Legal · DPA
Data Processing Addendum.
This Data Processing Addendum ("DPA") forms part of the Terms of Service between Riley Ventures LLC ("data.cool") and each owner, and each buyer to the extent data.cool processes personal data for it. It applies whenever data.cool processes personal data contained in a Dataset ("Dataset Personal Data") and takes effect when you accept the Terms.
Effective October 7, 2026 · Last updated October 7, 2026
1. Roles and scope
- Owner as controller. For Dataset Personal Data, the owner is the controller (or "business") and data.cool is its processor (or "service provider" or "contractor").
- Buyer as independent controller. A buyer that receives licensed data is an independent controller of it, bound by the Buyer (Lab) Terms. Where data.cool processes data for a buyer (for example, hosting a delivery), it does so as the buyer's processor under this DPA.
- data.cool as controller. For account, verification and billing data about users, data.cool is a controller under its Privacy Policy, and this DPA does not apply.
- Details of processing. Subject matter: vetting, de-identifying, sampling, delivering and deleting Datasets. Duration: the life of the listing and any license, plus the deletion periods below. Data subjects: the owner's employees, customers, contractors and correspondents. Categories: names, contact details, communications content, CRM and ticket records, call recordings and transcripts, and other business records. Special-category data is not permitted except through the Clean Room intake and screening.
2. Instructions
data.cool processes Dataset Personal Data only on the owner's documented instructions: the Terms, the Seller Terms, the owner's Mandate and listing choices, and its disclosure-mode election. We will tell the owner if we believe an instruction breaks the law. Under the CCPA, we will not sell or share Dataset Personal Data other than as instructed, retain, use or disclose it outside the direct business relationship with the owner, or combine it with other personal data except as the law allows; we certify that we understand these restrictions.
3. Confidentiality of personnel
Only personnel who need access to perform the services may access Dataset Personal Data. They are bound by confidentiality obligations, use named accounts, and every reveal of identity is logged.
4. Security
data.cool maintains technical and organizational measures appropriate to the risk, including:
- AES-256-GCM encryption at rest for identity fields, keyed blind indexes, and TLS in transit;
- row-level security, least-privilege service keys and named staff accounts;
- access logging of identity reveals and Clean Room downloads;
- de-identification with consistent pseudonyms, residual-risk measurement, watermarked short-lived downloads;
- scheduled purging of Clean Room originals and of identity on ended listings.
We review these measures periodically and may update them if the overall level of protection is not reduced.
5. Subprocessors
The owner authorizes data.cool to use the subprocessors listed on the Subprocessors page. We bind each by written terms at least as protective as this DPA and remain responsible for them. We will update that page at least 14 days before adding or replacing a subprocessor that processes Dataset Personal Data; an owner may object on reasonable data-protection grounds by emailing privacy@data.cool, and if we cannot resolve the objection, the owner may withdraw the affected listing without penalty.
6. Personal data breach
data.cool will notify the owner without undue delay, and in any case within 72 hours, after becoming aware of a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, Dataset Personal Data. The notice will describe the breach, likely consequences, and measures taken, as far as known, with updates as we learn more. Notice is not an admission of fault.
7. Assistance
Taking into account the nature of processing, data.cool will help the owner respond to data-subject requests, carry out data protection impact assessments and consult regulators. We will forward any data-subject request we receive about a Dataset to the owner and not respond to it except on the owner's instruction or as the law requires.
8. Deletion and return
When a listing is withdrawn, rejected or expires, or on the owner's written request, data.cool will delete Dataset Personal Data and identity data on its standard schedule (Clean Room originals within about 30 days; listing identity as the Privacy Policy states), unless the law requires us to keep it. Licensed data already delivered to a buyer is governed by the Buyer Terms, which require deletion when a license ends. On request before deletion, we will return Clean Room outputs to the owner.
9. Audits
On written request no more than once a year (or after a breach, or when a regulator requires), data.cool will provide information needed to demonstrate compliance with this DPA, such as written responses to security questionnaires and summaries of our controls. If that is not enough, the owner may conduct an audit, at its own cost, on 30 days' notice, during business hours, under confidentiality, and without access to other customers' data.
10. International transfers
data.cool and its subprocessors process data in the United States. For transfers of personal data from the EEA, the parties incorporate the Standard Contractual Clauses adopted by Commission Implementing Decision (EU) 2021/914, Module Two (controller to processor), with Clause 7 included, Clause 9 option 2 with the notice period in section 5, the Clause 11 optional language omitted, Clause 17 and 18 governed by and before the courts of Ireland, and Annexes completed by section 1 and section 4 of this DPA. For the UK, the International Data Transfer Addendum issued by the Information Commissioner applies; for Switzerland, the SCCs apply with the Federal Act on Data Protection in place of the GDPR where relevant. If these clauses conflict with this DPA, the clauses control.
11. Liability and precedence
Each party's liability under this DPA is subject to the limitation of liability in the Terms of Service, to the extent permitted by law. For personal data, this DPA controls over the Terms of Service.
Riley Ventures LLC, a Florida limited liability company, 1615 S Congress Ave, Ste 103, Delray Beach, FL 33445. Questions: privacy@data.cool. All legal documents: /legal.