Data Processing Addendum
Last updated August 5, 2026
Realytics Corp Limited
Last updated: 5 August 2026 | Effective: 5 August 2026
This Data Processing Addendum and its Annexes (the "DPA") reflect the agreement between Realytics and Customer (as defined below), together the "Parties", with respect to the Processing of Customer Personal Data under the terms of service, subscription agreement, order form or other written or electronic agreement between the Parties that references this DPA (the "Agreement").
This DPA is incorporated into the Agreement and forms an integral part of it without the need for any additional signature by either Party. A signable copy is available on request from for Customers whose internal procedures require one.
In the event of any conflict between this DPA and the Agreement, this DPA controls. In the event of any conflict between this DPA and the Standard Contractual Clauses referenced in Section 9, the Standard Contractual Clauses control.
1. Definitions
Capitalised terms not defined here have the meaning given in the Agreement.
"Affiliate" means an entity that owns or controls, is owned or controlled by, or is under common ownership or control with the subject entity, where "control" means the power to direct the management or affairs of an entity and "ownership" means beneficial ownership of fifty percent (50%) or more of the voting securities or equivalent voting interests.
"Applicable Data Protection Law" means all legislation relating to data protection and privacy applicable to the Processing under this DPA, including the European Data Protection Laws, the CCPA, the Virginia Consumer Data Protection Act, the Colorado Privacy Act, the Connecticut Data Privacy Act, the Utah Consumer Privacy Act, and other applicable United States state privacy laws.
"CCPA" means the California Consumer Privacy Act as amended by the California Privacy Rights Act, together with its implementing regulations.
"Controller" means the entity that determines the purposes and means of the Processing of Personal Data, including a "business" as that term is defined under Applicable Data Protection Law.
"Customer" means the entity that enters into the Agreement with Realytics for access to or use of the Services.
"Customer Personal Data" means the Personal Data described in Annex I that Customer or its Authorised Users submit to, upload to, or make accessible through the Services, or that Realytics Processes on Customer's behalf under the Agreement, and in respect of which Customer is either the Controller or a Processor acting on behalf of a third-party Controller.
"Data Subject", "Process", "Processed" and "Processing" each have the meaning given under Applicable Data Protection Law.
"Establishment-Level Data" means data that relates to a business, brand, store, branch, outlet, venue or other commercial location or legal person, and that is not used by Realytics to identify, single out, or build a profile of any natural person.
"European Data Protection Laws" means the GDPR, the United Kingdom Data Protection Act 2018 together with the UK GDPR, and the Swiss Federal Act on Data Protection, each as amended or replaced.
"GDPR" means Regulation (EU) 2016/679, and the same regulation as incorporated into the law of the United Kingdom.
"Personal Data" means personal data or personal information as defined under Applicable Data Protection Law.
"Personal Data Breach" means a breach of security leading to the accidental or unlawful destruction, loss, alteration, or unauthorised disclosure of or access to Personal Data transmitted, stored or otherwise Processed.
"Processor" means the entity that Processes Personal Data on behalf of a Controller, including a "service provider" as that term is defined under Applicable Data Protection Law.
"Realytics" means Realytics Corp Limited, a company registered in Cyprus under number HE424817, whose registered office is at 25 Martiou, 27, D. Michael Tower, office 105A, Nicosia, Cyprus, or, where the Agreement is entered into with Reality Analytics, Inc., that entity.
"Regulator" means the supervisory or enforcement authority with jurisdiction over the Processing.
"Services" means the services provided by Realytics to Customer under the Agreement.
"Standard Contractual Clauses" or "SCCs" means the standard contractual clauses approved by Commission Implementing Decision (EU) 2021/914 of 4 June 2021.
"Sub-Processor" means any Processor engaged by Realytics, including a Realytics Affiliate, to Process Customer Personal Data.
2. Roles and scope
2.1 Processor role. With respect to Customer Personal Data, Customer is the Controller and Realytics is the Processor. Where Customer acts as a Processor on behalf of a third-party Controller, Realytics acts as Customer's Sub-Processor, and Customer is responsible for ensuring that its instructions to Realytics are authorised by the relevant Controller. Realytics will Process Customer Personal Data only as set out in this DPA and in accordance with Customer's instructions.
2.2 Controller role. Realytics acts as a Controller, and not as a Processor, in respect of account registration data, authorised user details, billing and payment information, support correspondence, and Services usage and telemetry data, which Realytics Processes for the purposes of providing, securing, supporting, maintaining and improving the Services, managing the customer relationship, fraud prevention, business continuity, and conducting core business functions such as accounting, billing and legal compliance. Realytics' processing of that data as a Controller is described in the Realytics Privacy Policy and is not governed by this DPA.
2.3 Realytics' own data. The datasets that Realytics compiles, licenses, or derives independently of Customer — including data obtained by crawling publicly accessible web pages, licensed third-party datasets, and Establishment-Level Data — are not Customer Personal Data and are not governed by this DPA, regardless of whether they are presented to Customer through the Services.
2.4 Customer Affiliates. Where Customer's Affiliates have purchased subscriptions to the Services directly under the Agreement, this DPA applies to those subscriptions and each such Affiliate is deemed the Controller for its own Customer Personal Data. Customer is responsible for coordinating all communications with Realytics under this DPA on behalf of itself and its Affiliates and is entitled to make and receive such communications on their behalf.
2.5 Duration. Realytics will Process Customer Personal Data for the term of the Agreement and thereafter only as permitted by Section 8.
3. Customer obligations
3.1 Customer will Process Customer Personal Data, and issue instructions to Realytics, in accordance with Applicable Data Protection Law. Customer has sole responsibility for the accuracy, quality and legality of Customer Personal Data and for the means by which it obtained that data.
3.2 Customer warrants that it has all necessary rights, and a valid legal basis, to provide Customer Personal Data to Realytics for the Processing contemplated by the Agreement. Where required by Applicable Data Protection Law, Customer is responsible for obtaining and maintaining a record of any necessary Data Subject consents. If a consent is withdrawn, Customer is responsible for notifying Realytics, and Realytics remains responsible for implementing any resulting instruction consistent with this DPA.
3.3 Prohibited data. Customer will not submit to the Services, and will not permit its Authorised Users to submit:
(a) special categories of Personal Data within the meaning of Article 9 GDPR, being data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, genetic data, biometric data processed for identification purposes, data concerning health, or data concerning a natural person's sex life or sexual orientation;
(b) Personal Data relating to criminal convictions or offences;
(c) Personal Data of children under the age of sixteen (16); or
(d) payment card numbers, financial account numbers, government identification numbers, or precise geolocation data of an identified natural person.
The Services are not designed to Process the data described in this Section 3.3, and Realytics has no obligation or liability in respect of such data if submitted in breach of this Section.
3.4 Indemnity. Customer will defend, indemnify and hold harmless Realytics and its Affiliates against any claim, demand, proceeding, fine, loss or expense (including reasonable legal fees) arising out of or relating to (a) Customer Personal Data that Customer did not have a lawful basis or the necessary rights to provide to Realytics, (b) Customer's breach of Section 3.3, or (c) any instruction from Customer that causes Realytics to be in breach of Applicable Data Protection Law, provided that Realytics notified Customer under Section 4.1(c) where it was able to do so.
4. Realytics' obligations as Processor
4.1 To the extent Realytics Processes Customer Personal Data on Customer's behalf, Realytics will:
(a) Process Customer Personal Data only on documented instructions from Customer, which include the Agreement, this DPA, Customer's configuration and use of the Services, and any other reasonable written instruction consistent with this DPA, including with regard to transfers to third countries, except where required to comply with a law to which Realytics is subject;
(b) where a law requires Processing other than on Customer's instructions, inform Customer of that legal requirement before Processing, unless the law prohibits such disclosure;
(c) inform Customer promptly if, in Realytics' opinion, an instruction from Customer infringes Applicable Data Protection Law;
(d) ensure that personnel authorised to Process Customer Personal Data are bound by an obligation of confidentiality, and limit access to those personnel who need it to provide, support or secure the Services; and
(e) maintain a written information security policy covering the Processing of Customer Personal Data.
4.2 Service provider and processor restrictions. Realytics will not:
(a) retain, use or disclose Customer Personal Data other than as necessary to provide the Services and perform the Agreement, or as otherwise permitted by Applicable Data Protection Law;
(b) retain, use or disclose Customer Personal Data outside the direct business relationship between Realytics and Customer;
(c) "sell" or "share" Customer Personal Data, as those terms are defined under Applicable Data Protection Law; or
(d) combine Customer Personal Data with Personal Data received from or on behalf of any other person, or collected from Realytics' own interactions with individuals, except as permitted by Section 5 or as necessary to provide the Services.
The Parties acknowledge that Customer's disclosure of Customer Personal Data to Realytics does not form part of any monetary or other valuable consideration exchanged between the Parties. Realytics will provide Customer Personal Data with the same level of privacy protection required of Customer under Applicable Data Protection Law, and will notify Customer if it determines that it can no longer meet its obligations under Applicable Data Protection Law.
5. Establishment-level analysis and service improvement
5.1 Purpose. The Services function by resolving commercial activity to the level of a business, brand or physical location. Realytics does not seek to identify, single out, profile, or make decisions about individual natural persons, and does not attempt to re-identify natural persons within any dataset it holds.
5.2 Permitted use. Realytics may use Establishment-Level Data and aggregated or statistical data derived from the operation of the Services, including data derived from Customer Personal Data, to provide, secure, maintain, analyse and improve the Services, including to develop, train, test and evaluate the analytical and machine learning models that form part of the Services.
5.3 Limits. Realytics will only use data under Section 5.2 where it has been aggregated or reduced to Establishment-Level Data such that it no longer identifies, and cannot reasonably be used to identify, any natural person, and no longer identifies Customer. Realytics will not disclose Customer Personal Data itself, or any output that identifies Customer, to any other customer.
5.4 Individual-level data. Realytics does not hold or seek individual-level records of natural persons in the datasets underlying the Services.
5.5 Objection. Where a Data Subject exercises a right to object under Article 21 GDPR in respect of Processing carried out under this Section, Realytics will give effect to that objection in accordance with Applicable Data Protection Law.
6. Security
6.1 Taking into account the state of the art, the costs of implementation, and the nature, scope, context and purposes of the Processing, as well as the risks to Data Subjects, Realytics will implement and maintain appropriate technical and organisational measures to protect Customer Personal Data against a Personal Data Breach. Those measures are described in Annex II.
6.2 Realytics may update the measures in Annex II from time to time, provided that such updates do not result in a material degradation of the overall security of the Services.
6.3 On Customer's written request, and subject to the confidentiality provisions of the Agreement, Realytics will provide information reasonably necessary to demonstrate compliance with this Section 6, which may include completed security questionnaires and, where available, summaries of third-party audit reports or certifications, which may be redacted for security or confidentiality reasons.
6.4 Audit. Where Applicable Data Protection Law requires it, and where the information provided under Section 6.3 is not sufficient, Customer may request an audit of Realytics' Processing of Customer Personal Data. Such an audit may be conducted not more than once in any twelve (12) month period, requires at least thirty (30) days' prior written notice, and is subject to the Parties agreeing the scope, timing and duration in advance. Customer bears its own costs and will reimburse Realytics' reasonable costs for time spent supporting the audit. Audit results are the Confidential Information of Realytics. Customer will notify Realytics promptly of any non-compliance identified, and Realytics will use commercially reasonable efforts to remediate any confirmed non-compliance. Nothing in this Section limits an audit or inspection required by a Regulator.
7. Sub-processors
7.1 Authorisation. Customer grants Realytics general written authorisation to engage Realytics Affiliates and third-party Sub-Processors to Process Customer Personal Data in connection with the Services. This constitutes Customer's prior written authorisation for the purposes of Clause 9 of the Standard Contractual Clauses. The current list of Sub-Processors is available at realytics.com/legal/subprocessors and is reproduced at Annex III.
7.2 Notice and objection. Realytics will give notice of any new Sub-Processor by updating the list at least fifteen (15) days before that Sub-Processor is given access to Customer Personal Data, and will provide a mechanism by which Customer may subscribe to notifications of updates. Customer may object on reasonable grounds relating to data protection within fourteen (14) days of the notice. If Customer does not respond within that period, the Sub-Processor is deemed accepted.
7.3 Resolution. If Customer objects, the Parties will discuss the objection in good faith. If no resolution is reached within thirty (30) days, Customer may terminate the affected part of the Services on written notice, and Realytics will refund any prepaid fees covering the period after termination on a pro-rata basis.
7.4 Flow-down and liability. Realytics will impose on each Sub-Processor data protection obligations providing at least the same level of protection for Customer Personal Data as this DPA. Where a Sub-Processor fails to fulfil those obligations, Realytics remains liable to Customer for the performance of that Sub-Processor's obligations.
8. Deletion and return
8.1 On expiry or termination of the Agreement, on Customer's written request, or when the purpose of the Processing has been fulfilled, Realytics will delete Customer Personal Data within thirty (30) days, except to the extent that retention is required by law.
8.2 Customer Personal Data contained in routine backups will be deleted in accordance with Realytics' ordinary backup cycle and in any event within ninety (90) days of termination.
8.3 Customer may export Customer Personal Data using the export functionality of the Services at any time during the term at no additional charge. Where Customer requests a bespoke extraction requiring engineering effort, Realytics may charge its reasonable costs.
8.4 Realytics will maintain the confidentiality of any Customer Personal Data retained under Section 8.1 and will Process it only as necessary to comply with the law to which it is subject.
8.5 Aggregated and Establishment-Level Data lawfully created under Section 5 before termination, which does not identify Customer or any natural person, is not subject to deletion under this Section.
9. International transfers
9.1 Standard Contractual Clauses. Where Customer Personal Data originating in the European Economic Area, the United Kingdom or Switzerland is transferred to a country that has not been the subject of an adequacy decision, the Parties agree to be bound by Module Two (Controller to Processor) of the Standard Contractual Clauses, which are incorporated into this DPA by reference. Where Customer acts as a Processor on behalf of a third-party Controller, Module Three (Processor to Processor) applies instead. Customer complies with the obligations of the data exporter and Realytics complies with the obligations of the data importer.
9.2 Elections. For the purposes of the Standard Contractual Clauses:
(a) the optional docking clause in Clause 7 applies where either Party notifies the other in writing that it is required;
(b) in Clause 9, Option 2 (general written authorisation) applies, with the notice period set out in Section 7.2;
(c) in Clause 11, the optional independent dispute resolution language does not apply;
(d) in Clause 17, Option 1 applies and the Clauses are governed by the law of the Republic of Cyprus;
(e) in Clause 18(b), disputes will be resolved before the courts of the Republic of Cyprus;
(f) Annex I of the Standard Contractual Clauses is completed with the information in Annex I to this DPA, and Annex II with the information in Annex II to this DPA; and
(g) entry into this DPA constitutes each Party's signature of the Standard Contractual Clauses and their Annexes.
9.3 United Kingdom. For transfers subject to the UK GDPR, the Parties agree to the UK International Data Transfer Addendum (version B1.0) issued by the Information Commissioner, which is incorporated by reference. Table 1 is completed with the Parties' details in Annex I; Table 2 identifies the exporter as Controller and the importer as Processor; Tables 3 and 4 are completed with the information in Annexes I and II respectively.
9.4 Switzerland. For transfers subject to the Swiss Federal Act on Data Protection, the Federal Data Protection and Information Commissioner is the competent supervisory authority, references to the GDPR are read as references to the Swiss Act, and Data Subjects in Switzerland may enforce their rights in Switzerland.
9.5 Onward transfers. Realytics may transfer Customer Personal Data to Reality Analytics, Inc. and to the Sub-Processors listed in Annex III, in each case subject to appropriate safeguards under Applicable Data Protection Law.
9.6 Change of mechanism. If the Standard Contractual Clauses or the UK Addendum are amended, replaced, or held invalid or insufficient by a court or Regulator of competent jurisdiction, the Parties agree that the applicable replacement or updated clauses, or any alternative transfer mechanism that is valid under Applicable Data Protection Law, will apply automatically from the date they become applicable, and that Realytics may implement additional safeguards as necessary without amending this DPA.
10. Data subject rights and assistance
10.1 Where Realytics receives a request from a Data Subject to exercise rights of access, rectification, erasure, restriction, portability, or objection in respect of Customer Personal Data, Realytics will, to the extent legally permitted, promptly inform the Data Subject that the request should be directed to Customer, and will notify Customer of the request.
10.2 Taking into account the nature of the Processing, Realytics will assist Customer by appropriate technical and organisational measures, insofar as reasonably possible, in fulfilling Customer's obligation to respond to such requests. Where Customer cannot address a request through the functionality of the Services, Realytics will use commercially reasonable efforts to assist.
10.3 On Customer's request, and taking into account the nature of the Processing and the information available to Realytics, Realytics will provide reasonable assistance to Customer in carrying out a data protection impact assessment relating to Customer's use of the Services, and in any prior consultation with a Regulator under Article 36 GDPR, in each case to the extent Customer does not otherwise have access to the relevant information.
11. Personal Data Breach
11.1 Realytics will notify Customer of a Personal Data Breach affecting Customer Personal Data without undue delay and in any event within seventy-two (72) hours of becoming aware of it, using the contact details Customer has provided for that purpose. Customer is responsible for keeping those details current.
11.2 The notification will include, to the extent then known, the nature of the breach, the categories and approximate volume of Customer Personal Data affected, the likely consequences, and the measures taken or proposed. Where the information is not available at the time of notification, Realytics will provide it in stages as it becomes available.
11.3 Realytics will take commercially reasonable steps to contain and remediate the breach to the extent remediation is within its control, and will provide Customer with reasonable assistance to enable Customer to notify Regulators and affected Data Subjects where Customer is required to do so.
11.4 Customer is solely responsible for complying with breach notification obligations applicable to Customer and for any third-party notification obligations.
11.5 This Section does not apply to a Personal Data Breach caused by Customer, its Authorised Users, or products or services not provided by Realytics.
11.6 Realytics' notification of a Personal Data Breach is not an acknowledgement of fault or liability.
12. General
12.1 Liability. Each Party's liability, and that of its Affiliates, arising out of or relating to this DPA, whether in contract, tort or under any other theory of liability, is subject to the limitations and exclusions of liability set out in the Agreement. Any reference in the Agreement to the liability of a Party means the aggregate liability of that Party and all of its Affiliates under the Agreement and all data processing addendums together. Nothing in this DPA limits any liability that cannot be limited under Applicable Data Protection Law, including a Data Subject's rights under Articles 79 and 82 GDPR.
12.2 Governing law. This DPA is governed by the law applicable to the Agreement. Where the Agreement does not specify a governing law, this DPA is governed by the law of the Republic of Cyprus, and the courts of Cyprus have exclusive jurisdiction, subject to Sections 9.2(e) and 9.3.
12.3 Order of precedence. This DPA supersedes any conflicting term of the Agreement in respect of the Processing of Customer Personal Data. Save as amended by this DPA, the Agreement remains in full force.
12.4 Changes to this DPA. Realytics may update this DPA to reflect changes in Applicable Data Protection Law, the Services, or its Sub-Processors, provided that no update materially reduces the protections afforded to Customer Personal Data. Realytics will give notice of material changes at least thirty (30) days in advance by posting the updated DPA and, where Customer has subscribed to notifications, by email.
12.5 Severability. If any provision of this DPA is held invalid or unenforceable, the remainder continues in effect.
12.6 No partnership. Nothing in this DPA creates a partnership, joint venture or agency between the Parties.
12.7 Term. This DPA takes effect on the effective date of the Agreement and terminates automatically on the expiry or termination of the Agreement, save for provisions that survive by their nature, including Sections 8, 9 and 12.1.
12.8 Contact. Questions about this DPA may be sent to . Security matters may be sent to .
Annex I — Description of Processing
A. List of parties
Data exporter (Controller): Customer, as identified in the Agreement. Activities relevant to the transfer: receipt of the Services under the Agreement. Signature and date: entry into this DPA constitutes Customer's signature of this Annex.
Data importer (Processor): The Realytics entity identified in the Agreement, being either Realytics Corp Limited, registration number HE424817, 25 Martiou, 27, D. Michael Tower, office 105A, Nicosia, Cyprus, or Reality Analytics, Inc., 1000 N. West Street, Suite 1200, Wilmington, Delaware 19801, United States. Contact: . Activities relevant to the transfer: provision of the Services to Customer under the Agreement. Signature and date: entry into this DPA constitutes Realytics' signature of this Annex.
B. Description of the transfer
|
Item |
Description |
|---|---|
|
Categories of Data Subjects |
Customer's authorised users and personnel who access the Services; business contacts identified within data Customer submits |
|
Categories of Personal Data |
Business contact details (name, job title, work email address, telephone number); account and authentication data; Services usage and configuration data; online identifiers; support correspondence; the contents of files, lists and records that Customer chooses to submit to the Services |
|
Sensitive data |
None. Customer is prohibited by Section 3.3 from submitting special categories of Personal Data, criminal offence data, data relating to children under 16, payment card or financial account numbers, government identification numbers, and precise geolocation data of identified natural persons |
|
Frequency of transfer |
Continuous, for the duration of the Agreement |
|
Nature of the Processing |
Storage, hosting, organisation, retrieval, analysis, aggregation and display of Customer Personal Data as necessary to provide the Services, together with support, security and maintenance |
|
Purpose of the Processing |
Provision of the Services to Customer in accordance with the Agreement and Customer's instructions |
|
Retention period |
For the duration of the Agreement, then in accordance with Section 8 |
|
Transfers to Sub-Processors |
Subject matter, nature and duration as described in Section 7 and Annex III |
C. Competent supervisory authority
The Office of the Commissioner for Personal Data Protection of the Republic of Cyprus.
Annex II — Technical and organisational measures
Realytics maintains technical and organisational measures designed to protect Customer Personal Data against a Personal Data Breach, taking into account the nature, scope, context and purposes of the Processing and the risk to Data Subjects. Realytics does not publish detailed system architecture or security implementation details where doing so would create security risk.
A. Access control
Realytics restricts access to Customer Personal Data to personnel who need access to provide, support, maintain or secure the Services. Access is granted on a role basis, requires authentication, and is removed when it is no longer required. Personnel with access to Customer Personal Data are bound by confidentiality obligations.
B. Transmission security
Realytics protects Customer Personal Data transmitted over public networks using encryption in transit where technically appropriate.
C. Segregation and minimisation
Realytics uses logical controls designed to separate customer environments and data within the Services. Realytics limits Processing of Customer Personal Data to what is necessary for the purposes described in the Agreement and this DPA, and uses aggregation, de-identification or Establishment-Level Data where the purpose permits.
D. Backups and resilience
Realytics maintains backup and recovery measures designed to support availability and restoration of the Services and Customer Personal Data after an incident, subject to the Service tier and the Agreement.
E. Incident management
Realytics maintains procedures for identifying, investigating, containing and remediating security incidents affecting the Services.
F. Sub-processor management
Realytics contracts with Sub-Processors on terms imposing data protection obligations providing at least the same level of protection as this DPA, and maintains the published Sub-Processor list described in Section 7.
Annex III — Sub-processors
|
Sub-processor |
Function |
Location |
|---|---|---|
|
Amazon Web Services, Inc. |
Cloud infrastructure and storage |
United States, Ireland, Germany |
|
Google Cloud Platform (Google LLC / Google Ireland Ltd) |
Cloud infrastructure, data warehousing |
United States, European Union |
|
Hetzner Online GmbH |
Dedicated server hosting and data centre facilities |
Germany, Finland |
|
Cloudflare, Inc. |
Content delivery, traffic management and edge services |
Processed at the data centre nearest the end user |
|
Google Workspace (Google Ireland Ltd) |
Business email, document storage and collaboration |
European Union, United States |
|
Stripe, Inc. |
Payment processing and billing |
United States, Ireland |
|
HubSpot, Inc. |
Customer relationship management |
United States, European Union |
|
Klaviyo, Inc. |
Customer messaging and email delivery |
United States |
|
PostHog, Inc. |
Product analytics |
United States, European Union |
|
OpenAI, L.L.C. |
AI model inference for Services features |
United States |
|
Anthropic PBC |
AI model inference for Services features |
United States |
|
Google LLC (Gemini / Vertex AI) |
AI model inference for Services features |
United States, European Union |
|
Reality Analytics, Inc. |
Group Affiliate — product development, customer support and administration |
United States |
Notes. Hetzner Online GmbH provides dedicated bare-metal servers and data centre facilities. Realytics does not grant Hetzner access to Customer Personal Data and Hetzner does not Process Customer Personal Data on Realytics' behalf; it is listed for transparency as a provider of hosting infrastructure.
Meta Platforms, TikTok, LinkedIn and Google Ads are used by Realytics for its own marketing and advertising activities, in which Realytics acts as a Controller. They do not Process Customer Personal Data and are therefore not Sub-Processors under this DPA. Their role is described in the Realytics Privacy Policy.
Realytics does not permit the Sub-Processors listed above that provide AI model inference to use Customer Personal Data to train their own models, and contracts with them on terms that exclude such use.