These Master Data License and Management Services Agreement Terms and Conditions, including all schedules, exhibits, and addenda attached hereto, (the “Agreement”), govern the relationship between HealthLink Dimensions, LLC (“HealthLink” or “HL”), on its own behalf and its subsidiaries and affiliates, and Licensee. In consideration of the rights and benefits that Licensee and HealthLink ( each individually, a “Party” and together collectively, the “Parties”) will gain as a result of the commercial relationship contemplated by this Agreement and intending to be legally bound, the Parties agree as follows:
SECTION 15 OF THIS AGREEMENT CONTAINS PROVISIONS REGARDING DISPUTE RESOLUTION UNDER THIS AGREEMENT, INCLUDING AN AGREEMENT TO SUBMIT CERTAIN DISPUTES TO BINDING AND FINAL ARBITRATION.
HealthLink Dimensions may modify this Agreement at any time. By executing this Agreement or an Order Form for Licensed Data and Managed Services (“Order Form”), substantially in the form attached hereto as Schedule “A,” Licensee is agreeing to be bound by the terms and conditions of this Agreement. All Order Forms will be governed by the version of this Agreement in effect when the Order Form is executed, unless HealthLink Dimensions provides Licensee notice of a subsequent modification and Licensee agree to such modification in the manner specified in the notice.
WHEREAS HL is in the business of providing (i) healthcare data solutions to healthcare and life science organizations to improve master data management, compliance and marketing initiatives, leveraging the largest multi-sourced database of active practicing healthcare professionals and developing customized data solutions to help Licensees reach their target audience, enrich their business data, optimize claims processing, meet compliance requirements and solve master data quality problems and (ii) providing comprehensive, objective, online and mobile application community resource information databases, and licensing the Licensed Data (as defined below) content to Licensee(s); and
WHEREAS HL and Licensee desire to enter into this Agreement, whereby HL will grant a license to Licensee the right to access, display, and use the Licensed Data.
NOW THEREFORE, in consideration of the mutual promises and covenants contained herein and for other good and valuable consideration, the receipt and sufficiency of which are hereby acknowledged, the Parties agree as follows:
1. Definitions. As used in this Agreement, the following capitalized terms have the following meaning:
1.1 “Licensed Data” shall mean the following:
(A) master files, physician data, allied professional, facilities, emails, and any updates, modifications, and enhancements that HL provides to Licensee during the Term. Licensed Data shall also include any individual pieces of data comprised within the Licensed Data.
(B) any and all electronic and/or hard copy information that has been authored, created, and compiled by HL and various third-party data sources made accessible to Licensee under this Agreement. Such information pertains to community resource service providers, which may include but is not limited to, senior housing facilities, hospice providers, medical equipment suppliers, dialysis centers, medical rehabilitation providers, infusion centers, hospitals, and others. When appropriate, profile data may include business contact information, licensing information, and other descriptive information about the service providers compiled from the third parties’ sources and/or self-reported by the provider.
(C) the collection of information and data in paper or electronic form about local community resources and/or providers that has been authored, created and compiled, and that will continue to be authored, created and compiled, by HL about local resources and providers, including all Intellectual Property Rights thereto as defined in Section 4 below.
2. License and Management Services. HL and Licensee shall execute Order Form(s) referencing its incorporation of the terms and conditions of this Agreement and stating: the Licensed Data to be licensed, brief description of data, management services, and the fees. In the event of a conflict between the terms of this Agreement and the terms of any Order Form, the terms of this Agreement shall control unless the Order Form specifically (and not generally) identifies the conflicting terms in this Agreement and explicitly states that such terms shall not apply but shall instead be superseded by the Order Form. The Order Form will be signed by an authorized representative of Licensee.
3. License and Terms of Use.
3.1. Licensee agrees and understands that this Agreement is a restricted use license. Any rights not especially granted to Licensee are reserved. The Licensed Data is licensed, not sold. HL grants Licensee a temporary non-exclusive, non-transferable, limited license during the Term to access, display and use the Licensed Data. Without HL’s prior written approval, the Licensed Data may not be accessed or used outside of the United States or transmitted or communicated to any person outside of the United States. Licensee may only use licensed data for marketing purposes such as direct email outreach and not for identity resolution or social targeting unless agreed upon and stated in Schedule “A.” Licensee may place one copy of each Licensed Data on its network server, and Licensee may make one copy of the Licensed Data for archival or backup purposes. Except as is otherwise expressly permitted in this Agreement, Licensee may not copy, distribute, re-sell, sublicense, commercialize, release, disclose, publish, distribute, or provide any persons other than Licensee employees with access to the Licensed Data. If licensee works with a Third party on behalf of HealthLink Dimensions licensed data, a Third Party Agreement in the form attached hereto as Schedule “B” will be signed by the Parties. Licensee shall not alter, modify, enhance, reverse engineer, or create derivative works of the Licensed Data. Licensee agrees to take all necessary measures to (i) ensure that its employees and (subject to Section 4) any consultants and independent contractors abide by the terms of this Agreement, and (ii) protect the Licensed Data from any unauthorized use, reproduction, display, publication, disclosure, or distribution. Licensee shall be responsible for any breach of this Agreement by its employees and any acts by consultants or independent contractors with regard to the Licensed Data that are not expressly authorized in this Agreement.
3.2. Licensee will have no rights to use the Licensed Data other than the utilized and purchased categories in Order Form(s), as may be amended from time to time by mutual written agreement of the Parties, subject to the express terms of this Agreement, and any rights not expressly granted to Licensee in this Agreement are reserved exclusively for HL. All rights, title, and interest in and to the Licensed Data and any update, modification, enhancement, or alteration to them including without limitation, all patents, copyrights, Trade Secrets (as defined by law), or other Intellectual Property associated therewith are and shall be vested solely in HL. The Licensed Data shall be deemed to be the proprietary information solely of HL.
3.3. Licensee shall only have the right to display the Licensed Data, authorized URLs, approved mobile applications, or where HL has authorized Licensee to access through other means.
3.4. Licensee shall take commercially reasonable steps to ensure the security of the Licensed Data and to protect this information from unauthorized disclosure, downloading, or copying through such technologies such as screen scrapping. In addition, if Licensee becomes aware of any actual or threatened security breach, disclosure, or misuse by Licensee, it shall immediately notify HL and shall reasonably cooperate with HL in minimizing the impact of and correcting the breach, disclosure, or misuse.
3.5. Licensee will not grant access and use to the Licensed Data to any other party unless such party is approved in writing by HL.
3.6. Restriction on AI/ML Use. As used in this Agreement, "AI/ML System" includes any artificial intelligence, machine learning, large language model (LLM), deep learning algorithm, generative AI tool (whether proprietary or third-party), or automated decision-making software. Licensee expressly acknowledges and agrees that, absent specific approval documented by the Parties in a duly executed Order Form, the Licensed Data provided hereunder shall not be accessed, utilized, ingested, processed, or run through any AI/ML System for any purpose. This prohibition explicitly includes, but is not limited to:
- model training and fine-tuning: using the Licensed Data (or any derivative work or subset thereof) to train, calibrate, refine, benchmark, test, or improve any AI/ML model, neural network, or algorithm.
- automated processing and inference: using an AI/ML System to query, parse, extract insights from, or automate decision-making regarding the Licensed Data.
- A completed form submitted on the Client's proprietary website by an individual, providing the individual's name and contact information, along with a timestamp.
- A response from an individual to a Client-sponsored marketing initiative (e.g., phone, direct mail, email, digital, trade show, or event) that results in an EBR Record.
- Direct communication (e.g., phone call, email, online meeting, or face-to-face meeting) with the Client's sales or marketing team, creating an EBR Record.
- A signed contract between the Client and an individual, constituting an EBR Record.
Licensee shall not input, upload, submit, transfer to, or otherwise integrate the Licensed Data into any third-party or cloud-based AI platform or tool. Licensee agrees to ensure that any downstream service providers, contractors, or vendors utilized by it with regard to the Licensed Data are contractually bound by identical restrictions regarding the Licensed Data.
3.7. Licensee shall submit monthly usage reports to HL on all usage involving the Licensed Data. In the event the Licensee is a provider and using the data for care management this will include, but is not limited to, the aggregate number of discharges and the associated providers where each discharge was placed. HL implements the industry practice of placing seed records such as emails into the data set licensed to Licensees. This allows HL to monitor the Licensee’s adherence to the agreed upon email rental or license terms. In the event HL determines from its review of the seeds inserted in the Licensed Data that Licensee has used the Licensed Data beyond the Term of the Agreement or number of contracted Licensed Data without HL prior written approval, Licensee shall pay HL the annualized fees for the continued utilization of such Licensed Data as if this Agreement had not terminated.
3.8. HL may remove data from its Licensed Data at its discretion, which may include a request to do so by a third party who is the subject matter of any data, or if HL determines it does not have sufficient rights in any particular piece of data, or believes that doing so is necessary to avoid potential claims or damages.
3.9. [Reserved]
3.10. HL is granted permission by Licensee to use Licensee's name and logo solely for the purpose of promoting and showcasing the services provided under this Master Services Agreement. HL agrees to comply with Licensee’s guidelines related to this use and will modify such use upon request.
3.11. Notwithstanding the termination provisions in Section 12, Licensee rights to use certain Licensed Data as specified in Section 13 (Post-Termination Rights) under conditions of an Established Business Relationship (EBR) as defined in Section 14 shall persist beyond termination or expiration of this agreement.
4. Intellectual Property and Proprietary Rights. "Intellectual Property and Proprietary Rights" are any or all of the following and all rights, arising out of or associated with all of the following: (a) all United States, international and foreign patents and applications therefore and all reissues, divisions, renewals, extensions, provisionals, continuations and continuations-in-part thereof; (b) all inventions (whether patentable or not), invention disclosures, improvements, Trade Secrets, proprietary information, know-how, technology, technical data and customer lists, and all documentation relating to any of the foregoing throughout the world; (c) all copyrights and all other literary property or author rights, whether or not copyrightable, copyright registrations and applications therefore, and all other rights corresponding thereto throughout the world; (d) all industrial designs and any registrations and applications therefore throughout the world; (e) all internet uniform resource locators, domain names, trade names, logos, slogans, designs, common law trademarks and service marks, trademark and service mark registrations and applications therefore throughout the world; (f) all databases and data collections and all rights therein throughout the world; (g) all moral and economic rights of authors and inventors, however denominated, throughout the world; (h) all Internet related and world wide web related proprietary rights, and (i) any similar or equivalent rights to any of the foregoing anywhere in the world. Licensee shall have no rights in the Licensed Data other than that of a licensee subject to the express terms of this Agreement, and any rights not expressly granted to Licensee in this Agreement are reserved exclusively for HL. All right, title, and interest in and to the Licensed Data and any update, modification, enhancement, or alteration to them including, without limitation, all patents, copyrights, trade secrets, or other intellectual property rights associated therewith, are and shall be vested solely in HL. The Licensed Data shall be the Proprietary Information of HL. To the extent that, contrary to the above, any such rights are vested in the Licensee as a matter of law, Licensee agrees to take any action necessary to ensure that such rights are conveyed to and held by HL.
5. Fees. Licensee shall pay HL the fees for the Licensed Data as stated in the applicable Order Form(s). Any amounts not paid by the due date stated therein shall bear interest from such due date at the rate of eighteen percent (18%) per annum, or at the highest rate permitted by applicable law until such past due amount is paid in full. The fees do not include taxes. If HL is required to pay sales, use, property, value added, or other federal, state, or local taxes based on the license granted in this Agreement or the use of the Licensed Data, such taxes shall be billed to and paid by Licensee. Licensee may not deduct from any payment it owes HL an amount that Licensee claims HL owes Licensee. Licensee may not withhold payment of fees under this Agreement for any reasons. Any disputes to invoiced amounts shall be resolved by the dispute resolution procedures in this Agreement.
6. Confidentiality and Privacy.
6.1. Licensee and HL acknowledge that in fulfilling the responsibilities set forth in this Agreement, Licensee and HL may exchange Confidential and Proprietary information. Such information will not be disclosed to any third party without the written consent of the disclosing Party. Upon termination of this Agreement, all written documents or information shall, upon written request, either be destroyed or returned to the originating Party.
6.2. “Confidential and Proprietary Information” may include, but is not limited to, (a) Trade Secrets, (b) information of HL, to the extent not considered a Trade Secret under applicable law, that (i) relates to the business of HL, (ii) possess an element of value to HL, (iii) is treated by HL as confidential (iv) is not generally known to HL’s competitors and (v) would damage HL if disclosed, and (c) information of any third party provided to HL which HL is obligated to treat as confidential, including, but not limited to, information provided to HL by its licensors, suppliers, or customers. Confidential Information includes, but is not limited to, (i) future business plans, (ii) the composition, description, schematic, or design of products, future products or equipment of HL or any third party (iii) communication systems, audio systems, system designs and related documentation, (iv) advertising or marketing plans, (v) information regarding employees, customers, prospects, licensors, suppliers, customers or any third party, including, but not limited to, customer lists compiled by HL and customer information compiled by HL (vi) contractual arrangements and relationships with independent brokers, providers, customers, and prospective customers, (vii) pricing, fee, billing, discount, and marketing strategies, practices and characteristics, (viii) plans and strategies regarding mergers, acquisition, and market expansion, (ix) financial matters, (x) information concerning HL’s or third party’s financial structure and methods and procedures of operation, and (xi) any such information encompassed by the foregoing that is or has been obtained through the acquisition of any aspect of any other business or entity.
6.3. Confidential Information shall not include any information that (1) is or becomes generally available to the public other than as a result of an unauthorized disclosure, (2) has been independently developed and disclosed by others without violating this Agreement or the legal rights of any party, or (3) otherwise enters the public domain through lawful means.
6.4. HL is the possessor of proprietary and confidential rights in its Confidential Information and Trade Secrets, and desires to maintain the confidentiality of, and restrict the use of, its Confidential Information and Trade Secrets. Licensee shall not (a) use, disclose or reverse engineer the Confidential Information and/or Trade Secrets, in whole or in part, to any other person or entity for any purpose other than providing the Services under this Agreement, unless authorized in writing by HL, or (b) during the term of this Agreement use, disclose or reverse engineer any Confidential Information or Trade Secrets of any third party. The obligations of this Section 6.4 shall: (a) with regard the Trade Secrets, remain in effect as long as the information constitutes a Trade Secret under applicable law, and (b) with regard to the Confidential Information, remain in effect during the term of this Agreement and for a period of two (2) years after the termination of this Agreement for any reason. The obligations under this Section 6.4 shall not affect or relieve Licensee’s obligations to return Confidential Information and/or Trade Secrets to HL. Upon the termination of Licensee’s engagement for any reason, Licensee shall not: (a) retain any copies of HL’s Confidential Information which are in Licensee’s or a permitted third party’s possession, custody, or control, or (b) destroy, delete, or alter any HL Confidential Information without HL’s prior written consent.
6.5. The Parties agree that they shall keep the Confidential Information of the other strictly private and that they shall not disclose the Confidential Information of the other to any third party (other than their respective accountants or legal counsel). In addition, the Parties agree and promise that neither shall disclose the terms of this Agreement to any third party without the express written consent of the other Party.
6.6. Each Party shall promptly notify the other upon discovery of any loss or unauthorized access or disclosure of the Confidential Information of the other Party.
7. Training/Installation. Any training, installation, programming, hardware, or software required by the Licensee to use and access the Licensed Data shall be Licensee’s sole responsibility. At Licensee’s request, HL may provide training, programming, or consulting services to Licensee upon terms and conditions mutually agreeable to both parties and set forth in writing in a separate agreement and for a reasonable fee.
8. Mutual Obligations and Representations. Each person signing an Order Form on behalf of HL and Licensee represents and warrants that he or she has all requisite power and authority to execute and deliver this Agreement and to bind the party on whose behalf he or she has signed the Order Form. Each Party represents to the other that no exercise of any right or any obligation by the Party under this Agreement is prohibited by any other contract binding that Party or by any law or regulation that is applicable to that Party.
9. Warranty and Disclaimer. THE LICENSED DATA ARE PROVIDED “AS IS” WITHOUT WARRANTY OF ANY KIND, INCLUDING, WITHOUT LIMITATION, WARRANTIES AS TO THE TRUTH, ACCURACY, OR COMPLETENESS OF THE INFORMATION CONTAINED THEREIN OR THE SUITABILITY OF ANY OF THE LICENSED DATA FOR LICENSEE’S INTENDED PURPOSES. EXCEPT AS EXPRESSLY SET FORTH IN THIS SECTION, ALL WARRANTIES, EXPRESS OR IMPLIED, INCLUDING, BUT NOT LIMITED TO, WARRANTIES OF MERCHANTABILITY, NON-INFRINGEMENT OR FITNESS FOR A PARTICULAR PURPOSE ARE HEREBY DISCLAIMED. THE PARTIES PROVIDE SOLELY AND EXCLUSIVELY THE WARRANTY DESCRIBED IN SCHEDULE “C” TO THIS AGREEMENT (“E-MAIL DATABASE LIMITED WARRANTY), WHICH IS HEREBY INCORPORATED INTO THIS AGREEMENT.
10. Limited Liability. HL’S AGGREGATE LIABILITY, IF ANY, FOR DAMAGES RELATING TO THIS AGREEMENT OR TO THE LICENSED DATA, UNDER ANY LEGAL OR EQUITABLE THEORY, SHALL NOT EXCEED FEES PAID BY LICENSEE FOR ALL SERVICES DURING THE TWELVE (12) MONTHS IMMEDIATELY PRECEDING THE DATE OF THE CLAIM THAT GAVE RISE TO SUCH LIABILITY. IN NO EVENT SHALL HL BE LIABLE FOR ANY INDIRECT, INCIDENTAL, SPECIAL OR CONSEQUENTIAL DAMAGES OF ANY KIND INCLUDING, BUT NOT LIMITED TO, LOST INCOME, LOST REVENUE, OR LOST PROFITS, WHETHER BASED IN CONTRACT, TORT, OR ANY OTHER THEORY, EVEN IF HL HAS BEEN INFORMED OF THE POSSIBILITY OF SUCH DAMAGES.
11. Indemnification and Insurance. Licensee shall maintain, throughout the term of this Agreement, adequate professional and comprehensive general insurance. Upon written request of HL, Licensee shall provide to HL satisfactory evidence of such coverage. Licensee shall, at its own expense, defend against any claims, demand, suit or proceeding, and pay the actual damages incurred arising from (a) Licensee’s misuse of the HL Content, Data, and Licensed Database(s), (b) any data provided by Licensee to HL that is infringing on the proprietary or privacy rights of a third party, or (c) any customizations made by HL at the specific direction of Licensee. Each Party (the “Indemnifying Party”) will indemnify and hold harmless the other Party and its shareholders, officers, directors, employees, and agents, from and against any damages, liabilities, losses, costs, and expenses, including reasonable attorney fees, awarded to a third party by a court of competent jurisdiction that resulted from or arose from (x) any negligent act or omission of the Indemnifying Party; (y) Indemnifying Party’s material breach of any provision of this Agreement; or (z) Indemnifying Party’s breach of any duties and obligations under this Agreement.
12. Term and Termination.
12.1. Term. This Agreement shall remain in full force and effect for the entire period that HL provides services to Licensee or Licensee uses any Licensed Data, whichever is later (the “Term”).
12.2. Termination for Cause. Either Party may immediately terminate this Agreement, and simultaneously all Order Forms, upon a material breach by other Party if such breach is not cured within thirty (30) business days after receipt of written notice from the non-breaching Party. A material breach includes but may not be limited to the failure of either Party to meet any substantive covenant, provision, or obligation provided for in this Agreement which would permit the other Party to either compel performance or collect damages because of such breach. Notwithstanding the foregoing, HL may terminate this Agreement, and simultaneously all Order Forms, if Licensee is involved in the cessation, reorganization, sale, merger, bankruptcy, or insolvency of its business.
Upon termination or expiration of this Agreement, all rights to the Licensed Data cease, except as specifically granted under Section 13 pertaining to Established Business Relationships (EBRs) as further defined in Section 14. Upon termination, Licensee agrees to immediately pay any outstanding monies due to HL. Licensee shall return to HL, or shall remove, delete, or destroy, or render useless all copies of the Licensed Data. In order to ensure compliance with the termination provision of this Section 12, Licensee shall provide HL with the Certification of Destruction or Return of Confidential and Proprietary Information for executed by an officer of Licensee in the form attached hereto as Schedule “D” stating that Licensee has complied with the termination provisions of this Agreement. In the event of Licensee’s breach of Sections 3, 4, or 6, Licensee acknowledges that HL will suffer irreparable harm as a result of such default by Licensee and that HL’s remedies at law are inadequate. Licensee agrees that HL shall have the right to obtain immediate injunctive relief to protect any of its proprietary rights or other rights in and to the Licensed Data.
12.3. Auto-Renewal. The agreement will automatically renew unless licensee gives written notice of termination 60 days before the end of the current term.
12.4. Continued-Usage. Licensee acknowledges and agrees that any use of licensed data beyond the contract term shall be deemed as a renewal and will be subject to the Renewal Terms and Conditions set forth in this Agreement.
13. Post-Termination Rights.
Upon the expiration or termination of this Agreement, the Client shall cease the use of Licensed Data, except where an Established Business Relationship (EBR) exists. The Client may retain and continue to use contact information solely from such EBRs, under the conditions outlined herein, except in cases where termination is due to the Client’s material breach of this Agreement.
14. Definition and Conditions of an Established Business Relationship (EBR).
An Established Business Relationship is defined as a voluntary, two-way communication between the Client and an individual initiated by either party. This communication must involve an inquiry, transaction, or dialogue about the Client’s products or services, leading to the creation of an EBR Record. An EBR Record includes identifiable documentation of the contact, such as:
15. Dispute Resolution. It is understood and agreed that any dispute, controversy, or question arising under this Agreement shall be decided by binding arbitration by an arbitrator selected by the Parties. The proceeding shall be governed by the rules of the American Arbitration Association and held in Atlanta, GA. If the Parties are unable to agree upon such an arbitrator within thirty (30) days after either Party has given the other Party written notice of its desire to submit the dispute, controversy, or question for decision, then either Party may apply to the American Arbitration Association for the appointment of an arbitrator. Notwithstanding the foregoing, either Party may seek any right or remedy in any forum (judicial, equitable or otherwise) in order to protect its proprietary information or Intellectual Property Rights.
16. Audit Rights. HL is permitted, upon reasonable notice, to conduct audits within calendar thirty days (30) to determine compliance with this Agreement. Licensee agrees to comply and cooperate in all such audits. HL may conduct audits at Licensee’s location during normal business hours upon reasonable notice to Licensee. All information gathered in such audit shall be deemed confidential and will not be disclosed to any third party absent court or arbitration process or material breach of this Agreement. Both Parties are responsible for all their audit cost unless a prior audit reveals a material breach of this Agreement which then the cost will be borne by the Licensee.
17. General Terms and Conditions.
17.1. Specific Performance. Notwithstanding provisions of Section 13, any alleged, actual, or suspected breach of Confidentiality, Intellectual Property Rights or of the provisions or restrictions hereof, and all actions to ensure compliance with Section 6 or Section 15.10, shall be specifically enforceable in court only (without the necessity to post any bond). The Parties acknowledge and agree that the enforcing Party shall be entitled to equitable relief, including injunction and specific performance. The right to injunction and specific performance shall not in any way be deemed diminished by reason of the aggrieved Party’s termination of this Agreement for any reason. If an injunction issues, the period of the injunction shall date from the date of injunction entry and not from the date on which the violation commenced (without waiving the enjoining Party’s right to recover damages dating from the date on which such violation occurred). The Parties agree that they shall require all judgments, orders, and other matters be sealed from the public so as to prevent the public disclosure of same, including, without limitation, the Confidential Information of either Party. In the event that a proceeding is brought, in compliance with the above provisions, to determine the enforceability of any such provisions or restrictions (which restrictions the Parties acknowledge to be reasonable), which proceeding is not accompanied by an injunction restraining the Party allegedly violating such restrictions, and said provisions are subsequently determined to be enforceable, then the duration of such restrictions shall be deemed tolled from the date of the filing of such proceeding until the final resolution (including by permitted appeal, if any) of such issue, and said restrictive periods shall be revived and commence as of the date of said final disposition.
17.2. Jurisdiction. The Parties agree that any enforcement action or proceeding allowed shall be brought in the U.S. District Court or in the Superior Court located in Atlanta, Georgia.
17.3. Notice. All notices and other communications required or permitted to be given in connection with this Agreement shall be in writing and delivered by (a) U.S. mail, (b) Federal Express (or similar reputable express courier), or (c) electronic mail. All such notice shall be deemed given five (5) days after mailing, upon delivery if hand delivered, or upon receipt if transmitted by electronic mail.
If to HL:
HEALTHLINK DIMENSIONS, LLC
1001 SUMMIT BLVD NE, SUITE 1125
ATLANTA, GA 30319 U.S.A.
Attn. General Manager
[Email as listed on most recent Order Form.]
If to Licensee:
[to the name, address, and/or email listed on the most recent Order Form.]
17.4. Governing Law. This Agreement shall be governed by Georgia law, without regard to any contrary choice or conflicts of law principles.
17.5. Assignment. HL may assign this Agreement, to a wholly owned subsidiary or affiliate or to any affiliate or entity resulting from a sale, combination, or transfer of all or substantially all of the assets or capital stock, or from any other corporate form of reorganization. If assigned, this Agreement shall inure to the benefit of, and be binding upon, the respective successors and assignees. This Agreement may not be assigned by Licensee in any manner (including by operation of law) without the prior written consent of HL.
17.6. Severability and Enforceability; Headings. If any term or provision of this Agreement is found to be illegal, invalid, or unenforceable then: (i) such provision shall be construed as closely as possible to the Parties original intent in order to render such provision legal, valid, or enforceable, as applicable; and (ii) the remaining terms hereof, together with such reconstructed provision, shall constitute the Parties entire agreement hereof.
17.7. Entire Agreement; Waiver. This Agreement sets forth the entire understanding and agreement of the Parties, and supersedes any and all oral or written agreements or understandings between the Parties, as to the subject matter of this Agreement. This Agreement may only be modified or amended by a fully executed writing signed by duly authorized representatives of both Parties. The waiver of a breach of any provision of this Agreement will not operate or be interpreted as a waiver of such provision or any other or subsequent breach.
17.8. Force Majeure. Neither Party shall be in default or otherwise liable for any delay in or failure of its performance under this Agreement if such delay or failure arises by any reason beyond its reasonable control, including any act of God, any acts of the common enemy, the elements, earthquakes, floods, fires, epidemics, riots, failures or delay in transportation or communications. The Parties will promptly inform and consult with each other as to any of the above causes, which in their judgment may or could be the cause of a delay in the performance of this Agreement. Any episode of force majeure which continues for sixty (60) days from the date of notification of its existence shall give the non-affected Party the right to terminate this Agreement upon thirty (30) days additional notice.
17.9. Independent Contractors. The Parties are independent contractors, and no agency, partnership, joint venture, employee-employer, or franchisor-franchisee relationship is intended or created by this Agreement. Neither Party shall make any warranties or representations on behalf of the other Party.
17.10. Non-solicitation. During the Term of this Agreement and for a period of two (2) years following termination of this Agreement, neither Licensee nor its Representatives will: (i) solicit for employment, employ, or contract for personal services with any past or present employee, whether full or part-time, of HL or its affiliates, without the prior written consent of HL; or (ii) contract either directly or indirectly, for the purpose of bypassing HL, with any third parties that HL utilizes which HL has under Agreement.
17.11. Survival of Provisions. This following section will survive expiration or any termination of this Agreement: 4, 5, 6, 8, 9, 10, 11 12.2, 13, 14, 15, 16, and 17.10.
17.12. Compliance with Law. The Parties each represent and warrant that they will each comply with all laws applicable to their respective performance under this Agreement, including but not limited to, the California Consumer Privacy Act as amended (“CCPA”); the California Delete Act (Cal. Civ. Code §§ 1798.99.80 et seq.) and any regulations or platform requirements promulgated thereunder (including the Delete Request and Opt-Out Platform (“DROP”)); the Texas Data Broker Law (Tex. Bus. & Com. Code Ch. 509); the Oregon Data Broker Law (ORS 646A.592 et seq.); the Vermont Data Broker Law (9 V.S.A. Ch. 62); the Telephone Consumer Protection Act, 47 U.S.C. §227 (“TCPA”), and other applicable U.S. state privacy, data broker, and securities laws, each as amended, replaced, superseded, or enacted from time to time. The Parties each represent and warrant, further, that they will each comply with and, in their performance under this Agreement shall act in accordance with, the most recent Data Processing Agreement entered into by the Parties (“DPA”), which is attached hereto as Schedule “E” and, incorporated by reference herein, and made a part hereof.
17.13. Authority to Execute. HL and Licensee represent and warrant that all necessary and required corporate approvals have been obtained to lawfully permit their respective organizations to enter into and be bound by this Agreement.
17.14. Counterparts. This Agreement may be executed in one or more counterparts, each of which shall be deemed an original but all of which together shall constitute one and the same instrument.
17.15. Amendment. HL may modify this Agreement at any time. All Order Forms will be governed by the version of this Agreement in effect when the Order Form was executed, unless HL provides Licensee notice of a subsequent modification and Licensee agrees to such modification in the manner specified in the notice.
SAMPLE
SCHEDULE “A”
LICENSED DATA AND MANAGED SERVICES
This Schedule is made and executed in accordance with the terms and conditions outlined in the Master Data License and Management Services Terms and Conditions effective as of the Start Date (as noted below) and remains in full force and effect until the End Date (as noted below).
Licensee acknowledges that fees will increase for renewal of licensed data and managed services on each renewal term of this Schedule at a rate of five percent (5%) higher than previous term.
Start Date End Date
|
Product |
Line Item Description |
Quantity |
Sales Price |
Subtotal |
Total Price |
|
|
|
|
|
|
|
Total Price
Payment Terms Net 30
PO #
Billing Frequency One-Time
By the signatures of the duly authorized representatives below, the parties, intending to be legally bound, agree to all the provisions of this Schedule “A” and agree to and ratify the standard HealthLink Dimensions Master Data License and Management Services Agreement Terms and Conditions, including the HealthLink Unified Data Processing Agreement, both of which are hereby incorporated herein by reference.
The provision of a purchase order number, if required, is the responsibility of Licensee and should be included by Licensee on this Schedule “A.”

SCHEDULE “B”
HEALTHLINK DIMENSIONS TPA, “THIRD PARTY AGREEMENT”
THIRD PARTY SUPPORT USER AGREEMENT FOR USAGE OR SHARING OF LICENSED DATA. THIS AGREEMENT (the “Agreement”) is entered into on the date set forth below (the “Effective Date”) by and between HEALTHLINK DIMENSIONS. a corporation (“DBL”), and LICENSEE NAME (“Third Party Support User”). Each of the Exhibits listed below is incorporated into this Agreement as if fully set forth above the signatures. The Agreement relates to the use by Third Party Support User of Licensed Variables on behalf of LICENSEE/USER. and the additional entities listed below. The Term of the Agreement is from DATE (“Effective Date”) to DATE (“Initial Termination Date”).
|
Client Name |
Licensed Variables |
# of Records |
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
LICENSEE |
|
HealthLink Dimensions, LLC
|
||
|
By: |
\s1\ |
|
By: |
\s2\ |
|
Print Name: |
\n1\ |
|
Print Name: |
\n2\mmm |
|
Title: |
\t1\ |
|
Title: |
\t2\ |
|
Date: |
\d1\ |
|
Date: |
\d2\ |
SCHEDULE “C”
E-MAIL DATABASE LIMITED WARRANTY
HL warrants that:
1. It has used commercially reasonable efforts to comply with applicable legal and regulatory requirements and prevailing industry standards while compiling the email Licensed Data.
2. To the reasonable knowledge of HL, the email Licensed Data consist of email addresses of recipients who have agreed with HL to receive messages of the type provided, and who have not communicated their desire to stop receiving future commercial electronic mail messages.
3. Provision of the database to Licensee does not violate any contract between HL and a third party insofar as HL is reasonably aware.
4. At least 90% of the email addresses should result in delivered emails (excluding soft bounces) when deployed by HL. This warranty on deliverability shall last for 120 days after being ordered by Licensee. No deliverability guarantee applies if deployment takes place outside the one hundred twenty (120) day period.
5. At least 80% of the email addresses should result in delivered emails (excluding soft bounces) when deployed by Licensee or an authorized consultant or independent contractor. This warranty on deliverability shall last for 120 days after being ordered by Licensee. No deliverability guarantee applies if deployment takes place outside the one hundred twenty (120) day period.
LICENSEE LIMITATION ON USE AND WARRANTY:
Limitations on use of the deliverable email addresses:
Licensee shall use the deliverable email addresses in compliance with the Federal CAN-SPAM laws, statutes, rules, and regulations.
Licensee understands that deliverable email addresses have not been collected for credit purposes and are not intended to be indicative of any consumer’s credit worthiness, credit standing, credit capacity, or other characteristics listed in Section 603(d) of the Fair Credit Reporting Act, 15 U.S.C. § 1681 et seq. ("FCRA”).
Licensee Warranty:
Licensee represents and warrants that Licensee will not use any deliverable email addresses as a factor in establishing any consumer’s eligibility for (i) credit or insurance used primarily for personal, family or household purposes, (ii) employment purposes, or (iii) other purposes restricted by the FCRA.
i. The message content will not contain any of the following: (a) any unlawful, threatening, abusive, libelous, defamatory, obscene, pornographic, profane, or otherwise objectionable information; (b) any misleading or deceptive information, or any known misrepresentation with respect to products or services offered by Licensee; (c) any chain letters, illegal pyramid, or other such schemes; (d) any information known to be in violation of any person’s copyright, trademark or any other intellectual property rights; (e) any deceptive information which would imply endorsement, affiliation, or sponsorship with any entity or person other than Licensee without written consent of such entity/person; or (f) any known virus, worm, time bomb, or similar contaminating/destructive element.
ii. It will be clear in the message content provided by Licensee that the email is an advertisement.
iii. The opt-out link provided by Licensee will be functional for 30 days, and Licensee will act on each opt-out request within 10 business days from the request.
iv. Licensee will maintain a list of those individuals who have communicated the desire to stop receiving future commercial electronic mail messages from Licensee.
v. The opt-out information gathered by Licensee in connection with the List will not be used for any purpose except opt-out suppression in accordance with applicable laws, unless written permission is otherwise granted by HL.
vi. Licensee will use the List only as permitted under this Agreement.
vii. All email messages will clearly and conspicuously display Licensee opt-out header and/or footer.
viii. The email messages must have a functioning “Reply” capability for opt-outs, and this capability must be one that does not misrepresent or misdirect the opt-out return message.
ix. The e-mail message must contain a physical street address for Licensee return mail that is actively monitored daily.
x. It will use a correct “from” email domain, i.e., it will use Licensee and not that of HL.
xi. The “subject” line of the email will be clear and truthful and must match the content of the e-mail communication.
SCHEDULE “D”
CERTIFICATION OF DESTRUCTION OR RETURN OF
CONFIDENTIAL AND PROPRIETARY INFORMATION
TO: HealthLink Dimensions, LLC (“HL”)
RE: Confidential and Proprietary Information received under the Master Data License and Management Services Agreement (“Agreement”) dated as of , and entered into by and between HealthLink Dimensions, LLC, and (Licensee Name). .
I hereby confirm that in accordance with Section 12.2 of the Agreement:
- all hard-copy documents and materials have been destroyed;
- all electronic and non-electronic copies of documents and materials have been destroyed; and
- all electronic and non-electronic copies of documents and materials have been removed from all electronic apparatus and data storage media under my direction or control.
Date:
Signature:
Name:
Title:
SCHEDULE “E”
UNIFIED DATA PROCESSING AGREEMENT
This Unified Data Processing Agreement (the “Agreement”) is entered into as of the date of execution of the Master Services Agreement (defined herein) (the “Effective Date”) by and between HealthLink Dimensions, LLC (“HealthLink”), and the counterparty to that Master Services Agreement (“Company”). HealthLink and Company are sometimes referred to individually as a “Party” and collectively as the “Parties.”
This Agreement is intended to serve as a single data protection addendum that applies to the Parties’ Processing of Personal Information under the applicable Master Services Agreement, order, work order, data license, statement of work, or comparable governing agreement (collectively, the “Master Services Agreement”). The Parties acknowledge that the capacity in which either Party acts may differ by Processing Activity and may include Controller, Processor, or, where applicable, Processor acting in a chain of Processing in which both Parties are Processors for an upstream Controller.
1. Scope and Applicability.
1.1 This Agreement applies to each Processing Activity involving Personal Information performed by either Party in connection with the Services. A Party’s applicable Processing Role (e.g., Controller, Processor, etc.) for each material Processing Activity shall be determined by reference to the actual facts and Applicable Data Protection Law; contractual labels shall not control a regulator or court.
1.2 This Agreement governs, as applicable: (a) Controller-to-Controller Processing, where each Party independently determines the purposes and means of its Processing; (b) Controller-to-Processor Processing, where one Party determines the purposes and means and the other Processes Personal Information on its behalf; and (c) Processor-to-Processor Processing, where both Parties are Processors for an identified upstream Controller and the receiving Party acts as a Subprocessor or further Processor of the disclosing Party.
1.3 Unless otherwise expressly stated in the Master Services Agreement, this Agreement is effective for the term of the Master Services Agreement and applies to Personal Information Processed before or after the Effective Date to the extent necessary to perform the Services, satisfy Applicable Data Protection Law, or resolve an Individual request, Information Breach, investigation, or legal claim.
1.4 Nothing in this Agreement requires either Party to disclose regulated health information, payment card information, financial account information, biometric information, or other specially regulated information unless the Parties expressly identify the applicable category and required safeguards in the Master Services Agreement.
2. Processing Roles and Responsibility.
2.1 Role allocation is determined separately for each Processing Activity. A Party is a “Controller” when it determines, alone or jointly with another Controller, the purposes and means of Processing. A Party is a “Processor” when it Processes Personal Information on behalf of a Controller and does not determine the purposes and means except to the limited extent permitted by Applicable Data Protection Law.
2.2 Controller-to-Controller. Where both Parties are Controllers, each Party independently determines the purposes and means of its Processing and is solely responsible for its own Controller obligations. Neither Party is the Processor or Service Provider of the other for that Processing Activity.
2.3 Controller-to-Processor. Where HealthLink is the Controller and Company is the Processor, Company shall Process Personal Information only on HealthLink’s documented instructions and for the purposes described in the Master Services Agreement. Where Company is the Controller and HealthLink is the Processor, HealthLink shall do the same on Company’s documented instructions.
2.4 Processor-to-Processor. Where both Parties are Processors in relation to the same Personal Information, the Parties shall identify the upstream Controller. The disclosing Party shall remain responsible for the obligations applicable to it as an initial Processor, and the receiving Party shall act only as a further Processor/Subprocessor to the extent authorized by the upstream Controller and the disclosing Party. Neither Party shall acquire Controller status merely by receiving Personal Information from the other; however, a Party that independently determines purposes and means will be a Controller for that Processing.
2.5 Each Party shall comply with the obligations applicable to its role for each Processing Activity. Where a Party has different roles for different Processing Activities, its obligations shall be determined separately for each activity.
3. Description of Processing.
3.1 The subject matter, duration, nature and purpose of Processing, categories of Personal Information, categories of Individuals, and applicable Processing Roles shall be described in the Master Services Agreement.
3.2 The purposes may include, as applicable, delivery, measurement, attribution, optimization or administration of advertising or marketing services; data licensing, enrichment, matching, analytics, or professional contact data services; customer or account management; fraud and security; compliance; and other purposes expressly identified in the Master Services Agreement.
3.3 Unless otherwise specified in the Master Services Agreement, neither Party shall intentionally provide the other with Personal Information or any data that imposes specific data security or data protection obligations in addition to or different from those specified in this Agreement or the Master Services Agreement. (e.g., certain regulated health or payment card information).
4. Controller Obligations.
4.1 Each Party acting as a Controller shall independently establish and document an appropriate lawful basis for Processing, provide required notices, honor applicable privacy choices, maintain records of Processing where required, conduct required assessments, and comply with applicable Individual rights.
4.2 Each Controller represents and warrants that it has the legal right to disclose Personal Information to the other Party for the applicable Processing Activity, and that the disclosure and the other Party’s authorized Processing are consistent with applicable notices, consents, opt-outs, contractual restrictions, and Applicable Data Protection Law.
4.3 A Controller shall not instruct or require a Processor to Process Personal Information in a manner that violates Applicable Data Protection Law. Each Controller shall provide documented instructions that are sufficiently specific to permit the Processor to comply with this Agreement.
4.4 Where a disclosure constitutes a Sale, Share, targeted advertising disclosure, or comparable regulated disclosure under U.S. privacy law, each Party shall independently comply with the obligations applicable to its role, including applicable notice, opt-out, contractual, recordkeeping, and downstream restrictions. Where applicable, a Party acting as a Service Provider or Contractor shall comply with the restrictions applicable to that status.
5. Processor Obligations.
5.1 A Party acting as a Processor shall Process Personal Information solely for the purpose of providing the Services in accordance with the Master Services Agreement and only on documented instructions from the applicable Controller.
5.2 The Processor shall immediately inform the Controller if, in its reasonable opinion, an instruction infringes Applicable Data Protection Law. The Processor may suspend the affected Processing to the extent reasonably necessary to avoid unlawful Processing while the Parties resolve the issue.
5.3 The Processor shall ensure that persons authorized to Process Personal Information are bound by confidentiality obligations and receive appropriate privacy and security training.
5.4 The Processor shall not Sell or Share Personal Information or retain, use, disclose, combine, or otherwise Process Personal Information for a purpose other than the documented Business Purpose or other permitted purpose stated in the Master Services Agreement, except where Applicable Data Protection Law expressly permits the Processing. Nothing in this Section restricts a Processor from Processing information as necessary to comply with law, detect or respond to security incidents, prevent fraud or illegal activity, or exercise or defend legal rights, to the extent permitted by Applicable Data Protection Law and consistent with the applicable U.S. privacy requirements.
5.5 Where required by Applicable Data Protection Law, the Processor shall make available to the Controller information reasonably necessary to demonstrate compliance and shall permit and contribute to audits and inspections as described in Section 10.
6. Individual Privacy Rights and Requests.
6.1 Each Controller is independently responsible for responding to verified requests from Individuals relating to Personal Information for which it is the Controller.
6.2 A Processor shall provide reasonable assistance to the Controller, taking into account the nature of Processing, to enable the Controller to respond to requests for access, correction, deletion, portability, restriction, objection, opt-out, limitation, and other rights applicable under Applicable Data Protection Law.
6.3 If a Processor receives a request that identifies the other Party as Controller, the Processor shall promptly forward the request to the Controller and shall not respond except as authorized by the Controller or required by law.
6.4 Each Party shall honor documented deletion, opt-out, or suppression instructions communicated by the other Party. This includes applicable consumer Deletion Mechanisms and signals, including the California Delete Request and Opt-Out Platform (DROP), where applicable.
6.5 Neither Party shall reintroduce Personal Information or an identifier deleted or suppressed at the direction of the other Party for the same purpose in violation of Applicable Data Protection Law.
7. Affiliates and Subprocessors.
7.1 A Controller may authorize its Processor to engage Affiliates and Subprocessors as necessary to provide the Services. Where required by Applicable Data Protection Law, such authorization shall be specific or general written authorization.
7.2 The Processor shall provide notice of material changes to its Subprocessors where required by Applicable Data Protection Law and shall provide the Controller a reasonable opportunity to object on documented privacy or security grounds. If an objection cannot reasonably be resolved, the Parties shall discuss an alternative, or the Controller may terminate the affected Processing to the extent permitted by the Master Services Agreement.
7.3 The Processor shall impose written obligations on each Subprocessor that provide a level of protection for Personal Information no less protective than required by this Agreement and Applicable Data Protection Law. The Processor remains responsible for its Subprocessors’ compliance to the extent required by Applicable Data Protection Law.
7.4 Each Party may engage its own Affiliates and service providers for Controller Processing, provided that it remains responsible for their Processing and imposes appropriate contractual and legal safeguards.
8. Security and Confidentiality.
8.1 Each Party shall implement and maintain appropriate technical and organizational measures designed to protect Personal Information against accidental or unlawful destruction, loss, alteration, unauthorized disclosure, or unauthorized access, taking into account the nature, scope, context, purposes, and risks of Processing.
8.2 Such measures shall include, as appropriate, access controls and least privilege; authentication; encryption in transit and at rest where appropriate; logging and monitoring; vulnerability and patch management; secure development and change management; backup and recovery; data segregation; physical security; incident response; personnel confidentiality and training; business continuity; and periodic testing and assessment of security effectiveness.
8.3 Each Party shall maintain confidentiality of Personal Information and shall ensure that personnel and contractors with access are subject to appropriate confidentiality obligations.
9. Information Breaches and Security Incidents.
9.1 A Party that becomes aware of an Information Breach affecting Personal Information received from or Processed on behalf of the other Party shall notify the other Party without undue delay and, where feasible, within seventy-two (72) hours after becoming aware of the breach.
9.2 The notice shall include, to the extent then known: the nature of the incident; categories and approximate number of Individuals and records affected; likely consequences; containment and remediation measures; and a point of contact. The Party may supplement the notice as information becomes available.
9.3 The Parties shall reasonably cooperate in investigating, mitigating, documenting, and responding to an Information Breach. Each Party remains responsible for making notifications to Individuals, regulators, law enforcement, or other authorities that it is legally required to make in its capacity as Controller.
9.4 Neither Party shall make a public statement identifying the other Party in connection with an Information Breach without reasonable consultation, except where required by law.
10. Compliance Verification and Audits.
10.1 Each Party shall maintain records reasonably sufficient to demonstrate compliance with this Agreement and Applicable Data Protection Law.
10.2 Where a Party is acting as a Processor, the Controller may, upon reasonable written notice and no more than once in a twelve-month period unless more frequent verification is required by law, a regulator, or a documented Information Breach, obtain reasonable compliance information, including current independent audit reports, certifications, security questionnaires, or written attestations.
10.3 A Processor shall permit audits or inspections required by Applicable Data Protection Law. Audits shall be conducted during normal business hours, subject to reasonable security, confidentiality, and operational restrictions and without unreasonable disruption.
10.4 A Controller-to-Controller relationship does not create a general unilateral audit right. Each Controller shall independently demonstrate its own compliance, and the Parties shall provide reasonable cooperation where necessary to address a regulator request, Individual rights request, or Information Breach.
10.5 Each Party shall bear its own ordinary compliance and audit costs. A Party shall not be required to incur material extraordinary costs for an audit beyond the scope required by Applicable Data Protection Law without agreement on the allocation of those costs.
11. Data Protection Impact Assessments and Regulatory Cooperation.
11.1 A Processor shall provide reasonable assistance to the Controller with data protection impact assessments, prior consultations, records, security assessments, and other regulatory obligations to the extent required by Applicable Data Protection Law and relevant to the Services.
11.2 Each Party shall promptly notify the other of any material complaint, inquiry, investigation, or request from a supervisory authority or governmental authority concerning Personal Information received from or Processed for the other Party, unless prohibited by law.
11.3 The Parties shall reasonably cooperate with each other and with competent supervisory authorities where required by law.
12. International Data Transfers.
12.1 No Party shall transfer Personal Information internationally in a manner prohibited by Applicable Data Protection Law.
12.2 For transfers subject to GDPR Chapter V, the Parties shall use a lawful transfer mechanism, which may include an applicable adequacy decision, the EU-U.S. Data Privacy Framework where the U.S. recipient is eligible and certified for the relevant data, the European Commission Standard Contractual Clauses adopted by Commission Implementing Decision (EU) 2021/914, Binding Corporate Rules, or another lawful mechanism recognized under Applicable Data Protection Law.
12.3 The Parties shall perform any transfer impact assessment required by Applicable Data Protection Law and shall implement supplementary measures where required. If a transfer mechanism becomes invalid, unavailable, or insufficient, the Parties shall cooperate in good faith to implement a lawful alternative.
12.4 Where the UK GDPR applies, the Parties shall use an applicable UK transfer mechanism, including the UK International Data Transfer Agreement or UK Addendum to the EU SCCs, as applicable.
13. Return, Deletion, and Retention.
13.1 Upon termination or expiration of the Services, or earlier upon the Controller’s written request where required by Applicable Data Protection Law, a Processor shall return or delete Personal Information in accordance with the Controller’s instructions, unless retention is required by law.
13.2 A Processor may retain limited copies in secure archives where required by law or reasonably necessary for legal claims, audit, fraud prevention, security, or compliance, provided the retained information is isolated and protected and is not further Processed except for the purpose requiring retention.
13.3 Each Controller remains responsible for its own retention schedule. Deletion obligations shall not require a Party to delete information where doing so would conflict with a legal retention obligation.
14. Legal Requirements and Government Access.
14.1 A Party may be required by law to disclose Personal Information pursuant to subpoena, court order, regulatory demand, or government request, including requests for national security or law-enforcement purposes.
14.2 To the extent legally permitted, the receiving Party shall promptly inform the other Party and use reasonable efforts to redirect the requesting authority to the applicable Controller.
14.3 The receiving Party shall assess whether the request is legally valid and binding and shall resist unlawful or overbroad requests to the extent permitted by law. It shall disclose only the minimum information legally required.
15. Definitions.
15.1 “Applicable Data Protection Law” means all applicable federal, state, local, foreign, and international privacy, data protection, data security, breach-notification, consumer-protection, data broker, and direct-marketing laws and regulations governing the Processing, including, as applicable, the GDPR, the California Consumer Privacy Act as amended (“CCPA”), the California Delete Act (Cal. Civ. Code §§ 1798.99.80 et seq.) and any regulations or platform requirements promulgated thereunder (including the Delete Request and Opt-Out Platform (“DROP”)), the Texas Data Broker Law (Tex. Bus. & Com. Code Ch. 509), the Oregon Data Broker Law (ORS 646A.592 et seq.), the Vermont Data Broker Law (9 V.S.A. Ch. 62), the Telephone Consumer Protection Act, 47 U.S.C. §227 (“TCPA”), applicable U.S. state comprehensive privacy laws; state data broker and deletion laws; and sector-specific laws applicable to the data at issue each as amended, replaced, superseded, or enacted from time to time.
15.2 “CCPA” means the California Consumer Privacy Act, as amended by the California Privacy Rights Act, and implementing regulations, as amended from time to time.
15.3 “Controller” means the natural or legal person, public authority, agency, or other body that determines the purposes and means of Processing Personal Information, as set forth under Applicable Data Protection Law. Where Applicable Data Protection Law uses another term, Controller includes the equivalent concept, including “business” or other analogous regulated entity where applicable.
15.4 “Processor” means a natural or legal person, public authority, agency, or other body that Processes Personal Information on behalf of a Controller, as set forth under Applicable Data Protection Law. Where Applicable Data Protection Law uses another term, Processor includes the equivalent concept, including “business” or other analogous regulated entity where applicable.
15.5 “Processing/Process” means any operation or set of operations performed on Personal Information, whether or not by automated means, including collection, access, recording, organization, storage, alteration, retrieval, consultation, use, disclosure, transmission, dissemination, combination, restriction, deletion, or destruction, as set forth under Applicable Data Protection Law. Where Applicable Data Protection Law uses another term, Processing/Process includes the equivalent concept.
15.6 “Processing Activity” means a distinct category or purpose of Processing performed under the Services and identified in the Master Services Agreement.
15.7 “Personal Information” means personal data, personal information, personally identifiable information, or equivalent information regulated by Applicable Data Protection Law.
15.8 “Individual” means an identified or identifiable natural person, including a “data subject,” “consumer,” or equivalent term under Applicable Data Protection Law.
15.9 “Information Breach” means a breach of security leading to accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to Personal Information that compromises its security, confidentiality, or integrity.
15.10 “Sale,” “Share,” “Service Provider,” “Contractor,” “Business Purpose,” and “Commercial Purpose” means the meanings assigned under the CCPA or other applicable U.S. privacy law, as applicable to the relevant Processing.
15.11 “Subprocessor” means a Processor engaged by another Processor to Process Personal Information on behalf of the same upstream Controller.
15.12 “Upstream Controller” means the Controller for whom one or both Parties Process Personal Information in a Processor-to-Processor relationship.
15.13 “Affiliate” means an entity that controls, is controlled by, or is under common control with a Party.
15.14 “Deletion Mechanism” means any consumer-facing platform, registry, or signal established by Applicable Data Protection Law for deletion, opt-out, suppression, or similar requests directed to data brokers or other business, including the California Delete Request and Opt-Out Platform (DROP) and comparable mechanisms.
15.15 “Services” means the services or activities specified in the Master Services Agreement.
15.16 “Master Services Agreement” means the applicable master agreement, order, work order, data license, statement of work, service specification, or comparable governing document between the Parties.
15.17 “EU SCCs” means the Standard Contractual Clauses adopted by the European Commission in Commission Implementing Decision (EU) 2021/914, including the applicable Module and Annexes.
15.18 Other capitalized terms have the meanings provided in the Master Services Agreement unless defined differently in this Agreement.
16. Liability and Indemnification.
16.1 Each Party is responsible for its own violations of Applicable Data Protection Law and this Agreement in proportion to its role and conduct. Subject to any aggregate liability cap or other limitation in the Master Services Agreement, each Party shall indemnify, defend, and hold harmless the other from third-party claims and regulatory penalties to the extent arising from its material breach of this Agreement or Applicable Data Protection Law.
16.2 Nothing in this Agreement limits a Party’s liability to the extent such limitation is prohibited by Applicable Data Protection Law or the applicable EU SCCs.
17. Insurance.
The Parties shall maintain commercially reasonable cyber-liability or equivalent insurance coverage appropriate to the nature and volume of Personal Information Processed under the Services and consistent with the insurance obligations in the Master Services Agreement.
18. Term and Termination.
18.1 This Agreement becomes effective on the Effective Date and remains in effect for so long as the Master Services Agreement remains in effect. Sections relating to confidentiality, security, return/deletion, and liability shall survive any termination or expiration.
18.2 If a Party materially breaches this Agreement and fails to cure within a reasonable period after notice, the non-breaching Party may suspend the affected Processing or terminate the affected Services to the extent permitted by the Master Services Agreement and Applicable Data Protection Law.
18.3 If a change in Applicable Data Protection Law makes a material provision unlawful or inadequate, the Parties shall cooperate in good faith to amend the Agreement or implement an alternative lawful mechanism.
19. Governing Law and Miscellaneous.
19.1 Governing Law. Except to the extent superseded by mandatory Applicable Data Protection Law or the EU SCCs, this Agreement and any dispute arising from it shall be governed by the laws of the State of Georgia. Any dispute, controversy, or question arising under this Agreement shall be decided by binding arbitration by an arbitrator selected by the Parties. The proceeding shall be governed by the rules of the American Arbitration Association and held in Atlanta, GA. If the Parties are unable to agree upon such an arbitrator within thirty (30) days after either Party has given the other Party written notice of its desire to submit the dispute, controversy, or question for decision, then either Party may apply to the American Arbitration Association for the appointment of an arbitrator. Notwithstanding the foregoing, either Party may seek any right or remedy in any forum (judicial, equitable or otherwise) in order to protect its proprietary information or Intellectual Property Rights.
19.2 Amendments. Any modification must be in a written instrument signed by both Parties.
19.3 Severability. If any provision is held unenforceable, the remaining provisions remain in effect.
19.4 Precedence. In the event of conflict, the following order of precedence applies solely to the extent relevant to the conflict: (a) mandatory Applicable Data Protection Law; (b) the EU SCCs or other mandatory transfer instrument; (c) this Agreement; and (d) the Master Services Agreement. For Controller-to-Controller Processing, this Agreement does not convert either Party into a Processor or impose Processor obligations where the Parties are independent Controllers.
19.5 No third-party beneficiary. Except where mandatory law or an applicable transfer instrument provides otherwise, this Agreement does not confer contractual rights on any third party.

