1. Parties, scope, and incorporation
This DPA is between PCGROUP, LLC / JBComm (providing AIMarket / OmniReach) and the Customer under the Agreement. It applies to Customer Personal Data processed on the Customer’s behalf. Express incorporation, proper acceptance, and completed annexes are required; publication alone does not execute this DPA.
Distinct independent-controller purposes are not treated as processor activity. Independent Prospect/enrichment data sharing requires separately assessed roles and appropriate terms, not a generic Subprocessor label.
2. Definitions
Master Terms definitions apply. “Controller” determines purposes and essential means; “Processor” acts on another’s behalf under instructions. “Data Subject” is the individual concerned. “Processing” includes collection, use, storage, disclosure, correction, return, and deletion.
“Security Incident” means a breach causing accidental/unlawful destruction, loss, alteration, unauthorized disclosure of, or access to Customer Personal Data. Unsuccessful attempts without compromise are not alone an Incident, without removing prevention or legal duties. “CCPA” refers to the California Consumer Privacy Act as amended only where applicable; relevant business, service-provider, contractor, sell/share terms have their statutory meanings.
3. Roles and customer duties
For in-scope processing the Customer is Controller, or an authorized Processor for an upstream controller, and PCGROUP is Processor or Subprocessor accordingly. Appropriate state business/service-provider/contractor roles depend on actual activity and applicable law. Customers must be authorized to give instructions and appoint us and approved Subprocessors.
The Customer must establish lawful sources, purposes, instructions, notices, consents, access, and retention. We remain responsible for our own law/contract duties. Independent processing must be separately identified and disclosed.
4. Instructions and processing limits
We will process Customer Personal Data on documented lawful instructions for contracted Services, their security, maintenance, support, and authorized AI functions, or where law requires. The Agreement, completed annexes, and properly authorized service instructions form the documented instructions. Integrations/support requests do not authorize unrelated reuse.
Where law requires other processing, notify the Customer before processing when legally permitted. If we reasonably believe instructions violate applicable Data Protection Law, inform the Customer and pause affected processing as appropriate. Independent security/legal activity needs its own bounded lawful role and cannot justify unlimited reuse of tenant content.
We will not use identifiable Customer Data, Customer Content, Prospect Data, or tenant-specific data to train a shared or general model for unrelated customers unless the Customer separately authorizes that use.
5. Personnel confidentiality
Limit personnel access to permitted work and necessary purposes. Require confidentiality commitments or applicable legal duties, with access consistent with assigned responsibilities. Master Terms confidentiality continues to apply.
6. Security obligations
We will implement and maintain technical/organizational safeguards appropriate to processing risk and applicable law, as specified in completed Annex E and signed security commitments. Measures must address confidentiality, integrity, availability, and appropriate access. Public safeguard categories do not substitute for verified, agreed measures.
Changes must not materially reduce agreed protection as a whole, subject to law and signed terms. No certification, particular technology, recovery time, or security guarantee is created.
7. Subprocessors
Obtain required written Customer authorization. For general authorization, provide the approved scoped list before processing, with advance written notice of intended additions/replacements and a meaningful opportunity for reasonable data-protection objections. Annex F must establish notice/objection periods, channel, and resolution before execution.
Address objections through appropriate alternative, mitigation, or agreed termination of affected processing when no compliant alternative exists. Commercial consequences follow signed terms and law; no blanket refund rule is added. Subprocessors must have written protections appropriate to delegated duties and no less protective for those duties, including applicable AI restrictions. We remain responsible for their delegated processing performance.
An unpopulated public list is not authorization, proof of no suppliers, or permission to withhold required disclosures.
8. Data Subject and regulator assistance
Taking account of processing and available information, reasonably assist with required access, correction, deletion, export, restriction, opt-out, and other rights. Promptly inform the Customer of relevant direct requests and follow lawful instructions except where law requires our direct response.
Provide reasonably necessary information/assistance for applicable impact assessments, prior consultations, regulator inquiries, and compliance relating to our processing. Additional assistance charges may be agreed only where lawful and cannot prevent mandatory assistance or protected rights.
9. Security Incident notification
Notify the Customer without undue delay after awareness of a Security Incident affecting Customer Personal Data, and within any shorter law/signed-agreement deadline. Do not wait for a completed investigation. Give available information on nature, affected data/individuals where known, likely consequences, response, and coordination contact, with updates as facts emerge.
Take appropriate containment/remediation steps and reasonably assist required assessment/notifications. Notice is not admission of liability. Neither party may delay mandatory reporting while coordinating commercial matters. Customer directs its notices except where our own reporting duties apply.
10. Return, deletion, retention, and suppression
At processing end or applicable lawful instruction, return or delete Customer Personal Data at Customer choice and delete remaining copies unless law requires retention. Complete timing, format, assistance, backup expiry, and confirmation in Annex D and signed exit terms; incomplete details do not remove an applicable-law duty.
Restrict law-required retained data to its necessary purpose, protect it, and delete it when the requirement ends. Where legally permitted, backups may follow a documented expiry schedule only with appropriate isolation and respect for deletion/suppression after restoration.
Where lawful and necessary, deleting a prospect or contact may leave a minimum suppression record solely to prevent renewed contact, re-importing, or re-enrichment of that person. An identifiable suppression record remains Personal Data, must be restricted to honoring the request and protected against other use, and may be retained only for its justified purpose.
A processor must not retain suppression for its independent reuse without a separately valid role and basis. An unresolved suppression purpose is not an automatic exception to deletion instructions.
11. Information and audit rights
Make available information reasonably necessary to demonstrate processing compliance and allow/contribute to audits required by applicable Data Protection Law. Appropriate arrangements may protect other customers, security, and confidential materials without preventing legally required audit rights.
Routine review should first use sufficient information/reports actually available. No independent certification/report is represented as existing. Agree lawful timing, confidentiality, qualified reviewers, scope, and costs without restricting regulator access or non-waivable rights.
12. Service-provider/contractor restrictions where applicable
For in-scope CCPA service-provider or contractor processing, use information only for the limited specified purposes in this DPA and completed annexes. Do not sell/share it, process it outside those purposes/direct relationship, or combine it with other-source information except where applicable law permits and lawful instructions allow.
Comply with role-specific duties and required protection; notify the Customer if we can no longer comply. Permit reasonable appropriate steps to assess, stop, and remediate unauthorized use. Complete any required contractor certification/terms before reliance. This label does not authorize independent Prospect activity.
13. International transfers and contractual safeguards
Before a restricted transfer, identify exporter/importer roles, destinations, applicable rules, and a lawful safeguard, and complete required instruments/assessments. Applicable SCC version/modules, options, annexes, authority, transfer-law/forum, UK/Swiss adaptations where needed, onward transfers, and supplemental safeguards must be completed and agreed for the relevant restricted transfer.
A generic SCC reference is not execution. No participation in a certification-based transfer framework or foreign-law selection is asserted. Completed mandatory transfer terms control their subject matter. Arizona commercial law remains unchanged; any separate mandatory transfer law/forum must be expressly addressed in the applicable transfer instrument.
14. Liability, conflicts, and completion
The DPA controls Customer Personal Data processing conflicts in incorporated standard terms, subject to express negotiated provisions and non-waivable law or completed mandatory transfer terms. AI training restrictions continue. Master Terms section 23 supplies the subject-specific hierarchy.
Existing Master Terms liability exclusions, three-month cap, and original indemnity remain unchanged. No provider indemnity or voluntary cap carve-out is created. Nothing in this DPA limits liabilities or rights that mandatory law or binding transfer terms prohibit limiting. Complete annexes and supplier authorization before execution.
Annex A — Data Subjects
- Customer administrators, Authorized Users, and permitted portal users.
- Professional contacts, prospects, customer personnel, communication participants, and people represented in Customer records.
- Select actual categories for contracted Services; children/sensitive targeting are not approved by default.
Annex B — Personal Data categories
- Business identity/contact details, professional/company associations, and account records.
- Customer documents/messages/notes, communication content/metadata, and lawfully authorized recordings where enabled.
- Portal/support information, subscriptions, invoice/statement activity, and authorized payment references.
- Authorized AI Input/Output/Tenant Intelligence and necessary activity/usage information.
- Sensitive categories require explicit assessment, authorization, and safeguards; this is not unrestricted collection permission.
Annex C — Purposes and operations
Limited to documented Customer use of contracted, enabled Prospect, VCC, Portfolio, CSSM — Client Subscription Service Manager, and authorized AI. Operations may include receiving, organizing, storing, retrieving, presenting, updating, communicating, supporting, protecting, exporting, and deleting relevant records as instructed. Shared-model training and unrelated independent commercialization are excluded.
Annex D — Duration and deletion schedule
Duration follows the agreed service term and necessary instructed return/deletion or legally required retention. The parties must agree before execution: actual term, retention classes/legal requirements, return format, deletion schedule, backup expiry/isolation, provider deletion, legal holds, and lawful suppression instructions/retention criteria. No fixed retention period is established by this Annex.
Annex E — Safeguard categories
Safeguard categories: authentication, authorization, tenant separation, least privilege, access review, appropriate activity/audit records, protection of supported transmission channels, secure development, minimization, backups/recovery, incident management, and vendor risk. Security Overview explains categories conservatively.
The parties must agree before execution: verified measures/scope for each enabled Service, responsibility allocation, supporting evidence, backup limitations, and signed commitments. No certification or technical configuration is asserted.
Annex F — Approved Subprocessor reference
Reference: Subprocessor Policy and list. The public list does not currently identify suppliers; this does not mean no suppliers exist. The parties must agree before execution: approved scoped/versioned list or legally sufficient confidential disclosure, actual suppliers/purposes/Services/regions, notice channel/period, objection window/resolution, and written authorization. Proprietary concerns cannot excuse mandatory disclosure.