This Data Processing Addendum (“DPA”) supplements and is incorporated into the agreement(s) between you (“You” or “Company”) and DeepIntent, Inc. (“DeepIntent”), which may include, without limitation, any order form, data use agreement, data licensing agreement, or other service agreement (collectively, the “Agreement(s)”). To the extent of any conflict between this DPA and the Agreement(s) with respect to the processing of personal information, this DPA shall control. Capitalized terms not defined herein have the meanings given in the Agreement(s). Company's execution of the Agreement(s), and/or its continued access to or use of DeepIntent’s services or data constitutes its acceptance of this DPA.
- DEFINITIONS. As used in this DPA:
- Applicable Privacy Law means all U.S. federal and state privacy and data protection laws applicable to the processing of Personal Information hereunder, as amended from time to time, which may include without limitation: the California Consumer Privacy Act of 2018, as amended by the California Privacy Rights Act of 2020 (collectively, “CCPA/CPRA”); the Virginia Consumer Data Protection Act (“VCDPA”); the Colorado Privacy Act (“CPA”); the Connecticut Data Privacy Act (“CTDPA”); the Texas Data Privacy and Security Act (“TDPSA”); and any other substantially similar U.S. state privacy laws enacted or taking effect during the Term. For the avoidance of doubt, the GDPR and other non-U.S. privacy laws are outside the scope of this DPA unless expressly agreed in a separate written addendum signed by authorized representatives of both Parties.
- Company Data means Personal Information that Company provides or makes available to DeepIntent in connection with the Services, including but not limited to HCP target lists, pixel data, and any other data submitted by or on behalf of Company through DeepIntent’s platform, and excluding any DeepIntent Data and DeepIntent IP (as those terms are defined in the Agreement(s)).
- Controller means the Party that determines the purposes and means of Processing of a category of Personal Data, and is solely responsible for the lawfulness of its processing instructions with respect thereto, as identified for each category of Personal Data in Annex I.
- De-Identified Data has the meaning ascribed under Applicable Privacy Law and, in the healthcare advertising context, also means data that has been de-identified in accordance with the HIPAA Expert Determination method under 45 CFR § 164.514(b) as confirmed by an independent qualified statistician. De-Identified Data is not Personal Information for purposes of this DPA.
- DeepIntent Data means data generated by or derived from DeepIntent’s platform, systems, and products that does not constitute Company Data, including DeepIntent’s proprietary audience data, De-Identified Data, and aggregated, statistical data derived from the Services, and includes DeepIntent LLD (as defined in the Data Use Terms).
- Personal Information means information that identifies, relates to, describes, is reasonably capable of being associated with, or could reasonably be linked, directly or indirectly, with an identified or identifiable natural person or household, as defined under Applicable Privacy Law. Personal Information excludes De-Identified Data and publicly available information. As used in this DPA, “Personal Data” refers to the same category of information as “Personal Information” and the terms are used interchangeably to reflect terminology across different Applicable Privacy Laws.
- Permitted Purposes has the meaning set forth in Section 3(a) of this DPA.
- Processor means the Party that Processes Personal Data solely on behalf of, and in accordance with the documented instructions of, the Controller of such data, as identified for each category of Personal Data in Annex I.
- Security Incident means a confirmed unauthorized acquisition, access, use, or disclosure of Company Data that compromises the security, confidentiality, or integrity of such data. For the avoidance of doubt, a good-faith, accidental disclosure to an authorized employee of DeepIntent who promptly reports and remediates such disclosure does not constitute a Security Incident.
- Service Provider has the meaning given to that term (or the substantially equivalent term “Processor”) under Applicable Privacy Law.
- Service(s) has the meaning set forth in the Agreement(s).
- Subprocessor means any affiliate, vendor, contractor, or other third party engaged by a Processor that processes Personal Data of the Controller in connection with the Services.
- ROLES OF THE PARTIES.
- Controller. A Party acting as Controller with respect to a category of Personal Data, as identified in Annex I, determines the purposes and means of Processing such Personal Data and is solely responsible for the lawfulness of its processing instructions with respect thereto. Nothing in this DPA restricts a Party’s use of Personal Data with respect to which it is the Controller.
- Processor. The Processor shall Process Personal Data solely on behalf of, and in accordance with, the Controller’s documented instructions as set forth in this DPA and the Agreement(s). The Processor shall not: (a) sell or share such Personal Data; (b) retain, use, or disclose such Personal Data for any purpose other than the Permitted Purposes or as required by Applicable Privacy Law; or (c) combine such Personal Data with personal information obtained from other sources except as permitted to perform the Services or as otherwise permitted under Applicable Privacy Law.
- PERMITTED PURPOSES AND PROCESSING INSTRUCTIONS.
- Permitted Purposes. In addition to any Permitted Purposes expressly permitted in the Agreement(s), the Processor shall Process the Controller’s Personal Data solely for the following purposes (collectively, the “Permitted Purpose(s)”), which constitute the Controller’s complete and binding processing instructions:
- Providing the Services as described in the Agreement(s), which may include, without limitation, HCP and DTC audience targeting, ad delivery, campaign management, analytics, reporting, and measurement;
- Performing identity resolution, list matching, and audience segmentation in relation to the Services;
- Generating De-Identified Data and Aggregated Data from the Controller’s Personal Data for analytics, reporting, measurement, and service improvement, in each case where such outputs cannot be reasonably re-linked to any individual;
- Complying with Applicable Privacy Law and assisting the Controller in responding to data subject rights requests as set forth in Section 7;
- Detecting, preventing, responding to and remediating security incidents, fraud, and other unlawful activity; and
- any other purpose expressly authorized in writing by the Controller; provided that, including the applicable Permitted Purposes as set forth in the DeepIntent Data Use Terms.
- Controller’s Responsibility for Lawfulness of Instructions. The Controller represents, warrants, and covenants that: (a) it has all rights, consents, and legal bases necessary under Applicable Privacy Law to provide its Personal Data to the Processor and to authorize the processing contemplated by this DPA; (b) such Personal Data has been collected in compliance with Applicable Privacy Law, including through privacy notices that accurately describe the data practices contemplated herein; (c) the Controller will not share any Sensitive Personal Information (as defined under Applicable Privacy Law) unless previously mutually and expressly agreed in a separate written addendum executed by authorized representatives of both Parties; (d) the Controller will not share any data relating to individuals under the age of eighteen (18); and (e) the Controller will not share any Personal Information of individuals who have exercised applicable opt-out rights, including through Global Privacy Control signals. The Controller shall indemnify, defend, and hold harmless the Processor from and against all claims, losses, damages, and expenses (including reasonable attorneys’ fees) arising from the Controller’s failure to comply with this Section 3(b).
- Permitted Purposes. In addition to any Permitted Purposes expressly permitted in the Agreement(s), the Processor shall Process the Controller’s Personal Data solely for the following purposes (collectively, the “Permitted Purpose(s)”), which constitute the Controller’s complete and binding processing instructions:
- CONFIDENTIALITY.
- Confidential Information. All proprietary information disclosed by one Party (the “Disclosing Party”) to the other Party (the “Receiving Party”) in connection with this DPA shall be deemed the Confidential Information of the Disclosing Party (“Confidential Information”). For the avoidance of doubt, DeepIntent’s platform, DeepIntent Data, and any information and/or data made accessible by DeepIntent or through DeepIntent’s services is DeepIntent’s Confidential Information, and Company Data is Company’s Confidential Information. Confidential Information does not include information that: (i) is or becomes publicly available through no breach by the Receiving Party; (ii) was previously known to the Receiving Party prior to disclosure, as evidenced by contemporaneous written records; (iii) was acquired from a third party without breach of any obligation of confidentiality; (iv) was independently developed by the Receiving Party without reference to the Disclosing Party’s Confidential Information; or (v) is required to be disclosed pursuant to a subpoena or other order of a court or government authority, provided that the Receiving Party shall promptly notify the Disclosing Party in writing, cooperate with the Disclosing Party in limiting the scope of disclosure, and disclose only that Confidential Information strictly necessary to comply with such order.
- Obligations of Confidentiality. The Receiving Party shall not use or disclose the Disclosing Party’s Confidential Information to any third party except as specifically permitted under this DPA or the Agreement(s). The Receiving Party shall protect the Disclosing Party’s Confidential Information using the same standard of care it applies to its own confidential information of like nature, but in no event less than a reasonable standard of care. The Receiving Party shall be responsible for any and all third parties to whom it shares or gives access to Confidential Information, and all third parties shall be bound by obligations of confidentiality no less protective than those set forth in this Section 4.
- Unauthorized Disclosure. Each Party shall notify the other Party as soon as reasonably practicable upon becoming aware of any unauthorized use or disclosure of the other Party’s Confidential Information. The Receiving Party shall be fully responsible for any unauthorized use or disclosure of the Disclosing Party’s Confidential Information by the Receiving Party’s personnel, subprocessors, or other third parties to whom it has disclosed such information.
- Injunctive Relief. The Parties agree that any violation or threatened violation of this Section 4 will cause irreparable injury to the Disclosing Party for which monetary damages would be an insufficient remedy. Accordingly, the Disclosing Party shall be entitled to seek injunctive relief, without the necessity of posting bond or proving actual damages, in addition to any other rights and remedies available at law or in equity.
- SECURITY.
- Security Measures. Processor shall implement and maintain technical and organizational measures designed to protect Personal Data against unauthorized or unlawful processing and accidental loss, destruction, damage, or disclosure, having regard to the state of the art, cost of implementation, and the nature, scope, context, and purposes of the processing. Processor shall maintain such measures in the form of a written information security program (“WISP”) encompassing appropriate administrative, technical, and physical safeguards. Processor may update the WISP from time to time to reflect improvements in its security practices, provided that such updates shall not materially reduce the overall level of protection afforded to Personal Information.
- Security Incidents. In the event of a Security Incident, the following shall apply:
- Notification. In the event of a confirmed Security Incident affecting the Controller’s Personal Data, the Processor shall notify the Controller without undue delay and in any event within seventy-two (72) hours of confirming that a Security Incident has occurred. Such notice shall include, to the extent then reasonably available: (a) a description of the nature of the Security Incident; (b) the categories and approximate volume of Personal Data affected; (c) the likely consequences; and (d) the measures taken or proposed to address the Security Incident and mitigate its effects.
- No Admission. Notice of or response to a Security Incident shall not constitute an admission of fault, liability, or noncompliance with Applicable Privacy Law or this DPA. The Processor shall not make any public statement regarding a Security Incident affecting the Controller’s Personal Data without the Controller’s prior written consent, except as required by Applicable Privacy Law or order of a court or government authority.
- Controller Responsibility for Notifications. The Processor shall cooperate with the Controller’s reasonable requests in investigating and remediating a Security Incident. The Controller is solely responsible for providing all required notifications to data subjects, regulators, and other third parties in connection with a Security Incident, and shall bear all costs associated therewith.
- Post-Incident Review. Following remediation of a confirmed Security Incident affecting the Controller’s Personal Data, the Processor shall document the responsive actions taken and conduct a reasonable internal review of the events and actions taken, including any changes to security practices and procedures reasonably necessary to reduce the likelihood of recurrence. The Processor shall provide the Controller with a written summary of such review upon the Controller’s reasonable written request.
- SUBPROCESSORS.
- General Authorization. The Controller provides general express written authorization for the Processor to engage Subprocessors to Process the Controller’s Personal Data in connection with the Services. The Processor shall maintain a current, up-to-date list of its Subprocessors, made available at the URL identified in Annex II, and shall update such list as and to the extent required by Applicable Privacy Law.
- Subprocessor Obligations. The Processor shall impose data protection obligations on each Subprocessor that are no less protective of the Controller’s Personal Data than those set forth in this DPA. The Processor remains fully liable for the acts and omissions of its Subprocessors with respect to the Controller’s Personal Data to the same extent as if the Processor had performed the processing directly.
- Changes to Subprocessors. The Processor may add or replace Subprocessors at any time upon written notice to Controller. If the Controller has a reasonable, documented objection to a new Subprocessor on data protection grounds, the Controller shall notify the Processor in writing within thirty (30) days of any objections to the new Subprocessor. The Parties shall negotiate in good faith to resolve the concern for a period of fifteen (15) days; if no resolution is reached, either Party may terminate the portion of the affected Services that cannot be provided without the objected-to Subprocessor upon thirty (30) days’ written notice, without penalty, solely with respect to those Services that cannot be performed without the objected-to Subprocessor. Failure to timely object shall constitute acceptance of the new Subprocessor.
- DATA SUBJECT RIGHTS. If the Processor receives a request from a data subject exercising rights under Applicable Privacy Law that relates to the Controller’s Personal Data (a “Data Subject Request”), the Processor shall: (a) notify the Controller within ten (10) business days of receipt, to the extent permitted by Applicable Privacy Law; and (b) provide reasonable cooperation and assistance to enable the Controller to respond to such request. The Controller is solely responsible for responding to Data Subject Requests. The Processor shall not be required to respond directly to data subjects except to the extent expressly required by Applicable Privacy Law or at the Controller’s written direction. The Processor reserves the right to charge the Controller reasonable fees for compliance assistance that materially exceeds the Processor’s ordinary-course operational obligations.
- AUDIT RIGHTS. Because each Party may process the other’s data in connection with the Services, each Party shall have the right, upon at least ten (10) business days’ prior written notice and at its own expense, to send written audit questions to the other Party to verify that its use of the Services and/or the auditing Party’s data complies with the audited Party’s respective obligations under this DPA (“Compliance Check”). All Compliance Checks shall be conducted solely through written questions and written responses; no Compliance Check shall entitle either Party to physical access to the other Party’s premises or direct access to the other Party’s systems, infrastructure, or technology. Each Party may exercise its right to a Compliance Check up to once (1) per year, unless and additionally if the audited Party has experienced a Security Incident involving the auditing Party’s data or has otherwise breached its respective data use obligations under this DPA. The audited Party shall provide true, accurate, and complete responses to such written audit questions. Any information or documents provided by the audited Party shall be considered its confidential information and subject to the confidentiality protections in this DPA and/or the Agreement(s). In responding to such Compliance Check, each Party is not required to provide any information or data that reasonably: (i) is not directly related to the Services provided to Company; (ii) is the audited Party’s confidential information as it relates to its information security, servers, or data infrastructure; (iii) is related to the audited Party’s clients who are not related to this DPA; (iv) is related to the audited Party’s affiliates who do not provide the Services to Company; or (v) is related to the audited Party’s confidential accounting or financial information. In the event such audit reveals that the audited Party materially failed to comply with the terms of this DPA, the audited Party shall reimburse the auditing Party for its reasonable, incurred audit costs. For the avoidance of doubt, any reimbursement shall not preclude the exercise of any other rights or remedies that the auditing Party may have available to it as a result of such noncompliance.
- DE-IDENTIFIED AND AGGREGATED DATA. Notwithstanding any other provision of this DPA, DeepIntent may freely use, retain, disclose, and exploit: (a) De-Identified Data derived from Company Data, provided that DeepIntent implements and maintains appropriate technical and organizational safeguards designed to prevent re-identification, consistent with Applicable Privacy Law and DeepIntent’s HIPAA Expert Determination standards; and (b) aggregated, statistical data derived from the Services that does not identify Company or any individual (“Aggregated Data”). De-Identified Data and Aggregated Data are and shall remain the property of DeepIntent and may be used for any lawful purpose, including without limitation product development, benchmarking, modeling, research, and development of new products and services. Company shall have no rights in or to De-Identified Data or Aggregated Data.
- RETENTION AND DELETION. The Processor shall retain the Controller’s Personal Data only for as long as necessary to fulfill the Permitted Purposes or as required by Applicable Privacy Law or applicable backup and archival obligations. Upon termination or expiration of the Agreement(s), or upon the Controller’s written request, the Processor shall, at the Controller’s election: (a) securely delete or destroy such Personal Data from the Processor’s systems within sixty (60) days; or (b) return such Personal Data to the Controller in a mutually agreed format, to the extent technically feasible, within sixty (60) days. Upon the Controller’s written request, the Processor shall certify in writing that such deletion or return has been completed. Notwithstanding the foregoing, the Processor may retain copies of such Personal Data to the extent required by Applicable Privacy Law, legal hold requirements, or applicable backup and archival processes, provided that such retained data remains subject to the protections of this DPA.
- INABILITY TO COMPLY. Each Party shall notify the other Party in writing within ten (10) business days if it: (a) determines that it is unable to comply with any of its material obligations under this DPA and cannot cure such inability within a reasonable timeframe; or (b) becomes aware of any change in Applicable Privacy Law or other circumstance that is likely to prevent it from fulfilling its obligations under this DPA. Upon receipt of such notice, the Parties shall negotiate in good faith to amend this DPA as reasonably necessary to address the identified concern.
- STATE-SPECIFIC TERMS
- CCPA/CPRA COMPLIANCE. To the extent the CCPA/CPRA applies to the Processing of Personal Data under this DPA:
- The Processor is a “Service Provider” as defined under the CCPA/CPRA and shall not retain, use, or disclose the Controller’s Personal Data for any purpose other than the business purposes specified in this DPA and the Agreement(s), or as otherwise permitted under Cal. Civ. Code § 1798.140.
- The Processor hereby certifies that it understands and will comply with the restrictions applicable to Service Providers under Cal. Civ. Code § 1798.140(ag).
- The Processor certifies that it does not “sell” or “share” the Controller’s Personal Data as those terms are defined under the CCPA/CPRA, and Processes such Personal Data solely as a Service Provider or Processor for the applicable Permitted Purposes.
- The Processor shall not combine the Controller’s Personal Data with Personal Information obtained from other sources, except as permitted to perform the Services or as otherwise authorized under the CCPA/CPRA.
- The Processor shall reasonably cooperate with the Controller in responding to Consumer requests under the CCPA/CPRA in accordance with Section 7 of this DPA.
- The Controller acknowledges that the disclosure of its Personal Data to the Processor under this DPA constitutes a disclosure for a “business purpose” and does not constitute a “sale” or “sharing” of Personal Information under the CCPA/CPRA, subject to the Processor’s compliance with its obligations as a Service Provider hereunder.
- MULTI-STATE PRIVACY LAW COMPLIANCE. To the extent the Virginia Consumer Data Protection Act (VCDPA), Colorado Privacy Act (CPA), Connecticut Data Privacy Act (CTDPA), Texas Data Privacy and Security Act (TDPSA), or any substantially similar Applicable Privacy Law applies to the Processing of Personal Data under this DPA:
- The Processor shall Process the Controller’s Personal Data solely as a “Processor” (or equivalent role) under the applicable law, in accordance with the Controller’s documented instructions as set forth in this DPA;
- The Processor shall assist the Controller, to the extent technically and commercially feasible, in fulfilling the Controller’s obligations with respect to data subject rights requests under Applicable Privacy Law;
- The Processor shall notify the Controller promptly if it determines that it can no longer meet its obligations under Applicable Privacy Law; and
- The Controller, as “Controller” (or equivalent) under all applicable state privacy laws with respect to its Personal Data, bears full responsibility for the lawfulness of its processing instructions to the Processor.
- CCPA/CPRA COMPLIANCE. To the extent the CCPA/CPRA applies to the Processing of Personal Data under this DPA:
- LIMITATION OF LIABILITY; INDEMNIFICATION. IN NO EVENT SHALL DEEPINTENT BE LIABLE FOR ANY INDIRECT, INCIDENTAL, SPECIAL, OR CONSEQUENTIAL DAMAGES (INCLUDING LOSS OF INCOME, REVENUE, PROFITS, OR GOODWILL) ARISING UNDER OR RELATED TO THIS DPA, EVEN IF EITHER PARTY HAS BEEN ADVISED OF THE POSSIBILITY OF SUCH DAMAGES IN ADVANCE. In addition to any indemnification obligations under the Agreement(s) between the Parties, Company agrees to indemnify, defend and hold harmless DeepIntent and its directors, officers, shareholders, employees, members, agents, and their respective successors in interest from and against any claim, action, suit, proceeding, liability, loss, damage, cost, or expense, including, without limitation, attorneys’ fees, experts’ fees and court costs, whether or not a lawsuit is brought, arising out of any third party claim related to Company’s negligence, willful misconduct, and/or breach or alleged breach of its obligations, and/or representations and warranties under this DPA. Except for a party’s indemnification obligations in this DPA, neither Party's total aggregate liability for all claims arising out of or related to this DPA shall exceed $500,000. All remedies available to each Party will apply to Third Parties, including injunctive relief, and Company will reasonably assist DeepIntent in enforcing its rights and remedies against such Third Parties. Notwithstanding the foregoing, to the extent an exhibit or addendum contains additional limitations of liability apart from this DPA, the following order of precedence shall control in the event of conflict: (1) the exhibit or addendum (including, without limitation, the Data Use Terms), (2) this DPA; and (3) the Agreement(s).
- DOJ BULK DATA RULE COMPLIANCE. The Parties acknowledge that the DOJ's final rule implementing Executive Order 14117, "Preventing Access to Americans' Bulk Sensitive Personal Data and United States Government-Related Data by Countries of Concern" (28 C.F.R. Part 202, the "Bulk Data Rule"), may apply to certain transactions under this DPA. Each Party represents and warrants that: (a) it is not a "Covered Person" as defined under the Bulk Data Rule, and is not owned or controlled, directly or indirectly, by a "Country of Concern"; (b) it shall not sell, license, or otherwise transfer any data received under this DPA to any Country of Concern or Covered Person, or take any action that would constitute a prohibited "Covered Data Transaction" under the Bulk Data Rule; and (c) it shall promptly notify the other Party if it becomes aware of any circumstances that would cause a transaction under this DPA to violate the Bulk Data Rule, and the Parties shall cooperate in good faith to remediate any such violation.
- MISCELLANEOUS.
- Order of Precedence. In the event of any conflict between this DPA and the Agreement(s) with respect to the processing of Personal Information, this DPA shall control solely to the extent of such conflict and solely with respect to data protection obligations. All other terms of the Agreement(s) remain in full force and effect.
- Governing Law and Venue. This DPA shall be governed by and construed in accordance with the laws of the State of New York, without regard to its conflict of laws provisions. The exclusive forum for resolution of any dispute arising under this DPA shall be the state or federal courts located in New York, New York. Each Party consents to personal jurisdiction in such courts and waives any objection to the laying of venue therein.
- Entire Agreement. DeepIntent reserves the right to update this DPA from to time. This DPA, together with the Agreement(s) and any annexes hereto, constitutes the entire agreement between the Parties with respect to the processing of Company Data and supersedes all prior and contemporaneous discussions, representations, and agreements relating to such subject matter.
- Severability. If any provision of this DPA is held by a court of competent jurisdiction to be invalid or unenforceable, the remaining provisions shall continue in full force and effect, and such provision shall be modified to the minimum extent necessary to make it valid and enforceable consistent with the Parties’ intent.
- Notices. All notices under this DPA shall be provided in writing. Notices to DeepIntent shall be sent to legal@deepintent.com. Notices to Company shall be sent to the contact information provided in the applicable Order Form or Agreement. Notice shall be deemed effective upon confirmed receipt.
- No Waiver. DeepIntent’s failure to enforce any provision of this DPA shall not constitute a present or future waiver of such provision. All waivers by DeepIntent must be in writing to be effective.
ANNEX I
Description of Processing Activities
Controller / Business: With respect to Company Data — Company (as identified in the Agreement(s)); with respect to DeepIntent Data (including DeepIntent LLD) — DeepIntent, Inc.
Processor / Service Provider: With respect to Company Data — DeepIntent, Inc., 4 Bryant Park, Floor 4, New York, NY 10018; with respect to DeepIntent Data (including DeepIntent LLD) — Company.
Subject-Matter of Processing: Healthcare advertising campaign planning, targeting, delivery, measurement, and reporting
Duration of Processing: For the Term of the Agreement(s) and any post-termination period required by Applicable Privacy Law
Nature of Processing: Collection, storage, use, disclosure, analysis, segmentation, matching, reporting, and deletion of Personal Information
Purpose of Processing: Delivery of Services as described in the Agreement(s) and the Permitted Purposes set forth in Section 3(a) of this DPA
Types of Personal Information: Online identifiers (cookie IDs, MAIDs, IP addresses); publicly available healthcare provider identifiers (NPI numbers); pixel and impression data; audience segment data provided by Company
Categories of Data Subjects: Healthcare providers (HCPs) in the United States; consumers (DTC campaigns only, processed via de-identified data in a HIPAA-compliant secure environment)
Sensitive Personal Information: None. All healthcare claims data processed by DeepIntent is de-identified per HIPAA 45 CFR § 164.514.
Frequency of Processing: Continuous, as required to perform the Services
Retention Period: As set forth in Section 10 of this DPA; no longer than necessary to fulfill the Permitted Purposes
Subprocessors: See Annex II.
ANNEX II
Subprocessors
DeepIntent’s list of Subprocessors is available at the following URL: https://deepintent.com/subprocessors. DeepIntent reserves the right to modify this list from time to time in accordance with Section 6.
ANNEX III
Technical and Organizational Measures
The following are the technical and organizational measures implemented by DeepIntent:
Organizational Controls: Formal governance structure with executive and board-level oversight of security, risk, and privacy programs. All personnel are subject to security awareness training and written acknowledgment of security and privacy policies. Segregation of duties enforced across engineering and operations.
Access Controls: Single Sign-On (SSO) with Multi-Factor Authentication (MFA) enforced for all personnel; role-based access controls applied per dataset and system; least-privilege access model; regular accounts and permissions reviews.
Encryption: All customer data encrypted in transit and at rest using industry-standard encryption protocols; data classification levels defined with management policies applied per classification tier.
Network Security: Layered controls across perimeter, endpoint, and application layers; network segmentation by function and data sensitivity; Zero Trust principles applied; centralized log correlation, alerting, and forensic investigation capabilities; real-time threat intelligence monitoring.
Application Security: Secure software development lifecycle (SDLC) practices enforced; input validation and sanitization; secure HTTP headers; token-based authentication with session expiration; rate limiting on API endpoints; secrets management controls.
Vulnerability Management: Regular automated vulnerability scanning of network and endpoints; periodic third-party penetration testing; independent security process audits; regular patching policy across all systems and dependencies.
Data Clean Room: Sensitive data anonymized and stored in a firewalled Data Clean Room (DCR) with controlled ingress and egress, automated scanning, segregation of duties, and extensive monitoring. DCR design independently audited as part of SOC 2 Type II certification.
Subprocessor Controls: Due diligence conducted on all subprocessors prior to engagement and on a periodic basis. All subprocessors are bound by written agreements imposing data protection obligations consistent with DeepIntent’s partner commitments. DeepIntent remains liable for subprocessors’ processing of partner data.
Incident Response: Formal incident response plan maintained; seventy-two (72) hour notification commitment for confirmed Security Incidents; periodic tabletop exercises conducted.
Business Continuity: Disaster recovery plans maintained for all critical systems and tested periodically; backup and retention mechanisms documented per dataset.
Privacy Governance: Annual privacy audit covering policies, DPIAs, subprocessors, consumer rights, training, AI governance, and data flows; AI Governance Committee with cross-functional representation; formal AI Usage Policy with mandatory training; Global Privacy Control (GPC) integration for automated opt-out signal processing.
Healthcare-Specific Controls: Independent HIPAA Expert Determinations confirming a “very small” risk of re-identification for DeepIntent’s processes and datasets; statistical output suppression controls to prevent re-identification; NAI Health-Related Sensitive Personal Information (HSPI) guidance followed.
Certifications and Frameworks: SOC 2 Type II certified; ISO 27001 aligned; NAI member; CCPA/CPRA, VCDPA, CPA, CTDPA, TDPSA, and applicable multi-state privacy law compliant; HIPAA Expert Determinations maintained on an ongoing basis.
