Data Processing Agreement
Schedule to the Motiv Terms of Service · Version 1.0 · Effective 10 June 2026
Parties
This Data Processing Agreement (the “DPA”) is entered into between:
(1) HiMedia BV, a company incorporated under the laws of the Netherlands, with its registered office at Tijnmuiden 59, 1046 AK Amsterdam, the Netherlands, and registered with the Dutch Chamber of Commerce (KvK) under number 76941566, trading as “Motiv” (“Motiv”, the “Processor”); and
(2) the Customer, being the legal entity that has accepted the Agreement and is identified as the account Owner in the Motiv platform (the “Customer”, the “Controller”).
Each a “Party” and together the “Parties”.
The Customer accepts this DPA by agreeing to the Motiv Terms of Service when creating an account. Acceptance is recorded together with the version number, the date and the IP address.
Background
(A) Motiv provides a software-as-a-service conversion intelligence platform that captures the chain from advertising click to conversion, classifies each conversion according to the consent associated with it, and dispatches conversion data to advertising platforms on the Controller’s behalf (the “Service”), as further described in the Agreement.
(B) In providing the Service, Motiv Processes Personal Data on behalf of the Controller. This DPA sets out the terms on which Motiv Processes such Personal Data and forms an integral part of the Agreement.
(C) This DPA gives effect to Article 28 of the GDPR and applicable Dutch data protection law.
1. Definitions and Interpretation
1.1 Capitalised terms used but not defined in this DPA have the meaning given to them in the Agreement.
1.2 In this DPA:
“Agreement” means the Motiv Terms of Service and any order, subscription or schedule entered into between the Parties, to which this DPA is a schedule.
“Applicable Data Protection Law” means all laws and regulations relating to the protection of Personal Data applicable to the Processing under this DPA, including the GDPR and the Dutch GDPR Implementation Act (Uitvoeringswet AVG, the “UAVG”).
“Authorised Agency” means a marketing agency or other third party that the Controller authorises to access its account through the MCC, as described in Clause 7.
“Consent Signal” means the marketing-consent state for a Data Subject or event as determined by the Controller’s configured consent mechanisms (such as a consent management platform, a checkout confirmation, a platform-native lead form, or a CRM field).
“Controller”, “Processor”, “Data Subject”, “Personal Data”, “Personal Data Breach”, “Processing” and “Special Categories of Personal Data” have the meanings given to them in the GDPR.
“GDPR” means Regulation (EU) 2016/679.
“MCC” means the multi-client management layer of the Service through which an Authorised Agency may be granted access to one or more Controller accounts.
“Observed Conversion” means a conversion event that is captured and made available within the Service for measurement, attribution and reporting, but which is dispatched to an advertising platform only where the Consent Signal indicates that the required marketing consent for such dispatch is present.
“Restricted Conversion” means a conversion event that is classified at ingest as lacking the Consent Signal required for dispatch to an advertising platform, and which is therefore never dispatched.
“Standard Contractual Clauses” or “SCCs” means the standard contractual clauses for the transfer of personal data to third countries adopted by the European Commission under Implementing Decision (EU) 2021/914.
“Sub-Processor” means any processor engaged by Motiv to Process Personal Data on behalf of the Controller under this DPA.
1.3 References to Clauses and Annexes are to clauses of and annexes to this DPA. The Annexes form part of this DPA.
2. Roles and Scope of Processing
2.1 For the purposes of this DPA, and in respect of the Personal Data described in Annex A, the Controller acts as controller and Motiv acts as processor.
2.2 Annex A sets out the subject matter, duration, nature and purpose of the Processing, the types of Personal Data and the categories of Data Subjects. Motiv shall Process such Personal Data only as a processor on behalf of the Controller and for no other purpose.
2.3 This DPA does not apply to Personal Data that Motiv Processes as a controller in its own right, including the account registration and contact data of the Controller’s users and the Controller’s billing and payment data. Motiv Processes such data as controller under its Privacy Policy, on the legal bases of performance of a contract and compliance with a legal obligation.
2.4 The advertising platforms to which conversion data is dispatched act as independent controllers in respect of the data they receive for their own purposes. They are recipients and not Sub-Processors of Motiv. Clause 8 and Annex C address this further.
3. Processing Instructions
3.1 Motiv shall Process Personal Data only on documented instructions from the Controller, including with regard to transfers of Personal Data to a third country, unless required to do so by Union or Member State law to which Motiv is subject. In such a case, Motiv shall inform the Controller of that legal requirement before Processing, unless that law prohibits such information on important grounds of public interest.
3.2 The Controller’s instructions are set out in this DPA and the Agreement and are given through the Controller’s configuration and use of the Service in accordance with its documentation, including the configuration of consent sources, jurisdiction settings, routing rules and dispatch destinations.
3.3 By design, Motiv dispatches conversion data to an advertising platform only where the Controller’s configured Consent Signal indicates that the required marketing consent is present at the time of dispatch, and a Restricted Conversion is never dispatched. The Controller acknowledges that the lawful basis for, and the validity of, the consent obtained through its own consent mechanisms remain the Controller’s responsibility.
3.4 Motiv shall inform the Controller if, in its opinion, an instruction infringes Applicable Data Protection Law. Motiv is not obliged to carry out a legal review of the Controller’s instructions.
4. Confidentiality
4.1 Motiv shall ensure that persons authorised to Process the Personal Data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality.
4.2 Motiv shall ensure that access to Personal Data is limited to those personnel who require access in order to perform Motiv’s obligations under the Agreement.
5. Security
5.1 Taking into account the state of the art, the costs of implementation, and the nature, scope, context and purposes of Processing, as well as the risk to Data Subjects, Motiv shall implement the appropriate technical and organisational measures set out in Annex B to ensure a level of security appropriate to the risk.
5.2 The Controller acknowledges that Annex B describes the technical and organisational measures implemented by Motiv and that, having regard to the nature of the Personal Data, which is minimised and, in respect of directly identifying fields, hashed, they are appropriate to the risk presented by the Processing.
5.3 Motiv may update the measures in Annex B from time to time, provided that the updated measures do not result in a material reduction of the overall level of security.
6. Sub-Processors
6.1 The Controller provides a general written authorisation for Motiv to engage Sub-Processors to Process Personal Data, subject to this Clause 6. The Sub-Processors engaged at the date of this DPA are listed in Annex C.
6.2 Motiv shall inform the Controller of any intended addition or replacement of a Sub-Processor at least thirty (30) days in advance, giving the Controller the opportunity to object on reasonable data-protection grounds. Motiv will make such notifications available through the Service or by email to the Controller’s registered contact.
6.3 If the Controller objects on reasonable grounds within the notice period, the Parties shall discuss the objection in good faith. If no resolution is reached, the Controller may, as its sole remedy, terminate the affected part of the Service by written notice.
6.4 Motiv shall impose on each Sub-Processor, by way of a written contract, data-protection obligations that are no less protective than those set out in this DPA. Motiv remains fully liable to the Controller for the performance of each Sub-Processor’s obligations.
7. Authorised Agencies and MCC Access
7.1 The Controller may authorise an Authorised Agency to access its account through the MCC, either by accepting an invitation from the Agency or by linking the Agency from within its own account.
7.2 An Authorised Agency acts on behalf of, and under the instructions of, the Controller. The Authorised Agency is a processor of the Controller in its own right and is not a Sub-Processor of Motiv. The arrangement between the Controller and the Authorised Agency, including any data-processing agreement required between them, is the responsibility of the Controller. Motiv is not a party to that relationship.
7.3 The Controller acknowledges and agrees that the administrator of an Authorised Agency determines which individuals within that Agency are granted access to which Controller accounts, and that the Controller does not separately approve those individuals. The Authorised Agency is responsible for binding its personnel to confidentiality and for applying appropriate access controls to them.
7.4 The Controller may withdraw an Authorised Agency’s access at any time by removing the link to that Agency in the Service. Motiv logs access by Authorised Agencies in order to support auditability.
7.5 The commercial arrangements for payment of the Service, including any arrangement under which an Authorised Agency pays for the Service on behalf of the Controller, do not affect the roles, responsibilities or instructions set out in this DPA. The Controller remains the controller of the Personal Data regardless of who pays for the Service.
7.6 This DPA and Motiv’s role as processor apply regardless of any agency branding presented within the Service interface.
8. International Transfers
8.1 Personal Data Processed by Motiv on behalf of the Controller is stored at rest within the European Union.
8.2 Where a Sub-Processor Processes Personal Data outside the European Economic Area, Motiv ensures that an appropriate transfer mechanism under Chapter V of the GDPR is in place, being an adequacy decision of the European Commission and/or the Standard Contractual Clauses. The transfer mechanism applicable to each Sub-Processor is identified in Annex C.
8.3 The dispatch of conversion data to an advertising platform is carried out on the Controller’s instruction and configuration, and only to platforms the Controller has connected. Such platforms act as independent controllers in respect of the data they receive. The Controller is responsible for its own relationship with, and the terms it accepts from, those platforms, including any transfer mechanism that applies between the Controller and the platform. Motiv facilitates the dispatch in accordance with the Controller’s configuration and the consent gating described in Clause 3. The platforms to which the Controller may dispatch are listed in Annex C.
9. Assistance with Data Subject Rights
9.1 Taking into account the nature of the Processing, Motiv shall assist the Controller by appropriate technical and organisational measures, insofar as this is possible, to fulfil the Controller’s obligation to respond to requests by Data Subjects exercising their rights under Chapter III of the GDPR.
9.2 The Service enables the Controller to action requests from its own visitors directly through its account settings, including erasure, which is initiated without undue delay through the Service. On erasure, identity records are deleted, click identifier values held on touchpoints are nulled, directly identifying fields are removed from event payloads, consent records are deleted, behavioral event records are deleted, and the person reference on attribution records is removed. Residual copies present in backups are removed on backup rotation. Aggregated and de-identified data that no longer constitutes Personal Data is retained for the integrity of historical reporting.
9.3 Where the Controller submits a request to Motiv that requires Motiv’s own action or assistance, Motiv responds within seven (7) business days of receiving a complete request.
9.4 Client-side storage on the Controller’s website, such as click identifier hashes held in a visitor’s browser after consent, is under the Controller’s control. The Controller is responsible for providing a mechanism in its consent management platform that clears such storage on consent withdrawal or erasure.
9.5 If a Data Subject submits a request directly to Motiv, Motiv shall, where it can identify the relevant Controller, promptly forward the request to the Controller, and shall not respond to the request itself except on the Controller’s instruction or as required by law.
10. Personal Data Breach
10.1 Motiv shall notify the Controller without undue delay, and in any event within forty-eight (48) hours, after becoming aware of a Personal Data Breach affecting Personal Data Processed under this DPA.
10.2 The notification shall describe, to the extent known, the nature of the breach, the categories and approximate number of Data Subjects and records concerned, the likely consequences, and the measures taken or proposed to address it. Where the information cannot be provided at once, it may be provided in phases without undue further delay.
10.3 Motiv shall assist the Controller in meeting the Controller’s obligations under Articles 33 and 34 of the GDPR. Notification of a breach is not an acknowledgement by Motiv of fault or liability.
11. Data Protection Impact Assessments
11.1 Taking into account the nature of the Processing and the information available to Motiv, Motiv shall provide reasonable assistance to the Controller with any data protection impact assessment, and any prior consultation with a supervisory authority, that the Controller is required to carry out under Articles 35 and 36 of the GDPR.
12. Audits
12.1 Motiv shall make available to the Controller all information reasonably necessary to demonstrate compliance with the obligations set out in Article 28 of the GDPR and this DPA, and shall allow for and contribute to audits, including inspections, conducted by the Controller or an auditor mandated by the Controller.
12.2 The Controller’s audit right under Clause 12.1 is satisfied in the first instance by Motiv providing relevant documentation, responses to reasonable security questionnaires, and any third-party certifications and audit reports available to Motiv, including the certifications held by Motiv’s hosting provider in respect of the infrastructure layer.
12.3 Where the documentation referred to in Clause 12.2 is not sufficient to address a specific and reasonable concern, the Controller may carry out a further audit, subject to the following: the Controller gives at least thirty (30) days’ written notice; audits take place no more than once in any twelve (12) month period, save where required by a supervisory authority or following a Personal Data Breach; audits are conducted during business hours, in a manner that does not unreasonably disrupt Motiv’s operations, and subject to confidentiality; and, as Motiv operates on a remote basis without dedicated offices, audits are conducted remotely unless a competent supervisory authority requires otherwise. Each Party bears its own costs.
13. Return and Deletion of Personal Data
13.1 On termination or expiry of the Agreement, Motiv shall, at the Controller’s choice, delete or return the Personal Data Processed on the Controller’s behalf and delete existing copies, unless retention is required by Union or Member State law.
13.2 The Service provides a data-portability export that the Controller may use, before or shortly after termination, to obtain the Personal Data in a structured, commonly used and machine-readable format. Directly identifying fields are provided only in hashed form. Raw identifiers are not available for export where Motiv does not store them in raw form.
13.3 Following termination, Personal Data is deleted in accordance with the retention schedule in Annex D. Aggregated and de-identified data that no longer constitutes Personal Data may be retained. Billing and accounting records that Motiv holds as a controller are retained for the period required by applicable law.
14. Liability
14.1 The liability of each Party arising out of or in connection with this DPA is subject to the limitations and exclusions of liability set out in the Agreement.
14.2 Without prejudice to Clause 14.1, the total aggregate liability of Motiv arising out of or in connection with this DPA and the Agreement shall not exceed the total fees paid by the Controller to Motiv in the twelve (12) months preceding the event giving rise to the claim.
14.3 Nothing in this DPA or the Agreement limits or excludes either Party’s liability for matters which may not be limited or excluded under applicable law, including liability arising from intent or gross negligence (opzet of grove schuld) or for death or personal injury.
14.4 Nothing in this Clause 14 affects the rights of a Data Subject under the GDPR, including the right to receive compensation under Article 82 of the GDPR, which cannot be limited by agreement between the Parties.
14.5 Motiv maintains appropriate professional and cyber liability insurance cover with reputable insurers, consistent with the nature, scope and risks of the Processing.
15. Term
15.1 This DPA takes effect on the date the Controller accepts the Agreement and continues for as long as Motiv Processes Personal Data on behalf of the Controller. Clauses that by their nature should survive termination shall survive.
16. General
16.1 In the event of a conflict between this DPA and the Agreement in relation to the Processing of Personal Data, this DPA prevails.
16.2 This DPA is governed by the laws of the Netherlands. The Parties submit any dispute arising out of or in connection with this DPA to the exclusive jurisdiction of the competent court of the Rechtbank Oost-Brabant, without prejudice to any mandatory rights of a Data Subject.
16.3 If any provision of this DPA is held to be invalid or unenforceable, the remaining provisions continue in full force, and the Parties shall replace the invalid provision with a valid provision that reflects its purpose as closely as possible.
16.4 Motiv may amend this DPA where necessary to reflect changes in Applicable Data Protection Law, guidance from supervisory authorities, or changes to the Service, provided that any amendment does not materially reduce the protection afforded to Data Subjects. The current version is available at getmotiv.io/legal/dpa.
Acceptance of this DPA takes place electronically as part of the Customer’s acceptance of the Agreement, as described under Parties above. No signature is required.
Annex A: Details of the Processing
Subject matter
The Processing of Personal Data necessary for the provision of the Service, being the server-side capture, classification, attribution and consent-gated dispatch of conversion data.
Duration
For the term of the Agreement, subject to the retention and deletion provisions of Clause 13 and Annex D.
Nature and purpose of the Processing
Capturing the chain from advertising click to conversion; classifying each conversion as Observed or Restricted on the basis of the Consent Signal; attributing conversions to advertising channels and campaigns across an attribution window of up to 365 days; recording behavioral events, such as page views and clicks, for consented visitors, where the Controller has enabled journey tracking, to support journey analysis; and dispatching conversion data, where the Consent Signal indicates marketing consent, to the advertising platforms the Controller has connected.
Categories of Data Subjects
The Controller’s website visitors, prospects, leads and customers, whose interactions with the Controller’s websites, landing pages, lead forms and connected systems are tracked through the Service.
Types of Personal Data
- Hashed direct identifiers, such as email address and telephone number, stored only in hashed form (SHA-256);
- Advertising click identifiers (such as gclid, fbclid, ttclid, msclkid and equivalent platform click identifiers). Before a Consent Signal indicating marketing consent is present, these are read only into an in-memory variable in the visitor’s browser; they are not placed in URLs, written to any browser or server storage, or transmitted to Motiv. They are transmitted to and stored by Motiv only after the Consent Signal indicates marketing consent;
- Session identifiers;
- Behavioral event data, such as page views and clicks, for consented visitors, where the Controller has enabled journey tracking;
- IP address, processed in transit, including at the edge layer described in Annex C;
- Technical and device data associated with an event, such as user-agent and timestamp;
- Conversion and transaction data, such as event type, value and currency;
- Consent data, being the consent status, origin and time associated with a Data Subject or event;
- Lead status data received from the Controller’s connected CRM, where configured.
Hashed identifiers are treated as Personal Data under this DPA where they can reasonably be linked, matched or otherwise associated with a Data Subject.
Special Categories of Personal Data
The Service is not intended to Process Special Categories of Personal Data, and the Controller shall not configure the Service to transmit such data.
Annex B: Technical and Organisational Measures
Motiv applies the following technical and organisational measures, which it may update in accordance with Clause 5.3. Further detail on these measures is available to the Controller on request, subject to confidentiality.
Encryption and pseudonymisation
- Directly identifying fields are hashed (SHA-256) in the API layer before they are written to storage or to any queue.
- Platform credentials (OAuth access and refresh tokens) are stored encrypted using AES-256-GCM and are never stored or logged in plain text.
- Personal Data is encrypted in transit using TLS 1.2 or higher.
Pre-consent handling of click identifiers
- Before a Consent Signal indicating marketing consent is present, advertising click identifiers are processed only in the visitor’s browser memory. They are not placed in URLs, written to any browser or server storage, or transmitted to Motiv. They are transmitted to and stored by Motiv only after the Consent Signal indicates marketing consent.
- On server-to-server endpoints, sensitive parameters such as authentication tokens are redacted from logs and stored request payloads.
Data minimisation by design
- Each conversion is classified at ingest as Observed or Restricted, and this classification is immutable thereafter.
- Restricted Conversions are minimised at classification and are never dispatched to an advertising platform.
Access control and isolation
- Role-based access control with defined roles (Owner, Admin, Agency, User).
- Database row-level security enforcing tenant isolation, with the tenant context set on each request.
- Multi-factor authentication is enforced for Motiv personnel and for agency (MCC) access. Tenants can enable multi-factor authentication for their own accounts.
- Logging of administrative access and of any impersonation of a user by Motiv personnel.
- Least-privilege access to production systems, with secrets held in a dedicated managed secrets store.
Integrity, availability and resilience
- An asynchronous, queue-first processing pipeline; no inbound webhook is processed synchronously.
- Per-tenant rate limiting, circuit breakers on outbound platform interfaces, idempotency keys, domain allow-listing and signature validation of inbound requests.
- Nightly encrypted backups stored in EU object storage and retained on a rolling basis.
- EU data residency: hosting and storage within the European Union.
Monitoring and auditability
- Continuous monitoring (metrics, logs and tracing) and anomaly detection, with operational alerting.
- An immutable decision trail per event, enabling each Processing decision to be traced to an actor, a time and a ruleset.
Organisational measures
- Confidentiality obligations for personnel with access to Personal Data.
- Procedures for handling Personal Data Breaches and for assisting the Controller with Data Subject requests.
Annex C: Sub-Processors and Recipients
Part 1 lists the Sub-Processors engaged by Motiv to Process Personal Data on behalf of the Controller. Part 2 lists the advertising platforms to which the Controller may dispatch conversion data, where connected by the Controller; these act as independent controllers and recipients, not Sub-Processors.
Part 1: Sub-Processors
| Sub-Processor | Location | Data processed | Safeguards |
|---|---|---|---|
| Hetzner Online GmbH | Germany and Finland (EU) | All Personal Data, at rest, as required for hosting and infrastructure operation (database, cache, queue, object storage) | Processing within the EU only; ISO 27001-certified data centres; encrypted backups |
| Cloudflare, Inc. | United States | IP address and request metadata, in transit at the edge | EU-US Data Privacy Framework and EU SCCs; TLS; no access to Motiv’s application database; edge logging limited to operational and security metadata |
An up-to-date list of Sub-Processors is maintained at getmotiv.io/legal/sub-processors. Motiv notifies the Controller of changes in accordance with Clause 6.
Part 2: Advertising platform recipients (independent controllers)
Dispatch occurs only to platforms the Controller has connected. Each platform acts as an independent controller for the data it receives and applies its own terms. The transfer basis stated is indicative of the mechanism generally made available by the platform; the Controller remains responsible for verifying and accepting the applicable platform terms.
| Platform | Location | Transfer basis |
|---|---|---|
| Google LLC (Google Ads) | United States | EU-US Data Privacy Framework; SCCs |
| Google LLC (Display & Video 360) | United States | EU-US Data Privacy Framework; SCCs |
| Meta Platforms, Inc. | United States | EU-US Data Privacy Framework; SCCs |
| TikTok Inc. | United States | Standard Contractual Clauses |
| LinkedIn Ireland Unlimited Company | Ireland / United States | Standard Contractual Clauses |
| Microsoft Corporation | United States | EU-US Data Privacy Framework; SCCs |
| Snap Inc. | United States | Standard Contractual Clauses |
| Pinterest, Inc. | United States | Standard Contractual Clauses |
| Reddit, Inc. | United States | Standard Contractual Clauses |
| Taboola, Inc. | United States | Standard Contractual Clauses |
| Outbrain Inc. | United States | Standard Contractual Clauses |
| X Corp. | United States | Standard Contractual Clauses |
| Amazon.com, Inc. | United States | EU-US Data Privacy Framework; SCCs |
| Criteo SA | France / United States | EU-established; SCCs for US processing |
Annex D: Retention Schedule
Personal Data Processed on the Controller’s behalf is retained as set out below. Retention periods are enforced automatically and are not configurable by the Controller, except where stated.
| Data category | Retention | After retention |
|---|---|---|
| Observed conversion events | 90 days live; archived thereafter | Hard-deleted after 13 months |
| Restricted conversion events | 30 days (minimised at classification) | Hard-deleted; no archive |
| Behavioral events (journey tracking) | 90 days; 365 days for Enterprise | Hard-deleted |
| Touchpoints | 365 days | Hard-deleted |
| Attribution records | 13 months | Hard-deleted; person reference removed on erasure, aggregate retained |
| Processing and dispatch logs | 365 days | Hard-deleted |
| Consent records | Until erasure or account deletion (append-only) | — |
| Identity keys (hashed) | Until erasure or account deletion | — |
| Backups | Rolling encrypted backups, up to 7 days, in EU object storage | Overwritten on rotation |
| Billing and financial records (Motiv as controller) | 7 years (legal obligation) | Anonymised |
Enterprise customers may agree longer retention periods as a bespoke arrangement.