This Data Processing Addendum ("DPA") forms part of the Terms of Service (or other agreement governing the Service — the "Agreement") between Gen3 Marketing, LLC ("Gen3", the "Processor") and the customer organization ("Customer", the "Controller"). It applies to the extent Gen3 processes Personal Data on Customer's behalf in providing the AI Visibility service (the "Service").
This DPA is incorporated by reference into the Agreement and is effective upon Customer's acceptance of the Agreement — no signature is required. A countersigned copy is available for Enterprise customers on request (email aiv_legal@gen3marketing.com).
"Data Protection Laws" means all laws applicable to the processing of Personal Data under the Agreement, including the EU GDPR 2016/679, the UK GDPR, and the California Consumer Privacy Act as amended ("CCPA").
"De-Identified Data" means information that cannot reasonably be used to Infer information about, or otherwise be linked to, a particular consumer.
"Personal Data", "processing", "controller", "processor", "data subject", and "personal data breach" have the meanings in Data Protection Laws.
"Sell" has the meaning as set forth in the Data Protection Laws.
"Services" will have the same meaning provided under the Agreement.
"Share" has the meaning as set forth in the Data Protection Laws.
"SCCs" means the EU Commission Standard Contractual Clauses (Implementing Decision (EU) 2021/914).
"Sub-processor" means a third party engaged by Gen3 to process Personal Data on Customer's behalf.
"UK International Data Transfer Addendum" means the International Data Transfer Addendum to the EU Commission Standard Contractual Clauses, Version B1.0.
Customer is the controller (or a processor acting for another controller) and Gen3 is the processor of Personal Data submitted to the Service. The subject matter, duration, nature and purpose of processing, and the categories of data and data subjects are described in Annex I. For CCPA purposes, Gen3 is a "service provider"; Gen3 does not sell or share Personal Data, does not retain, use, or disclose it except to provide the Service, and certifies that it understands and will comply with these restrictions.
Gen3 will process Personal Data only on Customer's documented instructions — which consist of the Agreement, this DPA, Customer's configuration and use of the Service, and any further written instructions agreed by the parties — unless required otherwise by law (in which case Gen3 will inform Customer unless legally prohibited). Gen3 will promptly inform Customer if, in its opinion, an instruction infringes Data Protection Laws.
For the avoidance of doubt, Customer's instructions for the processing of Customer Personal Data shall comply with the Data Protection Laws. Customer acknowledges that Gen3 is reliant on Customer for direction as to the extent to which Gen3 is entitled to use and Process Customer Personal Data. Consequently, Gen3 will not be liable for any claim brought against Customer by a Data Subject arising from any act or omission by Gen3 to the extent that such act or omission resulted from Customer's instructions or Customer's use of the Services.
Gen3 shall not combine Customer Personal Data received from Customer with any other information Gen3 receives from or on behalf of another person or business or which it collects from its own interactions with Data Subjects.
Gen3 shall Process Personal Data under the Agreement in compliance with Data Protection Laws, including providing the same level of privacy protection required by Data Protection Laws. Gen3 will notify Customer if Gen3 determines it or its Sub-processors cannot meet its obligations under the Data Protection Laws, in which case Customer may, upon thirty (30) days' notice, take reasonable and appropriate steps to stop and remediate unauthorized Processing of Personal Data.
Gen3 ensures that personnel authorized to process Personal Data are bound by confidentiality obligations and process it only as needed to provide the Service.
Gen3 implements and maintains the technical and organizational measures described in Annex II, and will not materially decrease the overall security of the Service during a subscription term. Taking into account the state of the art and the nature of the data, these measures are designed to ensure a level of security appropriate to the risk (GDPR Art. 32).
Customer provides general authorization for Gen3 to engage Sub-processors, including those listed at /legal/subprocessors (Annex III). Gen3 will:
Gen3 may continue to use those Sub-processors already engaged by Gen3 as of the date of this DPA.
Taking into account the nature of the processing, Gen3 will assist Customer by appropriate technical and organizational measures in fulfilling Customer's obligation to respond to data-subject requests (access, rectification, erasure, restriction, portability, objection). If a data subject contacts Gen3 directly regarding Customer's workspace, Gen3 will redirect them to Customer and will not respond substantively except as legally required.
Both Parties will assist the other in communicating and cooperating with any regulators relating to Personal Data.
Gen3 shall notify Customer of all enquiries from a regulator that Gen3 receives which relate to the Processing of Personal Data under the Agreement, the provision or receipt of the Services, or either Party's obligations under the Agreement, unless prohibited from doing so at law or by the regulator.
Unless a regulator requests in writing to engage directly with Gen3, the Parties (acting reasonably and taking into account the subject matter of the request) agree that Customer shall be responsible for handling all regulator requests. Customer shall: (a) be responsible for all communications or correspondence with the regulator in relation to the Processing of Personal Data and the provision or receipt of the Services, and (b) keep Gen3 informed of such communications or correspondence to the extent permitted by law. At Customer's expense, Gen3 shall provide such assistance as Customer may request in relation to such a regulator request.
Gen3 will notify Customer without undue delay after becoming aware of a personal data breach affecting Customer's Personal Data, and will provide information reasonably required for Customer's own notification obligations, as it becomes available, along with reasonable cooperation and remediation. Gen3's notification of or response to a breach is not an acknowledgment of fault or liability.
Gen3 will provide reasonable assistance to Customer with data-protection impact assessments and consultations with supervisory authorities (GDPR Arts. 35–36), to the extent the required information is available to Gen3.
Gen3 will make available information reasonably necessary to demonstrate compliance with this DPA, including summaries of third-party audits or certifications of its cloud infrastructure providers. No more than once per 12 months (except after a personal data breach or at a supervisory authority's direction), Customer may conduct an audit — satisfied first through written responses and documentation, and, only where Data Protection Laws require more, through a remote or on-site inspection at reasonable notice, during business hours, without disrupting other customers, under confidentiality, and at Customer's reasonable expense.
Customer must provide Gen3 with any audit reports or findings generated in connection with any audit at no charge, unless prohibited by law. Customer may use the audit reports only for the purposes of meeting its audit requirements under Data Protection Laws and/or monitoring and confirming compliance with the requirements of this DPA. The audit reports shall constitute Confidential Information of the Parties under the Agreement.
Nothing in this Section shall require Gen3 to breach any duties of confidentiality owed to any of its customers or employees.
On termination or expiry of the Agreement, Gen3 will, at Customer's choice, delete or return Personal Data processed on Customer's behalf, and delete existing copies, completing deletion within ninety (90) days of termination (or such earlier time as Gen3 completes a verified deletion request, submitted as described in Section 8 of the Privacy Policy), except where law requires longer storage or where data remains in encrypted backups pending scheduled expiry (no more than 30 days), in which case this DPA continues to apply to that data until it is deleted. The Agreement provides a 30-day post-termination export window for Customer's reports and data.
Gen3 shall be responsible for its compliance with all laws regarding data that cannot reasonably identify, be related to, describe, be capable of being associated with or be linked directly or indirectly to a Data Subject. To the extent Gen3 Processes De-Identified Data under the Agreement, Gen3:
(a) Will not attempt to associate De-Identified Data with an individual;
(b) Will not attempt to re-identify De-Identified Data;
(c) Will maintain and use De-Identified Data only in a de-identified fashion; and
(d) Will not use De-Identified Data to infer information about, or otherwise link to, an identified or identifiable individual or a device linked to such an individual.
Where Customer transfers Personal Data protected by EU/EEA law to Gen3 in the United States (or another third country without an adequacy decision), the parties agree that the SCCs, Module Two (controller → processor), are incorporated into this DPA, completed as follows: Clause 7 (docking) included; Clause 9(a) Option 2 (general authorization, 30 days); Clause 11 optional redress not included; [CONFIRM: the 2026-08-20 counsel draft reads "Clause;" here, a stray fragment at the former Clause 17/18 placeholder; awaiting corrected text]; Annexes I–III below. Where Customer is itself a processor, Module Three applies on the same terms. For UK transfers, the UK International Data Transfer Addendum (Mandatory Clauses) is incorporated, with the tables completed by the information in this DPA. For Swiss data, the SCCs apply with the modifications required by the FDPIC.
Customer is solely responsible for ensuring that any authorized transfer of Customer Personal Data across national borders made by Gen3 at the Customer's direction complies with all laws, including, but not limited to, any cross-border data transfer requirements or prohibitions.
If the Standard Contractual Clauses are invalidated or modified by judicial proceeding, statute, regulation, or otherwise, the Parties shall cooperate to identify alternative data transfer mechanisms, if available, provided that either Party may decline to adopt such mechanisms or to accept a modification of the Standard Contractual Clauses in its sole discretion.
If the UK Addendum is invalidated or modified by judicial proceeding, statute, regulation, or otherwise, the Parties shall cooperate to identify alternative data transfer mechanisms, if available, provided that either Party may decline to adopt such mechanisms or to accept a modification of the UK Addendum in its sole discretion.
The Parties each represent and warrant to each other that they have read and understand the requirements of all applicable Data Protection Laws, and will be responsible for their own compliance with them.
Gen3 shall not have any liability to Customer to the extent the basis of liability arises from failure by Customer to obtain any necessary consents to collect, use, transfer, or otherwise Process Personal Data, or failure by Customer to fully comply with the Agreement, this DPA, or applicable Data Protection Laws.
The disclosure of Customer Personal Data to Gen3 does not constitute a Sale or Sharing under the Data Protection Laws. Notwithstanding anything in the Agreement, the Parties acknowledge and agree that Customer's provision of access to Personal Data is not part of and is explicitly excluded from the exchange of consideration or any other thing of value between the Parties.
Customer represents and warrants that, if required, it has provided notice that the Personal Data is being Processed and obtained any required consent consistent with the Data Protection Laws.
Each Party agrees that it is responsible for its own compliance with the requirements of applicable Data Protection Laws and agrees to indemnify, defend, and hold harmless the other Party from and against any claims, demands, losses, liabilities, fines, penalties, costs, and expenses arising out of or relating to its own acts and omissions that do not comply with the Data Protection Laws. This duty to indemnify, defend, and hold harmless includes fines that may be imposed by a governing authority and any and all reasonable attorneys' fees and court costs.
The Parties agree that where Gen3 processes Personal Data, it functions as a Service Provider and a Processor under the Data Protection Laws.
By entering into this DPA, Gen3 certifies that it understands the restrictions herein and will comply with them.
The obligations contained in this DPA shall not restrict Gen3 in its rights and/or obligations to: (a) comply with federal, state, or local laws, or to comply with a court order or subpoena to provide information or legal holds, or (b) to comply with a civil, criminal, or regulatory inquiry, investigation, subpoena, or summons by federal, state, or local authorities.
Each party's liability under this DPA is subject to the limitations of liability in the Agreement, to the extent permitted by Data Protection Laws. If this DPA conflicts with the Agreement, this DPA controls as to data protection; if the SCCs conflict with this DPA, the SCCs control.
A. List of parties. Data exporter: Customer (contact: Customer's workspace owner/billing email) — controller. Data importer: Gen3 Marketing, LLC, 960B Harvest Drive, Suite 210, Blue Bell, PA 19422 (contact: aiv_privacy@gen3marketing.com) — processor.
B. Categories of data subjects. Customer's personnel and authorized users of the Service; individuals whose personal data is incidentally contained in content Customer submits (Customer should not submit personal data beyond business contact details).
C. Categories of Personal Data. Name, business email address, authentication identifiers, role/membership data; workspace content Customer submits (brand/competitor/market information, which is generally not personal data); usage logs and technical identifiers (IP address, user-agent).
D. Special categories. None — prohibited by the Agreement.
E. Frequency. Continuous, for the duration of the subscription.
F. Nature and purpose. Hosting and operating the AI Visibility service: storing workspace configuration, executing brand-visibility scans against the AI providers Customer selects (transmitting Customer-curated prompts to those providers), generating reports and recommendations, sending transactional notifications, billing, support, and security.
G. Retention. Per Section 12 of this DPA and the retention table in the Privacy Policy.
H. Sub-processor transfers. As listed at /legal/subprocessors; subject matter, nature, and duration as described there and in the Agreement.
Competent supervisory authority: [CONFIRM: per Clause 13 SCCs — likely the authority of the EU member state of the exporter.]
The authorized Sub-processor list, including purpose and location for each, is maintained at /legal/subprocessors and is incorporated into this DPA. A point-in-time copy is available on request (email aiv_legal@gen3marketing.com).