Legal

Data Processing Addendum

Last updated: August 18, 2026

This Data Processing Addendum (“DPA”) forms part of the Terms of Service between Granularity, Inc. (“Granularity”) and the customer (“Customer”) and applies to the processing of personal information in connection with the Services. Where a signed DPA is required for your organization, contact [email protected].

1. Roles of the Parties

With respect to account and website data that Customer directs us to process, Granularity acts as a service provider/processor and processes personal information only to provide the Services and for the limited purposes permitted by applicable law. Customer is the business/controller and is responsible for the lawfulness of the data and for providing required notices and choices to individuals.

2. Scope and Purpose of Processing

We process personal information to recognize website visitors, perform identity resolution and enrichment, and deliver results to Customer, as well as to secure, maintain, and improve the Services. We will not retain, use, or disclose personal information for any purpose other than those permitted under this DPA and applicable law, and will not “sell” Customer personal information or combine it with data from other sources except as permitted by law.

3. Customer Obligations

  • Maintain a compliant privacy notice and any required consents on properties where the Services are deployed.
  • Honor individual rights requests and opt-out signals, including GPC.
  • Not use the Services for FCRA-regulated eligibility decisions or other prohibited purposes described in our Acceptable Use Policy.

4. Subprocessors

Customer authorizes Granularity to engage subprocessors (for example, hosting, data enrichment, and payment providers) to support the Services. We impose data-protection obligations on subprocessors consistent with this DPA and remain responsible for their performance.

5. Security

We maintain reasonable and appropriate administrative, technical, and physical safeguards designed to protect personal information against unauthorized access, use, or disclosure.

6. Data Subject and Consumer Requests

We will provide reasonable assistance to enable Customer to respond to verified individual rights requests. Where we receive a request directly relating to Customer’s data, we may refer the individual to Customer or coordinate a response.

7. Personal Data Breach

We will notify Customer without undue delay after becoming aware of a breach of security leading to the unauthorized disclosure of personal information processed on Customer’s behalf, and will provide information reasonably available to us to assist Customer’s obligations.

8. Return and Deletion

Upon termination, we will delete or de-identify personal information processed on Customer’s behalf within a commercially reasonable period, except where retention is required by law.

9. Contact

Questions about this DPA may be directed to [email protected].