Version:

1.3

Document ID: LG-DPA-001 Version: 1.3 Adopted: 2026-07-31 (v1.0); revised 2026-07-31 (v1.1); revised 2026-08-03 (v1.2); revised 2026-08-03 (v1.3) Changelog v1.1: Adversarial-review revision — contracting entity corrected to Label Grid, LLC (mirrors ToS); binding-formation and SCC third-party-beneficiary preservation added to the delivery form; Customer Personal Data definition extended to received/generated data; call-record and dual-purpose-copy treatment clarified; prohibited-data duties made continuing; DSP clause aligned with SCC Clause 8.8 (onward-transfer record, blanket disclaimer removed); Article 3 SCC-availability clause added; UK Addendum completed with the ICO mandatory-clauses incorporation and explicit Tables 1–4; Swiss adaptation restated as qualified substitution (natural persons only); documented TIA/TRA commitment added; breach notice re-triggered on awareness (72-hour outside limit, no investigation delay); audit exceptions for breach/authority/credible-noncompliance added; return/deletion rewritten (all data categories, deletion default, export deadlines, backup purge, no recharacterization of legally retained data, SCC continuity); SCC liability carve-outs from the Principal Agreement cap; sole-remedy clause made subject to non-waivable SCC rights; Annex I/II made executable per customer via the Execution Page; Annex II TOMs made specific and objective; Korea Rider completed (onward recipients, refusal method, direct PIPA duties, suspension of processing); U.S. State Privacy Rider added as Annex V. Changelog v1.2: Assurance-gate revision ahead of signing-template adoption — Promo.ly and eSignatures.io removed from Annex III as non-sub-processors (owner ruling 2026-08-03: Promo.ly is a destination to which a user may choose to export data, all processing there being Promo.ly’s own; eSignatures.io serves LabelGrid’s own execution of its agreements and is therefore a LabelGrid-side matter; each remains disclosed in the LabelGrid Privacy Policy), with their role-scoping removed from the Annex III note; Annex IV onward-recipient countries restated as the United States, the European Union, and the United Kingdom, superseding the 2026-08-01 amendment that had added Australia for eSignatures.io; Stripe entity corrected to Stripe, LLC; Annex III expanded toward SCC Annex III completeness with each Sub-processor’s registered or legal address and published privacy contact point, and with the subject matter, nature, and duration of each sub-processing stated expressly; Section 11.6 deletion certificate qualified by reference to data specifically identified as retained under Section 11.5, with final deletion certified after the legal retention requirement lapses; Section 7.3(d) restated in the ICO template’s Table 4 selection form (Importer and Exporter); Section 2.5 prohibited-data provision made without prejudice to obligations under the SCCs or Data Protection Laws that cannot be excluded by agreement; Annex V processor-contract citation narrowed to C.R.S. § 6-1-1305(5). Errata 2026-08-03: importer address line completed with ZIP 80203 (both occurrences). Changelog v1.3: Single-signer conversion (owner directive 2026-08-03 — LabelGrid executes every instrument by issuance and does not countersign) — Delivery Form route (b) restated as a standalone copy issued for signature at Customer’s request, executed by Label Grid, LLC on issuance, with the Customer-signed copy serving as the parties’ executed record; the annex route stated expressly to be executed by issuance of the Advanced Services Addendum signature envelope; an express execution-by-issuance clause added to the Execution Page and to Section 13.6 (counterparts), mirroring the Mutual NDA’s Section 16.6; the Execution Page signature block reduced to a customer-only block, removing the Label Grid, LLC signature column together with the `labelgrid_signatory_name` and `labelgrid_signatory_title` placeholders (written here without their braces so the send-time gate, which derives the required Execution-Page key set by scanning this document for placeholders, does not keep demanding two fields the document no longer renders); Sections 7.2(g), 7.3 and Annex I.A restated so that LabelGrid’s issuance is its signature of SCC Annex I and its acceptance of the UK Addendum and Customer’s signature completes execution — both parties’ signature of Annex I is therefore effected without any countersignature.

Delivery form. For customers executing the LabelGrid Advanced Services Addendum (API and Engine customers), this Data Processing Agreement is executed as an annex included in the same signature envelope as the Addendum, with the Execution Page and Annexes completed for that customer: LabelGrid executes it by issuing that envelope for signature, and Customer’s signature of the envelope completes execution of both instruments, no countersignature being required (Section 13.6). For all other customers, this Data Processing Agreement — as published at labelgrid.com/legal/dpa in the version identified above — forms part of the parties’ agreement upon the earlier of: (a) Customer’s acceptance of a version of the LabelGrid Terms of Service that incorporates this DPA by reference; and (b) Customer’s signature of a standalone copy that LabelGrid has issued for signature at Customer’s request, with the Execution Page completed; LabelGrid executes that copy by issuing it, no countersignature is required, and the Customer-signed copy serves as the parties’ executed record for the purposes of the SCCs. LabelGrid retains the version of this DPA in effect for each customer. The parties agree that no entire-agreement or no-third-party-beneficiary provision of the Principal Agreement excludes this DPA or the rights of data subjects as third-party beneficiaries under the SCCs, which are expressly preserved.


This Data Processing Agreement (the ”DPA”) forms part of the agreement for LabelGrid services between:

Label Grid, LLC, a limited liability company with its headquarters in Denver, Colorado, United States of America (”LabelGrid”, the ”Processor”); and

{{customer_legal_name}}, {{customer_entity_type_and_jurisdiction}}, with registered address at {{customer_registered_address}}, registration number {{customer_registration_number}} (”Customer”),

each a ”party” and together the ”parties”.

This DPA is effective as of {{effective_date}} (the ”Effective Date”) or, if earlier, the date the principal agreement between the parties takes effect.

1. Definitions

1.1 ”Principal Agreement” means the agreement under which LabelGrid provides the Services to Customer: the LabelGrid Terms of Service and, where executed, the Advanced Services Addendum, together with any order form or Schedule A thereunder.

1.2 ”Services” means the LabelGrid music distribution, royalty, analytics, and API/Engine services provided to Customer under the Principal Agreement.

1.3 ”Data Protection Laws” means all laws applicable to the processing of personal data under this DPA, including, to the extent applicable: Regulation (EU) 2016/679 (the ”GDPR”); the GDPR as incorporated into the law of the United Kingdom (the ”UK GDPR”) and the UK Data Protection Act 2018; the Swiss Federal Act on Data Protection (the ”FADP”); the Personal Information Protection Act of the Republic of Korea (the ”PIPA”); and applicable US state privacy laws, including the California Consumer Privacy Act as amended (the ”CCPA”) and the Colorado Privacy Act (see Annex V).

1.4 ”Customer Personal Data” means personal data described in Annex I that Customer (or a person acting on its behalf, or a controller for which Customer acts as processor) submits to the Services, or that LabelGrid receives or generates in the course of providing the Services and processes on Customer’s behalf — including DSP-supplied analytics records processed for Customer, to the extent they constitute personal data in LabelGrid’s hands. Customer Personal Data does not include the Excluded Data described in Section 2.4.

1.5 ”Standard Contractual Clauses” or ”SCCs” means the standard contractual clauses for the transfer of personal data to third countries adopted by the European Commission in Implementing Decision (EU) 2021/914.

1.6 ”UK Addendum” means the International Data Transfer Addendum to the EU Commission Standard Contractual Clauses issued by the UK Information Commissioner’s Office, version B1.0, in force 21 March 2022, as amended.

1.7 ”Sub-processor” means a third party engaged by LabelGrid to process Customer Personal Data on Customer’s behalf in connection with the Services.

1.8 The terms ”controller”, ”processor”, ”data subject”, ”personal data”, ”personal data breach”, ”processing”, and ”supervisory authority” have the meanings given in the GDPR, and equivalent terms under other Data Protection Laws are construed accordingly.

2. Scope, Roles, and Excluded Data

2.1 Roles. With respect to Customer Personal Data, Customer is the controller and LabelGrid is the processor; or, where Customer is itself a processor acting on behalf of one or more third-party controllers (including where Customer operates a white-label or reseller service on the LabelGrid Engine), Customer acts as processor and LabelGrid acts as Customer’s sub-processor, and references in this DPA to Customer’s instructions include the documented instructions of the relevant controllers passed through by Customer. Customer’s capacity for each data set is recorded on the Execution Page (Module Two / Module Three mapping).

2.2 Customer warranty of authority. Where Customer acts as processor, Customer represents and warrants that: (a) it is authorized by each relevant controller to engage LabelGrid as a sub-processor on the terms of this DPA and to agree to the international transfer mechanisms in Section 7 on that controller’s behalf; (b) its own contract with each relevant controller imposes data-protection obligations no less protective than this DPA; (c) the instructions it passes to LabelGrid are the lawful, documented instructions of the relevant controller; and (d) it will promptly relay to the relevant controllers all information and notifications that LabelGrid provides under this DPA. Customer remains fully responsible to LabelGrid for the acts and omissions of the controllers on whose behalf it acts, to the extent set out in the Principal Agreement’s liability terms.

2.3 Processor-scope data only. This DPA governs only the processing of Customer Personal Data — the categories described in Annex I, being: catalog metadata (including personal data of artists, contributors, and writers); royalty payee data processed for royalty computation and payment on Customer’s behalf; analytics personal data, if and to the extent any analytics record constitutes personal data in LabelGrid’s hands; support ticket data relating to Customer’s staff; and, for Engine customers, end-user data of Customer’s partners or clients as submitted to the Services. The permitted categories of Customer Personal Data are capped by contract as set out in Annex I; Customer must not submit categories of personal data outside Annex I without LabelGrid’s prior written agreement.

2.4 Excluded Data — independent controller carve-out. The following data is processed by LabelGrid as an independent controller for its own purposes (contract administration, billing, security, fraud and abuse prevention, record-keeping and confidentiality compliance, and compliance with its own legal obligations, including tax reporting, anti-money-laundering, and sanctions screening) and is expressly excluded from this DPA (”Excluded Data”): (a) Customer account and credential data, including logins, account emails, billing contacts, and IP/access logs; (b) KYC/KYB documents and identity-verification records; (c) tax, AML, and sanctions-screening records; and (d) recordings, transcripts, consent records, and disclosure logs of calls conducted under LabelGrid’s confidential-disclosure and call practices and the parties’ NDA or Addendum confidentiality terms, which LabelGrid processes for record-keeping, confidentiality-compliance, and dispute-resolution purposes. Excluded Data is governed by the LabelGrid Privacy Policy, available at labelgrid.com/privacy-policy, and not by this DPA. Nothing in this DPA is to be read as making LabelGrid a processor with respect to Excluded Data. Where the same data element exists in both a processor-scope record and an Excluded Data record (for example, an email address appearing in a royalty payout record and in a billing contact record), each copy is governed by the regime applicable to the record in which it resides and the purpose for which that copy is processed.

2.5 Prohibited data. The Services are not designed for, and Customer must not submit: (a) special categories of personal data within the meaning of Article 9 GDPR (or equivalent categories under other Data Protection Laws), or personal data relating to criminal convictions and offences; or (b) personal data of children where the processing would require parental consent under applicable law. If such data is nevertheless submitted, the obligations of Sections 4 (confidentiality), 5 (security), and 9 (breach) of this DPA continue to apply to it for as long as it is in LabelGrid’s systems; LabelGrid may quarantine such data on discovery and, after notice to Customer, securely delete it, and LabelGrid has no other obligation under this DPA to support its processing, without prejudice to any obligation under the SCCs or applicable Data Protection Laws that cannot be excluded by agreement.

3. Processing on Documented Instructions

3.1 LabelGrid will process Customer Personal Data only on Customer’s documented instructions, including with regard to transfers of personal data to a third country, unless required to do so by law to which LabelGrid is subject; in that case LabelGrid will inform Customer of that legal requirement before processing, unless the law prohibits such information on important grounds of public interest.

3.2 Customer’s documented instructions are: (a) this DPA; (b) the Principal Agreement; (c) Customer’s use and configuration of the Services, including each distribution, delivery, takedown, and payout instruction submitted through the Services or the API; and (d) any further written instructions agreed between the parties. LabelGrid will inform Customer if, in its opinion, an instruction infringes Data Protection Laws; LabelGrid may suspend performance of that instruction until it is confirmed or modified.

3.3 Delivery to DSPs. Delivery of Customer’s catalog, metadata, and associated content to digital service providers, stores, and platforms (”DSPs”) is performed on and constitutes part of Customer’s documented instruction, including for the purposes of Clause 8.8 of the SCCs where they apply. Each DSP receives that data as an independent controller acting under its own terms and for its own purposes; DSPs are not Sub-processors of LabelGrid. Where the SCCs apply and a delivery on Customer’s instruction constitutes an onward transfer to a third country, LabelGrid makes the disclosure in accordance with Clause 8.8: LabelGrid maintains a record of DSP recipients, their countries, the categories of data delivered, and the applicable onward-transfer ground for each (an adequacy decision, the DSP’s execution of or accession to appropriate safeguards, or another ground permitted by Clause 8.8), and will make that record available to Customer on reasonable request. LabelGrid is not responsible under this DPA for a DSP’s own processing of data lawfully delivered to it on Customer’s instruction, without prejudice to LabelGrid’s obligations under Clause 8.8 where the SCCs apply.

4. Confidentiality of Personnel

LabelGrid ensures that all persons it authorizes to process Customer Personal Data are bound by written confidentiality obligations or are under an appropriate statutory obligation of confidentiality, and process Customer Personal Data only as needed to perform the Services.

5. Security

5.1 LabelGrid implements and maintains the technical and organizational measures set out in Annex II (”TOMs”), which take into account the state of the art, the costs of implementation, and the nature, scope, context, and purposes of processing, so as to ensure a level of security appropriate to the risk, including protection against accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to Customer Personal Data.

5.2 LabelGrid may update the TOMs from time to time, provided the updates do not materially reduce the overall level of protection of Customer Personal Data.

6. Sub-processors

6.1 General written authorization. Customer grants LabelGrid general written authorization to engage Sub-processors for the processing of Customer Personal Data. LabelGrid’s current Sub-processors are listed at labelgrid.com/legal/subprocessors; the list as at the Effective Date is reproduced in Annex III.

6.2 Advance notice. LabelGrid will give Customer at least 30 days’ advance notice by email of any intended addition or replacement of a Sub-processor, identifying the Sub-processor, its role, and its processing location, thereby giving Customer the opportunity to object.

6.3 Objection. Customer may object to an intended addition or replacement within the notice period on reasonable, documented data-protection grounds. On receipt of an objection, the parties will discuss in good faith a resolution (for example, a configuration change or an alternative Sub-processor). If no resolution is reached within 30 days of the objection, Customer may terminate the affected Service (only) on written notice, and LabelGrid will refund any prepaid fees for the terminated Service pro-rated to the unused period. Such termination and refund is Customer’s sole and exclusive remedy for an unresolved Sub-processor objection, without prejudice to any non-waivable rights of Customer under Clauses 14 and 16 of the SCCs where they apply.

6.4 Flow-down and responsibility. LabelGrid will impose on each Sub-processor, by written contract, data-protection obligations that are in substance no less protective of Customer Personal Data than those in this DPA, including appropriate security measures, and LabelGrid remains fully liable to Customer for the performance of each Sub-processor’s obligations, to the extent set out in the Principal Agreement’s liability terms and subject to Section 12.

7. International Transfers

7.1 Processing location. Customer Personal Data is processed in the United States (and in the locations of the Sub-processors listed per Section 6). Customer authorizes such processing and the associated transfers, subject to this Section 7.

7.2 EU transfers — SCCs incorporated by reference. To the extent Customer Personal Data is subject to the GDPR and is transferred to LabelGrid in the United States (or another third country without an adequacy decision), the SCCs are incorporated into this DPA by reference and apply as follows:

(a) Module Two (controller to processor) applies where Customer acts as controller; Module Three (processor to processor) applies where Customer acts as processor under Section 2.1. Customer (and, under Module Three, the relevant controllers via Customer) is the data exporter; LabelGrid is the data importer. The data sets falling under each Module are recorded on the Execution Page; absent a contrary election there, all Annex I.B categories are transferred under Module Two except Engine end-user data submitted by Customer in a processor capacity, which is transferred under Module Three.

(b) Clause 7 (docking clause) applies.

(c) Clause 9: Option 2 (general written authorization) applies, with the notice period in Section 6.2 of this DPA.

(d) Clause 11(a): the optional independent-dispute-resolution language does not apply.

(e) Clause 13 and Annex I.C: the competent supervisory authority is determined per Clause 13 and recorded on the Execution Page; where Customer is established in an EU Member State, it is the supervisory authority of that Member State.

(f) Clause 17: the SCCs are governed by the law of Ireland. Clause 18: disputes are resolved before the courts of Ireland.

(g) Annexes I, II, and III of the SCCs are completed by Annexes I, II, and III of this DPA respectively, as completed for the specific Customer by the Execution Page. Execution of this DPA (or the assent described in the Delivery Form paragraph) constitutes each party’s signature of Annex I of the SCCs: LabelGrid signs Annex I by issuing this DPA for signature — whether as an annex within the Advanced Services Addendum signature envelope or as a standalone copy — and Customer signs it by signing this DPA (Section 13.6 and the Execution Page). No countersignature by LabelGrid is required for Annex I to be signed by both parties.

(h) In the event of conflict between the SCCs and any other term of this DPA or the Principal Agreement, the SCCs prevail to the extent of the conflict.

(i) Article 3 scope. The SCCs apply to a transfer only to the extent the processing by LabelGrid as importer is not itself directly subject to the GDPR under Article 3. To the extent LabelGrid’s processing of Customer Personal Data is directly subject to the GDPR, that processing is governed by the GDPR directly together with the substantive obligations of this DPA, the SCCs do not apply to it, and the parties will implement under Section 13.4 any alternative transfer mechanism required for it by Data Protection Laws.

7.3 UK transfers. To the extent Customer Personal Data is subject to the UK GDPR, the parties enter into the UK Addendum, completed as follows:

(a) Part 1, Table 1 (Parties): completed with the parties’ details set out in the party block above, on the Execution Page, and in Annex I.A; the start date is the Effective Date; the parties’ key contacts are those stated in Annex I.A.

(b) Part 1, Table 2 (Selected SCCs, Modules and Selected Clauses): the Approved EU SCCs as incorporated into this DPA and configured in Section 7.2, including the appendix information.

(c) Part 1, Table 3 (Appendix Information): Annexes I, II, and III of this DPA, as completed by the Execution Page.

(d) Part 1, Table 4 (Ending this Addendum when the Approved Addendum Changes): Importer and Exporter — either may end this Addendum as set out in Section 19 of the Mandatory Clauses.

(e) Part 2 (Mandatory Clauses): the parties agree to be bound by the Mandatory Clauses of the Approved Addendum, being the template Addendum B.1.0 issued by the Information Commissioner and laid before Parliament in accordance with s119A of the Data Protection Act 2018 on 2 February 2022, as it is revised under Section 18 of those Mandatory Clauses.

Execution of this DPA (or the assent described in the Delivery Form paragraph) constitutes the parties’ signature and acceptance of the UK Addendum as completed above — LabelGrid by its issuance of this DPA for signature and Customer by signing it, no countersignature being required (Section 13.6).

7.4 Swiss transfers. To the extent a transfer of Customer Personal Data is governed by the FADP, the SCCs as applied under Section 7.2 apply with the following adaptations: (a) insofar as the transfer is governed by the FADP, references in the SCCs to the GDPR are read as references to the FADP; where a transfer is governed by both the GDPR and the FADP, the references to the GDPR remain in effect and these adaptations apply in parallel solely insofar as the FADP governs; (b) insofar as the transfer is governed by the FADP, the competent supervisory authority under Clause 13 and Annex I.C is the Swiss Federal Data Protection and Information Commissioner (FDPIC), without prejudice to the parallel competence of the EU supervisory authority for transfers also governed by the GDPR; (c) the term ”Member State” is read so as not to exclude data subjects in Switzerland from enforcing their rights in their place of habitual residence; and (d) references to personal data in the SCCs as so adapted refer to data of natural persons.

7.5 Korea. Where Customer or a relevant controller is subject to the PIPA, the Korea Rider at Annex IV applies in addition to this Section 7.

7.6 No DPF reliance. The parties’ transfer mechanism under this DPA is the SCCs (as adapted for the UK and Switzerland). LabelGrid does not rely on the EU-U.S. Data Privacy Framework for transfers under this DPA.

7.7 Government access; transfer impact. LabelGrid maintains a documented transfer impact assessment addressing transfers of Customer Personal Data to the United States and to the Sub-processor locations listed in Annex III — serving as the transfer impact assessment contemplated by the SCCs and the UK transfer risk assessment — reviews it on any material change in law or circumstances, and will provide Customer a summary on reasonable request, together with such further information as is reasonably necessary for Customer’s own assessment. Unless legally prohibited, LabelGrid will promptly notify Customer of any legally binding request by a public authority for access to Customer Personal Data, will review the legality of such request and challenge it where there are reasonable grounds to do so, and will disclose only the minimum amount of Customer Personal Data legally required.

7.8 US state privacy laws. Where Customer Personal Data is subject to the CCPA or another applicable US state privacy law, the U.S. State Privacy Rider at Annex V applies.

8. Assistance; Data Subject Requests

8.1 Data subject requests. Taking into account the nature of the processing, LabelGrid will assist Customer by appropriate technical and organizational measures, insofar as this is possible, in fulfilling Customer’s obligation to respond to data subjects’ requests to exercise their rights under Data Protection Laws. If LabelGrid receives a request from a data subject that identifies Customer Personal Data, LabelGrid will not respond substantively but will promptly route the request to Customer, and will inform the data subject only that the request has been forwarded to the responsible party.

8.2 Articles 32–36 assistance. Taking into account the nature of the processing and the information available to it, LabelGrid will assist Customer in ensuring compliance with Customer’s obligations under Articles 32 to 36 GDPR (security, breach notification to authorities and data subjects, data protection impact assessments, and prior consultation) and their equivalents under other Data Protection Laws.

8.3 Costs. Assistance under this Section 8 and audits under Section 10 are provided at reasonable cost: LabelGrid may charge Customer its reasonable, documented costs for assistance that is material in scope, except where the need for assistance arises from LabelGrid’s breach of this DPA.

9. Personal Data Breach

9.1 LabelGrid will notify Customer without undue delay after becoming aware of a personal data breach affecting Customer Personal Data, and in any event within 72 hours of becoming aware. LabelGrid will not delay notification pending completion of its investigation or confirmation of the breach’s full scope or root cause; information not yet available when notice is first given is provided in phases under Section 9.2.

9.2 The notification will, to the extent the information is available (and may be provided in phases as the investigation progresses), describe: (a) the nature of the breach, including where possible the categories and approximate number of data subjects and records concerned; (b) the name and contact details of LabelGrid’s contact point for further information; (c) the likely consequences of the breach; and (d) the measures taken or proposed to address the breach and mitigate its possible adverse effects — corresponding to Article 33(3) GDPR.

9.3 LabelGrid will take reasonable steps to contain and remediate the breach and will cooperate with Customer’s reasonable requests for information concerning it.

9.4 LabelGrid will not notify any supervisory authority or any data subject of a breach on Customer’s behalf, and will not make any public statement concerning a breach that identifies Customer, unless required by law applicable to LabelGrid. Whether and how to notify Customer’s supervisory authority and affected data subjects is Customer’s decision and responsibility.

10. Audit

10.1 LabelGrid will make available to Customer information reasonably necessary to demonstrate compliance with this DPA and Article 28 GDPR, and will allow for and contribute to audits, as follows.

10.2 Documentation first. Customer’s audit rights are satisfied in the first instance by LabelGrid providing, on written request: (a) its then-current documentation of the TOMs; (b) summaries of relevant third-party certifications or audit reports, where available; and (c) written responses to a reasonable security and data-protection questionnaire, no more than once per 12-month period.

10.3 On-site audit. Where the responses under Section 10.2 are demonstrably insufficient to verify compliance, or where an audit is required of Customer by a supervisory authority, Customer (or an independent auditor mandated by it that is not a competitor of LabelGrid) may conduct an on-site audit of LabelGrid’s relevant processing operations, subject to all of the following: no more than once per 12-month period; at least 30 days’ prior written notice; during normal business hours; under written confidentiality obligations; without access to other customers’ data or to information whose disclosure would compromise LabelGrid’s security; and with minimal disruption to LabelGrid’s operations. Customer bears the costs of any audit, including LabelGrid’s reasonable costs of supporting it, except to the extent the audit reveals a material breach of this DPA by LabelGrid.

10.4 Exceptions. Notwithstanding the frequency and notice limits in Sections 10.2 and 10.3, Customer may conduct (or mandate) an audit in addition to the once-per-12-month limit and on shorter notice where: (a) a personal data breach affecting Customer Personal Data has occurred within the preceding 12 months; (b) a competent supervisory authority requires an audit or inspection; or (c) Customer has documented, credible grounds to believe LabelGrid is in material breach of this DPA — in each case with as much prior notice as is reasonably practicable in the circumstances, and otherwise subject to the conditions in Section 10.3. Nothing in this Section 10 limits the powers of a competent supervisory authority under applicable Data Protection Laws.

10.5 This Section 10 is without prejudice to the audit rights under Clause 8.9 of the SCCs where the SCCs apply; the parties agree that audits under the SCCs will be conducted in accordance with the procedure in this Section 10 to the extent permitted.

11. Return and Deletion

11.1 Scope. This Section 11 applies to all Customer Personal Data in all categories described in Annex I — catalog, royalty payee, analytics, support, and Engine end-user data — including copies held by Sub-processors.

11.2 Election; deletion by default. On termination or expiry of the Principal Agreement, Customer may elect in writing return (via the exit export), deletion, or return followed by deletion. If Customer makes no election within 30 days of termination, deletion under Section 11.4 is the default.

11.3 Return — structured exit export. Return is performed through LabelGrid’s structured exit export: a machine-readable export of Customer’s catalog masters, artwork, and metadata (including the personal data embedded in catalog and royalty records), made available to Customer in accordance with the offboarding provisions of the Principal Agreement, together with, on request, a machine-readable export of the other categories of Customer Personal Data in Annex I that are reasonably capable of export. Customer must request the exit export no later than 60 days after termination; the export window closes, and the export is deemed complete, no later than 90 days after termination.

11.4 Deletion. LabelGrid will delete remaining Customer Personal Data (including copies held by Sub-processors) within 90 days of the later of termination of the Principal Agreement or completion (or deemed completion) of the exit export, and in any event within 180 days of termination, except to the extent retention is required by law applicable to LabelGrid (Section 11.5). Copies residing in encrypted backup media are purged through routine backup rotation and are deleted or overwritten no later than 180 days after the primary deletion; until purged they remain protected under this DPA, are not restored to active systems except as necessary for disaster recovery, and are re-deleted promptly if restored.

11.5 Legally required retention — no recharacterization. To the extent law applicable to LabelGrid requires retention of specific Customer Personal Data, LabelGrid will retain only that data and only for as long as the law requires. Retained data remains Customer Personal Data protected by this DPA (and by the SCCs, where they apply) for the duration of the retention; LabelGrid will process it solely for the purposes of the applicable legal retention requirement, keep it confidential and secure per Sections 4 and 5, and delete it when the requirement lapses.

11.6 On written request, LabelGrid will provide a certificate of deletion confirming that deletion under Section 11.4 has been completed, subject to the specifically identified Customer Personal Data (if any) retained under Section 11.5, which the certificate identifies together with the legal retention requirement relied on and the expected duration of that retention. LabelGrid will provide a further certificate confirming the final deletion of that retained data promptly after it is deleted under Section 11.5, a request made under this Section 11.6 remaining effective for that purpose.

12. Liability

The liability of each party under or in connection with this DPA is subject to the exclusions and limitations of liability set out in the Principal Agreement. This DPA does not create a separate or additional liability cap. However, nothing in this Section 12 or in the Principal Agreement limits: (a) either party’s liability to data subjects under Clause 12 of the SCCs; (b) as between the parties, either party’s liability under the SCCs to the extent a contractual limitation would contradict or undermine the liability provisions of the SCCs; or (c) a party’s liability to the extent it cannot be limited under applicable Data Protection Laws.

13. Term, Precedence, and General

13.1 Term. This DPA takes effect on the Effective Date and remains in force for as long as LabelGrid processes Customer Personal Data — co-terminously with the Principal Agreement plus the deletion and backup-purge windows in Section 11 and any period of legally required retention under Section 11.5 — at the end of which this DPA expires automatically.

13.2 Precedence. In the event of conflict: (a) the SCCs (and, as applicable, the UK Addendum and the Swiss and Korean provisions) prevail over this DPA; (b) this DPA prevails over the Principal Agreement with respect to the processing of Customer Personal Data; and (c) the Principal Agreement governs all other matters, including liability (Section 12), governing law, and dispute resolution.

13.3 Governing law and disputes. Except where the SCCs require otherwise (Section 7.2(f)), this DPA is governed by the governing-law and dispute-resolution provisions of the Principal Agreement.

13.4 Amendments for legal change. If a change in Data Protection Laws or a decision of a competent authority or court invalidates or materially affects a transfer mechanism or other provision of this DPA, the parties will cooperate in good faith to implement promptly such replacement or additional measures as are reasonably required for continued lawful processing, and LabelGrid may update this DPA to the extent required by such change on notice to Customer.

13.5 Severability. If any provision of this DPA is held invalid or unenforceable, the remainder remains in effect, and the invalid provision is replaced by a valid provision that most closely achieves its intent.

13.6 Counterparts; electronic signature; execution by issuance. Where executed as a standalone document or as an annex to the Advanced Services Addendum, this DPA may be executed electronically and in counterparts, each of which is an original and all of which together constitute one instrument. Electronic signatures and records — including execution through an electronic-signature platform — are valid and enforceable to the same extent as handwritten signatures. Label Grid, LLC executes and delivers this DPA by issuing it for signature — whether as an annex within the Advanced Services Addendum signature envelope or as a standalone copy issued at Customer’s request — and no separate countersignature by Label Grid, LLC is required for this DPA to be fully executed, valid, and binding on both parties. Customer’s signature completes execution, and Label Grid, LLC’s issuance constitutes its signature and its agreement to be bound as of the date of Customer’s signature.


Execution Page — Per-Customer Completion

This page completes Annex I of the SCCs and Tables 1–3 of the UK Addendum for the specific Customer. Execution of this DPA constitutes signature of SCC Annex I and acceptance of the completed UK Addendum by both parties (Sections 7.2(g) and 7.3): Label Grid, LLC executes by issuing this DPA for signature and Customer executes by signing it, so both parties’ signature of SCC Annex I is effected without any countersignature (Section 13.6).

Customer (data exporter) details:

FieldEntry
Legal name{{customer_legal_name}}
Entity type and jurisdiction{{customer_entity_type_and_jurisdiction}}
Registered address{{customer_registered_address}}
Registration number{{customer_registration_number}}
Contact person (name, title, email){{customer_contact_name}}, {{customer_contact_title}}, {{customer_contact_email}}
Customer role / SCC Module mapping{{customer_role_module_mapping}} — e.g. ”Controller — Module Two, all Annex I.B categories” or ”Controller (Module Two: catalog, royalty, analytics, support) and Processor (Module Three: Engine end-user data)”
EU establishment or Article 27 representative (if any){{exporter_representative_details}}
Competent supervisory authority (SCC Clause 13 / Annex I.C){{competent_supervisory_authority}}
UK Addendum applies{{uk_applicability}} (yes/no)
Swiss adaptation (Section 7.4) applies{{swiss_applicability}} (yes/no)
Korea Rider (Annex IV) applies{{korea_applicability}} (yes/no)
U.S. State Privacy Rider (Annex V) applies{{us_state_applicability}} (yes/no)

LabelGrid (data importer) details:

FieldEntry
Legal nameLabel Grid, LLC
Address{{labelgrid_registered_address}}, Denver, Colorado 80203, United States of America
Contact[email protected]
RoleProcessor (SCC Modules Two and Three importer)

Executed (whether as an annex within the Advanced Services Addendum signature envelope or as a standalone copy issued for signature):

Execution by issuance. Label Grid, LLC executes and delivers this DPA by issuing it for signature — whether as an annex within the Advanced Services Addendum signature envelope or as a standalone copy issued at Customer’s request — and Customer’s signature below completes execution. No countersignature by Label Grid, LLC is required for this DPA, including its completion and signature of SCC Annex I and its acceptance of the UK Addendum, to be fully executed, valid, and binding on both parties; Label Grid, LLC’s issuance constitutes its signature and its agreement to be bound as of the date of Customer’s signature (Section 13.6).

Label Grid, LLC — executed and delivered by issuance through its electronic-signature system pursuant to Section 13.6; no countersignature required.

{{customer_legal_name}}

FieldEntry
Signature______________________
Name{{customer_signatory_name}}
Title{{customer_signatory_title}}
Date{{signature_date}}

Annex I — Description of the Processing

This Annex I also serves as Annex I of the SCCs (as applied under Section 7.2) and, with the Execution Page, completes Tables 1 and 3 of the UK Addendum.

A. List of Parties

Data exporter: Name: {{customer_legal_name}} Address: {{customer_registered_address}} Contact person: {{customer_contact_name}}, {{customer_contact_title}}, {{customer_contact_email}} Activities relevant to the transfer: submission of catalog, royalty, analytics, support, and (for Engine customers) end-user data to the Services for distribution, royalty administration, analytics, and support. Role: controller (SCC Module Two) or processor on behalf of third-party controllers (SCC Module Three), per Section 2.1 of the DPA and the Module mapping on the Execution Page. Signature and date: execution of the DPA per the Execution Page constitutes signature of this Annex — Customer signs by signing the Execution Page, and the date is the date of that signature.

Data importer: Name: Label Grid, LLC Address: {{labelgrid_registered_address}}, Denver, Colorado 80203, United States of America Contact: [email protected] Activities relevant to the transfer: provision of the LabelGrid music distribution, royalty, analytics, and API/Engine services. Role: processor. Signature and date: execution of the DPA per the Execution Page constitutes signature of this Annex — Label Grid, LLC signs by issuing the DPA for signature (Section 13.6), no countersignature being required. The date of Label Grid, LLC’s signature of this Annex is the date of Customer’s signature stated on the Execution Page, as of which Label Grid, LLC’s issuance binds it under Section 13.6; a single date therefore applies to both parties’ signature of this Annex.

B. Description of the Transfer

Categories of data subjects:

  • Artists, contributors, performers, writers, and other credited persons in Customer’s catalog
  • Royalty payees (artists, collaborators, and other persons entitled to splits)
  • End listeners, to the limited extent any DSP-supplied analytics record constitutes personal data in LabelGrid’s hands
  • Customer’s staff and authorized users, in respect of support ticket contents
  • For Engine customers: end users of Customer’s (or its clients’) white-label or reseller service, as submitted to the Services

Categories of personal data (capped — see Section 2.3 of the DPA):

  • Catalog metadata: names and stage names, contributor credits and roles, ISNI/IPI and similar identifiers, territory information
  • Royalty payee data: name, email address, payment details, split percentages, and tax identifiers where embedded in payout records processed on Customer’s behalf
  • Analytics data: pseudonymous usage statistics, territory, and demographic aggregates as supplied by DSPs, where personal data
  • Support data: names, business contact details, and ticket contents of Customer’s staff
  • Engine end-user data: account identifiers, email addresses, catalog and credit data, and service usage data, as submitted by Customer via the API

Module mapping: categories submitted by Customer as controller are transferred under SCC Module Two; categories submitted by Customer in a processor capacity for third-party controllers (typically Engine end-user data) are transferred under SCC Module Three — in each case as recorded on the Execution Page.

Excluded from this DPA (independent controller scope — Section 2.4): account and credential data, KYC/KYB documents, tax/AML/sanctions records, and call recordings/transcripts/consent records/disclosure logs.

Special categories of data: None. Submission of special-category data and of children’s personal data requiring parental consent is prohibited (Section 2.5).

Frequency of the transfer: continuous, for the duration of the Services.

Nature of the processing: hosting, storage, organization, formatting, transmission (including delivery to DSPs on Customer’s instruction), computation (royalty calculation), analysis (analytics presentation), disclosure to payout providers for payment execution, and erasure.

Purpose(s) of the transfer and further processing: provision of the Services under the Principal Agreement — music catalog distribution, royalty computation and payout, analytics, API/Engine services, and customer support.

Retention period: duration of the Principal Agreement plus the deletion, backup-purge, and legally-required-retention windows in Section 11 of the DPA.

Transfers to sub-processors: as set out in Annex III; subject matter, nature, and duration of sub-processing as described there and at labelgrid.com/legal/subprocessors.

C. Competent Supervisory Authority

The competent supervisory authority is the authority recorded on the Execution Page, determined as follows: where the data exporter is established in an EU Member State, the supervisory authority of that Member State; where the data exporter is not established in the EU but falls within Article 3(2) GDPR, the supervisory authority of the Member State of its Article 27 representative (as stated on the Execution Page), or otherwise as determined per Clause 13 of the SCCs. For UK transfers: the Information Commissioner’s Office. For Swiss transfers: the Federal Data Protection and Information Commissioner.


Annex II — Technical and Organizational Measures (TOMs)

This Annex II also serves as Annex II of the SCCs. The measures below are binding minimums; LabelGrid may evolve specific implementations provided the overall level of protection is not materially reduced (Section 5.2 of the DPA).

1. Encryption. Customer Personal Data is encrypted in transit over public networks using TLS 1.2 or higher, and at rest using AES-256 or encryption of equivalent strength. Encryption keys are managed through the managed key services of the infrastructure Sub-processors listed in Annex III, with key access restricted to authorized infrastructure roles.

2. Access control — RBAC and least privilege. Access to Customer Personal Data is restricted to personnel who need it to perform the Services, enforced through role-based access control, unique named accounts, and strong authentication; multi-factor authentication is required for administrative access to production systems. Access rights are reviewed at least quarterly and are revoked promptly on role change or departure, and in any event within five (5) business days.

3. Logging and monitoring. Administrative and data access to production systems is logged; security logs are retained for at least 12 months, protected against tampering, and monitored for anomalous activity; security alerts are triaged and investigated.

4. Backup and disaster recovery. Customer Personal Data is backed up at least daily; backups are encrypted and access-restricted; restoration procedures are tested at least annually. Recovery targets for core distribution services: restoration of availability targeted within 24 hours (recovery time objective) and data loss limited to no more than 24 hours of changes (recovery point objective). Deleted data is purged from backup media per Section 11.4 of the DPA (no later than 180 days after primary deletion).

5. Personnel confidentiality and training. All personnel with access to Customer Personal Data are bound by written confidentiality obligations (Section 4) and receive security and data-protection awareness training at onboarding and at least annually thereafter.

6. Vendor and Sub-processor management; control allocation. Sub-processors are assessed for security and data-protection posture before engagement, bound by written contracts per Section 6.4, and re-reviewed at least annually. Control allocation: physical and environmental security of production infrastructure is allocated to the infrastructure Sub-processors listed in Annex III (operating certified data centers); application-level access control, logging, encryption configuration, and data lifecycle controls are operated by LabelGrid.

7. Secure development (SDLC). Changes to production systems follow a controlled development lifecycle including code review, separation of development/test and production environments (no production personal data in development or test except where protected to production standard), dependency and vulnerability management with prioritized remediation — critical vulnerabilities patched on an expedited basis, targeting deployment within 30 days of a fix becoming available — and security testing proportionate to risk.

8. Physical and environmental security. Production infrastructure is hosted with the infrastructure Sub-processors listed in Annex III, whose data centers maintain industry-standard physical security, environmental controls, and independent certifications (e.g., ISO/IEC 27001 and/or SOC 2).

9. Incident response. LabelGrid maintains a documented incident-response process covering detection, containment, assessment, remediation, and the notification obligations in Section 9 of the DPA (notice on awareness, 72-hour outside limit, phased updates).

10. Data minimization, quality, and retention. The Services process the data categories capped in Annex I; retention, deletion, and backup purge follow Section 11 of the DPA.

11. Pseudonymization and separation. Where feasible for the processing purpose, data is pseudonymized or aggregated (in particular DSP-sourced analytics); customer environments are logically separated at the application tier.

12. Assistance measures. The measures above, together with the routing and assistance commitments in Section 8 of the DPA, constitute the technical and organizational measures by which LabelGrid provides assistance to the data exporter for data-subject requests and Articles 32–36 compliance, including search, export, correction, and deletion capabilities for Customer Personal Data.


Annex III — Sub-processors

This Annex III also serves as Annex III of the SCCs.

Authoritative list and change mechanism. LabelGrid’s current Sub-processor list is published at labelgrid.com/legal/subprocessors. That published list is the authoritative, current version; additions and replacements follow the 30-day email notice and objection procedure in Section 6 of the DPA. The list below is the state of the published list as at the adoption of this DPA.

Subject matter, nature, and duration of each sub-processing. For each Sub-processor listed below, the subject matter and nature of the sub-processing are the function stated in its row, performed on those categories of Customer Personal Data described in Annex I.B that are necessary for that function and for the purposes stated in Annex I.B, and the duration of the sub-processing is the term of LabelGrid’s engagement of that Sub-processor for that function and in no event longer than the duration of this DPA, subject in each case to the return and deletion provisions of Section 11.

Sub-processorFunctionProcessing locationRegistered / legal addressPrivacy contact
Amazon Web Services, Inc.Infrastructure hosting and storageUnited States410 Terry Avenue North, Seattle, WA 98109-5210, United States (ATTN: AWS Legal)aws.amazon.com/privacy; data protection officer for the EEA, UK and Switzerland: [email protected]
Hetzner Online GmbHInfrastructure hosting and storageGermany / Finland (EU)Industriestr. 25, 91710 Gunzenhausen, Germany[email protected]
Google LLCInfrastructure hosting and storageUnited States1600 Amphitheatre Parkway, Mountain View, California 94043, United Statessupport.google.com/policies/troubleshooter/7575787
Stripe, LLCPayment processingUnited States354 Oyster Point Boulevard, South San Francisco, California 94080, United States (registered office: Corporation Trust Center, 1209 Orange Street, Wilmington, Delaware 19801)[email protected]; data protection officer: [email protected]
Braintree (a PayPal service)Payment processingUnited StatesPayPal, Inc., 2211 North First Street, San Jose, California 95131, United Statespaypal.com/us/smarthelp/contact-us/privacy
PayPal, Inc.Payment and payout processingUnited States2211 North First Street, San Jose, California 95131, United Statespaypal.com/us/smarthelp/contact-us/privacy
Wise Payments LimitedPayout processingUnited Kingdom / EUWorship Square, 65 Clifton Street, London EC2A 4JE, United Kingdom (registered in England and Wales, company number 07209813)[email protected]
Atlassian Pty Ltd (Jira Service Management)Support operations (ticketing)United States / EUc/o Atlassian US, Inc., 350 Bush Street, Floor 13, San Francisco, California 94104, United States (ACN 102 443 916)[email protected]
Slack Technologies, LLCSupport operations (internal communications)United States50 Fremont Street, San Francisco, California 94105, United States[email protected]; data protection officer: [email protected]
Anthropic, PBCAI-assisted support toolingUnited States548 Market Street, PMB 90375, San Francisco, California 94104, United States[email protected]; data protection officer: [email protected]

Payment and payout providers act as Sub-processors only to the extent they process Customer Personal Data on Customer’s behalf in the execution of royalty payouts; to the extent a payment provider processes personal data under its own regulatory obligations (e.g., payment services regulation, AML), it does so as an independent controller under its own terms.


Annex IV — Korea Rider (PIPA)

This Annex applies where Customer, or a controller on whose behalf Customer acts, is subject to the Personal Information Protection Act of the Republic of Korea (PIPA). It supplements Section 7 of the DPA. Customer (or the relevant controller), as the transferring personal information controller, is responsible for establishing its lawful basis for the overseas transfer under Article 28-8 PIPA; LabelGrid provides the following disclosure items and commitments to support that basis.

1. Overseas-transfer disclosure items (Article 28-8 PIPA)

ItemDisclosure
Personal information items transferredThe categories of Customer Personal Data set out in Annex I.B (catalog metadata; royalty payee data; analytics personal data, if any; support data; Engine end-user data as submitted)
Destination countryUnited States of America
Date/time and method of transferContinuous transmission via secure network connection (TLS-encrypted) upon Customer’s submission of data to the Services, for the duration of the Services
Recipient (identity)Label Grid, LLC, Denver, Colorado, United States
Recipient contact[email protected]
Recipient’s purpose of useProvision of the Services under the Principal Agreement: music catalog distribution, royalty computation and payout, analytics, API/Engine services, and customer support (Annex I.B)
Retention and use periodDuration of the Principal Agreement plus the deletion and backup-purge windows in Section 11 of the DPA
Onward transfers (recipients and countries)The Sub-processors listed in Annex III, located in the United States, the European Union, and the United Kingdom, for the functions there described; the identity, country, and contact of each onward recipient are maintained on the published list at labelgrid.com/legal/subprocessors. Onward transfers are made under the Section 6.4 flow-down contracts and this DPA
Method and procedure for refusing the transferA data subject may refuse the overseas transfer by notifying Customer (or the relevant controller), or by contacting [email protected], which routes the request to Customer under Section 8.1 of the DPA; on a refusal communicated by Customer, the affected personal information is not transferred to (or is deleted from) the Services
Refusal consequencesIf transfer is refused, the Services cannot be provided with respect to the affected personal information; any further consequences for the data subject are stated by Customer in its own PIPA notices

Customer is authorized to reproduce the disclosure items above in its own privacy notices and consent forms as required by PIPA.

2. Security measures; direct duties

LabelGrid maintains, with respect to Customer Personal Data transferred from Korea, the technical and organizational measures in Annex II, which the parties record as the protective measures contemplated by PIPA and its Enforcement Decree for personal information transferred overseas (including encryption in transit and at rest, access control, logging, and incident response). LabelGrid will itself maintain the protective measures required of an overseas recipient under PIPA and its Enforcement Decree with respect to such data, and will instruct each Sub-processor that processes it to maintain equivalent measures through the Section 6.4 flow-down contracts.

3. Cooperation with the PIPC

LabelGrid will cooperate in good faith with inquiries, investigations, or requests of the Personal Information Protection Commission of the Republic of Korea (PIPC) concerning Customer Personal Data transferred under this DPA — through and with Customer and, where the PIPC lawfully addresses LabelGrid directly, directly — including providing information reasonably necessary for Customer to respond to the PIPC, to the extent not prohibited by law applicable to LabelGrid.

4. Suspension, deletion, and remediation

If a competent Korean authority lawfully requires suspension of the overseas transfer, or if continued transfer would breach PIPA: (a) Customer may suspend submission of the affected data; (b) Customer may additionally require LabelGrid to suspend processing and onward transfers of affected data already transferred, and LabelGrid will comply promptly; and (c) on Customer’s written instruction, LabelGrid will delete the affected data in accordance with Section 11 of the DPA. The parties will cooperate under Section 13.4 of the DPA to implement measures enabling lawful continuation; failing which, the affected Service may be terminated in accordance with the Principal Agreement.

5. Data subject rights of Korean data subjects

Requests from Korean data subjects are routed to Customer under Section 8.1 of the DPA. LabelGrid will assist Customer in honoring rights of access, correction, deletion, and suspension of processing under PIPA in accordance with Section 8 of the DPA.


Annex V — U.S. State Privacy Rider

This Annex applies where Customer Personal Data includes personal information subject to the CCPA or another applicable US state privacy law (including the Colorado Privacy Act, and the comprehensive privacy laws of other US states, together ”State Privacy Laws”). Capitalized terms used in this Annex and defined in the CCPA (”business”, ”service provider”, ”contractor”, ”sell”, ”share”, ”business purpose”, ”commercial purpose”, ”consumer”, ”personal information”) have the meanings given there; equivalent terms under other State Privacy Laws are construed accordingly.

1. Designation. With respect to Customer Personal Data subject to the CCPA, LabelGrid is a service provider (and, to the extent applicable, a contractor) to Customer, and Customer discloses Customer Personal Data to LabelGrid only for the limited and specified business purposes set out in the Principal Agreement, this DPA, and Annex I: provision of the Services (music catalog distribution, royalty computation and payout, analytics, API/Engine services, and customer support) and the related security, quality, and service-improvement purposes permitted for service providers. Under other State Privacy Laws, LabelGrid is Customer’s processor and this DPA constitutes the data processing contract those laws require (including C.R.S. § 6-1-1305(5) under the Colorado Privacy Act), with Sections 3–11 of this DPA supplying the required processing instructions, confidentiality, security, sub-processor, assistance, audit, and deletion terms.

2. Prohibitions. LabelGrid shall not: (a) sell or share Customer Personal Data; (b) retain, use, or disclose Customer Personal Data for any purpose other than the business purposes specified in Section 1 of this Annex, including any commercial purpose other than those business purposes, or as otherwise permitted for service providers by the CCPA and its regulations; (c) retain, use, or disclose Customer Personal Data outside the direct business relationship between LabelGrid and Customer; or (d) combine Customer Personal Data with personal information that LabelGrid receives from or on behalf of another person, or collects from its own interaction with a consumer, except as permitted for service providers by the CCPA and its regulations.

3. Compliance and same level of protection. LabelGrid will comply with all obligations applicable to service providers under the CCPA and, with respect to Customer Personal Data, will provide the same level of privacy protection as the CCPA requires of businesses. LabelGrid certifies that it understands the restrictions in this Annex and will comply with them.

4. Notification of inability to comply. LabelGrid will notify Customer promptly after making a determination that it can no longer meet its obligations under the CCPA or another applicable State Privacy Law.

5. Right to stop and remediate. On notice, including a notice under Section 4 of this Annex, Customer may take reasonable and appropriate steps to stop and remediate any unauthorized use of Customer Personal Data by LabelGrid.

6. Monitoring. Customer may take reasonable and appropriate steps — including the documentation, questionnaire, and audit measures in Section 10 of the DPA — to ensure that LabelGrid uses Customer Personal Data in a manner consistent with Customer’s obligations under State Privacy Laws.

7. Subcontracting. LabelGrid engages Sub-processors in accordance with Section 6 of the DPA and imposes on each Sub-processor, by written contract, obligations consistent with this Annex with respect to Customer Personal Data.

8. Consumer requests. LabelGrid will assist Customer in responding to verifiable consumer requests (access, deletion, correction, opt-out) as set out in Section 8 of the DPA, and will route any consumer request it receives directly to Customer per Section 8.1.

9. Deidentified data. If LabelGrid receives or creates deidentified data derived from Customer Personal Data, it will maintain and use it only in deidentified form, will not attempt to reidentify it (except as permitted by applicable law to test deidentification), and will contractually obligate any recipient to the same.


End of LabelGrid Data Processing Agreement, version 1.3 (LG-DPA-001), adopted 2026-07-31, as revised 2026-08-03.