Data Processing Addendum

Last updated: July 27, 2026

This Data Processing Addendum (“DPA”) is incorporated into and forms part of the Madison Terms of Service (the “Agreement”) between Madison AI LLC (“Madison”) and the customer agreeing to the Agreement (“Customer”), pursuant to Section 5.2 of the Agreement. It applies to the extent Madison Processes Personal Data contained in Customer’s Content on Customer’s behalf in providing the Services. Capitalized terms not defined here have the meanings given in the Agreement.

  1. Definitions

“Data Protection Laws” means all U.S. federal and state laws applicable to the Processing of Personal Data under the Agreement, including the California Consumer Privacy Act as amended by the California Privacy Rights Act (“CCPA”) and the comprehensive privacy laws of Virginia, Colorado, Connecticut, Texas, and other U.S. states, in each case as amended or replaced from time to time.


“Personal Data” means information within Customer’s Content that identifies, relates to, or could reasonably be linked to an identified or identifiable individual or household, and that Madison Processes on Customer’s behalf.


“Process” / “Processing” means any operation performed on Personal Data, such as collection, storage, use, analysis, disclosure, or deletion.


“Security Incident” means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to Personal Data Processed by Madison. Security Incidents do not include unsuccessful attempts or activity that does not compromise Personal Data, such as failed log-in attempts, pings, or port scans.


“Sub-processor” means a third party engaged by Madison to Process Personal Data on Madison’s behalf in providing the Services.


Terms such as “controller,” “processor,” “business,” “service provider,” “sell,” and “share” have the meanings given in applicable Data Protection Laws.

  1. Roles and Scope

As between the parties, Customer is the controller (or business) of Personal Data, or is a processor acting on behalf of another controller, and Madison is Customer’s processor (or service provider). Customer’s platforms of origin (the third-party services from which Content is retrieved under Customer’s connections) are not governed by this DPA. Madison acts as an independent controller of account, billing, and Services-usage records relating to Customer, which it Processes for administering the customer relationship, billing, security, and legal compliance; such records are not subject to this DPA.

  1. Processing Instructions

Madison will Process Personal Data only on Customer’s documented instructions. The parties agree that the Agreement (including this DPA), Customer’s configuration of the Services, and Customer’s use of the Services constitute Customer’s complete instructions. Madison will inform Customer if it becomes aware that it cannot comply with these instructions. Customer is responsible for ensuring its instructions comply with Data Protection Laws and that it has provided all notices and obtained all rights and consents necessary for Madison to Process Personal Data as described in the Agreement.

  1. Madison’s Obligations

Madison will: (a) ensure that personnel authorized to Process Personal Data are subject to confidentiality obligations; (b) not sell or share Personal Data as those terms are defined under the CCPA; (c) not retain, use, or disclose Personal Data for any purpose other than providing the Services under the Agreement, or outside the direct business relationship between the parties, except as permitted by Data Protection Laws; (d) not combine Personal Data with personal information received from other sources, except as permitted by Data Protection Laws for service providers; (e) comply with the obligations applicable to it as a service provider or processor under Data Protection Laws and provide the level of privacy protection they require; and (f) notify Customer if it determines it can no longer meet its obligations under Data Protection Laws, in which case Customer may take reasonable steps to stop and remediate unauthorized Processing.

  1. Data Subject Requests

The Services provide controls Customer can use to access, correct, and delete Personal Data. If Madison receives a request from an individual to exercise privacy rights regarding Personal Data, Madison will promptly forward the request to Customer and will not respond except to direct the individual to Customer. Taking into account the nature of the Processing, Madison will provide reasonable assistance to enable Customer to respond to such requests.

  1. Security

Madison will implement and maintain reasonable administrative, technical, and organizational safeguards designed to protect Personal Data against unauthorized access, use, disclosure, alteration, and destruction, as described in Annex B. Madison may update its safeguards from time to time, provided the updates do not materially reduce the protection of Personal Data.

  1. Security Incidents

Madison will notify Customer without undue delay after becoming aware of a Security Incident affecting Customer’s Personal Data. The notification will describe, to the extent known: the nature of the incident, the categories of Personal Data and approximate number of individuals affected, the measures taken or planned in response, and a contact point for further information. Madison will provide timely updates as the investigation proceeds and will provide reasonable assistance to enable Customer to meet its own notification obligations. Madison’s notification of a Security Incident is not an acknowledgement of fault or liability.

  1. Sub-processors

Customer provides general authorization for Madison to engage Sub-processors to provide the Services. Madison’s current Sub-processors, and their functions, are available on request to privacy@meetmadison.ai. Customer may subscribe to notification of Sub-processor changes at the same address; Madison will notify subscribed customers at least thirty (30) days before a new Sub-processor Processes Personal Data. Customer may object to a new Sub-processor on reasonable data-protection grounds within thirty (30) days of notice, in which case the parties will discuss the concern in good faith; if no resolution is reached, Customer may terminate the affected Services without penalty (without prejudice to fees accrued before termination). Madison will impose data protection obligations on each Sub-processor that are materially equivalent to those in this DPA and remains responsible for each Sub-processor’s performance.

  1. Sensitive Data

The Services are not intended for the Processing of sensitive personal information, and Customer does not instruct Madison to Process it. Customer acknowledges that content retrieved from platforms of origin (such as reviews and messages authored by third parties) may incidentally contain such information, and such content is Processed as ordinary Content under the Agreement.

  1. Audits

Upon Customer’s written request, no more than once per calendar year unless a Security Incident or reasonably suspected non-compliance justifies otherwise, Madison will make available its then-current SOC 2 report and will respond in writing to reasonable information security questionnaires. Customer agrees that its audit rights under Data Protection Laws are satisfied by these measures. Materials provided under this Section are Madison’s confidential information.

  1. Deletion and Return

Upon Customer’s written request, Madison will provide Customer with a copy of its Content in a commonly used electronic format. Upon Customer’s deletion request during the Subscription Term, Madison will delete the requested Personal Data within thirty (30) days; deletion of all Customer Personal Data (deletion of Customer’s organization) requires prior cancellation of active subscriptions, as the Services cannot be provided without it. Deletion of Personal Data does not terminate the Agreement or any Subscription Term and does not affect Customer’s payment obligations. Following termination of the Agreement, unless Customer requests earlier deletion, Madison retains Personal Data for twelve (12) months to permit Customer to reactivate the Services and to resolve billing disputes, after which it is deleted in accordance with Section 7.3 of the Agreement and Madison’s published data retention practices; where retention is required by applicable law, Madison will isolate and protect the Personal Data from further Processing and delete it when the requirement ends. Copies in encrypted backups are deleted in the ordinary rotation of those backups.

  1. General

This DPA is effective for the term of the Agreement plus any period during which Madison retains Personal Data. In case of conflict between this DPA and the Agreement regarding the Processing of Personal Data, this DPA prevails. Madison may update this DPA from time to time as described in Section 12 of the Agreement; updates will not materially reduce the protections in this DPA. Each party’s liability arising out of this DPA is subject to the limitations of liability in the Agreement. A signed courtesy copy of this DPA is available on request to privacy@meetmadison.ai.

Annex A - Details of Processing

Subject matter and duration: Processing of Personal Data in Customer’s Content to provide the Services, for the Subscription Term and the post-termination retention period described in Section 11.


Nature and purpose: Retrieval of Customer’s platform content under Customer’s connections; storage; analysis; generation of marketing content, including through AI models dedicated to Customer; publication to Customer’s connected platforms on Customer’s approval or configured schedule; customer support.


Categories of individuals: Customer’s personnel and account users; individuals who author reviews, messages, and other content on Customer’s connected platforms (such as Customer’s customers and prospective customers).


Categories of Personal Data: Names, usernames, and profile information of content authors; the content of reviews, messages, and social interactions, which may include contact details or other personal information the author includes; information about Customer’s personnel processed within the Services (such as user names and activity within Customer’s account).

Annex B - Security Measures

Madison maintains the security program described on its Security page at meetmadison.ai/security, including: encryption of data in transit and at rest, with application-level encryption of delegated login credentials for platforms that do not support OAuth; access on a least-privilege basis with multi-factor authentication or single sign-on for internal systems; logging across production systems; vulnerability management including automated scanning and annual third-party penetration testing; tested backups; and vendor security assessment for Sub-processors.

Annex C - Sub-processors

Madison’s current Sub-processors and their functions are available on request to privacy@meetmadison.ai, as updated in accordance with Section 8.

Your AI-Powered Digital Marketing Specialist

© Copyright 2026, All Rights Reserved