This Data Processing Addendum ("DPA") forms part of and is incorporated into the agreement between Yeet, Inc. d/b/a Creatorland ("Creatorland," "we," "us") and the customer agreeing to it ("Customer," "you") governing Customer's use of the Creatorland services, including the Creatorland Data match-and-enrich features (the "Services") (the "Agreement"). It governs our processing of Customer Personal Data on Customer's behalf. If there is a conflict between this DPA and the Agreement on the subject of data protection, this DPA controls.

1. Definitions

1.1 "Data Protection Laws" means all privacy and data protection laws applicable to the processing of Customer Personal Data under this DPA, including, where applicable, the California Consumer Privacy Act as amended by the California Privacy Rights Act ("CCPA/CPRA"), other U.S. state privacy laws, the EU General Data Protection Regulation (Regulation 2016/679) and the UK GDPR (together, "GDPR"), and the CAN-SPAM Act and Telephone Consumer Protection Act.

1.2 "Customer Personal Data" means personal data (or "personal information") contained in the identifiers and lists that Customer submits to the Services (such as email addresses, phone numbers, and social media handles) and that we process on Customer's behalf to provide the Services.

1.3 "Controller," "Processor," "Data Subject," "Personal Data," "Personal Data Breach," and "Process/Processing" have the meanings given in the GDPR; "Business," "Service Provider," "Sell," and "Share" have the meanings given in the CCPA/CPRA. Terms used and not defined have the meaning in the Agreement.

1.4 "Sub-processor" means any third party we engage to process Customer Personal Data.

2. Roles and scope

2.1 The parties acknowledge that, with respect to Customer Personal Data, Customer is the Controller (or a Processor acting on behalf of a third-party Controller) and Business, and Creatorland is the Processor and Service Provider. This DPA applies only to our processing of Customer Personal Data on Customer's behalf. It does not apply to data for which we are an independent controller (for example, the creator profile information in our own database).

2.2 Each party will comply with its obligations under Data Protection Laws.

3. Processing of Customer Personal Data

3.1 Instructions. We will process Customer Personal Data only on Customer's documented instructions, including as set out in this DPA and the Agreement and as necessary to provide the Services (for example, hashing submitted identifiers, matching them against our database, and returning results). Customer's use of the Services constitutes its instructions. We will notify Customer if, in our opinion, an instruction infringes Data Protection Laws (unless prohibited by law).

3.2 Details of processing. The subject matter, duration, nature and purpose of processing, types of Personal Data, and categories of Data Subjects are described in Annex I.

3.3 No retention of raw identifiers. We do not retain raw submitted identifiers in their original form; they are converted to a one-way salted hash for matching and then discarded. Downloadable result files we generate at Customer's request are stored briefly and automatically deleted (approximately 24 hours).

3.4 Service usage and query records. To operate, secure, debug, and improve the Services, we generate and retain records of Customer's use of the Services, including the text of search queries and filter parameters submitted to the Services' search and market-intelligence features, together with request metadata (such as the feature invoked, timestamps, result counts, error or refusal classifications, and credits consumed) ("Query Records"). Query Records are subject to the following limits: (a) they never include raw identifiers or lists submitted for matching or enrichment (which are handled exclusively as described in Section 3.3), nor the contents of outreach requests (creator names, contact details, or campaign terms); (b) where a lookup is performed using an email address or phone number, we record only the identifier type, never the value, and email addresses, phone numbers, and similar contact identifiers are automatically removed from free-text query content before storage; (c) Query Records are retained in identifiable form for no more than ninety (90) days, after which only aggregated or de-identified statistics are kept, with deletion enforced by automated process; and (d) Query Records are accessible only to authorized personnel, are used solely for service operation, security, abuse prevention, support, and product improvement, are never used to market to or profile the individuals referenced in a query, and are never Sold or Shared.

4. Customer obligations

4.1 Customer represents and warrants that it has, and will maintain, a lawful basis and all rights, consents, and notices necessary to provide Customer Personal Data to us and to instruct us to process it as contemplated by the Agreement and this DPA, and that its instructions will not cause us to violate Data Protection Laws.

5. Confidentiality

5.1 We will ensure that personnel authorized to process Customer Personal Data are bound by confidentiality obligations and process it only as instructed.

6. Security