Legal
Data Processing Agreement
How TapMind processes personal data on behalf of customers in connection with the Services.
This Data Processing Agreement (“DPA”) forms part of the agreement between TAPMIND TECHNOLOGIES PRIVATE LIMITED, (“TapMind”) with its registered office at Zed Pentagon, 4th floor, NGR Layout, Bengaluru, 560068, and [Customer legal name], with its registered office at [Customer address] (“Customer”).
This DPA governs the processing of Personal Data by TapMind on behalf of Customer in connection with the Services where and to the extent required by Applicable Data Protection Laws.
The parties agree as follows.
1. Definitions
For purposes of this DPA:
“Applicable Data Protection Laws” means all applicable laws and regulations relating to the protection, privacy, security, or processing of Personal Data applicable to the processing under this DPA, including, where applicable, the EU General Data Protection Regulation (“GDPR”), the UK GDPR, the UK Data Protection Act 2018, the California Consumer Privacy Act as amended by the California Privacy Rights Act (“CCPA/CPRA”), and other applicable U.S. state privacy laws.
“Controller” means the entity that determines the purposes and means of Processing Personal Data, or the equivalent concept under applicable privacy law.
“Customer Personal Data” means Personal Data Processed by TapMind on behalf of Customer in connection with the Services and subject to this DPA.
“Data Subject” means an identified or identifiable natural person to whom Personal Data relates, or the equivalent term under applicable law.
“Personal Data” means information relating to an identified or identifiable natural person, or information otherwise protected as personal information under Applicable Data Protection Laws.
“Process” or “Processing” means any operation performed on Personal Data, including collection, access, use, storage, disclosure, transmission, alteration, retrieval, combination, or deletion.
“Processor” means an entity that Processes Personal Data on behalf of a Controller, or the equivalent concept under applicable privacy law.
“Services” means the TapMind products and services provided under the applicable agreement, order form, statement of work, or other commercial arrangement between the parties, which may include mediation, orchestration, publisher monetization, Marketplace services, User Growth, App Publishing, SDKs, APIs, integrations, and related services.
“Subprocessor” means a third party engaged by TapMind to Process Customer Personal Data on behalf of Customer.
2. Scope and Applicability
2.1 Processing on Customer’s Behalf
This DPA applies to Customer Personal Data that TapMind Processes on behalf of Customer in connection with the Services where Customer acts as Controller, business, or equivalent and TapMind acts as Processor, service provider, contractor, or equivalent under Applicable Data Protection Laws.
2.2 Different Processing Roles
The parties acknowledge that TapMind may perform different functions within the AdTech ecosystem and may act in different legal capacities depending on the relevant Service, data flow, and applicable law.
Where TapMind independently determines the purposes and means of Processing Personal Data, including certain Processing undertaken for security, fraud prevention, legal compliance, operational administration, or other independently determined purposes, such Processing is not governed by the Processor obligations in this DPA unless otherwise agreed in writing.
2.3 Service-Specific Application
Where a particular Service, Order Form, Publisher Agreement, MSA, SDK License Agreement, or other written agreement establishes specific data-processing roles or obligations, those provisions will apply to the extent they are consistent with Applicable Data Protection Laws.
3. Roles and Responsibilities
3.1 Customer as Controller
For Customer Personal Data subject to this DPA, Customer is responsible for determining:
- the purposes for which Personal Data is collected and Processed;
- the categories of Personal Data and Data Subjects involved;
- the applicable legal basis for Processing;
- applicable consent requirements;
- privacy notices and disclosures provided to Data Subjects; and
- the lawfulness of Customer's instructions to TapMind.
3.2 TapMind as Processor
Where TapMind acts as Processor, TapMind will:
- Process Customer Personal Data only in accordance with Customer's documented instructions;
- comply with applicable Processor obligations under Applicable Data Protection Laws;
- implement appropriate technical and organizational measures;
- ensure authorized personnel are subject to confidentiality obligations;
- provide reasonable assistance to Customer as required under this DPA; and
- comply with the requirements applicable to Subprocessors.
3.3 Documented Instructions
Customer's documented instructions may include:
- this DPA and its Annexes;
- applicable Order Forms or Statements of Work;
- technical implementation documentation;
- configuration settings;
- written instructions provided through authorized Customer representatives; and
- other mutually agreed written instructions.
4. Customer Responsibilities
Customer is responsible for:
- establishing and maintaining an appropriate lawful basis for Processing Customer Personal Data;
- providing legally sufficient privacy notices and disclosures;
- obtaining and maintaining any consent required by Applicable Data Protection Laws;
- ensuring that its instructions to TapMind comply with Applicable Data Protection Laws;
- ensuring that Customer Personal Data provided to TapMind is reasonably necessary for the Services;
- maintaining appropriate retention and deletion requirements;
- responding to Data Subject requests, except to the extent TapMind is required to provide assistance under this DPA;
- ensuring that its publishers, advertisers, agencies, partners, or other customers and users comply with applicable privacy requirements; and
- complying with applicable laws governing advertising, tracking, cookies, SDKs, identifiers, consent, and related technologies.
5. TapMind Processing Obligations
Where TapMind acts as Processor, TapMind will:
5.1 Instructions
Process Customer Personal Data only for the purposes described in this DPA or otherwise documented by Customer.
5.2 Confidentiality
Ensure that persons authorized to Process Customer Personal Data are subject to appropriate confidentiality obligations.
5.3 Security
Implement appropriate technical and organizational measures designed to protect Customer Personal Data against unauthorized or unlawful Processing and against accidental loss, destruction, alteration, or damage.
5.4 Data Subject Assistance
Provide reasonable assistance to Customer in responding to Data Subject requests as required under Applicable Data Protection Laws.
5.5 Compliance Assistance
Taking into account the nature of Processing and information available to TapMind, provide reasonable assistance with:
- security obligations;
- Personal Data Breach response;
- Data Protection Impact Assessments;
- regulatory consultations; and
- other compliance obligations that directly relate to TapMind's Processing as Processor.
5.6 Unlawful Instructions
If TapMind reasonably believes that a Customer instruction infringes Applicable Data Protection Laws, TapMind will notify Customer before carrying out the relevant instruction, unless prohibited by law.
5.7 Records and Controls
Maintain appropriate records and controls relating to its Processing activities as required by Applicable Data Protection Laws.
6. Processing Instructions
TapMind may Process Customer Personal Data for the following purposes, to the extent applicable to the Services:
- providing and operating the Services;
- mediation and orchestration;
- operating and supporting integrations, SDKs, APIs, and adapters;
- Marketplace and programmatic advertising functions;
- reporting, measurement, optimization, and analytics;
- troubleshooting and technical support;
- maintaining platform performance and reliability;
- security and fraud prevention;
- detecting and preventing invalid or abusive activity;
- maintaining and improving the Services where permitted by Customer's instructions and Applicable Data Protection Laws; and
- carrying out other documented instructions from the customer.
TapMind will not Process Customer Personal Data for unrelated purposes outside the scope of the Services or Customer's documented instructions, except where required or permitted by Applicable Data Protection Laws.
7. Confidentiality
TapMind will treat Customer Personal Data as confidential and will not disclose it except:
- to authorized personnel and Subprocessors who have a legitimate need to access it;
- as necessary to provide the Services;
- as instructed or authorized by Customer;
- as required by Applicable Data Protection Laws; or
- as otherwise permitted by the applicable agreement.
Where legally permitted, TapMind will notify Customer of legally binding requests for disclosure of Customer Personal Data.
8. Security
8.1 Appropriate Security Measures
TapMind will implement and maintain appropriate technical and organizational measures appropriate to the nature, scope, context, and purposes of Processing and the risks presented by the Processing.
These measures may include:
- access controls and role-based permissions;
- authentication and authorization controls;
- encryption and other data-protection measures;
- logging and monitoring;
- vulnerability management;
- security testing;
- incident response procedures;
- backup and recovery mechanisms;
- business continuity and disaster recovery measures;
- personnel security and confidentiality controls; and
- physical and environmental security controls, where applicable.
8.2 Actual Controls
The specific technical and organizational measures applicable to TapMind will be documented in Annex 2 and must be reviewed and confirmed by TapMind's appropriate technical, security, and legal teams before execution.
9. Subprocessors
9.1 Authorization
Customer authorizes TapMind to engage Subprocessors as reasonably necessary to provide the Services.
9.2 Subprocessor Obligations
TapMind will require Subprocessors that Process Customer Personal Data to comply with contractual data-protection obligations appropriate to the Processing they perform.
9.3 TapMind Responsibility
To the extent required by Applicable Data Protection Laws, TapMind remains responsible for the performance of its Subprocessors with respect to their Processing of Customer Personal Data.
9.4 Subprocessor List
TapMind will maintain a list of authorized Subprocessors in Annex 3 or through another designated mechanism agreed with Customer.
Any notification, objection, or approval process relating to new Subprocessors will be subject to the requirements confirmed by the parties and Applicable Data Protection Laws.
10. Data Subject Requests
Where TapMind receives a request from a Data Subject relating to Customer Personal Data for which Customer is the Controller, TapMind will, where legally permitted:
- promptly notify Customer;
- refrain from responding substantively unless authorized or required by law; and
- provide reasonable assistance necessary for customers to respond.
The customer remains responsible for determining whether a request is valid and for providing the final response to the Data Subject, except where Applicable Data Protection Laws require otherwise.
11. Personal Data Breaches
11.1 Notification
TapMind will notify Customer without undue delay after becoming aware of a confirmed Personal Data Breach involving Customer Personal Data where notification is required by Applicable Data Protection Laws.
11.2 Information
To the extent reasonably available, the notification will include information concerning:
- the nature of the breach;
- the categories of Personal Data affected;
- the categories or approximate number of affected Data Subjects, where known;
- the likely consequences of the breach; and
- measures taken or proposed to address and mitigate the breach.
11.3 Cooperation
TapMind will provide reasonable cooperation and assistance to Customer in connection with investigation, mitigation, notification, and legally required remediation.
11.4 Regulatory or Data Subject Notification
Unless required by law or expressly authorized by Customer, TapMind will not independently notify affected Data Subjects or regulators of a breach involving Customer Personal Data.
12. Data Protection Impact Assessments and Regulatory Cooperation
Taking into account the nature of Processing and information reasonably available to TapMind, TapMind will provide reasonable assistance to Customer where necessary for Customer to:
- conduct a Data Protection Impact Assessment;
- evaluate risks associated with Processing;
- implement appropriate mitigation measures; and
- consult with a competent supervisory authority where required by Applicable Data Protection Laws.
Such assistance will be subject to reasonable limitations based on the Services, information available to TapMind, confidentiality obligations, security requirements, and applicable costs.
13. International Data Transfers
Where Customer Personal Data is transferred across jurisdictions, the parties will comply with Applicable Data Protection Laws governing international transfers.
Depending on the circumstances, lawful transfer mechanisms may include:
- an applicable adequacy decision;
- Standard Contractual Clauses (“SCCs”);
- the UK International Data Transfer Agreement or Addendum, where applicable;
- another legally recognized transfer mechanism; or
- another lawful safeguard permitted by Applicable Data Protection Laws.
The applicable transfer mechanism, countries, parties, and SCC modules, where relevant, will be identified in Annex 4.
14. Return and Deletion of Personal Data
Upon termination or expiration of the applicable Services, or upon Customer's written request where required by Applicable Data Protection Laws, TapMind will, subject to the applicable agreement and legal requirements:
- return Customer Personal Data to Customer; and/or
- delete Customer Personal Data.
TapMind may retain Personal Data where required by law or where reasonably necessary to establish, exercise, or defend legal claims, subject to applicable retention and security requirements.
Personal Data contained in backups may be deleted in accordance with TapMind's ordinary backup-retention and deletion processes.
15. Audits and Compliance Information
15.1 Information
Upon reasonable written request, TapMind will provide information reasonably necessary to demonstrate compliance with its obligations under this DPA, subject to confidentiality and security restrictions.
15.2 Audit Rights
Where required by Applicable Data Protection Laws, Customer may conduct or commission an audit of TapMind's relevant Processing activities, subject to:
- reasonable prior written notice;
- reasonable business hours;
- confidentiality requirements;
- reasonable scope and frequency;
- avoidance of unnecessary disruption;
- protection of TapMind's security and other customers' confidential information; and
- reasonable costs being borne by the requesting party unless otherwise required by law or agreed in writing.
15.3 Alternative Evidence
Where reasonably sufficient, TapMind may satisfy audit or information requests through available security certifications, independent audit reports, penetration-testing summaries, questionnaires, policies, or other relevant compliance documentation.
16. Third-Party and Independent Processing
The AdTech ecosystem may involve publishers, advertisers, agencies, DSPs, SSPs, exchanges, demand partners, supply partners, measurement providers, analytics providers, SDK providers, and other third-party technologies.
Those parties may independently Process Personal Data under their own privacy notices, agreements, lawful bases, and compliance obligations.
This DPA governs only Processing performed by TapMind as Processor on behalf of Customer.
Nothing in this DPA makes TapMind responsible for the independent Processing activities of third parties that are not acting as TapMind's Subprocessors.
17. Consent and Advertising Technology
The parties will comply with Applicable Data Protection Laws governing cookies, SDKs, advertising identifiers, device information, location information, personalized advertising, and other advertising technologies.
Customer is responsible for obtaining any consent or establishing any other lawful basis required for its collection and use of Personal Data and for making required disclosures to Data Subjects.
Where technically supported by the Services, TapMind may receive, process, transmit, or otherwise use consent signals, privacy signals, or consent strings supplied by Customer or other authorized parties.
18. Customer Use of TapMind Technology
Where the Services include SDKs, APIs, tags, adapters, integrations, or other technical components, Customer is responsible for:
- implementing the technology in accordance with TapMind documentation;
- configuring applicable privacy and consent settings;
- obtaining required permissions and consent;
- providing required disclosures;
- using the technology in compliance with Applicable Data Protection Laws; and
- ensuring that its implementation does not introduce unlawful Processing.
The availability of a technical mechanism does not by itself transfer Customer's independent legal obligations to TapMind.
19. Controller-to-Controller and Other Data Relationships
Not every exchange of Personal Data within the Services constitutes Processor-to-Controller Processing.
Where TapMind and Customer independently determine the purposes and means of Processing particular Personal Data, the parties may act as independent Controllers, businesses, or equivalent entities.
Where required, the parties will enter into additional contractual terms governing such Processing.
The applicable legal role will be determined by the actual Processing activity, contractual arrangement, and Applicable Data Protection Laws rather than solely by the terminology used in this DPA.
20. Liability
Each party's liability arising under or in connection with this DPA will be governed by the applicable commercial agreement between the parties, except to the extent otherwise required by Applicable Data Protection Laws.
21. Term and Termination
This DPA will remain effective for so long as TapMind Processes Customer Personal Data on behalf of Customer under the applicable Services.
Termination of this DPA will not relieve either party of obligations that, by their nature, survive termination, including confidentiality, data protection, deletion or return obligations, and applicable liability provisions.
22. Order of Precedence
In the event of a conflict:
- Applicable mandatory Data Protection Laws will prevail;
- applicable mandatory international-transfer mechanisms will prevail over conflicting provisions relating to international transfers;
- this DPA will prevail over conflicting data-processing provisions in the applicable commercial agreement, solely with respect to the Processing of Personal Data; and
- the applicable commercial agreement will otherwise govern the commercial relationship.
Product-specific agreements, Order Forms, Statements of Work, or other written agreements may establish additional data-processing requirements where expressly agreed by the parties.
23. Changes to this DPA
TapMind may update this DPA where reasonably necessary to reflect:
- changes in Applicable Data Protection Laws;
- regulatory requirements;
- changes to the Services;
- changes in technology or security practices; or
- changes in Subprocessors or data-processing arrangements.
Where required by Applicable Data Protection Laws or the applicable commercial agreement, TapMind will provide notice of material changes.
24. General Provisions
24.1 Entire Agreement
This DPA, together with the applicable commercial agreement and its referenced documents, constitutes the agreement between the parties regarding the Processing of Customer Personal Data covered by this DPA.
24.2 Severability
If any provision is determined to be invalid or unenforceable, the remaining provisions will remain in effect to the extent permitted by law.
24.3 No Third-Party Beneficiaries
Except where expressly required by Applicable Data Protection Laws, this DPA does not create rights for third parties.
24.4 Amendments
Any amendments required to comply with Applicable Data Protection Laws may be documented through an updated version of this DPA or another written agreement between the parties.
25. Data Protection Contact
TapMind Legal / Privacy Contact
Legal Entity: TAPMIND TECHNOLOGIES PRIVATE LIMITED
Address: Zed Pentagon, 4th floor, NGR Layout, Bengaluru, India – 560068
Privacy Email: dpo@tapmind.com
Data Protection Officer, if applicable: dpo@tapmind.com
ANNEX 1 — PROCESSING DETAILS
This Annex describes the Processing of Customer Personal Data contemplated by this DPA.
A. Subject Matter
Processing of Personal Data necessary to provide the Services, including mediation, orchestration, advertising technology, monetization, Marketplace functionality, reporting, optimization, integrations, and related services.
B. Duration
Customer Personal Data will be Processed for the duration of the applicable Services and thereafter as necessary to comply with applicable deletion, retention, legal, security, and contractual requirements.
C. Nature of Processing
Processing may include:
- collection;
- receipt;
- access;
- transmission;
- storage;
- organization;
- matching;
- analysis;
- reporting;
- optimization;
- disclosure to authorized demand/supply partners or Subprocessors where instructed or necessary for the Services;
- security and fraud prevention; and
- deletion.
D. Categories of Data Subjects
Depending on the Services and Customer's implementation, Data Subjects may include:
- users of websites and applications;
- publishers and publisher personnel;
- advertisers and advertiser personnel;
- agency personnel;
- business contacts; and
- other individuals whose Personal Data is submitted to or made accessible through the Services.
E. Categories of Personal Data
Depending on the Services and Customer's implementation, Personal Data may include:
- IP address;
- device identifiers;
- advertising identifiers;
- browser and device information;
- operating system information;
- application information;
- network information;
- approximate location information;
- online identifiers;
- cookie and similar technology information;
- consent signals and consent strings;
- advertising and interaction information;
- log and technical information;
- account and business contact information; and
- other Personal Data submitted or made available by Customer.
F. Special Categories / Sensitive Personal Data
Customers must not submit Special Categories of Personal Data or Sensitive Personal Data to TapMind unless expressly authorized in writing and supported by an applicable lawful basis and appropriate safeguards.
ANNEX 2 — TECHNICAL AND ORGANIZATIONAL SECURITY MEASURES
TapMind will maintain appropriate technical and organizational measures proportionate to the risks associated with its Processing of Customer Personal Data.
The applicable measures should include, where relevant:
1. Access Control
- role-based access;
- least-privilege principles;
- authentication controls;
- administrative access restrictions;
- access review procedures.
2. Data Protection
- encryption in transit;
- encryption at rest where appropriate;
- secure key-management practices;
- data minimization;
- appropriate segregation of customer environments or data where applicable.
3. Infrastructure Security
- secure cloud and hosting configurations;
- network security controls;
- system monitoring;
- logging;
- vulnerability management;
- security testing.
4. Incident Management
- documented incident-response procedures;
- incident detection and escalation;
- investigation and containment;
- remediation;
- breach notification procedures.
5. Business Continuity and Resilience
- backup procedures;
- recovery mechanisms;
- business continuity planning;
- disaster recovery measures;
- availability monitoring.
6. Personnel Security
- confidentiality obligations;
- security awareness and training;
- access authorization procedures;
- appropriate personnel controls.
7. Physical and Environmental Security
Where applicable, physical and environmental safeguards maintained by TapMind or its infrastructure providers.
ANNEX 3 — AUTHORIZED SUBPROCESSORS
The following Subprocessors are authorized as of the Effective Date:
- Subprocessor
Service / Function
Processing Location(s)
Data Processed
Transfer Mechanism
To be confirmed
To be confirmed
To be confirmed
To be confirmed
To be confirmed
To be confirmed
To be confirmed
To be confirmed
To be confirmed
To be confirmed
To be confirmed
To be confirmed
To be confirmed
To be confirmed
To be confirmed
ANNEX 4 — INTERNATIONAL DATA TRANSFERS
Where Customer Personal Data is transferred internationally, the applicable mechanism will be documented below.
EU / EEA Transfers
Data Exporter: TAPMIND TECHNOLOGIES PRIVATE LIMITED
Data Importer: TAPMIND TECHNOLOGIES PRIVATE LIMITED
Transfer Mechanism: To be confirmed in the executed DPA
SCC Module: To be confirmed in the executed DPA
Transfer Countries: To be confirmed in the executed DPA
UK Transfers
Transfer Mechanism: To be confirmed in the executed DPA
Parties: To be confirmed in the executed DPA
Transfer Countries: To be confirmed in the executed DPA
Other Jurisdictions
Applicable Mechanism: To be confirmed in the executed DPA
The parties will implement any additional safeguards required by Applicable Data Protection Laws.
ANNEX 5 — APPROVED PROCESSING ACTIVITIES
The following TapMind Services may involve Processing of Customer Personal Data, subject to the actual implementation and applicable contractual arrangement:
1. TapMind Ad Platform
Advertising mediation, monetization, reporting, optimization, and related platform functionality.
2. Mediation and Orchestration
Decisioning, demand management, publisher-selected demand partner integrations, Marketplace interactions, and related technical processing.
3. SDKs, APIs, Adapters, and Integrations
Technical integration and transmission of data required to operate applicable advertising and monetization functionality.
4. Marketplace
Programmatic demand and marketplace-related advertising operations where applicable.
5. User Growth
User acquisition, performance marketing, campaign measurement, and related services where applicable.
6. App Publishing
App or game acquisition, publishing, monetization, user acquisition, and related services where applicable.
7. Other Services
Other Services expressly agreed by the parties in an Order Form, Statement of Work, or other written agreement.
[TAPMIND LEGAL/PRODUCT REVIEW: Confirm final product/service list and the Processing activities associated with each.]