top of page

PRIMA ID DATA SERVICES AGREEMENT

Commercial, Data Processing & Identity-Provider Flow-Down Terms

Version 2026.3  ·  July 7, 2026
 

This Prima ID Data Services Agreement (“DSA”) is entered into pursuant to, incorporated into, and governed by the Master Services Agreement (“MSA”) between Tria Prima, LLC (“Company”) and the Client identified in the applicable Prima ID Order Form (“Client”). This DSA governs Client’s access to and use of the Prima ID Product Services and the processing of data in connection with them. In the event of a conflict between the MSA and this DSA, this DSA shall control with respect to Prima ID and the processing of data, subject to the order of precedence in the MSA. Capitalized terms not defined herein have the meanings set forth in the MSA.

 

1.  Description of Prima ID Services

Prima ID provides integration, orchestration, behavioral tracking, and CRM activation services that enable transmission of website behavioral data, identity resolution performed by an independent third-party identity resolution provider (“Identity Resolution Provider”), delivery of identity results into Client’s CRM, and workflow prioritization within Client’s CRM environment.

 

2.  Definitions

“Identity Data” means the identity-resolved records, match results, and enrichment data sourced from the third-party Identity Resolution Provider. “Client Data” means data provided or made available by Client, including website behavioral data. “Derived Insights” means data, reports, analysis, or other output developed by or on behalf of Client that is derived from Identity Data, provided that such output (i) does not contain any Identity Data and (ii) cannot be reverse engineered to obtain the original Identity Data. “Personal Data” means information that identifies, relates to, or could reasonably be linked, directly or indirectly, with a particular individual. “Permitted Use” means the manner in which Client is authorized to use Prima ID and Identity Data as set forth in this DSA and the applicable Order Form. “Applicable Law” means any international, federal, state, or local treaties, laws, rules, regulations, or ordinances applicable to Client’s use of Prima ID and Identity Data.
 

3. Third-Party Identity Resolution; Pass-Through of Provider Requirements

Identity matching and enrichment are performed exclusively by an independent Identity Resolution Provider. Company does not own, control, audit, or warrant the identity graph, underlying data sources, data accuracy, data completeness, or match rates. Identity Data and enrichment signals are provided strictly on an “AS IS” and “AS AVAILABLE” basis. Company disclaims all liability arising from or related to third-party identity data.
 

Company licenses the identity data services from the Identity Resolution Provider as its customer, and Client is an authorized end user of that data through the Prima ID service. The restrictions, data-protection, records, and deletion obligations set out in this DSA are intended to be back-to-back with, and no less protective than, the requirements that the Identity Resolution Provider imposes on Company. Client’s access to and use of Identity Data is at all times subject to those requirements as passed through in this DSA.
 

Additional Restrictions. The Identity Resolution Provider may, from time to time, impose additional or modified restrictions on the use of Identity Data, including as required by applicable law, regulatory or self-regulatory guidance, or its data licensors. Company will provide Client with reasonable advance notice of any such additional restrictions to the extent practicable, and Client agrees to comply with them upon notice.
 

4.  Data Handling; No Data Retention; Transient Processing

Company does not store, retain, aggregate, or maintain consumer Personal Data in connection with Prima ID beyond transient processing necessary for secure transmission and integration, and does not maintain a database of such data. Company will not accept or maintain consumer personally identifiable information (PII) beyond such transient processing. Notwithstanding the foregoing, during a proof-of-concept (“POC”) engagement for which Client has signed the separate POC agreement, data may be maintained in Company’s ‘sandbox’ environment solely during the three (3) week POC period and solely for the purposes of the POC.

 

5.  Use Restrictions

Client shall use Prima ID and Identity Data solely for the Permitted Uses, and shall not, and shall not permit any user to, use Prima ID, the Identity Data, or any Derived Insights:

  • to determine any person’s employability, credit worthiness, credit standing, credit capacity, or other characteristic listed in Section 603(d) of the Fair Credit Reporting Act, or for any other purpose requiring compliance with the Fair Credit Reporting Act or similar laws (Prima ID is not a consumer reporting agency and does not constitute a consumer report);

  • to make a decision by automated processing that evaluates, analyzes, or predicts an individual’s characteristics or preferences where the decision results in the provision or denial of financial or lending services, housing, insurance, education enrollment or opportunity, criminal justice, employment opportunities, healthcare services, or access to essential goods or services;

  • in any manner that violates Applicable Law;

  • to build or support any product or service that is competitive with the Identity Resolution Provider’s data services or with Company’s Product Services;

  • in any manner that exceeds the scope of the licenses granted or the limits or restrictions set forth in this DSA or the applicable Order Form; or

  • to train, fine-tune, or develop any generative AI system, large language model, or foundation model, or to develop any model or dataset made available to or accessible by a third party.
     

Client shall not sell, rent, license, sublicense, distribute, or otherwise make Identity Data available to any third party except as expressly permitted in the Order Form.
 

Permitted activations. For clarity, Client and its permitted end users may: (a) use Identity Data with the AI and machine-learning features of the business tools into which it is delivered, provided those features do not retain Identity Data, or incorporate it into — or make it extractable from — any underlying model (transient processing to generate outputs and local personalization for Client’s authorized users are permitted); (b) develop and use analytical or machine-learning models (e.g., segmentation, propensity, lookalike) for the business purposes of Client and its end users, including services they provide to their own customers, provided Client does not sell or redistribute Identity Data on a standalone or record-level basis; and (c) distribute identifiers (e.g., hashed emails, MAIDs) and audiences to service providers, advertising platforms, and partners for marketing and advertising activation, targeting, measurement, and attribution consistent with the Permitted Uses, provided that no such model or its outputs reproduces, retains, mimics, or reverse-engineers Identity Data or is used to reconstruct Identity Data.


Client shall bind its end users, service providers, and partners to restrictions at least as protective as this Section and use commercially reasonable efforts to enforce them. Notwithstanding anything to the contrary in this DSA or the MSA, Client shall remain fully, directly, and strictly responsible and liable to Company for any violation of this Section, the Use Restrictions, or the AI restriction by its end users, service providers, partners, or their respective customers, to the same extent as if committed by Client. Client’s liability under this Section is subject to the Limitation of Liability provisions of Section 12 of this DSA and Section 19 of the MSA, except that Client’s indemnification obligations under Section 13(b) are not so limited.

 

Suspension. Company may immediately suspend or disable Client's access to Prima ID and the Identity Data, in whole or in part and without liability, if: (a) Client breaches the Use Restrictions, the AI restriction, or the Sensitive Data Prohibition; (b) Company reasonably believes continued access creates a legal, security, or privacy risk, or risk to the Identity Resolution Provider's data; (c) the Identity Resolution Provider suspends, limits, or requires Company to suspend Client's access; or (d) suspension is required by Applicable Law. Company will restore access if and when the condition giving rise to the suspension is resolved. Suspension does not relieve Client of its payment obligations or limit Company's other rights, including termination.
 

6.  AI Restriction; Reconciliation with MSA

The restriction in Section 5(f) is required by the Identity Resolution Provider and, notwithstanding anything in the MSA or any Order Form to the contrary, controls with respect to Identity Data. For clarity, this restriction does not limit Client’s use of artificial intelligence, machine learning, or analytics (including the AI- and machine-learning-powered features built into Client’s CRM, marketing, and workflow systems) as applied to (i) Client’s own first-party data, (ii) Client’s behavioral data, and (iii) Derived Insights that do not themselves contain Identity Data. This Section reconciles the permitted-use provisions of the MSA with the pass-through requirements of this DSA.
 

7.  Client Responsibilities and Compliance

Client is solely responsible for: (a) lawful collection of website and other data; (b) maintaining a conspicuously posted privacy policy that complies with Applicable Law and accurately describes the collection, processing, use, and disclosure of data as contemplated by Prima ID; (c) obtaining all notices, consents, and rights required under Applicable Law for the collection and use of data, including any data Client submits to Company or the Identity Resolution Provider; (d) compliance with all applicable privacy, data-protection, and marketing laws; and (e) all downstream use of Identity Data within its CRM and marketing systems. Client acknowledges that Company does not provide legal advice and does not monitor Client’s compliance posture.

Submitted Information. "Submitted Information" means any data Client or its end users submit to Company or the Identity Resolution Provider in connection with Prima ID, including website behavioral data. Client grants Company a worldwide, non-exclusive, royalty-free, sublicensable license to use and to transmit Submitted Information to the Identity Resolution Provider for the provision of the Services. Client represents and warrants that: (i) it maintains a conspicuously posted privacy policy that complies with Applicable Law and accurately describes the processing, use, and disclosure of Submitted Information as contemplated by Prima ID; (ii) it has obtained all rights and consents necessary, including any third-party consents required under Applicable Law, to authorize Company and the Identity Resolution Provider to use the Submitted Information and to grant the licenses contemplated here and in Company's upstream agreement; (iii) its collection and disclosure of Submitted Information complies with Applicable Law and its privacy policy; and (iv) it will promptly notify Company of any notice from a governmental or regulatory authority alleging that any Submitted Information violates Applicable Law. Client shall not submit any information prohibited by the Sensitive Data Prohibition (Section 8)
 

8.  Sensitive Data Prohibition

Client shall not transmit or upload to Company or the Identity Resolution Provider, and shall not request or use Identity Data to assemble or augment, any individually identifiable health information (as defined under the Health Insurance Portability and Accountability Act), payment card information, bank account information, Social Security number, driver’s license information, government identification information, or any similarly sensitive information about any individual.

9.  Data Protection and Processing

This Section sets forth the parties’ data-processing terms and is intended to be back-to-back with, and no less protective than, the data-processing requirements imposed on Company by the Identity Resolution Provider.

  • Roles. As between the parties, with respect to Personal Data processed in connection with Prima ID, Client is the Controller (or, where Client acts on behalf of a third-party controller, the Processor) and Company is the Processor (or sub-processor, as applicable). Each party shall comply with the obligations applicable to it in such role under Applicable Law.

  • Processing Instructions. Company shall process Personal Data only to provide the Prima ID Product Services, to perform its obligations and exercise its rights under the integrated agreement, as necessary to address technical problems, and otherwise in accordance with Client’s documented instructions (which include the Permitted Uses and the applicable Order Form), unless required by Applicable Law. Client is responsible for the accuracy and lawfulness of its instructions and for having all necessary notices, consents, and rights for the processing.

  • Personnel; Confidentiality. Company shall ensure that personnel authorized to process Personal Data are bound by appropriate obligations of confidentiality and process such data only as needed for their job duties in connection with the Services.

  • Subprocessors. Company may engage subprocessors (including cloud-infrastructure providers) to process Personal Data in connection with the Services, provided that Company imposes data-protection obligations on each subprocessor that are no less protective than those in this Section and remains responsible for its subprocessors’ performance.

  • Data Subject Requests. Taking into account the transient nature of Company’s processing, Company shall provide reasonable assistance to enable Client to respond to verified data-subject requests under Applicable Law. If Company receives a data-subject request relating to Personal Data processed for Client, Company will, where permitted, advise the data subject to submit the request to Client, who is responsible for responding.

  • Security Measures. Company shall implement and maintain commercially reasonable administrative, technical, and physical safeguards appropriate to the nature of transient data transmission and designed to protect Personal Data against accidental or unlawful destruction, loss, alteration, or unauthorized disclosure or access. Company does not guarantee prevention of all security incidents.

  • Security Incidents. Company shall notify Client without undue delay after confirming a security incident affecting Company-controlled systems and shall take reasonable steps to identify the cause, minimize harm, and prevent recurrence. Company’s notification or response shall not be construed as an acknowledgment of fault or liability. Client shall, in turn, promptly notify Company of any actual or reasonably suspected breach of security or unauthorized access to, acquisition of, or disclosure of Identity Data of which Client becomes aware, without undue delay and in no event later than is necessary to enable Company to meet its own notification obligations to the Identity Resolution Provider; this obligation is intended to be back-to-back with, and no less protective than, the corresponding requirement the Identity Resolution Provider imposes on Company.

  • International Transfers. Company may process Personal Data in the United States or anywhere Company or its subprocessors maintain facilities. Client is responsible for ensuring that its use of the Services complies with any cross-border data-transfer restrictions of Applicable Law, and the parties will reasonably cooperate to put in place any transfer mechanism (e.g., standard contractual clauses) required by Applicable Law.

  • Records; Return or Deletion. Each party shall maintain complete and accurate books and records with respect to its activities and disclosures involving Personal Data during the term and for at least two (2) years after termination or expiration. Return or deletion of Identity Data on termination is governed by Section 11. Each party shall comply with its obligations under Applicable Law and provide the level of privacy protection required by Applicable Law.

  • Liability. Each party’s liability arising out of or related to this Section is subject to the Limitation of Liability provisions of Section 12 of this DSA and Section 19 of the MSA.
     

10.  Intellectual Property Ownership

Client retains ownership of Client Data. The Identity Resolution Provider retains ownership of its identity graph and all Identity Data, and Client receives only a limited, non-exclusive, non-transferable right to use Identity Data for the Permitted Uses during the term. Company's intellectual property and the parties' other ownership and use rights are governed by the Master Services Agreement.
 

11.  Termination of Data Rights; Deletion; Records and Audit

Automatic Termination of Data Rights. All rights to access and use Identity Data automatically terminate upon the expiration or termination of the applicable Order Form, this DSA, or Company’s upstream agreement with the Identity Resolution Provider, whichever occurs first.
 

Deletion on Termination. No later than thirty (30) days following termination or expiration, Client shall irrevocably delete all Identity Data (including identity-resolved match records and identifiers sourced from the Identity Resolution Provider) and shall execute and return the Data Deletion Acknowledgement in the form attached as Exhibit A. For clarity, Client is not required to delete (i) data already in Client’s possession prior to obtaining it from Company, or (ii) Derived Insights developed in compliance with this DSA prior to termination.
 

Records and Audit. Client shall maintain business and financial records for a rolling period of three (3) years sufficient to verify Client’s compliance with this DSA, including that its use of Identity Data complies with this DSA and that Identity Data has been deleted as required. Upon Company’s reasonable request (including where required by the Identity Resolution Provider), Client shall provide written confirmation of compliance and, where applicable, SQL logs or similar evidence reasonably requested to confirm deletion. If such evidence reveals that Client has failed to delete Identity Data as required, Client shall, on demand, pay the proportionate (pro-rata) fees that would have applied to maintain such Identity Data for the period between termination and the date of confirmation.
 

12.  Limitation of Liability

Notwithstanding anything in the MSA to the contrary, and except for Client’s payment obligations and the obligations described in the final sentence of this Section, Company’s total aggregate liability arising out of or related to Prima ID and this DSA, for any cause whatsoever and regardless of the form of the action, will at all times be limited to the total subscription fees paid or payable for Prima ID in the one (1) months preceding the event giving rise to the claim. The existence of more than one claim will not enlarge this limit. Company shall not be liable for regulatory fines, identity-data inaccuracies, third-party data claims, lost profits, reputational harm, or indirect, incidental, consequential, special, or punitive damages. The foregoing limitation is for the benefit of Company only and does not limit Client’s liability; Client’s payment obligations, Client’s indemnification obligations under Section 13(b), Client’s breach of the Use Restrictions, the AI restriction, or the sensitive-data prohibition, Client’s infringement or misappropriation of intellectual property, and Client’s misuse of Identity Data are not subject to any cap and survive. This Section is subject to and consistent with Section 19 (Limitation of Liability) of the MSA.
 

13.  Indemnification

  • Company Indemnity. Company shall indemnify Client solely for third-party claims alleging that Company’s proprietary integration technology directly infringes a valid U.S. intellectual property right. Company shall have no indemnification obligation for claims arising from identity data, third-party providers, Client tracking activities, privacy disclosures, or downstream business decisions. Company’s indemnification obligation under this Section 13(a) is subject to the limitation of liability in Section 12 of this DSA and Section 19(a) of the MSA.

  • Client Indemnity (Flow-Through). Client shall defend, indemnify, and hold harmless Company (and its officers, directors, employees, and agents) and, as applicable, the Identity Resolution Provider, from any third-party claims and all resulting losses (including reasonable attorneys’ fees) to the extent due to or arising out of: (i) Client’s breach or violation of the terms of this DSA, the MSA, or any Order Form; or (ii) Client’s violation of Applicable Law in connection with its activities hereunder or its use or distribution of Identity Data — excluding any such claims to the extent based on or arising out of any cause or circumstance for which Company is required to indemnify Client under Section 13(a). This indemnity expressly includes, on a full back-to-back basis, any claim, loss, fine, penalty, or liability that the Identity Resolution Provider or its data licensors assert against Company to the extent arising from Client’s acts or omissions, and is intended to pass through to Client one hundred percent (100%) of the corresponding indemnification and other obligations that Company owes to the Identity Resolution Provider with respect to such acts or omissions. Because this obligation flows down from the Identity Resolution Provider’s requirements, it is not subject to any limitation, exclusion, or cap on liability in the MSA or this DSA. Client’s obligations under this Section survive termination or expiration.
     

14.  Legal Proceedings; Cooperation; Professional Fees

Company shall not be required to participate in, respond to, defend, or appear in connection with any consumer claim, class action, regulatory inquiry, subpoena, or proceeding arising from Client’s tracking activities, privacy notices, consent mechanisms, or downstream data use. If Client requests Company’s assistance in connection with any such matter, Company may, at its sole discretion, provide assistance pursuant to a separate written engagement, billed at Company’s then-current hourly professional-services rate plus reasonable expenses. Company shall have no obligation to provide assistance absent such written agreement.

Accepted through the executed Order Form that references this Agreement. No separate signature is required for this document.

bottom of page