Home
Platform
  • Minute Video
  • Minute SSP
  • Content Offerings
  • Data & AI Tools
Solutions
  • Publishers
  • Advertisers
  • Teams & Leagues
  • Podcast Creators
Editorial
Company
  • About Us
  • Newsroom
  • Careers
  • Contact

Data Processing Addendum

Last updated September 14, 2026

This Data Processing Addendum, including Schedule A and Annexes 1-3 (collectively, the “Processor DPA”) forms an integral part of and supplements the main agreement (“Agreement”) entered into by Sportority Inc. d/b/a Minute, and/or its Affiliate entity as set out in the Agreement (“Recipient”) and the counterparty agreeing to those terms (“Company”). This Processor DPA will be effective from the effective date of the Agreement and applies to circumstances where Recipient is considered a processor under Data Protection Laws.

1. Introduction

1.1 This Processor DPA reflects the Parties’ agreement on the processing of Personal Data in connection with the Data Protection Laws.

1.2 Any ambiguity in this Processor DPA shall be resolved to permit the Parties to comply with all Data Protection Laws.

1.3 In the event and to the extent that the Data Protection Laws impose stricter obligations on the Parties than under this Processor DPA, the Data Protection Laws shall prevail.

2. Definitions and Interpretation

2.1 In this Processor DPA:

2.1.1 “Affiliate” means any person or entity that is directly or indirectly controlling, controlled by, or under common control with a Party. For the purpose of this definition, “control” (including, with correlative meanings, the terms “controlling”, “controlled by” and “under common control with”) means the power to manage or direct the affairs of the person or entity in question, whether by ownership of voting securities, by contract or otherwise.

2.1.2 “Approved Jurisdiction” means a member state of the European Economic Area or other jurisdiction or transfer mechanism approved as having adequate legal protections for data by the European Commission (currently available here), the UK Information Commissioner’s Office (currently available here), or the Swiss Federal Data Protection and Information Commissioner (“FDPIC”) (currently available here), as applicable.

2.1.3 “Data Protection Laws” means, as applicable, any and all domestic and foreign laws, rules, directives and regulations, on any local, provincial, state or federal or national level, pertaining to data privacy, data security and/or the protection of Personal Data, including, but not limited to: (i) the Privacy and Electronic Communications Directive 2002/58/EC (and respective local implementing laws) concerning the processing of personal data and the protection of privacy in the electronic communications sector (Directive on privacy and electronic communications); (ii) the Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data (“GDPR”); (iii) Data Protection Act 2018 and the GDPR as it forms part of the law of England and Wales, Scotland and Northern Ireland by virtue of section 3 of the European Union (Withdrawal) Act 2018 (“UK GDPR”); (iv) the Swiss Federal Act on Data Protection (“FADP”); (v) US Data Protection Laws; and (vi) the Canadian Personal Information Protection and Electronic Documents Act, and any substantially similar provincial legislation and any amendments or replacements to the foregoing.

2.1.4 “Data Subject” means a natural person to whom Personal Data relates. Where applicable, the term Data Subject shall include “Consumer”, as this term is defined under US Data Protection Laws (as applicable).

2.1.5 “EU-U.S. DPF” means the EU-U.S. Data Protection Framework adopted by the Commission Implementing Decision of 10.7.2023 pursuant to Regulation (EU) 2016/679 of the European Parliament and of the Council on the Adequate Level of Protection of Personal Data Under the EU-US Data Privacy Framework.

2.1.6 “European Economic Area” or “EEA” consists of the member states of the European Union (“EU”) and Iceland, Liechtenstein and Norway.

2.1.7 “Partner(s)” means Company’s supply and/or demand partners, as may be applicable (i.e., Company’s demand partners shall be considered Partners when Company acts as the recipient of Personal Data, and Company’s supply partners shall be considered Partners when Company acts as the discloser of Personal Data).

2.1.8 “Security Incident” shall mean any accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, Personal Data. For the avoidance of doubt, any Personal Data Breach (as defined in the GDPR) or any equivalent term under Data Protection Laws will comprise a Security Incident.

2.1.9 “Special Categories of Data” means personal data as defined under Article 9 of the GDPR and where applicable, “Sensitive Personal Information” or other equivalent terms as defined under Data Protection Laws.

2.1.10 “Standard Contractual Clauses” means the applicable module of the standard contractual clauses for the transfer of personal data to third countries pursuant to Regulation (EU) 2016/679 of the European Parliament and of the Council from June 4th 2021, as available here: https://eur-lex.europa.eu/eli/dec_impl/2021/914/oj?uri=CELEX:32021D0914&locale=en.

2.1.11 “UK Addendum” means the International Data Transfer Addendum to the EU Commission Standard Contractual Clauses, which was entered into force on March 21, 2022, as available here: https://ico.org.uk/media2/migrated/4019539/international-data-transfer-addendum.pdf.

2.1.12 “US Data Protection Laws” means any and all applicable acts, directive, decrees, laws, rules, and regulations, and binding regulatory guidance on any state or federal level, pertaining to data privacy, data security and the protection of Personal Data, including, without limitation, in California, Colorado, Connecticut, Utah, Virginia, Texas, Oregon, Florida, Montana, Iowa, Delaware, New Jersey, New Hampshire, and Nebraska, as well as any future laws, amendments, or regulations that may be enacted or promulgated governing data protection within the United States.

2.1.13 The terms “controller”, “Personal Data,” “process(ing)” and “processor” as used in this Processor DPA have the meanings given to them in Data Protection Laws. Where applicable, a controller shall be deemed a “Business”, a processor shall be deemed a “Service Provider” or a “Contractor”, and Personal Data shall be deemed “Personal Information” as these terms are defined under US Data Protection Laws.

2.1.14 Any reference to a legal framework, statute or other legislative enactment is a reference to it as amended or re-enacted from time to time.

3. Application of this Processor DPA

3.1 This Processor DPA will only apply to the extent the following conditions are met:

3.1.1 Recipient processes Personal Data that is made available by the Company solely in connection with the Agreement; and

3.1.2 The Data Protection Laws apply to the processing of Personal Data.

3.2 This Processor DPA shall not apply to the processing of the Parties as independent controllers as set forth in a separate Data Processing Addendum entered between the Parties.

4. Roles and Restrictions on Processing

4.1 The Parties acknowledge that Company is either: (a) a Controller of Personal Data; or (b) acting as a Processor on behalf of other Controllers and has been instructed and authorized by such Controllers to the processing of Personal Data by Recipient as Company’s Sub-processor, as set forth in this Processor DPA. Company represents and warrants that any Personal Data made available to Recipient is so processed lawfully under Data Protection Laws. Without derogating from the foregoing, Company shall maintain, and shall contractually require its applicable Partners to maintain, a publicly-accessible privacy policy on its mobile apps and websites that is available via a prominent link that satisfies transparency disclosure requirements of Data Protection Laws. Where Company or its applicable Partners rely on consent as its legal basis to process Personal Data, it shall ensure that it obtains, or otherwise contractually requires its applicable Partners to obtain, a proper affirmative act of consent from Data Subjects in accordance with Data Protection Laws in order for itself, the Company and the applicable Partners to process such Personal Data as set out herein and in the Agreements.

4.2 If Recipient has access to or otherwise processes Personal Data pursuant to the Agreement, then Recipient shall:

4.2.1 only process the Personal Data in accordance with Company’s instructions and on its behalf, and in accordance with the Agreement, this Processor DPA and the related attachments, unless required otherwise under the Data Protection Laws;

4.2.2 take reasonable steps to ensure the reliability of its staff and any other person acting under its supervision who may come into contact with, or otherwise have access to and process Personal Data;

4.2.3 ensure persons authorized to process the Personal Data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality;

4.2.4 assist Company as reasonably necessary to cooperate with and respond to requests from supervisory authorities or Data Subjects, or as otherwise required under the Data Protection Laws, at Company’s sole expense, related to Recipient’s processing of Personal Data, taking into account the nature of the processing and the information available to Recipient. Company shall reimburse Recipient for all reasonable costs incurred in providing such assistance, including personnel time at Recipient’s standard rates, provided that (i) such assistance shall not exceed ten (10) hours per calendar month without Recipient’s prior written consent; (ii) Company shall reimburse Recipient for all reasonable out-of-pocket expenses within thirty (30) days of invoice; and (iii) assistance exceeding the monthly hour cap may be provided at Recipient’s then-current standard professional services rates;

4.2.5 notify the Company without undue delay after becoming aware of a Security Incident;

4.2.6 upon receipt of: (a) requests from Data Subjects to exercise their rights, as applicable, under the Data Protection Laws in connection with Personal Data processed under this Processor DPA or (b) any requests or inquiries from supervisory authorities to provide information related to Recipient’s processing of Personal Data under this Processor DPA, the Recipient shall: (i) direct such requests to Company; (ii) not respond or act upon such requests without prior written approval from Company, except to the extent required by Data Protection Laws; and (iii) promptly, and in any case within the period of time required in Data Protection Laws, provide reasonable cooperation and assistance to Company in responding to and exercising such requests, at Company’s sole cost and expense, except where the foregoing shall not apply only and insofar as it conflicts with Data Protection Laws or requirements under any applicable laws. Company undertakes to lawfully handle such requests as required under Data Protection Laws;

4.2.7 maintain written records of processing activities of any Personal Data carried out under the Agreement, as required by Data Protection Laws, and shall make such records available to the applicable supervisory authority on request, and to Company, where necessary to demonstrate compliance with this Processor DPA;

4.2.8 not disclose Personal Data to any third party except on documented instructions from Company, unless required to do so by applicable law, or as explicitly permitted under this Processor DPA (including to authorized Sub-processors);

4.2.9 promptly notify Company of any investigation, litigation, arbitration or other dispute relating to the Recipient or the processing of Personal Data under the Agreement, to the extent legally permissible; and

4.2.10 promptly notify Company in writing, and provide Company an opportunity to intervene, in any judicial, enforcement, or administrative process if Recipient is required to disclose any Personal Data to any person other than Company (unless Recipient legally prohibited from doing so).

4.3 Upon termination or expiration of the Agreement, or upon Company’s written request at any time during the term of the Agreement, Recipient shall cease to process any Personal Data received from Company, and will, at the request of Company: (a) return the Personal Data; or (b) securely and completely destroy or erase all Personal Data in its possession or control (including any copies thereof), unless and solely to the extent the foregoing conflicts with any Data Protection Laws or when the Personal Data is stored in backups, in which case it shall be deleted upon the lapse of the relevant backup cycle.

5. Sub-processing

5.1 Recipient may subcontract its obligations under this Processor DPA to another person or entity (“Sub-processor(s)”), in whole or in part, subject to Company’s general written authorization. Company hereby provides general authorization for Recipient to engage Sub-processors, including those detailed in Annex III. Recipient shall inform Company of any intended changes concerning the addition or replacement of Sub-processors, thereby giving Company the opportunity to object to such changes. To the extent Company objects to the appointment of any new Sub-processor based on reasonable data protection concerns, the Parties shall negotiate in good faith this objection. In the event the Parties, acting reasonably and in good faith, have not reached an amicable solution, then the Company may terminate the portion of the Agreement that requires the employment of said Sub-processor if such Sub-processor is essential to the provision of such services.

5.2 Recipient will execute a written agreement with such approved Sub-processor containing terms sufficient to comply with Data Protection Laws.

5.3 Recipient shall be liable for the acts or omissions of Sub-processors to the same extent Recipient would be liable if it had directly performed such acts or omissions under this Processor DPA and Data Protection Laws, subject to the limitation of liability provisions set forth in the Agreement, provided that Recipient shall not be liable for any Sub-processor’s acts or omissions to the extent such acts or omissions were not reasonably foreseeable or preventable by Recipient despite Recipient’s exercise of reasonable due diligence and contractual safeguards.

6. Transfer of Personal Data

6.1 Where the GDPR, UK GDPR, or FADP is applicable, to the extent Recipient processes Personal Data outside the EEA, the UK, Switzerland, or an Approved Jurisdiction (respectively), the following shall apply:

6.1.1 If Recipient processes Personal Data in the United States and Recipient maintains current certification under the EU-U.S. DPF, the UK Extension to the EU-U.S. DPF and/or the Swiss-U.S. Data Privacy Framework, each where applicable (collectively, the “Data Privacy Frameworks”), such certifications shall serve as the transfer mechanism for transfers of Personal Data from the EEA, UK, and/or Switzerland to Recipient in the United States, and the Standard Contractual Clauses and UK Addendum shall not be required for such transfers.

6.1.2 If Recipient processes Personal Data outside the United States in a jurisdiction that is not an Approved Jurisdiction or not subject to the Data Privacy Frameworks, or Recipient processes Personal Data in the United States but is not certified under the Data Privacy Frameworks, then the Parties shall be deemed to have entered into the Standard Contractual Clauses and UK Addendum (as applicable) subject to any amendments contained in Schedule A, in which event: (i) the Standard Contractual Clauses and the UK Addendum are incorporated herein by reference; and (ii) Company shall be deemed a “data exporter” and the Recipient shall be deemed a “data importer” (as these terms are defined therein). To the extent the Parties rely on the Standard Contractual Clauses or UK Addendum, if the Standard Contractual Clauses or the UK Addendum are superseded by a new or modified mechanism, the new or modified mechanism shall be deemed to be incorporated into this Processor DPA and Recipient will promptly begin complying with such mechanism. Recipient will abide by the obligations set forth under the Standard Contractual Clauses and UK Addendum.

7. Security Standards

7.1 Recipient shall implement and maintain commercially reasonable and appropriate physical, technical and organizational security measures to protect Personal Data as detailed in Annex II. Such technical and organization measures shall be at least equivalent to that required under the Data Protection Laws to protect Personal Data against (i) accidental or unlawful destruction; (ii) accidental loss, alteration, unauthorized disclosure or access (iii) and all other unlawful forms of processing.

8. Obligations under US Data Protection Laws

8.1 To the extent that Recipient processes Personal Data which is subject to the US Data Protection Laws then, in addition to the obligations set out herein, Recipient shall not:

8.1.1 Process the Personal Data other than on Company’s instructions.

8.1.2 Sell or share Personal Data (as the terms “sell” and “share” are defined under US Data Protection Laws) disclosed to or collected by it (or on its behalf) in connection with the Agreement, or, except as necessary to perform the services, or where allowed in a separate agreement;

8.1.3 Retain, collect, use or disclose Personal Data disclosed to it or collected by it (or on its behalf), for any purpose, including commercial purposes, other than for the business purpose (as defined under US Data Protection Laws).

8.1.4 Recipient shall not combine the Personal Data of consumers that it collects, receives from, or on behalf of, the Company with Personal Data that the Recipient receives from, or on behalf of, another person or persons or collects from its own interaction with consumers unless and solely to the extent necessary to perform the business purpose.

8.2 Recipient acknowledges and understands its obligations under this clause and will comply with them.

8.3 Information and Audit. Recipient shall provide written responses to reasonable requests for information made by Company, including responses to security and data protection questionnaires, provided that such requests do not occur more than once per twelve (12)-month period.

8.4 In lieu of an initial physical audit, Recipient may provide Company, upon reasonable request, with documentation demonstrating its compliance with its obligations under this Agreement. This shall include, at a minimum, current certifications or summary audit reports from independent third-party auditors (e.g., ISO 27001, SOC 2 Type II, or equivalent).

8.5 Company may only conduct an audit of Recipient if: (a) the documentation and information provided is insufficient to demonstrate compliance; (b) Company has reasonable grounds to suspect a material breach of this Processor DPA; or (c) an audit is explicitly mandated by a competent Data Protection Authority.

8.6 To the extent applicable, audits shall be conducted with reasonable advanced notice to Recipient, but in no case less than thirty (30) days prior written notice and shall take place during normal business hours to reasonably limit any disruption to Recipient’s business. Such audits and inspections shall take place no more than once per calendar year by an independent third-party auditor under strict confidentiality obligations. Audit’s shall not exceed five (5) business days in duration. Company shall bear all costs and expenses associated with such audits, including Recipient’s reasonable personnel time (calculated at Recipient’s standard rates) and any out-of-pocket expenses. Company and its auditors shall maintain the confidentiality of any all information, whether proprietary or confidential information, of Recipient obtained, learned or otherwise discovered or provided by Recipient during such audits. Audits shall be limited in scope to Recipient’s compliance with this Processor DPA and Data Protection Laws related to the activities falling under this Processor DPA only.

9. Liability

9.1 Notwithstanding anything else in the Agreement, the total liability of Recipient towards Company under or in connection with this Processor DPA will be limited to US $50,000.

10. Indemnification

10.1 Company shall indemnify, defend, and hold harmless Recipient and its Affiliates from and against any and all claims, losses, damages, liabilities, and expenses (including reasonable attorneys’ fees) arising from or relating to: (i) Company’s instructions to Recipient regarding the processing of Personal Data; (ii) Company’s failure to comply with Data Protection Laws in its capacity as a controller; (iii) the accuracy, quality, or legality of Personal Data provided by Company to Recipient; or (iv) Company’s failure to obtain necessary consents or provide required notices to Data Subjects.

11. Priority

11.1 If there is any conflict or inconsistency between the terms of this Processor DPA and the remainder of the Agreement then, the terms of this Processor DPA will govern. Subject to the amendments in this Processor DPA, the Agreement remains in full force and effect.

12. Changes to this Processor DPA

12.1 Company acknowledges and agrees that Recipient may amend this Processor DPA as may be required from time-to-time, by posting an amended Processor DPA to this link: https://www.minutegroup.com/policies/processor-data-processing-addendum. Any amendments to the Processor DPA are effective as of the date of posting. Company’s continued use of the services after the amended Processor DPA is posted constitutes its agreement to, and acceptance of, the terms of the amended Processor DPA.

12.2 If any of the Data Protection Laws are superseded by new or modified Data Protection Laws (including any decisions or interpretations by a relevant court or governmental authority relating thereto), the new or modified Data Protection Laws shall be deemed to be incorporated into this Processor DPA, and each Party will promptly begin complying with such Data Protection Laws in respect of its respective processing activities.

Schedule A – Standard Contractual Clauses and the UK Addendum

This Schedule A shall only apply to the extent Recipient is required to enter into the Standard Contractual Clauses and UK Addendum. Where Recipient relies on its Data Privacy Framework certification as the transfer mechanism, this Schedule A shall not apply unless and until such certification becomes unavailable.

1. To the extent the Standard Contractual Clauses apply, the following shall apply:

1.1 Company is a controller – the Parties shall be deemed to enter into the Controller to Processor Standard Contractual Clauses (Module 2). If Company is a processor – the Parties shall be deemed to enter into the Processor to Processor Standard Contractual Clauses (Module 3).

1.2 This Schedule A sets out the Parties’ agreed interpretation of their respective obligations under Module Two or Module Three of the Standard Contractual Clauses (as applicable).

1.3 The Parties agree that for the purpose of transfer of Personal Data between the Company (Data Exporter) and the Recipient (Data Importer), the following shall apply:

1.3.1 Clause 7 of the Standard Contractual Clauses shall not apply.

1.3.2 In Clause 9, Option 1 shall apply. The Data Importer shall submit the request for specific authorization at least thirty (30) days prior to the engagement of the Sub-processor. Annex III shall be updated accordingly.

1.3.3 In Clause 11, Data Subjects shall not be able to lodge a complaint with an independent dispute resolution body.

1.3.4 In Clause 13, the applicable supervisory authority shall be the Irish Data Protection Commissioner.

1.3.5 In Clause 17, Option 1 shall apply. The Parties agree that the clauses shall be governed by the law of Ireland.

1.3.6 In Clause 18(b) the Parties choose the courts of Dublin, Ireland.

1.3.7 Annexes I-III shall be incorporated into the Standard Contractual Clauses.

2. To the extent the UK Addendum applies, the following shall apply:

2.1 All the information provided under the Standard Contractual Clauses shall apply to the UK Addendum with the necessary changes per the requirement of the UK Addendum. Annexes 1A, 1B and 2 to the UK Addendum shall be replaced with Annexes I–III, respectively.

2.2 In Table 4 of the UK Addendum, either Party may terminate the agreement in accordance with section 19 of the UK Addendum.

2.3 By entering into this Data Protection Agreement, the Parties hereby agree to the changes made to the UK Addendum.

3. To the extent the FADP applies, the following shall apply:

3.1 references to the GDPR are to be understood as references to the FADP.

3.2 the competent supervisory authority shall be the FDPIC.

3.3 references to “EU”, “Union” and “Member State” are replaced with “Switzerland”.

3.4 In Clause 17, Option 1 shall apply. The Parties agree that the clauses shall be governed by the law of Switzerland;

3.5 In Clause 18(b) the Parties choose the courts of Zurich, Switzerland as their choice of forum and jurisdiction.

Annex I – Description of Processing Activities

A. Identification of Parties

“Data Exporter”: the Company.

“Data Importer”: the Recipient.

B. Description of Transfer

Categories of data subject: Company’s end users and customers
Categories of Personal Data Device identifiers and internet or electronic network activity Geo-location information (non-precise)
Special Categories of Data/Sensitive Personal Information None
Nature of Processing Storage
Reporting Publishers
Frequency of Transfer Continuous
Purpose of the transfer and further processing As defined in the Agreement.
Retention period Personal Data will be retained for the term of the Agreement.

Annex II – Technical and Organizational Measures including Technical and Organizational Measures to Ensure the Security of the Data

Description of the technical and organizational measures implemented by the Recipient, acting as a data importer (including any relevant certifications maintained in Recipient’s ordinary course of business) to implement reasonable and appropriate security measures, taking into account the nature, scope, context and purpose of the processing, and the risks to the security of Personal Data of natural persons, commensurate with the nature of the services provided.

Security Management

Recipient maintains a written information security management system (ISMS), consistent with industry standards, that includes policies, processes, enforcement and controls governing all storage/processing/transmitting of Personal Data, designed to (a) secure Personal Data against accidental or unlawful loss, access or disclosure; (b) identify reasonable foreseeable and internal risks to security and authorized access to Recipient Network, and (c) minimize security risks, including through risk assessment and regular testing. Recipient shall maintain security measures appropriate to the nature and scope of processing activities. The information security program will include the following measures:

  • Recipient monitors information security trends and developments as well as legal developments with regards to the services provided and especially with regard to Personal Data and consider such insights to maintain its ISMS, as appropriate.

Maintain an Information Security Policy

Recipient’s ISMS is based on its security policies that are regularly reviewed (at least yearly) and maintained and disseminated to all relevant Parties, including all personnel. Security policies and derived procedures clearly define information security responsibilities including responsibilities for:

  • Maintaining security policies and procedures;
  • Secure development, operation and maintenance of software and systems;
  • Security alert handling;
  • Security incident response and escalation procedures;
  • User account administration; and
  • Monitoring and control of all systems as well as access to Personal Data.

Personnel are trained (and tested) through a formal security awareness program upon hire and annually. Security measures shall be implemented in accordance with access to Personal Data. This may include background checks, security training, and vendor management processes as Recipient deems appropriate.

Recipient has implemented a risk-assessment process for Personal Data that is based on recognized industry standard.

Secure Networks and Systems

Recipient has installed and maintains firewall configurations or equivalent network security controls to protect Personal Data that controls all traffic allowed between Recipient’s (internal) network and untrusted (external) networks, as well as traffic into and out of more sensitive areas within its internal network. This includes documentation and reviews as commercially reasonable.

Recipient does not use vendor-supplied defaults for system passwords and other security parameters on any systems and has developed configuration standards for all system components consistent with industry-accepted system hardening standards.

Encryption and Data Security

  • Recipient and its Sub-processors shall encrypt all Personal Data where feasible both in transit and at rest using industry-standard encryption algorithms (e.g., AES-256). Encryption keys will be securely managed and rotate periodically unless impracticable. Alternative measures may apply to low-risk data.
  • Where feasible and appropriate based on risk, Sensitive Personal Data shall be masked or anonymized for use in non-production environments to prevent exposure.

Data Retention and Minimization

  • Personal Data shall be retained only for the duration specified in the Agreement or as required by applicable law. Upon contract termination, Recipient must ensure the secure deletion or anonymization of all data in accordance with its standard data retention and deletion cycles except where legally prohibited.
  • Data minimization practices will include periodic reviews to identify and remove redundant data where technically feasible.

Protection of Personal Data

Recipient keeps Personal Data storage to a minimum and implements data retention and disposal policies to limit data storage to that which is necessary, in accordance with the needs of its customers. Upon termination of the Agreement, and subject to applicable legal retention requirements, Personal Data shall be deleted using secure deletion methods (e.g., NIST 800-88 guidelines) within 90 days, and written confirmation of deletion shall be provided upon request. Recipient shall implement and maintain encryption measures consistent with industry standards, using commercially reasonable encryption methods appropriate to the sensitivity of the data. Recipient may update encryption standards from time to time to align with industry best practices. Recipient has documented and implemented commercially reasonable procedures to protect (cryptographic) keys used to secure stored Personal Data against disclosure, misuse and prevent unauthorized access in accordance with industry standard practices.

Vulnerability Management Program

Recipient protects all systems against malware and regularly updates anti-virus software or programs to protect against malware – including viruses, worms, and Trojans. Anti-virus software is used on all systems commonly affected by malware to protect such systems from current and evolving malicious software threats.

Recipient develops and maintains secure systems and applications by:

  • Having established and evolving a process to identify and fix (e.g. through patching) security vulnerabilities, that ensures that all systems components and software are protected from known vulnerabilities;
  • Developing internal and external software applications, including web-applications, securely using commercially reasonable secure software development practices, that incorporates information security throughout the software-development lifecycle; and
  • Implementing a reasonable change management process and procedures for all changes to system components that include strict separation of development and test environments from production environments and limits the use of production data for testing or development except as necessary with appropriate safeguards.

Implementation of Strong Access Control Measures

“Recipient Network” means Recipient’s data center facilities, servers, networking equipment, and host software systems (e.g. virtual firewalls) as employed by Recipient to process or store Personal Data. The Recipient Network will be accessible to employees, contractors and any other person as necessary to provide the services to the Recipient. Recipient shall implement multi-factor authentication (MFA) for all systems accessing Personal Data based on Recipient’s risk assessment and the sensitivity of the data processed. Recipient will maintain corrective action and incident response plans to respond to potential security threats.

Recipient strictly restricts access to Personal Data on a need-to-know basis to ensure that critical data can only be accessed by authorized personnel. This is achieved by:

  • Limiting access to system components and Personal Data to only those individuals whose job requires such access;
  • Establishing and maintaining an access control system for system components that restricts access based on a user’s need to know, with a default “deny-all” setting; and
  • Access activities to systems containing Personal Data shall be logged and regularly reviewed.

Recipient identifies and authenticates access to all systems components by assigning a unique identification to each person with access. This ensures that each individual is uniquely accountable for its actions and any actions taken on critical data and systems can be traced to known and authorized users and processes. Necessary processes to ensure proper user identification management, including control of addition/deletion/modification/revocation/disabling of IDs and/or credentials as well as lock out of users after repeated failed access attempts and timely termination of idling session, have been implemented.

User authentication utilizes at least passwords that have to meet complexity rules, which need to be changed on a regular basis, and which are cryptographically secured during transmission and storage on all system components. All individual non-console and administrative access and all remote access use multi-factor authentication where technically feasible. Alternative compensating controls may be implemented for systems where MFA cannot be deployed.

Authentication policies and procedures are communicated to all users and group, shared or generic IDs/passwords are strictly prohibited.

Restriction of Physical Access to Personal Data

Any physical access to data or systems that house Personal Data are appropriately restricted using appropriate entry controls and procedures to distinguish between onsite personnel and visitors to the extent practicable. Access to sensitive areas is controlled and includes processes for authorization based on job function and access revocation for personnel and visitors.

Media and backups are secured and (internal and external) distribution is reasonably controlled. Media containing Personal Data that Recipient determines is no longer needed for business or legal reasons is deleted or destroyed using commercially reasonable methods. Recipient may retain data in backup systems until normal rotation/deletion cycles occur.

Regular Monitoring and Testing of Networks

All access to network resources and Personal Data is tracked and monitored using centralized logging mechanisms that allow for tracking, alerting, and analysis on a regular basis as well as when something does go wrong. All systems are provided with correct and consistent time and audit trails are secured and protected, including file-integrity monitoring to prevent change of existing log data and/or generate alerts in case. Audit trails for critical systems are kept for at least 180 days, or longer if required by applicable law.

Security of systems and processes is regularly tested, at least yearly. This is to ensure that security controls for system components, processes and custom software continue to reflect a changing environment. Security testing includes:

  • Processes to test rogue wireless access points,
  • Internal and external network vulnerability tests that are carried out at least annually. Upon Company’s expense, Recipients shall provide a summary of the most recent external vulnerability test report.
  • External and internal penetration tests using Recipient’s penetration test methodology that is based on industry-accepted penetration testing approaches that cover the all relevant systems and include application-layer as well as network-layer tests

All test results are kept on record, and any findings are remediated in a timely manner.

Recipient does not allow penetration tests carried out by or on behalf of its customers.

In daily operations IDS (intrusion detection system) is used to detect and alert on intrusions into the network and file-integrity monitoring has been deployed to alert personnel to unauthorized modification of critical systems.

Incident Management

Recipient has implemented and maintains an incident response plan appropriate to the nature of the services provided and is prepared to respond immediately to a system breach. To the extent commercially reasonable, Incident management includes:

  • Definition of roles, responsibilities, and communication and contact strategies in the event of a compromise, including notification of customers;
  • Specific incident response procedures;
  • Analysis of legal requirements for reporting compromises;
  • Coverage of all critical system components;
  • Regular review and testing of the plan,
  • Incident management personnel that is available 24/7,
  • Training of staff;
  • Inclusion of alerts from all security monitoring systems; and
  • Modification and evolution of the plan according to lessons learned and to incorporate industry developments.

Recipient shall implement and maintain reasonable business continuity (BCP) and disaster recovery plans (DRP) that is maintained and regularly tested, ensuring data integrity and availability during disruptions Data backup processes have been implemented and are tested regularly. Testing shall not disrupt Recipient’s normal business operations or other customer services.

Recipient shall notify Company without undue delay after becoming aware of a Security Incident. Post-incident, Recipient shall conduct a root cause analysis and implement industry standard measures to prevent recurrence. A summary report shall be shared with Company.

Access Control and Authentication

  • Access to systems handling Personal Data must be restricted to authorized personnel using role-based access control (RBAC) or comparable access control methods.
  • Multi-factor authentication (MFA) where technically feasible for all administrative and non-console access or equivalent alternatives.
  • Access rights must be reviewed and audited in accordance with Recipient’s security procedures.

Physical Access Controls

Physical components of the Recipient Network are housed in nondescript facilities (“Facilities”). Physical barrier controls are used to prevent unauthorized entrance to Facilities both at the perimeter and at building access points. Recipient implements commercially reasonable access controls appropriate to the sensitivity of the Personal Data processed. Visitors to sensitive areas follow Recipient’s standard visitor management procedures.

Limited Employee and Contractor Access

Recipient provides access to the Facilities to those employees and contractors who have a legitimate business need for such access privileges. When an employee or contractor no longer has a business need for the access privileges assigned to them, the access privileges are promptly revoked, even if the employee or contractor continues to be an employee of Recipient of its affiliates, unless required for business continuity.

Physical Security Protections

Based on the sensitivity of Personal Data processed, all access points (other than main entry doors) are maintained in a secured (locked) state. Access points to the Facilities may be monitored by appropriate security measures designed to record all individuals accessing the Facilities. Where appropriate to the risk level, Recipient may implement electronic intrusion detection systems designed to detect unauthorized access to the Facilities, including monitoring points of vulnerability (e.g., primary entry doors, emergency egress doors, etc.) with door contacts, or other devices designed to detect individuals attempting to gain access to the Facilities. Physical access to areas containing Personal Data to the Facilities by employees and contractors is logged and routinely audited.

Continued Evaluation

Recipient will conduct annual reviews of the Security of its Recipient Network and adequacy of its information security program, limited to the security measures specifically outlined in this Annex, as measured against industry security standards and its policies and procedures. Recipient will annually evaluate the security of its Recipient Network to determine whether commercially reasonable additional or different security measures are required to respond to new security risks or findings generated by the annual reviews. Additional security measures beyond this Annex requires mutual agreement.

Logging Monitoring

  • Recipient shall implement centralized logging mechanisms to track access to network resources and Personal Data. Logs must:
    • Be retained for a minimum of one year.
    • Be protected against tampering.
    • Be regularly monitored and audited.
  • Unusual patterns or unauthorized access attempts must trigger immediate alerts and investigation.

Regular Security Assessments

Recipient shall conduct security awareness training for all employees handling Personal Data. Training must cover secure data handling, phishing prevention, and compliance obligations. Sessions must be conducted annually and upon onboarding.

Annex III – List of Sub-processors

Below is the list of the Data Importer’s Sub-processors:

# Name Details
1 Google (GCP BigQuery) Address: 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA
Contact details: Google Help Center
Description of processing: Data Storage and processing
2 Amazon (Cloudfront) Address: 410 Terry Avenue North, Seattle, WA 98109-1226, USA
Contact details: Amazon Customer Service
Description of processing: CDN Service
3 Cloudflare Address: Cloudflare, Ltd. Attn: Data Protection, 2nd Floor, 25 Lavington Street, London SE1 0NZ, United Kingdom
Contact details: dpo@cloudflare.com
Description of processing: CDN Service
4 Clickhouse Address: 4113 Alpine Rd, Portola Valley, CA 94028, USA
Contact details: privacy@clickhouse.com
Description of processing: Data Base

The connected power of sports

Platform

  • Minute Video
  • Minute SSP
  • Content Offerings
  • Data & AI Tools

Solutions

  • Publishers
  • Advertisers
  • Teams & leagues
  • Podcast creators

Company

  • About Us
  • Editorial
  • Newsroom
  • Careers
  • Contact

Connect

  • LinkedIn
  • Twitter / X
  • Instagram

© 2026 Minute. All rights reserved.

  • Privacy policy
  • Terms of use
  • Cookie policy
  • UK Modern Slavery Act 2015
  • Data Processing Addendum