Data Processing Addendum
Effective Date: December 15, 2024 | Version 2.1
1. Preamble & Scope
This Data Processing Addendum (the "DPA") governs the processing of personal data by The Daily Pulse, Inc. ("The Daily Pulse", "Processor", or "We") on behalf of our clients, publishers, and enterprise subscribers ("Controller" or "You"). This DPA is incorporated by reference into the applicable Master Services Agreement, Subscription Agreement, or Platform Terms (collectively, the "Main Agreement").
Where this DPA and the Main Agreement conflict, the provisions of this DPA shall control with respect to data protection obligations. This DPA ensures compliance with applicable data protection laws, including but not limited to the GDPR, CCPA/CPRA, and other relevant privacy regulations.
2. Definitions
- "Personal Data" means any information relating to an identified or identifiable natural person.
- "Processing" means any operation performed on Personal Data, including collection, storage, use, disclosure, and deletion.
- "Data Subject" means the natural person to whom the Personal Data relates.
- "Controller" means the entity that determines the purposes and means of Processing.
- "Processor" means The Daily Pulse, which processes Personal Data on behalf of the Controller.
- "Applicable Data Protection Laws" means all laws, regulations, and industry standards governing data privacy and security in the jurisdictions where services are provided.
3. Data Subjects & Categories
The Daily Pulse may process Personal Data relating to the following categories of Data Subjects, depending on the services engaged:
- Registered subscribers and account holders
- News contributors, journalists, and content creators
- Advertising partners and campaign managers
- Analytics users and API integrators
- Customer support contacts and billing representatives
Categories of Personal Data processed include: identity data, contact information, authentication credentials, usage analytics, payment/billing information, and device/location metadata.
4. Processing Purpose & Instructions
The Daily Pulse shall process Personal Data solely:
- Pursuant to the Main Agreement and documented instructions provided by the Controller;
- To deliver, operate, and improve our news distribution, analytics, and content management platform;
- To comply with legal obligations applicable to The Daily Pulse as a Processor.
The Daily Pulse shall not process Personal Data for its own marketing, profiling, or commercial purposes unless explicit prior authorization is obtained. Any processing beyond the scope of this DPA requires written consent and may trigger additional contractual terms.
5. Security & Confidentiality
The Daily Pulse implements industry-standard technical and organizational measures ("TOMs") to safeguard Personal Data, including:
- Encryption of data in transit (TLS 1.2+) and at rest (AES-256)
- Role-based access control and multi-factor authentication for internal systems
- Regular security assessments, penetration testing, and vulnerability scanning
- Secure data retention and deletion protocols aligned with Controller instructions
- Employee training on data privacy, handling, and incident response
Confidentiality obligations survive termination of this DPA and bind all personnel, contractors, and subprocessors with access to Personal Data.
6. Subprocessors
The Daily Pulse may engage third-party subprocessors to assist in delivering services (e.g., cloud hosting, email delivery, analytics, payment processing). The Controller provides prior general authorization for the use of subprocessors, provided that:
- Each subprocessor is bound by a written agreement containing data protection obligations no less protective than this DPA;
- The Daily Pulse remains fully liable for subprocessor acts and omissions;
- The Controller may object to new subprocessors within 15 days of notice. If the objection is based on legitimate privacy grounds, The Daily Pulse will work in good faith to resolve the issue or remove the subprocessor.
A current list of authorized subprocessors is maintained at the daily pulse.com/subprocessors.
7. International Data Transfers
Personal Data may be transferred to and processed in jurisdictions outside the European Economic Area ("EEA"), United Kingdom, or California. The Daily Pulse ensures that such transfers comply with Applicable Data Protection Laws by relying on:
- European Commission Standard Contractual Clauses ("SCCs") where applicable;
- US-EU Data Privacy Framework certification for eligible services;
- Transfer Impact Assessments ("TIAs") conducted prior to cross-border data flows;
- Supplementary technical, contractual, and organizational safeguards.
8. Data Subject Rights & Cooperation
The Daily Pulse will assist the Controller in fulfilling data subject rights requests (access, rectification, erasure, restriction, portability, objection) upon receipt of a verified request. The Daily Pulse shall:
- Respond to Controller requests within 5 business days;
- Provide necessary technical and administrative assistance to enable compliance;
- Not directly respond to Data Subjects unless legally required or explicitly authorized by the Controller.
9. Data Breach Notification
In the event of a confirmed or suspected personal data breach, The Daily Pulse shall:
- Notify the Controller without undue delay, and in no case later than 48 hours after awareness;
- Provide details including nature of breach, categories/quantity of affected data, likely consequences, and mitigating measures;
- Cooperate fully with the Controller's investigation, regulatory notifications, and remediation efforts;
- Maintain detailed records of all breaches for a minimum of 24 months.
10. Audit & Monitoring
The Controller may request an audit or certification of The Daily Pulse's data protection compliance upon reasonable notice. Such audits shall:
- Be conducted by an independent third party or The Daily Pulse's own compliance team;
- Occur no more than once per calendar year unless a breach or material risk justifies additional reviews;
- Respect The Daily Pulse's confidentiality and operational security;
- Be completed within 30 days, with findings shared and remediation plans established promptly.
11. Term & Termination
This DPA remains in effect for the duration of the Main Agreement and any subsequent renewals. Upon termination or expiration, The Daily Pulse shall, at the Controller's direction, securely return or certify deletion of all Personal Data within 30 days, unless retention is required by law. Certificates of deletion will be provided upon request.
12. Contact Information
For questions regarding this Data Processing Addendum, data protection inquiries, or to exercise contractual rights, please contact:
Email: dpo@dailypulse.com
Address: 1200 Media Avenue, Suite 400, New York, NY 10001
DPO Portal: dailypulse.com/dpo-portal
Phone: +1 (800) 555-0198 (Mon–Fri, 9AM–6PM EST)
This document is periodically reviewed and updated. The most current version will always be available at /data-processing-addendum. Last revised: December 15, 2024.