Delivr.ai Legal
Data Processing Addendum
Version 2026-09-01 · Effective September 1, 2026
First publication at a versioned address. States the Data Processing Addendum of the Delivr.ai, Inc. Usage-based Service Agreement as amended by the concurrent agreement update, including the controller and processor role split and the corrected sub-processor schedule.
This policy forms part of the Delivr.ai, Inc. Usage-based Service Agreement. Delivr publishes each version of this policy at a dated address, and superseded versions remain available at their dated addresses, so the version in force at any given time is ascertainable.
The following description of processing forms the Data Processing Addendum to the Agreement. It supplements Section 3 (Privacy & Security) of the Standard Terms and the Delivr.ai Privacy Policy.
- Processing Roles
- (a) For personal data collected via the Delivr Pixel on Customer's properties and processed to provide the Cloud Service to Customer, Customer is the Controller and Provider is the Processor. (b) For Network Data and graph-level identifier mappings derived from pixel events as described in the Customer Site Data provision of the Agreement, and for personal data from Provider's proprietary intent and contact databases returned via the Intent & Audience API and Contact Data API, Provider is an independent Controller under its own privacy notice. (c) Provider's use of pixel-collected personal data to improve how the Cloud Service interprets behavior for Customer is Processor activity; the resulting models, calibrations, and aggregate statistics are not personal data. Each party is independently responsible for its own compliance obligations.
- Categories of Data Subjects
- Visitors to Customer's websites and landing pages; business professionals identified through Provider's intent and contact databases.
- Categories of Personal Data
- IP addresses and approximate geolocation; browser and device metadata; cookie identifiers and first-party tracking data; hashed email identifiers (MD5, SHA-256); plain text business email addresses; full name, job title, seniority, department; business phone numbers; company name, domain, industry, employee count, revenue range; web browsing behavior and topic-level intent signals; page URLs and on-site event data from Customer's properties.
- Sensitive Data
- The Delivr Pixel does not intentionally collect sensitive personal data or special categories of personal data, and Customer shall not configure pixel collection to capture them. Provider's proprietary intent taxonomy may process topic-level inferences that applicable law treats as sensitive when Provider acts as an independent Controller. Those topics are subject to suppression, consent gating, or jurisdiction-specific exclusion as applicable before licensing or activation.
- Sub-processors
- Amazon Web Services (cloud infrastructure — US); TheSpine (identity resolution processing — US); Concord (consent management for pixel surfaces); Unified ID 2.0, operated by The Trade Desk (identity tokenization; applies to UID2-based delivery); Sovrn (cookie synchronization within the Delivr Pixel — US).
- Retention
- Provider retains raw visitor-level pixel data for no more than 13 months from collection. Aggregated and de-identified data may be retained indefinitely. Upon termination, Provider will cease processing Customer's first-party pixel data within 30 days and delete or anonymize it within 90 days of written request.
- Security Measures
- Encryption in transit (TLS 1.2+) and at rest; API key authentication; role-based access controls; hosting on cloud platforms that maintain their own independent security attestations; vulnerability scanning; access logging and audit trails; 72-hour breach notification. Provider's security program is described at trust.delivr.ai.
- Lawful Basis (Provider as Controller)
- Provider processes personal data in its proprietary databases on the basis of legitimate interests in providing identity resolution, intent, and contact enrichment services, subject to applicable balancing tests under GDPR Article 6(1)(f).
Version history
- 2026-09-01 — effective September 1, 2026 (current)
