Documents
- Terms of Use
- Privacy Policy
- Acceptable Use Policy
- Data Protection Addendum
- Community Terms of Use
- Advertising Terms of Use
beehiiv Customer Data Protection Addendum
Date last modified: July 16, 2026
This Data Protection Addendum (“DPA”) forms part of the terms entered into by and between you (“Customer”) and beehiiv Inc. (“beehiiv”) pursuant to the Terms of Use or other ordering agreement under which beehiiv provides Services to you (the “Agreement”). beehiiv and Customer may each be referred to as a “Party” and or collectively referred to as the “Parties”.
Definitions
1. In this DPA:
a. "Applicable Law" means all laws, regulations and other legal requirements applicable to either (i) beehiiv as provider of the Services or (ii) Customer as user of the Services. For example, to the extent applicable, this includes the General Data Protection Regulation (Regulation (EU) 2016/679) ("GDPR"); equivalent requirements in the United Kingdom including the Data Protection Act 2018 and the UK General Data Protection Regulation ("UK Data Protection Law"); the Swiss Federal Act on Data Protection ("Swiss FADP"); the California Consumer Privacy Act, as amended by the California Privacy Rights Act and together with associated regulations ("CCPA"); as well as U.S. state laws similar to the CCPA, such as the Virginia Consumer Data Protection Act; the Colorado Privacy Act and related regulations; the Connecticut Act Concerning Personal Data Privacy and Online Monitoring; the Utah Consumer Privacy Act; Texas Data Privacy and Security Act; the Oregon Consumer Privacy Act; Florida Digital Bill of Rights; Montana Consumer Data Privacy Act, the Iowa Consumer Privacy Act; Tennessee Information Protection Act; the Indiana Consumer Data Protection Act, the New Jersey Privacy Act, the New Hampshire Privacy Act; Delaware Personal Data Privacy Act, Kentucky Consumer Data Protection Act, Nebraska Data Privacy Act, Minnesota Consumer Data Privacy Act, Maryland Online Data Privacy Act, and Rhode Island Data Transparency and Privacy Protection Act (together with the CCPA, as they become effective, the "U.S. State Privacy Laws").
b. "Designated Contact Address"means Customer's administrative email address provided when entering into the Agreement.
c. "Personal Data"means any information relating to an identified or identifiable individual, within the meaning of the GDPR (regardless of whether the GDPR applies), any information that qualifies as "personal information" under the CCPA (regardless of whether the CCPA applies) and any other information defined as "personal information," "personal data," or an analogous term in Applicable Law, in each case that is processed on behalf of the Customer to provide the Service.
d. "Personal Data Breach" means the accidental or unlawful destruction, loss, alteration, disclosure or other Processing of, or access to, Personal Data.
e. "Process" and "Processing" mean any operation or set of operations performed on Personal Data, whether or not by automated means, such as collection, recording, organization, creating, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction.
f. "Services" has the meaning ascribed to such term in the Agreement.
g. "Standard Contractual Clauses"refers to the clauses issued pursuant to the EU Commission Implementing Decision (EU) 2021/914 of 4 June 2021 on standard contractual clauses for the transfer of personal data to third countries pursuant to Regulation (EU) 2016/679 of the European Parliament and of the Council, available at http://data.europa.eu/eli/dec_impl/2021/914/oj and completed as described in the "Data Transfers" section below.
h. "Subprocessor" means a subcontractor engaged by beehiiv for the Processing of Personal Data.
i. "UK SCC Addendum"means the United Kingdom International Data Transfer Addendum to the EU Commission Standard Contractual Clauses (available as of 24 June 2025 at https://ico.org.uk/media2/migrated/4019539/international-data-transfer-addendum.pdf), completed as described in the "Data Transfers" section below.
2. For ease of reading, some other terms are defined later in the DPA.
Scope, Relationship of the Parties, and Data Use Limitations
3. This DPA applies only to the Personal Data the Services receive from or on behalf of Customer through Customer's use of the Services in compliance with the Agreement.
4. For such Personal Data, Customer is (or represents that it is acting with full authority on behalf of) the Controller, and beehiiv is Customer's Processor. If Customer is acting on behalf of a Controller (or on behalf of intermediaries such as other Processors of the Controller), then, to the extent legally permissible:
a. Customer will serve as the sole point of contact for beehiiv with regard to any such third parties;
b. beehiiv need not interact directly with any such third party in matters relating to this DPA; and
c. Where beehiiv would otherwise be required to provide information, assistance, cooperation, or anything else to such third party, beehiiv may provide it solely to Customer; but
d. beehiiv is entitled to follow the instructions of such third party with respect to such third party's Personal Data instead of Customer's instructions if beehiiv reasonably believes this is legally required under the circumstances.
5. Unless required by Applicable Law, beehiiv will Process the Personal Data only to (i) provide and ensure the proper operation of the Services consistent with the Agreement (such as for the detection and prevention of spam and other fraud); and (ii) carry out Customer's reasonable written instructions that are consistent with the Agreement. Without limiting the foregoing, beehiiv:
a. "shall not "sell" the Personal Data, as such term is defined in the U.S. State Privacy Laws (regardless of whether such laws apply);
b. shall not "share" the Personal Data, as such term is defined in the CCPA (regardless of whether the CCPA applies) or otherwise disclose it for targeted advertising purposes;
c. shall not retain, use, or disclose any such data outside of the direct business relationship between Customer and beehiiv, or for any purpose (including any commercial purpose) other than the limited business purposes specified in this DPA and as permitted by Applicable Law;
d. shall comply with any applicable restrictions under Applicable Law on combining the Personal Data that beehiiv receives from, or on behalf of, Customer with Personal Data that beehiiv receives from, or on behalf of, another person or persons, or that beehiiv collects from any other interaction between beehiiv and a data subject;
e. shall provide the same level of protection for the Personal Data subject to the CCPA as is required of businesses under the CCPA; and
f. hereby certifies that it understands the restrictions and obligations set forth in this DPA and that it will comply with them.
6. If Applicable Law requires beehiiv to engage in Processing not permitted by the above, beehiiv will first inform Customer of the relevant legal requirement unless Applicable Law prohibits such notification. beehiiv will notify Customer as soon as legally permissible if, for any other reason, beehiiv determines that beehiiv can no longer meet its obligations under Applicable Law.
7. Customer has the right to take reasonable and appropriate steps to (a) exercise its rights under the Compliance Verifications and Audits section of this DPA to ensure that beehiiv is using the Personal Data consistent with Customer's obligations under Applicable Law, and (b) stop and remediate unauthorized use by beehiiv of the Personal Data by terminating the Agreement pursuant to its provisions for termination for cause and by requesting deletion of the Personal Data and certification of such deletion pursuant to the Data Return and Destruction section of this DPA.
8. Customer is responsible for providing any legally required notices to the individual, obtaining any legally required consents from the individual, and taking any other steps required by Applicable Law, to enable Customer to lawfully use the Services, including as set forth in the Agreement. Customer shall not provide the Services with any Personal Data that is not reasonably necessary for Customer's use of the Services.
9. For the Personal Data, Customer is a "Controller" and beehiiv Processes it for Customer as a "Processor" as such terms are defined in the U.S. State Privacy Laws and in the GDPR, and, to the extent the CCPA applies, Customer is the "business" and beehiiv is Customer's "service provider" as such terms are defined in the CCPA.
Controller-to-Controller Processing; Subscriber Profiling and Data Enrichment
10. Applicability.Sections 10 through 18 of this DPA (collectively, the “Controller Sections”) apply solely to Customer's participation in beehiiv's advertising network (the “Ad Network”) and/or purchases of beehiiv data offerings (collectively, the "Enhanced Data Offerings"). If Customer does not participate in the Ad Network or purchase Enhanced Data Offerings, the Controller Sections do not apply. To the extent of any conflict between the Controller Sections and the remainder of this DPA with respect to processing in connection with the Ad Network and Enhanced Data Offerings, the Controller Sections control.
11. Controller-to-Controller Relationship.With respect to the Processing of Subscriber Profile Data (as defined below) for Ad Network and Enhanced Data Offering purposes and for purposes of providing Anonymized Audience Data to Customer, the parties acknowledge that each acts as an independent Controller as defined in the GDPR and as a “business” as defined in the CCPA. In this capacity, each party independently determines the purposes and means of its own Processing of Subscriber Profile Data and is individually and separately responsible for complying with Applicable Law. Neither party acts as the Processor or service provider of the other with respect to Subscriber Profile Data processed for Ad Network and Enhanced Data Offering purposes. The processor-to-controller framework set out in the remainder of this DPA does not apply to the Processing described in the Controller Sections.
12. Definitions. In the Controller Sections:
“Subscriber Profile Data”means data relating to Customer’s Users that beehiiv collects, derives, or enriches in connection with their interaction with Customer’s publications, including without limitation behavioral signals, engagement data, content interaction events, and demographic attributes appended through third-party data enrichment, as further described in the Terms of Use.
“Enrichment Data” means professional and demographic attributes obtained from reputable third-party data providers and appended to Subscriber Profile Data, such as industry vertical, job function, company size, seniority level, and geographic location.
“Anonymized Audience Data” means aggregated, de-identified data derived from Subscriber Profile Data that does not identify, and from which it is not reasonably practicable to re-identify, any individual data subject, produced in accordance with applicable de-identification standards under the GDPR and the CCPA.
“Enhanced Processing” means the collection, derivation, enrichment, profiling, and use of Subscriber Profile Data for the purposes of operating, optimizing, and improving the Ad Network and the Enhanced Data Offerings, including audience targeting, campaign delivery, frequency management, invalid traffic detection, performance reporting, and the production of Anonymized Audience Data for disclosure to Customer and advertisers.
13. beehiiv’s Processing Activities.Subject to Customer’s representations and warranties set out in the Terms of Use and in accordance with Applicable Law, beehiiv may, as an independent Controller, carry out the following Processing activities with respect to Subscriber Profile Data:
Profile Creation and Maintenance.Create, maintain, and update Subscriber Profile Data for Customer’s Users based on their interaction with Customer’s publications and the Services, including subscription events, content engagement, email open and click events, and other behavioral signals observed within the beehiiv platform;
Cross-Publication Behavioral Tracking.Observe and record the behavior of Customer’s Users across any of Customer’s publications hosted on the beehiiv platform (as well as any publications hosted on the beehiiv platform for other publishers) and associate such behavioral data with the applicable Subscriber Profile Data record;
Data Enrichment. Enrich Subscriber Profile Data with Enrichment Data obtained from third-party data providers in accordance with Applicable Law; and
Aggregated Audience Intelligence. Derive Anonymized Audience Data from Subscriber Profile Data for use in connection with operating, optimizing, and improving the Ad Network, the Enhanced Data Offerings and the Services.
14. Lawful Basis for Processing. beehiiv relies on the following lawful bases for Enhanced Processing:
Legitimate Interests (GDPR Article 6(1)(f)). beehiiv relies on its legitimate interests in operating and improving the Ad Network, the Enhanced Data Offerings and the Services, and in providing relevant advertising to data subjects, as the lawful basis for Enhanced Processing of Subscriber Profile Data of data subjects in the European Economic Area, the United Kingdom, and Switzerland. beehiiv has conducted and will maintain a legitimate interests assessment (LIA) and has determined that its legitimate interests are not overridden by the fundamental rights and freedoms of data subjects, taking into account the anonymization safeguards and purpose limitations described in the Controller Sections;
Consent (where required).To the extent that Applicable Law requires consent for any Enhanced Processing activity — including in jurisdictions where opt-in consent is required for behavioral profiling or targeted advertising — beehiiv shall not carry out such Processing in respect of a data subject unless and until Customer has represented and warranted to beehiiv that the required consent has been validly obtained from that data subject in accordance with Applicable Law; and
CCPA Business Purpose.For data subjects subject to the CCPA, beehiiv processes Subscriber Profile Data as a business for its own business purposes, including the operation and improvement of the Ad Network and the Enhanced Data Offerings. beehiiv shall not “sell” or “share” Subscriber Profile Data as those terms are defined in the CCPA, except to the extent that the disclosure of Anonymized Audience Data to advertisers constitutes such a disclosure, in which case beehiiv shall comply with all applicable CCPA requirements.
15. Restrictions on Disclosure of Subscriber Profile Data.beehiiv’s disclosure of data derived from Subscriber Profile Data is subject to the following mandatory restrictions:
Anonymization Requirement.beehiiv shall not disclose any Subscriber Profile Data, or any data from which an individual data subject could be identified, to any third party, including advertisers, advertising agencies, demand-side platforms, or data brokers, except in the form of Anonymized Audience Data that has been de-identified in accordance with Applicable Law and industry-standard de-identification practices. Individual-level Subscriber Profile Data — including data that has been pseudonymized but not fully anonymized — shall not be disclosed to any third party;
Purpose Limitation.Anonymized Audience Data shall be disclosed to third parties solely for the purpose of enabling those third parties to evaluate, plan, and optimize their advertising campaigns on the Ad Network. beehiiv shall not disclose Anonymized Audience Data for any other purpose without Customer’s prior written consent;
No Re-identification. beehiiv shall not take any action intended to re-identify Anonymized Audience Data and shall implement reasonable technical measures to prevent re-identification. beehiiv shall contractually prohibit any third party that receives Anonymized Audience Data from: (i) attempting to identify individual data subjects from such data; (ii) combining such data with other data sources in a manner intended to identify individual data subjects; or (iii) using such data for any purpose other than the evaluation and optimization of Ad Network campaigns and the Enhanced Data Offerings; and
Enrichment Data Restrictions. Enrichment Data shall be incorporated into Subscriber Profile Data solely for the purposes described in the Controller Sections and shall not be separately disclosed to any third party or used for any purpose outside the Ad Network and the Enhanced Data Offerings.
16. Data Subject Rights — Enhanced Processing. As an independent Controller for Enhanced Processing, beehiiv is independently responsible for responding to data subject rights requests relating to Subscriber Profile Data that beehiiv Processes for its own purposes, including rights of access, rectification, erasure, restriction, objection, and data portability under the GDPR, and rights of access, deletion, correction, and opt-out of targeted advertising under the CCPA and U.S. State Privacy Laws. Customer and beehiiv shall cooperate in good faith to ensure that data subject rights requests are appropriately routed and fulfilled:
Customer shall promptly forward to beehiiv at [email protected] any data subject rights request that Customer receives that relates, in whole or in part, to Enhanced Processing carried out by beehiiv as Controller; and
beehiiv shall promptly notify Customer of any data subject rights request that beehiiv receives that relates to Personal Data for which Customer is the Controller, and shall forward such requests to Customer at the Designated Contact Address within five (5) days of receipt.
17. International Transfers — Controller-to-Controller. To the extent that Enhanced Processing involves a transfer of Subscriber Profile Data from Customer (as Controller and data exporter) to beehiiv (as independent Controller and data importer) from the European Economic Area, the United Kingdom, or Switzerland to the United States, Module 1 (Controller-to-Controller) of the Standard Contractual Clauses is hereby incorporated by reference into this DPA as Schedule C and shall apply to such transfers, completed as follows:
Customer is the data exporter and beehiiv is the data importer;
The contact information for the parties is as set forth in Schedule A;
The categories of data subjects are Customer’s Users as described in Schedule A;
The categories of Personal Data transferred are Subscriber Profile Data, including behavioral engagement data and, following enrichment, Enrichment Data as described in the Controller Sections;
The purpose of the transfer is Enhanced Processing as defined in the Controller Sections;
The competent supervisory authority and governing law provisions are as set forth in Schedule A; and
The technical and organisational security measures are as set forth in Schedule B.
With respect to transfers governed by UK Data Protection Law or the Swiss FADP, the UK SCC Addendum and Swiss FADP modifications set out in the Data Transfers section of this DPA shall apply to the Module 1 Standard Contractual Clauses incorporated in the Controller Sections, mutatis mutandis.
18. Effect of Termination on Enhanced Processing.Upon termination or expiration of Customer’s participation in both the Ad Network and the Enhanced Data Offerings, beehiiv’s rights to carry out new Enhanced Processing with respect to Customer’s Users shall terminate. beehiiv may, following termination, continue to use previously collected and derived Subscriber Profile Data solely in Anonymized Audience Data form as permitted by Applicable Law and beehiiv’s data retention policies. beehiiv shall, upon Customer’s written request submitted within thirty (30) days of termination of both Ad Network and the Enhanced Data Offerings participation, delete or cease active use of Subscriber Profile Data that has not been anonymized, and shall provide certification of such deletion upon request.
Confidentiality and Training
19. beehiiv will ensure that the persons beehiiv authorizes to Process the Personal Data are contractually required to maintain the confidentiality of such data.
Security
20. beehiiv will comply with its security obligations under Applicable Law. beehiiv will assist Customer in Customer's compliance with such obligations by implementing the measures set forth in Schedule B. beehiiv may, without notice to Customer, make future replacements or updates to the measures that do not materially lower the level of security provided for the Personal Data. beehiiv is not responsible for any losses that arise from Customer's failure to use optional security features or optional security configurations of the Services.
Subprocessors
21. beehiiv may subcontract the collection or other Processing of Personal Data (i) only in compliance with Applicable Law regarding subprocessing, (ii) only with Customer's consent and (iii) only if beehiiv has imposed contractual obligations on the Subprocessor that are substantially the same as, or more restrictive than, those imposed on beehiiv under this DPA.
22. Current Subprocessors are listed at subprocessors.beehiiv.com/sub-processor-list. Customer consents to all Subprocessors on such list as of the date this DPA is entered into between the Parties. Unless exigent circumstances require the use of a new Subprocessor with the earlier Processing of Personal Data, beehiiv will notify Customer ("Subprocessor Notification") at least 15 days prior to giving the Subprocessor access to the Personal Data (the "Subprocessor Notification Period") by (i) updating that webpage and (ii) if Customer has subscribed on that page to email notifications, by emailing a notification to the email address supplied there by Customer.
23. Customer's sole recourse if it objects to a Subprocessor will be to terminate Customer's subscription to the Services within ten (10) days from the date of the Subprocessor Notification. Following such termination, Customer will be entitled to a refund of unused prepaid fees only if (a) beehiiv breached its obligation to maintain the requisite contract provisions with the Subprocessor, (b) beehiiv breached its obligation to conduct an annual security review of the Subprocessor, or (c) the Agreement otherwise provides for a refund. This is without prejudice to any right Customer may have under the Agreement to termination for breach of contract. Customer is deemed to consent to the new Subprocessor if Customer does not terminate the subscription as set forth above.
24. beehiiv remains liable for its Subprocessors' acts and omissions to the same extent beehiiv is liable for its own, consistent with the limitations of liability set forth in the Agreement.
Assistance Responding to Individuals' Requests to Exercise Rights
25. Customer authorizes beehiiv to honor individuals' requests to unsubscribe from Customer's mailing lists that are operated through the Services. beehiiv shall reflect the unsubscribe action within the Services. Nothing herein shall require beehiiv to send an email to an individual whom beehiiv reasonably believes has unsubscribed from such email.
26. Other than routine unsubscribe requests, which beehiiv may handle as set forth in the preceding section, if beehiiv receives a request from an individual or their representative for Customer to honor Personal Data-related rights under Applicable Law (a "Data Subject Request"), such as rights to access, correct, or delete their Personal Data, or a Personal Data-related complaint from an individual or their representative, and the communication identifies Customer, beehiiv will forward the communication to Customer at the Designated Contact Address:
a. as soon as commercially practicable; but
b. no later than within 5 days of receipt if the communication arrives via [email protected] or any other contact method specified in the privacy policy on beehiiv’s website.
27. Customer will be responsible for lawfully addressing the Data Subject Request, and beehiiv will provide prompt, reasonable cooperation to Customer, taking into account the nature of the Services, and the information available to beehiiv.
Personal Data Breach Notification
28. beehiiv will comply with the Personal Data Breach-related obligations applicable to it under Applicable Law. beehiiv will assist Customer in complying with those applicable to Customer by informing Customer of a confirmed Personal Data Breach without undue delay and in any event within 72 hours of becoming aware and by otherwise complying with this "Personal Data Breach Notification" section of the DPA.
29. beehiiv will provide such notification to Customer at the Designated Contact Address.
30. Such notification is not an acknowledgement of fault or responsibility. The notification will include beehiiv’s then-current assessment of the following:
a. The nature of the Personal Data Breach including, where possible, the categories and approximate number of data subjects concerned and the categories and approximate number of Personal Data records concerned;
b. The likely consequences of the Personal Data Breach; and
c. Measures taken or proposed to be taken by beehiiv to address the Personal Data Breach including, where applicable, measures to mitigate its possible adverse effects.
Assistance with DPIAs and Consultation with Supervisory Authorities
31. beehiiv will provide reasonable assistance to and cooperation with Customer, taking into account the nature of the Services and information available to beehiiv for (i) Customer's performance of any data protection impact assessment of the Processing or proposed Processing of the Personal Data involving beehiiv, and (ii) related consultation with supervisory authorities.
Data Return and Destruction
32. beehiiv will destroy all Personal Data within 30 days after the termination of this Agreement except to the extent Applicable Law requires storage of the Personal Data.
33. In the event of legally required retention, (i) beehiiv will retain Personal Data only as required by Applicable Law and will retain it only as long as is required, (ii) during the retention period, beehiiv will refrain from Processing the Personal Data other than as required by Applicable Law and will continue to comply with this DPA with respect to the Personal Data, to the extent permitted by Applicable Law, and (iii) beehiiv will promptly destroy the Personal Data when Applicable Law no longer requires its retention.
34. beehiiv will provide certification of the destruction upon request.
Compliance Verification and Audits
35. beehiiv will make available to Customer all information necessary to demonstrate compliance with the audit and information obligations imposed on processors under Article 28 of GDPR ("Article 28 Requirements"). To this end, beehiiv will provide written responses to all reasonable requests for information made by Customer, including responses to information security and audit questionnaires that are necessary to confirm beehiiv’s compliance with Article 28 Requirements, provided that Customer may not exercise this right more than once during any twelve (12) month period. If the requested audit scope is addressed in an industry-standard report issued by an independent third party auditor or security tester within the then-prior 12 months, and beehiiv provides a summary of such report to Customer and confirms that there are no known material changes in the controls audited or tested, Customer agrees to accept the findings presented in the summary report in lieu of requesting an audit of the same controls covered by the report. Nothing herein will require beehiiv to disclose or make available: (i) any data of any other customer of beehiiv; (ii) access to systems; (iii) beehiiv’s internal accounting or financial information; (iv) any trade secret of beehiiv; (v) any information or access that, in beehiiv’s reasonable opinion, could (a) compromise the security of beehiiv systems or premises; or (b) cause beehiiv to breach its obligations under applicable law or applicable contracts; or (vi) any information sought for any reason other than the good faith fulfilment of Customer’s obligations under Applicable Law to audit compliance under this DPA.
36. Any information that Customer receives under this Section is Confidential Information of beehiiv.
Data Transfers
37. Customer authorizes beehiiv to make international transfers of the Personal Data only if (i) Applicable Law for such transfers is respected and (ii) the transfer is otherwise permitted by this DPA.
38. To the extent legally required, the Standard Contractual Clauses form part of this DPA and take precedence over the rest of this DPA to the extent of any conflict, and, except as set forth further below in this Section, they will be deemed completed as follows:
a. Customer, the exporter, acts as a controller and beehiiv, the importer, acts as Customer’s processor with respect to the Personal Data subject to the Standard Contractual Clauses, and its Module 2 applies. Their contact information is set forth in Schedule A.
b. Clause 7 (the optional docking clause) is included.
c. Under Clause 9 (Use of sub-processors), the parties select Option 2 (General written authorization). The initial list of sub-processors is set forth at subprocessors.beehiiv.com/sub-processor-list, and beehiiv shall update that list at least 5 days in advance of any intended additions or replacements of sub-processors.
d. Under Clause 11 (Redress), the optional requirement that data subjects be permitted to lodge a complaint with an independent dispute resolution body does not apply.
e. Under Clause 17 (Governing law), the parties choose Option 1 (the law of an EU Member State that allows for third-party beneficiary rights). The parties select the law of Ireland.
f. Under Clause 18 (Choice of forum and jurisdiction), the parties select the courts of Ireland.
g. Annexes I and II of the Standard Contractual Clauses are set forth in Schedule A of the DPA.
h. Annex III of the Standard Contractual Clauses (List of subprocessors) is available at subprocessors.beehiiv.com/sub-processor-list.
39. With respect to Personal Data for which UK Data Protection Law governs the transfer, to the extent legally required, the UK SCC Addendum forms part of this DPA and takes precedence over the rest of this DPA to the extent of any conflict and shall be deemed completed as follows (with capitalized terms not defined elsewhere having the definition set forth in the UK SCC Addendum):
a. Table 1 of the UK SCC Addendum: The Parties, their details, and their contacts are those set forth in Schedule A.
b. Table 2 of the UK SCC Addendum: the "Approved EU Standard Contractual Clauses" shall be the Standard Contractual Clauses as set forth in the preceding Section of this DPA.
c. Table 3 of the UK SCC Addendum: Annexes I(A), I(B), and II are in Schedule A of the DPA, and Annex III is at subprocessors.beehiiv.com/sub-processor-list.
d. Table 4 of the UK SCC Addendum: neither party may exercise the right set forth in Section 19 of the UK SCC Addendum.
40. With respect to Personal Data for which the Swiss FADP governs the transfer, the Standard Contractual Clauses have the following differences to the extent required by the Swiss FADP:
a. References to the GDPR in the Standard Contractual Clauses are to be understood as references to the Swiss FADP insofar as the data transfers are subject exclusively to the Swiss FADP and not to the GDPR.
b. The term "member state" in Standard Contractual Clauses shall not be interpreted in such a way as to exclude data subjects in Switzerland from the possibility of suing for their rights in their place of habitual residence (Switzerland) in accordance with Clause 18(c) of the Standard Contractual Clauses.
c. Under Annex I(C) of the Standard Contractual Clauses (Competent supervisory authority):
i. Where the transfer is subject exclusively to the Swiss FADP and not the GDPR, the supervisory authority is the Swiss Federal Data Protection and Information Commissioner.
ii. Where the transfer is subject to both the Swiss FADP and the GDPR, the supervisory authority is the Swiss Federal Data Protection and Information Commissioner insofar as the transfer is governed by the Swiss FADP, and the supervisory authority is as set forth in the Standard Contractual Clauses insofar as the transfer is governed by the GDPR.
* * *
Schedule A
Annexes I and II of the Standard Contractual Clauses
ANNEX I
A. LIST OF PARTIES
MODULE TWO: Transfer controller to processor
Data exporter(s):
Name: Customer, as specified in the Agreement.
Address: as provided by Customer in connection with entering into the Agreement.
Contact person's name, position and contact details: as set forth in the Agreement
Activities relevant to the data transferred under these Clauses: Use of the importer’s Services.
Signature and date: as set forth in the Agreement.
Role (controller/processor): Controller
Data importer(s):
Name: beehiiv Inc.
Address: 228 Park Avenue S. # 29976, New York, New York 10003
Contact person’s name, position and contact details: [email protected]
Activities relevant to the data transferred under these Clauses: The importer will provide the Services.
Signature and date: as set forth in the Agreement.
Role (controller/processor): Processor
B. DESCRIPTION OF TRANSFER
MODULE TWO: Transfer controller to processor
Categories of data subjects whose personal data is transferred: Customer’s readers, listeners, website visitors, email list members and/or others to whom Customer sends content using the Services (“Customer’s Users”).
Categories of personal data transferred: The personal data of Customer’s Users may include name, email address, IP address, geo-location, device data, acquisition sources/attribution data, opens and clicks, avatar images and the responses to polls/surveys conducted by Customer using the Services. It is understood that Customer and Customer’s Users are not permitted to and shall not transfer sensitive personal information, such as social security numbers, protected health information, payment information and similar information into the Services.
Sensitive data transferred (if applicable) and applied restrictions or safeguards: Not applicable.
The frequency of the transfer: Continuous.
Nature of the processing: beehiiv provides Services as that term is defined in the purchasing agreement to which this DPA is attached.
Purpose(s) of the data transfer and further processing: Provision of the Services to Customer.
The period for which the personal data will be retained: The duration of the data processing under this DPA is during the term of the Agreement and 30 days thereafter.
For transfers to (sub-) processors, also specify subject matter, nature and duration of the processing: Provision of the Services to Customer as set forth in the DPA.
C. COMPETENT SUPERVISORY AUTHORITY
MODULE TWO: Transfer controller to processor
Identify the competent supervisory authority/ies in accordance with Clause 13: The parties shall follow the rules for identifying such authority under Clause 13 and, to the extent legally permissible, select the Irish Data Protection Commission.
ANNEX II
A. TECHNICAL AND ORGANISATIONAL MEASURES INCLUDING TECHNICAL AND ORGANISATIONAL MEASURES TO ENSURE THE SECURITY OF THE DATA
Description of the technical and organisational measures implemented by the data importer(s) to ensure an appropriate level of security: See Schedule B immediately below.
* * *
Schedule B
Information Security Addendum
beehiiv has established and agrees to maintain a written information security and privacy program (the "Information Security Program") designed to comply with this Information Security Addendum and Applicable Law.
As part of its Information Security Program, beehiiv has implemented and agrees to maintain administrative, technical, and physical security safeguards designed to protect the confidentiality, integrity, and availability of Personal Data, including but not limited to:
I. Administrative and Organizational Safeguards
a. beehiiv maintains policies and procedures for the security of Personal Data, including the following:
i. Written information security policies that set forth beehiiv’s procedures with regard to maintaining the safeguards set forth in this Information Security Addendum.
ii. An incident response plan, which sets forth beehiiv’s procedures to investigate, mitigate, remediate, and otherwise respond to security incidents.
b. beehiiv conducts regular assessments of the risks and vulnerabilities to the confidentiality and security of Personal Data.
c. beehiiv regularly tests and monitors the effectiveness of its Information Security Program, including through security audits, and will evaluate its Information Security Program and information security safeguards in light of the results of the testing and monitoring and any material changes to its operations or business arrangements.
d. beehiiv has appointed an individual to oversee and manage its Information Security Program and lead the response to any Personal Data Breach.
e. beehiiv maintains role-based access restrictions for its systems, including restricting access to only those beehiiv staff members that require access to perform the beehiiv Services or to facilitate the performance of such beehiiv Services, such as system administrators, consistent with the concepts of least privilege, need-to-know, and separation of duties.
f. beehiiv periodically reviews its access lists to ensure that access privileges have been appropriately provisioned and regularly reviews and terminates access privileges for beehiiv staff that no longer need such access.
g. beehiiv assigns unique usernames to authorized beehiiv staff and requires that beehiiv staff’s passwords satisfy minimum length and complexity requirements.
h. beehiiv regularly provides training to staff, as relevant for their roles, on confidentiality and security.
i. beehiiv requires relevant beehiiv staff to acknowledge beehiiv’s Information Security Program annually.
j. beehiiv has a policy in place to address violations of its Information Security Program.
II. Technical Security
a. beehiiv logs certain system activity—including authentication events, changes in authorization and access controls.
b. beehiiv maintains network security measures, including but not limited to firewalls, to segregate its internal networks from the internet, risk-based network segmentation, and anti-virus and malware protection software.
c. beehiiv has implemented workstation protection policies for its systems, including automatic logoff after a period of inactivity and locking the system after a defined number of incorrect authentication attempts.
d. beehiiv requires multi-factor authentication on key systems for workforce members acting as administrative users.
e. beehiiv conducts periodic vulnerability scans and assessments on systems storing, processing, or transmitting Personal Data to identify potential vulnerabilities and risks to Personal Data.
f. beehiiv remediates identified vulnerabilities in a risk-prioritized manner, including manufacturer- and developer-recommended security updates and patches to systems and software storing, transmitting, or otherwise Processing Personal Data.
III. Physical Security
a. beehiiv manages software on its computers and tracks the location of its equipment. beehiiv evaluates and assesses the physical security controls implemented by its sub-processors that supply critical infrastructure in physical spaces. These assessments are conducted through review of third-party audit reports, independent penetration testing results, facility architecture diagrams, and other documentation evidencing the physical security posture of such sub-processors’ facilities.
* * *
Schedule C
Module 1 (Controller-to-Controller) Standard Contractual Clauses — Ad Network Transfers
The Module 1 (Controller-to-Controller) Standard Contractual Clauses issued pursuant to EU Commission Implementing Decision (EU) 2021/914 are incorporated by reference into this DPA pursuant to the Controller Sections above. The full text of Module 1 is available at http://data.europa.eu/eli/dec_impl/2021/914/oj. The completion details for Module 1 are as set forth in the Controller Sections above. To the extent of any conflict between the Module 1 Standard Contractual Clauses and this Schedule C, the Module 1 Standard Contractual Clauses shall prevail.
* * *