Data Processing Addendum
Last revised: September 10, 2026
This Data Processing Addendum ("DPA") forms part of and is subject to the Subscription Agreement or other written or electronic terms of service or subscription agreement (the “Agreement”) between Smarty, LLC (“Smarty”) and the entity defined as “Subscriber” or an equivalent term thereunder, and each Subscriber Affiliate that is party to a Sales Order pursuant to the Agreement (collectively and individually referred to herein as “Subscriber”).
The person executing the DPA on the Subscriber’s behalf warrants that they have the authority to bind the Subscriber to this DPA. When the Subscriber agrees to the DPA in an online interface, Smarty, LLC is deemed to have executed the DPA with the Subscriber.
The date the Subscriber first clicks “I agree” with the DPA linked to the right (or words of similar effect) is the “DPA Effective Date.”
Terms defined in this DPA are found at the end, in Section 11. All capitalized terms not defined in this DPA have the definitions set forth in the Agreement.
1. APPLICABILITY, SCOPE AND DURATION
1.1. Applicability. This DPA applies (i) where Subscriber acts as the controller (or a “business”, as applicable) with respect to the processing of Personal Data and where Subscriber has appointed Smarty to process Personal Data as a processor or service provider (as applicable) on its behalf in connection with the Subscription Services and (ii) where Subscriber is a processor for a third-party controller and engages Smarty as a subprocessor. Where this DPA is applicable, it controls over any conflicting terms in the Agreement. This DPA is intended to demonstrate the parties’ compliance with the applicable Data Protection Laws.
1.2. Scope. To the extent Subscriber Data or Input Data includes or constitutes Personal Data, Smarty will process such Personal Data in accordance with this DPA. This DPA applies only to the processing of Personal Data contained in Subscriber Data and Input Data by Smarty while providing the Subscription Services.
1.3. Schedules. The subject matter and details of processing are set out in Schedule A (Data Processing Details). Schedule B (European Privacy Addendum) applies to Personal Data subject to European Data Protection Laws. Schedule C lists Smarty's authorized Infrastructure Subprocessors. Schedule D (Canadian Privacy Addendum) applies to Personal Data subject to Canadian Data Protection Laws.
1.4. Duration. This DPA commences on the DPA Effective Date and terminates upon expiration or termination of the Agreement (or, if later, the date on which Smarty has ceased all processing of Personal Data).
1.5. Termination. Either Party may terminate the Agreement or any active subscription upon written notice if: (i) the other Party materially breaches this DPA or the Agreement and fails to cure such breach within thirty (30) days after receiving written notice; or (ii) the other Party becomes insolvent, assigns assets for the benefit of creditors, becomes subject to bankruptcy or insolvency proceedings, or ceases normal business operations.
1.6. Business Relationship Data. Business relationship data such as administrative, transactional, or account-related information and data provided to or collected by Smarty in connection with the setup, administration, and ongoing use of the Subscription Services necessary to manage the business relationship between the parties is processed by Smarty as an independent controller and is governed by Smarty’s Privacy Policy.
2. PROCESSING OBLIGATIONS
2.1. Purpose. Smarty will process Personal Data only for the purposes described in the DPA, unless on further instructions from the Subscriber.
2.2. Documented Instructions. Smarty will process Personal Data (i) in accordance with Subscriber’s documented instructions as set forth in (A) this DPA, (B) the Agreement, and (C) any other written instructions provided by Subscriber that are consistent with the Subscription Services and constitute documented instructions for purposes of this DPA, including instructions relating to transfers, and (ii) as required by applicable Data Protection Laws.
2.3. Unlawful Instructions. Smarty shall inform Subscriber without undue delay if, in Smarty’s reasonable opinion, any instruction infringes applicable Data Protection Laws. Smarty will not be required to comply with such instruction until the parties resolve the matter in good faith.
2.4. Confidentiality Obligations. Smarty shall treat all Personal Data as confidential information and not disclose such confidential information without Subscriber’s prior written consent except: (i) to those Subprocessors listed in Schedule C to this DPA; (ii) to those of its personnel who need to know the confidential information in order to support and carry out the Subscription Services; and (iii) where it is required by a court to disclose Personal Data or there is a statutory obligation to do so, but only to the minimum extent necessary to comply with such court order or statutory obligation, and provided that any such disclosure shall be subject to the requirements of Section 9 of this DPA. Smarty shall ensure that all personnel authorized to process Personal Data are subject to written confidentiality obligations that survive termination of their engagement and receive appropriate privacy and security training.
2.5. Subscriber Responsibilities.
2.5.1. Subscriber shall not use the Subscription Services in a manner that violates applicable Data Protection Laws. Subscriber, and not Smarty, is responsible for determining the requirements of laws or regulations applicable to Subscriber’s business or for determining whether the Subscription Services meet the requirements of any such laws or regulations. As between the parties, Subscriber is responsible for the lawfulness of the processing of Personal Data and for implementing appropriate measures within Subscriber’s control to maintain the security, protection, and lawful deletion of such Personal Data.
2.5.2. Subscriber represents and warrants that: (i) Subscriber has established a valid lawful basis for Smarty’s processing of Personal Data under this DPA; (ii) to the best of Subscriber's knowledge, all required notices have been provided to and all required consents or other permissions have been obtained from relevant data subjects and any other required parties; and (iii) Personal Data provided to Smarty does not and will not include sensitive data, special categories of personal data (as defined under Data Protection Laws) or protected health information or the equivalent (unless the parties have entered into a Business Associate Agreement or an equivalent agreement for non-U.S. data).
2.5.3. Subscriber as Processor (Where Applicable). Where Subscriber processes Personal Data as a processor on behalf of Subscriber's customers, Subscriber shall (i) ensure that the responsibilities set forth in subsection 2.5.2 are fulfilled by the relevant controller(s) (Subscriber's customers); (ii) comply with all applicable processor obligations under applicable Data Protection Laws, including GDPR Article 28; and (iii) not instruct Smarty to process Personal Data in any manner that would violate the controller's instructions or applicable Data Protection Laws.
3. DATA USE AND ENHANCED PRIVACY OPTIONS
3.1. Address Data Use.
3.1.1. Smarty processes Input Data as a processor on behalf of Subscriber to deliver the API response. Following such processing, Smarty may extract the address components of Input Data, irreversibly separate them from any Subscriber account identifier, IP address, timestamps, or other Subscriber-context metadata, and retain such separated address components for the limited purposes of evaluating, improving, and updating the accuracy of Smarty's address validation, autocomplete, and geocoding datasets. Smarty's processing of such separated address components is governed by Section 3.2.4 (Deidentified Data) with respect to US State Privacy Laws, and by the equivalent provisions in Schedule B (European Privacy Addendum) and Schedule D (Canadian Privacy Addendum) with respect to those regimes.
3.1.2. Separately, Smarty acquires address data from independent third-party sources, including the United States Postal Service and data vendors that license government data. Address data acquired through such independent third-party sources is not Input Data or Subscriber Data even if the same address was previously submitted as Input Data, because Smarty's record of such address is sourced from and attributable to the third-party source rather than to any Subscriber API call. The legal characterization of Smarty's processing of separated address components and third-party-sourced address data under applicable Data Protection Laws is addressed in Section 3.2 (Compliance with US State Privacy Laws) and in the relevant Schedules to this DPA (specifically, Schedule B – European Privacy Addendum at paragraph 4 and Schedule D – Canadian Privacy Addendum at paragraph 8).
3.2. Compliance with US State Privacy Laws.
3.2.1. Service Provider Restrictions. Where Smarty processes Personal Data subject to US State Privacy Laws, Smarty acts as a service provider or processor (as applicable) and Subscriber acts as a business or controller (as applicable). Except with respect to data that constitutes deidentified data as described in Section 3.2.4, Smarty shall:
3.2.1.1. not sell or share (as those terms are defined under US State Privacy Laws) Personal Data received from or on behalf of Subscriber;
3.2.1.2. not retain, use, or disclose such Personal Data (i) for any purpose other than the business purposes specified in this DPA and the Agreement, including any commercial purpose, or (ii) outside of the direct business relationship between Smarty and Subscriber, except as expressly permitted by US State Privacy Laws;
3.2.1.3. not combine such Personal Data with personal information received from or on behalf of any other person or persons, or collected from Smarty's own interaction with the consumer, except to perform a business purpose as defined under applicable US State Privacy Laws and applicable implementing regulations;
3.2.1.4. not engage in cross-context behavioral advertising or targeted advertising (as those terms are defined under US State Privacy Laws) using Personal Data received under this DPA or the Agreement; and
3.2.1.5. notify Subscriber promptly if Smarty determines that it can no longer meet its obligations under applicable US State Privacy Laws.
3.2.2. Right to Stop and Remediate. Upon written notice from Subscriber identifying any unauthorized use of Personal Data by Smarty under this DPA, Subscriber may take reasonable and appropriate steps to stop and remediate such unauthorized use, and Smarty shall reasonably cooperate with Subscriber's efforts.
3.2.3. Compliance Monitoring. Subscriber's right to monitor Smarty's compliance with this Section 3.2, including through reasonable assessments, audits, or other technical and operational testing, is provided through the audit rights set forth in Section 6 of this DPA.
3.2.4. Deidentified Data. To the extent Smarty processes address components that have been separated and irreversibly disassociated from any Subscriber account identifier, IP address, timestamps, or other Subscriber-context metadata as described in Section 3.1 of this DPA, the parties agree such address components constitute deidentified data under applicable US State Privacy Laws. Smarty: (i) takes reasonable technical and organizational measures to ensure such data cannot be associated with or linked back to a particular consumer or household through any account identifier, IP address, or other Subscriber-context metadata previously associated with the data, including by not combining such data with other data that would permit reidentification; (ii) publicly commits, including through this DPA and Smarty's published privacy policies, to maintain and use such data only in such separated form and not to attempt reidentification of any consumer or household; and (iii) contractually obligates any recipient of such deidentified data, including any subprocessor and any licensee of any Smarty product that includes such data (including the Master Address List), to comply with the foregoing and to refrain from using such data to identify any consumer or household.
3.3. Enhanced Data Privacy. “Enhanced Data Privacy” is an optional solution available under certain subscription plans wherein Input Data is processed only in transient memory and is not stored, logged, or retained by Smarty after completion of the applicable address verification or address autocompletion request. Notwithstanding the foregoing, Smarty may retain a limited amount of Operational Data, such as usage metrics, error rates, timestamps, and account identifiers, as necessary to operate, maintain, secure, and support the Subscription Services, including for internal reporting, diagnostics, and service integrity.
3.4. Plans with Enhanced Data Privacy. If Subscriber does not wish to permit Smarty to retain Input Data for the purposes as described in Section 3.1, above, the solution is for plan subscriptions ordered by Subscriber to have the Enhanced Data Privacy upgrade. If a subscription to a plan with Enhanced Data Privacy is ordered, Smarty will then process Input Data in accordance with the Enhanced Data Privacy terms set forth herein for the duration of the applicable Subscription Term.
4. SECURITY MEASURES
4.1. Security Measures. Smarty will implement and maintain technical and organizational measures designed to protect Personal Data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure of or access to Personal Data taking into account the state of the art, the costs of implementation and the nature, scope, context and purposes of processing as well as the risk of varying likelihood and severity for the rights and freedoms of natural persons, all as described in Annex II to Schedule B of this DPA (the “Security Measures”). Subscriber Data in the form of Input Data processed through the Subscription Services will be logged, encrypted, compressed, and stored in a secure, isolated environment with access restricted to authorized personnel through role-based, multi-factor authentication.
4.2. Personal Data Breach Notification and Mitigation. In the event of a Personal Data Breach involving Subscriber Personal Data, including a breach that presents a real risk of significant harm, Smarty shall: (i) notify Subscriber within seventy-two (72) hours of becoming aware of the breach provided that where a full assessment is not possible within that timeframe, Smarty shall provide an initial notification within seventy-two (72) hours with such information as is then available, and shall supplement such notification as further information becomes available; (ii) take reasonable steps to contain and mitigate the breach; and (iii) provide Subscriber with reasonable cooperation and assistance necessary to fulfill any obligations of Subscriber to notify supervisory authorities and affected data subjects, as required by Data Protection Laws. These obligations will not apply where the Personal Data Breach results from Subscriber’s actions or omissions. Notification under this section will not be construed as an admission of fault or liability by Smarty.
4.3. Subscriber’s Security Assessment. Subscriber is solely responsible for evaluating whether the Subscription Services, the Security Measures, and Smarty’s commitments under this DPA are sufficient to meet Subscriber’s needs, including Subscriber’s security obligations under applicable Data Protection Laws or other applicable laws.
5. SUBPROCESSORS
5.1. Subprocessor Engagement.
5.1.1. Subscriber provides general authorization for Smarty to engage Subprocessors to process Subscriber Data, provided that Smarty complies with the requirements of this Section 5.
5.1.2. Subscriber authorizes Smarty to engage Infrastructure Subprocessors as Subprocessors. The Subprocessor List attached as Schedule C is a current list of all Infrastructure Subprocessors.
5.1.3. Subscriber further authorizes Smarty to engage Product Subprocessors as set forth in the Product Terms applicable to the API Products and incorporated in a Sales Order signed or digitally entered into by Subscriber. Product Subprocessors engaged solely in connection with a specific API Product are disclosed to the Subscriber in the applicable Product Terms. There are currently no Product Subprocessors for API Products returning Output Data relating to addresses or property located in the United States.
5.2. Requirements for Subprocessor Engagement. When engaging any Subprocessor, Smarty shall enter into a written agreement with such Subprocessor that imposes data protection obligations no less protective than those set forth in this DPA, to the extent applicable to the nature of the services provided by such Subprocessor.
5.3. Subprocessor Changes and Subscriber’s Opportunity to Object.
5.3.1. Smarty shall notify Subscriber of the engagement of any new Subprocessor during the term of the Agreement by providing notice at the same time as Smarty notifies its other customers generally, and in any event at least thirty (30) days prior to such engagement. Such notice will include the name and location of the Subprocessor and a description of the processing activities it will perform.
5.3.2. Subscriber may object to the engagement of a new Subprocessor by providing written notice to Smarty within the applicable notice period on reasonable grounds relating to the protection of Personal Data. Upon receipt of a valid objection, the parties will work together in good faith to identify a mutually acceptable resolution. If the parties are unable to reach a mutually acceptable resolution within a reasonable timeframe, Subscriber may, as its sole and exclusive remedy, terminate the Agreement and cancel the applicable subscription by providing written notice to Smarty.
5.4. Infrastructure Subprocessors. Nothing in this DPA will be construed to require Smarty to provide Subscriber with access to, or detailed information regarding, the facilities, systems, or internal practices of Infrastructure Subprocessors beyond the audit reports, certifications, or other compliance information that such Infrastructure Subprocessors make generally available to their customers.
6. AUDIT
6.1. Demonstrating Compliance. Upon Subscriber’s reasonable request, Smarty will make available to Subscriber information, materials and documents relating to the architecture, systems and procedures relevant to the protection of Personal Data that are necessary to demonstrate its compliance with the obligations set forth in this DPA. The information, materials, and documents made available under this Section 6 are intended to satisfy Subscriber's right to monitor Smarty's compliance under applicable Data Protection Laws, including US State Privacy Laws.
6.2. Annual Security Audit or Certification. If the controls or measures to be assessed are addressed in an SOC 2 Type 2 audit, ISO 27001 certification or similar report performed by a qualified third-party auditor within twelve (12) months of Subscriber’s audit request and Smarty has confirmed there are no known material changes in the controls audited, Subscriber may, in its reasonable discretion, accept such report in lieu of requesting an audit of such controls or measures, to the extent a statutory audit right is applicable. For clarity, nothing in this Section 6 (Audit) expands Subscriber’s audit rights with respect to Infrastructure Subprocessors beyond those expressly set forth in Section 5 (Subprocessors) of this DPA.
6.3. Statutory Audit Rights. Where the mandatory applicable Data Protection Laws provides Subscriber with a direct audit right, Smarty will allow for and operationally collaborate with audits, including inspections, conducted by Subscriber or another auditor designated by Subscriber (provided such an auditor is not a competitor of Smarty and has duly executed a non-disclosure agreement with Smarty). In case of such audit, Subscriber may contact Smarty to request an on-site audit with at least thirty (30) days’ prior notice. Before the commencement of any such on-site audit, Subscriber and Smarty will mutually agree upon the reasonable and necessary scope, timing, and duration of the audit, with the intent to reduce adverse impact on Smarty’s business activities. Subscriber shall promptly notify Smarty of any non-compliance discovered during the course of an audit. Subscriber will bear the reasonable costs of all such audits, as well as of any follow-up requested by Subscriber to Smarty; provided, however, that if the final results of such an audit reflect a material breach by Smarty of its obligations under this DPA, Smarty will reimburse Subscriber for its documented and reasonable out-of-pocket costs and expenses for such audit.
7. DATA SUBJECT RIGHTS
7.1. Subscriber’s Responsibility for Requests. If Smarty receives any request from a data subject in relation to the data subject’s Personal Data, Smarty will advise the data subject to submit the request to Subscriber, and Subscriber will be responsible for responding to any such request.
7.2. Request Assistance. Smarty will provide Subscriber with reasonable assistance as necessary for Subscriber to perform its obligation under applicable Data Protection Laws, taking into account the nature of the processing of Personal Data. Smarty shall promptly notify Subscriber if it receives any request, inquiry, or complaint from a data subject or supervisory authority relating to Subscriber Data and shall reasonably cooperate with Subscriber in addressing such requests or complaints. To the extent required by law and where Subscriber cannot reasonably respond without assistance, Smarty shall provide reasonable support to Subscriber, provided such assistance is legally permissible and technically feasible. Smarty may charge reasonable fees for such assistance as permitted by law.
8. RETURN OR DELETION OF DATA
8.1. Data Retention. Smarty’s obligations regarding the return or deletion of Subscriber Data are set forth in the Agreement and this DPA. Subscriber Data may only be retained to comply with legal requirements and in accordance with Smarty's data retention policies. Unless Subscriber opts for Smarty’s Enhanced Data Privacy solution, encrypted raw logs of calls containing cleansed Input Data made to Smarty’s Subscription Services under the Agreement, the validated output address, the caller's IP address, timestamps, and related technical metadata are retained by Smarty for up to 120 days from the date and time of the applicable API call, after which it is automatically and permanently deleted.
8.2. Business relationship data and Operational Data will be maintained separately and processed by Smarty as a data controller in accordance with Smarty's Privacy Policy.
9. GOVERNMENT AND LAW ENFORCEMENT REQUESTS.
9.1. Notice. If Smarty or any Subprocessor receives a request, demand, order, or other legal process from any government authority, regulatory body, or law enforcement agency requiring the disclosure of, or access to, any Personal Data processed under this DPA ("Government Request"), Smarty shall, to the extent permitted by applicable law, notify Subscriber promptly and in any event before complying with the Government Request, and shall provide Subscriber with sufficient information to enable Subscriber to seek a protective order, injunction, or other appropriate remedy.
9.2. Challenge. Smarty shall evaluate each Government Request for legal validity under applicable law. Where Smarty reasonably believes a Government Request is unlawful, overbroad, or otherwise not in compliance with applicable law, Smarty shall use reasonable legal means to challenge or seek to limit the request, at Subscriber's reasonable written request and expense.
9.3. Restricted Notice. Where Smarty is legally prohibited from notifying Subscriber of a Government Request, Smarty shall: (i) use reasonable efforts to obtain a waiver of such prohibition or to challenge its applicability; (ii) inform the relevant authority that Smarty processes Personal Data on behalf of Subscriber as a processor and that notification to Subscriber may be required; and (iii) notify Subscriber as soon as the legal prohibition ceases to apply.
9.4. Minimum Disclosure. In all cases, Smarty shall disclose only the minimum amount of Personal Data strictly necessary to comply with the Government Request, and shall document all Government Requests received and the responses provided.
10. MISCELLANEOUS PROVISIONS
10.1. Notices. Notwithstanding anything to the contrary in the Agreement, any notices required or permitted to be given by Smarty to Subscriber may be given in accordance with any notice clause of the Agreement.
10.2. Modification and Order of Precedence. Except as expressly modified by the DPA, the terms of the Agreement remain in full force and effect. To the extent of any conflict or inconsistency between this DPA and the other terms of the Agreement, this DPA will govern, but only with respect to Smarty’s processing activities hereunder. No amendment to this DPA shall be effective unless in writing and signed by both parties, except that Schedule C may be updated in accordance with Section 5.3.
10.3. Liability. Any liabilities arising in respect of this DPA are subject to the limitations of liability under the Agreement.
11. DEFINITIONS
The terms “business”, “controller”, “processing”, “processor”, “service provider”, and “supervisory authority” as used in this DPA have the meanings given in the applicable Data Protection Laws.
"Authorized Users" means any individual permitted by Subscriber to access the Subscription Services under its Subscription and account, whether through the Dashboard, via assigned security keys, or as otherwise authorized by Subscriber, including employees, contractors, agents, and third-party service providers acting on Subscriber's behalf, subject to the terms of this Agreement. Authorized Users do not include automated systems, External Systems, or bots.
"Canadian Data Protection Laws" means to the extent applicable to the processing in question: (i) the Personal Information Protection and Electronic Documents Act, S.C. 2000, c. 5 (PIPEDA), as amended from time to time, including by the Digital Privacy Act (S.C. 2015, c. 32); (ii) the Alberta PIPA; (iii) the BC PIPA; and (iv) Quebec Law 25. References to any Canadian Privacy Law include all regulations, guidance, orders, and decisions issued thereunder by competent authorities.
“Data Protection Laws” means all applicable laws, regulations, and other legal or regulatory requirements in any jurisdiction relating to privacy, data protection, data security, breach notification, or the processing of personal data, including without limitation, to the extent applicable, US State Privacy Laws, European Data Protection Laws, Canadian Data Protection Laws, the PRC’s Personal Information Protection Law (PIPL), India's Digital Personal Data Protection Act 2023 (DPDPA), Australia’s Privacy Act 1988, Brazil’s General Data Protection Law (LGPD), and Japan's Act on the Protection of Personal Information (APPI).
“Data Subject” means an identified or identifiable natural person to whom Personal Data relates, and is deemed to also include a “consumer” as defined under Data Protection Laws.
"European Data Protection Laws" means the EU/EEA General Data Protection Regulation, Regulation (EU) 2016/679 (“GDPR”), the United Kingdom Data Protection Act of 2018 (“UK GDPR”), the 2023 Swiss Federal Act on Data Protection (“nFADP”), together with any implementing legislation, regulations, or guidance issued thereunder, in each case as applicable to the processing in question.
“Input Data” means the address and location input data submitted to the APIs of the Subscription Services by Subscriber, Authorized Users or, if applicable, end users.
“Operational Data” means system-generated technical and diagnostic data generated during the runtime execution of the Subscription Services, including API interaction and usage data such as service-level metrics, latency, throughput, usage patterns, request and response activity, network connectivity, and related operational metadata. Operational Data excludes Subscriber Data, Input Data, and Output Data.
“Output Data” means any data, content, or other results made available to the Subscriber solely through subscribed API Products or other components of the Subscription Services, generated dynamically in response to Subscriber Data submitted through authenticated API calls.
“Personal Data” means any information relating to a living individual who can be identified, directly or indirectly, from such information alone or in combination with other information, as defined under applicable Data Protection Laws. For the purposes of this DPA, Personal Data refers only to such information that is submitted to, created by, or otherwise processed by Smarty in connection with the Subscription Services or the administration of the Agreement.
“Personal Data Breach” means a breach of the Security Measures causing the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, Personal Data in Smarty’s possession, custody or control. Personal Data Breaches do not include unsuccessful attempts or activities that do not compromise the security of Personal Data, including routine, unsuccessful log-in attempts, pings, port scans, denial of service attacks, or other network attacks on firewalls or networked systems.
"Restricted Transfer" means a transfer of Personal Data from the European Economic Area, United Kingdom, or Switzerland to a third country that is not recognized as providing an adequate level of data protection, where such transfer requires an appropriate safeguard under applicable European Data Protection Laws.
“Subprocessor” means a third party authorized under this DPA to process Personal Data in connection with the Subscription Services, including Infrastructure Subprocessors and Product Subprocessors.
(a) “Infrastructure Subprocessors” means third-party cloud hosting, infrastructure-as-a-service or platform service providers that process Personal Data solely to provide computing, storage, networking, or related technical platform services for the Subscription Services and that do not access Personal Data except on a purely incidental or automated basis (e.g., backup systems, migration tooling).
(b) “Product Subprocessors” means Subprocessors, other than Infrastructure Subprocessors, that process Personal Data in order to provide specific features or functionality of the Subscription Services and that may have logical access to Personal Data.
“Subscriber Data” has the meaning given in the Agreement for Subscriber Data or an equivalent defined term. In the absence of a defined term in the Agreement, “Subscriber Data” means data and content that, as between Subscriber and Smarty, Subscriber owns or controls and provides itself or through users to Smarty for processing.
"US State Privacy Laws" means all applicable US state privacy laws including the California Consumer Privacy Act (“CCPA”) and the California Privacy Rights Act (“CPRA,” and together with the CCPA, “California Privacy Law”), the Virginia Consumer Data Protection Act, the Colorado Privacy Act, the Connecticut Act Concerning Personal Data Privacy and Online Monitoring, the Oregon Consumer Privacy Act, the Maryland Online Data Privacy Act, the Texas Data Privacy and Security Act, and the New Jersey Data Privacy Law.
SCHEDULE A OF THE DPA – DATA PROCESSING DETAILS
This schedule forms part of the DPA and describes the processing that Smarty will perform on behalf of the Subscriber.
1. Subject Matter and Duration of Processing: Smarty will process Subscriber Data as described in the Agreement and applicable Sales Order, for the duration specified therein, unless otherwise agreed in writing.
2. Nature and Purpose of Processing: Under the Agreement, Smarty provides certain address validation Subscription Services to Subscriber. Smarty will process Subscriber Data as necessary to provide the Subscription Services to the Subscriber, including for the purposes of account management, technical support, system monitoring, security, maintaining and improving the services.
3. Categories of Data Subjects: Subscriber’s customers, employees or end users whose address data is processed through the Subscription Services.
4. Categories of Personal Data:
| Submitted Address Data | Street number, street name, city, state/province/territory, country, and ZIP/postal code submitted by Subscriber as Input Data |
| Locational Data | Geocoordinates specific to the address data |
| IP Address | Caller IP address collected as part of API log data |
5. IP Address Collection & Privacy: Smarty collects and retains end user IP addresses solely for operational, security, and service delivery purposes, including maintaining the security and integrity of the Subscription Services, preventing unauthorized use, and improving the relevance of results. IP addresses are retained for up to 120 days from the applicable API call and are then deleted in accordance with Section 8 of this DPA. IP addresses are not retained as part of separated address components following the separation process described in Section 3.1 of this DPA. Smarty does not sell, share, or use IP addresses for any purpose other than those set forth in this Schedule A.
6. Sensitive Data: Subscriber is prohibited from providing any sensitive data or special categories of personal data to Smarty, as defined under Data Protection Laws. Smarty and its Subprocessors do not intentionally collect or process any special categories of Personal Data in connection with the provision of the Subscription Services under the Agreement. Smarty implements enhanced measures to redact or remove any data not related to address data components. Smarty does not associate processed addresses with the names of individuals residing at or otherwise associated with such addresses, nor does it process genetic data, biometric data, or any other data that uniquely identifies a natural person.
For clarity, the Subscription Services are not designed or intended for use with Protected Health Information (PHI) as defined under the Health Insurance Portability and Accountability Act of 1996 and its implementing regulations (HIPAA). Smarty's separation of address components and processing of such components as deidentified data under US State Privacy Laws is not, and shall not be construed as, deidentification under HIPAA, which has different and more restrictive standards (45 C.F.R. §164.514(b)). Subscribers that are HIPAA covered entities or business associates shall not submit PHI to the Subscription Services without executing a Business Associate Agreement with Smarty as contemplated by Section 2.5.2 of this DPA.
SCHEDULE B OF THE DPA – EUROPEAN PRIVACY ADDENDUM
-
Applicability. This Schedule B applies solely to the Processing of Personal Data subject to European Data Protection Laws.
-
Subject Matter and Details of Processing. The subject matter, duration, nature, and purpose of the Processing, the categories of Personal Data, and the categories of Data Subjects are described in Schedule A (Data Processing Details).
-
Roles and Regulatory Compliance. The parties acknowledge and agree that: (i) Subscriber is a controller of the Personal Data or is acting as a processor for a third-party controller; (ii) Smarty is a processor or sub-processor of the Personal Data; and (iii) each party shall comply with the obligations applicable to it under European Data Protection Laws.
-
Smarty's Processing of Separated Address Components. With respect to address components that Smarty separates from Subscriber-context metadata for the limited purposes described in Section 3.1 of the DPA, Smarty acts as an independent controller, not as a processor of Subscriber, in respect of such separated address components. The parties acknowledge that such separated address components may remain personal data under European Data Protection Laws, and Smarty's processing of such data is conducted on the legitimate-interest legal basis under GDPR Article 6(1)(f) (or its equivalent under the UK GDPR or nFADP), subject to Smarty's documented balancing analysis and to appropriate technical and organizational safeguards. With respect to address data that Smarty acquires from independent third-party sources as described in Section 3.1 of the DPA, Smarty also acts as an independent controller, and such processing is governed by Smarty's privacy program rather than this DPA.
-
Data Security. Taking into account the nature of the Processing and the information available to Smarty, Smarty shall provide reasonable assistance to Subscriber in complying with Articles 32 to 34 of the GDPR, including by implementing the Security Measures and complying with the applicable security and breach notification provisions of the DPA.
-
**Impact Assessments and Prior Consultation. **Smarty shall reasonably assist Subscriber in complying with Articles 35 and 36 of the GDPR by making available relevant information regarding its Processing activities and security measures.
-
**Restricted Transfers. **Where the Processing involves a Restricted Transfer, such transfer will be made in accordance with Annex IV – Cross-Border Transfer Mechanisms.
-
Legal Restrictions. Smarty shall promptly notify Subscriber if it becomes aware of any law or practice that would materially prevent it or any Subprocessor from complying with European Data Protection Laws or applicable transfer mechanisms.
-
Conflict with SCCs. To the extent of any conflict between this Schedule B or the DPA and the EU SCCs or UK Addendum, the EU SCCs or UK Addendum (as applicable) shall prevail.
-
Annexes. The Annexes listed below form part of this Schedule B:
Annex I – Details of the Processing and Transfers
Annex II – Security Measures (Technical and Organizational Measures)
Annex III – List of Subprocessors: Schedule C – Subprocessor List is incorporated as Annex III
Annex IV – Cross-Border Transfer Mechanisms
ANNEX I: DETAILS OF THE PROCESSING AND TRANSFERS
| A. List of Parties | |
| Data Exporter (Controller) | Name: The Subscriber named in the Agreement Address: As in the Agreement or Order Role: Controller |
| Data Importer (Processor) | Name: Smarty, LLC Address: 1476 Sandhill Rd, Orem UT 84058 Contact: Legal Department Email: legal@smarty.com Role: Processor |
| B. Description of Transfer | |
| Categories of Data Subjects Whose Personal Data May Be Transferred | Subscriber’s customers, employees or end users whose address data is processed through the Subscription Services. |
| Categories of Personal Data Transferred | Address Data: Street number, street name, city, state/province/territory, country, and postal code Locational Data: Geocoordinates specific to the address data IP Address: Caller IP address collected as part of API log data |
| Sensitive Data | The Subscription Services are not intended for processing of Sensitive Data, and Subscriber shall not transfer Sensitive Data to Smarty. |
| Frequency of Transfer | The Personal Data transfers under the Agreement will take place on a continuous basis during the Subscription Term. |
| Nature of Processing | Under the Agreement, Smarty provides certain address validation Subscription Services to Subscriber. Smarty will process Subscriber Data as necessary to provide the Subscription Services to the Subscriber, including for the purposes of account management, technical support, system monitoring, security, maintaining and improving the services. |
| Retention Period | Personal Data will be retained in accordance with the Agreement and Smarty’s Data Retention Policy unless applicable law requires storage of the Personal Data for a longer period. |
| Competent Supervisory Authority | The supervisory authority will be the supervisory authority of the data exporter. |
| Transfer to Subprocessors | Smarty may process and transfer Personal Data to Subprocessors in relation to the performance of the DPA and the Agreement and in accordance with the following scope: Subject Matter: The subject matter of the processing under the DPA is to cleanse and standardize Subscriber’s address data. Nature of the Processing: Smarty and its Subprocessors are providing services or fulfilling contractual obligations to Subscriber, as described in the Agreement. These services may include the processing of Personal Data by Smarty and/or its Subprocessors. Duration: The duration of the processing under the DPA and Agreement will take place on a continuous basis during the Subscription Term. |
ANNEX II – SECURITY MEASURES (TECHNICAL AND ORGANIZATIONAL MEASURES)
Smarty maintains a documented information security program that includes administrative, technical, and physical safeguards designed to protect the confidentiality, integrity, and availability of systems and data processed through the Subscription Services. Smarty may update and modify the Security Measures from time to time provided that such updates and modifications do not result in a material degradation of the overall security of the Subscription Services provided under the Agreement.
|
|
Smarty maintains a comprehensive information security program that defines how it manages and protects its systems, data, and services. This program includes:
|
|
|
Smarty conducts periodic risk assessments to identify, evaluate, and mitigate potential security risks. It maintains processes for risk monitoring, reporting, and remediation. An asset management program classifies and manages hardware and software assets throughout their lifecycle to ensure appropriate protection and accountability. |
|
|
Smarty ensures personnel integrity and security awareness through:
|
|
|
Smarty implements robust access and authentication controls to protect systems and data:
|
|
|
Smarty’s Subscription Services are hosted on industry-leading, security-certified cloud infrastructure to ensure performance, reliability, and scalability. While third-party cloud providers manage and secure the underlying physical infrastructure, Smarty remains responsible for the design, implementation, and maintenance of its services and security controls. Physical access controls implemented by these providers include: Segmented access zones and role-based authorization; electronic key management systems; 24x7 monitoring through a global security operations center; video surveillance, alarm systems, and secure locking mechanisms; and trained, uniformed security personnel. Smarty reviews third-party audit reports to confirm appropriate physical access controls are maintained at all managed data centers. |
|
|
Smarty enforces operational and network security measures, including:
|
|
|
Smarty maintains secure application development and maintenance practices aligned with industry standards.
|
|
|
Smarty performs regular vulnerability assessments and penetration tests across systems and applications.
|
|
|
Smarty implements controls to ensure the confidentiality, integrity, and availability of data throughout its lifecycle.
|
|
|
Smarty maintains business continuity and disaster recovery plans consistent with industry standards and periodically tests these plans to ensure the continued availability and resilience of its Subscription Services. |
|
|
Smarty maintains a data security incident management program addressing detection, response, and notification of data incidents. Impacted Subscribers and regulatory authorities are notified in accordance with applicable laws and contractual requirements. |
|
|
Smarty maintains Service Organization Controls (“SOC”) auditing standards. A SOC 2 report is produced annually and may be provided upon request under a confidentiality agreement. Smarty may adopt additional standards or certifications as appropriate. Upon written request (no more than annually), Smarty will complete a data security questionnaire of reasonable scope regarding its security practices and controls. |
|
|
Smarty uses automated deployment and configuration management tools to enforce standardized, secure infrastructure settings. All configuration changes undergo formal code review and approval prior to release. Monitoring tools detect deviations from approved baselines. |
|
|
Smarty maintains documented data retention and deletion policies that define how and when data is retained, archived, or securely deleted in accordance with legal and contractual obligations. |
SCHEDULE C OF THE DPA (ANNEX III) – SUBPROCESSOR LIST
Smarty engages certain Subprocessors to support the delivery of the Subscription Services and to process Subscriber Data on its behalf, as permitted under the DPA. The table below identifies Subprocessors that provide general infrastructure as a service (IaaS) or platform as a service (PaaS). Infrastructure and platform Subprocessors, as used by Smarty, provide computing, storage, hosting, and related operational resources, and do not access, view, or independently process Subscriber Data.
Subprocessors engaged solely in connection with a specific API Product are disclosed to the Subscriber in the applicable Product Terms. For most of the API Products, there are no product-specific Subprocessors and the following list of infrastructure and platform Subprocessors is the complete list of Subprocessors.
Subscriber Data processed by Subprocessors is protected in accordance with the Security Measures described in Section 4 and Annex II to Schedule B of this DPA.
| Subprocessor Name | Service Provided | Data Access Level | Processing Location | Applicability |
| Amazon Web Services, Inc. (AWS) | Infrastructure as a Service: (Compute, Storage, Networking) | No direct access to Subscriber Data | United States | All API Products |
| UpCloud | Infrastructure as a Service: (Compute, Storage, Networking) | No direct access to Subscriber Data | United States United Kingdom | All API Products |
| Hetzner Online GmbH | Infrastructure as a Service: (Compute, Storage, Networking) | No direct access to Subscriber Data | United States (Smarty uses Hetzner’s U.S. data center) | All API Products |
| Tier.net | Infrastructure as a Service: (Compute, Storage, Networking) | No direct access to Subscriber Data | United States | All API Products |
| DigitalOcean | Infrastructure as a Service: (Compute, Storage, Networking) | No direct access to Subscriber Data | United Kingdom | All API Products |
| Google Cloud Services (GCS) | Infrastructure as a Service: (Compute, Storage) | No direct access to Subscriber Data | United States | Storage, Testing |
| Aiven | Platform as a Service: Managed Database Services | No direct access to Subscriber Data | United States | Database |
| Netlify | Website Hosting | No direct access to Subscriber Data | United States | Website |
| Vercel | Website Hosting | No direct access to Subscriber Data | United States | Website |
Service Category Definitions:
Infrastructure as a Service: Provision of cloud-based infrastructure for computing resources, storage, and networking used to operate the Subscription Services.
Platform as a Service: Managed Database Services: Third-party services that host Smarty’s database systems, storing account and subscription information, event streams, and other Operational Data, usage metadata, and Business relationship data.
Website Hosting: Hosting of Smarty’s website interfaces and web-based dashboards.
ANNEX IV – CROSS-BORDER TRANSFER MECHANISMS
1. Definitions. Capitalized terms not defined in this annex are defined in the DPA.
1.1. “EU Standard Contractual Clauses” or “EU SCCs” means the Standard Contractual Clauses approved by the European Commission in decision 2021/914.
1.2. “UK International Data Transfer Agreement” means the International Data Transfer Addendum to the EU Commission Standard Contractual Clauses issued by the UK Information Commissioner, Version B1.0, in force as of March 21, 2022.
2. EU Transfers. Where Personal Data is protected by EU GDPR and is subject to a Restricted Transfer, the following applies:
2.1. The EU SCCs are hereby incorporated by reference as follows:
(a) Module 2 (Controller to Processor) applies where Subscriber is a Controller of Personal Data and Smarty is a Processor of Personal Data;
(b) Module 3 (Processor to Processor) applies where Subscriber is a Processor of Personal Data (on behalf of a third-party Controller) and Smarty is a Processor of Personal Data;
(c) Subscriber is the “data exporter” and Smarty is the “data importer”; and
(d) by entering into this DPA, each party is deemed to have signed the EU SCCs (including their Annexes) as of the DPA Effective Date.
2.2. For each Module, where applicable the following applies:
(a) the optional docking clause in Clause 7 does not apply;
(b) in Clause 9, Option 2 will apply, the minimum time period for prior notice of Subprocessor changes shall be 30 days, as set out in Section 5 of this DPA, and Smarty shall fulfill its notification obligations by notifying Subscriber of any Subprocessor changes in accordance with Section 5 of this DPA;
(c) in Clause 11, the optional language does not apply;
(d) in Clause 13, all square brackets are removed with the text remaining;
(e) in Clause 17, Option 1 will apply, and the EU SCCs will be governed by Netherlands law;
(f) in Clause 18(b), disputes will be resolved before the courts of the Netherlands;
(g) Annex I (Details of the Processing and Transfers) to Schedule B of this DPA contains the information required in Annex 1 of the EU SCCs; and
(h) Annex II (Security Measures (Technical and Organizational Measures)) to Schedule B of this DPA contains the information required in Annex 2 of the EU SCCs.
2.3. Where context permits and requires, any reference in this DPA to the EU SCCs shall be read as a reference to the EU SCCs as modified in the manner set forth in this Section 2.
3. Swiss Transfers. Where Personal Data is protected by the FADP and is subject to a Restricted Transfer, the following applies:
3.1. The EU SCCs apply as set forth in Section 2 (EU Transfers) of this Annex IV with the following modifications:
(a) in Clause 13, the competent supervisory authority shall be the Swiss Federal Data Protection and Information Commissioner;
(b) in Clause 17 (Option 1), the EU SCCs will be governed by the laws of Switzerland;
(c) in Clause 18(b), disputes will be resolved before the courts of Switzerland;
(d) the term Member State must not be interpreted in such a way as to exclude Data Subjects in Switzerland from enforcing their rights in their place of habitual residence in accordance with Clause 18(c); and
(e) all references to the EU GDPR in this DPA are also deemed to refer to the FADP.
4. UK Transfers. Where Personal Data is protected by the UK GDPR and is subject to a Restricted Transfer, the following applies:
4.1. The EU SCCs apply as set forth in Section 2 (EU Transfers) of this Annex IV with the following modifications:
(a) each party shall be deemed to have signed the “UK Addendum to the EU Standard Contractual Clauses” (“UK Addendum”) issued by the Information Commissioner’s Office under section 119 (A) of the Data Protection Act 2018;
(b) the EU SCCs shall be deemed amended as specified by the UK Addendum in respect of the transfer of Personal Data;
(c) in Table 1 of the UK Addendum, the parties’ key contact information is located in Annex I (Details of the Processing and Transfers) to Schedule B of this DPA;
(d) in Table 2 of the UK Addendum, information about the version of the EU SCCs, modules and selected clauses which this UK Addendum is appended to are located above in this Annex IV;
(e) in Table 3 of the UK Addendum:
(i) the list of parties is located in Annex I (Details of the Processing and Transfers) to Schedule B of this DPA;
(ii) the description of transfer is located in Annex I (Details of the Processing and Transfers) to Schedule B of this DPA;
(iii) Annex II is located in Annex II (Security Measures (Technical and Organizational Measures)) to Schedule B of this DPA; and
(iv) the list of Subprocessors is located in Schedule C (Annex III) (Subprocessor List) of this DPA.
(f) in Table 4 of the UK Addendum, both the Importer and the Exporter may end the UK Addendum in accordance with its terms (and the respective box for each is deemed checked); and
(g) in Part 2: The Mandatory Clauses of the Approved Addendum, being the template Addendum B.1.0 issued by the ICO and laid before Parliament in accordance with section 119(A) of the Data Protection Act 2018 on 2 February 2022, as revised under section 18 of those Mandatory Clauses, are incorporated into this DPA by reference and shall apply in full.
5. Data Privacy Framework. For clarity, a transfer of Personal Data from the EU, UK or Switzerland to Smarty in the United States subject to the EU-U.S. Data Privacy Framework, the UK Extension to the EU-U.S. Data Privacy Framework, and/or the Swiss-U.S. Data Privacy Framework, as applicable (collectively, the “DPF”), shall not constitute a Restricted Transfer so long as Smarty maintains an active certification to the DPF and certification to the DPF remains a legal basis for transfer of Personal Data to the United States under the GDPR, UK GDPR or FADP, as applicable. If the DPF ceases to be a valid transfer mechanism, the SCCs (already incorporated) will automatically apply as the transfer mechanism for transfers previously covered by the DPF.
SCHEDULE D OF THE DPA – CANADIAN PRIVACY ADDENDUM
This Schedule D (the "Canadian Privacy Addendum" or "CPA") supplements the DPA between Smarty and Subscriber and applies solely to Personal Data subject to Canadian Data Protection Laws. To the extent of any conflict with the DPA or the Agreement with respect to Canadian Data Protection Laws, this CPA governs. Except as modified herein, all DPA obligations remain in full force. All capitalized terms have the meanings given in the DPA or the Agreement.
-
ROLES AND APPLICABILITY
Subscriber is an "organization" (PIPEDA, Alberta PIPA, BC PIPA) or a "person who collects, holds, uses, or communicates personal information" (Quebec Law 25) that has collected or controls Personal Data. Smarty is a third party engaged to process Personal Data on Subscriber's behalf. This CPA applies to processing subject to PIPEDA and, where applicable, the Alberta PIPA, BC PIPA, and Quebec Law 25.
-
CANADIAN-SPECIFIC PROCESSING OBLIGATIONS
2.1. Accountability (PIPEDA Principle 1). Smarty shall designate one or more individuals responsible for its compliance with this CPA and Canadian Data Protection Laws, implement policies and practices giving effect to applicable data protection principles, and upon written request provide Subscriber with information demonstrating such compliance.
2.2. Data Minimization and Accuracy. Smarty shall process only Personal Data reasonably necessary to provide the Subscription Services, consistent with Schedule A of the DPA, and shall implement reasonable measures to maintain accuracy of Personal Data within its control.
2.3. No Selling or Sharing. Smarty will not sell, rent, lease, or otherwise make Personal Data subject to Canadian Data Protection Laws available for commercial gain to any third party, and will not disclose such Personal Data except as permitted under this CPA, the DPA, or the Agreement, or as required by applicable law.
-
SUBSCRIBER RESPONSIBILITIES
3.1. Lawful Basis and Consent. Subscriber represents and warrants that it has obtained all necessary consents and provided all required notices to data subjects under Canadian Data Protection Laws, including notices regarding processing outside Canada, prior to transferring Personal Data to Smarty.
3.2. Cross-Border Transfer Disclosure. Subscriber acknowledges that Personal Data is transferred to Smarty's systems in the United States and to Subprocessors in other jurisdictions as identified in Schedule C. Subscriber is solely responsible for making all required disclosures to data subjects that their Personal Data may be processed outside Canada and may be accessible to foreign authorities, as required by PIPEDA Principle 4.1.3, Section 8 of the Alberta PIPA, Section 8 of the BC PIPA, and Section 17 of Quebec Law 25.
3.3. Privacy Impact Assessments. Subscriber is solely responsible for conducting any PIA required under Canadian Data Protection Laws, including under Section 63 of Quebec Law 25. Upon written request, Smarty shall make available relevant information about its processing activities, security measures, and Subprocessors to enable Subscriber to complete such assessment. Smarty is not required to prepare or file a PIA on Subscriber's behalf.
3.4. Sensitive Information. Subscriber shall not transfer to Smarty any sensitive personal information as defined under applicable Canadian Data Protection Laws (including health, financial, ethnic or racial origin, religious or political beliefs, sexual orientation, or biometric data).
-
CROSS-BORDER TRANSFER SAFEGUARDS
4.1. This CPA and the DPA together constitute the contractual safeguards required under PIPEDA Principle 4.1.3, Section 8 of the Alberta PIPA, Section 8 of the BC PIPA, and Section 17 of Quebec Law 25, and are intended to satisfy the written contract requirement under Section 23 of Quebec Law 25 for technology contracts communicating personal information outside Quebec. Subprocessor transfers are governed by Section 5.2 of the DPA.
-
BREACH NOTIFICATION
5.1. Breach notification obligations are governed by Section 4.2 of the DPA. In addition: (a) Smarty shall maintain records of all Personal Data Breaches involving Personal Data subject to Canadian Data Protection Laws, including facts, effects, and remedial actions, and shall make such records available to Subscriber upon written request to support Subscriber's compliance with Section 10.3 of PIPEDA; and (b) Subscriber is solely responsible for determining whether a breach triggers regulatory notification obligations under PIPEDA, the Alberta PIPA, BC PIPA, or Quebec Law 25, and for fulfilling all associated reporting obligations to the OPC, applicable provincial commissioners, or the CAI.
-
INDIVIDUAL RIGHTS
6.1. Data subject rights assistance is governed by Section 7 of the DPA. In addition, Subscriber is responsible for responding to all requests from data subjects ("individuals" under PIPEDA, Alberta PIPA, and BC PIPA; "persons concerned" under Quebec Law 25) including rights of access, correction, withdrawal of consent, and, under Quebec Law 25, rights to data portability (Section 27) and de-indexing (Section 28.1). Smarty shall use commercially reasonable efforts to assist with portability and de-indexing obligations to the extent technically feasible, subject to the acknowledgment that the nature of the Subscription Services limits the scope of Personal Data held by Smarty.
-
RETENTION, GOVERNMENT REQUESTS, AND AUDIT
7.1. Retention and deletion obligations are governed by Section 8 of the DPA. In addition, personal information subject to Quebec Law 25 shall be destroyed using reliable means as required by Section 23 of Quebec Law 25 once the applicable purpose and retention period have been fulfilled. Government request obligations are governed by Section 9 of the DPA and apply equally to requests from Canadian federal and provincial authorities, regulatory bodies, and law enforcement; Smarty shall not voluntarily disclose Personal Data subject to Canadian Data Protection Laws to any such authority without Subscriber's prior written consent except as required by mandatory applicable law or court order. Audit obligations are governed by Section 6 of the DPA.
-
SMARTY'S PROCESSING OF SEPARATED ADDRESS COMPONENTS
8.1. With respect to address components that Smarty separates from Subscriber-context metadata for the limited purposes described in Section 3.1 of the DPA, Smarty acts as an organization processing such data for its own purposes under Canadian Data Protection Laws, not on Subscriber's behalf. The parties acknowledge that such separated address components may remain personal information under Canadian Data Protection Laws, and Smarty's processing of such data is conducted for the limited and reasonable purpose of evaluating, improving, and updating the accuracy of Smarty's address validation, autocomplete, and geocoding datasets, subject to appropriate technical and organizational safeguards. Smarty's processing of such separated address components is governed by Smarty's privacy program rather than this DPA. With respect to address data that Smarty acquires from independent third-party sources as described in Section 3.1 of the DPA, Smarty also processes such data for its own purposes as an organization, and such processing is governed by Smarty's privacy program rather than this DPA.
-
DEFINITIONS
9.1. "Alberta PIPA" means the Personal Information Protection Act, S.A. 2003, c. P-6.5 (Alberta), as amended.
9.2. "BC PIPA" means the Personal Information Protection Act, S.B.C. 2003, c. 63 (British Columbia), as amended.
9.3. "CAI" means the Commission d'accès à l'information du Québec.
9.4. "OPC" means the Office of the Privacy Commissioner of Canada.
9.5. "PIPEDA" means the Personal Information Protection and Electronic Documents Act, S.C. 2000, c. 5, as amended, including by the Digital Privacy Act (S.C. 2015, c. 32).
9.6. "Quebec Law 25" means An Act respecting the protection of personal information in the private sector, CQLR c P-39.1, as amended by Bill 64, and as further amended from time to time, including all regulations made thereunder.
-
MISCELLANEOUS
10.1. Order of Precedence. This CPA governs to the extent of any conflict with the DPA or the Agreement with respect to Canadian Data Protection Laws.
10.2. Liability. Liabilities arising under this CPA are subject to the limitations of liability in the Agreement, including the Enhanced Cap on Aggregate Liability in Section 13.4. Nothing in the foregoing operates to limit any liability that cannot be limited or excluded under applicable Canadian Data Protection Laws.
10.3. Governing Law. This CPA shall be interpreted consistently with Canadian Data Protection Laws. Nothing in the Agreement precludes either party from bringing proceedings before a Canadian regulatory authority or court of competent jurisdiction where required by Canadian Data Protection Laws.
10.4. Updates. Smarty may update this CPA to reflect changes in Canadian Data Protection Laws upon at least thirty (30) days' advance written notice, provided such updates do not materially reduce Smarty's obligations.
10.5. Language. The parties have expressly requested that this CPA and all related documents be drafted in English. Les parties ont expressément demandé que la présente annexe et tous les documents connexes soient rédigés en anglais.