Utilen's Privacy Policy
Last updated: September 26, 2026
1 INTRODUCTION
1.1 Utilen (“we,” “us,” or “our”) is committed to protecting your privacy. This Privacy Policy explains how we collect, use, store, and protect personal information submitted through our website utilen.com, including via contact forms.
1.2 IMPORTANT: BY USING THE SITE AND/OR OFFERINGS AVAILABLE ON THIS SITE, YOU GIVE YOUR CONSENT THAT ALL PERSONAL DATA THAT YOU SUBMIT MAY BE PROCESSED BY US IN THE MANNER AND FOR THE PURPOSES DESCRIBED BELOW. IF YOU DO NOT AGREE TO UTILEN’S PRIVACY POLICY OR ITS MASTER SERVICES AGREEMENT OR THE TERMS AND CONDITIONS FOR THE RENDERED SERVICES, DO NOT USE THE SITE.
1.3 We reserve the right to change this Privacy Policy from time to time. We will notify you about significant changes in the way we treat personal information by sending a notice to the primary email address specified in your account, by placing a prominent notice on our site, and by updating any privacy information on this page. Your continued use of the Site and or Services available through this Site after such modifications will constitute your: (a) acknowledgment of the modified Policy; and (b) your agreement to abide and be bound by that Policy.
1.4 Under specific conditions, additional laws and regulations may apply to you that provides additional and/or alternative rights to you as a Customer. In this case, Utilen intends to abide by those laws. Utilen’s Data Processing Addendum is intended to address and explain these additional regulations, rights, and requirements. Utilen’s Data Processing Addendum only applies to the extent you are covered by these additional regulations.
2 INFORMATION WE COLLECT
2.1 We may collect the following types of information:
2.1.1 Identifiers: this includes Personally Identifiable Information (“PII”), including, without limitation, name, email, IP address;
2.1.2 Sensitive Personal Information: this is a subset of Identifiers, and includes PII of a sensitive natures, such as account login credentials, payment information, and precise geolocation, including addresses
2.1.3 Commercial information: this category of information covers information related to the enterprise, including, without limitation, purchase history;
2.1.4 Internet/Network Activity: this category of information covers your activity on the website, including, without limitation, browsing behavior, cookie data;
2.1.5 Geolocation Data: this category of information covers any location information received from your device while on the website;
2.1.6 Professional/employment information: this category of information covers information about your employment, including, without limitation, the company you work for, position, title, department, administrative role and/or access settings;
2.1.7 Inference information: are any inferences that can be drawn from the above, including vector embedding and other derived representations generated from any of the categories above;
2.1.8 Communications content: the content and metadata of messages exchanged between users through Platform messaging features, including message text, attachments, timestamps, the identity of sender and recipients, and delivery or read state; and
2.1.9 User-uploaded content: documents and files uploaded to the Platform by users, including the contents of those documents, any metadata supplied at the point of upload, and any personal information contained within them.
2.2 When you engage in certain activities on this Site, such as registering for an account, downloading or purchasing a product or service, submitting content and/or posting content in the user sections, or sending us feedback, we may ask you to provide certain information about yourself.
2.3 Utilen collects the following information for the following purpose:
2.4 Utilen’s internal operations console accesses production data stored on the Platform including any of the above identified data: Access to operational data is provided for user onboarding and assistance, technical support, trouble shooting, and verifying contractual and legal obligations.
3 HOW WE COLLECT YOUR INFORMATION
3.1 We do not collect any PII about you unless voluntarily provide it to us. This may include information received directly from you or provided by users of the platform in the form of customer data (see 3.2 below). You may be required to provide certain PII to us when you elect to use certain products or services available on the Site. These may include: (a) registering for an account on our Site; (b) sending us an email message; (c) submitting a form or transmitting other information by telephone or letter; or (d) submitting your credit card or other payment information when ordering and purchasing products and services on our Site. When processing certain information, such as payment information with affiliated banking institutions or payment processors, we encrypt the transaction, using Secure Socket Layer (SSL) encryption technology, in order to prevent your PII from being stolen or intercepted.
3.2 In addition to information you provide directly, the Platform collects information that arises from your use of it. This includes the content of messages you send through the Platform’s messaging features, the contents of documents and files you upload, and derived representations, including vector embeddings, generated from that content so that it can be searched and retrieved. This information is collected as a necessary function of providing those features.
4 COOKIES
4.1 Depending on how you use our Site, we may store cookies on your computer in order to collect certain aggregate data about our users and to customize certain aspects of your specific user experience. A cookie is a small data text file which is stored on your computer that uniquely identifies your browser. Cookies may also include more personalized information, such as your IP address, browser type, the server your computer is logged onto, the area code and zip code associated with your server, and your first name to welcome you back to our Site. We may use cookies to perform tasks such as: monitoring aggregate site usage metrics, storing and remembering your passwords (if you allow us to do so), storing account and advertising preferences that you have set, and personalizing the Services we make available to you.
4.2 How do we use cookies?
4.2.1 Essential / operational: These cookies are essential for our website to function. They usually enable your movement around our website and services you have specifically asked for, such as setting your privacy preferences, or filling in forms. For example, essential cookies include session cookies needed to transmit the website, authentication cookies, and security cookies. This category of cookies cannot be disabled.
4.2.2 Performance and analytics: These cookies allow us to learn how well our Websites perform. We also use these cookies to better understand how visitors use our Websites so we can improve their experience. For example, we use Google Analytics cookies to help us understand how visitors arrive at and browse our Websites and to identify areas for improvement such as navigation and marketing campaigns. If you do not allow these cookies, we will not know when you have visited our site and will not be able to monitor its performance.
4.2.3 Marketing: These cookies are used in order to better understand users’ needs and their interactions with our marketing communications, such as a marketing email or marketing-based landing page on our website. If you decide to identify yourself, e.g. by signing up or filling out a form, these cookies may collect personal information (e.g., email address) about you. In particular, we use a marketing database management platforms (such as Google Analytics) – that helps us improve our marketing and focus our marketing efforts to those most appreciated by our visitors and better understand our visitors’ needs and to optimize our Websites.
4.2.4 Targeting: These cookies may be set through our site by our advertising partners. They may be used to serve you with advertisements that may be relevant to you and your interests on other web sites and services, to suppress ads not relevant to you, (i.e., negative targeting), to refine our campaigns and to measure their effectiveness. If you do not allow these cookies, you will experience less targeted advertising.
4.3 Cookies used by third parties
4.3.1 Some third-party services that we may use may place their own cookies in your browser. This policy covers use of cookies by Utilen only and not the use of cookies by third parties. Third-party cookies are limited to our Websites and are not used in our Services.
4.3.2 Third party service providers that we currently use, and which may use and place their own cookies in your browser include:
4.3.3 The above list of third party service providers that place cookies is subject to change and the above list may not include all such providers at any given time. An updated vendor list may be found here (www.utilen.com/utilen-security), in which one or more of these vendors may use cookies according to their own policies.
4.4 Third-party embeds
4.4.1 Some of the contents that you see displayed on the Utilen websites is not hosted by Utilen. For example, when you play a YouTube video embedded in it, YouTube receives data about your activity. Utilen does not control what data third parties collect in cases like this, or what they will do with it. So, third-party embeds are not covered by this policy. They are covered by the privacy policy of the third-party service.
4.5 How you can control cookies?
4.5.1 Consent tool
4.5.1.1 Currently all users are opted-out of all non-essential cookies. Once additional cookies are incorporated, Utilen will provide users access to cookie settings to make selections regarding which cookies Utilen can use.
4.5.1.2 You can choose not to allow some types of cookies. To change your cookie settings and preferences, click the “Cookie Settings” link in the footer of the page. To apply changes, please refresh your browser after saving your settings. Please note that blocking some types of cookies may impact your experience and the full functionality of the website may no longer be available.
4.5.2 Browser settings
4.5.2.1 You are free to decline cookies by applying the appropriate browser settings. You can learn more about managing cookie settings at the following links. Chrome; Firefox; Microsoft Edge; Safari; Brave.
4.5.2.2 As there are lots of different browsers, we cannot give instructions for all of them here. For other browsers, please consult the documentation that your browser manufacturer provides.
4.6 Most browsers are initially set up to accept cookies, but you can reset your browser to refuse all cookies or to indicate when a cookie is being sent. However, some aspects of the Site may not function properly if you elect to disable cookies.
5 HOW WE STORE AND PROTECT YOUR INFORMATION
5.1 Your information is stored securely on our servers or those of trusted service providers. We implement reasonable technical and organizational measures to protect your data from unauthorized access, loss, or misuse. Data is retained only for as long as necessary to fulfill the purpose of your submission or as required by law.
5.2 Information including identifiers will be stored and used as long as a user account is active and for the legal period for retention thereafter according to the Master Services Agreement and related Terms and Conditions pertaining to the given information.
5.3 Commercial information, internet/network activity, and inferences drawn therefrom will be compiled in an aggregate, non-identifiable form and stored and may be used by Utilen indefinitely.
6 HOW WE USE YOUR INFORMATION
6.1 We will primarily use your information to provide product or service offerings to you. We will also use certain forms of information to enhance the operation of our Site, improve our internal marketing and promotional efforts, statistically analyze Site use, improve our product and service offerings, and customize our Site’s content, layout, and services. We may use information to deliver the Services to you and to contact you regarding administrative notices. Finally, we may use your information to resolve disputes, troubleshoot problems and enforce our agreements with you, including our User Terms of Use, and this Privacy Policy.
6.2 We do provide some of our product and service offerings through contractual arrangements made with affiliates, service providers, partners and other third parties (“Service Partners”). We and our Service Partners may need to use some information in order to perform tasks between our respective sites, or to deliver products or services to you. For example, we must release your credit card information to the card-issuing bank to confirm payment for products and services purchased on this Site; release your address information to the delivery service to deliver products that you ordered; and provide order information to third parties that help us provide customer service.
6.3 We may share your information with the following categories of third parties:
6.3.1 Service providers: these are entities that assist in rendering the Services or performing commercial actions at your request, including, without limitation, payment processors, shippers, and vendors;
6.3.2 Advertising partners: these are entities that provide advertising services;
6.3.3 Analytics providers: these are entities that observe usage and provide analytics about the activities on the website and Platform;
6.3.4 Affiliates: these are entities that are co-owned, owned by, own, or otherwise related to Utilen, including Utilen Canada.
6.3.5 Artificial intelligence and model providers: these are entities that provide large language model, embedding, and related inference services used to deliver search, retrieval, and AI-assisted features on the Platform.
6.4 We will encourage our Service Partners to adopt and promote strong privacy policies. However, the use of your information by our Service Partners is governed the respective privacy policies of those providers and is not subject to our control. Except as otherwise discussed in this Privacy Policy, this document only addresses the use and disclosure of information we collect from you. Other Sites accessible through this Site, including our Advertising and Service Partners, have their own privacy policies and data collection, use and disclosure practices. Please consult each Site’s privacy policy. We are not responsible for the policies or practices of third parties.
6.5 The following categories of third parties have access to the categories of information:
6.6 Occasionally we may be required by law enforcement or judicial authorities to provide PII to the appropriate governmental authorities. In such cases, we will disclose PII upon receipt of a court order, subpoena, or to cooperate with a law enforcement investigation. We fully cooperate with law enforcement agencies in identifying those who use our services for illegal activities. We reserve the right to report to law enforcement agencies any activities that we in good faith believe to be unlawful.
6.7 We may also collect certain Aggregate Information. For example, we may use your IP address to diagnose problems with our servers, software, to administer our Site and to gather demographic information.
6.8 We may also provide Aggregate Information about our customers’ sales, traffic patterns, and related Site information to third party advertisers, but these statistics do not include any Personally Identifiable Information.
6.9 Certain features of the Platform, including search, retrieval, and assisted drafting, are delivered using third-party artificial intelligence services. To provide these features, we transmit the relevant portions of your content to those providers over encrypted connections. The providers we currently use are identified in Annex 3 of our Data Processing Addendum and is provided on our Subprocessor list found www.utilen.com/utilen-security.
6.10 We do not permit our artificial intelligence and model providers to use content transmitted to them in the course of providing the Services to train or improve their models. This restriction is imposed by contract with each provider.
6.11 To make your content searchable, we generate vector embeddings and similar machine-readable representations from it. These representations are stored in a search index and exist independently of the content from which they were generated. They are subject to the deletion commitments in Sections 8.3 and 12.6.
6.12 We do not use automated processing to make decisions producing legal or similarly significant effects concerning you without human involvement. Where such processing is introduced, we will provide notice in advance and honor the rights described in Section 10.
7 THIRD-PARTY LINKS
7.1 Our website may link to external sites. We are not responsible for the privacy practices or content of these third-party sites.
8 YOUR ABILITY TO ACCESS, UPDATE, AND CORRECT INFORMATION
8.1 We believe you should have the ability to access and edit the PII that you have provided to us. You may change any of your PII in your account online at any time by linking to your account in accordance with instructions posted elsewhere on this Site. You may also access and correct your personal information and privacy preferences by emailing or writing us at:
Utilen
Attn: Privacy Compliance Officer, Utilen
PO BOX 270157 Saint Paul, MN 55127
Email:legal@utilen.com
8.2 Please include your name, address, and/or email address when you contact us.
8.3 We encourage you to promptly update your PII if it changes. You may ask to have the information on your account deleted or removed; however, some information, such as past transactions, logs of technical support calls, or other information may not be deleted. In addition, it may be impossible to completely delete your information without some residual information because of backups. Where information you have asked us to delete has been used to generate derived representations, including vector embeddings, we will delete or regenerate those representations so that they no longer reflect the deleted information.
9 YOUR CHOICES ON COLLECTION AND USE OF INFORMATION
9.1 We may, from time to time, send you email regarding new products and services that we feel may interest you. In addition, if you indicated upon registration that you are interested in receiving offers or information from us and our partners, we may occasionally call or send you direct mail about products and services that may be of interest to you. Only Utilen (or agents working on behalf of Utilen and under confidentiality agreements) will send you these solicitations, and only if you have previously indicated that you wish to receive them. If you do not want to receive solicitations from us, you can “opt-out” by accessing your account online editing your account information to no longer receive such offers and mailings.
9.2 You also have choices with respect to cookies, as described above. By modifying your browser preferences, you have the choice to accept all cookies, to be notified when a cookie is set, or to reject all cookies. If you choose to reject all cookies some parts of our Site may not work properly in your case.
10 YOUR RIGHTS
10.1 Depending on your jurisdiction, you may have the right to:
10.1.1 Right to know what is collected;
10.1.2 Access or correct your personal information;
10.1.3 Request deletion of your data;
10.1.4 Withdraw consent for data processing;
10.1.5 Opt-out of sale and sharing of your information;
10.1.6 Limit use of sensitive personal information; and
10.1.7 Data portability; and
10.1.8 Be informed of, and where applicable opt out of or appeal, decisions based solely on automated processing, including profiling.
10.2 Utilen provides additional privacy and data terms in its Data Processing Addendum that may apply depending on your jurisdiction accessible at utilen.com/privacy-policy. If your jurisdiction is not covered by the Data Processing Addendum, please reach out to us at legal@utilen.com to obtain any additional privacy and data terms that may apply to you.
10.3 Utilen will not discriminate against users who exercise their rights to control their information, and will not be denied service, charged different prices, or be given a lower quality of service.
10.4 To exercise these rights, contact us via our contact form on utilen.com/contact-us. We will respond within the timeframes required by applicable laws. For information requested under CCPA, Utilen will provide a response within forty-five (45) days.
You may also reach us by written communication at:
Attn: Privacy Compliance Officer, Utilen
PO BOX 270157 Saint Paul, MN 55127
Email: legal@utilen.com
10.5 Utilen may verify your identity before responding to a request to exercise your rights under this provision. Utilen may use contact information to contact you outside of the website or Platform to confirm your identity, including video conferencing, phone calls, emails, or other interface.
11 OUR COMPLIANCE WITH LAWS
11.1 We comply with applicable data protection laws, including the California Consumer Privacy Act (CCPA) for California residents, where relevant.
12 INTERNATIONAL DATA TRANSFER AND STORAGE
12.1 We are based in the United States, and the personal information we collect — including information about individuals named in procurement records, vendor contacts, and authorized users of the Platform — is stored and processed on servers located in the United States, operated by Amazon Web Services (AWS), in its US-East region. Certain sub-processors identified in Annex 3 of our Data Processing Addendum process or store personal information on their own infrastructure rather than on AWS, including our backup, authentication, electronic mail, notification, and artificial intelligence providers. The locations of such processing is provided in the Data Processing Addendum and on the Sub-Processor list found www.utilen.com/utilen-security.
12.2 By using our website or the Utilen Platform, you acknowledge that your personal information will be transferred to, stored in, and processed in the United States, and will therefore be subject to the laws of the United States, including laws that permit access to personal information by U.S. government authorities, courts, law enforcement, or regulatory agencies (such as the U.S. CLOUD Act).
12.3 We take contractual, technical, and organizational measures designed to protect personal information consistent with the standards required under Canadian privacy law, including the Personal Information Protection and Electronic Documents Act (PIPEDA) and applicable provincial legislation, regardless of where the information is processed. We remain accountable for personal information transferred to third parties for processing.
12.4 All categories of data as described in this Privacy Policy may be transferred to the United States.
12.5 A current list of sub-processors who may access or process personal information is available at www.utilen.com/utilen-security.
12.6 Unless deletion or removal is requested, we retain personal information for 7 years or the duration of contract plus 6 years and securely delete or anonymize it thereafter, except where retention is required by law. In the event of a request for deletion, your information is deleted or returned within sixty (60) days of the request unless the information is legally required. Information is legally required, for example, to maintain accounting records, to maintain vendor and sales information, to permit and meet notice requirements, to comply with litigation holds, for security for backup systems. The retention of data will depend on whether your use of our website, such as if you are a customer using our Platform or simply a visitor to the website. Messages exchanged through the Platform’s messaging features are retained according to our data retention policy, or until deleted by the Customer, whichever is earlier. Derived representations, including vector embeddings, are retained for no longer than the content from which they were generated, and are deleted or regenerated when that content is deleted.
12.7 Regardless of where your information is stored, you may request access to, correction of, or deletion of your personal information by contacting our Compliance Officer at legal@utilen.com.
12.8 If you are located in Quebec, additional rights and protections apply under Quebec's Act, including the right to request information about our cross-border transfer practices.
13 CHANGES TO THIS POLICY
13.1 We may update this Privacy Policy periodically. Changes will be posted on this page, and the “Last Updated” date will reflect the latest revision. Continued use of the website after changes constitutes acceptance of the updated policy.
14 CONTACT US
14.1 For questions or concerns about this Privacy Policy or your personal information, please contact us via our contact form.
15 MISCELLANEOUS
15.1 You must be at least 18 years old to have our permission to use this Site. Our policy is that we do not knowingly collect, use or disclose PII about minor visitors.
Data Processing Addendum
Last Updated: September 26, 2026
1 INTRODUCTION
1.1 Utilen (“we,” “us,” or “our”) has a standard Privacy Policy in place to which you are aware and bound and which explains how we collect, use, store, and protect personal information submitted through our website utilen.com, including via contact forms.
1.2 If you are using or engaging the Utilen Platform or accessing services provided by Utilen through its platform, you are operating under an agreement with Utilen, including, without limitation: Master Services Agreement, our User Terms of Use, and our Privacy Policy.
1.3 This Data Processing Addendum (“DPA”) is in addition to and supplements the Privacy Policy and applies when specific data privacy laws apply. All data-processing, sub-processing, security, incident-notification, and cross-border-transfer commitments applicable to Personal Data processed by Utilen — including with respect to Québec residents and other individuals in Canada — (inclusively “Processing”) are now consolidated in this single DPA.
1.4 Utilen wish to ensure that such Processing complies with the California Consumer Privacy Act of 2018, as amended by the California Privacy Rights Act of 2020, and its implementing regulations (collectively, “CCPA”); the Texas Data Privacy and Security Act (“TDPSA”); the Minnesota Consumer Data Privacy Act (“MCDPA”); the Delaware Personal Data Privacy Act (“DPDPA”); the Personal Information Protection and Electronic Documents Act, S.C. 2000 c. 5, and its regulations, including the Breach of Security Safeguards Regulations, SOR/2018-64 (collectively, “PIPEDA”); and Québec’s Act respecting the protection of personal information in the private sector, as amended by the Act to modernize legislative provisions as regards the protection of personal information (“Law 25”), together with any other applicable data protection or privacy law (collectively, “Data Protection Laws”).
1.5 Therefore, this DPA establishes the Parties respective rights and obligations concerning the Processing of Personal Data on the Utilen Platform.
1.6 IMPORTANT: BY USING THE SITE AND/OR OFFERINGS AVAILABLE ON THIS SITE, YOU GIVE YOUR CONSENT THAT ALL PERSONAL DATA THAT YOU SUBMIT MAY BE PROCESSED BY US IN THE MANNER AND FOR THE PURPOSES DESCRIBED HEREIN AND WITH RESPECT TO OUR PRIVACY POLICY. IF YOU DO NOT AGREE TO UTILEN’S PRIVACY POLICY, ITS MASTER SERVICES AGREEMENT, ANY APPLICABLE TERMS AND CONDITIONS FOR THE RENDERED SERVICES, OR THE TERMS CONTAINED HEREIN, DO NOT USE THE SITE.
1.7 We reserve the right to change this Data Processing Addendum from time to time. We will notify you about significant changes in the way we treat personal information by sending a notice to the primary email address specified in your account, by placing a prominent notice on our site, and by updating any privacy information on this page. Your continued use of the Site and or Services available through this Site after such modifications will constitute your: (a) acknowledgment of the modified DPA; and (b) your agreement to abide and be bound by that DPA.
2 DEFINITIONS
2.1 Terms Defined in the Agreement. Capitalized terms used but not defined in this DPA have the meanings given in the Master Services Agreement and Privacy Policy.
2.2 Cross-Jurisdictional Definitions. Because California, Delaware, Texas, Minnesota, Québec, and Canada (under PIPEDA) use different statutory vocabulary for the same underlying roles and concepts, this DPA uses the umbrella terms below. Where a jurisdiction-specific obligation applies only under a particular law, Articles 5–9 say so expressly. For purposes of PIPEDA, the umbrella terms correspond as follows: “Customer” is the “organization” that remains accountable for Personal Information under its control (PIPEDA Schedule 1, Principle 4.1); “Utilen” is a “third party” to which Personal Information is transferred for processing (Principle 4.1.3); “Personal Data” means “personal information”; “Data Subject” means “individual”; and “Security Incident” includes a “breach of security safeguards.”
2.3 Additional Definitions.
- “Customer Data” means all Personal Data and other information, content, and data submitted, transmitted, or uploaded to the Utilen Platform by or on behalf of Customer or its Authorized Users, excluding Feedback, as defined in the MSA.
- “Personal Data” means information that identifies, relates to, describes, or is reasonably capable of being associated with an identified or identifiable natural person, including “personal information” as defined under the CCPA, “personal data” as defined under the TDPSA, MCDPA, and DPDPA, “personal information” as defined under Law 25, and “personal information” as defined under PIPEDA, in each case to the extent it constitutes Customer Data.
- “Sensitive Personal Data” means Personal Data within a category subject to heightened protection under applicable Data Protection Laws, including “sensitive personal information” under the CCPA and “sensitive data” under the TDPSA, MCDPA, and DPDPA, and personal information that is sensitive within the meaning of PIPEDA Schedule 1, Principle 4.3.4.
- “Sell” / “Share” have the meanings given in Cal. Civ. Code § 1798.140.
- “Sub-processor” means any third party engaged by Utilen to Process Personal Data in connection with the Services, including infrastructure and hosting providers.
- “Security Incident” means any confirmed unauthorized or unlawful access to, acquisition of, disclosure of, or loss of Personal Data Processed by Utilen under this DPA, including a “Confidentiality Incident” as that term is used in Law 25, and a “breach of security safeguards” as defined in section 2(1) of PIPEDA.
- “ADMT” (Automated Decision-Making Technology) has the meaning given under the CCPA regulations (11 CCR § 7001, as amended), and refers to technology that processes Personal Data to substantially replace human decision-making in a manner that produces a legal or similarly significant effect concerning a consumer.
- “Processing” / “Process” means any operation performed on Personal Data, including collection, use, storage, disclosure, retrieval, or destruction.
2.4 Interpretation. In the event of a conflict between this DPA and the MSA with respect to the Processing of Personal Data, this DPA controls, except that nothing in this DPA expands Utilen’s liability beyond the limitations of liability set forth in the MSA, as clarified in Article 17.
3 SCOPE AND ROLES
3.1 Scope. This DPA applies to all Processing of Personal Data by Utilen on behalf of Customer in connection with the Services, including Personal Data of Data Subjects located in California, Texas, Delaware, Minnesota, and Canada (including Québec).
3.2 Roles.
(a)California: Customer is a Business and Utilen is a Service Provider (or, where applicable, a Contractor) with respect to Personal Information Utilen Processes on Customer’s behalf.
(b)Texas, Delaware, and Minnesota: Customer is the Controller and Utilen is the Processor with respect to Personal Data Utilen Processes on Customer’s behalf.
(c)Québec: Customer is the Person Carrying on an Enterprise and Utilen is the Mandatary performing this DPA and the Agreement (a contract for services within the meaning of Law 25, s. 18.3) with respect to Personal Information Utilen Processes on Customer’s behalf.
(d)Canada (PIPEDA): Customer is the organization accountable for Personal Information under its control, including Personal Information it transfers to Utilen, and Utilen is a third party that Processes such Personal Information on Customer’s behalf within the meaning of PIPEDA Schedule 1, Principle 4.1.3.
3.3 Instructions. Utilen shall Process Personal Data only (a) to provide, maintain, and support the Services under the Agreement; (b) in accordance with Customer’s documented instructions, including those in the Agreement and this DPA; or (c) as required by applicable law, in which case Utilen will, where legally permitted, notify Customer before such Processing. The Agreement, this DPA, and Customer’s configuration and use of the Services constitute Customer’s complete documented instructions to Utilen.
3.4 Customer Responsibilities. Customer is responsible for (a) the accuracy, quality, and legality of Personal Data and the means by which it was collected; (b) providing any notices to, and obtaining any consents required from, Data Subjects; and (c) ensuring it has a lawful basis for the Processing it instructs Utilen to perform, including any disclosure to Utilen itself.
3.5 Details of Processing. The subject matter, duration, nature, and purpose of the Processing, the categories of Personal Data, and the categories of Data Subjects are described in Annex 1.
4 REQUIREMENTS COMMON TO ALL JURISDICTIONS
4.1 Confidentiality. Utilen shall ensure that each person it authorizes to Process Personal Data (including employees, contractors, and Sub-processors) is subject to a written or statutory duty of confidentiality with respect to that Personal Data.
4.2 Purpose Limitation. Utilen shall not retain, use, or disclose Personal Data for any purpose other than the specific business purpose(s) of providing the Services under the Agreement, and shall not use Personal Data for its own independent business purposes, except as expressly permitted by Section 4.5 (De-Identified and Aggregated Data) or as otherwise required by law.
4.3 No Combining of Data. Utilen shall not combine or update Personal Data received under this DPA with personal information Utilen receives from or on behalf of another customer, or that Utilen collects from its own interactions with the Data Subject, except: (a) to detect security incidents, protect against fraud, or debug; (b) for the limited allowed purposes stated in Annex 1; or (c) with Customer’s prior written consent.
4.4 Security Measures. Utilen shall implement and maintain the technical and organizational security measures described in Annex 2, appropriate to the risk presented by the Processing, including access controls, encryption in transit and at rest, and a tested incident response plan.
4.5 De-Identified and Aggregated Data. Nothing in this DPA restricts Utilen’s ability to create and use aggregated or de-identified data (as those terms are defined under the CCPA, TDPSA, DPDPA, and MCDPA) and, for PIPEDA, information for which there is no serious possibility that an individual could be identified, alone or in combination with other available information) derived from Personal Data, provided that Utilen: (a) takes reasonable measures to ensure the data cannot be associated with a Data Subject; (b) publicly commits to maintaining and using the data only in de-identified form; and (c) contractually obligates any recipient of such data to comply with these requirements. For clarity, this Section does not authorize Utilen to re-identify, or attempt to re-identify, de-identified data.
4.6 Deletion or Return. On termination or expiration of the Agreement, or on Customer’s written request, Utilen shall, at Customer’s election, delete or return all Personal Data Processed under this DPA, except to the extent retention is required by applicable law, as further described in Article 16.
4.7 Compliance Information and Assessments. Utilen shall make available to Customer, on reasonable request, information reasonably necessary to demonstrate Utilen’s compliance with this DPA, and shall allow and reasonably cooperate with assessments as described in Article 15.
4.8 Allocation of Security Responsibility. The parties agree that: Utilen is responsible for the technical and organizational security measures described in Annex 2 with respect to the Utilen Platform and infrastructure under its control; Customer is responsible for its own access credentials, user-permission configuration within the Platform, and the security of any systems from which Customer or its Authorized Users access the Platform. This allocation satisfies the parties’ obligation under the MCDPA to establish a clear allocation of security responsibilities.
5 CALIFORNIA-SPECIFIC REQUIREMENTS (CCPA/CPRA)
5.1 This article implements the mandatory service-provider contract terms of 11 CCR § 7051, and the related 2026 amendments addressing automated decision-making technology, risk assessments, and cybersecurity audits, and is applicable only for California residents when the CCPA/CPRA applies.
5.2 Business Purpose. Utilen is disclosed Personal Information solely for the business purpose of providing, maintaining, securing, and supporting the Utilen Platform and Services described in the Agreement (the “Business Purpose”), and for no other business purpose.
5.3 No Sale or Sharing. Utilen shall not sell or share (as those terms are defined under the CCPA) any Personal Information it collects, receives, or accesses under this DPA.
5.4 Purpose Limitation and No Retention Beyond Purpose. Utilen shall not retain, use, or disclose Personal Information for any purpose other than the Business Purpose specified in Section 5.2, or as otherwise permitted by the CCPA, including Section 4.5 above.
5.5 Standard of Protection. Utilen shall comply with all applicable sections of the CCPA and its implementing regulations and shall provide the same level of privacy protection as is required of a business under the CCPA.
5.6 Right to Audit and Remediate. Customer has the right, upon reasonable notice, to take reasonable and appropriate steps to ensure Utilen uses Personal Information in a manner consistent with Customer’s obligations under the CCPA, including ongoing manual reviews, automated scans, and the assessment and audit rights described in Article 15. If Customer determines that Utilen is using Personal Information in an unauthorized manner, Customer may direct Utilen to stop and remediate the unauthorized use, and Utilen shall comply promptly.
5.7 Notice of Inability to Comply. Utilen shall notify Customer promptly if it determines it can no longer meet its obligations under the CCPA.
5.8 Consumer Requests. Utilen shall assist Customer in responding to verified consumer requests to know, delete, correct, or opt out of the sale/sharing of Personal Information, and to limit the use of Sensitive Personal Information, as further described in Article 13.
5.9 Automated Decision-Making Technology (ADMT). To the extent Utilen provides or supports any ADMT used by Customer to make a decision that produces a legal or similarly significant effect concerning a consumer, Utilen shall: (a) provide Customer with the information reasonably necessary for Customer to issue any required Pre-Use Notice; (b) support consumer opt-out and appeal mechanics, including honoring any downstream notification obligations within fifteen (15) days following a post-processing opt-out communicated by Customer; and (c) provide information sufficient for Customer to respond to consumer access requests concerning the ADMT.
5.10 Risk Assessment Support. Where Customer’s use of the Services triggers an obligation to conduct a risk assessment under the CCPA regulations, Utilen shall provide Customer with the information reasonably necessary to complete that assessment, including the categories of recipients of Personal Information (identifying Utilen and any Sub-processors) and, to the extent Utilen provides ADMT used for a significant decision, the logic, inputs, and outputs of that ADMT.
5.11 Cybersecurity Audit Cooperation. If Customer is subject to the CCPA’s annual cybersecurity audit requirement, Utilen shall provide Customer with reasonable visibility into Utilen’s security program sufficient to support that audit, including making relevant security documentation available on request, subject to reasonable confidentiality protections.
6 TEXAS-SPECIFIC REQUIREMENTS (TDPSA)
6.1 This article implements the specific requirements under Texas privacy laws, including TDPSA, and is applicable only for Texas Customers and Texas residents and where the TDPSA applies.
6.2 Processor Contract Terms. In accordance with Tex. Bus. & Com. Code § 541.105, this DPA sets forth clear instructions for Processing (Article 3 and Annex 1), the nature and purpose of Processing (Annex 1), the type of Personal Data subject to Processing (Annex 1), the duration of Processing (Article 18), and the rights and obligations of both parties (this DPA in its entirety).
6.3 Processor Obligations. Utilen shall: (a) ensure each person Processing Personal Data is subject to a duty of confidentiality (Section 4.1); (b) at Customer’s direction, delete or return Personal Data after the provision of Services is complete, unless retention is required by law (Article 16); (c) make available to Customer, on reasonable request, information necessary to demonstrate compliance with the TDPSA (Section 4.7); (d) allow and cooperate with reasonable assessments by Customer or Customer’s designated assessor (Article 15); and (e) engage Sub-processors only pursuant to a written contract requiring the Sub-processor to meet Utilen’s obligations with respect to the Personal Data (Article 10).
6.4 Assistance. Utilen shall assist Customer, taking into account the nature of the Processing and information available to Utilen, in meeting Customer’s obligations to respond to consumer rights requests, maintain appropriate security, provide breach notification, and conduct and document data protection assessments under the TDPSA.
7 MINNESOTA-SPECIFIC REQUIREMENTS (MCDPA)
7.1 This article implements the requirements under Minnesota privacy laws, including MCDPA, and is applicable only for Minnesota entities and Minnesota user residents when the MCDPA applies.
7.2 Processor Contract Terms. In accordance with Minn. Stat. § 325O, this DPA is a binding contract that clearly sets forth instructions for Processing, the nature and purpose of Processing, the type of Personal Data subject to Processing, the duration of Processing, and the rights and obligations of both parties, as set out in Article 3 and Annex 1.
7.3 Processor Obligations. Utilen shall: (a) ensure each person Processing Personal Data is subject to a duty of confidentiality (Section 4.1); (b) at Customer’s direction, delete or return all Personal Data as requested at the end of the provision of Services, unless retention is required by law (Article 16); (c) make available to Customer, on reasonable request, all information necessary to demonstrate compliance with the MCDPA (Section 4.7); (d) allow for, and contribute to, reasonable assessments and inspections by Customer or Customer’s designated assessor (Article 15); and (e) engage a Sub-processor only after providing Customer an opportunity to object, pursuant to a written contract requiring the Sub-processor to meet Utilen’s obligations with respect to the Personal Data (Article 10).
7.4 Security Allocation. The parties’ allocation of technical and organizational security responsibilities is set out in Section 4.8.
7.5 Assistance. Utilen shall assist Customer in meeting Customer’s obligations relating to the security of Processing and shall provide Customer with information necessary to enable Customer to conduct and document any data privacy and protection assessment required under the MCDPA.
8 DELAWARE-SPECIFIC REQUIREMENTS (DPDPA)
8.1 Processor Contract Terms. In accordance with the Delaware Personal Data Privacy Act (6 Del. C. § 12D-101 et seq.), this DPA sets forth clear instructions for Processing (Article 3 and Annex 1), the nature and purpose of Processing (Annex 1), the type of Personal Data subject to Processing (Annex 1), the duration of Processing (Article 18), and the rights and obligations of both parties (this DPA in its entirety).
8.2 Processor Obligations. Utilen shall: (a) ensure each person Processing Personal Data is subject to a duty of confidentiality (Section 4.1); (b) at Customer’s direction, delete or return all Personal Data to Customer at the end of the provision of Services, unless retention is required by law (Article 16); (c) make available to Customer, on reasonable request, all information in Utilen’s possession necessary to demonstrate compliance with the DPDPA (Section 4.7); (d) cooperate with Customer’s data protection assessments under the DPDPA (Article 15); and (e) provide Customer an opportunity to object before engaging a new Sub-processor, and engage that Sub-processor only pursuant to a written contract requiring it to meet Utilen’s obligations with respect to the Personal Data (Article 10).
8.3 Assistance. Utilen shall assist Customer in meeting Customer’s obligations under the DPDPA relating to consumer rights requests and the security of Processing, taking into account the nature of the Processing and the information available to Utilen.
8.4 De-Identified Data. Section 4.5 of this DPA (De-Identified and Aggregated Data) is intended to satisfy the DPDPA’s requirements applicable to de-identified data, including the public-commitment and downstream-contract obligations described there.
9 CANADIAN AND QUÉBEC-SPECIFIC REQUIREMENTS (PIPEDA AND LAW 25)
9.1 Section 9.1 through 9.7 implement Section 18.3 of Law 25, which requires a written contract as a condition of Customer disclosing Personal Information to Utilen as a service provider without the consent of the individuals concerned, and apply only for Quebec, Canadian entities and Quebec user residents when the Law 25 applies.
9.2 Written Mandate. This DPA, together with the Agreement, constitutes the written contract required under Law 25, Section 18.3 for Customer to entrust Personal Information to Utilen for the purpose of performing the Services.
9.3 Confidentiality and Purpose Limitation. Utilen shall: (a) protect the confidentiality of all Personal Information communicated to it by Customer, consistent with the measures described in Annex 2; (b) use such Personal Information only for carrying out this DPA and the Agreement; and (c) not retain such Personal Information after the expiry or termination of the Agreement, except as permitted under Article 16.
9.4 Notification of Confidentiality Incidents. Utilen shall notify Customer’s privacy officer without delay of any Confidentiality Incident, and of any actual or attempted violation by any person of the confidentiality obligations described in Section 9.3(a), affecting Personal Information Utilen Processes on Customer’s behalf. This notification obligation is in addition to and shares the same two business day target described in, Article 12. All other notifications will be handled under Utilen’s security incidence response or disaster recovery plans.
9.5 Verification Rights. Utilen shall allow Customer’s privacy officer (person in charge of the protection of personal information) to conduct any verification relating to the confidentiality requirements of this Article 9, subject to the audit conditions in Article 15.
9.6 Cross-Border Transfer of Québec Personal Information. The parties acknowledge that Customer’s use of the Services will result in Personal Information of individuals located in Québec being transferred to, and Processed in, the United States. To support Customer’s obligations under Law 25 with respect to that transfer, Utilen shall:
(a)provide Customer with the information reasonably necessary for Customer to assess whether the Personal Information will receive a level of protection in the United States that is equivalent to the protection it would receive under Québec law, including the information described in Annex 1 and Annex 2 and the safeguards described in this DPA;
(b)provide reasonable cooperation and information necessary for Customer to conduct a privacy impact assessment (or equivalent transfer impact assessment) with respect to the transfer, on request and at reasonable intervals; and
(c)not further transfer Personal Information of Québec individuals to a jurisdiction other than the United States without providing Customer prior notice sufficient for Customer to complete any assessment Law 25 requires with respect to that further transfer.
Customer remains responsible for completing its own assessment of the destination jurisdiction, conducting any required privacy impact assessment, and informing the individuals whose Personal Information is transferred, as required under Law 25.
9.7 Data Subject Rights Under Law 25. Utilen shall provide reasonable assistance to Customer in responding to requests from Québec Data Subjects to exercise their rights of access, rectification, cessation of dissemination, re-indexing, de-indexing, portability, and withdrawal of consent, and their rights with respect to decisions based exclusively on automated processing, as further described in Article 13.
9.8 PIPEDA Application. Sections 9.8 through 9.16 implement PIPEDA and apply to Personal Information that is collected, used, or disclosed in the course of commercial activities and is subject to PIPEDA, including Personal Information of individuals in Canada that is transferred across provincial or national borders. Where Personal Information of Quebec individuals is subject to both Law 25 and PIPEDA, Utilen shall comply with both, and the more protective requirement applies.
9.9 Accountability and Comparable Protection. Customer remains accountable under PIPEDA Schedule 1, Principle 4.1.3 for Personal Information it transfers to Utilen for processing. This DPA, together with the Agreement, constitutes the contractual means by which Customer ensures that Utilen provides a comparable level of protection while the Personal Information is being Processed by Utilen’s Privacy compliance Officer, reachable at the address in Section 20.4.3, is accountable for Utilen’s compliance with Section 9.8 through 9.16.
9.10 Purpose Limitations and Safeguards. Utilen shall Process Personal Information subject to PIPEDA only for the purposes for which Customer transferred it and in accordance with Section 3.3, and shall protect it by security safeguards appropriate to its sensitivity, as required by PIPEDA Schedule 1 Principle 4.7, including the measures described in Annex 2, Customer is responsible for identifying those purposes and obtaining any consent required under PIPEDA Schedule 1, Principles 4.2 and 4.3.
9.11 Breach of Security Safeguards. Utilen shall notify Customer in accordance with Article 12 of any breach of security safeguards involving Personal Information subject to PIPEDA, whether or not Utilen has determined that the breach creates a real risk of significant harm to an individual, so that Customer can determine whether it must report the breach to the Office of the Privacy Commissioner of Canada and notify affected individuals and other organizations under sections 10.1 and 10.2 of PIPEDA. Utilen shall provide the information reasonably required for any such report or notifications, including the information described in section 2 of the Breach of Security Safeguards Regulations, and shall maintain, and on request provide to Customer, a record of each such breach sufficient for Customer to meet its record-keeping obligations under section 10.3 of PIPEDA, for at least twenty-four (24) months after Utilen notifies customer of the breach.
9.12 Access, Correction, and Challenges. Utilen shall provide reasonable assistance, as further described in Article 13, to enable Customer to respond to requests from individuals to access or correct their Personal Information under PIPEDA Schedule 1, Principles 4.6 and 4.9, and to challenges concerning Customer’s compliance under Principle 4.10, within the time limits set out in Section 8 of PIPEDA.
9.13 Cross-Border Processing and Openness. The parties acknowledge that Personal Information of individuals in Canada will be transferred to, and Processed in, the United States as described in Section 14.1, where it may be accessible to courts, law enforcement, and national security authorities under the laws of the United States. Utilen shall provide Customer with the information reasonably necessary for Customer to meet its openness obligations under PIPEDA Schedule 1, Principle 4.8, including informing individuals that their Personal information may be Processed outside Canada, and shall not transfer Personal Information subject to PIPEDA to a jurisdiction other than the United States without prior notice to Customer under Section 10.3.
9.14 Retention and Destruction. Consistent with PIPEDA Schedule 1, Principle 4.5, Utilen shall not retain Personal Information subject to PIPEDA longer than necessary to fulfill the purpose for which it was transferred, and shall destroy, erase, or anonymize it in accordance with Article 16.
9.15 Regulatory Cooperation. Utilen shall reasonably cooperate with Customer in responding to any complaint, investigation, or audit by the Office of the Privacy Commissioner of Canada relating to Personal Information Utilen Processes on Customer’s behalf, subject to Article 15.
9.16 Successor Legislation. Reference in this DPA to PIPEDA includes any legislation that amends or replaces Part 1 of PIPEDA, including the Protecting Privacy and Consumer Data Act proposed in Bill C-36, from the date that legislation comes into force. Utilen may amend this DPA under Section 20.1 to reflect such legislation.
10 SUB-PROCESSING
10.1 General Authorization. Customer provides general authorization for Utilen to engage Sub-processors to Process Personal Data in connection with the Services, subject to this Article.
10.2 Current Sub-processors. A list of Utilen’s current Sub-processors is available at www.utilen.com/utilen-security.
10.3 Notice of New Sub-processors. Utilen shall provide Customer at least thirty (30) days’ prior written notice (by email or by posting an updated list to the URL in Section 10.2, with email notification of the update) before authorizing a new Sub-processor to Process Personal Data.
10.4 Objection Rights. Customer may object in writing to a new Sub-processor on reasonable data-protection grounds within fifteen (15) days of Utilen’s notice. This objection right satisfies the Minnesota MCDPA’s requirement that Customer be given an opportunity to object before a new Sub-processor is engaged. If the parties cannot resolve the objection in good faith within thirty (30) days, and Utilen cannot reasonably avoid using the objected-to Sub-processor for the affected Services, Customer may, as its sole remedy, terminate the affected portion of the Services, and Utilen shall refund any prepaid, unused fees for that portion.
10.5 Flow-Down. Utilen shall impose on each Sub-processor, by written contract, data protection obligations substantially equivalent to those in this DPA, including confidentiality, security, purpose limitation, and (where applicable) the Canadian and Québec-specific requirements in Article 9. Utilen remains fully responsible to Customer for each Sub-processor’s Processing of Personal Data to the same extent Utilen would be responsible if performing that Processing directly.
11 SECURITY MEASURES
11.1 Utilen shall implement and maintain the technical and organizational measures described in Annex 2, taking into account the state of the art, the costs of implementation, and the nature, scope, and risk of the Processing.
11.2 Utilen may update its security measures over time, provided the update does not materially reduce the overall level of protection.
12 SECURITY INCIDENT NOTIFICATION
12.1 Notification. Utilen shall notify Customer without undue delay, and in any event within two business days after confirming a Security Incident creating a real risk of significant harm and affecting Personal Data Utilen Processes on Customer’s behalf (or, for Personal Information subject to PIPEDA, any breach of security safeguards, as described in Section 9.11). This single two business day standard applies uniformly across all jurisdictions covered by this DPA and is intended to satisfy the Québec “without delay” standard described in Article 9 as well as reasonable-notice expectations under the CCPA, DPDPA, TDPSA, and MCDPA, and to enable Customer to report and notify “as soon as feasible” as required by section 10.1 of PIPEDA.
12.2 Content. The notification shall include, to the extent known: (a) the nature of the Security Incident; (b) the categories and approximate number of Data Subjects and records affected; (c) measures taken or proposed to address the incident; and (d) a contact point for further information. If not all information is available at the time of initial notice, Utilen shall provide updates in phases without undue further delay.
12.3 Cooperation. Utilen shall reasonably cooperate with Customer, at Customer’s expense for material additional costs, to enable Customer to meet its own notification obligations to Data Subjects, regulators, the Québec Commission d’accès à l’information, or the Office of the Privacy Commissioner of Canada, as applicable.
12.4 No Acknowledgment of Fault. Utilen’s notification of, or response to, a Security Incident is not an acknowledgment of fault or liability.
12.5 Customer Responsibility. Customer is solely responsible for making any notifications to Data Subjects or regulators required by applicable law, except to the extent this Article or applicable Data Protection Laws expressly place that obligation on Utilen.
13 DATA SUBJECT AND CONSUMER RIGHTS ASSISTANCE
13.1 General. Utilen shall provide reasonable assistance to Customer to enable Customer to respond to requests from Data Subjects or consumers exercising rights under applicable Data Protection Laws, including rights of access, correction/rectification, deletion, portability, opt-out of sale/sharing or targeted advertising, restriction of Sensitive Personal Data use, non-discrimination, and, where applicable, rights related to profiling and automated decision-making, and challenges concerning compliance under PIPEDA.
13.2 Request Handling. If Utilen receives a request directly from a Data Subject or consumer, Utilen shall, within two (2) business days: (a) inform Customer of the request; and (b) not respond to the request substantively except on Customer’s documented instructions or as required by law.
13.3 Timeframe for Assistance. Utilen shall use commercially reasonable efforts to respond to Customer’s requests for assistance under this Article within ten (10) business days, or such shorter period as is reasonably necessary for Customer to meet a statutory deadline of which Utilen has been given reasonable notice.
13.4 Limitations. Utilen’s assistance obligations under this Article do not require Utilen to (a) disclose Personal Data of other Data Subjects, (b) disclose its own confidential business information or trade secrets, or (c) provide assistance disproportionate to the fees Customer pays for the Services.
14 LOCATION AND CROSS-BORDER TRANSFER OF PERSONAL DATA
14.1 Location of Processing. Personal Data is hosted, stored, and Processed in the United States, consistent with the MSA.
14.2 Canadian Transfers. Transfers of Personal Information of Québec individuals to the United States are governed by Section 9.6 above, and transfers of other Personal Information subject to PIPEDA to the United States are governed by Section 9.13 above.
14.3 No EEA/UK/Swiss Processing Contemplated. This DPA does not address transfers subject to the GDPR, the UK Data Protection Act 2018, or the Swiss Federal Act on Data Protection, because the Services are provided only within the Territory defined in the MSA (the United States and Canada). If the parties later agree to expand the Territory to include the European Economic Area, the United Kingdom, or Switzerland, the parties will execute a separate transfer addendum (including Standard Contractual Clauses, as applicable) before any such Processing begins.
15 AUDITS AND RECORDS
15.1 Records. Utilen shall maintain records sufficient to demonstrate its compliance with this DPA.
15.2 Third-Party Certifications. On reasonable written request, no more than once per twelve-month period (except following a Security Incident or as required by a regulator), Utilen shall make available to Customer a summary of its then-current security certifications or audit reports (e.g., SOC 2 Type II - once complete), or, where unavailable, shall respond to reasonable written security questionnaires.
15.3 On-Site or Direct Audits. Where a third-party certification under Section 15.2 is not sufficient to satisfy Customer’s obligations under applicable Data Protection Laws (including a regulator-mandated audit), Customer or its designated, independent, and appropriately confidentiality-bound auditor may conduct a direct audit or inspection, subject to: (a) at least thirty (30) days’ prior written notice; (b) execution during Utilen’s normal business hours in a manner that does not unreasonably interfere with Utilen’s operations or the security of its other customers; (c) a limit of once per calendar year, unless a Security Incident, a documented material compliance concern, or a regulatory requirement justifies a further audit; and (d) Customer bearing the reasonable costs of the audit, unless the audit reveals a material breach of this DPA by Utilen, in which case Utilen bears those costs.
16 RETURN OR DELETION OF PERSONAL DATA
16.1 Upon termination or expiration of the Agreement, or upon Customer’s written request at any time, Utilen shall, at Customer’s election: (a) return all Personal Data to Customer in a commonly used, machine-readable format; or (b) securely delete or destroy all Personal Data and certify such deletion in writing.
16.2 Utilen shall complete the return or deletion within sixty (60) days of Customer’s request or of the effective date of termination. Retention may be legally required under Section 16.3, for example, to maintain accounting records, to maintain vendor and sales information, to permit and meet notice requirements, to comply with litigation holds, for security for backup systems.
16.3 Utilen may retain Personal Data to the extent required by applicable law or for legitimate archival/back-up purposes, provided Utilen continues to protect that retained data in accordance with this DPA and Processes it only for the purpose requiring retention.
16.4 Utilen shall ensure Sub-processors comply with this Article with respect to Personal Data in their possession.
16.5 Utilen’s obligations under this Article extend to vector embeddings and other derived representations generated from Personal Data. Where deletion of an individual derived representation is not technically feasible without regenerating an index, Utilen shall regenerate the affected index so that it no longer reflects the deleted Personal Data, within the period specified in Section 16.2.
17 LIABILITY
17.1 Each party’s liability arising out of or related to this DPA is subject to the limitations and exclusions of liability set out in the MSA, provided that nothing in the MSA or this DPA limits either party’s liability for its own violation of applicable Data Protection Laws to the extent such a limitation is not permitted by those laws.
17.2 Utilen shall indemnify and defend Customer from third-party claims, fines, and regulatory penalties directly arising from Utilen’s Processing of Personal Data in material violation of this DPA, except to the extent such claim arises from Customer’s instructions, Customer’s breach of this DPA or the Agreement, or Customer’s own violation of applicable Data Protection Laws.
17.3 TO THE EXTENT PERMITTED BY LAW, UTILEN WILL NOT BE LIABLE (WHETHER IN CONTRACT, WARRANTY, TORT (INCLUDING NEGLIGENCE, PRODUCT LIABILITY, OR OTHER THEORY, OR OTHERWISE) TO YOU OR ANY OTHER PERSON FOR COST OF COVER, RECOVERY, OR RECOUPMENT OF ANY INVESTMENT MADE BY YOU OR YOUR AFFILIATES IN CONNECTION WITH THIS AGREEMENT, OR FOR ANY LOSS OF PROFIT, REVENUE, BUSINESS, OR DATA OR PUNITIVE OR CONSEQUENTIAL, INDIRECT, SPECIAL, INCIDENTAL, OR BUSINESS INERRUPTION DAMAGES ARISING OUT OF OR RELATING TO THIS AGREEMENT, EVEN IF UTILEN HAS BEEN ADVISED OF THE POSSIBILITY OF THOSE COSTS OR DAMAGES. FURTHER, OUR AGGREGATE LIABILITY ARISING OUT OF OR IN CONNECTION WITH THIS AGREEMENT OR THE TRANSACTIONS CONTEMPLATED WILL NOT EXCEED AT ANY TIME THE TOTAL AMOUNTS DURING THE TWELVE (12) MONTH PERIOD PRECEDING THE DATE THE CLAIM AROSE PAID BY YOU TO UTILEN IN CONNECTION WITH THE PARTICULAR SERVICE GIVING RISE TO THE CLAIM, OR IF SERVICES ARE PROVIDED WITHOUT COST THEN THE MAXIMUM LIABILITY OF ANY CLAIM WILL BE ONE THOUSAND DOLLARS ($1,000).
18 TERM AND TERMINATION
18.1 This DPA commences on and runs concurrently with the Privacy Policy and remains in effect for as long as Utilen Processes Personal Data on Customer’s behalf under the Agreement, unless earlier terminated in accordance with this Article or the Agreement.
18.2 Either party may terminate this DPA immediately on written notice if the other party materially breaches this DPA and fails to cure within thirty (30) days of written notice, except that no cure period applies to a breach that is incurable or that requires immediate cessation of Processing to comply with Data Protection Laws.
18.3 Termination or expiration of the Agreement automatically terminates this DPA, subject to Section 18.4.
18.4 The following provisions survive termination or expiration of this DPA: Article 2 (Definitions), Sections 4.1–4.3 (Confidentiality, Purpose Limitation, No Combining), Article 12 (with respect to incidents occurring before termination), Article 16 (Return or Deletion), Article 17 (Liability), and this Article 18.
19 RELATIONSHIP TO THE AGREEMENT; PRECEDENCE
19.1 This DPA supplements and forms part of the Agreement. Except as expressly modified by this DPA, the Agreement remains in full force and effect.
19.2 This DPA is the sole and exclusive data-processing schedule between the parties. It supersedes and replaces any prior Data Processing Addendum previously exchanged between the parties.
19.3 Order of Precedence. In the event of a conflict specifically concerning the Processing of Personal Data, this DPA controls over the MSA and any other Order Form, Documentation, or policy, except that the MSA’s limitation of liability provisions control as described in Article 17.
20 MISCELLANEOUS
20.1 Amendments. Utilen may amend this DPA to reflect changes in Data Protection Laws or regulatory guidance by providing Customer at least sixty (60) days’ prior written notice. If Customer reasonably objects to an amendment required to maintain compliance, the parties will negotiate in good faith; if they cannot agree, Customer’s sole remedy is to terminate the affected Services.
20.2 Severability. If any provision of this DPA is held invalid or unenforceable, the remaining provisions remain in effect, and the parties will negotiate in good faith to replace the invalid provision with one that achieves the original intent.
20.3 Governing Law. This DPA is governed by the same governing law as the Agreement, without prejudice to any mandatory provisions of Data Protection Laws that require application of a different law with respect to the Processing of Personal Data of a given Data Subject.
20.4 Notices. Notices under this DPA follow the notice provisions of the Agreement, except that notices concerning Security Incidents (Article 12) and Data Subject/consumer requests (Article 13) may be sent:
20.4.1 by certified next day delivery where you and Utilen are in the same country; or
20.4.2 by certified airmail where you and Utilen are in different countries.
20.4.3 Notices to Utilen must be sent to Utilen, Attn: Legal, Utilen, PO BOX 270157 Saint Paul, MN 55127, with a copy to legal@Utilen.com.
20.4.4 If to Customer: the contact designated in the applicable Order Form or to you at any of your addresses listed in your Agreement.
20.5 Entire Agreement. This DPA, together with the Agreement and its Annexes, is the entire agreement between the parties regarding the Processing of Personal Data and supersedes all prior understandings on that subject, written or oral.
ANNEX 1 — DETAILS OF PROCESSING
1 Categories of Data Subjects
Customer’s employees, contractors, and Authorized Users of the Utilen Platform.
- Individuals identified in Customer’s procurement and vendor records (e.g., vendor and supplier contacts, bid participants).
- Customer’s vendors, clients, contacts or relationship information that may be identified in Customer Data.
- Where applicable, individuals whose information appears in commercial documents exchanged through the Platform (purchase orders, change orders, invoices, inspection forms, packing slips).
2 Categories of Personal Data
- Identifiers: name, business email address, business phone number, job title, IP address.
- Account and authentication data: login credentials, user roles and access levels.
- Commercial information: purchase history, orders, invoices, and related procurement records to the extent they contain identifiable information.
- Internet/network activity: browsing behavior and cookie data collected via the Utilen website (see Website Privacy Policy).
- Professional/employment information: employer, title, department, and platform access role.
- Communications content: message text, attachments, and associated metadata exchanged between users through the Platform’s messaging features.
- User-uploaded content: documents and files uploaded to the Platform, including any Personal Data contained within them.
- Derived representations: vector embeddings and other machine-readable representations generated from Customer Data for search and retrieval.
3 Categories of Sensitive Personal Data
Account login credentials and precise geolocation (where collected) are treated as Sensitive Personal Information/Sensitive Data under applicable Data Protection Laws. Utilen does not intentionally collect government identifiers, financial account credentials, health information, or biometric data through the Platform; Customer should not upload such categories of data unless the parties agree in writing to additional safeguards. For clarity of what Utilen may collect, Utilen may obtain access to government identifiers or financial account credentials outside of its Platform as services are rendered and paid for by customers.
4 Nature and Purpose of Processing
- Hosting, storage, and analysis of procurement and coordination data for tracking and reporting purposes as configured by Customer.
- Provision of user authentication, account management, and access-control functionality.
- Customer support and Platform maintenance.
- Generation of aggregated, de-identified analytics and benchmarking outputs as permitted under Section 4.5 of this DPA and Section 8 of the MSA.
- Operation of messaging features between users, including storage, indexing, and delivery of message content.
- Transmission of relevant Customer Data to third-party artificial intelligence and embedding providers for the purpose of generating search indices and AI-assisted responses.
- Verifying transactions for application of transaction fees on suppliers.
5 Duration of Processing
For the term of the Agreement, plus any retention period specified in Article 16 of this DPA or required by applicable law.
6 Location of Processing
United States —AWS US-East region.
Sub-processors listed in Annex 3 and their corresponding location.
ANNEX 2 — TECHNICAL AND ORGANIZATIONAL SECURITY MEASURES
1 Access Control
- Role-based access controls limiting access to Personal Data to personnel who require it.
- Multi-factor authentication for administrative access to production systems.
- Periodic access reviews and de-provisioning upon role change or termination.
2 Encryption
- Encryption of Personal Data in transit (TLS 1.2+).
- Encryption of Personal Data at rest (AES-256).
3 Infrastructure and Network Security
- Firewalls, network segmentation, and intrusion detection/prevention.
- Vulnerability scanning and a defined patch-management cadence.
- Third-party penetration testing at least annually.
4 Organizational Measures
- Confidentiality obligations for personnel with access to Personal Data.
- Security awareness training for personnel.
- A documented incident response plan, tested at least annually.
5 Certifications
SOC 2 Type I is currently underway with the intention of SOC 2 Type 2 during 2027.
ANNEX 3 — SUB-PROCESSOR LIST
1 An up-to-date list is also available at www.utilen.com/utilen-security, which Customer may subscribe to for change notifications.
2 A Sub-processor may collect the following types of information:
2.1 Identifiers: this includes Personally Identifiable Information (“PII”), including, without limitation, name, email, IP address;
2.2 Sensitive Personal Information: this is a subset of Identifiers, and includes PII of a sensitive natures, such as account login credentials, payment information, and precise geolocation, including addresses
2.3 Commercial information: this category of information covers information related to the enterprise, including, without limitation, purchase history;
2.4 Internet/Network Activity: this category of information covers your activity on the website, including, without limitation, browsing behavior, cookie data;
2.5 Geolocation Data: this category of information covers any location information received from your device while on the website;
2.6 Professional/employment information: this category of information covers information about your employment, including, without limitation, the company you work for, position, title, department, administrative role and/or access settings; and
2.7 Inference information: are any inferences that can be drawn from the above.