Supplier Data Sharing Agreement

We've worked very hard and we are very proud to say that our in-house platform, procedures and standards are compliant with all current regulations in Europe, UK, and USA. Ongoing due diligence is something that is part of our operation

Roles and Nature of Processing

To the extent Bspec (the “Supplier”) processes personal data on the Client’s behalf in connection with our marketing services, the Client acts as the Controller and Supplier acts as a Processor/Service Provider. If Supplier provides business contact data sourced from third parties, Supplier may act as an independent controller of that Supplier Data prior to disclosure to the Client. Data processing is strictly limited to the use of Data to conduct marketing activities on behalf of the Client.

Subject Matter and Data Categories

Supplier may store public business information together with Personally Identifiable Information (PII) as required to conduct targeted marketing communications. Data categories shall strictly not include special categories such as racial or ethnic origin, political opinions, religious beliefs, genetic data, biometric data, or health-related data.

Lawful Basis for Processing

Supplier’s lawful basis in relation to the services offered is the legitimate interests of the supplier, specifically to operate, promote, and develop our business.

Security Measures and Confidentiality

Supplier maintains appropriate technological and organizational measures to protect personal data against unauthorized or unlawful processing, accidental loss, destruction, or damage. Supplier warrants that all individuals involved in processing the data are subject to a strict duty of confidence.

Subprocessors, Right to Audit and Intra-Group Transfers

Supplier may engage third-party subprocessors, as well as its own affiliated corporate entities, to provide the Services. The Client expressly authorizes Bspec INC to transfer personal data to its intra-group affiliates, specifically Bspec Group Limited (UK) and CNS DOOEL (North Macedonia), who act as authorized subprocessors for the purpose of campaign execution, platform management, and data enrichment.

Supplier will impose appropriate contractual obligations on all subprocessors (including intra-group entities) consistent with applicable data protection laws. Where these transfers involve the movement of data from the UK or EEA to a third country, Supplier warrants that it has executed the appropriate Standard Contractual Clauses (SCCs) or equivalent transfer mechanisms between its entities to legitimize and secure the transfer.

Regional Compliance (CAN-SPAM & CCPA)

Supplier strictly complies with the CAN-SPAM Act of 2003, including providing valid physical postal addresses, maintaining clear unsubscribe mechanisms, and honoring all opt-out requests promptly. Under applicable U.S. state privacy laws (including CCPA), Supplier acts as a service provider and will not sell or share personal information.

Updated: 10 August 2026