Legal
Data Processing Addendum
Version 1.0 · Last updated January 1, 2026 · Effective January 1, 2026
This Data Processing Addendum (“DPA”) forms part of the FirstParty Terms of Service available at gofirstparty.com/terms (the “Agreement”) between Boats LLC, a Nevada limited liability company doing business as FirstParty (“FirstParty,” “we,” “us”), and the customer that accepts the Agreement (“Customer,” “you”).
No signature is required. This DPA applies automatically and is binding on both parties from the moment you accept the Agreement or begin using the Services, whichever occurs first. It is incorporated into the Agreement by reference.
Capitalized terms not defined here have the meanings given in the Agreement.
If your procurement process requires a countersigned document, contact support@gofirstparty.com and we will provide an executable copy of these same terms.
1. Definitions
“Applicable Data Protection Law” means all United States federal and state privacy, data protection, data security and communications-interception laws applicable to the Processing of Customer Personal Data under this DPA, including US State Privacy Laws, state data breach notification statutes, and state wiretapping, eavesdropping and pen register statutes as applied to online tracking technologies.
“US State Privacy Laws” means the California Consumer Privacy Act as amended by the CPRA (“CCPA”), the Virginia CDPA, the Colorado Privacy Act, the Connecticut CTDPA, the Utah UCPA, the Texas TDPSA, the Oregon OCPA, the Montana MCDPA, and any other comparable US state privacy statute in effect and applicable to the Services.
“Marketing Data” means event, identifier and attribution data generated by visitors to and users of Customer’s marketing properties, together with associated lead, contact and opportunity records used for conversion measurement, as described in Annex A.
“Customer Personal Data” means Personal Data contained within the Marketing Data that FirstParty Processes on behalf of Customer in the course of providing the Services. Customer Personal Data does not include Excluded Data.
“Excluded Data” means any data that Customer Processes on behalf of its own customers or end clients in a processor or service provider capacity, including without limitation applicant, candidate, patient, student, employee, member or subscriber records held within Customer’s own product or platform. Excluded Data is outside the scope of the Services and of this DPA. See Section 3.
“Ad Platform” means a third-party advertising, analytics, marketing or measurement platform to which Customer directs FirstParty to transmit Marketing Data, including Google Ads, Google Analytics, Meta, LinkedIn, Microsoft Advertising, TikTok, Reddit, Pinterest, Snapchat, OpenAI, Klaviyo and any other destination Customer configures. A representative list is at Annex D.
“Services” means the server-side tag management, event collection, identifier persistence and conversion forwarding services FirstParty provides under the Agreement.
“Sub-processor” means any third party engaged by FirstParty to Process Customer Personal Data on FirstParty’s behalf in connection with the Services. The current list is set out at Annex C.
“Personal Data” means information that identifies, relates to, describes, is reasonably capable of being associated with, or could reasonably be linked, directly or indirectly, with a particular Consumer or household, as defined under US State Privacy Laws. It includes “Personal Information” as defined in the CCPA.
“Business”, “Service Provider”, “Consumer”, “Sell”, “Share” and “Sensitive Personal Information” have the meanings given in the CCPA. “Controller”, “Processor”, “Targeted Advertising” and “Data Protection Assessment” have the meanings given in the applicable US State Privacy Law.
“Process” or “Processing” means any operation performed on Personal Data, whether or not by automated means, including collection, use, storage, disclosure, transmission, analysis, modification and deletion.
“Security Incident” means a breach of security leading to the accidental or unlawful destruction, loss, alteration, or unauthorized disclosure of or access to Customer Personal Data Processed by FirstParty, including any event constituting a “breach of the security of the system” or equivalent under an applicable state breach notification statute.
2. Roles, Scope and Instructions
2.1 Roles. With respect to Customer Personal Data, Customer is the Business (California) and Controller (all other applicable US State Privacy Laws), and FirstParty is the Service Provider (California) and Processor (all other applicable US State Privacy Laws). Each party is independently responsible for compliance with its own obligations under Applicable Data Protection Law.
2.2 Details of Processing. The subject matter, duration, nature and purpose of the Processing, the types of Personal Data and the categories of Consumers are set out in Annex A.
2.3 Documented instructions. FirstParty Processes Customer Personal Data only on Customer’s documented instructions, unless required otherwise by law. The Agreement, this DPA, and the tag, event and destination configuration approved by Customer within its server-side container together constitute Customer’s complete and final documented instructions. Additional or alternate instructions must be agreed in writing and may be subject to additional fees.
2.4 Unlawful instructions. FirstParty will notify Customer without undue delay if, in its opinion, an instruction infringes Applicable Data Protection Law, and may suspend performance of the affected instruction until it is confirmed, amended or withdrawn.
2.5 No Sale or Share. FirstParty will not: (a) Sell or Share Customer Personal Data; (b) retain, use or disclose Customer Personal Data for any purpose other than performing the Services, or as otherwise permitted by the CCPA; (c) retain, use or disclose Customer Personal Data outside the direct business relationship between the parties; or (d) combine Customer Personal Data with Personal Information received from or on behalf of any other person, or collected from its own interactions with a Consumer, except as permitted under the CCPA. FirstParty certifies that it understands and will comply with these restrictions.
2.6 Customer responsibilities. Customer is solely responsible for:
- the accuracy, quality and legality of Customer Personal Data and the means by which it was acquired;
- establishing and maintaining a valid legal basis, and where required obtaining and honoring valid end-user consent, for the collection of Marketing Data and its transmission to each Ad Platform;
- the deployment, configuration and correct operation of its consent management platform, and the transmission of accurate consent signals to the Services;
- maintaining accurate and complete privacy notices, including any notice at collection required under the CCPA, describing the Processing and each category of third party to which Personal Data is disclosed; and
- its own agreements and data protection terms with each Ad Platform.
2.7 Tracking technologies and interception statutes. The Services operate tracking technologies on Customer’s web properties at Customer’s direction. Customer acknowledges that the deployment of such technologies is subject to state wiretapping, eavesdropping and pen register statutes as those statutes have been applied to online tracking. Customer is responsible for determining what disclosures and consents are required in the jurisdictions where its users are located, and for obtaining them. FirstParty makes no representation that any particular configuration of the Services satisfies those requirements.
3. Excluded Data
3.1 The Services are designed to measure Customer’s own marketing properties and signup or lead funnels. Many FirstParty customers operate platforms in which they act as a processor or service provider for their own customers. Data of that kind is Excluded Data and is outside the scope of this DPA.
3.2 Customer will not configure, transmit, or otherwise cause Excluded Data to be sent to FirstParty or to any Ad Platform through the Services.
3.3 If FirstParty becomes aware that Excluded Data has been transmitted to it, FirstParty will promptly notify Customer and will, at Customer’s direction, delete the data or cease Processing it.
3.4 Nothing in this DPA appoints FirstParty as a sub-processor of Customer’s own customers or end clients.
4. Ad Platforms and Onward Recipients
4.1 Independent capacity. Each Ad Platform determines the purposes and means of its own Processing of data it receives and, in respect of that data, acts as a service provider to Customer or as a third party under that Ad Platform’s own terms — not as a Sub-processor of FirstParty. Ad Platforms are listed at Annex D for transparency, not as Sub-processors under Section 8.
4.2 Direct relationship. Customer is responsible for entering into and maintaining any required data protection terms directly with each Ad Platform, including as applicable the Google Ads Data Processing Terms, the Meta Business Tools Terms, and the LinkedIn Ads Agreement.
4.3 FirstParty’s role. FirstParty’s role with respect to Ad Platforms is limited to transmitting Marketing Data to the destinations and in the payload configuration instructed by Customer. FirstParty does not control, and is not responsible for, an Ad Platform’s Processing of data once received.
5. Confidentiality
5.1 FirstParty treats Customer Personal Data as confidential and ensures that persons authorized to Process it are bound by an appropriate obligation of confidentiality, whether contractual or statutory.
5.2 FirstParty limits access to Customer Personal Data to personnel who require it to perform the Services, and applies the principle of least privilege to administrative access to the infrastructure described in Annex B.
6. Security
6.1 Measures. FirstParty implements and maintains the technical and organizational measures set out in Annex B, taking into account the state of the art, the costs of implementation, the nature and purposes of Processing, and the risk to Consumers.
6.2 Architecture. The Services are designed to Process Customer Personal Data transiently: events are received, transformed and forwarded to configured Ad Platforms without FirstParty creating a persistent database of Customer Personal Data, other than the limited operational logging described in Annex A.6 and Annex B.5.
6.3 Changes. FirstParty may update the measures in Annex B from time to time, provided the updated measures do not materially decrease the overall level of protection of Customer Personal Data.
6.4 Customer assessment. Customer is responsible for independently determining whether the measures in Annex B meet its requirements and obligations under Applicable Data Protection Law.
7. Consumer Rights Requests
7.1 Assistance. Taking into account the nature of the Processing, FirstParty provides reasonable assistance to Customer, insofar as it is able, in fulfilling Customer’s obligations to respond to verifiable Consumer requests to know, access, delete, correct, or opt out of the Sale, Sharing, or use for Targeted Advertising of Personal Data.
7.2 Requests received directly. If FirstParty receives a Consumer request relating to Customer Personal Data, it will not respond substantively except to acknowledge receipt and direct the Consumer to Customer, and will forward the request to Customer without undue delay.
7.3 Deletion requests. On receiving a verified deletion request from Customer, FirstParty will delete any Customer Personal Data within its possession or control and, where technically feasible, transmit a corresponding deletion request to those Ad Platforms that expose an API supporting one. FirstParty cannot compel deletion within an Ad Platform.
7.4 Limits of assistance. Customer Personal Data Processed by the Services consists substantially of pseudonymous online identifiers and hashed values that FirstParty cannot, without additional information supplied by Customer, associate with an identified Consumer. FirstParty’s assistance obligations are limited accordingly. Records held in Customer’s CRM, consent management platform, or an Ad Platform are within Customer’s or that platform’s control, not FirstParty’s.
8. Sub-processors
8.1 General authorization. Customer grants FirstParty general authorization to engage Sub-processors to Process Customer Personal Data, subject to this Section 8. The current list is set out at Annex C.
8.2 Flow-down. FirstParty enters into a written agreement with each Sub-processor imposing data protection obligations no less protective than those in this DPA, and remains fully liable to Customer for each Sub-processor’s performance.
8.3 Notice and objection. FirstParty will provide at least thirty (30) days’ notice by email to Customer’s designated contact, and by updating Annex C, before authorizing a new Sub-processor. Customer may object on reasonable data protection grounds within fifteen (15) days of notice. If the parties cannot resolve the objection in good faith, Customer may terminate the affected Services without penalty, and FirstParty will refund any prepaid fees covering the remainder of the terminated term.
9. Security Incidents
9.1 FirstParty will notify Customer without unreasonable delay, and in any event within seventy-two (72) hours, after becoming aware of a Security Incident affecting Customer Personal Data.
9.2 The notification will describe, to the extent known and updated as further information becomes available: the nature of the Security Incident, including where possible the categories and approximate number of Consumers and records concerned; the likely consequences; the measures taken or proposed to address it and mitigate its effects; and a point of contact for further information.
9.3 FirstParty will provide reasonable cooperation and assistance in connection with Customer’s obligations under applicable state breach notification statutes. Customer is solely responsible for determining whether notification is required and for making any such notification. FirstParty will not make any public statement or regulatory notification that identifies Customer without Customer’s prior written consent, unless required by law.
9.4 FirstParty’s notification of or response to a Security Incident is not an acknowledgement of fault or liability.
10. Data Protection Assessments
10.1 Processing under this DPA includes Processing of Personal Data for purposes of Targeted Advertising, which may require Customer to conduct and document a data protection assessment under the Virginia CDPA, the Colorado Privacy Act, the Connecticut CTDPA, the Texas TDPSA, or other applicable US State Privacy Laws, and to conduct risk assessments under the CCPA regulations as and when those requirements take effect.
10.2 FirstParty provides reasonable assistance and such information as is reasonably available to it to support any such assessment. Customer remains responsible for conducting, documenting and retaining it.
11. Return and Deletion
11.1 On termination or expiry of the Agreement, or earlier on Customer’s written request, FirstParty will cease Processing Customer Personal Data and will, at Customer’s election, delete or return all Customer Personal Data then in its possession or control, and delete existing copies, within thirty (30) days, unless retention is required by law.
11.2 Where retention is legally required, FirstParty will isolate and protect the data from further Processing except as required by that law, and will inform Customer unless prohibited from doing so.
11.3 Customer Personal Data transmitted to an Ad Platform is retained and deleted according to that Ad Platform’s own retention policies and Customer’s settings within that platform. FirstParty cannot delete it on Customer’s behalf.
11.4 Customer is responsible for exporting any configuration or container versions it wishes to retain before termination takes effect.
12. Documentation and Audit
12.1 Documentation. FirstParty makes available the information reasonably necessary to demonstrate compliance with its obligations under this DPA, including this DPA and its Annexes, and responses to a reasonable written security questionnaire no more than once in any twelve (12) month period.
12.2 Standard audit method. Customer’s audit right is satisfied by the documentation described in Section 12.1, together with any then-current third-party audit reports or certifications held by FirstParty’s Sub-processors, which FirstParty will provide on request where it is permitted to do so.
12.3 On-site audit. Where Applicable Data Protection Law entitles Customer to an on-site audit that cannot be satisfied under Section 12.2, or following a confirmed Security Incident affecting Customer Personal Data, Customer may audit FirstParty’s compliance on at least thirty (30) days’ prior written notice, no more than once in any twelve (12) month period. Audits will be conducted during normal business hours, will not unreasonably interfere with FirstParty’s operations, will be subject to reasonable confidentiality obligations, and will not include access to any data or systems of FirstParty’s other customers. Customer bears the reasonable costs of any on-site audit, including FirstParty’s time and expenses, unless the audit reveals a material breach of this DPA by FirstParty.
13. Processing Location and Territorial Scope
13.1 Processing location. The Services are hosted on Google Cloud in a region located in the central United States. Customer instructs FirstParty to Process Customer Personal Data in the United States. FirstParty will not Process Customer Personal Data outside the United States without Customer’s prior written consent.
13.2 United States scope. This DPA is scoped to the Processing of Personal Data subject to United States federal and state law. It does not address the EU General Data Protection Regulation, the UK GDPR, the Swiss FADP, Canadian PIPEDA, or any other non-US privacy regime, and no such terms are implied.
13.3 Customer representation and geographic limitation. Customer represents that it does not direct the Services to collect or Process Personal Data of individuals located in the European Economic Area, the United Kingdom, or Switzerland. Customer is responsible for implementing any geographic suppression, consent gating, or regional routing at the collection layer necessary to give effect to this representation. If Customer requires the Services to Process Personal Data subject to a non-US privacy regime, the parties must first execute a written amendment containing the transfer mechanism and terms required by that regime. Contact support@gofirstparty.com.
13.4 Government access requests. If FirstParty receives a subpoena, court order, warrant, or other legally binding request from a governmental or regulatory authority for disclosure of Customer Personal Data, FirstParty will, unless legally prohibited, notify Customer without undue delay so Customer may seek a protective order or other remedy, and will disclose only the minimum amount of data legally required.
14. US State Privacy Law Terms
14.1 Customer discloses Customer Personal Data to FirstParty solely for the limited and specified business purposes set out in Annex A. Such disclosure is not a Sale or Share and is not made in exchange for monetary or other valuable consideration.
14.2 FirstParty complies with its obligations as a Service Provider (California), Processor (Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana) or equivalent designation under each applicable US State Privacy Law, and provides the same level of privacy protection as required of Customer thereunder.
14.3 FirstParty will notify Customer if it determines that it can no longer meet its obligations under Applicable Data Protection Law. On such notice, Customer may take reasonable and appropriate steps to stop and remediate unauthorized use of Customer Personal Data.
14.4 Sensitive data. Customer will not transmit to FirstParty, or configure the Services to collect, any Sensitive Personal Information or sensitive data as defined under any US State Privacy Law, including Personal Data revealing racial or ethnic origin, religious beliefs, health or mental health condition, sexual orientation, citizenship or immigration status, precise geolocation, government identifiers, account log-in or financial account numbers, genetic or biometric data, or Personal Data of a known child under 16. The Services are not designed to Process such data, and FirstParty has no obligation to detect or filter it.
14.5 Customer disclosures to Ad Platforms. Customer’s disclosure of Personal Data to an Ad Platform for cross-context behavioral advertising or Targeted Advertising may constitute a Sale or Share by Customer under Applicable Data Protection Law, notwithstanding that no Sale or Share occurs between Customer and FirstParty. Customer is solely responsible for the resulting notice, disclosure and opt-out obligations, including maintaining a compliant “Do Not Sell or Share My Personal Information” mechanism and disclosing the categories of third parties in its notice at collection.
14.6 Opt-out signals. Customer is responsible for detecting and honoring Consumer opt-out requests, including opt-out preference signals such as Global Privacy Control, at the collection layer, and for ensuring that events subject to an opt-out are not transmitted to the Services. FirstParty honors opt-out and consent state that Customer transmits to the Services in the agreed format, and configures the Services to suppress or redact fields accordingly. FirstParty is not responsible for opt-out signals that are not detected by Customer’s consent management platform or not transmitted to the Services.
15. Liability
15.1 Each party’s liability arising out of or in connection with this DPA is subject to the limitations and exclusions of liability set out in the Agreement. Any reference in the Agreement to the liability of a party means that party’s aggregate liability under the Agreement and this DPA together.
15.2 Nothing in this DPA limits any liability that cannot be limited under Applicable Data Protection Law, including any Consumer’s statutory right to damages or statutory penalties.
15.3 Allocation of responsibility. FirstParty’s obligations are limited to the correct technical operation of the Services in accordance with Customer’s documented instructions. Customer retains sole responsibility for: the lawfulness of the collection and transmission of Marketing Data; the accuracy and completeness of consent signals transmitted to the Services; the configuration and operation of its consent management platform; its privacy notices; and the Processing of data by any Ad Platform. Any tracking audit, assessment, configuration review or recommendation FirstParty provides is informational, does not constitute legal advice, and does not transfer compliance responsibility to FirstParty.
16. Changes to this DPA
16.1 FirstParty may update this DPA from time to time. The current version is always available at gofirstparty.com/dpa, with the version number and last-updated date shown at the top.
16.2 FirstParty will not make a change that materially reduces Customer’s rights or FirstParty’s obligations under this DPA except: (a) to reflect a change in Applicable Data Protection Law, a regulatory decision, or guidance from a supervisory or enforcement authority; (b) to reflect a change to the Services, a new feature, or a new Sub-processor; or (c) for reasons of clarity, accuracy or correction of an error.
16.3 For any material change, FirstParty will provide at least thirty (30) days’ notice by email to Customer’s designated contact and by posting the updated version. If Customer objects to a material change on reasonable data protection grounds, Customer may terminate the affected Services without penalty before the change takes effect, and FirstParty will refund any prepaid fees covering the remainder of the terminated term. Continued use of the Services after the effective date of a change constitutes acceptance of it.
16.4 Non-material changes — including corrections, clarifications and additions to Annex D — take effect on posting.
17. General
17.1 Term. This DPA takes effect when Customer accepts the Agreement or begins using the Services, and continues until the later of expiry or termination of the Agreement and the date FirstParty ceases all Processing of Customer Personal Data.
17.2 Order of precedence. In the event of a conflict between this DPA and the Agreement with respect to the Processing of Customer Personal Data, this DPA prevails. In all other respects the Agreement continues in full force.
17.3 Governing law. This DPA is governed by the laws of the State of Nevada, without regard to its conflict of laws principles, and the parties submit to the exclusive jurisdiction of the state and federal courts located in Clark County, Nevada.
17.4 Notices. Data protection notices to FirstParty should be sent to support@gofirstparty.com. Notices to Customer will be sent to the administrative or billing contact on Customer’s account. Customer may designate a separate privacy contact by writing to the address above.
17.5 Severability. If any provision of this DPA is held invalid or unenforceable, the remaining provisions remain in full force and effect.
Annex A — Details of Processing
A.1 Parties
- Customer
- The entity that accepts the Agreement. Role: Business / Controller. Relevant activities: operation of marketing properties and signup or lead funnels; digital advertising and conversion measurement.
- FirstParty
- Boats LLC d/b/a FirstParty, a Nevada limited liability company. Role: Service Provider / Processor. Relevant activities: server-side event collection, identifier persistence, and forwarding of conversion events to Ad Platforms on Customer’s instruction. Privacy contact: support@gofirstparty.com
A.2 Subject Matter, Nature and Purpose
- Subject matter
- Provision of first-party, server-side marketing measurement and conversion attribution services for Customer’s marketing properties.
- Nature of Processing
- Collection of website and application events via a first-party subdomain endpoint; persistence and propagation of advertising click identifiers across Customer’s domains; normalization and SHA-256 hashing of user-provided contact fields for conversion matching; transformation of events into Ad Platform payload formats; transmission of conversion events to configured Ad Platforms; transmission of offline conversion events derived from Customer CRM records.
- Purpose
- Attribution of marketing spend to signups, leads and closed opportunities; improving conversion measurement accuracy and match rates within Ad Platforms; reporting campaign performance to Customer.
- Duration
- For the term of the Agreement, plus the deletion period in Section 11.1.
- Frequency
- Continuous, on an event-triggered basis.
A.3 Categories of Consumers
- Visitors located in the United States to Customer’s marketing website and associated landing pages.
- Prospective customers who submit a lead form or begin a signup flow on Customer’s properties.
- Existing and prospective business contacts recorded in Customer’s CRM whose records are used to generate offline conversion events.
Excluded: individuals whose records Customer holds on behalf of its own customers or end clients (see Section 3), and individuals located in the European Economic Area, the United Kingdom or Switzerland (see Section 13.3).
A.4 Categories of Personal Data
| Category | Examples | Notes |
|---|---|---|
| Advertising click identifiers | gclid, gbraid, wbraid, fbclid, li_fat_id, msclkid, ttclid | Pseudonymous; assigned by the Ad Platform |
| Advertising cookie identifiers | _fbp, _fbc, _ga / GA client ID, FirstParty first-party identifier | Pseudonymous; set in the first-party context |
| Campaign and referral data | utm_source, utm_medium, utm_campaign, utm_term, utm_content, referrer URL, landing page URL | May be included in event payloads |
| Device and connection data | IP address, user agent string, screen resolution, language, timestamp | IP address is Personal Information under the CCPA |
| Behavioral event data | Page views, form submissions, signup events, conversion events and associated values | No cross-site tracking beyond Customer’s properties |
| Contact identifiers for conversion matching | Email address, phone number, first and last name, city, region, postal code, country | Hashed with SHA-256 before transmission where the destination Ad Platform supports hashed matching |
| CRM record data | Lead, contact and opportunity record identifiers, lifecycle or deal stage, conversion value and currency, conversion timestamp | Used to construct offline conversion imports |
A.5 Sensitive Data
None. The Services are not configured to Process Sensitive Personal Information or sensitive data, and Customer is prohibited from transmitting it under Section 14.4.
A.6 Retention
| Data | Location | Retention |
|---|---|---|
| Event payloads in transit | Server container memory (Google Cloud) | Transient — not written to persistent storage by FirstParty; discarded on completion of the request |
| Advertising and first-party identifiers | End-user browser (first-party cookies on Customer’s subdomain) | As configured for Customer, up to thirteen (13) months; stored on the user’s device, not by FirstParty |
| Operational request logs | Google Cloud Logging (US central region) | 30 days, then automatically deleted |
| Container configuration and version history | Server container configuration store | For the term of the Agreement; contains configuration, not Customer Personal Data |
| Data transmitted to Ad Platforms | Ad Platform systems | Per each Ad Platform’s own retention policy and Customer’s platform settings — outside FirstParty’s control |
Annex B — Technical and Organizational Measures
B.1 Hosting and Infrastructure
- The Services run on Google Cloud in a region located in the central United States, within a Google Cloud Platform project owned, controlled and billed by FirstParty and dedicated to Customer.
- Each customer is provisioned in a separate, isolated Google Cloud project. Customer Personal Data is not commingled with data of other FirstParty customers, and no FirstParty customer has access to another customer’s project.
- The service endpoint is exposed on a subdomain of Customer’s own domain via a verified domain mapping, so requests are made in a first-party context.
- FirstParty inherits the physical, environmental and infrastructure security controls of Google Cloud Platform, which maintains ISO/IEC 27001, ISO/IEC 27017, ISO/IEC 27018 and SOC 2 Type II certifications.
B.2 Encryption
- All data in transit between the end user, the server container, and the Ad Platforms is encrypted using TLS 1.2 or higher.
- Data at rest within Google Cloud Platform, including logs, is encrypted using AES-256 with Google-managed encryption keys.
- Contact identifiers used for conversion matching are normalized and hashed using SHA-256 before transmission where the destination Ad Platform supports hashed matching.
B.3 Data Minimization and Pseudonymization
- The Services are architected for transient Processing. Event payloads are received, transformed and forwarded without FirstParty writing Customer Personal Data to a persistent datastore under its control.
- Event payloads are limited to the fields required by the destination Ad Platform for the configured conversion action.
- Where a destination supports it, plaintext contact identifiers are replaced with hashed values before transmission.
- Consent state received from Customer’s consent management platform is enforced at the server container, including suppression or redaction of fields where consent is absent.
B.4 Access Control
- Administrative access to Google Cloud projects and server containers is restricted to named FirstParty personnel who require it to deliver the Services, applying least-privilege IAM roles.
- Multi-factor authentication is enforced on all FirstParty administrative accounts.
- Access is provisioned on engagement and revoked promptly on role change or termination.
- Because the Google Cloud project is owned and controlled by FirstParty, Customer does not have direct administrative access to the underlying infrastructure. Customer is granted access to its server container configuration so it may review and export the configuration governing what data is collected and where it is sent.
B.5 Logging and Monitoring
- Server container service logs and error reporting are enabled for operational monitoring and troubleshooting, with the retention period stated in Annex A.6.
- Google Cloud audit logs record administrative actions taken on the project.
- Logging is configured to minimize the capture of request payload contents.
B.6 Change Management and Availability
- Server container changes are made through versioned container publishes, providing a change record and rollback path.
- Container instances autoscale. The service is stateless, and no data is lost on instance recycling because no Customer Personal Data is persisted at the instance level.
- Availability and durability of the underlying platform are provided by Google Cloud Platform under its own service level commitments.
B.7 Organizational Measures
- Personnel with access to Customer Personal Data are bound by written confidentiality obligations.
- FirstParty maintains an incident response process covering detection, containment, assessment, notification under Section 9, and remediation.
- Sub-processors are subject to written agreements imposing data protection obligations no less protective than this DPA.
B.8 Assistance to Customer
The measures above, together with FirstParty’s obligations under Sections 7, 9, 10 and 11, constitute the technical and organizational measures by which FirstParty assists Customer in responding to Consumer rights requests, conducting data protection assessments, and meeting its security and breach notification obligations under Applicable Data Protection Law.
Annex C — Sub-processors
The Google Cloud Platform project hosting the Services is owned and controlled by FirstParty. Google is therefore engaged as FirstParty’s Sub-processor, not Customer’s, and FirstParty remains responsible for Google’s performance under Section 8.2.
The Sub-processors engaged as of the last-updated date above are:
| Sub-processor | Purpose | Processing location | Contractual safeguard |
|---|---|---|---|
| Google LLC | Cloud hosting of the server-side container and operational logging | United States (central region) | Google Cloud Platform Terms of Service and Cloud Data Processing Addendum |
Annex D — Ad Platform Destinations
The destinations below receive Marketing Data at Customer’s instruction. As set out in Section 4, these parties are not Sub-processors of FirstParty. Customer is responsible for maintaining appropriate data protection terms directly with each. This list is representative; the destinations that apply to Customer are those Customer configures.
| Destination | Data typically transmitted | Capacity |
|---|---|---|
| Google Ads (including Enhanced Conversions and offline conversion import) | Click identifiers, hashed email and phone, conversion action, value, currency, timestamp, IP address, user agent | Service provider or third party under the Google Ads Data Processing Terms and Google Ads Data Protection Terms, as applicable |
| Google Analytics 4 | Client ID, session and event parameters, page and campaign data, IP address, user agent | Service provider under the Google Ads Data Processing Terms |
| Meta (Conversions API) | fbc, fbp, hashed email and phone, hashed name and location fields, event name, value, currency, IP address, user agent | Third party under the Meta Business Tools Terms; disclosure may constitute a Sale or Share by Customer |
| LinkedIn (Conversions API) | li_fat_id, hashed email, conversion event, value, currency, timestamp | Third party under the LinkedIn Ads Agreement; disclosure may constitute a Sale or Share by Customer |
| Microsoft Advertising (Conversions API) | msclkid, hashed email and phone, conversion event, value, currency, timestamp | Third party under the Microsoft Advertising Agreement; disclosure may constitute a Sale or Share by Customer |
| TikTok (Events API) | ttclid, hashed email and phone, event name, value, currency, IP address, user agent | Third party under the TikTok Business Products Terms; disclosure may constitute a Sale or Share by Customer |
| Reddit (Conversions API) | rdt_cid, hashed email, hashed phone, event name, value, currency, IP address, user agent | Third party under the Reddit Advertising Agreement; disclosure may constitute a Sale or Share by Customer |
| Pinterest (Conversions API) | Pinterest click identifier, hashed email and phone, event name, value, currency, IP address, user agent | Third party under the Pinterest Advertising Services Agreement; disclosure may constitute a Sale or Share by Customer |
| Snapchat (Conversions API) | Snapchat click identifier, hashed email and phone, event name, value, currency, IP address, user agent | Third party under the Snap Business Services Terms; disclosure may constitute a Sale or Share by Customer |
| OpenAI / ChatGPT | Assistant referral and source parameters, conversion event, value, currency, timestamp | Third party under the OpenAI terms applicable to the integration |
| Klaviyo | Email address, phone number, Klaviyo profile identifier, event name, value, currency, timestamp | Service provider or processor under the Klaviyo Terms of Service and its data processing terms |
Questions about this DPA: support@gofirstparty.com