OpenWild ← All legal documents

Data Protection Addendum

Effective August 19, 2026 · Last updated August 19, 2026

Related documents: Creator Terms of Use Brand Terms of Use Privacy Policy Cookie Notice Acceptable Use Policy

DATA PROCESSING ADDENDUM

LAST UPDATE: August 19, 2026

This Data Processing Addendum ("Addendum") is supplementary to, and forms part of, the Terms of Use (the "Agreement") between [COMPANY_LEGAL_NAME], with offices at [REGISTERED_ADDRESS] ("OpenWild"), and [CLIENT_LEGAL_NAME] ("Client"). This Addendum applies to the Personal Data which OpenWild makes available to the Client, and which the Client obtains, through the Platform in connection with campaigns published by the Client, and to the Personal Data which the Client makes available to OpenWild. The parties acknowledge that each of them acts as an independent Controller in respect of the Personal Data it processes for its own purposes, and that neither party processes Personal Data on behalf of, or under the documented instructions of, the other.

1. Definitions and Interpretation

In this Addendum, the following terms shall have the following meanings:

(a) "Applicable Privacy Laws" means all worldwide data protection and privacy laws and regulations applicable to the Personal Data in question, including, where applicable: (i) European Privacy Laws; (ii) the Personal Data Protection Code No. 6698 ("KVKK"); (iii) the California Consumer Privacy Act of 2018 and its regulations (the "CCPA") (iv) the Virginia Consumer Data Protection Act of 2021 (the “VCDPA"); (v) Delaware Online Privacy and Protection Act (the “DOPPA”); in each case as amended, superseded or replaced from time to time.

(b) "Data Subject" means an identified or identifiable individual whose Personal Data is processed.

(c) "European Privacy Laws" means: (i) Regulation 2016/679 of the European Parliament and of the Council on the protection of natural persons with regard to the Processing of Personal Data and on the free movement of such data (General Data Protection Regulation) (the "GDPR"); (ii) the GDPR as incorporated into United Kingdom domestic law pursuant to Section 3 of the European Union (Withdrawal) Act 2018 (the "UK GDPR"); (iii) the Swiss Federal Data Protection Act of 19 June 1992 and its corresponding ordinances (the "Swiss DPA"); (iv) EU Directive 2002/58/EC on Privacy and Electronic Communications; and (v) any national law made under or pursuant to items (i) – (iv); in each case as amended, superseded or replaced from time to time.

(d) "Personal Data" means any information relating to an identified or identifiable individual or any other information defined as 'personal data' or 'personal information' under Applicable Privacy Laws.

(e) "Restricted Transfer" means (i) where the EU GDPR applies, a transfer of Personal Data from the EEA to a country outside the EEA which is not subject to an adequacy determination by the European Commission; (ii) where the UK GDPR applies, a transfer of Personal Data from the UK to any other country which is not based on adequacy regulations pursuant to Section 17A of the UK GDPR; and (iii) where the Swiss DPA applies, a transfer of Personal Data to a country outside of Switzerland which is not included on the list of adequate jurisdictions published by the Swiss Federal Data Protection and Information Commissioner.

(f) "SCCs" means the standard contractual clauses annexed to the European Commission’s Decision (EU) 2021/914 of 4 June 2021(opens in a new tab or window), as may be amended, superseded or replaced from time to time.

(g) "UK Addendum" means the International Data Transfer Addendum to the EU Commission Standard Contractual Clauses (version B1.0) issued by the Information Commissioner's Office under s.119(A) of the UK Data Protection Act 2018, as may be amended, superseded or replaced from time to time.

(h) The terms "Controller/Exporter", "Processor/Importer", "Data Subject" and "processing" have the meanings given to them in Applicable Privacy Laws or, if not defined therein, the GDPR (and "process", "processes" and "processed" shall be interpreted accordingly) and the terms "Business" and "Service Provider" have the meanings given to them in the CCPA.

(i) "Creator" means a natural person registered to the Platform in order to produce and submit content, and "Creator Data" means the Personal Data relating to a Creator which is made available to the Client through the Platform in connection with a campaign published by the Client, namely the Creator's username, profile picture, country, connected social media account identifier, the content submitted and the associated performance statistics, and any free-text note added to the submission.

Any capitalized terms used but not defined in this Addendum shall have the meanings given to them under the Agreement.

2. Processing of Personal Data

2.1. Relationship of the parties: Each party is an independent Controller (or Business, as applicable) in respect of the Personal Data it processes for its own purposes. OpenWild is the Controller of the Personal Data of Creators, Brands and Users which it processes in order to operate the Platform, as described in its Privacy Policy. The Client is the Controller of the Creator Data from the moment it obtains that data through the Platform and processes it for its own purposes. Neither party is a Processor of the other, neither party acts under the documented instructions of the other, and the parties are not joint controllers, save where they expressly agree otherwise in writing in respect of a specific processing activity. Each party shall comply with its own obligations under Applicable Privacy Laws.

2.2. Purpose limitation and lawful basis: The Client shall process Creator Data only for the purposes which are compatible with the purpose for which it was made available, namely the assessment of submissions against the campaign brief, the approval or rejection of claims, and the exercise of the content licence granted to the Client under the Agreement. The Client shall determine and be able to demonstrate a lawful basis for its own processing, shall provide the Creators with the information required under Applicable Privacy Laws in respect of that processing, and shall not: (i) use Creator Data for any incompatible purpose, including the building of marketing profiles or direct marketing, without a separate lawful basis; (ii) enrich, combine or match Creator Data with data from other sources in order to identify or profile a Creator beyond what is necessary for the campaign; or (iii) "sell" or "share" Creator Data within the meaning of the CCPA or any equivalent legislation. OpenWild shall process any Personal Data which the Client makes available to it only as described in its Privacy Policy and as necessary to provide the Platform.

2.3. International transfers: Where a party transfers Personal Data to a country other than the country in which it was first collected, it shall first take such measures as are necessary to ensure that the transfer is made in compliance with Applicable Privacy Laws, including by entering into standard contractual clauses adopted by the European Commission, the UK Secretary of State or, where the KVKK applies, the standard contract notified to the Turkish Personal Data Protection Board, or by relying on another lawful transfer mechanism.

2.4. Accuracy: If a party becomes aware that Personal Data it has received from the other is inaccurate or has become outdated, it shall inform the other party without undue delay and the parties shall cooperate to erase or rectify the data.

2.5. Confidentiality of processing: Each party shall grant access to Personal Data received from the other only to those of its personnel, agents and subcontractors who need access for the purposes set out in this Addendum, and shall ensure that every such person is subject to a strict duty of confidentiality, whether contractual or statutory.

2.6. Security: Each party shall implement appropriate technical and organisational measures to protect the Personal Data it holds from accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, that data (a "Security Incident"), taking into account the state of the art, the costs of implementation and the nature, scope, context and purposes of the processing. The measures implemented by OpenWild are set out in Annex 2. In the event of a Security Incident affecting Personal Data received from the other party, the following applies:

2.6.1. Each party maintains an internal data breach procedure. The affected party will analyse the cause, the impact and the affected Data Subjects, will notify the other party without undue delay and in any event within forty-eight (48) hours of becoming aware of the Security Incident, and will notify the competent supervisory authority and the affected Data Subjects where and within the periods required by Applicable Privacy Laws.

2.6.2. OpenWild will provide highly detailed information about:

i) The nature of the breach, including a description of the incident, the nature of the personal data or categories of affected data subjects, an estimate of the number of affected data subjects and databases that may be affected, as well as an indication of when the incident occurred;

ii) Any measures already taken by OpenWild in order to stop the breach;

iii) Any measures to be taken by the affected Data Subjects (what can the affected data subjects themselves do, such as “keep an eye on your emails, change your passwords”, etc.);

iv.) Any measures to be taken by OpenWild in order to prevent a future breach.

2.7. Service providers and onward disclosure: Each party may engage service providers to process Personal Data on its behalf for the purposes set out in this Addendum, provided that:

2.7.a OpenWild maintains a list of the service providers it engages in Annex 3 and in its Privacy Policy, and will provide reasonable prior notice of at least fourteen (14) days before the addition or replacement of a service provider which processes Creator Data or Client Personal Data, by updating that list and by notifying the Client by e-mail, so as to allow the Client to raise reasonable objections on data protection grounds; and

2.7.b Each party imposes on any service provider it engages data protection terms which ensure substantially the same standard of protection as that provided under this Addendum, and remains responsible for the acts and omissions of that service provider.

2.8. Cooperation and Data Subjects' rights: Each party shall be responsible for responding to requests from Data Subjects in respect of its own processing. Each party shall provide the other with all reasonable and timely assistance necessary to enable the other to respond to: (i) any request from a Data Subject to exercise any of its rights under Applicable Privacy Laws; and (ii) any other correspondence, enquiry or complaint received from a Data Subject, regulator or other third party in connection with the processing covered by this Addendum. Where a request relates to the other party's processing, the receiving party shall promptly redirect the Data Subject and inform the other party.

2.9. Data Protection Impact Assessment: Each party shall provide the other with such reasonable and timely assistance as the other may require in order to comply with its obligation under Applicable Privacy Laws to conduct data protection impact assessments and, if necessary, to consult its relevant data protection authority, in respect of the processing covered by this Addendum.

2.10. Security Incidents: Upon becoming aware of a Security Incident affecting Personal Data received from the other party, the affected party shall inform the other without undue delay and shall provide all such timely information and cooperation as the other may reasonably require in order to fulfil its own breach reporting obligations under (and within the timescales required by) Applicable Privacy Laws. The affected party shall further take all such measures as are reasonably necessary to remedy or mitigate the effects of the Security Incident and shall keep the other informed of all material developments, including those listed in Article 2.6 herein.

2.11. Dispute Resolution: In case of a dispute between a data subject and one of the Parties as regards compliance with this Addendum, that Party shall use its best efforts to resolve the issue amicably in a timely fashion. The Parties shall keep each other informed about such disputes and, where appropriate, cooperate in resolving them.

2.12. Deletion of Data: Upon termination or expiry of the Agreement, and upon expiry of the content licence granted to the Client under the Agreement, the Client shall cease processing Creator Data and shall delete it, together with all copies, save to the extent that retention is required by a law applicable to the Client or is necessary for the establishment, exercise or defence of legal claims, in which event the Client shall isolate and protect that data from any further processing until deletion is possible. OpenWild shall retain and delete Personal Data in accordance with the retention periods set out in its Privacy Policy.

2.13. Standard contractual clauses: To the extent that a transfer of Personal Data between the parties involves a Restricted Transfer, the SCCs shall be incorporated by reference and form an integral part of this Addendum, with the disclosing party as "data exporter" and the receiving party as "data importer". For the purposes of the SCCs: (i) the module one (controller-to-controller) terms shall apply and the module two, three and four terms shall be deleted in their entirety; (ii) in Clause 11, the optional language shall be deleted; and (iii) the Annexes to this Addendum shall be deemed to complete the Annexes to the SCCs.

2.14. Client-specific obligations: The Client shall not attempt to identify, contact or profile a Creator otherwise than through the Platform or through the social media account which the Creator has published, shall not scrape or systematically extract Creator Data from the Platform, shall not attempt to re-identify any individual from aggregated or anonymised outputs, and shall not disclose Creator Data to any third party other than a service provider engaged in accordance with Article 2.7 or where required by law.

2.15. Records and audit: Each party shall maintain records of its processing under this Addendum as required by Applicable Privacy Laws and shall, upon reasonable written request and no more than once in any twelve (12) month period, make available to the other such information as is reasonably necessary to demonstrate compliance with this Addendum. Nothing in this Addendum entitles either party to access the other's systems, premises or the personal data of other customers.

2.16. Liability: Each party is liable for its own compliance with Applicable Privacy Laws in respect of its own processing. Neither party is liable for the other's processing. The limitations of liability set out in the Agreement apply to this Addendum, save to the extent that Applicable Privacy Laws provide otherwise in respect of claims by Data Subjects or supervisory authorities.

2.17. Order of precedence: In the event of a conflict between this Addendum and the Agreement, this Addendum prevails in respect of the subject matter of this Addendum.

ANNEXES

ANNEX I. A. LIST OF PARTIES

Data exporter(s):

Name: [COMPANY_LEGAL_NAME] (OpenWild), where OpenWild discloses Creator Data to the Client; and [CLIENT_LEGAL_NAME], where the Client discloses Personal Data to OpenWild.

Address: [REGISTERED_ADDRESS] for OpenWild; [CLIENT_ADDRESS] for the Client.

Contact person’s name, position and contact details: OpenWild: [email protected]. Client: [CLIENT_CONTACT_NAME], [CLIENT_CONTACT_POSITION], [CLIENT_CONTACT_EMAIL].

Activities relevant to the data transferred under these Clauses: OpenWild operates a user-generated content and influencer campaign marketplace and discloses to the Client the Creator Data relating to the Creators who join the Client's campaigns, so that the Client may assess the submissions against its campaign brief, approve or reject claims and exercise the content licence granted to it.

Role (controller/processor): controller

Data importer(s):

Name: [CLIENT_LEGAL_NAME] (where OpenWild discloses Creator Data to the Client); [COMPANY_LEGAL_NAME] (where the Client discloses Personal Data to OpenWild).

Address: [CLIENT_ADDRESS] for the Client; [REGISTERED_ADDRESS] for OpenWild.

Activities relevant to the data transferred under these Clauses: The Client publishes reward-based content campaigns on the Platform, reviews the submissions made to those campaigns and uses the resulting content for its own marketing purposes within the scope of the licence granted to it.

Contact person’s name, position and contact details: Client: [CLIENT_CONTACT_NAME], [CLIENT_CONTACT_POSITION], [CLIENT_CONTACT_EMAIL]. OpenWild: [email protected].

Role (controller/processor): controller

Annex 1.B. DESCRIPTION OF TRANSFER

Categories of data subjects:

- Creators who join campaigns published by the Client;

- Third-party individuals whose personal data is included in the content submitted by a Creator or in the brand assets uploaded by the Client; and

- Where the Client makes them available, the individual representatives of the Client who use the Client's Account.

Categories of personal data:

- Creator Data, namely username, profile picture, country, connected social media account identifier and public profile information, the content submitted and the link to it, the associated performance statistics, and any free-text note added to the submission;

- Personal data of the Client's representatives, namely name, business e-mail address and account credentials; and

- any other personal data which the Client includes in a campaign brief or in brand assets, or which a Creator includes in submitted content. OpenWild does not receive card, bank account or identity verification data, which is collected directly by Stripe.

Sensitive data transferred (if applicable) and applied restrictions or safeguards:

Neither party intends to process any special category of personal data through the Platform. The Acceptable Use Policy prohibits campaigns which request or solicit special categories of personal data. Where such data is nevertheless included in submitted content or in brand assets, this is determined and controlled by the party which uploaded it, at its sole discretion. The restrictions and safeguards in Annex 2 also apply.

Frequency of the transfer: Continuous

Nature of the processing: Disclosure by OpenWild to the Client of the Creator Data relating to the Creators who join the Client's campaigns, and the Client's subsequent collection, review, storage and use of that data in order to assess submissions, approve or reject claims and exercise the content licence granted to it; and OpenWild's processing of the Client's account, campaign, wallet and transaction data in order to provide the Platform.

Purpose(s) of the data transfer and further processing: Provision of the Service pursuant to the Agreement.

Period for which the personal data will be retained: the Client shall retain Creator Data for no longer than the term of the content licence granted to it and any period required for the establishment, exercise or defence of legal claims, in accordance with Section 2.12 of this Addendum. OpenWild retains personal data in accordance with the retention periods set out in its Privacy Policy.

ANNEX 2 - TECHNICAL AND ORGANIZATIONAL MEASURES INCLUDING TECHNICAL AND ORGANIZATIONAL MEASURES TO ENSURE THE SECURITY OF THE DATA

OPENWILD has implemented the following security measures to protect its product or service:

  1. All traffic between users and the Platform is encrypted with TLS (Cloudflare and Let's Encrypt).

  2. Passwords are stored only in irreversibly hashed form (scrypt); plain-text passwords are never stored. Procedures are in place to ensure that only authorised personnel have access to personal data, and a non-disclosure and confidentiality agreement ensures that this continues to apply when a member of staff leaves.

  3. Optional two-factor authentication (TOTP) with backup codes is offered to all users.

  4. OAuth tokens for connected social accounts are stored encrypted in the database using AES-256-GCM.

  5. The database and Redis are accessible only from within the private network and Redis is password-protected.

  6. Role-based access control (Creator / Brand / Admin) and server-side authorisation checks are applied, and administrative privileges are further differentiated among authorised personnel.

  7. An audit log (action, actor, IP address and user agent) is kept for all critical operations.

  8. E-mail verification is required on registration.

  9. Session cookies are set with the HttpOnly, Secure and SameSite attributes and sessions expire after seven (7) days.

  10. The application, database and cache are hosted on infrastructure located in Türkiye; user uploads are stored in Cloudflare R2 object storage which is not publicly listable and is accessed through time-limited presigned URLs.

  11. Schema validation is applied to every input and webhook signatures are verified.

  12. Card data never reaches the Platform servers; the PCI DSS scope remains with Stripe.

  13. IP-based rate limiting is applied to authentication endpoints in order to protect against brute-force attacks.

  14. OpenWild intends to work together with external security service providers to perform periodic penetration tests.

ANNEX 3 – LIST OF OPENWILD SERVICE PROVIDERS

OpenWild engages the service providers listed below in connection with the operation of the Platform. The list is provided for transparency and may be updated in accordance with Article 2.7 of this Addendum.

Sub-processor Purpose Contact Address
Stripe, Inc. / Stripe Payments Europe, Limited Payment processing, escrow of reward pools and payouts 354 Oyster Point Blvd, South San Francisco, CA 94080, USA
Cloudflare, Inc. Content delivery network, security proxy and R2 object storage 101 Townsend St, San Francisco, CA 94107, USA
Google LLC YouTube Data API (social account connection and video statistics); Gmail SMTP (transactional e-mail delivery) 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA
Meta Platforms, Inc. Instagram API with Instagram Login (account connection and media statistics) 1 Meta Way, Menlo Park, CA 94025, USA
TikTok Pte. Ltd. TikTok API (account connection and video statistics) 1 Raffles Quay, Singapore 048583
Features and Labels, Inc. (fal.ai) Artificial-intelligence image and video generation San Francisco, California, USA
Anthropic, PBC Campaign assistant and content studio prompt functionality (Claude API) 548 Market St, San Francisco, CA 94104, USA
RNG Bilişim Teknolojileri San. ve Tic. Ltd. Şti. Server hosting (application, PostgreSQL database and Redis) Türkiye

© 2026 OpenWild — All rights reserved. Questions about this document? Email [email protected].