A. LIST OF PARTIES
Data exporter:
- Name: Customer as defined in the Principal Agreement
- Address: See signature page in the Principal Agreement
- Contact person’s name, position and contact details: See signature in the Principal Agreement
- Activities relevant to the data transferred: Receiving the Services as described in this DPA and the Principal Agreement
- Signature and date: See signature page in the Principal Agreement
- Role (Controller/Processor): Controller
Data importer:
- Name: Mastercard as defined in the Principal Agreement
- Address: See signature page in the Principal Agreement
- Contact person’s name, position and contact details: See signature page in the Principal Agreement
- Activities relevant to the data transferred: Providing the Services as described in this DPA and the Principal Agreement
- Signature and date: See signature page in the Principal Agreement
- Role (Controller/Processor): Processor
B. DESCRIPTION OF TRANSFER
- Categories of Data Subjects whose Personal Data is transferred: End-users (i.e., cardholders and consumers)
- Categories of Personal Data transferred:
- Geographic information (city, state, country and as applicable, postal code);
- Audience membership – based on real time user segmentation and backend historical calculations;
- IP address;
- Online identifiers (i.e., online data collected from end-user’s devices, applications and protocols), such as UDID, cookie identifiers, and other unique ID that Mastercard or Customer assigns to end-users’ devices;
- Device and browser attributes;
- Page views and interactions;
- As applicable: Customer events (e.g., and “add to cart” or other interactions and engagement set up by Customer);
- As applicable: search query terms;
- Only as applicable, the information you provide to us:
- mail address;
- CRM data and other data that Customer elects for onboarding (e.g., gender, status, average order value, number of items ordered, days since last order, net sales, items per order, days since first order, sessions since last order, days since last visit, average interpurchase time, last order site, loyalty status, etc.);
- Online purchase history on the Customer website;
- Offline purchase history;
- For financial institutions only: transaction data (e.g., end-users’ spend history, predictive spend, travel spend).
- Sensitive data transferred (if applicable) and applied restrictions or safeguards that fully take into consideration the nature of the data and the risks involved, such as for instance strict purpose limitation, access restrictions (including access only for staff having followed specialized training), keeping a record of access to the data, restrictions for onward transfers or additional security measures: No Sensitive Data.
- The frequency of the transfer (e.g., whether the Personal Data is transferred on a one-off or continuous basis): On a continuous basis.
- Nature of the Processing: The Personal Data will be processed and transferred as described in this DPA and the Principal Agreement.
- Purpose(s) of the transfer and further Processing: The Personal Data will be processed and transferred for the provision of the Services as described in this DPA and the Principal Agreement, in particular to:
- Personalize end users’ interaction with Customer’s online platforms across the web, mobile web, mobile apps and email and other channels;
- Build actionable end users’ segments in real time, enabling Customer to take instant action via personalization, product/content recommendations, automatic optimization, real-time messaging and other activation modules offered by Mastercard from time to time;
- As applicable, and for financial institutions only: examine spending patterns [on end-user transaction data/consumer payment cards] to improve card engagement and usage;
- As applicable, and for financial institutions only: prepare and furnish aggregated reports on end-users’ spending patterns.
- The period for which the Personal Data will be retained, or, if that is not possible, the criteria used to determine that period: Personal Data will be retained for as long as necessary taking into account the purpose of the Processing, and in compliance with applicable laws, including laws on the statute of limitations and Privacy and Data Protection Law.
- For transfer to Sub-Processors, also specify subject matter, nature and duration of the Processing: The Personal Data may be transferred to Sub-Processors to provide the Services as described in this DPA and the Principal Agreement.
C. COMPETENT SUPERVISORY AUTHORITY
The Belgian Supervisory Authority shall act as the competent Supervisory Authority.