Skip to content

Ventura Data Processing Addendum

Last Updated: September 3, 2026

This Ventura Data Processing Addendum (this “DPA”) supplements, is in addition to, and is hereby incorporated by reference into the Ventura Distribution Agreement entered into by Company and TTD (the “Agreement”) agreed to by Company. TTD may make reasonable changes to this DPA from time to time, and such changes shall become effective immediately upon posting here. If there is any conflict between the Agreement and the terms of this DPA, this DPA will govern. Any capitalized term used but not defined herein shall have the meaning ascribed to it in the Agreement.

1. Definitions

“Consumer” means “consumer,” “data subject,” and analogous variations of such terms under Data Protection Laws.

“Controller” means “controller” and “business” and analogous variations of such terms under Data Protection Laws. TD is the “Controller” of the Controller Data under this DPA.

“Controller Data” means the Personal Data set forth in Exhibit A to this DPA.

“Data Protection Laws” means Laws applicable to the processing of Personal Data pursuant to the Agreement that relate to data protection or privacy, wiretapping or the interception/​security of communications, or the privacy and safety of minors online.

“Personal Data” means personal data, personal information, or analogous variations of such terms under Data Protection Laws that relate to Consumers’ access to and use of the Platform.

“Processor” means “processor” and “service provider” and analogous variations of such terms under Data Protection Laws. Publisher is the “Processor” of the Controller Data under this DPA.

2. Compliance

Each party’s processing of Personal Data provided or accessed under the Agreement will at all times comply with this DPA and all Data Protection Laws applicable to its processing of such Personal Data. Each party will implement and maintain appropriate technical and organizational measures designed to protect the confidentiality, integrity, and availability of Personal Data.

3. International Transfers

If the Territory expands beyond the United States of America, the parties agree to work together in good faith to enter into any required data transfer agreements.

4. Processor Obligations

With respect to Controller Data, the parties agree:

4.1. The Processor will:

  • Process Controller Data pursuant solely to the Controller’s instructions and only as necessary to permit Consumers to access and use the Apps, Ventura OS, and Device.
  • Promptly delete Controller Data at the request of the Controller or upon the termination or expiration of the Agreement.
  • Provide the Controller with reasonable assistance required to fulfill the Controller’s obligations under Data Protection Laws, including responding to data subject requests and conducting data protection impact assessments, taking into account the nature of the Controller Data processed by the Processor.
  • Provide access to Controller Data only to those of its personnel subject to contractual or statutory confidentiality obligations with respect to Controller Data.
  • Permit subcontractors to access Controller Data only after notifying the Controller of, and permitting the Controller to object to, such subcontractors, and imposing data protection obligations at least as stringent as those set forth in this DPA on any such subcontractors.
  • Notify the Controller of any accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, Controller Data (a “Data Breach”) without undue delay upon becoming aware of the Data Breach, such notice to include all information necessary for the Controller to comply with its obligations under Data Protection Laws, and refrain from communicating with any third parties regarding the Data Breach (unless required by Data Protection Law to do so).
  • Make information available to the Controller to demonstrate compliance with this DPA and Data Protection Laws, and allow for and contribute to audits conducted by the Controller or a qualified independent auditor at the Controller’s election, provided that such audits shall occur no more than once per year at a mutually agreeable date and time following reasonable written notice of Controller’s intent to audit, except that in the event of a Data Breach, regulatory inquiry, or similar emergency circumstance such limitations shall not apply.
  • Notify the Controller if it makes a determination that it can no longer meet its obligations under Data Protection Laws with regards to the Controller Data.

4.2. The Processor will not:

  • Sell or share (as those terms are defined by Data Protection Laws) Controller Data.
  • Process Controller Data outside of its relationship with Controller.
  • Combine Controller Data with Personal Data it receives from other sources or directly from Consumers, except as permitted by Data Protection Laws.
  • Export, extract, or otherwise scrape any Controller Data in any form from the Apps, Ventura OS, or Device, except as expressly instructed by Controller.
  • Otherwise process Controller Data for its own purposes.

4.3. The Controller shall have the right to, upon reasonable suspicion of noncompliance and prior written notice, take reasonable and appropriate steps to stop and remediate the Processor’s unauthorized use of Controller Data. If Controller reasonably believes that Processor is using such Controller Data in an unauthorized manner, Controller can notify Processor of such belief and the parties can work together in good faith to stop or, if necessary, remediate the allegedly unauthorized use of Controller Data.

5. Aggregated Data

To the extent the Controller transfers Controller Data that has been aggregated and/​or de-identified such that Consumers cannot reasonably be identified (“Aggregated Data”) to the Processor, the Processor shall make no attempts to re-identify the Aggregated Data.

Exhibit A

Controller Data

Data Sets:
Examples:

  • End User account information and Emails used to authorize the profiles Device
  • End User payment information
  • User IDs
  • End User activity on the Device and within the Ventura OS but outside the Apps within the Ventura OS
  • End User launch activity