| Control area | Contractual baseline |
|---|---|
| 1. Governance and risk | Maintain written security policies, assigned ownership, risk assessments and periodic review appropriate to the Services and data. Track material risks and remediation to accountable owners. |
| 2. Personnel and confidentiality | Screen personnel where lawful and appropriate; require confidentiality; provide recurring security and privacy training; apply joiner, mover and leaver processes; and discipline policy violations. |
| 3. Data inventory and classification | Maintain reasonable inventories of systems and data flows; classify data by sensitivity; document retention; and apply handling rules proportionate to classification. |
| 4. Identity and access management | Use unique identities, role-based and least-privilege access, strong authentication, multi-factor authentication for privileged or otherwise high-risk access, timely revocation, and periodic access review. |
| 5. Encryption and key management | Use industry-standard encryption for Processor Data in transit over public networks and at rest where appropriate to risk. Restrict and rotate cryptographic keys under documented procedures. |
| 6. Infrastructure and network security | Harden cloud and network configurations, segment environments where appropriate, restrict administrative interfaces, use firewalls or equivalent controls, monitor material configuration drift, and protect production from unauthorised access. |
| 7. Secure development and change | Apply documented development and change-management practices, code review and testing proportionate to risk, dependency management, secrets protection, separation of duties where practical, and controlled production deployment. |
| 8. Vulnerability management | Scan systems and dependencies on a risk-based schedule, prioritise remediation based on severity and exploitability, perform periodic penetration testing by qualified personnel, and track exceptions to closure. |
| 9. Logging and monitoring | Log material authentication, administrative and security events; protect logs from unauthorised modification; synchronise time where practical; monitor for anomalous activity; and retain logs for a period appropriate to investigation and legal needs. |
| 10. Incident response | Maintain and test an incident-response plan addressing triage, containment, eradication, recovery, evidence preservation, communications and lessons learned. Maintain an escalation path for privacy and customer notification. |
| 11. Availability and resilience | Use backups, redundancy and recovery procedures appropriate to the Services; protect backups; test restoration on a risk-based schedule; and maintain business-continuity and disaster-recovery plans for material systems. |
| 12. Supplier assurance | Conduct proportionate security and privacy diligence before onboarding material Subprocessors; impose written security, confidentiality, incident and deletion obligations; and reassess based on risk or material change. |
| 13. Data minimisation and disposal | Limit collection and access to what is needed; use pseudonymisation or aggregation where practical; apply documented retention; securely delete or render data unrecoverable when no longer required; and control removable media. |
| 14. Physical and environmental security | Rely on hosting providers with physical access controls, monitoring, environmental protections and media-handling measures; protect Starti offices and devices proportionate to risk. |
| 15. Customer isolation and testing | Use logical controls designed to prevent one customer from accessing another’s data. Avoid use of live Processor Data in non-production environments unless necessary and protected to an equivalent standard. |
| 16. Assurance evidence | Starti maintains internal records reasonably necessary to demonstrate the security measures described in this Schedule. Starti does not currently represent that it holds an independent security certification or third-party audit report. |
Security-specific completion fields
| Field | Validated value |
|---|---|
| Security owner | Starti Engineering and Security Team, under executive management oversight. |
| Incident contact | contact@starti.ai, with internal escalation to the Starti Engineering and Security Team. |
| Primary hosting | Amazon Web Services infrastructure in the United States and Southeast Asia. |
| Backup / disaster recovery | Backups and disaster-recovery resources are maintained using Amazon Web Services infrastructure in the United States and Southeast Asia. Ordinary backup copies are rotated or deleted within 90 days after termination of the affected Services or a valid deletion request. Restoration procedures are tested on a risk-based schedule. |
| Encryption | Industry-standard encryption is used for Processor Data in transit over public networks and at rest where appropriate to the risk and supported by the applicable service. |
| Privileged access | Privileged access is restricted by role and least privilege, protected by strong authentication and multi-factor authentication for high-risk access, reviewed on a risk-based schedule, and revoked when no longer required. |
| Vulnerability management | Systems and dependencies are assessed on a risk-based schedule. Remediation is prioritised according to severity, exploitability and potential impact, with material issues tracked through closure. |
| Independent assurance | None currently maintained or represented by Starti. Starti will identify any future certification or independent audit report only while it is valid and applicable to the Services. |
Schedule 3 — Subprocessors and independent recipients
Part A. Authorised Subprocessors
| Provider legal entity | Category | Service / purpose | Processing location(s) | Data categories |
|---|---|---|---|---|
| Amazon Web Services, Inc. | Cloud infrastructure | Hosting, storage, networking, backup and disaster recovery. | United States and Southeast Asia. | Processor Data hosted or transmitted through the Services, including account, campaign, event, log and pseudonymous advertising data. |
| AppsFlyer | Mobile measurement partner integration | Mobile campaign measurement and attribution, when enabled by Client configuration. | Locations selected or used under the applicable AppsFlyer service terms and Client configuration. | Pseudonymous device identifiers, ad exposure, interaction, install, conversion and attribution events. |
| Adjust | Mobile measurement partner integration | Mobile campaign measurement and attribution, when enabled by Client configuration. | Locations selected or used under the applicable Adjust service terms and Client configuration. | Pseudonymous device identifiers, ad exposure, interaction, install, conversion and attribution events. |
| Singular | Mobile measurement partner integration | Mobile campaign measurement and attribution, when enabled by Client configuration. | Locations selected or used under the applicable Singular service terms and Client configuration. | Pseudonymous device identifiers, ad exposure, interaction, install, conversion and attribution events. |
Part B. Independent advertising and measurement recipients
| Recipient category | Typical data | Purpose | Disclosure / list |
|---|---|---|---|
| Supply-side platforms and publishers | Ad request, device/CTV/online identifiers, IP, approximate location, consent signals and ad delivery events. | Ad opportunity, delivery, frequency, reporting and marketplace integrity. | Google and RTBMax. |
| Ad exchanges / marketplace partners | Pseudonymous online identifiers, request/context data, bid and delivery events. | Programmatic auction, delivery and settlement. | No additional marketplace partners currently used beyond the supply partners listed above. |
| Demand-side or buying partners | Campaign, bid, impression/click and pseudonymous identifier data. | Campaign execution, optimisation and reporting. | None currently used; Starti operates its own DSP. |
| Identity / matching providers | Hashed or pseudonymous identifiers, device identifiers, match and suppression signals. | Audience matching, cross-device measurement and suppression. | None currently used. |
| Measurement / attribution providers | Exposure, interaction, conversion and pseudonymous identifiers. | Campaign measurement, attribution, reach and frequency. | AppsFlyer, Adjust and Singular, when enabled by Client configuration. |
Part C. Change notice
| Field | Value |
|---|---|
| Subprocessor list | Amazon Web Services, Inc.; AppsFlyer; Adjust; Singular. |
| Notice method | Email notice to the Client privacy contact or a notice delivered through the Client’s Starti account. |
| Notice recipient | Client privacy contact in Schedule 1, unless Client registers another address. |
| Standard advance notice | 30 days, subject to the urgent-change exception in Section 10.2. |
Schedule 4 — International transfer mechanism completion
Part A. EU SCC selections
| SCC item | Selection / completion |
|---|---|
| Applicable Modules | Module 1 for Controller-to-Controller transfers; Module 2 for Client Controller-to-Starti Processor transfers; Module 3 where Client is a Processor and Starti is its Subprocessor. Each Module applies only to its corresponding activity. |
| Clause 7 — Docking | Applies. |
| Clause 9 — Subprocessors | Option 2, general written authorisation. Advance-notice period: 30 days, subject to Section 10.2. |
| Clause 11 — Independent redress body | Does not apply unless the Parties expressly select it in a signed amendment. |
| Clause 17 — Governing law | Law of Ireland, unless another EU Member State law is required and selected in a signed order. |
| Clause 18 — Courts | Courts of Ireland, unless another eligible EU Member State forum is selected in a signed order. |
| Annex I.A — Parties | The exporter and importer details are in the customer-specific DPA, order form or Agreement. Signature of that customer-specific record is deemed signature of the applicable EU SCC Module. |
| Annex I.B — Transfer description | Schedule 1 Parts B–D, limited to the activities and data subject to a Restricted Transfer. |
| Annex I.C — Supervisory authority | For Processing subject to United States privacy law, Starti complies with applicable federal requirements and the privacy laws and competent authorities of the relevant U.S. state. For a transfer subject to the GDPR and the EU SCCs, the competent supervisory authority is determined under Clause 13 of the SCCs according to the relevant data exporter, Data Subjects and transfer. Starti also complies with applicable EU data-protection requirements and transfer safeguards for such Processing. |
| Annex II — Security measures | Schedule 2. |
| Annex III — Subprocessors | Schedule 3 Part A, for Modules 2 and 3. |
Part B. UK Addendum completion
| UK Addendum item | Completion |
|---|---|
| Table 1 — Parties | The customer-specific DPA, order form or Agreement. Key contacts are the privacy contacts recorded there. |
| Table 2 — Selected SCCs | The EU SCC Module(s) and selections in Part A of this Schedule. |
| Table 3 — Appendix information | Schedule 1 Parts B–D; Schedule 2; and Schedule 3 Part A. |
| Table 4 — Ending the Addendum | Either Party may end the UK Addendum as permitted by Section 19 of the mandatory clauses. |
| Approved version | The UK Information Commissioner’s mandatory addendum in force on the DPA Effective Date, as updated or replaced under its terms. |
Part C. Swiss adaptations
| Adaptation | Application |
|---|---|
| Law references | References to the GDPR include the Swiss FADP to the extent it governs the transfer; references to EU/Member State include Switzerland where appropriate. |
| Personal Data | Includes data relating to an identified or identifiable individual protected by the Swiss FADP. |
| Supervisory authority | The Swiss Federal Data Protection and Information Commissioner is competent where the Swiss FADP applies; an EU authority may remain competent where the GDPR also applies. |
| Data Subject rights | The SCCs protect Swiss Data Subjects to the extent required by the Swiss FADP. |
| Forum | The SCC forum selection does not prevent rights or proceedings before competent Swiss authorities or courts where required by Swiss law. |
Part D. Transfer and localisation facts
| Fact | Validated value |
|---|---|
| Customer-specific transfer facts | Exporter/importer entities, access countries, adequacy decisions, TIA and supplementary measures are completed in the customer-specific DPA, order form or Agreement. |
| Starti public transfer statement | Starti is established in the United States and may host, process or permit access to Personal Data in the United States and Southeast Asia through Amazon Web Services and the authorised providers listed in Schedule 3. Starti follows applicable U.S. state privacy requirements and, where EU, UK or Swiss Personal Data is transferred internationally, uses the applicable Standard Contractual Clauses, UK Addendum, adequacy decision or other lawful transfer mechanism. Starti operates its SSP and advertising-partner integrations in accordance with the applicable data-use and privacy requirements established by those partners for the regions in which campaigns are delivered. |