Approval: Kfir Pravda Approval Date: 2025-09-25 Protocol Type: Public-Unlisted Document Status: Reviewed
25/04/2020 (Benny Akler)
As a responsible, forward-looking business, Pravda Media Group recognizes at senior levels the need to comply with the provisions of the Regulation (EU) 2016/679 of the European Parliament (General Data Protection Regulation – "GDPR") and ensure that effective measures are in place to protect the Personal Data of our customers.
This Data Processing Addendum (“DPA”) forms part of the Framework Agreement or other written or electronic agreement between Pravda Media Group ("PMG" or "Us" or "Our") and you, the customer ("You" or the "Customer"), for the purchase of paid media campaign services from PMG (identified either as “Services” or otherwise in the applicable agreement, and hereinafter defined as “Services”) (the "Contract").
This DPA reflect our obligations with regard to the processing of "Personal Data" - any information relating to, directly or indirectly, an identified or identifiable natural person, collected and/or stored or processed by us on behalf of you. This DPA does not address or limit the processing of aggregated anonymous data that can no longer be identified or associated with a particular natural person ("Anonymized Data"). We may use and process Anonymize Data , under our sole discretion, for our statistical needs and/or in order to improve our systems and services, even if such Anonymized Data was produced using Personal Data (e.g. aggregative data which was derived from raw Personal Data).
We will maintain administrative, physical, and technical safeguards for the protection of the security, confidentiality, availability, and integrity of Personal Data in accordance with applicable law and industry standards. Those safeguards will include, but will not be limited to: security-related policies and procedures, standards and practices designated for the protection of Personal Data and for preventing access, use, modification or disclosure of Personal Data by our personnel except (a) to provide the Services and prevent or address service or technical problems, (b) as compelled by law and subject to any exclusions and condition hereunder, or (c) as You expressly permit in writing.
For the performance of our obligations under the Contract and for the provision of the Services as requested and instructed by you, we process Personal Data. Part of the Personal Data is being provided to us by you and some of it is being obtained directly from users, website visitors, Your clients or potential clients, etc. We keep that Personal Data in Our systems, analyze it and process it by various tools including third party tools, in order to provide you with the Services. The Personal Data will be kept in our systems until the end of the provision of the Services, as detailed hereunder.
In accordance with Article 28 of the GDPR, we undertake to:
6.1. process the Personal Data only on documented instructions from you;
6.2. not use the Personal Data for any purpose other than the strict performance of the Contract and the provision of the Services as requested by you. Notwithstanding the preceding, we shall be entitled to use the Personal Data for statistical and financial purposes, provided however that any personal attributes shall be removed from the Personal Data, or otherwise if such is maintained under aggregate basis;
6.3. ensure that Our personnel who authorized to process the Personal Data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality;
6.4. Take commercially reasonable steps to ensure that (i) persons employed by Us and (ii) other persons engaged to perform on PMG's behalf, comply with the terms of this DPA;
6.5. take all measures required pursuant to Article 32 of the GDPR, namely to implement appropriate technical and organizational measures to ensure a level of security appropriate to the risk to the rights and freedoms of natural persons;
6.6. respect the conditions referred to in paragraphs 2 and 4 of Article 28 of the GDPR for engaging another Processor, namely that we may not engage another Processor (Sub-Processor) without your prior authorization. At the date of this agreement, you acknowledge and agree that for the provision of the Services, we may use the following external services:
Background
This document serves as the official registry of software applications, vendor solutions, and technology packages that have been evaluated, vetted, and approved for use within PMG.. Employees and departments must reference this approved list before procuring, installing, or implementing any software solutions. The use of non-approved software without proper authorization through the established review process is strictly prohibited and may result in security vulnerabilities, compliance violations, and potential disciplinary action. This document is maintained by the CTO and CEO of PMG.
Web & Edge device Software
Software On-Device/Web Description Notes Google Workspace
https://workspace.google.comWeb Based Identity Platform and SSO authentication, Gmail - Custom business email, Drive - secured cloud storage, "Meet" - Video conferencing, Calendar - Shared calendars, Gemini - AI assistant, Docs - Word processing, Sheets - Spreadsheets, Slides - Presentation builder, NotebookLM - AI research assistant Google NotebookLM Privacy Information
Google Workspace Terms of Service
How Gemini for Google Cloud uses your data1Password
https://1password.comOn-Device & Web Based PMG approved password manager 1password Security Notes: https://support.1password.com/1password-security/
1Password Trust Center:
https://app.conveyor.com/profile/1password
1Password SOC certification: https://1password.com/soc/Teamwork
https://www.teamwork.comWeb Based PMG approved project management system and secure platform for hosting client-sent database. Teamwork Trust Center:
https://www.teamwork.com/security/Notion
https://www.notion.soWeb Based PMG approved project management system Notion Trust Center:
https://www.notion.com/security
Notion AI terms:
https://notion.notion.site/Notion-AI-Supplementary-Terms-fa9034c8b5a04818a6baf3eac2adddbbHubSpot
https://hubspot.comWeb Based CRM and Marketing Automation software used to manage PMG internal database, outreach programs and ad management. HubSpot Trust Center:
https://legal.hubspot.com/securityOpenAI (Chatgpt.com)
https://chatgpt.comWeb Based AI assistance used for development and content summarization. Setting set not to train models. OpenAI Enterprise Privacy Anthropic (Claude.ai website)
https://claude.aiWeb Based AI assistance used for development and content summarization. Setting set not to train models. Anthropic Trust Center
How Anthropic Uses Personal Data in Model TrainingGemini Web Interface
https://gemini.google.comWeb Based AI assistance used for development and content summarization. Does not train models, included as part of Google Workspace. How Gemini for Google Cloud uses your data
https://facebook.comWeb Based Social & Ad network Not used for: any client data, any PII information
https://linkedin.comWeb Based Social & Ad network, prospect acquisition tool (LinkedIn Sales Navigator) Not used for: any client data, any PII information X (formerly Twitter)
https://twitter.comWeb Based Social & Ad network Not used for: any client data, any PII information YouTube
https://youtube.comWeb Based Social & Ad network Not used for: any client data, any PII information Google Ads Web Based Ad network Not used for: any client data, any PII information Google Analytics & Google Tag Manager Web Based Analytics and Website Automations Not used for: any client data, any PII information The following document describes how PMG uses AI and LLM assisted tools in a responsible, safe manner:
Operating Systems
Device Type Operation System Minimum Requirements Last Reviewed Mobile Android Android 13 with Latest vendor updates September 2025 Mobile iOS Any currently supported, latest updated iOS version - iPhones 11 and upward suppors the latest updated version until 2026. September 2025 Desktop Class (Laptops, Mini-PCs, Desktop or AIO computers) Windows 11 Professional, macOS Tahoe (version 26), Ubuntu 24 or upward, PopOS (Ubuntu variant) 22.04 LTS or upward. Latest supported update of either operation systems is a requirement for ongoing use. Devices must support the latest updated Windows or macOS version, or in case of Ubuntu/PopOS - the latest LTS version. September 2025 Development Server (Virtual PC) Ubuntu LTS Ubuntu 24.04.3 LTS or upward September 2025 Development Tools
Software On-Device/Web Description Notes Microsoft VScode
https://code.visualstudio.comOn-Device Development IDE platform Python
https://www.python.orgOn-Device Python programming language and tools from official Python repository - https://www.python.org Python Packages:
requests
httpx
json
csv
time
flask
pandas (data analysis library - https://pandas.pydata.org)
RapidFuzz (fuzzy matching library - https://pypi.org/project/RapidFuzz/)
simstring-pure (fuzzy matching library for fast, less accurate calculations - https://pypi.org/project/simstring-pure/0.0.1/)
For LLM Enabled Projects:
OpenAI
Anthropic
google-genai
For Offline LLM/Machine Learning projects:
tensorflow
scikit-learn
numpy
transformers
torch
Pillow
opencv-python
Ollama is used for local running LLMs.On-Device These python packages supports verious PMG built software for Database cleanup, data review, data import etc. These python packages are commonly used within PMG. Packages not mentioned in this list are examined per-project, according to project requirements.
In all cases where a Sub-Processor is engaged, the Sub-Processor must be subject to the same contractual terms as described in this DPA.[1] [M2]
6.7. in any case where we process Personal Data in a jurisdiction other than a jurisdiction in the EEA, we undertake to do so only in accordance with the requirements of the GDPR:
a. in countries approved by an adequacy decision under Article 45 of the GDPR; or
b. by Sub-Processors or third-party services which operate under the EU-US Privacy Shield / U.S. Privacy Shield.[3] [M4]
6.8. assist you by appropriate technical and organizational measures, insofar as this is possible, for the fulfillment your obligation to respond to requests for exercising the data subject's rights laid down in Chapter III of the GDPR;
6.9. assist you in ensuring compliance with the obligations under Articles 32 to 36 of the GDPR, relating to the security of processing, Personal Data Breaches and Data Protection Impact Assessments, as defined under the GDPR;
6.10. at your choice, delete or (where possible) return all the Personal Data to you after the end of the provision of Services, and delete existing copies unless applicable law requires storage of the Personal Data;
6.11. give you access to all information necessary to demonstrate compliance with the obligations laid down in Article 28 of the GDPR and allow for and contribute to audits, including inspections, conducted by you or another auditor mandated by you;
6.12. Upon becoming aware of any Breach Incident, we will notify you without undue delay, and will provide you with information relating to the Breach Incident as reasonably requested by you. We will use reasonable endeavors to assist you in mitigating, where possible, the adverse effects of any such Breach Incident. "Breach Incident" - means a breach of security leading to the accidental or unlawful distraction, loss, Alteration, unauthorized disclosure of, or access to, Personal Data.