Advertise across 5,000+ premium sites and apps on the open web

BidSystem Data Processing Agreement

Last updated: August 25, 2026

This Data Processing Agreement (this "DPA") is between Ezoic Inc., a Delaware corporation d/b/a BidSystem, with offices located at 6023 Innovation Way, Suite 200, Carlsbad, CA 92009, on behalf of itself and its Affiliates that provide BidSystem ("BidSystem") and the advertiser, agency, demand-side platform, or other buyer that accesses or uses BidSystem ("Advertiser").

Advertiser and BidSystem have entered into, or are entering into, an agreement for Advertiser to access and use BidSystem's advertising exchange (the "BidSystem Agreement") under which BidSystem makes available bid requests for advertising inventory from its Supply Partners and Advertiser submits bids on, and may purchase, such inventory. This DPA sets out the additional terms, requirements, and conditions on which the parties will obtain, handle, process, disclose, transfer, or store Personal Data in connection with BidSystem.

BidSystem's processing of Personal Data in connection with BidSystem is further described in BidSystem's Privacy Policy at: https://bidsystem.ai/privacy. This DPA supplements the BidSystem Agreement. In the event of conflict, this DPA shall control solely with respect to data protection obligations required by applicable Privacy and Data Protection Requirements, and otherwise the BidSystem Agreement shall prevail.

NOW, THEREFORE, the parties hereto agree as follows:

1. Definitions and Interpretation

1.1 Definitions:

"Affiliate" means any entity that directly or indirectly controls, is controlled by, or is under common control with a party.

"BidSystem" means BidSystem's advertising exchange and related bidding, auction, reporting, and delivery services made available to Advertiser under the BidSystem Agreement.

"Bid Request Data" means the Personal Data made available to Advertiser in or in connection with a bid request through BidSystem, which may include online identifiers (such as IP address and cookie, device, or advertising identifiers), device, browser, and operating system information, approximate geolocation derived from IP address, contextual information regarding the page or property on which the advertising inventory appears, ad interaction data, and associated Consent Signals.

"Business Purpose" means Advertiser's evaluation of and bidding on advertising inventory made available through BidSystem, and the parties' related auction operation, ad selection and delivery, measurement and reporting, frequency capping, billing and reconciliation, and fraud detection and prevention activities described in this DPA and BidSystem's Privacy Policy.

"Consent Signal" means an IAB Transparency and Consent Framework (TCF) consent string, IAB Global Privacy Platform (GPP) string, U.S. Privacy String, Global Privacy Control signal, or other industry-standard mechanism used to communicate a Data Subject's consent or opt-out preferences.

"Data Privacy Framework" or "DPF" means the EU-U.S. Data Privacy Framework, the UK Extension thereto, and the Swiss-U.S. Data Privacy Framework, as applicable.

"Data Subject" means an individual who is the subject of the Personal Data and to whom or about whom the Personal Data relates or identifies, directly or indirectly.

"Personal Data" means any information processed in connection with BidSystem that (a) identifies or relates to an individual who can be identified directly or indirectly from that data alone or in combination with other information in a party's possession or control or that the party is likely to have access to, or (b) the relevant Privacy and Data Protection Requirements otherwise define as protected personal data.

"Processing," "processes," or "process" means any activity that involves the use of Personal Data or that the relevant Privacy and Data Protection Requirements may otherwise include in the definition of processing, processes, or process, including obtaining, recording, holding, organizing, amending, retrieving, using, disclosing, transferring, erasing, or destroying it.

"Privacy and Data Protection Requirements" means all applicable laws and regulations relating to the processing, protection, or privacy of Personal Data, including where applicable the guidance and codes of practice issued by regulatory bodies in any relevant jurisdiction. This includes, but is not limited to, GDPR, UK GDPR, CCPA/CPRA, and other applicable U.S. state privacy laws.

"Security Breach" means any act or omission that compromises the security, confidentiality, or integrity of Personal Data or the physical, technical, administrative, or organizational safeguards put in place to protect it. A Security Breach does not include unsuccessful attempts or activities that do not compromise the security of Personal Data, such as unsuccessful log-in attempts, pings, port scans, denial of service attacks, or other network attacks on firewalls or networked systems.

"Standard Contractual Clauses (SCC)" means the standard contractual clauses adopted by the European Commission pursuant to Commission Implementing Decision (EU) 2021/914, and any equivalent or successor transfer clauses approved under applicable Privacy and Data Protection Requirements, in each case as applicable to the relevant transfer.

"Supply Partners" means the publishers, sellers, and other supply sources whose advertising inventory is made available through BidSystem.

"UK Addendum" means the International Data Transfer Addendum to the EU Commission Standard Contractual Clauses issued by the UK Information Commissioner (version B1.0).

1.2 This DPA is subject to the terms of the BidSystem Agreement and is incorporated into the BidSystem Agreement. Interpretations and defined terms set forth in the BidSystem Agreement apply to the interpretation of this DPA.

1.3 A reference to writing or written includes email.

2. Roles of the Parties; Personal Data Types and Processing Purposes

2.1 Each party acts as an independent controller (or, where applicable under U.S. state law, a separate "business") with respect to the Personal Data it processes in connection with BidSystem. Neither party is a processor, service provider, or contractor of the other with respect to such Personal Data, and this DPA does not create a controller-processor relationship between the parties.

2.2 Each party is responsible for its own compliance obligations under applicable Privacy and Data Protection Requirements with respect to the Personal Data it processes, including its own notices, its own legal basis for processing, and its own responses to Data Subject requests.

2.3 BidSystem processes Personal Data as described in this DPA, BidSystem's Privacy Policy, and Ezoic's Advertising Partners page. The subject matter, duration, nature, and purpose of Processing, as well as the types of Personal Data and categories of Data Subjects, are set out in Annex 1 to this DPA, as further described in BidSystem's Privacy Policy.

3. Advertiser's Obligations

3.1 Advertiser will process Bid Request Data solely for the Business Purpose and in a manner consistent with applicable Privacy and Data Protection Requirements and any Consent Signal transmitted with or in connection with the applicable bid request.

3.2 Advertiser will not process Bid Request Data in a manner inconsistent with a Consent Signal indicating that a Data Subject has withheld consent or exercised an opt-out right, including any signal indicating an opt-out of the sale or sharing of personal information or of targeted advertising.

3.3 Advertiser will not (a) attempt to re-identify any Data Subject from pseudonymous or hashed identifiers contained in Bid Request Data, or (b) retain Bid Request Data associated with bid requests for which Advertiser does not purchase the impression for longer than reasonably necessary for the Business Purpose.

3.4 Advertiser will maintain a legally compliant privacy policy that accurately describes its processing of Personal Data in connection with interest-based advertising, and will ensure that any service providers or processors it engages in connection with BidSystem are subject to written obligations regarding Personal Data that are no less protective than those set out in this DPA.

3.5 Advertiser certifies that it understands the restrictions in this Section 3 and will comply with them, and will provide at least the same level of privacy protection for Bid Request Data as is required of businesses under applicable U.S. state privacy laws. Advertiser will notify BidSystem if it makes a determination that it can no longer meet its obligations under this DPA or applicable Privacy and Data Protection Requirements, and upon such notice or where BidSystem reasonably believes Advertiser is processing Bid Request Data in an unauthorized manner, BidSystem may take reasonable and appropriate steps to stop and remediate such unauthorized use.

3.6 Advertiser will not use Bid Request Data to identify, infer, or create audience segments based on sensitive or special-category personal data, including data concerning health, sex life or sexual orientation, racial or ethnic origin, religious beliefs, or immigration status, except as expressly permitted by applicable Privacy and Data Protection Requirements with any legally required consent.

3.7 Advertiser will comply with the Children's Online Privacy Protection Act (COPPA) and other applicable children's privacy laws, and will honor any child-directed, age, or similar flags or signals transmitted with or in connection with a bid request.

4. BidSystem's Obligations

4.1 BidSystem will transmit to Advertiser the applicable Consent Signals received from its Supply Partners with or in connection with each bid request, as received by BidSystem.

4.2 BidSystem will process Personal Data received from Advertiser in connection with BidSystem, including campaign parameters, creatives, pixels, and reporting data, for the Business Purpose and in a manner consistent with applicable Privacy and Data Protection Requirements and any applicable Consent Signal.

4.3 Without limiting its rights under the BidSystem Agreement, BidSystem may suspend, filter, or restrict Advertiser's access to bid requests or Bid Request Data where BidSystem reasonably believes that Advertiser's processing of Personal Data violates this DPA or applicable Privacy and Data Protection Requirements, without liability to Advertiser and without limiting BidSystem's other rights and remedies.

5. Security

5.1 Each party shall implement appropriate technical and organizational measures designed to safeguard Personal Data as required by applicable Privacy and Data Protection Requirements. A summary of each party's minimum measures is set out in Annex 2.

5.2 Each party will take reasonable precautions to preserve the integrity of any Personal Data it processes, to the extent required by applicable Privacy and Data Protection Requirements.

6. Security Breaches and Personal Data Loss

6.1 Each party will notify the other of any Security Breach affecting Personal Data received from the other party in connection with BidSystem without undue delay after confirming the Security Breach, and will reasonably cooperate as required under applicable Privacy and Data Protection Requirements.

6.2 Each party's liability arising out of a Security Breach shall be subject to the limitations of liability set forth in the BidSystem Agreement.

7. Cross-Border Transfers of Personal Data

7.1 BidSystem maintains a self-certification under the Data Privacy Framework and relies on the DPF as the primary legal mechanism for transfers of Personal Data from the EEA, UK, and Switzerland to the United States, where applicable and for so long as such self-certification remains active. Where the DPF is not available or applicable for a transfer, the parties shall rely on the applicable Standard Contractual Clauses, the UK Addendum where applicable, or another valid transfer mechanism under applicable Privacy and Data Protection Requirements. Each party may implement supplementary measures as reasonably required.

7.2 Where the SCCs apply to a transfer under this DPA, the SCCs (Module One, controller to controller) are incorporated into this DPA by reference and completed as follows: (a) the party transferring the Personal Data is the data exporter and the party receiving the Personal Data is the data importer; (b) Clause 7 (docking clause) is included; (c) in Clause 11(a), the optional language is not included; (d) in Clause 17, Option 1 applies and the SCCs are governed by the law of Ireland; (e) in Clause 18(b), disputes shall be resolved before the courts of Ireland; (f) Annex I of the SCCs is deemed completed with the information set out in Annex 1 of this DPA; and (g) Annex II of the SCCs is deemed completed with the information set out in Annex 2 of this DPA.

7.3 For transfers subject to the UK GDPR, the UK Addendum is incorporated by reference; its Tables 1 through 3 are deemed completed with the corresponding information in this DPA and its Annexes, and for Table 4, either party may end the UK Addendum as set out in Section 19 thereof. For transfers subject to Swiss law, the SCCs are deemed adapted as required by the Swiss Federal Act on Data Protection, including that the term "member state" shall not be interpreted to exclude Data Subjects in Switzerland from enforcing their rights, and the competent supervisory authority is the Swiss Federal Data Protection and Information Commissioner.

8. Service Providers

8.1 Each party may engage its own processors and service providers in connection with its processing of Personal Data under this DPA, will ensure such processors and service providers are subject to appropriate data protection obligations, and remains responsible for their acts and omissions.

9. Data Subject Requests, Complaints, and Third-Party Rights

9.1 Each party is responsible, at its own cost, for responding to Data Subject requests and consumer complaints it receives relating to its own processing of Personal Data.

9.2 Each party will use commercially reasonable efforts to cooperate with the other party, at the requesting party's expense, in responding to a Data Subject request to the extent required under applicable Privacy and Data Protection Requirements.

10. Term and Termination

10.1 This DPA will remain in full force and effect so long as:

(a) the BidSystem Agreement remains in effect; or

(b) either party retains any Personal Data received from the other party in connection with BidSystem in its possession or control (the "Term").

10.2 Any provision of this DPA that expressly or by implication should come into or continue in force on or after termination of the BidSystem Agreement in order to protect Personal Data will remain in full force and effect.

10.3 A material breach of this DPA shall constitute a material breach of the BidSystem Agreement, subject to any applicable notice and cure rights set forth in the BidSystem Agreement.

11. Data Return and Destruction

11.1 On termination of the BidSystem Agreement for any reason or expiration of its term, each party will retain or delete Personal Data received from the other party in connection with BidSystem in accordance with its standard data retention practices, unless retention is required by law.

11.2 If any law, regulation, or government or regulatory body requires a party to retain any documents or materials that it would otherwise be required to return or destroy, it will notify the other party in writing that a legal retention requirement applies, and will delete the retained Personal Data once that requirement ends.

11.3 Upon a party's written request, the other party will confirm deletion of Personal Data to the extent required by applicable Privacy and Data Protection Requirements.

12. Records

12.1 Each party will maintain records relating to its Processing of Personal Data as required by applicable Privacy and Data Protection Requirements (the "Records").

13. Audit

13.1 Each party will make available information reasonably necessary to demonstrate its compliance with this DPA as required under applicable Privacy and Data Protection Requirements.

14. Warranties

14.1 Advertiser represents and warrants that its processing of Bid Request Data and its use of BidSystem will comply with this DPA and all applicable Privacy and Data Protection Requirements.

14.2 Except as expressly set forth in this DPA, each party disclaims all other warranties to the extent permitted by law.

15. Indemnification

15.1 Each party's liability under this DPA, including any claims arising from a party's breach of this DPA or applicable Privacy and Data Protection Requirements, shall be subject to the limitations of liability set forth in the BidSystem Agreement.

16. Notice

16.1 Any notice or other communication given to a party under or in connection with this DPA must be in writing and delivered (a) to BidSystem at privacy@ezoic.com, and (b) to Advertiser at the business contact address set forth in the BidSystem Agreement or associated with Advertiser's BidSystem account.

16.2 This Section 16 does not apply to the service of any proceedings or other documents in any legal action or, where applicable, any arbitration or other method of dispute resolution.

16.3 Notices may be provided by email where permitted under the BidSystem Agreement.

ANNEX 1 — Description of Processing

This Annex 1 describes the processing of Personal Data by the parties as independent controllers in connection with BidSystem, and is deemed to complete Annex I of the SCCs (Module One) where applicable. The processing described in this Annex 1 is supplemented by, and should be read together with, BidSystem's Privacy Policy.

A. List of Parties. Data exporter: the party transferring the Personal Data (controller). Data importer: the party receiving the Personal Data (controller). BidSystem's contact details: Ezoic Inc., 6023 Innovation Way, Suite 200, Carlsbad, CA 92009, USA; privacy@ezoic.com. Advertiser's contact details: those set forth in the BidSystem Agreement or associated with Advertiser's BidSystem account.

B. Subject matter of processing: the making available of, evaluation of, and bidding on advertising inventory through BidSystem, and related auction operation, ad selection and delivery, measurement and reporting, frequency capping, billing and reconciliation, and fraud detection and prevention.

C. Duration: the Term of this DPA, plus any retention period under Section 11, with retention as further described in BidSystem's Privacy Policy.

D. Nature and purpose of processing: the transmission, receipt, evaluation, use, and storage of Personal Data as necessary for the Business Purpose, as further described in BidSystem's Privacy Policy.

E. Categories of Data Subjects: visitors and end users of Supply Partners' websites, applications, and other properties on which advertising inventory is made available through BidSystem.

F. Categories of Personal Data: Bid Request Data, including online identifiers (such as IP address and cookie, device, or advertising identifiers); device, browser, and operating system information; approximate geolocation derived from IP address; contextual information regarding the page or property; ad interaction data; and associated Consent Signals.

G. Sensitive data: none intended. Neither party intends that sensitive or special-category Personal Data be processed in connection with BidSystem, and neither party will use BidSystem to intentionally collect or derive sensitive or special-category Personal Data.

H. Frequency of transfer: continuous, for the duration of the Term.

I. Competent supervisory authority (SCC Clause 13): the supervisory authority of the EU member state in which the data exporter is established or, where the exporter is not established in the EU, the Irish Data Protection Commission.

ANNEX 2 — Technical and Organizational Measures

Each party maintains a written information security program that includes, at a minimum, the following categories of measures, and is deemed to complete Annex II of the SCCs where applicable: (a) access controls and authentication requirements for systems processing Personal Data; (b) encryption of Personal Data in transit over public networks; (c) network and infrastructure security, including firewalls and monitoring; (d) personnel measures, including confidentiality obligations and security awareness training; (e) service provider and vendor management, including data protection diligence and contractual safeguards; (f) incident detection and response procedures; (g) business continuity and backup procedures; and (h) secure development and change management practices. Additional detail is available upon reasonable written request.