Data Processing Addendum

Version: 5.0.0
Effective Date: October 2, 2026
Last Updated: October 2, 2026
Suite: P3RSON Legal Suite 5.0.0

1. Purpose and Scope

This Addendum applies when P3RSON, Inc. ("P3RSON") processes personal information on behalf of an Agency or Brand customer, for example talent roster data an Agency loads into the platform. It is part of the Terms of Service. For personal information that P3RSON collects directly from you, the Privacy Policy applies.

P3RSON offers the service in the United States. This Addendum is written for U.S. state privacy laws, including the California Consumer Privacy Act as amended (CCPA). It does not apply the GDPR, UK GDPR or any transfer mechanism for them.

2. Roles

3. What P3RSON Agrees To

P3RSON will:

  1. Process the personal information only to provide the service to the customer, as the Terms and the customer's use of the service instruct.
  2. Not sell or share the personal information, as those terms are defined in the CCPA.
  3. Not retain, use or disclose it outside the direct business relationship with the customer or for any purpose other than the services, except as the law allows.
  4. Not combine it with personal information from other sources, except as the CCPA allows for service providers.
  5. Keep it confidential and limit access to staff who need it.
  6. Keep reasonable security: encryption in transit and at rest, role-based access, multi-factor authentication for administrators, and the written security program summarized in the Data Retention Policy.
  7. Tell the customer by email within 72 hours after confirming a security incident that affects the customer's information.
  8. Help the customer answer requests from individuals (access, deletion, correction, export) within 30 days of the customer's request.
  9. Delete or return the information within 30 days after the customer ends the account, except for records we must keep by law (see the Data Retention Policy).
  10. Tell the customer if P3RSON can no longer meet these terms. The customer may then stop the processing and take reasonable steps to fix unauthorized use.
  11. Allow the customer to take reasonable steps to confirm compliance, by written questions once a year, answered within 30 days.

4. What the Customer Agrees To

The customer will:

  1. Have the right to upload the personal information and give any notices and get any consents the law requires.
  2. Not upload information about children under 13, and follow the Guardian and COPPA document for minors.
  3. Use the service according to the Terms, the Community Guidelines and the Creator Rights document.
  4. Handle requests from individuals about the information it controls, with our help under Section 3.

5. Sub-Processors

The customer allows P3RSON to use the sub-processors listed in the Sub-Processors document. P3RSON binds each to written terms that give the same protection for the information. P3RSON gives 30 days' notice by email before adding one. The customer may object by emailing [email protected] within 15 days.

6. Sensitive Data

Digitals, AI audit results and similar data are sensitive. Customers must not upload or request analysis of a person's Digitals without that person's own consent. See the AI Features Notice and the Biometric and Sensitive Data Notice.

7. Liability and Disputes

Liability under this Addendum is subject to the limits in the Terms of Service. Disputes are resolved as stated in the Terms of Service and the Dispute Resolution document.

8. Contact

[email protected] for privacy matters. [email protected] for legal notices about this Addendum.