DataProcessingAddendum.

Version 1.4 | Effective Date: April 2026 | Amended: 25 September 2026, version 1.4 (the introduction and Sections 1.1, 1.4, 2.1, 2.1.1, 2.1.2, 2.1.5 to 2.1.7, 2.2, 2.3, 3.1, 3.2, 4.2 to 4.4, 5.1 to 5.3, 5A.4, 6.1 to 6.3, 7.1 to 7.3, 7.5, 8.2, 11.1 to 11.3, 12.1 and 13.1: per-person records, the attributes a cloud model infers from camera frames and speech transcripts, the screen's GPS location, the device's advertising identifier, QR code scans, the radio and location sensing Trillboards turns on by default, face-identity templates and the person identifiers built from them, the categories of data partners and the data each receives, data received from data partners, the processing Trillboards carries out on its own account, retention periods including backups, sub-processors and hosting locations, described as practised) | Previously amended: September 2026, version 1.3 (Sections 2.1.6, 2.2, 3.2, 4, 5A.1, 6, 7.3, 7.6, 8.2, 11 and 13.1: delivery of measurement data to data partners at full granularity with counts, and the encrypted archive of radio and derived identifiers; Sections 2.1.2, 2.3 and 7.3: per-person, per-frame measurements and speech transcripts; Section 2.1.6: proximity device signals added as an enumerated category); August 2026 (Sections 2.3, 5.1, 6.1, 7.2 and 7.3: cloud image analysis, face-identity templates and their retention); July 2026 (Section 5A: Data Monetization Addendum framework added)

This Data Processing Addendum ("DPA") forms part of the agreement between the venue partner ("Controller", "Earner", "you") and Trillboards, Inc. ("Processor", "Trillboards", "we", "us") under which Trillboards provides its digital out-of-home advertising platform and related services (the "Services"). This DPA is incorporated by reference into the Trillboards Terms of Service and the Earner Agreement (collectively, the "Agreement").

This DPA reflects the parties' agreement with respect to the processing of Personal Data by Trillboards in connection with the Services, on behalf of the Controller and, as described in Section 2.2, on Trillboards' own account, in compliance with applicable data protection laws including the California Consumer Privacy Act (CCPA), the California Privacy Rights Act (CPRA), the General Data Protection Regulation (GDPR), and other applicable privacy and data protection legislation.

1. DEFINITIONS

1.1 "Personal Data" means any information relating to an identified or identifiable natural person, or that constitutes "personal information" as defined by applicable data protection law. In the context of Trillboards Services, this includes device identifiers, IP addresses (raw and hashed), and any audience measurement data that could, alone or in combination, relate to an identifiable individual.

1.2 "Processing" means any operation or set of operations performed on Personal Data, whether or not by automated means, including collection, recording, organization, structuring, storage, adaptation, alteration, retrieval, consultation, use, disclosure by transmission, dissemination, alignment, combination, restriction, erasure, or destruction.

1.3 "Controller" means the natural or legal person that determines the purposes and means of Processing Personal Data. Under this DPA, the venue partner (Earner) is the Controller for audience measurement data collected at their venue location(s).

1.4 "Processor" means the natural or legal person that processes Personal Data on behalf of the Controller. Under this DPA, Trillboards is the Processor for the processing it carries out on the Controller's behalf to provide the Services. For the processing described in Section 2.2(9) to (11), Trillboards determines the purposes and means of processing on its own account.

1.5 "Sub-processor" means any third party engaged by the Processor to process Personal Data on behalf of the Controller.

1.6 "Data Subject" means an identified or identifiable natural person to whom Personal Data relates. In the context of Trillboards Services, Data Subjects include individuals in the vicinity of the Controller's screen(s) whose presence may be detected by audience measurement technology.

1.7 "Data Subject Access Request" or "DSAR" means a request by a Data Subject (or an authorized agent on their behalf) to exercise their rights under applicable data protection law, including rights of access, correction, deletion, portability, or objection.

1.8 "Security Incident" means any accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to Personal Data transmitted, stored, or otherwise processed by the Processor.

1.9 "Standard Contractual Clauses" or "SCCs" means the standard contractual clauses for the transfer of Personal Data to processors established in third countries, as approved by the European Commission or other relevant authority.

1.10 "Applicable Data Protection Law" means all laws and regulations applicable to the processing of Personal Data under this DPA, including the CCPA/CPRA, GDPR, and any other applicable federal, state, or international privacy laws.

2. SCOPE OF PROCESSING

2.1 Categories of Data Processed

Trillboards processes the following categories of data in connection with the Services:

2.1.1 Device Telemetry

  • Heartbeat signals (device online/offline status, uptime metrics)
  • Battery and power status
  • Network health (connectivity status, bandwidth, latency)
  • Software version and configuration state
  • Hardware diagnostics (temperature, storage utilization, memory usage)
  • Device identifiers: the device's fingerprint and IP address and, from the Trillboards tablet, tablet-lite and Fire TV apps, its advertising identifier (the Google Advertising ID or the Fire OS advertising ID), which those apps read and send by default with no consent dialog

2.1.2 Audience Metrics and Per-Person Records

  • Face count: Number of detected faces in the vicinity of the screen, counted per time interval.
  • Per-person records: For each detected person (each face track), a record of that person's estimated age range, estimated gender, dominant emotion, dwell time and gaze time, stored with the screen and the time of the observation.
  • Per-person, per-frame measurements (agent-core 1.21 and later): for each detected person on each analysed camera frame, the head orientation (yaw, pitch, roll), face position and size in the frame, eye-open and smile probabilities, the position of each iris within its eye, 52 facial-expression coefficients, and 13 upper-body points. These are transmitted and stored. Face-identity templates and the person identifiers built from them are handled as described in Section 2.3.3.
  • Attention score: Estimated percentage of detected individuals facing the screen, calculated as a statistical ratio.
  • Dwell time: Estimated duration that each individual remains within the detection zone, stored in that person's record and aggregated into time buckets.
  • Demographic estimates: The estimated age range (0-9, 10-19, 20-29, 30-39, 40-49, 50-59, 60-69 or 70+) and estimated gender of each detected person, derived from on-device machine learning models. Each person's estimates are stored in that person's record, and age and gender distributions are computed from them.
  • Emotion estimates: The dominant emotion of each detected person (e.g., neutral, happy, angry, sad, surprised), estimated by on-device models and stored in that person's record, and emotional engagement distributions computed from those estimates.
  • Attributes inferred in the cloud: for each camera frame analysed under Section 2.3.2, Trillboards stores, with the screen and the time, a cloud model's estimates for the people in view: their dominant ethnicity (asian, black, hispanic, middle_eastern, south_asian, southeast_asian, white, mixed, other or unclear); their age band (0-2, 3-5, 6-10, 11-13, 14-17, 18-20, 21-24, then five-year bands from 25-29 to 70-74, and 75+) and gender; their social composition (solo, a pair of partners, a pair of friends, a family with children, a family without children, coworkers or strangers); their purchase-intent stage (browsing, researching, comparing, ready to buy or post-purchase); their activity; their phone and device use; their attire and apparel tier, including visible luxury branding; the items they carry; IAB lifestyle segments; their mood; the position of each occupant in the frame, including whether that occupant is driving; a written description of the scene; and a one-sentence narrative of the audience.
  • Ambient audio classification: Classification of the ambient audio environment (e.g., quiet, moderate noise, music playing, conversation), with the sound level of each audio snapshot.
  • Speech transcripts (agent-core 1.21 and later): speech is transcribed on-device; the transcript text and its segment times are transmitted and stored. A cloud model analyses each transcript for purchase intent, brands mentioned, sentiment and conversation type, and Trillboards stores the results. No audio recording is transmitted or stored.
  • Vehicle counting: Where applicable, estimated vehicle traffic count in the vicinity of outdoor screens.

2.1.3 Ad Delivery Data

  • Impression records (ad served, timestamp, duration, screen identifier)
  • Fill rate and fill status (filled, unfilled, error)
  • Error codes and error descriptions for failed ad deliveries
  • Revenue data (CPM, clearing price, advertiser identifier)
  • Creative metadata (advertiser name, campaign identifier, media type)

2.1.4 Screen Performance Metrics

  • Content playback status and content rotation logs
  • Screen brightness and display health
  • Scheduled versus actual uptime
  • Content delivery network performance

2.1.5 Environmental Context and Screen Location

  • Weather conditions at the screen location (sourced from WeatherAPI.com using the screen's coordinates)
  • Live event and sports scores displayed as ambient content (sourced from API-Sports)
  • Screen location: the venue address, and the GPS position the screen reports with its time and accuracy. Trillboards stores these positions as the screen's location trail; for a screen in a vehicle, the trail records the route the vehicle travels. Trillboards turns GPS location reporting on for every screen by default. Where a screen is registered without coordinates, Trillboards derives an approximate location from the public IP address of the phone or browser registering it, and where a screen has no coordinates and no address, from the screen's public IP address.

2.1.6 Proximity Device Signals

Screens configured for radio sensing observe the wireless signals that nearby personal devices broadcast. These are device-level signals, not aggregates, and they are Personal Data under Section 1.1:

  • Bluetooth Low Energy advertisements: the advertised hardware address, which on many devices is a rotating random address and on some is a fixed one; received signal strength; the Bluetooth SIG manufacturer company identifier; and Apple Continuity advertisement structure.
  • Wi-Fi: the BSSID of access points observed in range.
  • mDNS / SSDP / HTTP service discovery: the advertised hostname, service type, vendor, model and software version a device publishes on the local network.
  • UWB and Channel Sounding peers, and Auracast broadcast identifiers, where the device and the screen both support them.
  • Derived device identity: a cross-day device key computed from the above, and the exposure windows (screen, start, end, dwell) built from it. Trillboards links device keys to the person identifiers described in Section 2.3.3 and to the Intuizi device identifiers described in Section 4.4.

Each observation is classified identifiable, environmental or transient. Identifiers in this category are stored both verbatim and as keyed HMAC hashes. Section 7 governs how they are secured, Section 6.1 how long they are kept, and Sections 4.3 and 5A how they are shared.

Trillboards sets the radio sensing configuration of every screen and turns radio sensing on by default.

2.1.7 QR Code Scans

When a person scans a QR code shown on a screen, Trillboards records the scan: its time and screen, the phone's IP address and user agent, and the characteristics its browser reports (screen size, pixel ratio, graphics renderer, languages, time zone, network type, battery level and a browser fingerprint). Where the phone's IP address matches the screen's, Trillboards links the phone to the screen in its identity graph.

2.2 Purpose of Processing

Trillboards processes Personal Data for the following purposes. Trillboards carries out purposes (1) to (8) on the Controller's instructions, which include this DPA and any Data Monetization Addendum. Trillboards determines purposes (9) to (11) on its own account:

  1. Operating the audience measurement sensors on the Controller's screen(s). Trillboards sets each screen's camera sensing mode by default ('auto', in which Trillboards chooses the mode), and the Controller may select another mode in the Trillboards portal; Trillboards configures radio and GPS location sensing and turns both on for every screen by default (Sections 2.1.5 and 2.1.6)
  2. Delivering and optimizing advertisements on the Controller's screen(s)
  3. Measuring and reporting advertising campaign performance
  4. Generating audience analytics reports for the Controller
  5. Maintaining device health and uptime of the Controller's screen(s)
  6. Processing revenue calculations and payment disbursements
  7. Sending the screen's live audience measurements, its IP address and its location (its live GPS position where the screen reports one) to demand-side platforms (DSPs) and ad exchanges in bid requests, for programmatic advertising through the Trillboards advertising network
  8. Where the Controller has executed a Data Monetization Addendum pursuant to Section 5A, licensing or otherwise making available to Trillboards' authorized data partners the specific categories of Personal Data identified in that addendum, for the business and commercial purposes described therein
  9. Delivering measurement and location data to Trillboards' data partners as described in Section 4.3, and keeping data in Trillboards' encrypted archive for measurement continuity as described in Section 6.1
  10. Linking observations of the same person and of the same device across screens, days and Controllers, through the person identifiers described in Section 2.3.3 and the derived device keys described in Section 2.1.6, for cross-screen and returning-visitor measurement
  11. Combining the data described in this DPA with the device visit data Trillboards receives from Intuizi, as described in Section 4.4

2.3 Nature of Processing

Audience measurement is performed primarily on-device using embedded AI/ML models. Camera and microphone inputs are processed locally and, except as described in 2.3.2 and 2.3.3 below, are discarded from device memory once their outputs are computed. The screen transmits to Trillboards servers: statistical outputs (counts, ratios, distributions and categorical labels); the per-person records, per-frame measurements and speech transcripts listed in Section 2.1.2; the proximity device signals listed in Section 2.1.6, including the verbatim identifiers nearby devices broadcast; and the GPS positions described in Section 2.1.5.

2.3.1 Audio. Audio is classified and speech is transcribed on-device. Transcript text and segment times are transmitted and stored; no audio recording is transmitted or stored at any time.

2.3.2 Images selected for cloud analysis. A subset of camera frames is selected for analysis by a cloud vision model where on-device inference is unavailable or insufficient for the configured sensing profile. Such a frame is transmitted over TLS and analysed; the cloud model's analysis of each frame is stored as described in Section 2.1.2. The frame is retained by Trillboards in private storage for four hundred (400) days from the day it is written to that storage, after which it is deleted automatically. Frames moved into that storage from Trillboards' previous storage on 11 September 2026 count from that day and are deleted on or after 16 October 2027. The 282,838 frames captured between 5 May and 21 June 2026 and kept as a model-evaluation set have no scheduled deletion. These images are stored on a non-public prefix, are accessible only through short-lived signed URLs to authorized Trillboards personnel and systems, and are used for model evaluation and quality assurance and for the purposes described in Section 2.2. They are not published, and are not disclosed to any third party except a Sub-processor listed in Section 5.1 acting on Trillboards' instructions, or a data partner under a Data Monetization Addendum executed pursuant to Section 5A.

2.3.3 Face-identity templates and person identifiers. On devices running the full sensing profile, an on-device model computes a numerical face-identity template (a vector of 512 numbers) for each detected person, and the screen transmits it with that person's record. A template is a mathematical representation and cannot be used to reconstruct an image. Trillboards clusters templates into person identifiers, which recognise the same person across observations, screens and days and de-duplicate audience counts. Trillboards links each person identifier to the device key of the device observed with that person (Section 2.1.6) and, through that device key, to Intuizi device identifiers (Section 4.4), and attaches person identifiers to its records of device exposures. Templates and person identifiers are kept as set out in Section 6.1. Templates are excluded from every partner-facing and buyer-facing export by an automated control that fails closed; they are never sold, licensed or otherwise disclosed to a data partner under Section 5A.

2.3.4 Video. Where a Controller has enabled video capture, the applicable terms, retention and purposes are set out in a separate written addendum. Absent such an addendum, no video recording is captured, transmitted or stored.

3. ROLES AND RESPONSIBILITIES

3.1 Controller Responsibilities

The Controller (venue partner) shall:

  1. Ensure a lawful basis exists for the collection and processing of Personal Data at their venue location(s), including providing appropriate notice to individuals at the venue
  2. Post signage at screen locations disclosing the presence of audience measurement technology and that data collected at the venue, including device-level data, is delivered to Trillboards' data partners as described in Section 4.3, in accordance with applicable law and Trillboards' recommended signage guidelines
  3. Configure audience measurement sensors in compliance with applicable law for their jurisdiction
  4. Respond to Data Subject requests, with Trillboards' assistance as described in Section 8
  5. Ensure that any instructions given to Trillboards for Processing comply with Applicable Data Protection Law
  6. Conduct and maintain a data protection impact assessment where required by applicable law

3.2 Processor Responsibilities

Trillboards (Processor) shall:

  1. Process Personal Data on documented instructions from the Controller, which include this DPA and the transfers described in Section 12, unless required to do so by applicable law, in which case Trillboards shall inform the Controller of that legal requirement before processing unless prohibited by law. Trillboards carries out the processing described in Section 2.2(9) to (11) on its own account
  2. Ensure that persons authorized to process the Personal Data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality
  3. Implement and maintain appropriate technical and organizational security measures as described in Section 7
  4. Engage Sub-processors only in accordance with Section 5
  5. Assist the Controller by appropriate technical and organizational measures in fulfilling the Controller's obligation to respond to Data Subject requests
  6. Assist the Controller in ensuring compliance with obligations related to security, breach notification, data protection impact assessments, and prior consultation with supervisory authorities
  7. After the end of the provision of Services, return Personal Data to the Controller on request as described in Section 11.1(2). Personal Data is kept after the end of the provision of Services for the periods set out in Section 6.1, and data in Trillboards' encrypted archive is kept with no scheduled deletion
  8. Make available to the Controller all information necessary to demonstrate compliance with this DPA and allow for and contribute to audits as described in Section 10

4. DATA ISOLATION

4.1 Logical Separation

Trillboards maintains logical separation of each Controller's data within its systems. The derived device and person identifiers described in Section 6.1 link observations of the same device or person at screens of different Controllers, for cross-screen measurement, and measurement data from multiple Controllers' screens is delivered to data partners as described in Section 4.3.

4.2 Access Controls

Access to a Controller's data is restricted to:

  • The Controller's own authorized users via the Trillboards portal and API
  • Trillboards personnel who require access for the purpose of providing the Services, subject to confidentiality obligations
  • Sub-processors as listed in Section 5, to the extent necessary for them to provide their services
  • Trillboards' data partners, to which Trillboards sells and shares venue data: data buyers, data valuation partners, measurement partners and advertising partners, including 375ai and Intuizi, each for the data described in Section 4.3
  • Demand-side platforms and ad exchanges, for the data sent to them in bid requests as described in Section 2.2(7)

4.3 Delivery to Data Partners

Trillboards sells and shares measurement and location data collected at Controllers' screens, including data combined across multiple Controllers' venues, with its data partners, for their own purposes. Trillboards' data partners include data buyers, data valuation partners, measurement partners and advertising partners, including 375ai and Intuizi. Each category receives the following:

  1. Measurement partners, including 375ai and Intuizi: every hour, one row for each screen and hour carrying the screen's venue type, face counts, attention, dwell time, ambience, daypart and evidence grade, and the screen's GPS position nearest the middle of that hour, taken from the positions the screen reported during that hour or within 15 minutes before or after it. Every row is delivered with its count, however small; no minimum threshold is applied, and no cell is suppressed or generalized. Intuizi also receives, every day, the location trail of every screen that reports GPS positions (each position with its time and accuracy) and a location record for each approved screen that has coordinates (its name, address, coordinates and venue category).
  2. Data buyers: datasets built from measurement data, including a directory of screens, hourly activity at each screen, the mix of audience attributes by venue type and market, daily screen-to-screen mobility flows and hourly ad delivery at each screen.
  3. Data valuation partners, which evaluate or appraise Trillboards' data: extracts of measurement data, delivered as files or through read access to copies held in Trillboards' storage, including per-screen audience metrics, the per-observation attributes described in Section 2.1.2, attention and inference records, device exposure records and screen-to-screen device flows, hashed IP address observations, ad auction, impression and request logs, billboard passes, the links in Trillboards' identity graph between sensed devices and mobile advertising identifiers, and the mobile advertising identifier visits to Trillboards screens received from Intuizi (Section 4.4).
  4. Advertising partners: demand-side platforms and ad exchanges receive each screen's IP address, location and live audience measurements in bid requests (Section 2.2(7)).

Trillboards' Data API also offers each data partner an audience loyalty export for the screens associated with that partner: one row per device observed at those screens, carrying the device's raw radio identifiers (BLE address, mDNS hostname and Wi-Fi BSSID), a pseudonymous device identifier specific to that partner, and the device's visit pattern across those screens.

Each category of data partner, and the data it receives, is described at https://trillboards.com/legal/data-partners.

4.4 Data Received from Data Partners

Trillboards receives from Intuizi, every day, records of mobile devices observed at Trillboards screen locations: Intuizi's identifier for each device, the screen location and the time of the visit. Trillboards joins these records to its screens and links Intuizi device identifiers to the device keys observed at the same screens at the same times (Section 2.1.6), and through them to person identifiers (Section 2.3.3). Trillboards also receives from Intuizi records of the same devices' visits to stores and other places (store visits, dwell times, visit origins and audience memberships) and joins them to its records of devices exposed at Trillboards screens, for attribution. Trillboards makes Intuizi's device visit records available to data valuation partners as described in Section 4.3.

5. SUB-PROCESSORS

5.1 Authorized Sub-processors

The Controller hereby grants general written authorization for Trillboards to engage the following Sub-processors:

Sub-processorServiceProcessing LocationData Processed
Microsoft Corporation (Microsoft Azure)Cloud hosting, databases, data storage, compute infrastructure, operational loggingUnited States: Central US region (Iowa); database backups replicated to the East US 2 region (Virginia); operational logs and application telemetry in the South Central US region (Texas)All categories listed in Section 2.1; operational logs, which include screen IP addresses and screen identifiers
Amazon Web Services, Inc.Data storage (Amazon S3); backups (AWS Backup)United States: US-East-1 (N. Virginia); a backup copy in US-West-2 (Oregon)Files delivered to and received from data partners under Sections 4.3 and 4.4; copies of measurement data in the categories listed in Section 2.1, including the copies data valuation partners read under Section 4.3; snapshots of Trillboards' former Postgres database, holding every category in Section 2.1 that database held, and of server volumes, taken before the move to Microsoft Azure (Section 6.2)
Stripe, Inc.Payment processing, Connect payoutsUnited StatesController account data, revenue data, payment information
Google LLC (Google Cloud: Vertex AI and BigQuery)AI/ML inference and model evaluation, embedding generation; data warehousingVertex AI: any Google Cloud region, as Vertex AI is called through its global endpoint; BigQuery: United States (US multi-region)Camera frames selected for cloud analysis under Section 2.3.2, including images of venue interiors and the people in them; speech transcripts (Section 2.1.2), for extraction of purchase intent, brand mentions and sentiment; request-level ad data with device identifiers, and hourly audience measurements for each screen, for model training (BigQuery); ad creative analysis
IPinfo, Inc.IP geolocationUnited StatesPublic IP addresses that Trillboards' local geolocation file cannot place, including the IP addresses of screens, ad events and measurement SDK requests; the public IP address of the phone or browser that registers a screen without coordinates
WeatherAPI.comEnvironmental data enrichmentUnited States / EUThe screen's coordinates (latitude and longitude), and the screen's IP address when the screen requests weather itself
PostHog, Inc.Product analyticsUnited StatesScreen device fingerprints, screen identifiers and screen error events
API-SportsLive sports scores and event dataEurope (France)No Personal Data; sports event identifiers only

5.2 Notification of Changes

Trillboards notifies the Controller of changes to the list of Sub-processors by updating the Sub-processor list at https://trillboards.com/legal/sub-processors.

5.3 Objection Right

If the Controller objects to a new Sub-processor on reasonable grounds related to data protection, the Controller shall notify Trillboards in writing within fifteen (15) days of the update to the Sub-processor list that adds it. The parties shall discuss the objection in good faith. If the parties cannot resolve the objection, the Controller may terminate the affected Services without penalty by providing written notice.

5.4 Sub-processor Obligations

Trillboards shall:

  1. Impose data protection obligations on each Sub-processor that are no less protective than those in this DPA
  2. Remain fully liable to the Controller for the performance of each Sub-processor's obligations

5A. DATA MONETIZATION ADDENDUM

5A.1 General Prohibition

Except as described in Section 4.3, or as expressly authorized under a Data Monetization Addendum executed in accordance with this Section 5A, Trillboards shall not sell, license, or otherwise share the Controller's Personal Data with any third party for that third party's own independent business purposes.

5A.2 Data Monetization Addendum

The Controller and Trillboards may separately execute a written "Data Monetization Addendum" authorizing Trillboards to license, sell, or share specifically identified categories of Personal Data collected at the Controller's venue(s) with one or more named data partners, for purposes independent of the Services described in Section 2.2(1)-(7). Each Data Monetization Addendum shall specify, at minimum:

  1. The specific categories of data authorized for sharing (which may be narrower than the full set of categories described in Section 2.1)
  2. The identity of the authorized data partner(s) or a defined class of authorized recipients
  3. The compensation, if any, payable to the Controller
  4. Any data categories expressly excluded from the addendum's scope
  5. A representation from the Controller that it has, and will maintain for the duration of the addendum, a lawful basis for the collection described in Section 3.1(1), and that it has posted the signage required under Section 3.1(2)

Prior to the effective date of any Data Monetization Addendum, Trillboards shall complete a risk assessment of the processing it authorizes, consistent with applicable CPRA risk-assessment requirements, and shall make a summary available to the Controller upon request.

A Data Monetization Addendum governs over the general prohibition in Section 5A.1 and over Section 13.1(2) and (4), solely with respect to the Controller, data categories, and recipients it identifies. It does not affect the rights or obligations of any Controller that has not executed one.

5A.3 Third-Party Recipient Obligations

Where Personal Data is shared pursuant to a Data Monetization Addendum, Trillboards shall require the receiving data partner, by written contract, to:

  1. Use the shared data solely for the purposes disclosed in the applicable Data Monetization Addendum
  2. Not further sell or disclose the data to any additional third party except as necessary to provide services back to the data partner's own customers in a manner consistent with applicable law
  3. Implement reasonable security measures no less protective than those described in Section 7
  4. Honor deletion requests relayed by Trillboards pursuant to the Controller's or a Data Subject's rights under this DPA

5A.4 Data Partner List

Trillboards describes its data partners at https://trillboards.com/legal/data-partners (or such other location as Trillboards designates): each category of data partner that receives data under Section 4.3 and the data it receives, and any data partner authorized under a Data Monetization Addendum. That page is separate and distinct from the Sub-processor list in Section 5.1. Sub-processors under Section 5 process data on Trillboards' instructions, for the purposes in Section 2.2, including the purposes Trillboards carries out on its own account. Data partners receive data for their own independent business purposes. The two are not interchangeable, and a Sub-processor engagement does not itself authorize any sale or sharing under this Section 5A.

5A.5 Indemnification

  1. Controller indemnification. Where a Data Monetization Addendum is in effect for the Controller's venue(s), the Controller shall indemnify, defend, and hold harmless Trillboards from and against any third-party claim, regulatory action, or loss arising from: (a) the Controller's breach of its representations under Section 5A.2; or (b) the Controller's failure to have a lawful basis for the collection of Personal Data at its venue as required by Section 3.1(1) or to post the signage required by Section 3.1(2).
  2. Data partner indemnification. Trillboards shall require each data partner receiving Personal Data under a Data Monetization Addendum to indemnify Trillboards, by written contract, for claims arising from that data partner's use of the shared data outside the purposes authorized in the applicable addendum, or from that data partner's failure to meet the obligations described in Section 5A.3, and to maintain insurance reasonably sufficient to support that obligation.
  3. Scope. Nothing in this Section 5A.5 limits Trillboards' own responsibility for its direct breach of this DPA, its own negligence, or its own violation of Applicable Data Protection Law, nor does it shift to the Controller or any data partner liability that a regulator or court determines is Trillboards' own as a matter of law. This Section allocates financial responsibility between the contracting parties; it does not, and cannot, extinguish or transfer any Data Subject's or regulator's independent claim against Trillboards.

5A.6 Suspension

Trillboards may suspend a Controller's participation in any Data Monetization Addendum, or a data partner's access to shared data, immediately upon reasonable belief that the Controller has failed to meet its obligations under Section 3.1 or 5A.2, or that a data partner has failed to meet its obligations under Section 5A.3, pending resolution of the issue.

6. DATA RETENTION

6.1 Retention Schedule

Trillboards retains data according to the following schedule. For each category, the period given is the longest period for which the data is kept in any of Trillboards' active systems; what the encrypted archive keeps is stated in its own row:

Data CategoryRetention PeriodJustification
Device telemetry (heartbeat, health)30 days; device stability events (memory, temperature and crash records), 180 days; hourly uptime summaries, 400 daysOperational monitoring and troubleshooting
Audience metrics (face count, attention, dwell, demographics, emotion, audio classification)400 days for window records; per-screen hourly and daily summaries (viewers, attention, dwell, mood, income tier, age and gender mix, lifestyle segments, audience reaction, conversation intent and sentiment, brands heard), no scheduled deletionCampaign measurement and reporting
Attributes inferred in the cloud (Section 2.1.2)400 days in window records; 12 months as per-observation attributes; in per-screen hourly summaries, no scheduled deletionAudience measurement
Per-person records and per-frame measurements (Section 2.1.2)400 daysCampaign measurement and reporting
Speech transcripts (Section 2.1.2)400 daysAudience measurement
Camera frames selected for cloud analysis (Section 2.3.2)400 days from the day the frame is written to Trillboards' storage; frames moved into that storage on 11 September 2026 are deleted on or after 16 October 2027; the 282,838 frames captured between 5 May and 21 June 2026 have no scheduled deletionModel evaluation and quality assurance; deleted automatically by storage lifecycle policy
Face-identity templates (Section 2.3.3)400 daysRecognising the same person across observations and screens
Person identifiers and their links to device keys and Intuizi device identifiers (Section 2.3.3)No scheduled deletion; their attachment to device exposure records, 180 daysCross-screen and returning-visitor measurement
Ad impression recordsNo scheduled deletionAdvertiser billing reconciliation, campaign reporting, and contractual obligations with demand-side platforms
Screen performance metrics730 days (content playback records); per-screen hourly and daily ad delivery and playback summaries, no scheduled deletion; hourly uptime summaries, 400 daysOperational monitoring and proof of play
Proximity device signals: verbatim identifiers (Section 2.1.6: BLE address, Wi-Fi BSSID, mDNS/SSDP hostname)14 days in active systems; no scheduled deletion in the encrypted archiveSession stitching and same-visit de-duplication; measurement continuity
Proximity device signals: derived device key and exposure windows (Section 2.1.6)400 days in active systems; no scheduled deletion in the encrypted archiveReturning-visitor and cross-screen measurement; measurement continuity
Device visit data received from Intuizi (Section 4.4)Files in Amazon S3, 365 days; in Trillboards' analytics systems, 180 days (screen visits, store visits, visit origins and audience memberships), 400 days (store dwell by device) and 800 days (store visit counts by location)Attribution and cross-screen measurement
Revenue and payment recordsAs required by law (minimum 7 years)Tax and financial regulatory compliance
Aggregated network-level statistics (no Controller attribution)IndefiniteAnonymized, aggregated data that cannot be attributed to any individual Controller or Data Subject
Encrypted archive: the data in every category above except camera frames, including verbatim radio identifiers, derived device keys and exposure windows, and the person identifier derived from a cluster of face-identity templates and linked to the device key observed with itNo scheduled deletionMeasurement continuity
Screen location: GPS positions (Section 2.1.5)No scheduled deletionAd delivery, measurement, and delivery to data partners (Section 4.3)
QR code scans (Section 2.1.7)No scheduled deletionAttribution
Files delivered to data partners in Amazon S3 (Section 4.3)GPS trails and location records, 365 days; hourly audience files, no scheduled deletionDelivery to data partners
Copies of measurement data read by data valuation partners (Section 4.3)No scheduled deletionEvaluation and appraisal of Trillboards' data
Ad request records and hourly audience measurements copied to Google BigQuery (Section 5.1)No scheduled deletionModel training for ad delivery
Operational logs, which include screen IP addresses and screen identifiers (Section 5.1)30 days; application telemetry, 90 daysOperations and troubleshooting

6.2 Retention Principles

  1. All retention periods begin from the date of collection or generation of the data
  2. Upon expiration of the retention period, data is automatically deleted from active systems. Systems that store data in monthly partitions delete a month's data once the whole month has passed its retention period. Data with no scheduled deletion in Section 6.1, including the data in Trillboards' encrypted archive, is kept
  3. Backups other than the encrypted archive are kept as follows: Azure Database for PostgreSQL backups, 14 days; ClickHouse backups, 15 days (incremental) and 36 days (full). AWS Backup keeps snapshots of Trillboards' former Postgres database, taken before the move to Microsoft Azure: each weekly snapshot taken from 28 June to 6 September 2026 is deleted 90 days after it was taken, the last on 5 December 2026, and the snapshot of 1 April 2026, with its copy in US-West-2 (Oregon), is deleted on 1 April 2027. Snapshots of server volumes taken before the move are deleted by 15 October 2026. The AWS Backup vaults are locked, and their snapshots cannot be deleted before those dates
  4. The Controller may request early deletion of their data at any time, subject to Section 11

6.3 Summaries and Network-Level Statistics

Per-screen summaries of audience metrics are kept with no scheduled deletion (Section 6.1). Network-level statistics with no Controller attribution are kept indefinitely.

7. SECURITY MEASURES

7.1 Encryption

  1. In transit: All data transmitted between the screen device and Trillboards servers is encrypted using TLS 1.2 or higher. API communications use HTTPS exclusively.
  2. At rest: All data stored in Trillboards databases and storage systems is encrypted using AES-256 encryption. Database storage (Azure Database for PostgreSQL) uses Microsoft-managed encryption keys.

7.2 Hashing and Pseudonymization

  1. Device identifiers: Analytics systems key records by each screen's Trillboards screen identifier. The device registry stores each device's fingerprint, advertising identifier and IP address as the device reports them
  2. IP addresses: The device registry stores each screen's IP address, and bid requests to demand-side platforms and ad exchanges carry it (Section 2.2(7)). A QR code scan stores the scanning phone's IP address (Section 2.1.7). Trillboards' IP address observations, the analytics record of the addresses screens and devices connect from, are stored as HMAC-SHA256 hashes under a secret key
  3. Face-identity templates: No voiceprint, retina or iris scan, or finger or hand scan is generated, transmitted or stored at any time. Face-identity templates are generated and handled only as described in Section 2.3.3: computed on-device, stored as fixed-length numerical vectors from which no image can be reconstructed, clustered into person identifiers that are linked to device keys and Intuizi device identifiers, and blocked from every partner-facing and buyer-facing export by an automated control that fails closed.

7.3 On-Device Processing Architecture

  1. Camera frames are processed by on-device ML models in real time and discarded from device memory after their outputs are computed, except for frames selected for cloud analysis, which are transmitted and retained as described in Section 2.3.2
  2. Audio samples are processed by on-device audio classification and speech-to-text models and then discarded; no audio recording is transmitted or stored, and transcripts are transmitted as described in Section 2.3.1
  3. Apart from the device telemetry and device identifiers described in Section 2.1.1, the camera frames described in Section 2.3.2, the face-identity templates described in Section 2.3.3, the per-person records, per-frame measurements and speech transcripts described in Section 2.1.2, the GPS positions described in Section 2.1.5, and the proximity device signals described in Section 2.1.6, only statistical outputs (counts, ratios, distributions, categorical labels) are transmitted to Trillboards servers
  4. On-device models operate without network connectivity: sensor processing continues even when the device is offline, with outputs queued for transmission when connectivity is restored

7.4 Access Controls

  1. Role-based access control (RBAC) for all Trillboards personnel and systems
  2. Multi-factor authentication (MFA) required for access to production systems
  3. Principle of least privilege applied to all system and database access
  4. Access logs maintained and reviewed regularly

7.5 Infrastructure Security

  1. Production infrastructure is hosted on Microsoft Azure in the Central US region, and the Amazon S3 storage and AWS Backup vaults listed in Section 5.1 on AWS; both providers hold SOC 2 Type II, ISO 27001, and FedRAMP certifications
  2. Network segmentation between production, staging, and development environments
  3. Regular vulnerability scanning and penetration testing
  4. Automated patch management for operating systems and dependencies

7.6 Cross-Network Outputs

Cross-network analytical outputs that aggregate data across multiple Controllers' venues are delivered at full granularity, as described in Section 4.3: every output cell is published with its count, however few data points it contains. No k-anonymity threshold is applied.

8. DATA SUBJECT RIGHTS

8.1 Assistance with Data Subject Requests

Trillboards shall assist the Controller in responding to Data Subject Access Requests (DSARs) by:

  1. Promptly forwarding to the Controller any DSAR received directly by Trillboards that relates to the Controller's venue(s)
  2. Providing the Controller with self-service tools via the Trillboards portal to search and export data associated with their venue(s)
  3. Providing reasonable technical assistance to help the Controller locate, access, correct, or delete Personal Data processed on their behalf
  4. Implementing technical measures to facilitate the Controller's compliance with DSAR response obligations

8.2 Locating a Data Subject's Records

Trillboards can locate a Data Subject's records by mobile advertising identifier (through the links described in Sections 2.3.3 and 4.4), by device key (Section 2.1.6) or by IP address (Sections 2.1.7 and 7.2).

8.3 Response Timing

Trillboards shall respond to the Controller's DSAR assistance requests within ten (10) business days, or such shorter period as required by applicable law.

9. SECURITY INCIDENT NOTIFICATION

9.1 Notification to Controller

In the event of a Security Incident involving Personal Data processed on behalf of the Controller, Trillboards shall:

  1. Notify the Controller without undue delay and in any event within seventy-two (72) hours after becoming aware of the Security Incident
  2. Provide the following information in the notification (to the extent known):
    • Description of the nature of the Security Incident, including the categories and approximate number of Data Subjects and data records concerned
    • Name and contact details of the Trillboards data protection contact
    • Description of the likely consequences of the Security Incident
    • Description of the measures taken or proposed to address the Security Incident, including measures to mitigate its possible adverse effects

9.2 Cooperation

Trillboards shall:

  1. Cooperate with the Controller and take reasonable steps to assist in the investigation, mitigation, and remediation of the Security Incident
  2. Take immediate steps to contain the Security Incident and minimize any ongoing harm
  3. Preserve evidence related to the Security Incident for forensic and legal purposes
  4. Not notify any third party (including regulators or Data Subjects) of the Security Incident without the Controller's prior written consent, unless required by applicable law

9.3 Record Keeping

Trillboards shall maintain a record of all Security Incidents, including the facts of the incident, its effects, and the remedial action taken, regardless of whether notification to the Controller was required.

10. AUDIT RIGHTS

10.1 Annual Audit

The Controller may audit Trillboards' compliance with this DPA up to once per twelve (12) month period, subject to the following conditions:

  1. The Controller shall provide at least thirty (30) days' written notice of the audit
  2. The audit shall be conducted during normal business hours and shall not unreasonably interfere with Trillboards' business operations
  3. The Controller may use a qualified, independent third-party auditor, subject to Trillboards' reasonable approval (not to be unreasonably withheld) and provided the auditor executes a confidentiality agreement acceptable to Trillboards
  4. The scope of the audit shall be limited to Trillboards' compliance with the obligations set forth in this DPA

10.2 Audit Reports and Certifications

In lieu of an on-site audit, and to the extent Trillboards makes available:

  1. SOC 2 Type II reports or equivalent certifications covering Trillboards' information security program
  2. Results of penetration tests or vulnerability assessments (in summary form)
  3. Written responses to reasonable audit questionnaires submitted by the Controller

the Controller shall consider such documentation in determining whether to exercise its on-site audit right.

10.3 Costs

Each party shall bear its own costs associated with any audit. If an audit reveals a material breach of this DPA by Trillboards, Trillboards shall bear the reasonable costs of the audit.

11. DATA DELETION AND RETURN

11.1 Upon Termination

Upon termination or expiration of the Agreement:

  1. Retention after termination: Termination does not start a deletion and does not shorten the retention periods in Section 6.1. Personal Data processed on behalf of the Controller is kept after termination for the periods set out in Section 6.1 and deleted as that Section describes. Data in Trillboards' encrypted archive is kept with no scheduled deletion.
  2. Return: Trillboards shall, at the Controller's request made within thirty (30) days of termination, export and return all Personal Data to the Controller in a commonly used, machine-readable format (CSV or JSON).

11.2 Legal Holds

Trillboards may also retain Personal Data after termination to the extent required by applicable law (e.g., financial records for tax compliance), and continues to protect retained data in accordance with this DPA.

11.3 Backup Purge

Data in backup and disaster recovery systems, other than Trillboards' encrypted archive described in Section 6.1, is kept for the periods set out in Section 6.2(3), including the locked AWS Backup snapshots kept until 1 April 2027. Trillboards shall not actively restore deleted data from backups except in a disaster recovery scenario, in which case any restored Controller data shall be re-deleted promptly.

12. INTERNATIONAL DATA TRANSFERS

12.1 Primary Processing Location

Primary data processing occurs in the United States, in the Microsoft Azure Central US region (Iowa). Database backups are replicated to the Azure East US 2 region (Virginia), and operational logs and application telemetry are kept in the Azure South Central US region (Texas). Files exchanged with data partners, and stored copies of measurement data, are kept in the AWS US-East-1 region (N. Virginia), and snapshots of Trillboards' former Postgres database are kept in AWS US-East-1 and US-West-2 (Oregon) until 1 April 2027. Ad request records and hourly audience measurements are copied to Google BigQuery in the United States. Camera frames selected for cloud analysis, and speech transcripts, are processed by Google Vertex AI through its global endpoint, which serves each request from any Google Cloud region, including regions outside the United States.

12.2 Standard Contractual Clauses

To the extent that Personal Data originating from the European Economic Area (EEA), United Kingdom, or Switzerland is transferred to the United States or any other country not recognized as providing an adequate level of data protection:

  1. The parties agree that such transfers shall be governed by the Standard Contractual Clauses (Module Two: Controller to Processor) as approved by the European Commission Decision 2021/914, which are hereby incorporated by reference into this DPA
  2. For transfers from the United Kingdom, the UK International Data Transfer Addendum to the EU SCCs shall apply
  3. For transfers from Switzerland, the SCCs shall apply with the modifications required by the Swiss Federal Act on Data Protection (FADP)

12.3 Transfer Impact Assessment

Trillboards shall maintain a transfer impact assessment evaluating the legal framework of the destination country and the supplementary measures in place to protect transferred data. This assessment shall be updated as circumstances require and made available to the Controller upon request.

12.4 Data Localization

The Controller may request that Trillboards process their data exclusively within a specified geographic region, subject to technical feasibility and any additional costs, which shall be agreed upon in writing.

13. CCPA/CPRA SPECIFIC PROVISIONS

13.1 Service Provider Status

For purposes of the CCPA and CPRA, Trillboards is a "Service Provider" as defined in Cal. Civ. Code Section 1798.140(ag) for the processing it carries out on the Controller's behalf. For the processing described in Section 2.2(9) to (11), Trillboards acts on its own account, and its delivery of Personal Information to data partners under Section 4.3, and to demand-side platforms and ad exchanges in bid requests under Section 2.2(7), is a sale and a sharing of that Personal Information. Trillboards:

  1. Processes Personal Information on behalf of the Controller for the business purposes specified in the Agreement and this DPA, and on its own account for the purposes described in Section 2.2(9) to (11)
  2. Except as described in Sections 2.2(7) and 4.3, or to the extent the Controller has executed a Data Monetization Addendum under Section 5A, does not "sell" or "share" (as defined by the CCPA/CPRA) the Controller's Personal Information
  3. Does not retain, use, or disclose the Controller's Personal Information for any purpose other than the business purposes specified in the Agreement, including for any commercial purpose other than providing the Services, except as described in Sections 2.2(9) to (11), 4.3, 4.4 and 6.1 or authorized under Section 5A
  4. Except as described in Sections 2.2(9) to (11), 4.3, 4.4 and 6.1, or to the extent the Controller has executed a Data Monetization Addendum under Section 5A, does not retain, use, or disclose the Controller's Personal Information outside of the direct business relationship between Trillboards and the Controller
  5. Combines the Controller's Personal Information with Personal Information collected at other Controllers' screens (Sections 2.2(10) and 4.1) and with the device visit data it receives from Intuizi (Section 4.4)

13.2 Compliance Certification

Trillboards certifies that it understands and will comply with the restrictions set forth in Section 13.1. Trillboards shall notify the Controller if it determines that it can no longer meet its obligations under the CCPA/CPRA.

13.3 Right to Monitor

The Controller has the right to take reasonable and appropriate steps to help ensure that Trillboards uses the Controller's Personal Information in a manner consistent with the Controller's obligations under the CCPA/CPRA, including the audit rights set forth in Section 10.

13.4 Obligations Where a Data Monetization Addendum Is in Effect

Where a Data Monetization Addendum executed under Section 5A authorizes the sale or sharing of Personal Information, Trillboards shall, with respect to the data categories it covers:

  1. Honor any applicable consumer opt-out preference signal (including the Global Privacy Control)
  2. Ensure the "Do Not Sell or Share My Personal Information" mechanism required by the CCPA/CPRA is available and functioning
  3. Impose the contractual restrictions described in Section 5A.3 on the receiving data partner
  4. Provide the Controller, upon request, with a description of the categories of Personal Information sold or shared under the applicable addendum during the preceding twelve (12) months

14. GOVERNING LAW

This DPA shall be governed by and construed in accordance with the laws of the State of California, without regard to its conflict of laws provisions. To the extent that the GDPR or other non-US data protection law applies to the Processing, the provisions of this DPA that implement those requirements shall be interpreted in accordance with the applicable law.

15. TERM AND TERMINATION

15.1 Term

This DPA shall remain in effect for the duration of the Agreement. The obligations of Trillboards with respect to the processing of Personal Data shall continue for as long as Trillboards retains any Personal Data processed on behalf of the Controller.

15.2 Survival

Sections 6 (Data Retention), 7 (Security Measures), 9 (Security Incident Notification), 11 (Data Deletion and Return), and 14 (Governing Law) shall survive termination of this DPA.

16. AMENDMENTS

This DPA may be amended only by written agreement of both parties. Trillboards may update the Sub-processor list and the technical security measures described herein to reflect changes in its operations, provided that such changes do not materially diminish the level of data protection afforded to the Controller's Personal Data. Material changes to this DPA shall require the Controller's written consent.

17. CONTACT

For questions or requests related to this DPA:

Trillboards, Inc. 25 Grace Street San Francisco, CA 94103 United States