Data Processing, Data Privacy, and Information Security Addendum

Last Updated: July 17, 2026

This Data Processing, Data Privacy, and Information Security Addendum ("DPA/ISA") forms part of the BrightLake Services Agreement or other written or electronic terms of service agreement ("Agreement") between BrightLake International Inc. and the entity or individual agreeing to these terms ("Customer").

This DPA/ISA applies where, and to the extent that, BrightLake Processes Personal Data on behalf of Customer as a Processor when providing Services under the Agreement. This DPA/ISA does not apply where BrightLake determines the purpose and means of the Processing of Personal Data independently.

By executing the Agreement that incorporates this DPA/ISA by reference, Customer enters into this DPA/ISA on behalf of itself and, to the extent required under applicable Data Protection Laws, in the name and on behalf of its Authorized Affiliates.

All capitalized terms not defined in this DPA/ISA shall have the meanings set forth in the Agreement.

1. Definitions

For the purposes of this DPA/ISA, the following terms shall have the meanings set out below:

1.1 "Advertising Data" means data relating to advertising campaigns and advertising performance, including campaign performance metrics, attribution data, conversion data, bid information, creative asset metadata, keyword data, budget information, and related analytics processed through the Services. Advertising Data is generally business or platform-provided data and is not intended to include Personal Data unless expressly made available by Customer or a Third-Party Platform.

1.2 "Affiliate" means any entity that directly or indirectly controls, is controlled by, or is under common control with the subject entity, where "control" means direct or indirect ownership of more than 50% of the voting interests of the subject entity.

1.3 "AI-Powered Features" means the artificial intelligence and machine learning capabilities provided as part of the Services that process and analyze Customer Data and user inputs to generate outputs, including automated insights, recommendations, analytics, reports, and forecasts.

1.4 "Authorized Affiliate" means any of Customer's Affiliate (s) permitted to use the Services pursuant to the Agreement.

1.5 "Controller" means the natural or legal person, public authority, agency, or other body which, alone or jointly with others, determines the purposes and means of the Processing of Personal Data.

1.6 "Customer Data" means any data, content, or information that Customer or its Authorized Users upload, submit, store, transmit, connect, or otherwise make available through the Services, including Advertising Data, business data, campaign data, performance metrics, market or competitive intelligence queries, AI prompts and outputs, and data retrieved from Third-Party Platforms via authorized API connections. Customer Data may include Personal Data, but only to the extent such data relates to an identified or identifiable natural person.

1.7 "Data Protection Laws" means all laws and regulations applicable to the Processing of Personal Data under the Agreement, including:
(a) the General Data Protection Regulation(EU) 2016/679("GDPR");
(b) the UK Data Protection Act 2018 and UK GDPR;
(c) the Swiss Federal Act on Data Protection("FADP");
(d) any applicable U.S. state privacy laws;
(e) the Brazilian Lei Geral de Proteção de Dados ("LGPD"); and
(f) any other applicable privacy and data protection legislation.

1.8 "Data Subject" means the identified or identifiable natural person to whom Personal Data relates.

1.9"EEA" means the European Economic Area.

1.10 "Authorized User" means any individual authorized by Customer to access or use the Services on behalf of Customer.

1.11 "Personal Data" means any information relating to an identified or identifiable natural person that is Processed by BrightLake on behalf of Customer in connection with the Services.

1.12 "Personal Data Breach" means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, Personal Data transmitted, stored, or otherwise Processed.

1.13 "Processing"(and "Process")means any operation or set of operations performed on Personal Data or sets of Personal Data, whether or not by automated means, such as collection, recording, organization, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure, or destruction.

1.14 "Processor" means a natural or legal person, public authority, agency, or other body which Processes Personal Data on behalf of the Controller.

1.15 "Security Incident" means any accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to Customer Data, including Personal Data, on systems managed or controlled by BrightLake or its Sub-processors.

1.16 "Sensitive Data" means Personal Data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, genetic data, biometric data for uniquely identifying a natural person, data concerning health, sex life or sexual orientation, or data relating to criminal convictions and offenses.

1.17 "Services" means the BrightLake AI-powered advertising management platform and any related services provided to Customer pursuant to the Agreement.

1.18 "Standard Contractual Clauses" or "SCCs" means:

  1. for transfers subject to the GDPR, the standard contractual clauses for the transfer of personal data to third countries pursuant to Commission Implementing Decision (EU) 2021/914;

  2. for transfers subject to the UK GDPR, the International Data Transfer Addendum to the EU Commission Standard Contractual Clauses issued by the UK Information Commissioner; and

  3. for transfers subject to the FADP, the applicable clauses recognized under Swiss law.

1.19 "Subprocessor" means any third party engaged by BrightLake to Process Personal Data on behalf of Customer in connection with the Services. For clarity, third parties that provide data, content, market intelligence, AI model services, or infrastructure to BrightLake but do not Process Personal Data on behalf of Customer may be identified separately as service providers or third-party providers and are not Subprocessors for purposes of this DPA/ISA unless they Process Personal Data on behalf of Customer.

1.20 "Third-Party AI Providers" means third-party artificial intelligence and machine learning service providers including large language model providers, embedding model providers, and related AI infrastructure providers, that BrightLake uses to provide AI-Powered Features, as described in Annex 4 or other applicable service documentation.

1.21 "Third-Party Platforms" means external platforms, services, or application programming interfaces, or data sources that are not owned or controlled by BrightLake and that are integrated with, accessed through, or used in connection with the Service, including, without limitation, Apple Ads Services, MMPs, customer-authorized advertising or measurement platforms, and third-party market, app, keyword, creative, or competitive intelligence data providers.

2. Scope and Application

2.1 Scope of Processing. This DPA/ISA applies only to the extent BrightLake Processes Personal Data contained in Customer Data on behalf of Customer when providing the Services. Customer Data that does not constitute Personal Data is governed by the Agreement and not by this DPA/ISA, except for confidentiality, security, and other contractual commitments that expressly apply to Customer Data. The subject matter, nature, purpose, and duration of the Processing of Personal Data, as well as the types of Personal Data and categories of Data Subjects, are described in Annex 1 (Details of Processing).

2.2 Roles of the Parties.

  1. Customer as Controller. Customer is the Controller of Personal Data contained in Customer Data. Customer determines the purposes and means of Processing such Personal Data and is responsible for compliance with Data Protection Laws applicable to Controllers, including establishing a lawful basis for Processing and providing appropriate notices to Data Subjects.

  2. BrightLake as Processor. BrightLake is the Processor of Personal Data contained in Customer Data and shall Process such Personal Data only on behalf of and in accordance with Customer's documented instructions as set forth in this DPA/ISA, the Agreement, and any subsequent written instructions agreed upon by the parties.

  3. Customer as Processor. Where Customer acts as a Processor on behalf of a third-party Controller, BrightLake shall act as Customer's Subprocessor with respect to the relevant Personal Data.

  4. Aggregated and De-identified Data. For the avoidance of doubt, BrightLake may process Aggregated or De-identified Data for internal analytics, service improvement, testing, evaluation, benchmarking, research, and product development purposes, provided that such data does not identify Customer, any Authorized User, or any individual and is not reasonably capable of being used to re-identify them.

2.3 Customer Responsibilities. Customer represents, warrants, and undertakes that:

  1. It has complied, and will continue to comply, with all applicable Data Protection Laws in respect of its Processing of Personal Data and any Processing instructions it issues to BrightLake;

  2. It has obtained, and will maintain, all necessary rights, consents, and authorizations required under applicable Data Protection Laws to enable BrightLake to Process Personal Data contained in Customer Data as contemplated by this DPA/ISA;

  3. It has provided, and will continue to provide, all necessary notices to Data Subjects regarding the Processing of their Personal Data, including disclosure of BrightLake's involvement as a Processor and the use of AI-Powered Features and Third-Party AI Providers where required;

  4. It has the authority to transfer, or provide access to, Customer Data to BrightLake, including any data retrieved from Third-Party Platforms; and

  5. Customer's instructions to BrightLake will not cause BrightLake to violate any applicable law, regulation, or third-party rights.

2.4 SaaS Nature of Services. Customer acknowledges that the Services are provided as a software-as-a-service offering. Customer controls what Customer Data is uploaded to or connected with the Services. BrightLake does not independently determine the categories or volume of Personal Data that Customer chooses to Process through the Services.

2.5 Sensitive Data. The Services are not specifically designed to Process Sensitive Data. Customer shall not submit Sensitive Data to the Services unless Customer has obtained BrightLake's prior written consent, and the parties have agreed upon additional safeguards appropriate to the Processing of such data.

3. Processing Instructions and Restrictions

3.1 Processing Instructions. BrightLake shall Process Personal Data contained in Customer Data:

  1. For the purpose of providing, maintaining, securing, supporting, and improving the Services in accordance with the Agreement and Customer's documented instructions;

  2. To comply with applicable laws, regulations, or binding orders of governmental authorities;

  3. As necessary to detect, prevent, or address fraud, security issues, or technical problems with the Services; and

  4. As otherwise agreed in writing by Customer.

3.2 Documented Instructions. Customer's instructions for Processing Personal Data contained in Customer Data are set forth in and limited to:

  1. this DPA/ISA;

  2. the Agreement;

  3. Customer's configuration of the Services through available settings and controls; and

  4. any subsequent written instructions agreed upon by the parties.

3.3 Notification of Unlawful Instructions. BrightLake shall notify Customer if, in BrightLake's reasonable opinion, an instruction from Customer infringes applicable Data Protection Laws. BrightLake may suspend performance of the relevant instruction until Customer confirms or modifies such instruction. If BrightLake suspends an instruction under this Section 3.3, Customer remains responsible for any resulting inability to use impacted features and for any fees owed under the Agreement.

3.4 Processing Restrictions. BrightLake shall not:

  1. Process Personal Data contained in Customer Data for purposes other than as necessary to provide, maintain, secure, support, or improve the Services or as otherwise instructed by Customer;

  2. Sell Personal Data, as "sell" is defined under applicable U.S. privacy laws, provided that disclosures to Subprocessors solely to provide, secure, and support the Services in accordance with this DPA/ISA will not be deemed a "sale";

  3. Share Personal Data for cross-context behavioral advertising purposes, as "share" is defined under applicable U.S. state privacy laws;

  4. Retain, use, or disclose Personal Data outside of the direct business relationship with Customer except (i) to provide, maintain, improve, secure, and support the Services, (ii) to comply with applicable laws, regulations, or binding orders of governmental authorities, (iii) to detect, prevent, or address fraud, security issues, technical problems, or misuse of the Services, or (iv) as otherwise permitted for processors or service providers under applicable U.S. state privacy laws;

  5. Combine Personal Data received from or on behalf of Customer with Personal Data received from or on behalf of another party, or collected from BrightLake's own interactions with individuals, except as necessary to provide the Services, as permitted by applicable Data Protection Laws, or where the resulting data is Aggregated or De-identified Data that does not identify Customer or any individual and is not reasonably capable of being used to re-identify them; or

  6. Process Personal Data in a manner that would cause Customer or BrightLake to violate applicable Data Protection Laws.

4. AI-Powered Features and Third-party Ai Providers

4.1 AI-Powered Features Disclosure. Customer acknowledges and agrees that the Services include AI-Powered Features that analyze Customer Data and user-provided inputs to generate insights, recommendations, forecasts, reports, and other outputs. To provide AI-Powered Features, BrightLake may transmit certain Customer Data to Third-Party AI Providers.

4.2 Third-Party AI Provider List. The current list of Third-Party AI Providers, including the nature of services provided and categories of data transmitted, is set forth in Annex 4 or other applicable service documentation. BrightLake may update Third-Party AI Providers from time to time based on Customer configuration, feature availability, routing, cost, performance, reliability, and failover requirements.

4.3 AI Data Processing Safeguards. With respect to Customer Data transmitted to Third-Party AI Providers, BrightLake implements the following safeguards:

  1. Purpose Limitation. Customer Data transmitted to Third-Party AI Providers is used for the purpose of providing AI-Powered Features to Customer.

  2. No Intentional Personal Data Transmission. BrightLake does not intentionally transmit Personal Data, including enterprise user names, email addresses, phone numbers, login information, IP addresses, device identifiers, Cookie IDs, session IDs, or Apple Ads account identifiers, to Third-Party AI Providers for AI-Powered Features.

  3. Data Minimization. BrightLake transmits only the Customer Data reasonably necessary to provide the requested AI-Powered Features. Where technically feasible, BrightLake may apply filtering, summarization, rewriting, de-identification, or other data minimization techniques before transmission.

  4. Model Training and Evaluation. BrightLake does not use identifiable Personal Data to train or fine-tune AI models. BrightLake may use Customer Data, prompts, outputs, interaction records, and related metadata in aggregated, de-identified, filtered, summarized, rewritten, or otherwise limited forms for evaluation, testing, quality assurance, benchmarking, service improvement, and research purposes, subject to the Agreement, Privacy Policy, and available customer controls.

  5. Third-Party Provider Practices. Where commercially and technically feasible, BrightLake configures Third-Party AI Providers not to use Customer Data submitted through the Service for model training. Customer acknowledges that Third-Party AI Providers operate under their own terms, policies, configurations, and data handling practices, and BrightLake does not control their internal systems or practices except to the extent set forth in BrightLake's applicable agreements or configurations with such providers.

  6. AI Interaction Records. BrightLake may retain AI prompts, outputs, tool calls, model metadata, token usage, and related interaction records within the Service for service continuity, auditability, quality assurance, evaluation, troubleshooting, security, and service improvement, as described in the Agreement and Privacy Policy.

  7. Contractual Protections. BrightLake maintains agreements with Third-Party AI Providers that include confidentiality obligations and, where available, data protection commitments appropriate to the nature of the Customer Data transmitted.

  8. Encryption in Transit. Customer Data transmitted to Third-Party AI Providers is encrypted in transit using industry-standard protocols.

4.4 AI Output Ownership and Disclaimer.

  1. Output Ownership. Subject to the terms of the Agreement, Customer owns all rights in specific outputs generated by AI-Powered Features from Customer Data. BrightLake retains all rights in the underlying AI models, algorithms, and technology.

  2. Output Disclaimer. Customer acknowledges that:

  • AI-generated outputs are probabilistic in nature and may contain errors, inaccuracies, omissions, or statements commonly referred to as "hallucinations";

  • Customer is solely responsible for reviewing, validating, and making independent decisions regarding AI-generated outputs before relying on or implementing them;

  • BrightLake does not warrant or guarantee any specific business outcomes, accuracy, or fitness for purpose of AI-generated outputs; and

  • AI-Powered Features and their capabilities may change, be updated, or be discontinued at any time.

4.5 Customer AI Controls. Customer may, through available settings in the Services or by written request to BrightLake:

  1. Select or switch among supported Third-Party AI Providers or AI model options where such options are made available in the Service;

  2. Request information about the categories of Customer Data transmitted to Third-Party AI Providers; and

  3. Request to opt out of the use of Customer Data for model improvement or evaluation purposes where such opt-out is made available by BrightLake and is technically feasible.

4.6 Human Oversight. Customer acknowledges its responsibility to implement appropriate human oversight and review of AI-generated outputs. BrightLake recommends that Customer does not rely solely on AI-generated outputs for critical business decisions without independent human review and validation.

4.7 Customer AI Input Restrictions. Customer will not (and will ensure its Authorized Users do not) submit to AI-Powered Features: (i) Sensitive Data, (ii) data about children, or (iii) any other data that Customer is not authorized to provide to BrightLake and the applicable Third-Party AI Provider. Customer is solely responsible for the content of prompts/inputs and for providing any required notices and obtaining any required consents relating to Customer’s use of AI-Powered Features.

4.8 No High-Risk / Regulated Decisions. Customer will not use AI-Powered Features to make automated decisions producing legal or similarly significant effects on individuals, or for eligibility decisions (including employment, credit, insurance, housing), unless expressly agreed in writing by BrightLake and subject to additional controls.

5. Security Measures

5.1 Security Implementation. BrightLake has implemented and shall maintain appropriate technical and organizational security measures designed to protect Customer Data against Security Incidents. The Security Measures applicable to the Services are described in Annex 2 (Technical and Organizational Security Measures).

5.2 Security Measures Updates. Customer acknowledges that the Security Measures are subject to technical progress and development. BrightLake may update or modify the Security Measures from time to time, provided that such updates and modifications do not result in a material degradation of the overall security of the Services. Material updates to Security Measures will be communicated to Customer.

5.3 Personnel Confidentiality. BrightLake shall ensure that any person authorized to Process Customer Data:

  1. Has committed to confidentiality obligations or is under an appropriate statutory obligation of confidentiality; and

  2. Has received appropriate training regarding their data protection responsibilities.

5.4 No Guarantee. While BrightLake implements Security Measures designed to protect Customer Data, BrightLake does not warrant that the Security Measures will be effective under all circumstances or against all types of threats. Security is a shared responsibility, and Customer must also take appropriate measures to protect Customer Data.

5.5 Customer Security Responsibilities. Customer agrees that, except as expressly provided in this DPA/ISA, Customer is responsible for:

  1. The security of Customer Data within Customer's own systems and during transmission to the Services;

  2. Implementing appropriate security measures for any systems that connect to or interact with the Services;

  3. Maintaining the confidentiality and security of Customer's account credentials and access keys;

  4. Configuring the Services appropriately for Customer's security requirements using available settings;

  5. Ensuring that Customer's Authorized Users comply with applicable security requirements; and

  6. Maintaining backup copies of Customer Data as Customer deems appropriate.

5.6 Third-Party Platforms. Customer acknowledges that data retrieved from or transmitted to Third-Party Platforms is subject to the security practices of those Third-Party Platforms. BrightLake is not responsible for the security of Third-Party Platforms or data in transit between Third-Party Platforms and the Services.

6. Sub-processors

6.1 Authorization. Customer hereby provides general authorization for BrightLake to engage Subprocessors to Process Personal Data contained in Customer Data in connection with the provision of the Services, subject to the requirements of this Section 6.

6.2 Subprocessor List. The current list of Subprocessors is set forth in Annex 3 (Subprocessors) or otherwise made available by BrightLake upon request. The list includes the name, location, and Processing activities of each Subprocessor. BrightLake may update the list from time to time in accordance with this Section 6.

6.3 Subprocessor Requirements. BrightLake shall:

  1. Enter into a written agreement with each Subprocessor that imposes data protection obligations on the Subprocessor that are no less protective than those set forth in this DPA/ISA;

  2. Remain responsible for its compliance with this DPA/ISA and for the acts and omissions of its Subprocessors in performing Processing on BrightLake’s behalf under this DPA/ISA, subject to the limitations of liability in the Agreement and excluding any failure caused by (i) Customer’s configuration or instructions, (ii) Third-Party Platforms, or (iii) events outside BrightLake’s reasonable control; and

  3. Conduct appropriate due diligence on Sub-processors to verify that they are capable of providing the level of protection for Customer Data required by this DPA/ISA.

6.4 New Subprocessor Notification.

  1. BrightLake shall provide Customer with prior written notice at least thirty(30) days before authorizing any new Subprocessor to Process Customer Data. Such notice shall include the name, location, and Processing activities of the proposed Subprocessor.

  2. Notice may be provided by email to Customer's designated contact, by posting to BrightLake's website, or by notification through the Services.

6.5 Objection to New Sub-processors.

  1. Customer may object to BrightLake's use of a new Subprocessor on reasonable grounds relating to data protection by providing written notice to BrightLake within fifteen (15) days of receipt of BrightLake's notice.

  2. If Customer objects, BrightLake and Customer shall work together in good faith to find a mutually acceptable resolution. Such resolution may include:

  • BrightLake providing additional information or assurances regarding the Subprocessor;

  • BrightLake making available a change in the Services that avoids the use of the objected-to Subprocessor; or

  • The parties agreeing upon alternative measures to address Customer's concerns.

  1. If the parties are unable to reach a resolution within thirty (30) days of Customer's objection, Customer may, as its sole remedy, terminate the affected portion of the Services by providing written notice to BrightLake. Any termination right under this Section shall be limited to the affected Processing under this DPA/ISA and shall not entitle Customer to a refund of prepaid fees, except where required by applicable law or expressly agreed in writing in an applicable order form.

  2. If Customer does not object within the fifteen (15) day period, Customer shall be deemed to have accepted the new Subprocessor.

6.6 Emergency Sub-processors. In urgent circumstances where engagement of a new Subprocessor is necessary to maintain the security, availability, or continuity of the Services (an "Emergency Subprocessor") , BrightLake may engage such Subprocessor with less than thirty (30) days' notice, provided that BrightLake notifies Customer as soon as reasonably practicable and provides Customer with the opportunity to object in accordance with Section 6.5.

7. Security Incident Response

7.1 Incident Notification. Upon confirming a Security Incident affecting Customer Data, BrightLake shall:

  1. Notify Customer without undue delay and, where feasible, no later than seventy-two (72) hours after becoming aware of the Security Incident; and

  2. Provide Customer with sufficient information to allow Customer to meet any obligations to report or inform Data Subjects or regulatory authorities of the Security Incident under applicable Data Protection Laws.

7.2 Notification Content. BrightLake's notification shall include, to the extent then known:

  1. A description of the nature of the Security Incident, including, where possible, the categories and approximate number of Data Subjects concerned and the categories and approximate number of Customer Data records concerned;

  2. The name and contact details of BrightLake's data protection contact from whom more information can be obtained;

  3. A description of the likely consequences of the Security Incident; and

  4. A description of the measures taken or proposed to be taken by BrightLake to address the Security Incident, including measures to mitigate its possible adverse effects.

7.3 Ongoing Information. Where it is not possible to provide all information at the same time, BrightLake shall provide information in phases as it becomes available without further undue delay.

7.4 Mitigation. BrightLake shall take reasonable steps to contain, investigate, and mitigate the effects of the Security Incident. BrightLake shall cooperate with Customer's reasonable requests for information and assistance relating to the Security Incident.

7.5 Customer Responsibilities. Customer is solely responsible for:

  1. Determining whether the Security Incident constitutes a Personal Data Breach requiring notification to supervisory authorities or Data Subjects under applicable Data Protection Laws; and

  2. Making any such required notifications.

7.6 No Admission. BrightLake's obligation to report or respond to a Security Incident under this Section 7 is not and shall not be construed as an acknowledgment by BrightLake of any fault or liability with respect to the Security Incident.

7.7 Communication. BrightLake's notifications and communications regarding a Security Incident shall be delivered to Customer's designated security contact or, if none is designated, to Customer's primary contact under the Agreement.

8. Data Subject Rights

8.1 Data Subject Requests. Taking into account the nature of the Processing, BrightLake shall assist Customer by appropriate technical and organizational measures, insofar as this is possible, in fulfilling Customer's obligations to respond to requests from Data Subjects exercising their rights under Data Protection Laws("Data Subject Requests"), including rights of access, rectification, erasure, restriction, data portability, and objection. This includes reasonable assistance with verified consumer requests under applicable U.S. state privacy laws to the extent such laws apply to Customer Data.

8.2 BrightLake's Response to Data Subject Requests. If BrightLake receives a Data Subject Request relating to Customer Data directly from a Data Subject, BrightLake shall:

  1. Without undue delay and in any event within a reasonable time, notify Customer of the request and provide Customer with details of the request;

  2. Not respond directly to the Data Subject except to acknowledge receipt of the request and advise the Data Subject that the request has been forwarded to Customer; and

  3. Cooperate with Customer's reasonable instructions regarding the response to the request.

8.3 Customer Export and Available Controls. Where the Services include functionality that enables Customer to access, export, or manage Customer Data, Customer shall use such functionality to respond to Data Subject Requests to the extent reasonably available before requesting assistance from BrightLake. Customer acknowledges that certain deletion, correction, or restriction requests may require BrightLake's assistance and may be subject to technical feasibility, legal requirements, security requirements, and contractual limitations.

8.4 Costs. BrightLake shall provide reasonable assistance with Data Subject Requests to the extent required by applicable Data Protection Laws. Such assistance will be provided at no additional charge where it can be accomplished through existing self-service functionality or standard processes. For any non-standard assistance requiring engineering effort or material operational burden, BrightLake may charge its then-current professional services rates upon prior notice to Customer.

9. Data Protection Impact Assessments and Consultations

9.1 Assistance. Taking into account the nature of the Processing and the information available to BrightLake, BrightLake shall provide reasonable assistance to Customer in ensuring compliance with Customer's obligations relating to:

  1. Data protection impact assessments, to the extent required under Article 35 of the GDPR or equivalent provisions under other Data Protection Laws; and

  2. Prior consultation with supervisory authorities, to the extent required under Article 36 of the GDPR or equivalent provisions under other Data Protection Laws.

9.2 Information Requests. Upon Customer's written request, BrightLake shall provide Customer with information reasonably necessary for Customer to conduct data protection impact assessments, including information about BrightLake's Processing activities, Security Measures, and Sub-processors.

9.3 Costs. Assistance under this Section 9 shall be provided at Customer's expense, except where such assistance is required due to BrightLake's failure to comply with its obligations under this DPA/ISA.

10. Audits and Compliance Verification

10.1 Audit Information. BrightLake shall make available to Customer, upon written request, information necessary to demonstrate compliance with this DPA/ISA. Such information may include:

  1. Copies of relevant third-party certifications and audit reports(e.g., SOC 2 Type II, ISO 27001);

  2. Responses to reasonable written information security questionnaires or due diligence inquiries; and

  3. Summaries of penetration test results or security assessments.

10.2 On-Site Audits. Customer may, no more than once per twelve (12) month period, request an audit of BrightLake's Processing activities and Security Measures to verify compliance with this DPA/ISA, subject to the following conditions:

  1. Customer shall provide BrightLake with at least thirty (30) days' prior written notice of the proposed audit, including the proposed scope and duration;

  2. The audit shall be conducted during BrightLake's normal business hours and shall not unreasonably interfere with BrightLake's business operations;

  3. The audit shall be conducted by Customer or an independent third-party auditor that:

  • is bound by appropriate confidentiality obligations;

  • is not a competitor of BrightLake; and

  • possesses the necessary qualifications and experience to conduct the audit;

  1. Customer shall bear all costs of the audit, including BrightLake's reasonable costs for time and resources expended in connection with the audit;

  2. The audit scope shall be limited to verifying BrightLake's compliance with this DPA/ISA and shall not extend to information relating to other BrightLake customers or proprietary information unrelated to the Processing of Customer Data, provided that the audit scope shall also exclude (i) source code, (ii) penetration testing, vulnerability scanning, or similar testing of BrightLake systems, and (iii) access to environments not used to Process Customer Data;

  3. Customer and its auditor shall comply with BrightLake's reasonable security and confidentiality requirements; and

  4. Audit results and reports shall be treated as Confidential Information of BrightLake.

10.3 Regulatory Audits. The limitations in Section 10.2 shall not apply where an audit is required by a supervisory authority or other regulatory body with authority over Customer, provided that Customer provides BrightLake with as much advance notice as reasonably practicable and cooperates with BrightLake to minimize disruption.

10.4 Alternative Audit Mechanisms. Where Customer's audit requirements can be satisfied through provision of third-party audit reports, certifications, or other documentation, BrightLake may provide such documentation in lieu of permitting an on-site audit.

11. International Data Transfers

11.1 Data Storage Location. BrightLake stores Customer Data in the geographic location(s) specified in the Agreement or, if not specified, in the United States. BrightLake may transfer Customer Data to other locations as necessary to provide the Services, subject to the requirements of this Section 11.

11.2 Transfer Mechanisms. Where BrightLake transfers Personal Data contained in Customer Data to a country that has not been recognized as providing an adequate level of data protection under applicable Data Protection Laws:

  1. Standard Contractual Clauses. The parties agree that the Standard Contractual Clauses shall apply to such transfers, as set forth in Annex 5 (Standard Contractual Clauses) ;

  2. Module Application. The Standard Contractual Clauses shall apply as follows:

  • Module Two (Controller to Processor) shall apply where Customer is a Controller and BrightLake is a Processor;

  • Module Three (Processor to Processor) shall apply where Customer is a Processor acting on behalf of a third-party Controller and BrightLake is a Sub-processor;

  • UK Transfers. For transfers subject to the UK GDPR, the UK International Data Transfer Addendum to the EU Commission Standard Contractual Clauses, issued by the UK Information Commissioner's Office, shall apply;

  • Swiss Transfers. For transfers subject to the Swiss FADP, the Standard Contractual Clauses shall apply with the modifications necessary to comply with Swiss law.

11.3 Transfer Impact Assessments. Upon Customer's written request, BrightLake shall provide information reasonably necessary to enable Customer to conduct transfer impact assessments, including information regarding the laws and practices of destination countries relevant to the Processing of Customer Data.

11.4 Supplementary Measures. BrightLake implements supplementary measures to protect Customer Data transferred internationally, including:

  1. Encryption of Customer Data in transit and at rest;

  2. Access controls limiting access to Customer Data to authorized personnel;

  3. Contractual commitments with Sub-processors regarding data protection; and

  4. Security Measures as described in Annex 2.

11.5 Alternative Transfer Mechanisms. If an alternative transfer mechanism becomes available under applicable Data Protection Laws that provides an adequate level of protection for Personal Data, BrightLake may adopt such alternative mechanism in lieu of or in addition to the Standard Contractual Clauses, upon notice to Customer.

12. Data Retention and Deletion

12.1 Retention Principles. BrightLake may retain Customer Data for as long as reasonably necessary to provide the Services, maintain historical analytics, support account continuity, preserve auditability, troubleshoot issues, improve and secure the Services, comply with legal obligations, resolve disputes, enforce agreements, and maintain business records.

12.2 Personal Data Retention. To the extent Customer Data includes Personal Data, BrightLake shall retain such Personal Data only for as long as reasonably necessary for the purposes described in this DPA/ISA, the Agreement, and the Privacy Policy, or as required or permitted by applicable law. Retention periods may vary depending on the nature of the Personal Data, the purpose of Processing, security needs, legal requirements, and contractual obligations.

12.3 Customer Business Data. Customer Data that does not constitute Personal Data, including campaign data, performance metrics, Apple Ads imported data, MMP-derived non-user-level data or files, imported advertising data, market or competitive intelligence queries and data, AI interaction records, tool usage records, diagnostic records, and related business or operational records, may be retained for extended periods, including indefinitely, for service continuity, historical analytics, auditability, troubleshooting, evaluation, product improvement, security, legal, business, and operational purposes, unless otherwise agreed in writing.

12.4 Backup Data. Backup data is deleted or overwritten in accordance with BrightLake's standard backup rotation practices.

12.5 Assistance with Personal Data Requests. To the extent required by applicable Data Protection Laws, BrightLake will provide reasonable assistance to Customer in responding to valid deletion or restriction requests relating to Personal Data, subject to technical feasibility, legal retention requirements, security requirements, and contractual limitations.

12.6 Aggregated and Anonymized Data. BrightLake may retain Aggregated, anonymized, de-identified, filtered, summarized, or otherwise limited data that does not identify Customer, any Authorized User, or any individual and is not reasonably capable of being used to re-identify them for an indefinite period for analytics, benchmarking, research, testing, evaluation, service improvement, product development, and statistical purposes.

13. U.S. State Privacy Law Compliance

13.1 U.S. State Privacy Laws (Where Applicable). To the extent required by applicable U.S. state privacy laws, BrightLake shall comply with the applicable requirements for processors or service providers under such laws. To the extent applicable U.S. state privacy laws apply to Customer Data, BrightLake shall process Customer Data:

  1. to provide the Services and as otherwise set forth in the Agreement and this DPA/ISA;

  2. in a manner consistent with Customer’s documented instructions; and

  3. in compliance with applicable U.S. state privacy laws’ requirements applicable to processors/service providers, to the extent such requirements apply to BrightLake in its role as a processor. Customer is solely responsible for determining whether and to what extent any U.S. state privacy law applies to Customer Data and for providing any required consumer notices and opt-out mechanisms.

**13.2 No Sale/Share (Where Applicable).**To the extent applicable U.S. state privacy laws apply, BrightLake shall not sell or share Customer Data as those terms are defined under applicable U.S. state privacy laws, except as permitted by applicable U.S. state privacy laws.

13.3 Consumer Rights Requests. BrightLake shall assist Customer in responding to verifiable consumer requests under applicable U.S. state privacy laws, in accordance with Section 8 of this DPA/ISA.

14. Liability

14.1 Liability Cap. Any claims or remedies Customer may have against BrightLake arising under or in connection with this DPA/ISA are subject to any limitation of liability provisions, including any agreed aggregate financial cap, that apply under the Agreement.

14.2 Allocation. For the avoidance of doubt:

  1. This DPA/ISA does not increase or modify the limitations of liability set forth in the Agreement; and

  2. Each party's liability under this DPA/ISA shall be aggregated with its liability under the Agreement for purposes of calculating total liability under applicable limitation of liability provisions.

14.3 Regulatory Fines. To the extent permitted by applicable law, any regulatory fines, penalties, or assessments imposed on BrightLake as a direct result of Customer's breach of this DPA/ISA or Customer's failure to comply with applicable Data Protection Laws shall:

  1. be the responsibility of Customer; And

  2. count toward and reduce any aggregate liability cap applicable to BrightLake under the Agreement.

    14.4 Customer Indemnity. Customer will defend, indemnify, and hold harmless BrightLake and its Affiliates from and against any third-party claims, regulatory investigations, fines, penalties, or damages arising out of or relating to (i) Customer Data provided to BrightLake in violation of Customer’s obligations, (ii) Customer’s failure to provide required notices, obtain required consents, or honor consumer rights/opt-outs, (iii) Customer’s instructions or configurations, or (iv) Customer’s use of Third-Party Platforms and any data obtained from such Third-Party Platforms.

15. Term and Termination

15.1 Term. This DPA/ISA shall remain in effect for the duration of the Agreement and shall automatically terminate upon the termination or expiration of the Agreement, except that the provisions of this DPA/ISA relating to data retention, deletion, return, and confidentiality shall survive termination.

15.2 Effect of Termination. Upon termination of the Agreement, BrightLake shall cease Processing Personal Data contained in Customer Data except as necessary to comply with this DPA/ISA, the Agreement, the Privacy Policy, applicable law, legal retention requirements, security requirements, dispute resolution, auditability, or other legitimate business purposes. Customer Data will be retained or deleted in accordance with Section 12.

16. General Provisions

16.1 Order of Precedence. In the event of any conflict or inconsistency between the provisions of this DPA/ISA and the provisions of the Agreement:

  1. The provisions of this DPA/ISA shall prevail with respect to matters relating to data protection and the Processing of Personal Data;

  2. The Standard Contractual Clauses shall prevail over this DPA/ISA and the Agreement to the extent of any conflict; and

  3. In all other respects, the Agreement shall prevail.

16.2 Amendment. BrightLake may modify, amend, or supplement the terms of this DPA/ISA where required by changes to Data Protection Laws, court or regulatory guidance, or industry best practices. Material modifications shall be communicated to Customer at least thirty (30) days before taking effect, and Customer's continued use of the Services after such period constitutes acceptance of the modified terms.

16.3 Severability. If any provision of this DPA/ISA is found to be invalid or unenforceable by a court of competent jurisdiction, such invalidity or unenforceability shall not affect the remaining provisions of this DPA/ISA, which shall remain in full force and effect.

16.4 No Third-Party Beneficiaries. Except as expressly set forth in the Standard Contractual Clauses with respect to Data Subject rights, this DPA/ISA does not create any rights for any third party.

16.5 Governing Law. This DPA/ISA shall be governed by and construed in accordance with the governing law provisions of the Agreement, except that:

  1. The Standard Contractual Clauses shall be governed by the law of the EU Member State specified therein; and

  2. Where Data Protection Laws require a different governing law to apply to certain provisions of this DPA/ISA, such law shall apply to those provisions.

16.6 Entire Agreement. This DPA/ISA, together with the Agreement and the Annexes hereto, constitutes the entire agreement between the parties with respect to the Processing of Customer Data and supersedes all prior agreements, representations, and understandings relating to such subject matter.

16.7 Counterparts. This DPA/ISA may be executed in counterparts, each of which shall be deemed an original and all of which together shall constitute one and the same instrument.

17. Contact Us

Questions or requests relating to this DPA/ISA should be directed to:

BrightLake International Inc.
One Dock Street, Suite 402,

Stamford, CT 06902
United States

Email: service@brightlake.ai

ANNEX 1: Details of Processing

1. List of Parties

Data Exporter (Controller) :

  • Name: The Customer identified in the Agreement

  • Address: As specified in the Agreement

  • Contact Person: Customer's designated privacy contact or primary contact under the Agreement

  • Activities Relevant to the Data Transferred: Use of the BrightLake Services for advertising management and optimization

  • Role: Controller

Data Importer (Processor) :

  • Name: BrightLake International Inc.

  • Address: One Dock Street, Suite 402, Stamford, CT 06902, United States

  • Contact Person: BrightLake privacy contact

  • Activities Relevant to the Data Transferred: Provision of AI-powered advertising, analytics, and market intelligence services

  • Role: Processor

2. Description of Processing

ElementDescription
Subject MatterProcessing of Customer Data in connection with the provision of AI-powered advertising management services
DurationFor the term of the Agreement plus any applicable data retention period
Nature of ProcessingCollection, storage, organization, structuring, retrieval, consultation, use, disclosure by transmission, alignment, combination, analysis, and deletion
Purpose of ProcessingTo provide the Services, including: managing and optimizing advertising campaigns; providing analytics and performance insights; generating AI-powered recommendations and insights; enabling integrations with Third-Party Platforms; providing conversational AI-Powered Features; and providing customer support
Categories of Data SubjectsCustomer's employees, contractors, representatives, account administrators, and Authorized Users who access, administer, or use the Services on behalf of Customer
Categories of Personal DataBusiness contact information, account login and authentication information, user account identifiers, access credentials or permissions, IP addresses, device and browser information, Cookie IDs, session identifiers, usage logs, security logs, audit logs, and other technical or account-related information, to the extent such information relates to an identified or identifiable individual
Categories of Customer Data generally not intended to include Personal Data:Company product data, campaign data, performance metrics, advertising analytics, MMP files and objective tracking data that do not include user-level data, keywords, app identifiers, creative metadata, market intelligence queries, AI prompts prepared for the Service, AI outputs, tool calls, model metadata, and other business, advertising, or operational data provided by or on behalf of Customer
Sensitive DataNot applicable. Customer shall not submit Sensitive Data to the Services without BrightLake's prior written consent and additional agreed safeguards
Frequency of TransferContinuous, on an ongoing basis as necessary for the provision of Services
Retention PeriodAs described in Section 12 of this DPA/ISA and BrightLake's Privacy Policy. Personal Data is retained only for as long as reasonably necessary for the applicable Processing purposes or as required or permitted by law. Customer business data that does not constitute Personal Data may be retained for extended periods for service continuity, historical analytics, auditability, troubleshooting, evaluation, product improvement, security, legal, and business purposes

ANNEX 2: Technical and Organizational Security Measures

BrightLake implements and maintains the following technical and organizational security measures to protect Customer Data:

1. Access Control

CategoryMeasures
Physical Access ControlData centers operated by certified cloud infrastructure providers (AWS/GCP) with: 24/7 security personnel; Biometric and badge access controls; CCTV monitoring; Visitor management and escort requirements
System Access ControlUnique user identification; Role-based access control (RBAC) ; Multi-factor authentication (MFA) for privileged access; Strong password policies; Automatic session timeout; Access logging and monitoring
Data Access ControlLeast privilege principle; Need-to-know access restrictions; Segregation of duties; Regular access reviews and recertification; Prompt access revocation upon role change or termination

2. Data Protection

CategoryMeasures
Encryption in TransitTLS 1.2 or higher for all external communications; Certificate management and rotation
Encryption at RestAES-256 encryption for stored data; Encryption with key management controls, with HSMs or equivalent mechanisms where applicable
Data MinimizationCollection of only necessary data; Data retention limits; Pseudonymization where feasible
Backup and RecoveryRegular automated backups; Geographically distributed backup storage; Tested recovery procedures; Recovery time and point objectives

3. Network Security

CategoryMeasures
Perimeter SecurityEnterprise-grade firewalls; Web application firewalls(WAF) ; DDoS protection and mitigation
Network MonitoringIntrusion detection systems (IDS); Intrusion prevention systems (IPS); security monitoring tools, which may include SIEM or equivalent mechanisms; Regular security monitoring
Network SegmentationSeparation of production, staging, and development environments; Network isolation for sensitive systems

4. Application Security

CategoryMeasures
Secure DevelopmentSecure coding standards and guidelines; Code review requirements; Static and dynamic application security testing; Dependency vulnerability scanning
Vulnerability ManagementRegular vulnerability assessments; Periodic penetration testing or independent security assessment, where appropriate; Timely security patching; Responsible disclosure program
Change ManagementDocumented change control procedures; Testing and approval requirements before production deployment; Rollback procedures

5. Operational Security

CategoryMeasures
Personnel SecurityBackground checks or equivalent personnel screening where permitted by applicable law and appropriate to role; Confidentiality agreements; Security awareness training; Role-specific security training
Incident ResponseDocumented incident response plan; Designated incident response team; Regular incident response testing; Post-incident review and improvement
Business ContinuityBusiness continuity and disaster recovery plans; Regular testing of continuity procedures; Redundancy and recovery measures appropriate to the Service architecture

ANNEX 3: Subprocessors

This Annex identifies third parties engaged by BrightLake to Process Personal Data on behalf of Customer in connection with the Services.

For clarity, not all third parties used in connection with the Services are Subprocessors under this DPA/ISA. Third parties that provide AI model services, market intelligence data, app intelligence data, keyword data, creative intelligence data, or other business data services, but do not Process Personal Data on behalf of Customer, may be identified separately in the Agreement, Privacy Policy, Annex 4, or other service documentation.

BrightLake may update this Annex from time to time in accordance with Section 6 of this DPA/ISA.

SubprocessorLocationProcessing ActivitiesCategories of Personal Data
Amazon Web Services, Inc.United States(with global regions)Cloud infrastructure, hosting, storage, database, backup, logging, networking, security, and related infrastructure services used to provide and operate the ServiceAccount information, business contact information, login and authentication data, IP addresses, device and browser information, cookie/session identifiers, usage logs, audit logs, diagnostic logs, and other limited Personal Data processed within the Service

Note:

  1. Sentry and Langfuse are self-hosted by BrightLake on its cloud infrastructure and are not listed as separate Subprocessors unless BrightLake uses externally hosted services provided by Sentry, Langfuse, or their affiliates.

  2. Redis, MySQL, S3, SQS, and similar infrastructure components are not listed separately where they are used as part of BrightLake's cloud infrastructure environment.

  3. Apple Ads, MMPs, and other customer-authorized third-party platforms are Third-Party Platforms used at Customer's direction and are not BrightLake Subprocessors unless expressly stated otherwise.

  4. Third-Party AI Providers are described in Annex 4. BrightLake does not intentionally transmit Personal Data to Third-Party AI Providers for AI-Powered Features.

ANNEX 4: Third-party AI Providers

1. Current Third-Party AI Providers

BrightLake may use Third-Party AI Providers to provide AI-Powered Features. The specific Third-Party AI Providers used may vary based on Customer configuration, feature availability, routing, cost, performance, reliability, and failover requirements.

BrightLake does not intentionally transmit Personal Data, including enterprise user names, email addresses, phone numbers, login information, IP addresses, device identifiers, Cookie IDs, session IDs, or Apple Ads account identifiers, to Third-Party AI Providers for AI-Powered Features.

Customer Data transmitted to Third-Party AI Providers may be filtered, summarized, rewritten, de-identified, or otherwise processed to reduce unnecessary or personal information where technically feasible.

ProviderServices ProvidedCategories of Data TransmittedData Handling
DeepSeekDeepSeek AI models for conversational AI, analysis, and generation of AI outputsCustomer business data, prompts, campaign metadata, performance metrics, MMP-derived non-user-level data, market or competitive intelligence context, tool call context, and related non-personal inputsProvide AI-Powered Features. BrightLake does not intentionally transmit Personal Data. Processing is subject to applicable provider terms, configurations, and available controls
OpenAI, Inc.GPT models for natural language processing, conversational AI-Powered Features, content generationProvide AI-Powered Features, embeddings, fallback, or related functionality. BrightLake does not intentionally transmit Personal Data. Processing is subject to applicable provider terms, configurations, and available controls
Google LLC (Gemini)Gemini AI models for advanced analytics, pattern recognition, optimization insightsUsed where enabled or selected for AI-Powered Features. BrightLake does not intentionally transmit Personal Data. Processing is subject to applicable provider terms, configurations, and available controls
Anthropic PBCClaude AI models for conversational interfaces and analysis(where enabled by Customer)

2. AI Data Processing Commitments

2.1 No Intentional Transmission of Personal Data. BrightLake does not intentionally transmit Personal Data to Third-Party AI Providers for AI-Powered Features.

2.2 No Training or Fine-Tuning by BrightLake. BrightLake does not use identifiable Personal Data to train or fine-tune AI models.

2.3 Evaluation and Service Improvement. BrightLake may use Customer Data, prompts, outputs, interaction records, and related metadata in aggregated, de-identified, filtered, summarized, rewritten, or otherwise limited forms for evaluation, testing, quality assurance, benchmarking, service improvement, and research purposes, subject to the Agreement, Privacy Policy, and available customer controls.

2.4 Third-Party Provider Practices. Third-Party AI Providers operate under their own terms, policies, configurations, and data handling practices. Where commercially and technically feasible, BrightLake configures Third-Party AI Providers not to use Customer Data submitted through the Service for model training. BrightLake does not control the internal systems or practices of Third-Party AI Providers except to the extent set forth in BrightLake's applicable agreements or configurations with such providers.

2.5 Provider Changes. BrightLake may update this Annex from time to time in accordance with the Agreement and this DPA/ISA.

ANNEX 5: Standard Contractual Clauses

1. EU Standard Contractual Clauses

For transfers of Personal Data from the EEA to third countries, the parties agree to be bound by the Standard Contractual Clauses adopted by the European Commission pursuant to Implementing Decision (EU) 2021/914.

For clarity, these Clause 17/18 selections apply solely to the SCCs and do not amend the governing law / venue provisions of the Agreement for non-SCC matters.

Module Applied: Module Two (Controller to Processor)

Clause-Specific Selections:

ClauseSelection
Clause 7 (Docking clause)The optional docking clause shall NOT apply
Clause 9 (a)(Use of sub-processors)OPTION 2: General written authorization with 30-day notice period
Clause 11 (a)(Redress)The optional language shall NOT apply
Clause 17 (Governing law)The laws of Ireland
Clause 18 (b)(Choice of forum and jurisdiction)The courts of Ireland

Annex Completion:

Annex I.A (List of Parties): As set forth in Annex 1, Section 1 of this DPA

Annex I.B (Description of Transfer): As set forth in Annex 1, Section 2 of this DPA/ISA

Annex I.C (Competent Supervisory Authority): The Irish Data Protection Commission

Annex II (Technical and Organizational Measures): As set forth in Annex 2 of this DPA

2. UK International Data Transfer Addendum

For transfers of Personal Data from the United Kingdom, the UK International Data Transfer Addendum to the EU Commission Standard Contractual Clauses, issued by the UK Information Commissioner's Office under S119A (1) Data Protection Act 2018, shall apply.

Table Completion:

TableEntry
Table 1 (Parties)As set forth in Annex 1, Section 1 of this DPA
Table 2 (Selected SCCs, Modules and Selected Clauses)The Approved EU SCCs, Module Two, as modified by this DPA
Table 3 (Appendix Information)As set forth in the Annexes to this DPA
Table 4 (Ending this Addendum when the Approved Addendum Changes)Neither party may end this Addendum as set out in Section 19

Competent Supervisory Authority: The UK Information Commissioner's Office(ICO)

3. Swiss Data Transfers

For transfers of Personal Data from Switzerland, the Standard Contractual Clauses shall apply with the following modifications:

  1. References to "Regulation (EU) 2016/679" shall be interpreted as references to the Swiss Federal Act on Data Protection (FADP);

  2. References to "EU,""Union," and "Member State" shall not be interpreted in such a way as to exclude Data Subjects in Switzerland from exercising their rights;

  3. References to the "competent supervisory authority" and "competent courts" shall be interpreted as references to the Swiss Federal Data Protection and Information Commissioner (FDPIC) and competent Swiss courts, respectively;

  4. The governing law for contractual claims shall be the laws of Switzerland; and

  5. The Standard Contractual Clauses shall also protect the data of legal entities until the entry into force of the revised FADP.

Signature Page

This Data Processing Addendum is entered into and becomes a binding part of the Agreement as of the date Customer accepts the Agreement or, if later, the date this DPA/ISA is executed below.

CUSTOMER (Data Controller)

Company Name:
Authorized Signatory Name:
Title:
Signature:
Date:
Email:

BRIGHTLAKE (Data Processor)

Company Name: BrightLake International Inc.
Authorized Signatory Name:
Title:
Signature:
Date:
Email:

END OF DATA PROCESSING ADDENDUM