# Data Processing Addendum [DPA]

**Approval**: Kfir Pravda
**Approval Date**: 2025-09-25
**Protocol Type**: Public-Unlisted
**Document Status**: Reviewed

# **Data Processing Addendum**

## Date of update:

- 25/04/2020 (Benny Akler)

1.   As a responsible, forward-looking business, Pravda Media Group recognizes at senior levels the need to comply with the provisions of the Regulation (EU) 2016/679 of the European Parliament (General Data Protection Regulation – "GDPR") and ensure that effective measures are in place to protect the Personal Data of our customers.

2.   This Data Processing Addendum (“DPA”) forms part of the Framework Agreement or other written or electronic agreement between Pravda Media Group ("PMG" or "Us" or "Our") and you, the customer ("You" or the "Customer"), for the purchase of paid media campaign services from PMG (identified either as “Services” or otherwise in the applicable agreement, and hereinafter defined as “Services”) (the "Contract").

3.   This DPA reflect our obligations with regard to the processing of "Personal Data" - any information relating to, directly or indirectly, an identified or identifiable natural person, collected and/or stored or processed by us on behalf of you. This DPA does not address or limit the processing of aggregated anonymous data that can no longer be identified or associated with a particular natural person ("Anonymized Data"). We may use and process Anonymize Data , under our sole discretion, for our statistical needs and/or in order to improve our systems and services, even if such Anonymized Data was produced using Personal Data (e.g. aggregative data which was derived from raw Personal Data).

4.   We will maintain administrative, physical, and technical safeguards for the protection of the security, confidentiality, availability, and integrity of Personal Data in accordance with applicable law and industry standards. Those safeguards will include, but will not be limited to: security-related policies and procedures, standards and practices designated for the protection of Personal Data and for preventing access, use, modification or disclosure of Personal Data by our personnel except (a) to provide the Services and prevent or address service or technical problems, (b) as compelled by law and subject to any exclusions and condition hereunder, or (c) as You expressly permit in writing.

5.   For the performance of our obligations under the Contract and for the provision of the Services as requested and instructed by you, we process Personal Data. Part of the Personal Data is being provided to us by you and some of it is being obtained directly from users, website visitors, Your clients or potential clients, etc. We keep that Personal Data in Our systems, analyze it and process it by various tools including third party tools, in order to provide you with the Services. The Personal Data will be kept in our systems until the end of the provision of the Services, as detailed hereunder.

6.   In accordance with Article 28 of the GDPR, we undertake to:

6.1.   process the Personal Data only on documented instructions from you;

6.2. not use the Personal Data for any purpose other than the strict performance of the Contract and the provision of the Services as requested by you. Notwithstanding the preceding, we shall be entitled to use the Personal Data for statistical and financial purposes, provided however that any personal attributes shall be removed from the Personal Data, or otherwise if such is maintained under aggregate basis;

6.3. ensure that Our personnel who authorized to process the Personal Data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality;

6.4. Take commercially reasonable steps to ensure that (i) persons employed by Us and (ii) other persons engaged to perform on PMG's behalf, comply with the terms of this DPA;

6.5. take all measures required pursuant to Article 32 of the GDPR, namely to implement appropriate technical and organizational measures to ensure a level of security appropriate to the risk to the rights and freedoms of natural persons;

6.6. respect the conditions referred to in paragraphs 2 and 4 of Article 28 of the GDPR for engaging another Processor, namely that we may not engage another Processor (Sub-Processor) without your prior authorization. At the date of this agreement, you acknowledge and agree that for the provision of the Services, we may use the following external services:

> ## Background
>
> This document serves as the official registry of software applications, vendor solutions, and technology packages that have been evaluated, vetted, and approved for use within PMG.. Employees and departments must reference this approved list before procuring, installing, or implementing any software solutions. The use of non-approved software without proper authorization through the established review process is strictly prohibited and may result in security vulnerabilities, compliance violations, and potential disciplinary action. This document is maintained by the CTO and CEO of PMG.
>
> ## Web & Edge device Software
>
> | **Software** | **On-Device/Web** | **Description** | **Notes** |
> | --- | --- | --- | --- |
> | Google Workspace<br>[https://workspace.google.com](https://workspace.google.com/) | Web Based | Identity Platform and SSO authentication, Gmail - Custom business email, Drive - secured cloud storage, "Meet" - Video conferencing, Calendar - Shared calendars, Gemini - AI assistant, Docs - Word processing, Sheets - Spreadsheets, Slides - Presentation builder, NotebookLM - AI research assistant | [Google NotebookLM Privacy Information](https://support.google.com/notebooklm/answer/15724963?hl=en#:~:text=We%20value%20your%20privacy%20and,personal%20data%20to%20train%20NotebookLM)<br><br>[Google Workspace Terms of Service](https://workspace.google.com/terms/premier_terms/?sjid=17756812278584567358-EU)<br><br>[How Gemini for Google Cloud uses your data](https://cloud.google.com/gemini/docs/discover/data-governance) |
> | 1Password<br>[https://1password.com](https://1password.com/) | On-Device & Web Based | PMG approved password manager | 1password Security Notes: [https://support.1password.com/1password-security/](https://support.1password.com/1password-security/)<br>1Password Trust Center:<br>[https://app.conveyor.com/profile/1password](https://app.conveyor.com/profile/1password)<br>1Password SOC certification: [https://1password.com/soc/](https://1password.com/soc/) |
> | Teamwork<br>[https://www.teamwork.com](https://www.teamwork.com/) | Web Based | PMG approved project management system and secure platform for hosting client-sent database. | Teamwork Trust Center:<br>[https://www.teamwork.com/security/](https://www.teamwork.com/security/) |
> | Notion<br>[https://www.notion.so](https://www.notion.so/) | Web Based | PMG approved project management system  | Notion Trust Center:<br>[https://www.notion.com/security](https://www.notion.com/security)<br><br>Notion AI terms:<br>[https://notion.notion.site/Notion-AI-Supplementary-Terms-fa9034c8b5a04818a6baf3eac2adddbb](https://notion.notion.site/Notion-AI-Supplementary-Terms-fa9034c8b5a04818a6baf3eac2adddbb) |
> | HubSpot<br>[https://hubspot.com](https://hubspot.com/) | Web Based | CRM and Marketing Automation software used to manage PMG internal database, outreach programs and ad management. | HubSpot Trust Center:<br>[https://legal.hubspot.com/security](https://legal.hubspot.com/security) |

... and 48 more lines
Total document length: 14059 characters
