Data Processing Agreement (DPA) / Service Provider Agreement (SPA / LSPA)

This Agreement is designed to satisfy the Service Provider requirements under the California Privacy Rights Act (CCPA/CPRA) §1798.140(v) and the Processor requirements under GDPR Art.28.

1. Role and Purpose Limitation

Aidenix (Aidenix, Inc.) acts solely as a Service Provider under CCPA/CPRA and as a Processor under GDPR. Processing is strictly limited to defined business purposes requested by the Client, including data enrichment, psychographic signal generation, risk analysis, and lead scoring, based only on Client-submitted identifiers.

2. No Sale or Share

Processor shall not sell or share Personal Information as defined by CCPA/CPRA. No cross-context behavioral advertising, unrelated profiling, or onward transfer of Personal Information.

3. Lookalike and Matching

Matching or lookalike modeling is performed exclusively with Client-submitted data and Processor’s de-identified datasets. Results are returned only to the Client or Client-authorized platforms and are not retained, reused, or resold.

4. Confidentiality and Security

Processor ensures the confidentiality of all Personal Information. Appropriate administrative, technical, and organizational safeguards are implemented at or above industry standards. Sub-processors must be contractually bound to equivalent protections.

5. Rights and Assistance

Processor supports Client in fulfilling consumer rights under applicable laws (access, correction, deletion, opt-out). Data is deleted or de-identified upon Client’s instruction or contract termination.

6. Restrictions

Outputs must not be used as the sole basis for adverse decisions (e.g., hiring, credit, housing). Reverse engineering of enrichment signals is prohibited.

7. Data Combination Limitations

Processor may combine Client data with its own datasets only as necessary to fulfill agreed business purposes. Such combinations must not transform Client data into a proprietary asset.

8. Retention and Deletion

Personal Information is retained only as long as necessary for the stated business purpose. Data is deleted or de-identified promptly upon request or contract termination.

9. Liability

Processor’s liability is limited to direct damages only. Each party is responsible for its own compliance with applicable regulations.

10. Governing Law

This Agreement is governed by the laws of California and, where applicable, GDPR.