Part A — Roles of the parties
A0. Definitions
A0.1 "SignalBridge Technology" means any software development kit, JavaScript tag, pixel, API integration or other code or interface made available by SignalBridge and deployed by the Partner on a Property, by means of which personal data is collected from an end user's device and transmitted to SignalBridge.
A0.2 "Permitted Purpose" means the selection, delivery, frequency capping and measurement of advertising, and the detection of invalid traffic and fraud, in each case in accordance with the Agreement.
A0.3 "Independent Transfer" means any transmission of personal data between the parties that does not involve SignalBridge Technology deployed on a Property, including any transmission through a third-party supply-side platform, ad exchange or server-to-server integration.
A1. Joint processing
A1.1 This Part A1 applies solely to the collection of personal data through SignalBridge Technology on the Partner's app, website or other property (the "Property") and its subsequent transmission to SignalBridge for the Permitted Purpose (the "Joint Processing"). In respect of the Joint Processing, the parties are joint controllers in accordance with Article 26 GDPR.
A1.2 Each party shall notify the other without undue delay, and in any event within five (5) business days, if it is contacted by a supervisory authority or by a data subject in relation to the Joint Processing. Notices to SignalBridge are to be sent to [email protected].
A1.3 The allocation of responsibilities for the Joint Processing is set out in the matrix in Part A3. Irrespective of that allocation, a data subject may exercise rights against either party.
A2. Independent processing
A2.1 Any processing carried out by either party after completion of the Joint Processing, and any processing of personal data received by way of an Independent Transfer, is carried out by each party as a separate and independent controller. Neither party is a processor of the other in respect of such processing.
A2.2 Legal basis and signals. Each party is responsible for establishing its own legal basis. The transmitting party warrants that, before each Independent Transfer, all consents required under Article 5(3) of the ePrivacy Directive as implemented in the relevant country and under Article 6 GDPR have been obtained, and that any consent or preference signal transmitted with the data (including any IAB TCF TC String or Global Privacy Platform string) accurately reflects the permission actually obtained. A signal indicating reliance on legitimate interests in place of consent shall not be transmitted where consent was required.
A2.3 Purpose limitation. The receiving party shall process personal data received by way of an Independent Transfer only for the Permitted Purpose. In particular it shall not (a) combine that data with other datasets in order to re-identify a data subject; (b) disclose that data onward except to recipients whose involvement is necessary for the Permitted Purpose and who are bound by equivalent obligations; or (c) use that data to train, enrich or validate models for any purpose other than the Permitted Purpose, provided that each party may use such data to operate, secure, measure and improve the services comprised in the Permitted Purpose, including bid optimisation, delivery, measurement and invalid-traffic and fraud detection models, in each case in accordance with applicable law.
A2.4 Transfers. Part B applies to each Independent Transfer, and Module One of the Standard Contractual Clauses applies between the parties as separate and independent controllers.
A2.5 Data subject requests and authorities. Each party shall handle requests relating to its own processing, and shall forward any request that is properly directed to the other party without undue delay and in any event within five (5) business days. Each party shall notify the other within three (3) business days if it is contacted by a supervisory authority in relation to an Independent Transfer.
A2.6 Breaches. The Partner shall notify SignalBridge of any personal data breach affecting personal data transmitted or received by way of an Independent Transfer without undue delay and in any event within twenty-four (24) hours of becoming aware of it. SignalBridge shall notify the Partner of any such breach without undue delay after becoming aware of it, and shall provide such information and reasonable cooperation as the Partner reasonably requires in order to meet its own notification obligations. Information may be provided in phases where it is not reasonably available at the time of the initial notification. A notification under this clause is not, of itself, an acknowledgement of fault or liability.
A2.7 Verification and suspension. SignalBridge may require evidence that the consents referred to in clause A2.2 have been obtained and that the signals transmitted accurately reflect them, including by sampling the inventory supplied and inspecting the consent interface presented to end users. Where SignalBridge identifies that valid consent has not been obtained, or that a transmitted signal misrepresents the permission obtained, it may suspend the affected supply immediately and withhold payment for the affected inventory.
A3. Allocation of responsibilities (Article 26(1))
| # | Matter | Partner | SignalBridge |
|---|---|---|---|
| A | Legal basis and consent (Art 6, and Art 5(3) ePrivacy) | Obtains and maintains all consents required before information is read from or stored on the device, and transmits the resulting consent signal accurately | Acts only in accordance with the signal received; does not process where no valid signal is present other than for contextual delivery |
| B | Information to data subjects (Arts 13–14) ) | Provides the required information at the point of collection, including a link to the SignalBridge End-User Privacy Notice | Maintains and publishes the End-User Privacy Notice and keeps it accurate |
| C | Essence of the arrangement (Art 26(2)) | Makes the essence of these terms available to data subjects, including the division of responsibilities and the contact point | Publishes a summary of the arrangement in the End-User Privacy Notice |
| D | Data subject rights (Arts 15–20) | Handles requests relating to processing on the Property and forwards other requests without undue delay | Handles requests relating to personal data processed after transmission, and responds within statutory time limits |
| E | Records of processing (Art 30) | Maintains its own record for the Joint Processing | Maintains its own record for the Joint Processing |
| F | Security (Art 32) | Responsible for correct technical implementation and configuration of the SignalBridge Technology on the Property | Responsible for the security of the SignalBridge Technology and of its own systems |
| G | Personal data breaches (Arts 33–34) | Notifies SignalBridge without undue delay and in any event within twenty-four (24) hours of becoming aware of a breach affecting the Joint Processing | Notifies the Partner without undue delay, and each party discharges its own notification obligations |
A3.1 The Partner represents, warrants and undertakes on a continuing basis that it shall not configure or deploy the SignalBridge Technology on, and shall not supply inventory from, any Property that is directed at children or at minors, or whose content falls within a category not permitted under the Advertising and Prohibited Content Policy, in each case without SignalBridge's prior written approval. The Partner shall not transmit to SignalBridge, and shall not enable SignalBridge to collect, any special category data, any data relating to children or minors, or any data relating to a data subject who has exercised a right to opt out of targeted advertising, sale or sharing. Where the Partner is not itself the publisher, it shall procure that each publisher whose inventory it supplies complies with this clause A3.1.
A4. Consent signals
A4.1 Where the Partner or a Property uses an industry privacy or consent framework, including the IAB Europe Transparency and Consent Framework (“TCF”), the IAB Tech Lab Global Privacy Platform (“GPP”), the US Privacy String or the Google Additional Consent String, the Partner shall comply with the requirements applicable to its use of that framework and shall ensure that any consent or privacy signals transmitted to SignalBridge are accurate, current and not misleading. The Partner remains responsible for the lawfulness of its own processing irrespective of its participation in any such framework.
A4.2 The Partner shall not transmit any signal indicating consent, opt-in, legitimate interest or other permission or legal basis unless the relevant requirements for transmitting that signal have been satisfied.
A4.3 This Part A4 applies equally to Independent Transfers, and the Partner shall procure that each publisher whose inventory it supplies meets the same standard.
A4.4 SignalBridge may take appropriate action where it reasonably believes that inventory or privacy signals supplied by the Partner do not comply with applicable law, this Agreement or applicable industry framework requirements, including suspending the affected inventory or Property.
Part B — International transfers
B1. Where a party transfers personal data covered by these terms from the European Economic Area to a country not benefiting from an adequacy decision, the parties enter into the Standard Contractual Clauses approved by Commission Implementing Decision (EU) 2021/914, and Module One (controller to controller) applies. Clause 7 (docking) applies. The optional redress clause in Clause 11(a) does not apply. In Clause 17, the governing law is the law of the Republic of Cyprus, and in Clause 18(b) the forum is the courts of the Republic of Cyprus. Annex I Part A is completed by the details of the parties set out in the Agreement; Annex I Part B and Annex II are completed by the Data Processing Description and the Technical and Organisational Measures set out in Annex 1 and Annex 2 to these terms; and Annex I Part C is completed in accordance with clause B1.1.
B1.1 The competent supervisory authority for the purposes of Annex I Part C is the supervisory authority of the Member State in which the data exporter is established or, where the data exporter is not established in the European Economic Area, the supervisory authority of the Member State in which the data exporter's Article 27 representative is established or in which the data subjects whose personal data is transferred are located.
B2. For transfers subject to the UK GDPR, the Standard Contractual Clauses apply as amended by the International Data Transfer Addendum issued by the Information Commissioner, with Tables 1 to 3 completed by reference to clause B1 and the "Importer" option selected in Table 4.
B3. For transfers subject to the Swiss Federal Act on Data Protection, the Standard Contractual Clauses apply with references to the GDPR read as references to the Swiss Act, the competent authority being the Federal Data Protection and Information Commissioner, and the governing law and forum being Swiss.
B4. Where required by applicable law, the transferring party shall carry out and record an assessment of the circumstances of the transfer, taking into account applicable regulatory guidance, and shall implement such supplementary measures as it reasonably considers necessary. Where SignalBridge grants access to personal data to personnel or contractors located outside the EEA, such access shall be provided only through controlled means, and the parties acknowledge that the measures recorded in Annex 2 form part of the basis on which the transfer is made.
B5. If a transfer mechanism relied on under this Part B ceases to be valid, the parties shall work together in good faith to put an alternative mechanism in place without undue delay, and pending that, the transferring party shall suspend the affected transfers.
Part C — Security, audit, retention and breaches
C1. Each party shall implement and maintain appropriate technical and organisational measures designed to ensure a level of security appropriate to the risks presented by the processing, in accordance with applicable data protection laws. The measures maintained by SignalBridge are described generally in Annex 2 and may be updated from time to time, provided that no update shall materially reduce the overall level of protection for personal data.
C2. Each party shall, upon reasonable written request, provide the other party with information reasonably necessary to demonstrate its compliance with its obligations under these terms. Such a request may be made no more than once in any twelve (12) month period (save where required by a competent supervisory authority or following a personal data breach), shall be made on at least thirty (30) days' prior written notice, shall be at the requesting party's cost, shall be subject to confidentiality, and shall not extend to premises, systems, source code, or information relating to other customers or partners. The responding party may satisfy such a request by providing a summary of its policies, a current third-party audit report or a security certification (such as ISO/IEC 27001 or SOC 2) where one is available. Where required by applicable law or a competent supervisory authority, the parties shall reasonably cooperate in relation to any audit, inquiry or compliance assessment concerning the processing covered by these terms.
C3. Each party shall retain personal data only for as long as reasonably necessary for the purposes for which it is processed, subject to applicable legal, regulatory, accounting or other legitimate retention requirements. Personal data that is no longer required shall be deleted or anonymised in accordance with applicable law and the party’s applicable retention practices.
C4. Without prejudice to clause A2.6, each party shall notify the other without undue delay after becoming aware of a personal data breach that materially affects the processing covered by these terms and shall provide such information and reasonable cooperation as may be necessary to enable the other party to comply with its applicable data breach notification obligations. Information may be provided in phases where it is not reasonably available at the time of the initial notification.
Neither party shall, where reasonably practicable, make a public statement identifying the other party in connection with a personal data breach without prior consultation, except where required by applicable law or a competent authority.
Part D — General
D1. These terms form part of the Agreement. In the event of conflict between these terms and the remainder of the Agreement in relation to the processing of personal data, these terms prevail. In the event of conflict between these terms and the Standard Contractual Clauses, the Standard Contractual Clauses prevail. In the event of conflict between these terms and a Jurisdiction-Specific Annex, that Annex prevails in respect of the jurisdiction to which it relates.
D2. These terms are made in the English language; any translation is for convenience only.
D3. Each party may engage service providers and other recipients to process personal data covered by these terms for the Permitted Purpose, provided that each such recipient is bound by written obligations no less protective than those in these terms. SignalBridge maintains a list of the categories of recipients to which it discloses personal data for the Permitted Purpose, which is available on request or at the address notified from time to time.
D4. Any liability of either party under or in connection with these terms is subject to the limitations and exclusions of liability set out in the Agreement, save to the extent that applicable law or the Standard Contractual Clauses provide otherwise.
D5. SignalBridge may update these terms from time to time where necessary to reflect a change in applicable law, in regulatory guidance, in an approved transfer mechanism, or in the manner in which the Permitted Purpose is carried out. SignalBridge will give reasonable prior notice of any update that materially and adversely affects the Partner, and the Partner may terminate the Agreement before the update takes effect if it does not accept it.
D6. Jurisdiction-Specific Annexes. The processing of personal data governed by the law of a jurisdiction identified in a Jurisdiction-Specific Annex is subject to the additional or alternative terms set out in that Annex, which forms part of these terms. Jurisdiction-Specific Annexes are to be issued for, at least: the United States (state consumer privacy laws, including the California Consumer Privacy Act as amended, and the Colorado, Connecticut, Utah, Virginia and Texas privacy laws, and the Children's Online Privacy Protection Act); Brazil (LGPD); and the principal Asia-Pacific and Middle East markets in which the parties operate. Until a Jurisdiction-Specific Annex is issued for a jurisdiction, each party shall process personal data governed by the law of that jurisdiction in accordance with these terms and with applicable law, and neither party shall sell or share personal data received from the other, or use it for cross-context behavioural advertising, except as permitted by applicable law and by the signals received.
Annex 1 — Data processing description
| Item | Detail |
|---|---|
| Categories of data subjects | End users of the Partner's apps and websites |
| Categories of personal data | Device and network identifiers; device and technical characteristics; approximate location; advertising opportunity context; interaction data; consent signals |
| Special category data | None. Neither party shall transmit special category data |
| Frequency of transfer | Continuous, on a per-request basis |
| Nature and purpose | Selection, delivery and measurement of advertising; fraud and invalid traffic detection |
| Retention | As set out in the End-User Privacy Notice and clause C3 |
| Competent supervisory authority | Determined in accordance with clause B1.1 |
Annex 2 — Technical and organisational measures
- SignalBridge maintains appropriate technical and organisational measures designed to protect personal data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure or access. Such measures are implemented having regard to the nature, scope, context and purposes of the processing and the risks presented by the processing, and may include, as appropriate:
- Access control: measures designed to restrict access to personal data to authorised personnel on a need-to-know basis, including appropriate authentication and access management controls.
- Segregation: logical or other appropriate measures designed to prevent unauthorised access between customers, systems or environments.
- Remote access: controls designed to secure remote access to systems processing personal data and to limit such access to authorised personnel.
- Encryption: appropriate encryption or other security measures for personal data in transit and at rest, where appropriate.
- Pseudonymisation and data minimisation: measures designed to reduce the identifiability and amount of personal data used or made available where appropriate for the relevant processing purpose.
- Logging and monitoring: appropriate logging, monitoring and detection measures designed to identify and respond to unauthorised or anomalous activity.
- Vendor management: appropriate contractual, security and data protection controls for service providers and processors that process personal data on SignalBridge’s behalf.
- Incident management: processes designed to identify, assess, manage and respond to personal data and security incidents.
- Business continuity: appropriate backup, resilience and recovery measures designed to support the availability and restoration of systems and data.
- SignalBridge may update these measures from time to time to reflect changes in technology, processing activities, risks and applicable legal requirements, provided that such updates do not materially reduce the overall level of protection for personal data.