1. Scope, Structure and Relationship to the Agreement
1.1 Incorporation. This Data Processing Addendum (the "DPA") is incorporated into and forms part of the Master Subscription Agreement (the "Master Terms") and any Order between Incenti Solutions, Inc. ("Incenti") and the Customer identified on the Order (together with all Schedules and Addenda, the "Agreement"). Capitalized terms not defined here have the meanings given in the Agreement.
1.2 What this DPA governs. This DPA governs Incenti's Processing of Personal Data contained within Customer Data where Incenti Processes it as a Processor or Service Provider on Customer's behalf. It does not govern:
(a) Personal Data for which Incenti is a Controller in its own right, which is described in the Privacy Policy Part II and summarized at § 3.2 below;
(b) Aggregated Data, which is governed by Master Terms § 13 and by § 16 of this DPA;
(c) Usage Data, which is governed by Master Terms § 13.10 and by § 16.4 of this DPA; or
(d) disclosures to the Integration Partner in its independent-recipient capacity under Master Terms § 5.1.1(c), which are governed by § 8.4 below.
1.3 Order of precedence. In the event of conflict, the order of precedence is: (a) the Standard Contractual Clauses or UK Addendum where activated under § 14; (b) this DPA; (c) the Master Terms and Schedules; (d) the Order. This DPA prevails over the Master Terms as to the subject matter of this DPA only, and Master Terms § 3 governs in all other respects.
1.4 No independent term. This DPA takes effect on the Effective Date and continues for so long as Incenti Processes Personal Data on Customer's behalf. §§ 12, 13, 16, 17 and 18 survive termination.
2. Definitions
2.1 The following terms have the meanings below. Where a Data Protection Law defines an equivalent term, that definition governs for Processing subject to that law.
"Controller" means the entity that determines the purposes and means of Processing, and includes a "business" under the CCPA and equivalent terms under other Data Protection Laws.
"Data Protection Laws" means all laws applicable to the Processing of Personal Data under the Agreement, including the CCPA, the Texas Data Privacy and Security Act (Tex. Bus. & Com. Code ch. 541) ("TDPSA"), the comprehensive consumer privacy statutes of other US states as they come into effect, and, where activated under § 14, the GDPR and UK GDPR.
"Data Subject" means an identified or identifiable natural person, and includes a "consumer" under the CCPA and the TDPSA.
"Personal Data" means information within Customer Data relating to a Data Subject that is protected as personal data, personal information or an equivalent category under Data Protection Laws.
"Processing" means any operation performed on Personal Data, and "Process," "Processes" and "Processed" are construed accordingly.
"Processor" means the entity that Processes Personal Data on behalf of a Controller, and includes a "service provider" and a "processor" under the CCPA and other Data Protection Laws.
"Sensitive Personal Data" means Personal Data within a category treated as sensitive under an applicable Data Protection Law, including the CCPA's "sensitive personal information" and the TDPSA's "sensitive data."
"Standard Contractual Clauses" or "SCCs" means the clauses approved by Commission Implementing Decision (EU) 2021/914.
"UK Addendum" means the International Data Transfer Addendum to the SCCs issued by the UK Information Commissioner under s.119A of the Data Protection Act 2018.
2.2 Terms defined in the Agreement. "Aggregated Data," "Authorized User," "Customer Data," "Integration Partner," "Offering," "Security Incident," "Subprocessor," "Tier 1 Data," "Tier 2 Data," "Tier 3 Data" and "Usage Data" have the meanings given in the Agreement, including Schedule D.
3. Roles of the Parties
3.1 General. For Personal Data within Customer Data, Customer is the Controller and Incenti is the Processor, except as stated in § 3.2.
3.2 Role map. The parties' roles for each Processing activity are as follows.
| Processing activity | Incenti's role | Governing provisions | |
|---|---|---|---|
| (a) | Incenti EDOS Customer Data — forms, Submissions, projects, pipelines, Program Data, property records, CRM records, compliance records, historical archives | Processor / Service Provider | This DPA; Master Terms § 5; Schedule A § A.12 |
| (b) | Cross-product movement between Incenti EDOS and Incenti Insights for the Customer whose data it is | Processor / Service Provider, on the instruction at § 4.3 | This DPA § 4.3; Master Terms § 5.1.1(a) |
| (c) | Integration Partner as Subprocessor — proposal generation and form data handling performed on Incenti's instructions | Processor; partner is Subprocessor | This DPA § 8; Master Terms §§ 5.1.1(b), 10 |
| (d) | Incenti Insights reference data — federal, state, commercial and Incenti-proprietary datasets; the State Benchmark | Controller | Privacy Policy Part II; Schedule B §§ B.3, B.15 |
| (e) | Website visitors, prospects, marketing contacts, newsletter subscribers, account administrators | Controller | Privacy Policy Part II §§ 5–10 |
| (f) | Consulting and professional services engagements under Schedule C | Processor / Service Provider for Client-Furnished Materials and Deliverables; Controller of Incenti's own engagement working papers | Schedule C §§ C.6, C.14.3; Privacy Policy § 14A |
| (g) | Aggregated Data and Usage Data | Controller, once outside scope under § 16 | Master Terms § 13; this DPA § 16 |
| (h) | Incenti's own business records — billing, account administration, security logging, legal compliance | Controller | Privacy Policy Part II |
| (i) | Incenti Contacts — professional contact entries submitted directly to Incenti by the individuals they describe | Controller | Privacy Policy § 7; Schedule A § A.20 |
3.3 Customer's responsibilities as Controller. Customer represents that it has provided all notices and obtained all consents, permissions and lawful bases necessary for Incenti to Process Personal Data as contemplated by the Agreement, consistent with Master Terms § 5.4. Customer is responsible for the accuracy, quality and legality of Personal Data it submits and for its instructions to Incenti.
3.4 Individuals whose data a Customer submits. Much of the Personal Data in Incenti EDOS relates to individuals who are not Authorized Users — contacts at companies, agency staff, consultants, and individuals named in Submissions, RFIs and compliance records. Incenti has no direct relationship with those individuals and will not contact them except at Customer's instruction or as required by law. Requests received directly are handled under § 11.2.
3.5 Independent Controllers. Where Incenti and Customer each act as Controller for the same Personal Data, each is independently responsible for its own compliance. Nothing in the Agreement creates a joint controllership within the meaning of GDPR Art. 26, and the parties do not intend one.
3.6 No change of role by conduct. Neither party's role changes by reason of a course of dealing, a support interaction, a professional-services engagement or an integration Customer enables. A change of role requires an amendment to this § 3.
4. Customer Instructions
4.1 Documented instructions. Incenti will Process Personal Data only on Customer's documented instructions, which consist of: (a) the Agreement, including this DPA; (b) Customer's configuration and use of the Offerings through their features and controls; (c) any Statement of Work under Schedule C; and (d) any further written instruction the parties agree.
4.2 Instructions Incenti will not follow. Incenti will notify Customer if, in its opinion, an instruction infringes a Data Protection Law, and may suspend performance of that instruction until it is withdrawn, amended or confirmed. Incenti is not obliged to provide legal advice and a decision not to notify is not an assurance of legality.
4.3 Express instruction — cross-product processing. Customer instructs Incenti to move Personal Data within Customer Data between Incenti's Offerings — from Incenti EDOS to Incenti Insights and from Incenti Insights to Incenti EDOS — solely to deliver project-management and site-selection functionality to Customer, and solely with respect to Customer's own Customer Data, as described in Master Terms § 5.1.1(a) and licensed at Master Terms § 5.2(e).
This instruction does not extend to, and Incenti will not rely on it for:
(a) any use for Incenti's own purposes, including product improvement, model development, model training, research or benchmarking;
(b) any Processing that makes one customer's Personal Data visible or available to another customer; or
(c) any Processing of Personal Data belonging to a customer that is not a party to the Order under which the instruction is given.
Processing described in (a) is governed exclusively by Master Terms §§ 13 and 13.10 and by § 16 of this DPA, and is permitted only where the data has left the scope of this DPA under § 16.1.
4.4 Instruction to disclose to the Integration Partner as Subprocessor. Customer instructs Incenti to disclose Tier 1 Data and Tier 2 Data to the Integration Partner acting as a Subprocessor, for proposal generation and form data handling, as described in Master Terms § 5.1.1(b) and subject to § 8. No Tier 3 Data is disclosed under this instruction.
4.5 Instructions given through the Offerings. Where Customer enables an integration, connects a third-party service, authorizes a link under Master Terms § 5.1.2, or enables property sharing under Schedule A § A.6, that act is Customer's instruction for the resulting Processing. Incenti records the act, the Authorized User and the date.
5. Incenti's Processing Obligations
5.1 Purpose limitation. Incenti will Process Personal Data only for the purposes set out in Annex 1 and will not Process it for any other purpose.
5.2 No own-purpose use. Incenti will not retain, use or disclose Personal Data for any purpose other than performing the Offerings and the services specified in the Agreement, including any commercial purpose of its own, except as permitted by § 16 once data has left the scope of this DPA.
5.3 Confidentiality of personnel. Incenti will ensure that personnel authorized to Process Personal Data are bound by written confidentiality obligations, are subject to the personnel measures at Master Terms § 9.4, and access Personal Data only on a need-to-know basis.
5.4 Data minimization in support. Incenti will limit support and administrative access to Personal Data to what is necessary to perform the task, and will log such access consistent with the Security Annex.
5.5 No sale of Personal Data. Incenti will not sell or share Personal Data, as those terms are defined by the CCPA and the TDPSA, and will not use Personal Data for cross-context behavioural advertising or targeted advertising.
6. CCPA / CPRA Service Provider Terms
6.1 Status. With respect to Personal Data Incenti Processes on Customer's behalf, Incenti is a "service provider" as defined in Cal. Civ. Code § 1798.140(ag) and Customer is a "business" or, where Customer is itself a service provider or contractor, Incenti is a subcontractor.
6.2 Required terms. Incenti:
(a) will not sell or share Personal Data;
(b) will not retain, use or disclose Personal Data for any purpose other than the business purposes specified in the Agreement and Annex 1, including outside the direct business relationship between the parties, except as permitted by the CCPA;
(c) will not retain, use or disclose Personal Data outside the direct business relationship;
(d) will not combine Personal Data received from or on behalf of Customer with personal information it receives from or on behalf of another person, or collects from its own interaction with a Data Subject, except as expressly permitted by Cal. Civ. Code § 1798.140(ag)(1)(D) and the implementing regulations;
(e) certifies that it understands the restrictions in (a) through (d) and will comply with them;
(f) will comply with the obligations applicable to service providers under the CCPA and provide the same level of privacy protection the CCPA requires;
(g) will notify Customer without undue delay if it determines it can no longer meet its obligations under the CCPA; and
(h) grants Customer the right to take reasonable and appropriate steps under § 13 to stop and remediate unauthorized use of Personal Data.
6.3 No B2B exemption. The parties acknowledge that the CCPA's business-to-business and employee exemptions expired on 1 January 2023, and that a California resident's business contact information, title and employer are Personal Data of a "consumer" under the CCPA. Incenti's obligations under this § 6 apply to such information.
6.4 Deidentified data. Where Incenti creates deidentified data, § 16 applies.
7. Other US State Privacy Laws
7.1 Texas (TDPSA). With respect to Processing subject to Tex. Bus. & Com. Code ch. 541, and consistent with § 541.104, this DPA sets out: the nature and purpose of Processing (Annex 1); the type of data Processed (Annex 1); the duration of Processing (§ 1.4); and the rights and obligations of both parties. Incenti will:
(a) adhere to Customer's instructions and assist Customer in meeting its obligations under ch. 541;
(b) ensure each person Processing Personal Data is subject to a duty of confidentiality;
(c) delete or return Personal Data at Customer's direction on termination, as provided in § 12;
(d) make available to Customer, on reasonable request, information sufficient to demonstrate compliance;
(e) permit and cooperate with reasonable assessments by Customer or its designated assessor, or arrange for an independent assessment, as provided in § 13; and
(f) engage Subprocessors only under a written contract imposing the same obligations, as provided in § 8.
7.2 Other states. Incenti will comply with the processor obligations of every other state comprehensive privacy law applicable to the Processing, including those of Virginia, Colorado, Connecticut, Utah, Oregon, Montana, Delaware, Iowa, Nebraska, New Hampshire, New Jersey, Minnesota, Tennessee, Maryland, Indiana, Kentucky and Rhode Island, and of any state statute that comes into effect during the term. Where a state law imposes an obligation more protective than this DPA, that obligation applies.
7.3 Sensitive Personal Data. Where Customer submits Sensitive Personal Data, Customer is responsible for obtaining any consent required under the applicable statute, including the TDPSA's consent requirement and the equivalent requirements in other states. Incenti does not require Sensitive Personal Data to deliver the Offerings, and Master Terms § 25 (Compliance and Restricted Data) governs categories Customer must not submit.
8. Subprocessors
8.1 General authorization. Customer grants Incenti general authorization to engage Subprocessors, subject to this § 8. The current Subprocessor List at https://incenti.co/legal/subprocessors identifies each Subprocessor, the Processing it performs, and the country of Processing, and identifies each Integration Partner by name.
8.2 Flow-down and liability. Incenti will impose on each Subprocessor, by written contract, data protection and security obligations no less protective than those in this DPA, and remains liable for the acts and omissions of its Subprocessors to the same extent as for its own (Master Terms § 10.2).
8.3 Notice and objection. Incenti will give Customer at least thirty (30) days' advance notice before adding or replacing a Subprocessor, by email to the administrator contact and by updating the Subprocessor List. Customer may object on reasonable data protection or security grounds within that period; if the parties cannot resolve the objection in good faith, Customer may terminate the affected Offering without penalty and receive a pro-rata refund of prepaid, unused fees (Master Terms § 10.3).
8.4 The Integration Partner's two capacities. The Integration Partner acts in two distinct capacities and only the first is within this DPA:
(a) As a Subprocessor (Master Terms § 5.1.1(b)), performing proposal generation and form data handling on Incenti's documented instructions, receiving Tier 1 and Tier 2 Data only, bound by the flow-downs at § 8.2, and permitted to use the data for no purpose of its own. This is a service-provider relationship under the CCPA and is within this DPA.
(b) As an independent recipient (Master Terms § 5.1.1(c)), receiving Tier 1 Data only, on Customer's authorization under Master Terms §§ 5.1.2 and A.6 and on no other basis, and using it for its own purposes under its own terms with Customer. This is a genuine disclosure to a third party. It is not Processing by a Subprocessor, Incenti does not instruct it, and this DPA does not govern it. Schedule A § A.9.3 applies: Incenti cannot compel deletion of copies the partner has already distributed or cached.
Incenti will maintain technical separation between the two data paths, so that Personal Data disclosed under (a) cannot be retained or reused by the Integration Partner under (b).
8.5 AI Subprocessors. Subprocessors providing AI model hosting or inference are separately identified on the Subprocessor List with (a) whether inputs and outputs are retained, (b) the retention window, and (c) confirmation of the no-training commitment (Master Terms § 10.4). § 15 governs.
9. Security
9.1 Measures. Incenti will implement and maintain the technical and organizational measures described in the Security Annex made available to Customer under the Agreement, incorporated by reference and summarized at Annex 2, and will not amend the Security Annex during a Subscription Term in a manner that materially reduces the protections afforded to Personal Data (Master Terms § 9.1).
9.2 Appropriateness. The measures are appropriate to the risk, taking into account the state of the art, the costs of implementation, and the nature, scope, context and purposes of Processing, including the presence of Tier 3 Data under Schedule D.
9.3 Encryption. Personal Data is encrypted in transit and at rest to the standard stated at Master Terms § 9.5.
9.4 Evidence. § 13 governs Customer's right to evidence of compliance.
10. Security Incidents
10.1 Notification. Incenti will notify Customer without undue delay and in any event within forty-eight (48) hours after Incenti confirms a Security Incident affecting Personal Data (Master Terms § 11.1).
10.2 Content and phasing. The initial notice will contain the information then reasonably available, including the nature of the incident, the categories and approximate number of Data Subjects and records concerned to the extent known, the likely consequences, the measures taken or proposed, and a point of contact. Incenti may provide information in phases and the initial notice is not an acknowledgment of fault (Master Terms § 11.2).
10.3 Customer owns the notification decision. Customer is responsible for determining whether notification to Data Subjects, regulators or any other party is required, and for making it. Incenti will not notify any Data Subject, regulator or third party regarding a Security Incident affecting Customer Data without Customer's prior written consent, except as required by law or by a certification or authorization program to which Incenti is subject (Master Terms § 11.3).
10.4 Cooperation and preservation. Incenti will reasonably cooperate with Customer's investigation and notification obligations and will take such actions as necessary to preserve forensic evidence (Master Terms § 11.4).
10.5 No root-cause exclusion. Incenti's obligations under this § 10 apply regardless of the root cause, including where the incident originated from a compromised Authorized User credential. Liability remains subject to Master Terms §§ 22 and 4.4 (Master Terms § 11.5).
10.6 Cross-tenant transmissions. A transmission in breach of the cross-tenant rule at Master Terms § 5.1.2 is a Security Incident for the purposes of this § 10.
10.7 Costs. Each party bears its own costs of investigation and notification, except that Incenti will bear the reasonable, documented cost of notification to Data Subjects where the Security Incident resulted from Incenti's breach of Master Terms § 9, subject to Master Terms § 22.4.
11. Assistance to Customer
11.1 Data Subject rights. Taking into account the nature of the Processing, Incenti will assist Customer by appropriate technical and organizational measures, insofar as possible, to fulfill Customer's obligation to respond to Data Subject requests, including requests to access, correct, delete, obtain a portable copy of, limit the use of, or opt out of certain Processing of Personal Data. The Offerings provide self-service tools for access, correction, export and deletion, and Customer's use of those tools is the primary mechanism.
11.2 Requests received directly. If Incenti receives a request from a Data Subject relating to Personal Data Incenti Processes on Customer's behalf, Incenti will not respond substantively except to acknowledge receipt and direct the Data Subject to Customer, and will forward the request to Customer without undue delay, unless applicable law requires otherwise.
11.3 Other assistance. Incenti will provide reasonable assistance to Customer with data protection impact assessments, prior consultations with supervisory authorities, and security-related obligations, in each case taking into account the nature of the Processing and the information available to Incenti.
11.4 Automated decision-making. Where Customer enables AI Grading or another AI Feature, Incenti will provide the transparency records described at Schedule A § A.14.6 to support Customer's obligations regarding automated decision-making, profiling and adverse-action explanation, including under the TDPSA, Colorado SB 26-189, the California ADMT regulations and, where applicable, GDPR Art. 22.
11.5 Limits. Incenti may charge a reasonable fee for assistance that is materially disproportionate to the ordinary course, on prior written notice and Customer's approval. Incenti will not charge for assistance arising from a Security Incident caused by Incenti's breach of Master Terms § 9.
12. Return and Deletion
12.1 During the term. Customer may export Personal Data at any time using the Offerings' export tools, in the formats described at Schedule A § A.16.4.
12.2 On termination. On expiry or termination, Incenti will, at Customer's election, return or delete Personal Data as provided at Master Terms §§ 19.4 and 19.5. Where the Offerings do not provide an export tool for a given module, Customer may request a full export by written notice to legal@incenti.co, and Incenti will comply within thirty (30) days of the request, provided the request is made within the sixty (60)-day Export Window at Master Terms § 19.4.
12.3 Backups. Personal Data in backups is deleted on the ordinary backup expiry cycle described at Master Terms § 19.5, within ninety (90) days of deletion from production, and remains subject to §§ 5, 9 and 10 until deleted.
12.4 Retained data. Incenti may retain Personal Data to the extent required by applicable law, and may retain Aggregated Data and Usage Data in accordance with § 16, which are not Personal Data and are not subject to this § 12.
12.5 Data not subject to export. Consistent with Master Terms § 19.4, Incenti's proprietary incentives database and other reference data that did not originate from Customer are not Customer Data and are not exportable. This § 12 does not apply to them.
12.6 Consulting working papers. Incenti retains engagement working papers for seven (7) years after completion, as Controller of its own engagement records (§ 3.2(f); Schedule C § C.14.3), to evidence and defend its work. Working papers are outside the return and deletion obligations of this § 12. Client-Furnished Materials are returned or deleted under § 12.2, except to the extent they are incorporated in retained working papers, which remain subject to §§ 5 and 9 for the retention period.
13. Audits and Information Rights
13.1 Information. On Customer's written request, not more than once per year and additionally following a Security Incident affecting Customer's Personal Data, Incenti will provide information sufficient to demonstrate compliance with this DPA, including its then-current audit reports (if any), penetration test summary, and a completed security questionnaire (Master Terms § 9.7).
13.2 Assessments. Where a Data Protection Law entitles Customer to conduct or mandate an assessment, Incenti will permit and contribute to it. The parties will agree scope, timing and duration in advance. An assessment will be conducted during business hours, subject to confidentiality obligations, and in a manner that does not disrupt the Offerings or compromise the confidentiality of other customers' data.
13.3 Third-party reports first. Customer will accept Incenti's then-current third-party audit reports and completed questionnaires in satisfaction of § 13.2 where they reasonably address the subject matter of the proposed assessment.
13.4 On-site audits. An on-site audit may be conducted once per twelve-month period, on thirty (30) days' prior written notice, at Customer's cost, save where the audit reveals material non-compliance, in which case Incenti bears the reasonable cost.
13.5 Public sector. Where a Data Protection Law, a State Rider or a Customer's own statutory audit authority requires broader access, that requirement governs and this § 13 does not limit it.
14. International Transfers
14.1 Current position. As at the Effective Date, Incenti Processes Personal Data in the United States and does not offer the Offerings in the European Economic Area, the United Kingdom or Switzerland. §§ 14.2 to 14.4 take effect only if and when activated under § 14.5.
14.2 Standard Contractual Clauses. Where the GDPR applies and Personal Data is transferred from the EEA to Incenti, the SCCs are incorporated, with Module Two (controller to processor) applying where Customer is a controller and Module Three (processor to processor) where Customer is itself a processor. The parties agree: docking clause applies; Clause 9 Option 2 (general written authorization) with the notice period at § 8.3; Clause 11 optional redress clause does not apply; Clause 17 governed by the law of Ireland; Clause 18(b) forum Ireland; Annex I, II and III are Annexes 1, 2 and 3 of this DPA.
14.3 UK. Where the UK GDPR applies, the UK Addendum is incorporated, with Table 1 completed from Annex 1, Tables 2 and 3 from § 14.2 and the Annexes, and Table 4 specifying that neither party may end the Addendum as set out in Section 19.
14.4 Switzerland. Where Swiss law applies, references in the SCCs are read as references to the Swiss FADP, the competent authority is the FDPIC, and the clauses protect data of legal entities until the FADP is amended.
14.5 Activation. §§ 14.2 to 14.4 take effect on the earlier of (a) an Order stating that the Offerings are provided to Customer in the EEA, the UK or Switzerland, and (b) written notice from either party that a transfer subject to those laws has commenced. No amendment to this DPA is required.
14.6 Transfer impact. On request, Incenti will provide information reasonably necessary for Customer to complete a transfer impact assessment, including the information at Annex 1 and any government access requests received, to the extent disclosure is lawful.
15. Artificial Intelligence Processing
15.1 No training on Personal Data. Incenti does not use Personal Data within Customer Data to train, fine-tune or otherwise develop machine-learning models, and does not permit its AI Subprocessors to do so (Master Terms § 12.2).
15.2 Cross-tenant isolation. Personal Data submitted to an AI Feature by one customer is not used to generate output for another customer and does not enter a shared index, embedding store or model.
15.3 Scope of the AI Assistant. The Incenti EDOS AI Assistant reads and analyzes Customer Data within the requesting Customer's own account — and only that account — to produce summaries, trends and other analysis, and does not retrieve external content (Schedule A § A.15).
15.4 AI Subprocessor retention. Retention windows for each AI Subprocessor are published on the Subprocessor List (Master Terms § 10.4). Incenti does not represent that any AI Subprocessor operates on a zero-retention basis except where the Subprocessor List states so for that Subprocessor.
15.5 AI Features are opt-in. AI Grading is off by default and Processes Personal Data only where Customer enables it for a form (Schedule A § A.14). Customer's act of enabling is its instruction under § 4.5.
15.6 Design intent. The AI Features are not designed to make automated decisions about individuals. They are designed to assist Customer's personnel, and Master Terms § 12.6 requires human review.
16. Aggregated, De-Identified and Usage Data
16.1 Exit from scope. Where Personal Data is transformed into Aggregated Data meeting the de-identification standard at Master Terms § 13.1, the aggregation floor at Master Terms § 13.2 and the Tier 3 exclusion at Master Terms § 13.3, it ceases to be Personal Data and ceases to be governed by this DPA, consistent with Master Terms § 13.9.
16.2 Obligations that survive the exit. § 16.1 does not release Incenti from the obligations that attach to deidentified data as such. Incenti will:
(a) take reasonable measures to ensure the data cannot be associated with a Data Subject, household or device;
(b) publicly commit to maintain and use the data in deidentified form and not to attempt to reidentify it, as required by Cal. Civ. Code § 1798.140(m) and mirrored at Master Terms § 13.6 and Privacy Policy § 11.4;
(c) contractually obligate any recipient to comply with (a) and (b); and
(d) not attempt to reidentify the data except to test the effectiveness of its own deidentification, and then only under controls.
16.3 Opt-out. Customer may exercise the aggregated-data opt-out at Master Terms § 13.5, including by email to legal@incenti.co. On exercise, Incenti ceases to include Customer's Customer Data in newly created Aggregated Data. The opt-out does not require Incenti to withdraw or recompute Aggregated Data already created.
16.4 Usage Data. Usage Data as defined in Master Terms § 2 excludes the substantive content of Customer Data and is governed by Master Terms § 13.10. To the extent Usage Data contains Personal Data, this DPA applies to it.
16.5 Current position on Insights. As at the Effective Date, Incenti Insights is compiled from federal, state, commercial and Incenti-proprietary reference data, and the State Benchmark is compiled exclusively from publicly available information (Schedule B § B.15). Customer Data is not a source for Insights except to the extent § 16.1 permits and Customer has not opted out under § 16.3.
17. Public Sector Customers and Records Law
17.1 Records requests. Where Customer is subject to a public records, open records or freedom of information statute, Customer is the custodian of its records and is responsible for responding to requests. Incenti will provide reasonable assistance, including export under § 12.1, at Customer's cost where the request is materially disproportionate.
17.2 Requests received by Incenti. If Incenti receives a records request, subpoena or other legal demand for Customer Data, Incenti will notify Customer without undue delay unless legally prohibited, will provide Customer a reasonable opportunity to seek protective relief, and will disclose only what is legally required.
17.3 Public Data. Personal Data that is Public Data as defined in Master Terms § 2 is excluded from Confidential Information by Master Terms § 7.3(c). That exclusion does not remove it from this DPA, and Incenti's obligations under §§ 5, 9, 10 and 12 continue to apply to it.
17.4 Constructive custody. The parties acknowledge that records held by Incenti may fall within Customer's constructive custody under applicable records law, and that Master Terms § 8 and Addendum 1 govern.
18. Liability, Precedence, Term and General
18.1 Liability. Each party's liability under this DPA is subject to the limitations and exclusions in Master Terms § 22, including the security super-cap at § 22.4. Nothing in this DPA limits liability that cannot lawfully be limited, including under the SCCs where activated.
18.2 Changes to this DPA. Incenti may amend this DPA on thirty (30) days' notice where required by a change in Data Protection Laws or to reflect a change in the Offerings, provided the amendment does not materially reduce the protections afforded to Personal Data. Any other amendment requires the parties' written agreement.
18.3 Severability. If a provision is held invalid, the remainder continues in effect and the parties will substitute a valid provision achieving the same commercial and legal purpose.
18.4 Governing law. This DPA is governed by the law stated at Master Terms § 24, except where a Data Protection Law or the SCCs require otherwise.
18.5 Signature. Where a signed DPA is required, execution of an Order incorporating this DPA constitutes execution of this DPA.
ANNEX 1 — DESCRIPTION OF PROCESSING
This Annex is required by GDPR Art. 28(3) and Tex. Bus. & Com. Code § 541.104. It is completed at the level of the Offerings; an Order may narrow it but may not broaden it.
A. Parties. Data exporter: Customer, as identified on the Order. Data importer: Incenti Solutions, Inc., a Delaware corporation, notice address as stated at Master Terms § 27.1.
B. Subject matter. Provision of the Offerings identified on the Order — Incenti EDOS, Incenti Insights, and any professional services under Schedule C.
C. Duration. The Subscription Term, plus the export and deletion periods at § 12.
D. Nature and purpose of Processing. Hosting, storage, transmission, indexing, display, reformatting, backup, access management, support, security monitoring, and — where enabled by Customer — AI-assisted grading and analysis, in each case to deliver the Offerings to Customer. Cross-product movement between Incenti EDOS and Incenti Insights under § 4.3.
E. Categories of Data Subjects.
- Authorized Users and account administrators
- Customer's staff and contractors
- Contacts at companies, prospects and projects recorded in CRM and project records
- Staff of partner agencies, consultants and site selectors
- Individuals named or depicted in Submissions, RFIs, responses, compliance records and property records
- Individuals named in historical archives migrated by Customer
F. Categories of Personal Data.
- Identifiers: name, title, employer, business contact details, account identifiers
- Professional information: role, organization, areas of interest, properties of interest
- Communications and content: form responses, correspondence, notes, documents, images, video, audio and other media submitted through the Offerings
- Compliance and program records: information relating to incentive applications, awards and compliance, to the extent it identifies an individual
- Technical data: log data, IP address, device and access records
- Any other Personal Data Customer elects to submit, which Customer controls through its form and field configuration under Schedule D § D.6B
G. Sensitive Personal Data. Not required by the Offerings. Master Terms § 25 identifies categories Customer must not submit. Where Customer submits Sensitive Personal Data notwithstanding, § 7.3 applies and the measures at Annex 2 apply.
H. Frequency. Continuous.
I. Retention. As stated at § 12 and Master Terms § 19.
J. Subprocessors. As stated at Annex 3.
ANNEX 2 — TECHNICAL AND ORGANIZATIONAL MEASURES
The measures are set out in the Security Annex made available to Customer under the Agreement, incorporated by reference under § 9.1. The Security Annex describes:
| Area | Content required |
|---|---|
| Access control | Passwordless authentication (magic link) and SSO, role-based access, staff access limitation and logging, prompt revocation on departure |
| Encryption | In transit and at rest, per Master Terms § 9.5, across all stores including backups, logs, indices and object storage |
| Tenant separation | The control relied on by Master Terms § 4.1 and § 15.2 |
| Logging and monitoring | Security-event logging and its retention period, error and uptime monitoring |
| Vulnerability management | Scanning cadence, patching SLAs, penetration testing frequency |
| Backup and recovery | RPO and RTO figures, backup encryption, restoration testing, expiry cycle per Master Terms § 19.5 |
| Business continuity | Continuity and disaster recovery arrangements |
| Personnel | Background checks, confidentiality agreements, security training, per Master Terms § 9.4 |
| Endpoint security | Controls on the devices of Incenti's distributed personnel (disk encryption, screen lock, remote wipe); Incenti operates no office and relies on its hosting providers' physical data-center controls |
| Subprocessor management | Diligence, contracting, monitoring |
| Incident response | Detection, triage, the 48-hour clock at § 10.1, forensic preservation |
| Certifications | Stated accurately, including where the answer is that Incenti holds none, per Master Terms § 9.3 |
ANNEX 3 — SUBPROCESSORS
The current list is published at https://incenti.co/legal/subprocessors and is incorporated by reference under § 8.1. It states, for each Subprocessor: legal entity name, the Processing performed, the categories of Personal Data, and the country of Processing. Integration Partners are identified by name. AI Subprocessors are separately identified with retention windows and no-training confirmation under § 8.5 and Master Terms § 10.4.
The Integration Partner is listed in each of its capacities under § 8.4, with the two listings distinguished on their face.
ANNEX 4 — TRANSFER MECHANISMS
Reserved. Activated under § 14.5. On activation, this Annex incorporates the SCCs with the elections at § 14.2, the UK Addendum with the elections at § 14.3, and the Swiss adaptations at § 14.4, with Annexes I, II and III of the SCCs completed by Annexes 1, 2 and 3 of this DPA.