Pet Life Journey

Schedule D — Data Sharing and Privacy

The customer dataset, permitted uses, security requirements, marketing status and suppression handling.

Forms part ofPartner Agreement

This Schedule D — Data Sharing and Privacy (“Schedule D”) is incorporated into and forms part of the Pet Life Journey Partner Agreement (the “Agreement”) between Ody Health, a Wyoming corporation doing business as Pet Life Journey (“PLJ”), and [PARTNER LEGAL NAME] (“Partner”).

Capitalized terms not defined in this Schedule D have the meanings given in the Agreement.

1.PURPOSE AND DATA RELATIONSHIP

1.1Purpose

This Schedule D establishes the Parties’ respective rights and obligations concerning Personal Information collected, received, disclosed, or otherwise processed in connection with Partner’s participation in the PLJ Program.

The Parties acknowledge that providing Partner with information concerning End Customers attributable to Partner is a material component of the commercial relationship.

1.2Independent Uses of Personal Information

Except where the Parties expressly agree otherwise in writing for a particular processing activity, each Party determines its own lawful purposes and means for its use of Personal Information in its possession or control.

Neither Party is designated generally as the other Party’s service provider, contractor, processor, agent, or similar restricted data processor merely because Personal Information is disclosed between the Parties under the Agreement.

Each Party is independently responsible for complying with Privacy Laws applicable to its own collection, receipt, use, disclosure, retention, and other processing of Personal Information.

1.3No Ownership Characterization

The Parties will not characterize Personal Information as property “owned” by either Party.

The Agreement and this Schedule D instead establish each Party’s contractual rights to collect, receive, use, retain, disclose, and otherwise process Personal Information, subject to:

  1. (a)applicable Privacy Laws;
  2. (b)disclosures made to the applicable End Customer;
  3. (c)applicable End Customer choices and consents;
  4. (d)the Agreement; and
  5. (e)this Schedule D.

2.DEFINITIONS

2.1Personal Information

“Personal Information” means information that identifies, relates to, describes, is reasonably capable of being associated with, or could reasonably be linked, directly or indirectly, with an identified or identifiable natural person or household, together with any substantially similar category of information protected as personal information or personal data under applicable Privacy Laws.

2.2Privacy Laws

“Privacy Laws” means applicable laws and regulations governing privacy, data protection, data security, direct marketing, or the processing of Personal Information.

2.3Partner Customer Data

“Partner Customer Data” means Personal Information concerning an End Customer attributable to Partner that PLJ makes available to Partner pursuant to the Agreement and this Schedule D.

2.4End Customer Choices

“End Customer Choices” means legally effective consents, opt-outs, marketing preferences, suppression requests, privacy requests, and other choices exercised by an End Customer concerning the processing of Personal Information.

2.5Security Incident

“Security Incident” means unauthorized access to, acquisition of, disclosure of, alteration of, destruction of, or loss of Personal Information maintained under this Schedule D that triggers a notification, investigation, remediation, or other obligation under applicable Privacy Laws.


3.PLJ COLLECTION OF END CUSTOMER INFORMATION

3.1PLJ Collection

As seller and merchant of record, PLJ may collect Personal Information directly from End Customers in connection with PLJ Product transactions.

Such information may include, as applicable:

  1. (a)name;
  2. (b)email address;
  3. (c)telephone number;
  4. (d)billing address;
  5. (e)shipping address;
  6. (f)order information;
  7. (g)products purchased;
  8. (h)transaction amounts;
  9. (i)transaction dates;
  10. (j)subscription or recurring-purchase status;
  11. (k)customer-service communications;
  12. (l)return and refund information;
  13. (m)fraud and security information;
  14. (n)device, browser, cookie, or similar online information;
  15. (o)applicable marketing preferences and consents; and
  16. (p)other information reasonably necessary to operate the PLJ Program or comply with law.

3.2Payment Information

Payment-card information may be collected or processed by PLJ’s payment processor or other payment-service provider.

PLJ will not provide Partner with full payment-card numbers, card-security codes, bank credentials, or other payment credentials that Partner does not reasonably require.

3.3PLJ Purposes

Subject to applicable Privacy Laws and PLJ’s disclosures to End Customers, PLJ may process Personal Information for purposes including:

  1. (a)processing orders and payments;
  2. (b)fulfilling and shipping orders;
  3. (c)providing order confirmations and transactional communications;
  4. (d)administering subscriptions and recurring purchases;
  5. (e)providing customer service;
  6. (f)administering returns, refunds, replacements, and chargebacks;
  7. (g)detecting and preventing fraud, abuse, and security threats;
  8. (h)maintaining tax, accounting, transaction, and business records;
  9. (i)providing product recalls, safety notices, and other product-related communications;
  10. (j)administering and improving PLJ storefronts and commerce systems;
  11. (k)analyzing PLJ Product and Program performance;
  12. (l)managing the relationship among PLJ, End Customers, Partners, manufacturers, suppliers, fulfillment providers, and other service providers;
  13. (m)complying with applicable law and enforcing legal rights; and
  14. (n)marketing PLJ Products and services where legally permitted.

4.PARTNER CUSTOMER DATA PROVIDED BY PLJ

4.1Customer Dataset

Subject to applicable Privacy Laws, End Customer Choices, and PLJ’s consumer-facing disclosures, PLJ will make available to Partner Partner Customer Data reasonably associated with End Customers attributable to Partner.

4.2Standard Partner Customer Data

The standard Partner Customer Data may include:

  1. (a)End Customer name;
  2. (b)email address;
  3. (c)telephone number, where appropriate;
  4. (d)shipping address, where appropriate;
  5. (e)order number;
  6. (f)order date;
  7. (g)PLJ Products purchased;
  8. (h)quantity purchased;
  9. (i)amount paid;
  10. (j)subscription or recurring-purchase status;
  11. (k)refund or cancellation status;
  12. (l)marketing-consent or marketing-preference information made available by PLJ; and
  13. (m)other customer or transaction information PLJ determines is appropriate for the purposes authorized under this Schedule D.

4.3Data Minimization

PLJ may omit or restrict particular fields where PLJ reasonably determines that disclosure:

  1. (a)is not reasonably necessary for Partner’s permitted purposes;
  2. (b)would be inconsistent with an End Customer Choice;
  3. (c)would violate applicable Privacy Laws;
  4. (d)would create an unreasonable security risk; or
  5. (e)is otherwise inappropriate in light of the nature of the information.

4.4No Payment Credentials

Partner Customer Data will not include full payment-card numbers, card-security codes, bank-account credentials, or similar payment authentication information.


5.PARTNER PERMITTED PURPOSES

5.1Specified Purposes

Subject to applicable Privacy Laws, End Customer Choices, and the restrictions in this Schedule D, Partner may use Partner Customer Data for the following specified purposes:

  1. (a)maintaining Partner’s customer, member, supporter, donor, client, or community records;
  2. (b)communicating with End Customers concerning Partner and Partner’s activities;
  3. (c)sending Partner newsletters and organizational communications;
  4. (d)communicating concerning Partner programs, services, events, memberships, or activities;
  5. (e)lawful fundraising communications;
  6. (f)promoting Partner’s PLJ Storefront and PLJ Products offered through it;
  7. (g)promoting Partner’s own products, services, programs, memberships, events, and activities;
  8. (h)understanding and analyzing engagement by Partner’s customers, supporters, members, donors, clients, or community;
  9. (i)measuring the performance of Partner’s PLJ Storefront and related promotional activities;
  10. (j)responding to inquiries concerning Partner;
  11. (k)maintaining records reasonably necessary for Partner’s accounting, compliance, governance, or other legitimate organizational functions; and
  12. (l)complying with law and exercising or defending legal rights.

5.2Reasonably Necessary and Proportionate Use

Partner will limit its use of Partner Customer Data to Personal Information reasonably necessary and proportionate for the applicable permitted purpose.

5.3No Unrelated Third-Party Commercial Marketing

Partner may not use Partner Customer Data to advertise or promote an unrelated third party’s products or services unless:

  1. (a)the End Customer has provided any consent required by applicable law;
  2. (b)the use is consistent with the disclosures made to the End Customer; and
  3. (c)the use is otherwise expressly permitted by PLJ in writing.

6.PROHIBITED DATA PRACTICES

Except where expressly authorized by this Schedule D or otherwise agreed by the Parties in writing and permitted by applicable law, Partner will not:

  1. (a)sell Partner Customer Data;
  2. (b)rent Partner Customer Data;
  3. (c)license Partner Customer Data as a standalone customer list;
  4. (d)disclose Partner Customer Data to a data broker;
  5. (e)provide Partner Customer Data to an unrelated third party for that third party’s independent direct marketing;
  6. (f)use Partner Customer Data for a materially different purpose from the purposes specified in Section 5;
  7. (g)attempt to obtain payment-card credentials or other restricted payment information from PLJ systems;
  8. (h)use Partner Customer Data in violation of an applicable End Customer Choice;
  9. (i)knowingly combine Partner Customer Data with unlawfully obtained Personal Information;
  10. (j)use Partner Customer Data for unlawful discrimination or another unlawful purpose; or
  11. (k)circumvent a technical or contractual restriction PLJ implements to comply with Privacy Laws or an End Customer Choice.

Nothing in this Section prohibits Partner from using its own independently collected information in accordance with applicable law.


7.END CUSTOMER NOTICE AND TRANSPARENCY

7.1PLJ Consumer Disclosures

PLJ will provide or make available consumer-facing privacy disclosures reasonably necessary to describe PLJ’s collection, use, and disclosure of Personal Information in connection with PLJ Product transactions.

7.2Disclosure of Partner Relationship

Where appropriate under applicable Privacy Laws, PLJ’s checkout, privacy notice, notice at collection, or other applicable disclosure will inform the End Customer that information associated with the End Customer’s transaction may be provided to the Partner whose Storefront or PLJ commerce experience generated the transaction.

7.3Identification of Partner

Where reasonably practicable, the applicable Partner will be identified to the End Customer so that the End Customer can understand the organization receiving Partner Customer Data.

7.4Partner Privacy Notice

Partner will maintain any privacy notice required by applicable Privacy Laws for Partner’s independent processing of Personal Information.

Partner’s privacy notice will not materially contradict PLJ’s disclosures concerning the operation of the PLJ Program.

7.5No Hidden Expansion of Use

Neither Party will use this Schedule D as a substitute for consumer notice or consent where applicable Privacy Laws require notice or consent for a particular processing activity.


8.MARKETING COMMUNICATIONS

8.1Email

Partner may use an End Customer’s email address for commercial, organizational, fundraising, or other communications only to the extent permitted by applicable law and applicable End Customer Choices.

Partner is responsible for legally required sender identification, disclosures, unsubscribe mechanisms, suppression, and other requirements applicable to Partner’s communications.

8.2Telephone and Text Messaging

Receipt of an End Customer’s telephone number from PLJ does not, by itself, constitute consent for Partner to send marketing text messages, use automated telephone technology, place marketing calls, or engage in any other communication requiring affirmative consent.

Partner may use telephone information for such purposes only when Partner has a legally sufficient basis to do so.

8.3Transactional Communications

PLJ may send transactional communications reasonably necessary to administer PLJ Product transactions regardless of whether the End Customer has opted out of marketing communications, to the extent permitted by law.

8.4Suppression

Each Party will honor legally applicable unsubscribe, suppression, and other marketing requests relating to that Party’s communications.


9.PRIVACY RIGHTS AND CONSUMER REQUESTS

9.1Each Party’s Responsibilities

Each Party is responsible for responding to privacy requests directed to that Party to the extent required by applicable Privacy Laws.

Such requests may include requests concerning:

  1. (a)access;
  2. (b)knowledge;
  3. (c)correction;
  4. (d)deletion;
  5. (e)portability;
  6. (f)sale or sharing;
  7. (g)use or disclosure of sensitive Personal Information; and
  8. (h)other rights recognized by applicable Privacy Laws.

9.2Requests Affecting the Other Party

If a Party receives a request that reasonably appears to concern Personal Information maintained by the other Party, the receiving Party will, where appropriate and legally permitted:

  1. (a)direct the End Customer to the other Party; or
  2. (b)notify the other Party of the request.

9.3Cooperation

The Parties will reasonably cooperate where a consumer request implicates Personal Information disclosed between them and cooperation is reasonably necessary for either Party to comply with applicable Privacy Laws.

9.4Requests to Delete

If PLJ informs Partner that Partner Customer Data must be deleted because of a legally effective End Customer request, Partner will delete the applicable Partner Customer Data to the extent required by applicable law, subject to any applicable legal exception permitting retention.

The same obligation applies to PLJ if Partner properly informs PLJ of a request that legally requires PLJ to take corresponding action.

9.5Correction

If either Party becomes aware that material Partner Customer Data disclosed between the Parties is inaccurate and applicable law requires correction, the Parties will reasonably cooperate to correct the information in systems under their respective control.


10.CALIFORNIA-SPECIFIC DATA TRANSFER TERMS

10.1Applicability

This Section applies to the extent the California Consumer Privacy Act, as amended (“CCPA”), applies to a disclosure of Personal Information between PLJ and Partner.

10.2Specified Purposes

The limited and specified purposes for which PLJ makes Partner Customer Data available to Partner are the purposes expressly identified in Section 5 of this Schedule D.

10.3Use Consistent With CCPA

Partner will process California Personal Information made available by PLJ only for purposes consistent with this Schedule D and PLJ’s obligations under the CCPA.

Partner will not process such Personal Information for a purpose outside the purposes specified in this Schedule D unless the processing is otherwise permitted by the CCPA and any legally required consumer notice, consent, or other condition has been satisfied.

10.4Same Level of Privacy Protection

Partner will provide the level of privacy protection for Personal Information required by the CCPA with respect to Partner’s processing of California Personal Information received from PLJ.

10.5Compliance Verification

To the extent required by the CCPA, PLJ may take reasonable and appropriate steps to help ensure that Partner uses California Personal Information transferred by PLJ in a manner consistent with PLJ’s obligations under the CCPA.

Such steps may include reasonable written compliance inquiries, certifications, or other proportionate measures.

10.6Notice of Inability to Comply

Partner will notify PLJ if Partner determines that it can no longer meet its obligations under this Section with respect to California Personal Information received from PLJ.

10.7Remediation

If PLJ reasonably determines that Partner is using California Personal Information transferred by PLJ in violation of this Schedule D or applicable CCPA requirements, PLJ may take reasonable and appropriate steps to stop and remediate the unauthorized use.

10.8Reciprocal Transfers

To the extent Partner makes Personal Information available to PLJ in circumstances subject to equivalent CCPA contractual requirements, the obligations in Sections 10.2 through 10.7 apply reciprocally, with the Parties’ roles reversed and with the applicable specified purposes determined by the Agreement and this Schedule D.


11.SALE, SHARING, AND OPT-OUT RIGHTS

11.1Legal Characterization

The Parties will determine their obligations concerning a “sale” or “sharing” of Personal Information based on applicable Privacy Laws and the actual facts of the applicable data transfer, rather than solely on the terminology used in this Agreement.

11.2Required Consumer Choices

If applicable Privacy Laws give an End Customer a right to opt out of a sale, sharing, targeted advertising, cross-context behavioral advertising, or similar processing conducted by a Party, that Party is responsible for providing and honoring the applicable choice mechanism.

11.3Effect on Partner Customer Data

If a legally effective End Customer Choice requires PLJ to cease making particular Personal Information available to Partner, PLJ may discontinue or limit the applicable data transfer.

Partner acknowledges that PLJ’s obligation to provide Partner Customer Data is subject to applicable Privacy Laws and legally effective End Customer Choices.

11.4No Circumvention

Neither Party will attempt to circumvent a legally effective opt-out or other End Customer Choice by obtaining substantially equivalent Personal Information through another Party to the Agreement.


12.SERVICE PROVIDERS AND CONTRACTORS

12.1Use of Vendors

Each Party may use hosting providers, cloud providers, email providers, analytics providers, professional advisers, technology vendors, and other service providers or contractors to process Personal Information on its behalf where permitted by applicable law.

12.2Responsibility for Vendors

Each Party is responsible for entering into contracts with its service providers or contractors to the extent required by applicable Privacy Laws.

12.3Restricted Use

A Party will not disclose Partner Customer Data to a vendor in a manner that gives the vendor independent rights to use the information for unrelated purposes where such disclosure would violate this Schedule D or applicable Privacy Laws.


13.DATA SECURITY

13.1Reasonable Safeguards

Each Party will maintain reasonable administrative, technical, and physical safeguards appropriate to:

  1. (a)the nature of the Personal Information it processes;
  2. (b)the sensitivity of that information;
  3. (c)the reasonably foreseeable risks associated with the processing; and
  4. (d)the Party’s size, resources, and processing activities.

13.2Access Controls

Each Party will limit access to Partner Customer Data to personnel and contractors who reasonably require access for authorized purposes.

13.3Credentials

Neither Party will knowingly disclose credentials providing access to systems containing Partner Customer Data except to persons authorized to access those systems.

13.4Security Practices

Reasonable safeguards may include, as appropriate:

  1. (a)access controls;
  2. (b)authentication controls;
  3. (c)encryption in transit;
  4. (d)encryption at rest where appropriate;
  5. (e)system monitoring;
  6. (f)vulnerability and patch management;
  7. (g)backups;
  8. (h)employee or contractor confidentiality obligations; and
  9. (i)incident-response procedures.

14.SECURITY INCIDENTS

14.1Notice

If a Party discovers a Security Incident involving Partner Customer Data that reasonably may require action by the other Party, the discovering Party will notify the other Party without unreasonable delay.

14.2Notice Content

To the extent reasonably available, the notice will describe:

  1. (a)the nature of the Security Incident;
  2. (b)the categories of Personal Information affected;
  3. (c)the approximate number of affected individuals, if known;
  4. (d)the corrective measures taken or planned; and
  5. (e)information reasonably necessary for the other Party to evaluate its legal obligations.

14.3Investigation and Mitigation

The Party responsible for the affected systems will promptly investigate and take reasonable steps to contain, mitigate, and remediate the Security Incident.

14.4Regulatory and Consumer Notices

Each Party is responsible for notifications legally required of that Party.

The Parties will reasonably coordinate notices where a Security Incident creates overlapping notification obligations.

Neither Party will identify the other Party as responsible for a Security Incident in a public notice, regulatory communication, or customer communication unless:

  1. (a)legally required;
  2. (b)factually accurate; or
  3. (c)approved by the other Party.

15.DATA RETENTION AND DELETION

15.1Retention

Each Party may retain Personal Information for as long as reasonably necessary and proportionate for its permitted purposes, subject to applicable Privacy Laws.

15.2Legitimate Retention

Nothing in this Schedule D requires deletion of Personal Information that a Party may lawfully retain for purposes including:

  1. (a)completing transactions;
  2. (b)accounting;
  3. (c)tax compliance;
  4. (d)fraud prevention;
  5. (e)security;
  6. (f)product recalls or safety matters;
  7. (g)warranty administration;
  8. (h)regulatory compliance;
  9. (i)dispute resolution;
  10. (j)establishment, exercise, or defense of legal claims; or
  11. (k)another legally permitted purpose.

15.3Termination

Termination of the Agreement does not automatically require either Party to delete all Personal Information previously lawfully collected or received.

Following termination, each Party may retain and process such information only to the extent permitted by applicable Privacy Laws, End Customer Choices, the Agreement, and this Schedule D.


16.SENSITIVE PERSONAL INFORMATION

Neither Party intends the standard Partner Customer Data to include sensitive categories of Personal Information beyond information reasonably necessary for the ordinary operation of the PLJ Program.

PLJ may restrict or exclude sensitive information from Partner Customer Data.

Partner will not request that PLJ provide sensitive Personal Information unless:

  1. (a)there is a legitimate Program-related need;
  2. (b)the Parties expressly agree to the transfer;
  3. (c)appropriate safeguards are implemented; and
  4. (d)the transfer and intended use comply with applicable Privacy Laws.

17.CHILDREN’S DATA

The PLJ Program is not intended to collect Personal Information directly from children for purposes of establishing a customer relationship with the child.

Neither Party will knowingly use Partner Customer Data in a manner that violates laws governing children’s or minors’ Personal Information.

If either Party becomes aware that information subject to heightened legal protections for children or minors has been improperly collected or disclosed through the Program, the Parties will reasonably cooperate to take appropriate corrective action.


18.CHANGES IN LAW

18.1Compliance Modifications

PLJ may modify data fields, transfer methods, technical controls, consumer-choice mechanisms, or other privacy-related Program operations when reasonably necessary to comply with changes in Privacy Laws.

18.2Material Contractual Changes

A material change to the Parties’ respective rights to use Partner Customer Data requires a written amendment to this Schedule D except where the change is required by applicable law or a legally effective End Customer Choice.

18.3Additional State Requirements

If a Privacy Law applicable to a particular End Customer, Partner, or transaction requires contractual terms not contained in this Schedule D, the Parties will reasonably cooperate to implement the required terms.


19.EFFECT OF CHARITABLE STATUS

Partner’s status as a nonprofit or charitable organization does not, by itself, expand or restrict the data rights granted under this Schedule D.

To the extent a Charitable Partner is subject to additional privacy, donor-information, fundraising, or confidentiality requirements, Partner is responsible for complying with requirements applicable to its independent use of Partner Customer Data.

Any Charitable Partner Addendum may impose additional data restrictions where required by applicable law.


20.CONFLICTS AND ORDER OF PRECEDENCE

20.1Privacy Matters

If this Schedule D conflicts with the Agreement concerning the collection, disclosure, permitted use, security, retention, deletion, or other processing of Personal Information, this Schedule D controls with respect to that privacy or data-sharing matter.

20.2Charitable Partner Addendum

If the Charitable Partner Addendum imposes a more specific requirement concerning donor or customer information in connection with a regulated charitable activity, the Charitable Partner Addendum controls with respect to that specific regulated activity.

20.3Applicable Law

Nothing in the Agreement or this Schedule D authorizes either Party to process Personal Information in a manner prohibited by applicable Privacy Laws.

Legal