Cognitiv Data Processing Addendum

Effective Date: July 20, 2026

This Cognitiv Data Processing Addendum (the “DPA”) forms part of the Agreement between Cognitiv and Customer (each a “Party” and together the “Parties”), pursuant to which Cognitiv provides its Services to Customer, reflects the agreement of the Parties with respect to the Processing of Personal Data, and takes effect as of the Effective Date.  

Capitalized terms used but not defined in this DPA have the meaning given to them in the Agreement.  If you are accepting this DPA on behalf of Customer, you warrant that: (a) you have read, understood and have the full legal authority to bind Customer to terms of this DPA; and (b) you agree, on behalf of Customer, to the terms of this DPA.

Background

  • Customer has engaged Cognitiv to provide certain advertising, measurement, and related Services, as further specified in the Agreement.
  • This DPA sets forth the privacy, security, and related terms applicable to the Agreement and the processing of Personal Data (defined below) pursuant to the Services.
  1. Scope and Interpretation. This DPA supplements the terms of, is incorporated by reference into, and is hereby made a part of, the Agreement. The Parties agree that the terms of this DPA apply to the performance of the Services and the Processing of Customer Personal Data pursuant to the Services and the Agreement.
  2. Definitions. The definitions set forth in this Section 2 apply to the terms of this DPA. Capitalized terms that are used but not otherwise defined in this in the DPA, shall have the meanings given to them under the Agreement. 
    1. Advertising Purposes means all advertising, analytics and related activities performed or provided to Customer under the Agreement, including first-party advertising, modeling, audience building, frequency capping, ad fraud detection, conversion tracking, ad performance measurement, negative targeting, research to generate campaign insights, viewability or suitability determinations, and, as applicable, Targeted Advertising and Third-Party Segment Creation.
    2. Agreement” means, collectively, the Order Form(s), proof of concept agreement, master services agreement, and/or other written agreement between the Parties, including any addenda, appendices, schedules, statements of work, exhibits, or amendments thereto, pursuant to which Customer has engaged Cognitiv to provide Services to Customer for Advertising Purposes. 
    3. Applicable Privacy Laws” means all applicable laws, rules and regulations governing privacy, data security, marketing, and the Processing of Personal Data, including (but not limited to) the CCPA, federal and state consumer privacy laws, and consumer health data privacy laws in the United States, to the extent applicable.
    4. Business Purpose” has the meaning set forth under the CCPA.
    5. CCPA” means the California Consumer Privacy Act together with the regulations promulgated thereto, each as amended.
    6. Cognitiv” means Cognitiv Corp., a Delaware corporation with offices at 215 Park Ave South, New York, NY 10003.
    7. Controller” means the entity which, alone or jointly with others, determines the purposes and means of the Processing of Personal Data and includes a “business” as defined by the CCPA.
    8. Consumer” means a natural person who is acting in a personal or household context or is otherwise a “consumer” as defined by Applicable Privacy Laws.
    9. Consumer Request” means any request from a Data Subject to exercise their privacy rights under Applicable Privacy Laws, including requests to access, correct, delete, or opt out of Sales, Sharing or Targeted Advertising.
    10. Customer” means the entity that executed the Agreement with Cognitiv (which for the avoidance of doubt includes an entity that has signed or entered into an Order Form for the Services). 
    11. Customer Personal Data” means Personal Data that: (i) is provided, disclosed or otherwise made available to Cognitiv, by or on behalf of Customer, pursuant to the Services, including (if applicable) any Personal Data that is transmitted or otherwise made available to Cognitiv, by or on behalf of Customer, pursuant to the Pixel; or (ii) that Cognitiv otherwise Processes as a Processor on behalf of Customer, pursuant to the provision of the Services. 
    12. Security Incident” means a confirmed unauthorized access by a third-party or confirmed accidental or unlawful destruction, loss, or alteration of Customer Personal Data.
    13. Data Subject” means the Consumer about whom certain Personal Data relates.
    14. De-identified Data” means “de-identified” or “deidentified” data or information as defined under Applicable Privacy Laws.
    15. Effective Date” means the date on which the Customer accepted, or the Parties otherwise agreed to, this DPA. 
    16. Order Form” means an order form, insertion order, statement of work, pixel request form, or other ordering document, pursuant to which Customer engages Cognitiv to provide Services for any of the Advertising Purposes. 
    17. Global Opt Out” means: (i) Global Privacy Control signals; and (ii) any other universal opt-out signal recognized by Applicable Privacy Laws, which enables a Consumer to opt out of the Sale, Sharing, or Processing of Personal Data for Targeted Advertising through an opt-out preference signal, which is sent by a platform, technology, or similar mechanism with the consent of the Consumer.
    18. Limited Advertising Purposes” means all Advertising Purposes except for (i) the Targeted Advertising Purposes, and (ii) to the extent the CCPA applies, only those Advertising Purposes that constitute a valid Business Purposes under the CCPA.
    19. Personal Data” means information that identifies, relates to, describes, is reasonably capable of being associated with, or could reasonably be linked, directly or indirectly, with a particular consumer or household, as well as any information that is "personal information," "personal data" or other equivalent term under Applicable Privacy Laws. Personal Data does not include any De-identified Data that is maintained in accordance with and as required by Applicable Privacy Laws.
    20. Pixel” means the particular e-tag, pixel, javascript, software development kit or other measurement code provided by Cognitiv and incorporated by Customer into its website or other online content for Advertising Purposes and/or pursuant to the Services.
    21. Process,” “Processed” or “Processing” means any operation or set of operations which is performed upon Personal Data, whether or not by automated means, such as collection, recording, organization, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction.
    22. Processor” means an entity that Processes Personal Data on behalf of, and subject to the written instructions of, the Controller, and is a “processor” as defined by Applicable Privacy Laws or a “service provider” as defined by the CCPA.
    23. Sensitive Data” means (i) any Personal Data that meets the definition of “sensitive personal information,” “sensitive data,” “protected health information” or any equivalent term under Applicable Privacy Laws; and (ii) any Personal Data about a Data Subject that is known or reasonably should be known to be under the age of 18 years old.
    24. Services” means all advertising, activation, campaign management, and related services that Cognitiv provides to or performs on behalf of Customer for Advertising Purposes (including any related technical or customer support), pursuant to the Agreement.
    25. Sale” and the correlated terms “Sell” and “Sold” have the meaning given under Applicable Privacy Laws. 
    26. Share” and the correlated terms “Shared” and “Sharing” have the meaning given under the CCPA. 
    27. Sub-provider” means a third-party entity engaged by Cognitiv to provide or perform certain services that Processes Customer Personal Data.
    28. Targeted Advertising” means all activities and Processing of Personal Data that constitute “targeted advertising” or “cross-context behavioral advertising” (or other equivalent terms) under Applicable Privacy Laws.
    29. Targeted Advertising Purposes” means: (i) any activities or Processing of Personal Data that amount to Targeted Advertising or Sales under Applicable Privacy Laws (including the CCPA); and (ii) any activities or Processing of Personal Data about California Consumers that amount to Sharing under the CCPA.
    30. Third-Party Segment Creation” means the Processing of Personal Data (including but not limited to Customer Personal Data in match files) for generating and matching audience segments for the purpose of Targeted Advertising. 
  3. Processing Activities and Roles of the Parties
    1. The Parties agree that (i) Customer is a Controller with respect to the Customer Personal Data; and (ii) except as otherwise set forth hereunder, Cognitiv is a Processor for the Customer Personal Data. Each of the Parties will comply with their respective obligations under the DPA and Applicable Privacy Laws.
    2. A description of the processing and a list of relevant Sub-providers is (a) provided in Exhibit A (Description of Processing) to this DPA, and (b) may also be set forth or supplemented by the Parties, including in one or more Order Form(s).
  4. Processing Instructions
    1. Customer instructs Cognitiv to Process Customer Personal Data, in accordance with the Agreement and this DPA: (i) for the Advertising Purposes under the Agreement, including related customer and technical support services: (ii) to provide the Services under the Agreement, including for quality control, audit, security, fraud detection and prevention, improvement, and similar operational activities related to the Services provided to Customer under the Agreement, to the extent such constitute a valid Business Purpose and are permitted by Applicable Privacy Laws; (iii) to comply with other reasonable instructions provided by Company where such instructions are consistent with the terms of the Agreement and this DPA); and (iv) as otherwise expressly authorized under the Agreement or this DPA.
    2. Customer also authorizes Cognitiv to engage Sub-providers and to disclose or make available Customer Personal Data as necessary to perform the Services or where otherwise expressly directed or authorized by Customer. 
    3. Customer acknowledges and agrees that Cognitiv may use AI and machine learning tools, including those provided by Sub-providers, to perform analytics, optimization, and audience insights in support of the Services. Such processing is subject to the same purpose limitations, data security, and Sub-provider obligations set forth in this DPA.
  5. Customer’s Personal Data Obligations. Customer will comply with its obligations under this DPA, including this Section 5, and its obligations as a Controller under Applicable Privacy Laws.
    1. Notice, Transparency, and Accuracy. Customer will (i) provide prior notice to Data Subjects of the Processing of their Personal Data, as contemplated by the Agreement and the performance of the Services, in compliance with all Applicable Privacy Laws; (ii) obtain prior consent or authorization from Data Subjects for the collection and Processing of their Personal Data pursuant to the Services (including via the Pixel, if applicable), where required under Applicable Privacy Laws; and (iii) inform Data Subjects of their rights under Applicable Privacy Laws, including to opt out of Sales, Sharing, and the Processing of Personal Data for Targeted Advertising (collectively, the right to “Opt Out”). Without limiting the foregoing, the notice provided to Data Subjects under paragraph (i) of this Section 5.1, must specifically inform Data Subjects that their Personal Data will be disclosed and Processed (including by third parties) for the Advertising Purposes under the Agreement.
    2. Consumer Rights and Opt-Outs. Customer will provide Data Subjects with clear, free, and easy-to-use methods for submitting Consumer Requests, including Consumer Requests to Opt Out, and will process and honor Consumer Requests, in compliance with all Applicable Privacy Laws. Without limiting the foregoing, Customer will: (i) comply with the Global Opt-Out, display to Data Subjects whether it has processed the Global Opt-Out, and include a statement in its privacy policy that the Customer responds to, and abides by, the Global Opt-Out, in each case, in a manner consistent with Applicable Privacy Laws; and (ii) notify Cognitiv and any other third-parties of a Data Subject’s Opt Out preference in accordance with Applicable Privacy Laws and in accordance with an technical specifications mutually agreed on between Cognitiv and Customer.
    3. Limited Advertising Purposes. If a Data Subject has submitted a Consumer Request to Opt Out, Customer will either: (i) not disclose, transmit or make available the Data Subject’s Personal Data to Cognitiv; or (ii) disclose, provide or make available the Data Subject’s Personal Data to Cognitiv only (a) for the Limited Advertising Purposes, and (b) after ensuring that any such Customer Personal Data has been provided along with a signal or indicator, in a mutually-agreeable format, that the Personal Data may only be used for the Limited Advertising Purposes (in which case such information is hereafter “Limited Use Data”). 
    4. Processing Instructions and Restrictions. Customer will ensure that its instructions for the Processing of Personal Data comply with Applicable Privacy Laws, and will: (i) not direct, permit or authorize Cognitiv to Process Personal Data or take any action pursuant to the Services that would violate Applicable Privacy Laws or the privacy rights of any Data Subject; (ii) not disclose, make available, or direct or cause Cognitiv to Process any Sensitive Data pursuant to the Agreement or the provision of the Services; and (iii) only Process, and direct Cognitiv to Process, Personal Data that (a) has been lawfully and validly collected, (b) is relevant and proportionate to the uses contemplated by the Agreement, and (c) where the Processing has been disclosed to Data Subjects as required by Applicable Privacy Laws.
    5. Customer will inform Cognitiv promptly if it knows or reasonably believes that it has not or cannot comply with the terms of this Section 5 or Applicable Privacy Laws. 
  6. Cognitiv Obligations. With respect to its provision of the Services and performance of the Agreement, Cognitiv will: (i) comply with its obligations under this DPA and Applicable Privacy Laws and; (ii) only Process Customer Personal Data as permitted under this DPA, except to the extent otherwise required by applicable law or a legal obligation to which Cognitiv is subject; (iii) only Process Limited Use Data for the Limited Advertising Purposes, and not for Targeted Advertising Purposes (including on behalf of Customer); (iv) implement and maintain reasonable security procedures and practices to protect Customer Personal Data from unauthorized or illegal access, destruction, use, modification, or disclosure that are appropriate to the nature of the Personal Data and the requirements of Applicable Privacy Laws; and (v) comply with its obligations under Section 6.1, 6.2, and 7, each as applicable.
    1. 6.1 Processor Obligations. Where Cognitiv Processes Customer Personal Data on behalf of Customer, as a Processor:
  1. Cognitiv will only Process Customer Personal Data to perform the Services under the Agreement, including for the Customer Advertising Purposes under the Agreement, and as otherwise necessary to comply with Cognitiv’s legal obligations; 
  2. Cognitiv will not Sell Customer Personal Data or Process Customer Personal Data for Targeted Advertising Purposes;
  3. Cognitiv will also comply with the terms of Section 6.2 (CCPA Service Provider Terms), to the extent applicable.
  4. Taking into account the nature of the relevant Services and the information available to it, upon request Cognitiv will provide reasonable cooperation and support as necessary to enable Customer to comply with its obligations under Applicable Privacy Laws, including its requirements to perform and document consumer privacy or data protection assessments, comply with Consumer Requests, ensure the security of Processing the Customer Personal Data, and respond to Security Incidents under Applicable Privacy Laws;
  5. Except to the extent otherwise required by applicable laws to which Cognitiv is subject, Cognitiv will treat Customer Personal Data as confidential and will only disclose Customer Personal Data to: (i) its affiliates and Sub-providers in compliance with the terms of this DPA (including Section 8); (ii) its employees, personnel and agents who have a business-need to Process the Customer Personal Data and are subject to a duty of confidentiality; and (iii) to others where directed or authorized by Customer in writing (including under this DPA or the Agreement);
  6. Cognitiv will inform Customer promptly if it believes that an instruction from Customer violates Applicable Privacy Laws; and
  7. Cognitiv will require Relevant Personnel to undergo appropriate training on their responsibilities in respect of Personal Data Processing and take commercially reasonable steps to ensure the reliability of Relevant Personnel and to inform Relevant Personnel of the confidential nature of the Customer Personal Data;
  8. Cognitiv will delete or return the Customer Personal Data to Customer upon the termination of the Agreement and the completion of the Services provided thereunder, except to the extent continued retention is necessary to comply with law or a legal obligation to which Cognitiv is subject; 
  9. Subject to Section 10 (Audits and Assessments), Cognitiv will allow, and cooperate with, reasonable assessments by Customer or its designated third-party assessor, and in doing so will make available sufficient information as necessary to demonstrate Cognitiv’s compliance with its obligations under Applicable Privacy Laws and this DPA, with respect to Customer Personal Data;
  1. 6.2 CCPA Service Provider Terms. Where the CCPA applies to Cognitiv’s Processing of Customer Personal Data, on behalf of Customer, as a Processor:
  1. Cognitiv is a “service provider” as defined under CCPA and the Customer Personal Data is being disclosed or made available by Customer to Cognitiv (a) for the Limited Advertising Purposes, and (b) not for purposes of Targeted Advertising or Third-Party Segment Creation.
  2. Cognitiv will not Share the Customer Personal Data it receives for any Limited Advertising Purposes with a third-party in a manner that would be considered Targeted Advertising or Third-Party Segment Creation.
  3. Customer may monitor Cognitiv’s compliance with this DPA and Applicable Privacy Laws as set forth in Section 10 (Audits and Assessments).
  4. Cognitiv will not use, retain, or disclose Customer Personal Data collected on behalf of Customer, pursuant to the Limited Advertising Purposes, outside Cognitiv’s direct business relationship with Customer, except where expressly permitted by the CCPA.
  5. Cognitiv will not combine the Customer Personal Data it receives on behalf of Customer, pursuant to the Limited Advertising Purposes, with Personal Data that Cognitiv receives from or on behalf of a third-party or collects independently from California Consumers, except to the extent as expressly permitted by the CCPA.
  6. Cognitiv will, with respect to the Processing of Personal Data of California Consumers, provide the same level of privacy protection as required of the Customer under the CCPA, such as by assisting Customer in completing cybersecurity audits and conducting risk assessments, as required by the CCPA.
  7. Cognitiv will notify Customer if it makes a determination that it can no longer meet its obligations under the CCPA and allow Customer to take reasonable and appropriate steps to stop and remediate any unauthorized use of Customer Personal Data by Cognitiv.
  1. Targeted Advertising. The terms of this Section 7 will apply, in lieu of Section 6.1 (Additional Processor Obligations) and Section 6.2 (CCPA Service Provider Terms), to any Processing of Customer Personal Data for Targeted Advertising Purposes under the Agreement. For the avoidance of doubt, the Parties acknowledge and agree the Cognitiv will act as a Controller (or a Third Party under the CCPA), with respect to any Customer Personal Data that is disclosed, provided, made available or otherwise Processed for Targeted Advertising Purposes under the Agreement. 
    1. 7.1 With respect to the Customer Personal Data that Cognitiv Processes for Targeted Advertising Purposes under the Agreement, Cognitiv will comply with its relevant obligations under Applicable Privacy Laws, the Agreement and this DPA. Except to the extent necessary to comply with Cognitiv’s applicable legal obligation, protect or defend the rights of Cognitiv, or protect or defend the rights, health, or safety a third party, Cognitiv will:
  1. Only disclose such Customer Personal Data to: (i) third parties as reasonably necessary for the Targeted Advertising Purposes of Customer under the Agreement; and (ii) its Sub-providers in accordance with the terms of this DPA. 
  2. Only Process such Customer Personal Data for the Advertising Purposes under the Agreement, or for another valid Business Purpose(s) permitted by Applicable Privacy Laws, provided such Processing is (a) necessary and proportionate to such purpose(s), and (b) compatible with context in which the Customer Personal Data has been collected under the Agreement and the Services; 
  3. Not Process any Limited Use Data for Targeted Advertising Purposes; and
  4. Upon request, reasonably cooperate with Customer as necessary for Customer to comply with its obligations under Applicable Privacy Laws.
  1. 7.2 In addition, with respect to any Processing of Customer Personal Data about California Consumers for Targeted Advertising Purposes under the Agreement, the Parties agree:
  1. Cognitiv is a Third Party (as that term is defined by the CCPA) for such Customer Personal Data;/
  2. Such Customer Personal Data is being made available for the Advertising Purposes under the Agreement, including Targeted Advertising, and Cognitiv will only use such Customer Personal Data for the foregoing limited and specific purposes and other compatible Business Purpose(s) as permitted by the CCPA.
  3. Cognitiv will comply with the applicable requirements of the CCPA and will provide the same level of privacy protection for such Personal Data as is required of Controllers (including Customer) under the CCPA. Without limiting the foregoing, Cognitiv will process and respond to Consumer Requests to Opt Out (including those communicated by Customer to Cognitiv and those received directly by Cognitiv) as required by the CCPA.
  4. Customer may take reasonable and appropriate steps to ensure that Cognitiv uses the Customer Personal Data in a manner consistent with Customer’s obligations under the CCPA by requesting that Cognitiv attest that it treats such Customer Personal Data in the manner that Customer is obligated to treat it under the CCPA. Such requests may be made up to one (1) time per calendar year.
  5. Cognitiv will notify Customer if it makes a determination that it cannot comply with its obligations under the CCPA (including this Section 7.2) and will allow Customer to take reasonable and appropriate measures where needed to stop and remediate any unauthorized use of such Customer Personal Data by Cognitiv.
  1. 7.3 In the event of a conflict with any other terms of the DPA, this Section 7 will apply with respect to any Targeted Advertising and the Processing of Customer Personal Data for Targeted Advertising Purposes pursuant to the Services under the Agreement.
  1. Sub-providers. Customer agrees that Cognitiv may engage Sub-providers to Process Customer Personal Data, in connection with the provision of the Services, subject to the terms of this Section 8. 
    1. Each Sub-provider will be subject to a written agreement that contains obligations in respect of data protection compliance and information security that are no less protective than those applicable to Customer Personal Data hereunder.
    2. Cognitiv will (i) take reasonable steps to ensure the reliability of its Sub-providers; (ii) remain liable for any breach of its obligations under this DPA by its Sub-providers; and (iv) allow Customer to object to the appointment of any new Sup-providers in accordance with Section 8.3.
    3. A list of Cognitiv’s Sub-providers is set forth in Appendix A to this DPA. Customer may subscribe to receive notices prior to Cognitiv’s appointment of new or additional Sub-providers by providing Cognitiv a designated email address to receive such notices (a “Designated Contact”). Cognitiv will send a notice via email to Designate Contacts, prior to engaging a new Sub-provider (the “Sub-provider Notice”). If Customer objects to the appointment of a Sub-provider, it must notify Cognitiv of its objections in writing within fourteen (14) days of the date Cognitiv sends the Sub-provider Notice, or it will be deemed to have accepted the new Sub-provider. If Customer objects to a Sub-provider in accordance with the foregoing procedure, Cognitiv: (i) will not permit such Sub-provider to Process Customer Personal Data, unless Customer subsequently provides its written consent; and (ii) either Party may terminate the portion of the Agreement that relates to any Services that cannot be reasonably provided without the use of the new Sub-provider.
  2. Security Incidents
    1. Cognitiv will notify Customer promptly, and without undue delay, upon discovering a Security Incident that materially impacts the confidentiality, security, or integrity of the Customer Personal Data, by notifying any of Customer’s business, technical or administrative contacts by any means, including via email or phone. Customer is responsible for ensuring that Cognitiv has accurate and up-to-date contact information for relevant personnel. 
    2. Cognitiv will: (i) take reasonable steps to investigate and remediate a Security Incident; and (ii) taking into account the circumstances of the Security Incident and the nature of the Customer Personal Data, Cognitiv will provide accurate and complete information to Customer, upon request, as necessary to enable Customer to evaluate and respond to a Security Incident as required by Applicable Privacy Laws.
    3. Notwithstanding Section 9.1 or Section 9.2, Cognitiv is not liable or responsible for any Security Incidents that are caused by Customer or Customer’s personnel or end users. 
  3. Audits and Assessments. Where required by Applicable Privacy Laws and as permitted hereunder, Cognitiv will allow for, and cooperate with, reasonable assessments of Cognitiv’s compliance with its privacy and security obligations under this DPA and Applicable Privacy Laws, subject to this Section 10. 
    1. Assessments may be conducted by Company or a qualified and independent third-party assessor appointed by Company (the “Assessor”) using an appropriate and accepted control standard or framework for such assessments, and will be limited to: (i) a review of Cognitiv’s privacy and security policies and the technical and organizational measures that support its obligations for Customer Personal Data hereunder; and (ii) one (1) time per calendar year, except where otherwise necessary for Customer to respond to a (a) Security Incident, or (b) a written inquiry from a regulatory authority with jurisdiction over Customer.
    2. Assessments will be carried out with reasonable notice, during regular business hours, and under a duty of confidentiality; all reasonable and appropriate steps will be taken to limit any disruption to Cognitiv’s business and operations from such assessment. 
    3.  Cognitiv will be provided with access to or a copy of the results or findings of any such assessment. In the event an assessment identifies any material issues or deficiencies in Cognitiv’s policies or practices, the Parties will work together in good faith to agree upon any appropriate remedial actions necessary in respect of Customer Personal Data. 
    4. Customer and any Assessor will cooperate in good faith with requests by Cognitiv to enter into a written confidentiality agreement in respect of the assessment, including any findings, reports, or remedial actions pursuant to the assessment.
    5. Customer will be responsible for all third-party costs associated with any assessment conducted by Customer under this DPA, including the costs of any Assessor. 
  4. Liability and Indemnity. Except as set forth in Section 11.2 below, in no event will (a) either Party be liable for any indirect, incidental, consequential, punitive, special or exemplary damages, whether or not such damages are foreseeable or a Party has been advised of the possibility thereof, and (b) either Party’s maximum aggregate liability for damages arising from breach of this DPA exceed US$1,000,000 (one million US dollars).
    1. Except as set forth in Section 11.2 below, each Party (as the “Indemnifying Party”) will indemnify, defend and hold harmless the other Party (as the “Other Party”), and their respective directors, officers, employees and agents (and successors, heirs and assigns) (“Representatives”) against any liabilities (including reasonable costs and expenses) incurred in connection with any third party claim arising out of or relating to the Indemnifying Party’s breach of this DPA. The Other Party will: (i) provide the Indemnifying Party with prompt notice of any such claim (provided that the failure to promptly notify shall only relieve the Indemnifying Party of its obligation to the extent it can demonstrate material prejudice from such failure); and (iii) at the Indemnifying Party’s expense, provide assistance reasonably necessary to defend such claim. The Indemnifying Party will not enter into a settlement that would result in liability to the Other Party or its Representatives without the Other Party’s prior written consent, which shall not be unreasonably withheld or delayed. 
    2. Notwithstanding anything to the contrary in this DPA or the Agreement, Cognitiv shall have no indemnification obligations to Customer to the extent any liability arises from Customer’s breach of Section 5 (Customer’s Personal Data Obligations). Customer shall be required to indemnify Cognitiv for any liabilities (including reasonable costs and expenses) arising from any such breach and such indemnification obligations shall not be subject to the limitation of liability set forth in Section.
  5. General
    1. Governing Law; Jurisdiction; Venue. The Federal Arbitration Act, Delaware state law, and applicable U.S. federal law, without regard to the choice or conflicts of law provisions, will govern this DPA and the Agreement. Foreign laws do not apply. Any disputes arising out of or relating to this DPA, the Agreement, or the Services will be heard in the appropriate state or federal court of competent jurisdiction for the City of Wilmington, Delaware, and each Party consents and irrevocably submits to the jurisdiction and venue of such courts.
    2. Entire Agreement; Conflicts. This DPA is a legal, valid, and binding obligation of, and enforceable against, each Party.  This DPA constitutes the entire agreement and understanding of the Parties and supersedes any prior agreement or understanding between the Parties (including any and all prior data processing addenda or agreements), with respect to the matters addressed herein. In the event of a conflict between a term of this DPA and any other term of the Agreement, this DPA shall control with respect to the Processing of Personal Data, the performance of the Services, and the subject matter hereunder. For clarity, if Customer has more than one Agreement, this DPA will apply to and amend each of the Agreements separately.
    3. Severability; Waiver; Survival. If any provision of this DPA is determined to be invalid, illegal, or unenforceable, the remaining provisions of the DPA will remain in full force. Neither Party’s failure or delay to, at any time, enforce a provision or exercise a right or remedy hereunder operates as a waiver, except to the extent expressly stated hereunder. Neither Party’s waiver of any provision of this DPA is effective unless in writing and signed by the Party against whom the waiver is to be enforced. The Parties may amend this DPA only by a written agreement signed by the Parties that identifies itself as an amendment to this DPA.
    4. Survival. The rights, remedies, and obligations of the Parties under this DPA shall survive the expiration or termination of the Agreement and/or completion of the Services, to the extent necessary to carry out the intentions of the Parties under this DPA.

Appendix A: Description of Processing

Purpose of Processing: Cognitiv will Process Customer Personal Data to perform the Services and for the Advertising Purposes under the Agreement.

Types of Personal Data: The types of Customer Personal Data Processed by Cognitiv for the purposes of the Agreement may include the following:

  • Online identifiers, including IP addresses; device identifiers; cookie identifiers; UIDs; advertising identifiers; and other online identifiers.
  • Web browsing, interest, and demographic data associated with online identifiers.
  • Other Pixel data (where applicable), such as date and time stamps, browser, device and operating system type and version, referring URL, page URL, and event data (if applicable), such as Event ID, Tag Manager Event, order ID, customer ID, product type, and basket value.
  • Other Customer Personal Data that Customer provides or makes available to Cognitiv for the Advertising Purposes (such as CRM data for the purposes of modeling and creating Third-Party Segments for activation). 

Sub-providers: In the provision of the Services, Cognitiv may use Sub-providers, including:

This list is subject to change, upon notice, in accordance with Section 8 (Sub-providers) of the DPA.

How to Contact Us

You can reach us by email at privacy@cognitiv.ai or at the following mailing address:

Cognitiv


215 Park Ave S, Floor 16

New York, NY 10003

©2026 Cognitiv Corp. All Rights Reserved.