Privacy Policy

Effective Date: July 6, 2026

INTRODUCTION

DataCurve, Inc. ("DataCurve," "we," "our," or "us") is committed to enabling trusted digital relationships among Users, Participating Organizations, sponsors, brands, and other authorized participants through responsible identity management, transparent information practices, and privacy-conscious innovation.

This Privacy Policy explains how DataCurve receives, collects, uses, discloses, stores, retains, protects, and otherwise processes Personal Information in connection with the DataCurve Platform, including FanHub, FanGraph, AURA ID, Digital Credentials, Engagement Services, Rewards, AI Services, Digital Wallet functionality, Data Intelligence, and other Platform Services (collectively, the "Platform").

The Platform enables Participating Organizations to better understand, communicate with, recognize, reward, and engage their customers, fans, members, guests, supporters, and other authorized Users while providing Users with personalized experiences, Rewards, Digital Credentials, and other Platform capabilities.

Because the Platform supports interactions among multiple participants, DataCurve may receive Personal Information directly from Users, from Participating Organizations, from Authorized Data Sources, through User-directed interactions, or through information generated during operation of the Platform. Depending upon the circumstances, DataCurve may process Personal Information as a controller, processor, service provider, contractor, or in another capacity recognized under applicable law.

PRIVACY POLICY TERMS

1. Scope and Application.

This Privacy Policy is intended to describe those processing activities in a transparent, technology-neutral, and commercially reasonable manner while supporting compliance with applicable privacy and data protection laws.

Additional information regarding DataCurve's privacy principles is provided in Appendix A. Information regarding privacy requests and Data Subject Request procedures is provided in Appendix B.

1.1 Scope 

This Privacy Policy applies to Personal Information processed by DataCurve in connection with the Platform and all related products, services, websites, applications, software, APIs, SDKs, Digital Credentials, FanHub, FanGraph, AURA ID, Digital Wallet functionality, AI Services, Data Intelligence, Engagement Services, Rewards, communications, events, and other authorized Platform Services, unless a separate privacy notice expressly governs a particular product or service.

This Privacy Policy applies regardless of whether Personal Information is collected directly from a User, received from a Participating Organization or another Authorized Data Source, generated through Platform interactions, or otherwise processed in accordance with applicable law. This Privacy Policy applies to individuals who access or use the Platform, create an Account, receive an AURA ID, interact with Participating Organizations, participate in FanHub experiences, receive Digital Credentials, administer or use Digital Wallet functionality, participate in Rewards, communicate with DataCurve, or otherwise interact with the Platform.

Nothing in this Privacy Policy limits any rights that Users may have under applicable privacy or data protection laws.

1.2 Relationship to the Platform Terms of Service

This Privacy Policy is incorporated into and forms part of the DataCurve Platform Terms of Service. Unless otherwise expressly provided, capitalized terms used but not defined in this Privacy Policy have the meanings assigned in the Platform Terms of Service. In the event of a conflict between this Privacy Policy and a separate written agreement governing specific services between DataCurve and a Participating Organization, the applicable written agreement will control solely with respect to those services to the extent of the conflict.

Nothing in this Privacy Policy modifies any obligations established under an applicable Master Services Agreement, Data Processing Addendum, enterprise agreement, or other written agreement between DataCurve and a Participating Organization.

1.3 Privacy Philosophy

DataCurve believes that trusted digital relationships depend upon responsible information governance, meaningful transparency, appropriate User choice, and commercially reasonable privacy and security practices. The Platform has been designed to facilitate trusted interactions among Users, Participating Organizations, sponsors, brands, and other authorized participants while supporting personalized experiences, Rewards, Digital Credentials, audience engagement, AI Services, FanHub, FanGraph, and other Platform capabilities.

DataCurve seeks to process Personal Information responsibly and in accordance with applicable law while enabling Participating Organizations to better understand, communicate with, engage, recognize, and provide value to their customers and communities.

The Privacy Principles summarized in Appendix A reflect the governance philosophy that guides DataCurve's approach to privacy and information management.

1.4 Definitions

For purposes of this Privacy Policy, the following terms have the meanings set forth below:

"Account" means a User account established to access or use one or more Platform Services.

"AI Services" means artificial intelligence, machine learning, predictive analytics, recommendation engines, generative AI capabilities, automation services, and other intelligent technologies provided by or through the Platform.

"Authorized Data Sources" means Users, Participating Organizations, service providers, integration partners, public sources, and other persons or entities from whom DataCurve lawfully receives Personal Information or other information in connection with the Platform and applicable law.

"AURA ID" means DataCurve's persistent identity framework that enables Users to interact with the Platform and Participating Organizations across authorized Platform Services.

"Data Intelligence" means analytics, benchmarking, insights, audience intelligence, engagement metrics, predictive models, aggregated reporting, de-identified information, and other informational outputs generated by or through the Platform.

"Digital Credentials" means digital records, memberships, badges, tickets, certifications, permissions, entitlements, or other electronic credentials issued, administered, recognized, or supported through the Platform.

"Digital Wallet" means a Platform feature through which a User may store, manage, access, organize, or use Digital Credentials, Rewards, memberships, tickets, identity information, or other authorized Platform assets.

"Engagement Services" means the Platform capabilities that enable DataCurve and Participating Organizations to communicate with Users, administer Rewards, issue or manage Digital Credentials, facilitate loyalty programs, memberships, ticketing, promotions, personalized experiences, sponsorship activations, community engagement initiatives, recognition programs, and other authorized interactions through the Platform.

"FanGraph" means DataCurve's proprietary relationship and audience intelligence framework that organizes information, interactions, preferences, engagement history, Digital Credentials, and other authorized data to support Platform Services, personalization, analytics, Data Intelligence, and Engagement Services.

"FanHub" means DataCurve's engagement platform through which Participating Organizations may better understand, communicate with, recognize, reward, and engage Users through authorized Platform Services.

"FanZone" means DataCurve's unified identity solution, an AI-driven fan engagement platform that creates and activates personalized experiences for Users and as may be further described at https://datacurve.io/platform.

"Participating Organization" means any sports organization, league, team, venue, athlete, educational institution, nonprofit organization, sponsor, brand, promoter, event organizer, community organization, business, governmental entity, or other organization that utilizes or participates in the Platform pursuant to an agreement with DataCurve.

"Personal Information" means information that identifies, relates to, describes, is reasonably capable of being associated with, or could reasonably be linked, directly or indirectly, with an identified or identifiable individual, or that otherwise constitutes personal data, personal information, personally identifiable information, or similar information under applicable law.

"Platform" means the DataCurve technology platform and all related Platform Services, including AURA ID, FanHub, FanGraph, FanZone, Digital Credentials, Digital Wallet functionality, Engagement Services, Rewards, AI Services, Data Intelligence, websites, mobile applications, APIs, SDKs, software, communications, and related services made available by DataCurve.

"Platform Services" means all products, software, applications, features, services, technologies, APIs, SDKs, websites, mobile applications, communications, Digital Credentials, Engagement Services, Data Intelligence capabilities, AI Services, and other functionality provided by or through the Platform.

"Rewards" means loyalty benefits, promotional offers, discounts, incentives, memberships, tickets, hospitality opportunities, travel opportunities, digital assets, exclusive experiences, sponsor benefits, community engagement opportunities, charitable initiatives, recognition programs, and other benefits made available through the Platform by DataCurve, Participating Organizations, sponsors, brands, or other authorized parties.

"Sensitive Personal Information" means Personal Information that receives heightened protection under applicable privacy or data protection laws, including, where applicable, sensitive personal information, sensitive data, special categories of personal data, or similar categories recognized under applicable law.

"User" means an individual who accesses, uses, registers for, interacts with, or otherwise participates in the Platform, whether directly with DataCurve or through a Participating Organization.

1.5 Interpretation

Unless the context requires otherwise, references in this Privacy Policy to the singular include the plural, and references to the plural include the singular. Headings are included solely for convenience and shall not affect the interpretation of this Privacy Policy.

References to "including," "includes," or similar expressions mean "including without limitation."

References to applicable law include any amendments, successor legislation, implementing regulations, judicial interpretations, or substantially similar laws enacted after the Effective Date. Where this Privacy Policy refers to rights or obligations that depend upon applicable law, those rights and obligations shall apply only to the extent required by the laws governing the particular processing activity.

1.6 Relationship Among DataCurve Legal Documents

This Privacy Policy is one component of DataCurve's broader legal and information governance framework. Depending upon the circumstances, the processing of Personal Information may also be governed by one or more of the following:

(a) the Platform Terms of Service;

(b) a Master Services Agreement;

(c) a Data Processing Addendum;

(d) a Cookie Policy;

(e) API, SDK, or developer terms;

(f) service-specific privacy notices;

(g) enterprise agreements;

(h) event-specific terms and conditions; or

(i) other written agreements between DataCurve and a User or Participating Organization.

Where multiple documents apply, they should be interpreted together to the greatest extent possible. If an irreconcilable conflict exists, the more specific agreement governing the applicable service or processing activity will control to the extent of the conflict.

1.7 Technology-Neutral Interpretation

The Platform is designed to evolve as technology, business practices, and applicable law develop.

Accordingly, this Privacy Policy is intended to apply to current and future Platform Services that are substantially similar in function, even if those services are delivered through technologies, devices, communication channels, artificial intelligence capabilities, digital identity systems, or interaction models that do not exist on the Effective Date of this Privacy Policy. Nothing in this Privacy Policy shall be interpreted to limit DataCurve's ability to develop new Platform capabilities, provided that the collection, use, disclosure, and processing of Personal Information remain consistent with applicable law, this Privacy Policy, and any applicable contractual commitments.

 

2. Platform Privacy Framework.

This section describes how DataCurve governs Personal Information throughout the lifecycle of the Platform and explains DataCurve's privacy roles, Authorized Data Sources, information governance principles, and the manner in which Personal Information moves through AURA ID, FanHub, FanGraph, Engagement Services, Data Intelligence, and other Platform Services.

2.1 Overview

DataCurve has developed the Platform to enable trusted digital relationships among Users, Participating Organizations, sponsors, brands, service providers, and other authorized participants. The Platform facilitates identity management, audience engagement, Digital Credentials, Rewards, personalized experiences, Data Intelligence, and other Platform Services while supporting responsible information governance and compliance with applicable privacy and data protection laws.

Because the Platform supports a diverse ecosystem of participants and services, Personal Information may be collected, received, generated, disclosed, stored, or otherwise processed through multiple Platform components. The specific processing activities performed by DataCurve depend upon the nature of the Platform Service, the relationship between the parties, User choices, applicable contractual obligations, and applicable law.

This Part II describes the principles that govern DataCurve's processing of Personal Information throughout the Platform.

2.2 The DataCurve Platform Ecosystem

The Platform is designed to facilitate authorized interactions among multiple participants while maintaining appropriate privacy protections and information governance practices.

Depending upon the applicable Platform Service, the Platform may facilitate interactions among:

(a) Users;

(b) Participating Organizations;

(c) sponsors and brands;

(d) service providers;

(e) integration partners;

(f) technology providers;

(g) payment processors;

(h) identity verification providers;

(i) governmental entities where required by law; and

(j) other authorized participants.

Each participant may contribute information, receive information, or interact with the Platform in different capacities depending upon the applicable service, contractual relationship, and legal requirements.

2.3 Core Platform Components

The Platform consists of multiple integrated services that operate together to provide identity management, audience engagement, communications, personalization, and information governance.

These services include, without limitation:

(a) AURA ID, which provides a persistent digital identity framework for Users across authorized Platform Services;

(b) FanGraph, which organizes relationships, engagement history, audience intelligence, preferences, Digital Credentials, and other authorized information to support Platform functionality;

(c) FanHub, which enables Participating Organizations to communicate with, recognize, reward, and engage Users through authorized Platform Services;

(d) Engagement Services, (including FanZone) which facilitate fan interactions,Rewards, memberships, Digital Credentials, ticketing, promotions, personalized experiences, and other interactions between Users and Participating Organizations;

(e) Data Intelligence, which provides analytics, reporting, audience insights, benchmarking, sponsorship measurement, predictive analytics, and other informational outputs;

(f) AI Services, which support automation, personalization, recommendations, analytics, content generation, fraud prevention, customer support, operational efficiency, and other Platform capabilities; and

(g) additional Platform Services developed or introduced by DataCurve from time to time.

These Platform components operate together to create a trusted environment in which Users may receive value through personalized experiences while Participating Organizations may better understand and engage their audiences in accordance with applicable law.

2.4 Privacy Roles

DataCurve recognizes that different Platform Services involve different privacy roles and legal responsibilities. Accordingly, DataCurve may process Personal Information in one or more capacities depending upon the applicable processing activity.

These roles may include:

(a) controller;

(b) business;

(c) processor;

(d) service provider;

(e) contractor; or

(f) another legally recognized capacity under applicable privacy law.

The determination of DataCurve's role depends upon the specific processing activity, the contractual relationship between the parties, and applicable law, rather than any single provision of this Privacy Policy.

Nothing in this Privacy Policy is intended to modify the allocation of responsibilities established under a Master Services Agreement, Data Processing Addendum, enterprise agreement, or other applicable written agreement.

2.5 Authorized Data Sources

DataCurve receives, collects, generates, and otherwise processes Personal Information only through Authorized Data Sources and where a lawful basis exists under applicable law. Depending upon the circumstances, Authorized Data Sources may include:

(a) Users;

(b) Participating Organizations;

(c) service providers;

(d) integration partners;

(e) publicly available sources where permitted by law;

(f) information generated through Platform interactions;

(g) information derived from User-authorized integrations;

(h) information received from identity verification providers;

(i) information provided through Digital Credentials;

(j) information generated by AI Services; and

(k) other lawful sources consistent with this Privacy Policy and applicable law.

DataCurve does not knowingly obtain Personal Information from sources that it reasonably believes lack the legal authority to provide such information.

2.6 Lawful Collection and Processing

DataCurve collects and processes Personal Information only where it has a lawful basis to do so under applicable law. Depending upon the circumstances, that lawful basis may include:

(a) the performance of a contract with a User or Participating Organization;

(b) User consent;

(c) legitimate business interests;

(d) compliance with legal obligations;

(e) protection of vital interests;

(f) performance of a task carried out in the public interest where authorized by law; or

(g) another lawful basis recognized under applicable privacy or data protection laws.

The lawful basis applicable to a particular processing activity depends upon the nature of the Platform Service, the relationship among the parties, applicable contractual commitments, and the governing law. More than one lawful basis may apply to a particular processing activity.

2.7 Data Stewardship

DataCurve recognizes that Personal Information entrusted to the Platform may originate from multiple Authorized Data Sources and may be processed for multiple lawful purposes throughout the lifecycle of the Platform.

Accordingly, DataCurve seeks to process Personal Information in a manner that is transparent, proportionate, secure, and consistent with applicable law, this Privacy Policy, the Platform Terms of Service, and applicable contractual commitments.

DataCurve's approach to data stewardship is intended to promote responsible information governance while enabling Participating Organizations to better understand, communicate with, recognize, reward, and engage their customers, fans, members, guests, supporters, and other authorized Users.

Nothing in this Privacy Policy is intended to expand or diminish any legal rights or obligations established under applicable law or written agreements.

2.8 Progressive Identity

The Platform is designed to support an evolving relationship between Users and Participating Organizations. As Users continue to participate in Platform Services, they may elect to provide additional information, receive additional Digital Credentials, participate in loyalty programs, connect Digital Wallet functionality, engage with Participating Organizations, receive Rewards, or otherwise expand their participation in the Platform.

As a result, the information associated with a User's AURA ID and FanGraph may develop over time to support additional Platform functionality, personalization, Engagement Services, Data Intelligence, and other authorized Platform capabilities.

DataCurve seeks to ensure that such processing remains consistent with applicable law, User choices, applicable contractual commitments, and this Privacy Policy.

2.9 Privacy by Design

DataCurve seeks to incorporate privacy considerations throughout the design, development, implementation, operation, and enhancement of the Platform. When introducing new Platform Services or materially modifying existing Platform functionality, DataCurve may consider, as appropriate:

(a) the categories of Personal Information involved;

(b) the purposes of processing;

(c) reasonably foreseeable privacy risks;

(d) the availability of appropriate technical, administrative, physical, and organizational safeguards;

(e) User expectations and available choices;

(f) contractual obligations;

(g) applicable legal and regulatory requirements; and

(h) the overall objectives of responsible information governance.

Privacy by Design is an ongoing operational objective rather than a guarantee regarding any specific Platform feature or technology.

2.10 Responsible Artificial Intelligence

Artificial intelligence is an important component of the Platform and may be used to support personalization, recommendations, analytics, automation, fraud prevention, operational efficiency, customer support, Data Intelligence, and other Platform Services. DataCurve seeks to develop and deploy AI Services responsibly by considering, where appropriate:

(a) transparency;

(b) privacy;

(c) security;

(d) fairness;

(e) appropriate human oversight;

(f) monitoring and continuous improvement;

(g) data quality;

(h) lawful processing; and

(i) applicable legal and regulatory requirements.

Unless otherwise expressly stated, AI-generated outputs are intended to assist Platform functionality and should not be interpreted as guarantees, professional advice, or the sole basis for decisions producing legal or similarly significant effects concerning an individual.

2.11 Information Governance Principles

The Platform is supported by an information governance program intended to promote responsible management of Personal Information throughout its lifecycle. DataCurve seeks to implement governance practices that support:

(a) accountability;

(b) transparency;

(c) data minimization;

(d) purpose limitation;

(e) appropriate access controls;

(f) security;

(g) responsible vendor management;

(h) lawful disclosures;

(i) continuous improvement; and

(j) compliance with applicable privacy and data protection laws.

Additional information regarding DataCurve's information governance philosophy is summarized in Appendix A.

2.12 User Choice and Control

DataCurve recognizes that meaningful privacy depends upon providing Users with appropriate information and choices regarding the processing of their Personal Information. Depending upon the applicable Platform Service and governing law, Users may be able to:

(a) access or update certain Account information;

(b) manage communication preferences;

(c) manage certain privacy settings;

(d) connect or disconnect authorized integrations;

(e) manage Digital Wallet functionality;

(f) participate in or discontinue certain Engagement Services;

(g) manage preferences relating to Rewards;

(h) exercise privacy rights under applicable law; and

(i) otherwise manage aspects of their participation in the Platform.

The availability of particular choices may depend upon the applicable Platform Service, the User's relationship with a Participating Organization, technical capabilities, contractual commitments, and applicable law.

2.13 Relationship with Participating Organizations

Participating Organizations play an important role within the Platform ecosystem. Depending upon the applicable Platform Service, Participating Organizations may provide information to DataCurve, receive information from DataCurve, communicate with Users, administer memberships, issue Digital Credentials, provide Rewards, facilitate events, administer loyalty programs, conduct sponsorship activations, and otherwise engage Users through the Platform.

Each Participating Organization remains responsible for its own privacy practices, notices, and legal obligations with respect to Personal Information that it controls. Where DataCurve processes Personal Information on behalf of a Participating Organization, the parties' respective responsibilities are governed by the applicable agreement and applicable law.

 

3. Personal Information We Collect

3.1 Overview

Because the Platform provides numerous Platform Services that may be used independently or together, the categories of Personal Information collected from a particular User will vary depending upon the Platform features utilized, the User's interactions with Participating Organizations, the User's choices, applicable contractual relationships, and applicable law. This part of this Privacy Policy describes the categories of Personal Information that DataCurve may collect, receive, generate, or otherwise process in connection with the Platform. We explain in greater detail the categories of Personal Information processed by DataCurve, the purposes for which such information is processed, the circumstances in which it may be disclosed, the rights available to Users, and the governance practices that support responsible information management throughout the Platform.

DataCurve may receive, collect, generate, infer, or otherwise process Personal Information from multiple Authorized Data Sources in connection with the operation of the Platform and the provision of Platform Services. The categories of Personal Information processed by DataCurve depend upon numerous factors, including:

(a) the Platform Services utilized;

(b) the User's relationship with one or more Participating Organizations;

(c) the User's interactions with the Platform;

(d) User preferences and choices;

(e) Digital Credentials issued or managed through the Platform;

(f) Rewards selected or redeemed;

(g) integrations authorized by the User or a Participating Organization;

(h) applicable contractual relationships; and

(i) applicable law.

Not every User provides every category of Personal Information described in this Privacy Policy, and DataCurve does not necessarily process every category of information for every Platform Service.

3.2 Information Provided Directly by Users

Users may provide Personal Information directly to DataCurve when creating an Account, establishing or managing an AURA ID, participating in FanZone, managing a Digital Wallet, redeeming Rewards, communicating with DataCurve, participating in surveys or promotions, attending events, or otherwise interacting with the Platform. Depending upon the applicable Platform Service, this information may include:

(a) name;

(b) username;

(c) email address;

(d) telephone number;

(e) mailing address;

(f) date of birth;

(g) profile photograph or avatar;

(h) communication preferences;

(i) account credentials;

(j) Digital Wallet information;

(k) payment-related information where applicable;

(l) identity verification information;

(m) preferences and interests;

(n) accessibility preferences;

(o) marketing preferences; and

(p) any other information voluntarily submitted by the User.

3.3 Information Received from Participating Organizations

Participating Organizations may also provide Personal Information to DataCurve where they have the legal authority to do so, including where Users have provided the required consent or another lawful basis for such disclosure exists. Depending upon the applicable Platform Service, Participating Organizations may provide:

(a) membership information;

(b) season ticket or ticketing information;

(c) event attendance information;

(d) loyalty program information;

(e) purchase history;

(f) concession, merchandise, hospitality, or retail transaction information;

(g) sponsorship participation information;

(h) community engagement information;

(i) payment information;

(j) Digital Credentials;

(k) demographic information;

(l) communications history;

(m) marketing preferences;

(n) customer relationship information, including Personal Information; and

(o) other information reasonably related or necessary to support their business.

DataCurve processes such information only in accordance with applicable law, this Privacy Policy, and applicable agreements with the Participating Organization.

3.4 Information Generated Through Platform Activity

As Users interact with the Platform, DataCurve may generate additional information relating to the operation of Platform Services. This information may include:

(a) Account activity;

(b) authentication events;

(c) Digital Credential usage;

(d) Digital Wallet activity;

(e) Rewards activity;

(f) FanHub participation;

(g) FanGraph relationship information;

(h) User interaction information from FanZone;

(i) Platform preferences;

(j) communication history;

(k) engagement metrics;

(l) feature utilization;

(m) session information;

(n) transaction history;

(o) support interactions; and

(p) other operational information generated through Platform use.

3.5 Device and Technical Information

DataCurve may receive or collect technical information relating to the devices and systems used to access the Platform. Such information may include:

(a) IP address;

(b) browser type;

(c) operating system;

(d) device identifiers;

(e) application version;

(f) network information;

(g) language preferences;

(h) referring URLs;

(i) log information;

(j) timestamps;

(k) session identifiers;

(l) diagnostic information; and

(m) other information reasonably necessary to support Platform functionality, security, and performance.

Technical information may be collected through cookies, SDKs, APIs, pixels, log files, and other Tracking Technologies as described in Section 9.

3.6 Location Information

Where permitted by applicable law and consistent with User settings, DataCurve may process location-related information to support Platform functionality. Depending upon the Platform Service, location information may include:

(a) approximate location derived from an IP address or generally determined from a User’s interaction with the Platform and Platform Services;

(b) city, state, or country;

(c) event venue location;

(d) location selected by a User;

(e) travel-related information associated with Platform experiences; and

(f) precise geolocation only where expressly authorized by the User or otherwise permitted by applicable law.

Location information may be used to provide localized Platform Services, facilitate event participation, improve personalization, administer Rewards, and support Participating Organization engagement activities.

3.7 Information from Third-Party Integrations

Where authorized by a User or Participating Organization, DataCurve may receive information from integrated third-party services to enhance Platform functionality and improve the User experience. Such integrations may include identity verification providers, payment processors, ticketing systems, loyalty platforms, communications providers, travel or hospitality partners, social media integrations, analytics services, technology providers or other authorized service and commercial partners.

DataCurve processes information received through such integrations in accordance with applicable law, the applicable integration, this Privacy Policy, and any relevant contractual commitments.

3.8 Sensitive Personal Information

DataCurve may process Sensitive Personal Information only where reasonably necessary to provide Platform Services, comply with applicable law, protect the security and integrity of the Platform, or where another lawful basis exists. Depending upon the applicable Platform Service and User interactions, Sensitive Personal Information may include:

(a) government-issued identification information used for identity verification;

(b) financial account or payment information processed in connection with authorized transactions;

(c) account authentication credentials;

(d) precise geolocation information where expressly authorized by the User;

(e) information relating to accessibility accommodations or similar preferences voluntarily provided by a User;

(f) biometric information or biometric identifiers only where expressly disclosed, lawfully collected, and permitted by applicable law; and

(g) other categories of Sensitive Personal Information recognized under applicable privacy or data protection laws.

DataCurve does not process Sensitive Personal Information for purposes incompatible with this Privacy Policy or applicable law and seeks to limit such processing to what is reasonably necessary for the applicable Platform Service.

3.9 Information Generated Through AI Services

The Platform may generate or derive information through AI Services to support Platform functionality and improve User experiences. Depending upon the applicable Platform Service, AI-generated information may include:

(a) recommendations;

(b) personalization insights;

(c) audience segmentation;

(d) engagement predictions;

(e) customer support responses;

(f) content suggestions;

(g) operational analytics;

(h) fraud detection indicators;

(i) security monitoring information; and

(j) other analytical outputs designed to improve Platform functionality.

Unless expressly stated otherwise, AI-generated information is intended to support Platform operations and does not replace human judgment where such review is appropriate or required by applicable law.

3.10 Inferred Information

DataCurve may generate inferences from Personal Information and Platform interactions to enhance Platform Services and improve User experiences. Examples of inferred information may include:

(a) communication preferences;

(b) interests;

(c) participation patterns;

(d) engagement trends;

(e) loyalty indicators;

(f) content preferences;

(g) event interests;

(h) sponsorship engagement;

(i) audience segmentation; and

(j) other insights reasonably related to the operation of the Platform.

DataCurve seeks to ensure that inferred information is used in a manner consistent with applicable law, User choices, and the purposes described in this Privacy Policy.

3.11 FanGraph Information

FanGraph is DataCurve's proprietary audience intelligence framework designed to organize authorized relationships, interactions, engagement history, preferences, Digital Credentials, Rewards, and other information necessary to support Platform Services. Information associated with FanGraph may include:

(a) User identity attributes;

(b) relationships with Participating Organizations;

(c) event participation;

(d) loyalty and membership activity;

(e) communications history;

(f) Digital Credentials;

(g) Rewards participation;

(h) engagement history;

(i) personalization preferences;

(j) audience insights; and

(k) other information reasonably necessary to support authorized Platform functionality.

FanGraph is intended to enhance Platform Services by helping DataCurve and Participating Organizations deliver more relevant communications, experiences, engagement opportunities, and Data Intelligence while respecting applicable legal requirements and User privacy choices.

3.12 AURA ID Information

AURA ID serves as the Platform's persistent identity framework and may be associated with information reasonably necessary to authenticate Users, administer Platform Services, maintain Digital Credentials, facilitate Engagement Services, and support authorized interactions across the Platform.

The information associated with an AURA ID may expand over time as a User elects to participate in additional Platform Services, receive Digital Credentials, manage Digital Wallet functionality, participate in Rewards, or interact with additional Participating Organizations.

DataCurve seeks to ensure that the information associated with an AURA ID is processed consistently with this Privacy Policy, applicable agreements, and applicable law.

3.13 Data Intelligence

DataCurve may generate Data Intelligence through the analysis of Platform activity, User interactions, audience engagement, operational metrics, and other authorized information. Data Intelligence may include:

(a) aggregated analytics;

(b) benchmarking;

(c) audience trends;

(d) engagement metrics;

(e) sponsorship measurement;

(f) campaign performance;

(g) predictive analytics;

(h) operational reporting;

(i) de-identified insights; and

(j) other analytical outputs that assist DataCurve and Participating Organizations in understanding audience behavior and improving Platform Services.

Where appropriate, DataCurve seeks to use de-identified or aggregated information when generating Data Intelligence intended for broader analytical purposes.

3.14 De-Identified and Aggregated Information

DataCurve may create, use, disclose, license, and otherwise process information that has been de-identified, aggregated, anonymized, or otherwise processed so that it is not reasonably capable of identifying an individual, where permitted by applicable law. Such information may be used for purposes including:

(a) Platform Services and improvement;

(b) product development;

(c) research;

(d) analytics;

(e) benchmarking;

(f) sponsorship measurement;

(g) operational reporting;

(h) security;

(i) artificial intelligence development;

(j) Data Intelligence; and

(k) other lawful business purposes.

Where information has been de-identified in accordance with applicable law, DataCurve is not obligated to attempt to re-identify individuals except as required by law.

3.15 Information We Do Not Intentionally Collect

Except where specifically required to provide a Platform Service or otherwise permitted by applicable law, DataCurve does not intentionally request or require Users to provide Personal Information that is unnecessary for the operation of the Platform.

Users should not submit Sensitive Personal Information or other confidential information that is not requested or reasonably necessary for the applicable Platform Service.

If DataCurve determines that unnecessary Personal Information has been submitted, DataCurve may delete or otherwise manage such information in accordance with applicable law, this Privacy Policy, and applicable operational requirements.

 

4. Processing of Personal Information

This section explains the purposes for which DataCurve processes Personal Information, the applicable lawful bases under relevant privacy laws, the categories of recipients, and the relationship between those processing activities and the Platform Services provided to Users and Participating Organizations.

4.1 Overview

DataCurve processes Personal Information only for lawful, specified, and legitimate purposes that are compatible with the operation of the Platform, the services requested by Users and Participating Organizations, applicable contractual commitments, and applicable law.

The purposes described in this section explain the principal ways in which DataCurve processes Personal Information. Depending upon the Platform Service utilized, a particular processing activity may involve one or more categories of Personal Information, more than one lawful basis under applicable law, and one or more categories of authorized recipients.

Not every processing activity applies to every User, Participating Organization, or Platform Service.

4.2 Account Administration and Identity Management

Purpose. DataCurve may process Personal Information to establish, administer, maintain, secure, and support Platform Accounts, AURA IDs, Digital Wallet functionality, and related identity management services.

Categories of Personal Information. Depending upon the applicable Platform Service, this processing may involve Account information, contact information, authentication credentials, identity verification information, Digital Credentials, Digital Wallet information, communication preferences, and related operational information.

Lawful Basis. Performance of a contract, legitimate interests, legal obligations, User consent where required, or another lawful basis recognized under applicable law.

Typical Recipients. DataCurve personnel with a legitimate business need to know, identity verification providers, authentication providers, cloud hosting providers, security service providers, and other authorized service providers.

4.3 Delivery of Platform Services

Purpose. DataCurve processes Personal Information to provide, operate, maintain, enhance, and support the Platform and Platform Services requested by Users or Participating Organizations.

This includes the operation of FanHub, FanGraph, Engagement Services, Digital Credentials, Rewards, AI Services, Digital Wallet functionality, Data Intelligence, APIs, mobile applications, websites, communications, and related Platform capabilities.

Categories of Personal Information. Any category of Personal Information reasonably necessary to provide the requested Platform Service.

Lawful Basis. Performance of a contract, legitimate interests, User consent where required, and other lawful bases recognized under applicable law.

Typical Recipients. Authorized DataCurve personnel, Participating Organizations, service providers, cloud providers, communications providers, and other authorized technology partners.

4.4 Communications

Purpose. DataCurve processes Personal Information to communicate with Users regarding Platform Services, Account administration, Digital Credentials, Rewards, customer support, security notices, legal notices, service updates, surveys, educational materials, promotional communications, and other authorized communications. Where required by applicable law, marketing communications are provided only with the User's consent or another lawful basis.

Users may manage certain communication preferences through available Platform settings or by following applicable unsubscribe or preference-management instructions.

4.5 FanHub and Engagement Services

Purpose. DataCurve processes Personal Information to facilitate communications and engagement between Users and Participating Organizations through FanHub and related Engagement Services.

Processing activities may include administering memberships, loyalty programs, Digital Credentials, personalized experiences, event participation, sponsorship activations, community engagement initiatives, recognition programs, and Rewards.

DataCurve seeks to ensure that such processing is conducted in accordance with User choices, applicable agreements, and applicable law.

4.6 Rewards

Purpose. DataCurve may process Personal Information to administer, personalize, issue, validate, manage, fulfill, and improve Rewards made available through the Platform.

Rewards may be provided by DataCurve, Participating Organizations, sponsors, brands, or other authorized parties.

Processing may include eligibility determination, redemption management, fraud prevention, communications, reporting, and operational support reasonably necessary to administer the applicable program.

Participation in certain Rewards programs may require the processing of Personal Information necessary to administer those programs.

4.7 Digital Credentials and Digital Wallet

Purpose. DataCurve may process Personal Information to issue, validate, administer, manage, display, and support Digital Credentials and Digital Wallet functionality.

Digital Credentials may include memberships, tickets, badges, certifications, entitlements, permissions, access rights, recognition programs, or other electronic credentials supported by the Platform.

Digital Wallet functionality allows Users to organize, access, and manage Digital Credentials and related Platform assets.

Processing is limited to that necessary to support authorized Platform functionality and applicable contractual commitments.

4.8 Data Intelligence and Analytics

Purpose. DataCurve processes Personal Information to generate Data Intelligence that assists in understanding audience engagement, improving Platform Services, measuring program effectiveness, evaluating sponsorship performance, enhancing User experiences, and supporting Participating Organizations.

Data Intelligence may include aggregated analytics, audience trends, engagement metrics, benchmarking, campaign measurement, predictive analytics, operational reporting, and other analytical insights.

Where appropriate, DataCurve seeks to generate Data Intelligence using de-identified or aggregated information rather than information that directly identifies individual Users.

DataCurve does not use Data Intelligence to identify individual Users except where necessary to provide Platform Services, comply with applicable law, protect Platform security, or otherwise as described in this Privacy Policy.

Lawful Basis. Legitimate interests, performance of a contract, User consent where required, or another lawful basis recognized under applicable law.

Typical Recipients. DataCurve, Participating Organizations, authorized analytics providers, and other authorized recipients consistent with this Privacy Policy.

4.10 Artificial Intelligence and Personalization

Purpose. DataCurve may use AI Services to improve Platform functionality, personalize User experiences, automate operational processes, enhance customer support, recommend content, facilitate communications, improve Rewards, assist Participating Organizations, and develop new Platform capabilities.

AI Services may analyze Platform interactions, FanZone engagement history, FanGraph information, AURA ID information, Digital Credentials, preferences, and other authorized information to improve Platform performance and provide more relevant experiences.

Where appropriate, DataCurve seeks to incorporate human oversight into AI-supported processes and periodically evaluates AI Services to improve quality, reliability, transparency, and compliance with applicable law.

Unless expressly stated otherwise, AI-generated outputs are intended to assist Platform functionality and should not be interpreted as legal, financial, medical, or other professional advice.

4.11 Platform Improvement and Product Development

Purpose. DataCurve may process Personal Information to improve existing Platform Services and develop new products, technologies, features, integrations, Digital Credentials, Engagement Services, AI capabilities, FanHub functionality, FanGraph capabilities, Data Intelligence, and related Platform offerings. Processing activities may include:

(a) evaluating Platform performance;

(b) identifying operational improvements;

(c) testing new functionality;

(d) developing analytics models;

(e) improving personalization;

(f) measuring User engagement;

(g) evaluating Platform reliability;

(h) conducting research and development; and

(i) improving the overall User experience.

Where practicable, DataCurve will use aggregated or de-identified information for product development activities.

4.12 Security, Fraud Prevention, and Platform Integrity

Purpose. DataCurve may process Personal Information to maintain the confidentiality, integrity, availability, and security of the Platform. Processing activities may include:

(a) authenticating Users;

(b) protecting Accounts;

(c) detecting unauthorized access;

(d) monitoring Platform security;

(e) preventing fraud;

(f) preventing abuse;

(g) investigating suspected misconduct;

(h) enforcing Platform policies;

(i) protecting Participating Organizations and Users; and

(j) maintaining the operational integrity of the Platform.

These processing activities are intended to protect both individual Users and the broader Platform ecosystem.

4.13 Legal Compliance and Protection of Rights

Purpose. DataCurve processes Personal Information where reasonably necessary to:

(a) comply with applicable law;

(b) respond to lawful governmental requests;

(c) comply with judicial proceedings;

(d) satisfy regulatory obligations;

(e) protect legal rights;

(f) enforce agreements;

(g) resolve disputes;

(h) establish, exercise, or defend legal claims;

(i) protect public safety; and

(j) otherwise fulfill legal obligations.

DataCurve seeks to disclose only the information necessary under the circumstances and, where appropriate, may object to requests that it believes are unlawful or overly broad.

4.14 Lawful Basis Summary

Where applicable privacy laws require a lawful basis for processing Personal Information, DataCurve relies upon one or more of the following, depending upon the particular processing activity:

(a) performance of a contract;

(b) User consent;

(c) legitimate interests;

(d) compliance with legal obligations;

(e) protection of vital interests;

(f) performance of tasks carried out in the public interest where authorized by law; or

(g) another lawful basis recognized under applicable law.

The specific lawful basis applicable to a processing activity depends upon the nature of the Platform Service, the relationship among the parties, User choices, contractual commitments, and applicable law. More than one lawful basis may apply to a particular processing activity.

4.15 Processing on Behalf of Participating Organizations

In certain circumstances, DataCurve processes Personal Information on behalf of Participating Organizations pursuant to applicable agreements.

Where DataCurve acts solely as a processor, service provider, or contractor under applicable law, DataCurve processes Personal Information only in accordance with documented instructions from the applicable Participating Organization, subject to applicable law and contractual commitments.

Nothing in this Privacy Policy modifies the allocation of controller, processor, business, service provider, contractor, or similar responsibilities established by applicable agreements.

 

5. Disclosure of Personal Information

This section explains the circumstances under which DataCurve may disclose Personal Information, the categories of recipients, the safeguards applicable to such disclosures, and the principles governing responsible information sharing throughout the Platform ecosystem.

5.1 Overview

DataCurve may disclose Personal Information to authorized recipients only where such disclosure is reasonably necessary to provide Platform Services, fulfill User requests, support Participating Organizations, administer Engagement Services, comply with applicable law, protect the Platform, or otherwise further a lawful purpose described in this Privacy Policy. Each disclosure is intended to be consistent with the applicable Platform Service, User choices, contractual commitments, applicable law, and DataCurve's information governance program.

Depending upon the circumstances, DataCurve may disclose Personal Information as a controller, processor, service provider, contractor, or in another legally recognized capacity.

5.2 Disclosures to Participating Organizations

The Platform is designed to facilitate trusted interactions between Users and Participating Organizations. Accordingly, DataCurve may disclose Personal Information to a Participating Organization where necessary to:

(a) provide requested Platform Services;

(b) administer memberships;

(c) issue or manage Digital Credentials;

(d) facilitate FanHub activities;

(e) administer Engagement Services;

(f) provide Rewards;

(g) support ticketing, hospitality, travel, or event-related services;

(h) facilitate customer support;

(i) measure audience engagement;

(j) administer loyalty or recognition programs; or

(k) otherwise fulfill the purposes for which the information was collected.

DataCurve seeks to disclose only the Personal Information necessary to support the applicable Platform Service. Participating Organizations remain independently responsible for their own processing of Personal Information that they control, including compliance with applicable privacy and data protection laws.

5.3 Information Received from Participating Organizations

Participating Organizations may disclose Personal Information to DataCurve where they have the legal authority to do so, including where they have obtained the required consent from Users or where another lawful basis exists under applicable law.

DataCurve processes such information only for the purposes authorized by applicable agreements, this Privacy Policy, User choices, and applicable law. Where DataCurve processes Personal Information solely on behalf of a Participating Organization, the applicable agreement between the parties governs the allocation of privacy responsibilities.

5.4 Service Providers and Contractors

DataCurve may disclose Personal Information to service providers, contractors, subprocessors, and other technology providers that perform services on DataCurve's behalf. These services may include:

(a) infrastructure services;

(b) authentication services;

(c) payment processing;

(d) customer support;

(e) analytics;

(f) fraud prevention;

(g) cybersecurity;

(h) software development;

(i) data storage;

(j) disaster recovery; and

(k) other operational services supporting the Platform.

DataCurve will require such providers to process Personal Information only for authorized purposes and in accordance with applicable contractual obligations.

5.5 Sponsors, Brands, and Promotional Programs

Certain Platform Services enable Users to participate in sponsorship activations, promotional campaigns, community initiatives, loyalty programs, contests, sweepstakes, charitable activities, or similar Engagement Services sponsored or supported by Participating Organizations, sponsors, or brands.

Where a User voluntarily participates in such activities, DataCurve may disclose Personal Information necessary to administer the applicable program, verify eligibility, provide Rewards, communicate with participating Users, measure campaign effectiveness, and otherwise fulfill the purposes of the program.

Where required by applicable law, DataCurve will obtain User consent before making disclosures that require consent.

5.6 User-Directed Disclosures

The Platform includes features that allow Users to voluntarily disclose or direct DataCurve to disclose Personal Information to Participating Organizations or other authorized recipients. Examples include:

(a) registering for events;

(b) redeeming Rewards;

(c) connecting Digital Wallet functionality;

(d) claiming Digital Credentials;

(e) participating in FanHub and FanZone activities;

(f) authorizing third-party integrations;

(g) sharing profile information;

(h) responding to promotions; or

(i) otherwise directing DataCurve to facilitate an interaction through the Platform.

DataCurve processes such disclosures in accordance with the User's instructions, the applicable Platform Service, and applicable law.

5.7 Analytics and Data Intelligence

DataCurve may disclose Data Intelligence, analytics, benchmarking information, audience insights, and similar informational outputs to Participating Organizations and other authorized recipients to support Platform Services, sponsorship measurement, audience engagement, operational planning, product improvement, and related business purposes.

Where practicable and consistent with the intended purpose, DataCurve seeks to provide such information in aggregated or de-identified form.

Where individualized Personal Information is necessary to provide a requested Platform Service or fulfill a contractual obligation, DataCurve may disclose such information in accordance with this Privacy Policy, applicable agreements, and applicable law.

5.9 Legal Compliance and Protection of Rights

DataCurve may disclose Personal Information where DataCurve reasonably believes such disclosure is necessary to:

(a) comply with applicable law;

(b) comply with a subpoena, court order, warrant, or other lawful legal process;

(c) respond to requests from governmental authorities or regulatory agencies;

(d) enforce the Platform Terms of Service, this Privacy Policy, or other applicable agreements;

(e) investigate suspected violations of law or contractual obligations;

(f) detect, prevent, or respond to fraud, abuse, cybersecurity incidents, or other unlawful activities;

(g) establish, exercise, or defend legal claims;

(h) protect the rights, property, safety, or security of DataCurve, Users, Participating Organizations, or other persons; or

(i) otherwise protect the integrity of the Platform.

Where appropriate and legally permissible, DataCurve may object to requests that it reasonably believes are unlawful, overly broad, or inconsistent with applicable legal protections.

5.10 Publicly Available Information

The Platform may permit Users to make certain information publicly available through profile settings, community features, event participation, recognition programs, or other Engagement Services.

Information that a User intentionally elects to make publicly available may be viewed, accessed, copied, or used by other Users, Participating Organizations, sponsors, brands, or members of the public.

Users remain responsible for the information they voluntarily choose to make publicly available through the Platform.

5.11 De-Identified and Aggregated Information

DataCurve may create, use, disclose, license, and otherwise process information that has been de-identified, anonymized, aggregated, or otherwise processed so that it is not reasonably capable of identifying an individual, where permitted by applicable law.

Such information may be used to:

(a) improve Platform Services;

(b) support Data Intelligence;

(c) develop analytics;

(d) measure audience engagement;

(e) evaluate sponsorship effectiveness;

(f) conduct research;

(g) improve artificial intelligence models;

(h) enhance Platform security;

(i) develop new products and services; and

(j) support other lawful business purposes.

DataCurve does not attempt to re-identify de-identified information except where required or permitted by applicable law, necessary to validate de-identification methodologies, protect Platform security, investigate fraud, or comply with legal obligations.

5.12 Cross-Border Disclosures

Personal Information may be disclosed to authorized recipients located in jurisdictions outside the country in which the information was originally collected.

Where applicable law restricts international disclosures, DataCurve seeks to implement appropriate safeguards, including contractual protections, recognized transfer mechanisms, technical safeguards, or other measures described in Section 7 of this Privacy Policy.

5.13 No Sale of Personal Information in the Ordinary Sense

While DataCurve may receive or process Personal Information as described in this Section 5, DataCurve is not in the business of selling Personal Information in a commercial sense.

5.14 Disclosure Safeguards

Before disclosing Personal Information, DataCurve will, where appropriate, consider:

(a) the purpose of the disclosure;

(b) the lawful basis for the disclosure;

(c) the categories of Personal Information involved;

(d) the identity and role of the recipient;

(e) applicable contractual commitments;

(f) applicable privacy laws;

(g) confidentiality obligations;

(h) appropriate security measures; and

(i) whether de-identified or aggregated information could reasonably satisfy the intended purpose.

DataCurve seeks to disclose only the Personal Information necessary for the applicable purpose.

 

6. Privacy and Information Governance

This section explains the governance practices, organizational controls, privacy management program, and accountability measures that DataCurve has established to support responsible information stewardship throughout the Platform.

6.1 Overview

DataCurve maintains a privacy and information governance program designed to promote the responsible collection, use, disclosure, retention, protection, and disposal of Personal Information throughout the lifecycle of the Platform.

The governance program is intended to support compliance with applicable privacy and data protection laws while enabling the Platform to provide identity management, FanHub, FanGraph, FanZone, Digital Credentials, Engagement Services, Rewards, AI Services, Data Intelligence, and other Platform Services.

DataCurve periodically reviews and enhances its governance practices as technology, regulatory requirements, business operations, and industry standards evolve.

6.2 Governance Principles

DataCurve's governance program is guided by principles that include:

(a) accountability;

(b) transparency;

(c) lawfulness;

(d) fairness;

(e) purpose limitation;

(f) data minimization;

(g) accuracy;

(h) integrity and confidentiality;

(i) responsible innovation; and

(j) continuous improvement.

These principles are summarized in Appendix A and are reflected throughout this Privacy Policy.

6.3 Privacy by Design

DataCurve seeks to incorporate privacy considerations throughout the planning, design, development, deployment, operation, and enhancement of Platform Services.

When introducing new products or materially modifying existing Platform functionality, DataCurve may evaluate, where appropriate:

(a) the categories of Personal Information involved;

(b) the purposes of processing;

(c) available User controls;

(d) security requirements;

(e) applicable contractual obligations;

(f) regulatory requirements;

(g) reasonably foreseeable privacy risks; and

(h) available technical and organizational safeguards.

Privacy by Design is an ongoing governance objective rather than a guarantee regarding any particular technology or Platform feature.

6.4 Information Lifecycle Management

DataCurve seeks to manage Personal Information throughout its lifecycle in accordance with applicable law, contractual commitments, operational requirements, and this Privacy Policy.

Information lifecycle management may include:

(a) collection;

(b) validation;

(c) storage;

(d) authorized use;

(e) disclosure;

(f) retention;

(g) archival;

(h) de-identification;

(i) deletion; and

(j) secure disposal.

Retention and deletion practices are described in greater detail in Section 11.

6.5 Access Management

DataCurve seeks to limit access to Personal Information to personnel, contractors, and authorized service providers who require access to perform authorized business functions.

Access controls may include:

(a) role-based access;

(b) authentication mechanisms;

(c) authorization controls;

(d) logging and monitoring;

(e) periodic access reviews; and

(f) other administrative, technical, and organizational safeguards appropriate to the applicable Platform Service.

Access privileges will be modified or revoked when no longer required.

6.6 Workforce Responsibilities

Personnel who have authorized access to Personal Information are expected to comply with applicable confidentiality obligations, information security requirements, internal governance practices, and applicable law. DataCurve will provide privacy, information security, and compliance training appropriate to the responsibilities of personnel who process Personal Information.

6.7 Vendor Governance

DataCurve may engage service providers, contractors, subprocessors, and technology partners that support Platform Services. Where appropriate, DataCurve seeks to evaluate such providers based upon factors including:

(a) information security practices;

(b) privacy capabilities;

(c) operational reliability;

(d) regulatory compliance;

(e) contractual commitments;

(f) technical capabilities; and

(g) the nature of the services provided.

DataCurve seeks to require vendors that process Personal Information on its behalf to process such information only for authorized purposes and in accordance with applicable contractual obligations.

6.8 Security Governance

DataCurve maintains an information security program designed to protect the confidentiality, integrity, and availability of Personal Information and Platform Services. Depending upon the applicable Platform Service, security measures may include:

(a) administrative safeguards;

(b) technical safeguards;

(c) physical safeguards;

(d) encryption technologies;

(e) authentication controls;

(f) monitoring and logging;

(g) vulnerability management;

(h) incident response procedures;

(i) disaster recovery planning; and

(j) business continuity planning.

Additional information regarding security practices is provided in Section 10.

6.9 AI Governance

DataCurve recognizes that AI Services require ongoing governance to promote responsible use and maintain User trust.

Accordingly, DataCurve seeks to implement governance practices that support:

(a) transparency;

(b) appropriate human oversight;

(c) lawful processing;

(d) data quality;

(e) security;

(f) monitoring;

(g) continuous improvement;

(h) accountability; and

(i) compliance with applicable law.

DataCurve periodically evaluates AI Services as technology and regulatory expectations evolve.

6.10 Risk Assessment and Continuous Improvement

DataCurve periodically reviews its privacy, security, and information governance practices to identify opportunities for improvement and to address evolving operational, technological, contractual, and regulatory considerations. Where appropriate, DataCurve will conduct privacy assessments, security assessments, vendor reviews, operational reviews, or other governance activities to support responsible information management.

The frequency, scope, and methodology of such reviews are determined by DataCurve based on the nature of the applicable Platform Services and reasonably foreseeable risks.

6.11 Incident Response

DataCurve maintains processes designed to identify, investigate, manage, and respond to actual or suspected security incidents affecting the Platform. Where required by applicable law, DataCurve will provide notifications regarding certain security incidents to affected individuals, Participating Organizations, regulators, or other parties within the timeframes required by law.

Nothing in this Privacy Policy creates independent notification obligations beyond those imposed by applicable law or contractual commitments.

6.12 Accountability

DataCurve seeks to maintain governance practices that support ongoing accountability for the responsible processing of Personal Information. Accountability may include:

(a) documented governance practices;

(b) internal policies and procedures;

(c) contractual protections;

(d) workforce training;

(e) vendor oversight;

(f) privacy reviews;

(g) security reviews;

(h) regulatory compliance activities; and

(i) continuous improvement initiatives.

The governance program described in section 6 is intended to support responsible stewardship of Personal Information and should not be interpreted as creating independent contractual obligations beyond those expressly established by applicable agreements or law.

 

7. International Privacy and Data Protection

This section describes additional rights, safeguards, and processing obligations that may apply where DataCurve processes Personal Information subject to the General Data Protection Regulation, the UK GDPR, the Swiss Federal Act on Data Protection, or other applicable international privacy and data protection laws.

For purposes of this section, references to a "User" include any individual who qualifies as a "data subject" or equivalent term under applicable international privacy and data protection law.

7.1 Scope

This Section 7 supplements the remainder of this Privacy Policy and applies where DataCurve processes Personal Information that is subject to the General Data Protection Regulation (Regulation (EU) 2016/679) ("GDPR"), the UK General Data Protection Regulation ("UK GDPR"), the Swiss Federal Act on Data Protection ("Swiss FADP"), or other substantially similar international privacy and data protection laws.

The rights and obligations described in this section apply only to the extent required by applicable law. Nothing in Section 7 limits any rights or obligations established elsewhere in this Privacy Policy or under applicable law.

7.2 DataCurve's Privacy Roles

Depending upon the applicable Platform Service, the relationship among the parties, and the relevant processing activity, DataCurve may process Personal Information in different legal capacities.

(a) Controller. DataCurve acts as a controller where it determines the purposes and means of processing Personal Information. Examples include the administration of:

(i) Platform Accounts;

(ii) AURA IDs;

(iii) FanGraph;

(iv) FanHub;

(v) FanZone;

(vi) Digital Credentials;

(vii) Data Intelligence;

(vii) Rewards;

(ix) Platform security; and

(xi) other Platform Services operated by DataCurve.

(b) Processor. DataCurve may act as a processor where it processes Personal Information solely on behalf of a Participating Organization in accordance with documented instructions and an applicable written agreement. Where DataCurve acts as a processor, the applicable Master Services Agreement, Data Processing Addendum, or other written agreement governs the allocation of responsibilities between the parties.

(c) Service Provider or Contractor. Where applicable United States privacy laws apply, DataCurve may process Personal Information as a service provider or contractor under applicable law.

Nothing in this Privacy Policy modifies the contractual allocation of responsibilities established between DataCurve and a Participating Organization.

7.3 Lawful Bases for Processing

Where applicable law requires a lawful basis for processing Personal Information, DataCurve processes Personal Information only where one or more lawful bases exists.

Depending upon the circumstances, more than one lawful basis may apply to a particular processing activity. Lawful bases may include:

(a) performance of a contract;

(b) User consent;

(c) legitimate interests;

(d) compliance with legal obligations;

(e) protection of vital interests;

(f) performance of tasks carried out in the public interest where authorized by law; or

(g) another lawful basis recognized under applicable privacy or data protection law.

The lawful basis applicable to any particular processing activity depends upon the nature of the Platform Service, the relationship among the parties, User choices, contractual commitments, and applicable law.

7.4 International Transfers of Personal Information

The Platform operates internationally, and Personal Information may be processed or disclosed in jurisdictions outside the country in which it was originally collected. Where applicable law restricts international transfers of Personal Information, DataCurve seeks to implement appropriate safeguards, which may include:

(a) adequacy decisions;

(b) Standard Contractual Clauses approved by the European Commission;

(c) the UK International Data Transfer Addendum or other approved UK transfer mechanisms;

(d) contractual safeguards with service providers, subprocessors, and Participating Organizations;

(e) recognized certification frameworks, where applicable; or

(f) other lawful transfer mechanisms recognized under applicable law.

Additional safeguards may be implemented as privacy laws evolve.

7.5 Automated Decision-Making and Profiling

The Platform may use AI Services, Data Intelligence, Participating Organizations, analytics, and other technologies to assist in providing personalized experiences, recommendations, fraud prevention, security monitoring, audience engagement, Rewards, and operational analytics.

Unless expressly stated otherwise, DataCurve does not knowingly engage in automated decision-making that produces legal effects concerning an individual or similarly significant effects without appropriate safeguards where required by applicable law.

Where applicable law provides Users with rights relating to profiling or automated decision-making, DataCurve will honor those rights in accordance with applicable law.

7.6 Data Subject Rights

Subject to applicable law, individuals may have the right to:

(a) obtain confirmation regarding the processing of Personal Information;

(b) request access to Personal Information;

(c) request correction of inaccurate Personal Information;

(d) request deletion of Personal Information;

(e) request restriction of processing;

(f) object to certain processing activities;

(g) receive Personal Information in a structured, commonly used, and machine-readable format where applicable;

(h) withdraw consent where processing is based upon consent; and

(i) lodge a complaint with an appropriate supervisory authority.

These rights are not absolute and may be subject to limitations, exceptions, or conditions established by applicable law.

7.7 Exercising Privacy Rights

Users may submit privacy requests using the contact information provided in Section 14 or through available Platform functionality.

To protect Personal Information and prevent unauthorized disclosures, DataCurve may request information reasonably necessary to verify the identity of the requesting individual or the authority of an authorized representative. DataCurve will respond to verified requests within the timeframes required by applicable law.

Additional guidance regarding privacy requests is provided in Appendix B.

7.8 Supervisory Authorities

Where applicable law provides the right to lodge a complaint with a supervisory authority or similar regulatory body, Users may do so in accordance with the laws of the applicable jurisdiction. DataCurve encourages Users to contact DataCurve first so that concerns may be reviewed and, where appropriate, resolved promptly and efficiently.

Nothing in this Privacy Policy limits any rights an individual may have to seek review by a supervisory authority or competent court under applicable law.

7.9 Future International Compliance

DataCurve continually monitors developments in international privacy and data protection law. As appropriate, DataCurve will adopt additional governance practices, contractual safeguards, certifications, technical measures, organizational controls, or operational procedures to support compliance with evolving legal and regulatory requirements.

Where required by applicable law, DataCurve will update this Privacy Policy to reflect material changes in its international privacy practices.

 

8. United States Privacy Rights

This section describes additional privacy rights that may be available to residents of certain United States jurisdictions, including California and other states that have enacted comprehensive consumer privacy legislation. Those rights supplement this Privacy Policy and apply only where required by applicable law.

8.1 Scope

Section 8 applies to individuals who are entitled to privacy rights under applicable United States federal, state, or local privacy laws, including the California Consumer Privacy Act, as amended by the California Privacy Rights Act ("CPRA"), and other applicable state consumer privacy laws. The rights described apply only to the extent required by applicable law and may be subject to exceptions, limitations, verification requirements, and other conditions permitted by applicable law.

Nothing in this section limits any other rights available under this Privacy Policy or applicable law.

8.2 Categories of Personal Information

During the preceding twelve (12) months, DataCurve may have collected, received, generated, or otherwise processed the categories of Personal Information described in Section 3 of this Privacy Policy.

These categories may include:

(a) identifiers;

(b) contact information;

(c) account information;

(d) commercial information;

(e) transaction information;

(f) internet or electronic activity information;

(g) device and technical information;

(h) location information;

(i) demographic information;

(j) Digital Credentials;

(k) AURA ID information;

(l) FanGraph information;

(m) Engagement Services information;

(n) Rewards information;

(o) AI-generated information;

(p) inferred information;

(q) Sensitive Personal Information, where applicable; and

(r) any additional categories described in Part III.

Not every category of Personal Information is collected from every User or processed for every Platform Service.

8.3 Sources of Personal Information

DataCurve may collect or receive Personal Information from one or more Authorized Data Sources, including:

(a) Users;

(b) Participating Organizations;

(c) service providers;

(d) integration partners;

(e) technology providers;

(f) identity verification providers;

(g) payment processors;

(h) publicly available sources where permitted by law;

(i) Platform interactions;

(j) AI Services;

(k) Digital Credentials;

(l) User-authorized integrations; and

(m) other lawful sources.

Additional information regarding Authorized Data Sources is provided in Section 2.

8.4 Business and Commercial Purposes

DataCurve processes Personal Information for the purposes described throughout this Privacy Policy, including to:

(a) provide Platform Services;

(b) administer Accounts;

(c) maintain AURA IDs;

(d) operate FanHub and FanZone;

(e) maintain FanGraph;

(f) administer Digital Credentials;

(g) operate Digital Wallet functionality;

(h) provide Engagement Services;

(i) administer Rewards;

(j) support AI Services;

(k) generate Data Intelligence;

(l) improve Platform Services;

(m) maintain security;

(n) comply with legal obligations; and

(o) support other lawful business purposes described in this Privacy Policy.

8.5 Categories of Recipients

Depending upon the applicable Platform Service, DataCurve may disclose Personal Information to the categories of authorized recipients described in section 5, including:

(a) Participating Organizations;

(b) service providers;

(c) contractors;

(d) cloud hosting providers;

(e) analytics providers;

(f) AI service providers;

(g) communications providers;

(h) payment processors;

(i) identity verification providers;

(j) professional advisors;

(k) governmental authorities where required by law;

(l) successor entities; and

(m) other authorized recipients consistent with this Privacy Policy.

8.6 Consumer Privacy Rights

Subject to applicable law, Users may have one or more of the following rights with respect to their Personal Information.

8.6.1 Right to Know

Users may request information regarding the categories of Personal Information collected, the categories of sources from which the information was collected, the business or commercial purposes for processing, the categories of authorized recipients, and the categories of Personal Information disclosed.

8.6.2 Right of Access

Users may request access to Personal Information that DataCurve maintains about them, subject to applicable legal limitations.

8.6.3 Right to Correction

Users may request correction of inaccurate Personal Information maintained by DataCurve, subject to applicable law.

8.6.4 Right to Deletion

Users may request deletion of Personal Information maintained by DataCurve, subject to legal obligations, contractual commitments, fraud prevention requirements, security needs, and other exceptions recognized by applicable law.

8.6.5 Right to Data Portability

Where required by applicable law, Users may request that certain Personal Information be provided in a portable and, where technically feasible, readily usable format.

8.6.6 Right to Opt Out

Where applicable law provides Users with the right to opt out of the sale of Personal Information, the sharing of Personal Information for cross-context behavioral advertising, targeted advertising, profiling, or similar processing activities, DataCurve will honor verified requests in accordance with applicable law.

8.6.7 Right to Limit the Use of Sensitive Personal Information

Where applicable law provides such a right, Users may request that DataCurve limit certain processing of Sensitive Personal Information, subject to applicable legal exceptions.

8.6.8 Right to Non-Discrimination

DataCurve will not discriminate against a User for exercising privacy rights provided by applicable law. Nothing in this Section limits DataCurve's ability to provide different products, services, programs, Rewards, pricing, or benefits where such differences are reasonably related to the value of data, participation in a program, contractual relationships, or otherwise permitted by applicable law.

8.7 Verification of Requests

Before fulfilling a privacy request, DataCurve may require information reasonably necessary to verify the identity of the requesting individual or the authority of an authorized representative. If DataCurve cannot reasonably verify the request, DataCurve may deny the request or request additional information consistent with applicable law.

8.8 Authorized Agents

Where permitted by applicable law, an authorized agent may submit a privacy request on behalf of a User. DataCurve may require documentation reasonably necessary to verify both the identity of the User and the authority of the authorized agent before responding to such requests.

8.9 Requests Involving Participating Organizations

Certain Personal Information processed through the Platform is controlled by Participating Organizations. Where a request relates primarily to Personal Information controlled by a Participating Organization, DataCurve may:

(a) refer the User to the applicable Participating Organization;

(b) coordinate with the Participating Organization to respond to the request;

(c) process the request in accordance with applicable contractual commitments; or

(d) otherwise respond as required by applicable law.

Nothing in this Section alters the allocation of responsibilities established between DataCurve and Participating Organizations under applicable agreements.

8.10 California "Sale" and "Sharing" Disclosures

Certain disclosures of Personal Information through the operation of the Platform may constitute a "sale," "sharing," or similar disclosure under the CPRA or other applicable state privacy laws because those statutes define such terms broadly. DataCurve does not sell Personal Information for monetary consideration in the ordinary commercial sense.

Where applicable law provides Users with opt-out rights relating to such disclosures, DataCurve will honor verified requests in accordance with applicable law.

8.11 Appeals

Where applicable law provides a right to appeal the denial of a privacy request, Users may submit an appeal using the contact information provided In Section 14 or through other procedures made available by DataCurve. DataCurve will review and respond to appeals within the timeframes required by applicable law.

8.12 Future United States Privacy Laws

United States privacy laws continue to evolve. DataCurve will modify its privacy practices, operational procedures, and this Privacy Policy to address new legal requirements, regulatory guidance, judicial decisions, industry standards, and technological developments. Where required by applicable law, DataCurve will provide notice of material changes affecting Users' privacy rights.

 

9. Cookies, Tracking Technologies, and Online Analytics

This Section 9 explains how DataCurve (or Participating Organizations) may use cookies, software development kits (SDKs), pixels, APIs, log files, analytics technologies, device identifiers, and other tracking technologies to support Platform Services, maintain security, improve functionality, personalize User experiences, and administer Engagement Services in accordance with applicable law.

9.1 Overview

DataCurve uses cookies, software development kits ("SDKs"), application programming interfaces ("APIs"), pixels, tags, log files, local storage technologies, device identifiers, browser technologies, and other tracking technologies (collectively, "Tracking Technologies") to operate, secure, maintain, improve, and personalize the Platform.

Tracking Technologies assist DataCurve in providing Platform Services, authenticating Users, protecting Accounts, maintaining security, measuring Platform performance, administering Engagement Services, supporting FanHub, improving FanGraph, delivering Rewards, operating AI Services, generating Data Intelligence, and enhancing the overall User experience.

Not every Tracking Technology is used in every Platform Service, and the technologies employed may vary depending upon the device, browser, application, operating system, Platform feature, or service being utilized.

9.2 Categories of Tracking Technologies

Depending upon the applicable Platform Service, DataCurve may use one or more categories of Tracking Technologies, including:

(a) essential cookies;

(b) authentication technologies;

(c) security technologies;

(d) preference and functionality technologies;

(e) analytics technologies;

(f) performance monitoring technologies;

(g) SDKs used within mobile applications;

(h) APIs supporting Platform functionality;

(i) browser and device storage technologies;

(j) session identifiers;

(k) server logs;

(l) advertising technologies where permitted by applicable law;

(m) fraud prevention technologies; and

(n) other technologies reasonably necessary to provide Platform Services.

DataCurve may adopt new Tracking Technologies as technology evolves, provided that their use remains consistent with this Privacy Policy and applicable law.

9.3 Essential Technologies

Certain Tracking Technologies are necessary for the operation of the Platform. These technologies may be used to:

(a) authenticate Users;

(b) maintain secure sessions;

(c) remember User preferences;

(d) support Digital Wallet functionality;

(e) administer AURA IDs;

(f) protect Platform security;

(g) facilitate FanHub and FanZone functionality;

(h) issue or validate Digital Credentials;

(i) maintain Platform reliability; and

(j) otherwise provide requested Platform Services.

Because these technologies are necessary for Platform functionality, disabling them may affect the availability or operation of certain Platform Services.

9.4 Analytics and Performance

DataCurve uses Tracking Technologies to understand how Users interact with the Platform and to improve Platform functionality. Analytics may include information relating to:

(a) Platform usage;

(b) feature utilization;

(c) navigation patterns;

(d) session duration;

(e) device performance;

(f) application performance;

(g) error reporting;

(h) operational metrics;

(i) engagement trends; and

(j) other information reasonably necessary to improve Platform Services.

Where reasonably practicable, DataCurve seeks to use aggregated or de-identified information when conducting analytics activities.

9.5 Personalization

Tracking Technologies may be used to personalize Platform Services and improve User experiences. Personalization may include:

(a) presenting relevant content;

(b) improving navigation;

(c) recognizing returning Users;

(d) supporting FanHub and FanZone interactions;

(e) improving FanGraph insights;

(f) administering Rewards;

(g) recommending Platform features;

(h) improving communications; and

(i) supporting AI Services.

Personalization is intended to improve Platform functionality and User engagement and is conducted in accordance with applicable law and User choices.

9.6 Advertising and Marketing Technologies

Where permitted by applicable law and consistent with User preferences, DataCurve or Participating Organizations may use Tracking Technologies to measure the effectiveness of marketing campaigns, sponsorship activations, communications, and promotional activities.

Depending upon applicable law, Users may have the ability to limit or opt out of certain advertising-related Tracking Technologies through browser settings, device settings, Platform preferences, or other mechanisms made available by DataCurve.

Additional information regarding applicable opt-out rights is provided in Section 8.

9.7 Third-Party Technologies

Certain Platform Services may incorporate Tracking Technologies provided by authorized third-party service providers. Such providers may include:

(a) cloud hosting providers;

(b) analytics providers;

(c) communications providers;

(d) payment processors;

(e) identity verification providers;

(f) AI service providers;

(g) security providers;

(h) customer support providers;

(i) ticketing providers;

(j) travel and hospitality partners; and

(k) other authorized technology providers.

These providers process information in accordance with applicable agreements, their respective privacy obligations, and applicable law.

9.8 Browser and Device Controls

Many browsers, mobile operating systems, and devices provide controls that allow Users to manage certain Tracking Technologies. Depending upon the applicable Platform Service and technology, Users may be able to:

(a) delete cookies;

(b) block cookies;

(c) manage browser privacy settings;

(d) reset device identifiers;

(e) manage application permissions;

(f) control location settings;

(g) manage advertising identifiers; and

(h) adjust other privacy settings.

Disabling certain Tracking Technologies may affect the functionality, availability, or performance of some Platform Services.

9.9 Do Not Track and Similar Signals

Some web browsers and devices transmit "Do Not Track" or similar privacy preference signals.

Because no uniform industry standard currently governs the interpretation of such signals, DataCurve responds to legally recognized browser-based privacy preference signals, including Global Privacy Control ("GPC") signals, where required by applicable law.

Where applicable law does not require recognition of such signals, DataCurve may not respond to them.

9.10 Future Tracking Technologies

Technology continues to evolve, and new methods of supporting authentication, personalization, analytics, security, communications, artificial intelligence, and Platform functionality may emerge.

Accordingly, DataCurve may adopt additional Tracking Technologies in the future, provided that their use remains consistent with this Privacy Policy, applicable law, and DataCurve's information governance program.

Where required by applicable law, DataCurve will provide additional notice or obtain consent before implementing new Tracking Technologies.

 

10. Information Security

This section describes the administrative, technical, physical, and organizational safeguards that DataCurve employs to protect data, maintain Platform security, and support the confidentiality, integrity, and availability of Platform Services.

10.1 Overview

DataCurve maintains an information security program designed to protect the confidentiality, integrity, availability, and resilience of the Platform and the Personal Information processed through the Platform. The information security program is intended to support responsible information governance, protect against reasonably foreseeable risks, maintain Platform operations, and satisfy applicable legal and contractual obligations.

Information security is an ongoing process. Accordingly, DataCurve periodically reviews and updates its administrative, technical, physical, and organizational safeguards as technology, business operations, industry standards, and applicable legal requirements evolve.

10.2 Security Program

DataCurve seeks to maintain security measures that are appropriate to the nature of the Platform, the categories of Personal Information processed, the sensitivity of the information involved, the reasonably foreseeable risks to individuals, and the cost and feasibility of available safeguards. Depending upon the applicable Platform Service, such measures may include:

(a) administrative safeguards;

(b) technical safeguards;

(c) physical safeguards;

(d) organizational safeguards;

(e) identity and access management;

(f) authentication controls;

(g) encryption technologies;

(h) network security measures;

(i) system monitoring;

(j) logging and audit capabilities;

(k) vulnerability management;

(l) backup and recovery procedures; and

(m) other commercially reasonable security measures appropriate to the circumstances.

The particular safeguards implemented for any Platform Service may vary depending upon operational requirements, technological developments, contractual commitments, and applicable law.

10.3 Access Controls

DataCurve seeks to limit access to Personal Information to individuals who require such access to perform authorized business functions. Access management practices may include:

(a) role-based access controls;

(b) least-privilege principles;

(c) authentication requirements;

(d) authorization controls;

(e) periodic access reviews;

(f) credential management;

(g) monitoring of privileged access; and

(h) timely modification or revocation of access rights when no longer required.

10.4 Encryption and Transmission Security

Where appropriate, DataCurve uses commercially reasonable measures to protect Personal Information during transmission and storage.

Depending upon the applicable Platform Service, such measures may include encryption, secure communication protocols, key management practices, tokenization, hashing, or other technologies designed to reduce the risk of unauthorized access or disclosure.

The specific technologies employed may change over time as industry standards and security practices evolve.

10.5 Vendor Security

DataCurve may engage service providers, cloud providers, subprocessors, and other technology partners that process Personal Information on DataCurve's behalf. Where appropriate, DataCurve seeks to evaluate such providers based upon factors including:

(a) information security capabilities;

(b) privacy practices;

(c) operational reliability;

(d) contractual commitments;

(e) regulatory compliance;

(f) business continuity capabilities; and

(g) the nature of the services provided.

DataCurve seeks to require such providers to implement appropriate safeguards for the Personal Information they process on DataCurve's behalf.

10.6 Security Monitoring

DataCurve seeks to monitor the Platform for activities that may affect the security, integrity, availability, or reliability of Platform Services. Security monitoring may include:

(a) system monitoring;

(b) event logging;

(c) fraud detection;

(d) anomaly detection;

(e) vulnerability assessments;

(f) threat intelligence;

(g) operational monitoring; and

(h) other security-related activities reasonably necessary to protect the Platform.

Monitoring activities are conducted for legitimate security and operational purposes and in accordance with applicable law.

10.7 Security Incidents

DataCurve maintains procedures designed to identify, investigate, contain, manage, and respond to actual or suspected security incidents affecting the Platform. Where required by applicable law or contractual commitments, DataCurve will provide notice of certain security incidents to affected individuals, Participating Organizations, regulators, or other authorized parties within the timeframes required by law or applicable agreement.

The nature, timing, and content of any notification will depend upon the circumstances of the incident, applicable law, and the contractual relationship between the parties.

10.8 User Responsibilities

Users also play an important role in maintaining Platform security. Users are responsible for:

(a) maintaining the confidentiality of Account credentials;

(b) using strong authentication practices where available;

(c) protecting devices used to access the Platform;

(d) promptly notifying DataCurve of suspected unauthorized access;

(e) maintaining current contact information where appropriate; and

(f) complying with the Platform Terms of Service and other applicable agreements.

DataCurve is not responsible for security incidents resulting from a User's failure to maintain appropriate security over the User's own devices, credentials, or accounts.

10.9 No Guarantee of Absolute Security

Although DataCurve implements commercially reasonable administrative, technical, physical, and organizational safeguards, no method of transmitting, storing, or processing information is completely secure. Accordingly, DataCurve cannot and does not guarantee that unauthorized access, disclosure, alteration, destruction, loss, cyberattack, system failure, human error, or other security events will never occur.

Users acknowledge that they provide and transmit information to the Platform at their own risk, subject to DataCurve's obligations under applicable law and any applicable written agreements. Nothing in this Privacy Policy shall be interpreted as creating a guarantee of absolute security or expanding any contractual obligations beyond those expressly assumed by DataCurve.

10.10 Security Program Evolution

Information security threats, technologies, legal requirements, and industry practices continue to evolve. Accordingly, DataCurve may modify, enhance, replace, or otherwise update its information security program from time to time in order to improve the security, reliability, and resilience of the Platform.

Nothing in this Privacy Policy requires DataCurve to maintain any specific technology, certification, product, or security control, provided that DataCurve continues to maintain a commercially reasonable information security program appropriate to the nature of the Platform.

 

11. Data Retention and Deletion

This section describes DataCurve's approach to data retention, archival, de-identification, and secure disposal of Personal Information.

11.1 Overview

DataCurve retains Personal Information only for as long as reasonably necessary to fulfill the purposes described in this Privacy Policy, provide Platform Services, satisfy contractual commitments, comply with applicable law, resolve disputes, protect the Platform, enforce legal rights, and support legitimate business operations.

Because the Platform provides numerous services to Users and Participating Organizations, retention periods may vary depending upon the category of Personal Information, the applicable Platform Service, the nature of the User's relationship with the Platform, contractual requirements, operational needs, and applicable legal obligations.

DataCurve periodically reviews retained Personal Information and seeks to securely delete, anonymize, or de-identify information that is no longer reasonably necessary to fulfill the purposes for which it was retained, unless continued retention is required or permitted by applicable law.

11.2 Retention Criteria

DataCurve determines appropriate retention periods by considering one or more of the following factors:

(a) the purpose for which the Personal Information was collected;

(b) the nature of the applicable Platform Service;

(c) the User's relationship with the Platform;

(d) the relationship with one or more Participating Organizations;

(e) contractual commitments;

(f) applicable statutes of limitation;

(g) legal and regulatory obligations;

(h) tax, accounting, and financial reporting requirements;

(i) security and fraud prevention needs;

(j) operational requirements;

(k) dispute resolution requirements;

(l) business continuity considerations; and

(m) other legitimate business or legal considerations.

Not all categories of Personal Information are retained for the same period.

11.3 Account Information

Personal Information associated with a User's Account, AURA ID, FanGraph, FanZone, Digital Credentials, Digital Wallet, Engagement Services, Rewards, and other Platform Services may be retained while the applicable Account remains active or while reasonably necessary to provide requested Platform Services. Following account closure or termination, certain information may continue to be retained where reasonably necessary to:

(a) comply with applicable law;

(b) enforce agreements;

(c) resolve disputes;

(d) detect or prevent fraud;

(e) protect Platform security;

(f) preserve audit records;

(g) comply with regulatory requirements; or

(h) satisfy other legitimate business purposes consistent with this Privacy Policy.

11.4 Participating Organization Information

Where Personal Information is processed on behalf of a Participating Organization, DataCurve retains such information in accordance with the applicable written agreement, documented instructions, applicable law, and operational requirements. Upon expiration or termination of the applicable agreement, DataCurve may return, delete, de-identify, or otherwise manage such information in accordance with the applicable agreement, applicable law, and DataCurve's information governance program.

Nothing in this Privacy Policy modifies any retention obligations established under a Master Services Agreement, Data Processing Addendum, or other written agreement with a Participating Organization.

11.5 De-Identification and Anonymization

Where permitted by applicable law, DataCurve may convert Personal Information into information that has been de-identified, anonymized, aggregated, or otherwise processed so that it is not reasonably capable of identifying an individual. De-identified information may be retained and used for purposes including:

(a) Platform improvement;

(b) Data Intelligence;

(c) audience analytics;

(d) benchmarking;

(e) sponsorship measurement;

(f) research and development;

(g) AI Services;

(h) operational reporting;

(i) security analysis; and

(j) other lawful business purposes.

Where information has been de-identified in accordance with applicable law, DataCurve is not required to maintain or restore the ability to identify individual Users except where required by law.

 

11.6 Secure Disposal

When Personal Information is no longer required to be retained, DataCurve will securely dispose of, delete, anonymize, or de-identify such information using methods that are appropriate to the nature of the information and the reasonably foreseeable risks associated with unauthorized access or disclosure.

Depending upon the applicable circumstances, secure disposal may include deletion from active systems, archival management, destruction of physical records, cryptographic erasure, anonymization, or other appropriate disposal methods.

Certain residual copies may continue to exist in backup systems, disaster recovery environments, or archival media for a limited period where reasonably necessary for operational continuity, legal compliance, or security purposes.

11.7 Legal Holds and Preservation Obligations

Notwithstanding any other provision of this Privacy Policy, DataCurve may retain Personal Information for longer periods where reasonably necessary to:

(a) comply with applicable law;

(b) respond to litigation or anticipated litigation;

(c) comply with court orders or governmental requests;

(d) preserve evidence;

(e) investigate suspected misconduct;

(f) enforce contractual rights;

(g) establish, exercise, or defend legal claims; or

(h) otherwise satisfy legal preservation obligations.

Where a legal hold applies, deletion or disposal of affected information may be suspended until the applicable preservation obligation has been satisfied.

11.8 User Requests for Deletion

Where applicable law provides Users with the right to request deletion of Personal Information, DataCurve will evaluate and respond to verified requests in accordance with applicable law.

Deletion requests may be denied, delayed, or partially fulfilled where DataCurve is required or permitted to retain Personal Information for one or more of the purposes described in this Part XI or as otherwise permitted by applicable law.

Where Personal Information has been provided to DataCurve by or on behalf of a Participating Organization, DataCurve may coordinate with the applicable Participating Organization when responding to deletion requests, consistent with applicable agreements and legal obligations.

Additional information regarding privacy requests is provided in Section 8 and Appendix B.

11.9 Retention Program Evolution

DataCurve periodically reviews its retention schedules, operational practices, contractual commitments, and applicable legal requirements.

Accordingly, DataCurve may modify its retention practices from time to time to reflect changes in technology, Platform Services, legal requirements, industry standards, operational needs, and information governance practices. Material changes affecting Users will be reflected in updated versions of this Privacy Policy where required by applicable law.

 

12. Children's Privacy

12.1 Overview

DataCurve is committed to protecting the privacy of children and minors while supporting lawful participation in Platform Services offered by Participating Organizations.

The Platform is generally intended for individuals who have reached the age of majority in their applicable jurisdiction unless a particular Platform Service is expressly designed to permit participation by minors with appropriate authorization, parental involvement, educational authorization, or other lawful basis under applicable law.

DataCurve recognizes that different jurisdictions impose different legal requirements concerning the collection and processing of Personal Information relating to children and minors. Accordingly, DataCurve seeks to comply with applicable age-related privacy laws in the jurisdictions in which the Platform operates.

12.2 Children Under Applicable Age Thresholds

DataCurve does not knowingly collect Personal Information directly from children where such collection is prohibited by applicable law.

Where DataCurve becomes aware that Personal Information has been collected directly from a child in violation of applicable law, DataCurve will take commercially reasonable steps to investigate the matter and, where appropriate, delete or otherwise manage such information in accordance with applicable legal requirements.

12.3 Platform Services Involving Minors

Certain Participating Organizations may sponsor or administer programs that involve minors, including youth sports, educational programs, camps, community events, charitable initiatives, scholarship programs, and similar activities. Where the Platform is used in connection with such programs, Personal Information relating to minors may be processed only where an appropriate legal basis exists, including, where applicable:

(a) parental or legal guardian consent;

(b) authorization by an educational institution;

(c) authorization by the applicable Participating Organization;

(d) another lawful basis recognized under applicable law; or

(e) a combination of the foregoing.

The Participating Organization remains responsible for obtaining any consents, notices, or authorizations required under applicable law unless otherwise expressly agreed in writing.

12.4 Parents and Legal Guardians

Where required by applicable law, parents or legal guardians may have the right to:

(a) review certain Personal Information relating to their child;

(b) request correction of inaccurate information;

(c) request deletion of Personal Information;

(d) withdraw previously provided consent where applicable;

(e) request that certain processing activities cease; or

(f) exercise other rights provided under applicable law.

DataCurve may require information reasonably necessary to verify both the identity of the requesting individual and the individual's authority to act on behalf of the child before responding to such requests.

12.5 Educational Institutions

Certain Platform Services may be made available through educational institutions, schools, universities, athletic associations, or similar organizations. Where DataCurve provides Platform Services through such organizations, DataCurve processes Personal Information in accordance with applicable agreements, educational privacy requirements, applicable law, and documented instructions from the applicable institution where appropriate.

Nothing in this Privacy Policy modifies responsibilities allocated by written agreement between DataCurve and an educational institution or Participating Organization.

12.6 Youth Sports and Community Programs

The Platform may support youth sports organizations, amateur athletic associations, community outreach initiatives, nonprofit organizations, and similar programs. Where such organizations utilize the Platform, DataCurve seeks to process Personal Information only to the extent reasonably necessary to provide the applicable Platform Services, facilitate participation, administer Digital Credentials, provide Engagement Services, communicate with participants, administer Rewards, and support other authorized program activities.

DataCurve encourages Participating Organizations operating youth programs to maintain appropriate privacy notices and obtain any consents or authorizations required under applicable law.

12.7 International Requirements

Where Personal Information relating to minors is subject to international privacy or data protection laws, DataCurve seeks to process such information in accordance with the applicable legal requirements of the relevant jurisdiction. Because age thresholds and parental consent requirements vary among jurisdictions, DataCurve may implement different operational procedures depending upon the applicable law.

12.8 Reporting Concerns

If any person believes that Personal Information relating to a child has been submitted to the Platform in violation of applicable law or this Privacy Policy, DataCurve encourages that person to contact DataCurve promptly using the contact information provided in Section 14.

DataCurve will review reported concerns and, where appropriate, investigate and respond in accordance with applicable law and its information governance practices.

 

13. Changes to this Privacy Policy

As the Platform, applicable law, and privacy practices continue to evolve, DataCurve may update this Privacy Policy from time to time.

13.1 Updates to this Privacy Policy

DataCurve may modify, revise, supplement, or otherwise update this Privacy Policy from time to time to reflect changes in the Platform, Platform Services, business operations, technology, legal requirements, regulatory guidance, industry standards, or DataCurve's information governance practices.

13.2 Notice of Material Changes

Where required by applicable law, DataCurve will provide notice of material changes to this Privacy Policy using one or more methods reasonably calculated to inform affected Users. Depending upon the circumstances, such notice may be provided through:

(a) the Platform;

(b) electronic mail;

(c) Account notifications;

(d) updates posted on DataCurve's website;

(e) notices provided through Participating Organizations where appropriate; or

(f) other reasonable means of communication.

The method of notice may vary depending upon the nature of the change, applicable legal requirements, and the affected Platform Services. DataCurve may also provide supplemental privacy notices for particular Platform Services, Participating Organizations, jurisdictions, promotions, events, or technologies. In the event of a conflict between a supplemental privacy notice and this Privacy Policy, the supplemental privacy notice will control solely with respect to the specific processing activity described therein.

13.3 Continued Use

Unless otherwise required by applicable law, the revised Privacy Policy becomes effective on the Effective Date identified in the updated version. A User's continued access to or use of the Platform following the Effective Date constitutes acknowledgment of the revised Privacy Policy, except where applicable law requires additional consent for specific processing activities.

Nothing in this Section limits any rights a User may have under applicable privacy or data protection laws.

13.4 Previous Versions

DataCurve may maintain prior versions of this Privacy Policy for legal, regulatory, operational, audit, or historical purposes. Earlier versions are not intended to govern processing activities occurring after the Effective Date of a revised Privacy Policy unless otherwise required by applicable law.

 

14. Contact Information

14.1 Contacting DataCurve

Questions regarding this Privacy Policy, DataCurve's privacy practices, the processing of Personal Information, or the exercise of privacy rights may be directed to DataCurve using the contact information below.

Privacy Inquiries
Email: [email protected]

Legal Inquiries
Email: [email protected]

Mailing Address
DataCurve, Inc.
Attn: Privacy and Legal Department
276 State Street
Los Altos, California 94022
United States

DataCurve may update its contact information from time to time. The most current contact information will be made available through the Platform or DataCurve's website.

14.2 Privacy Requests

Users wishing to exercise privacy rights available under applicable law may submit requests using the contact information provided above or through any privacy request mechanisms made available through the Platform.

Depending upon the applicable jurisdiction, Users may request access to, correction of, deletion of, portability of, restriction of, or objection to certain processing of Personal Information, or exercise other rights provided by applicable law.

Additional information regarding privacy requests is provided In Sections 7, 8, and Appendix B.

14.3 Requests Relating to Participating Organizations

Certain Personal Information processed through the Platform may be controlled by Participating Organizations. Where a request primarily concerns Personal Information controlled by a Participating Organization, DataCurve may:

(a) direct the User to the applicable Participating Organization;

(b) coordinate with the Participating Organization in responding to the request;

(c) respond in accordance with the applicable written agreement between DataCurve and the Participating Organization; or

(d) otherwise process the request as required by applicable law.

Nothing in this Privacy Policy alters the respective privacy responsibilities allocated between DataCurve and Participating Organizations under applicable agreements.

14.4 Identity Verification

To protect Personal Information and prevent unauthorized disclosures, DataCurve may require information reasonably necessary to verify:

(a) the identity of the requesting individual;

(b) the authority of an authorized representative;

(c) the identity of a parent or legal guardian acting on behalf of a minor; or

(d) the authority of another individual submitting a request on behalf of a User.

DataCurve may deny or defer a request where it cannot reasonably verify the identity or authority of the requesting party, consistent with applicable law.

14.5 Response Times

DataCurve seeks to acknowledge and respond to verified privacy requests within the timeframes required by applicable law.

Response times may vary depending upon:

(a) the applicable jurisdiction;

(b) the nature and complexity of the request;

(c) the information reasonably necessary to verify identity;

(d) whether the request involves one or more Participating Organizations;

(e) applicable legal obligations; and

(f) other circumstances recognized by applicable law.

Where permitted by law, DataCurve may extend applicable response periods upon providing any required notice to the requesting individual.

14.6 Complaints and Supervisory Authorities

Users who believe that DataCurve has not complied with applicable privacy or data protection laws may contact DataCurve using the contact information provided above. Where applicable law provides the right to file a complaint with a supervisory authority, attorney general, data protection authority, consumer protection agency, or other governmental regulator, Users may exercise those rights in accordance with applicable law.

DataCurve encourages Users to contact DataCurve first so that concerns may be reviewed and, where appropriate, resolved promptly and efficiently.

14.7 Accessibility

DataCurve is committed to making its privacy information reasonably accessible to Users. Individuals who require this Privacy Policy or related privacy information in an alternative format due to a disability or accessibility need may contact DataCurve using the contact information provided above.

DataCurve will make commercially reasonable efforts to provide appropriate accommodations where required by applicable law.

14.8 Entire Privacy Policy

This Privacy Policy, together with any supplemental privacy notices applicable to particular Platform Services, constitutes DataCurve's comprehensive statement regarding the collection, use, disclosure, retention, protection, and processing of Personal Information through the Platform.

This Privacy Policy should be read together with the Platform Terms of Service and any applicable agreements governing specific Platform Services.

Nothing in this Privacy Policy creates contractual obligations beyond those expressly established by applicable law or written agreement.

DataCurve believes that trusted digital relationships are built upon transparency, accountability, responsible innovation, and respect for individual privacy. This Privacy Policy reflects DataCurve's commitment to responsible information stewardship while enabling Participating Organizations and Users to realize the full value of the Platform through secure, personalized, and engaging experiences.

APPENDIX A

DATACURVE PRIVACY PRINCIPLES

The following Privacy Principles summarize the governance philosophy that guides DataCurve's collection, use, disclosure, retention, protection, and processing of Personal Information throughout the Platform.

These principles are intended to explain DataCurve's approach to privacy and information governance. They are not intended to create independent contractual obligations beyond those expressly established by applicable law or written agreement.

A.1 Transparency

DataCurve seeks to communicate its privacy practices in a clear, understandable, and accessible manner so that Users and Participating Organizations understand how Personal Information is processed throughout the Platform.

A.2 Lawfulness and Accountability

DataCurve seeks to process Personal Information only where a lawful basis exists and to maintain governance practices that promote accountability, responsible stewardship, and compliance with applicable privacy and data protection laws.

A.3 Purpose Limitation

DataCurve seeks to collect and process Personal Information only for specified, legitimate, and authorized purposes consistent with this Privacy Policy, applicable agreements, and applicable law.

A.4 Data Minimization

DataCurve seeks to limit the collection and processing of Personal Information to that which is reasonably necessary to provide Platform Services, support Participating Organizations, fulfill User requests, and achieve other legitimate business purposes.

A.5 User Choice

Where appropriate and required by applicable law, DataCurve seeks to provide Users with meaningful choices regarding the collection, use, disclosure, and management of Personal Information.

A.6 Security

DataCurve seeks to maintain commercially reasonable administrative, technical, physical, and organizational safeguards designed to protect Personal Information throughout its lifecycle.

A.7 Responsible Innovation

DataCurve believes that privacy and innovation should operate together. As the Platform evolves, DataCurve seeks to develop new technologies, AI Services, FanGraph capabilities, FanHub functionality, Digital Credentials, Rewards, and Data Intelligence in a manner that respects privacy and applicable law.

A.8 Data Stewardship

DataCurve seeks to act as a responsible steward of Personal Information entrusted to the Platform by Users, Participating Organizations, and other Authorized Data Sources.

A.9 Continuous Improvement

Privacy, security, governance, and compliance are ongoing processes. DataCurve periodically reviews and enhances its information governance practices to address evolving technologies, operational requirements, legal developments, and industry standards.

A.10 Trusted Value Exchange

The Platform is designed to create mutual value for Users, Participating Organizations, sponsors, brands, and other authorized participants by enabling trusted digital relationships, meaningful engagement, personalized experiences, and responsible information governance.

APPENDIX B

Privacy Rights and Request Procedures

This Appendix describes DataCurve's general procedures for receiving, evaluating, verifying, coordinating, and responding to requests relating to Personal Information.

These procedures supplement Parts VII, VIII, and XIV of this Privacy Policy.

B.1 Submitting a Request

Individuals may submit privacy requests using one of the following methods:

(a) Email to [email protected];

(b) Platform functionality designated for privacy requests, if available;

(c) Other methods made available by DataCurve from time to time.

Requests should include sufficient information to enable DataCurve to identify the applicable Account or processing activity and to verify the identity or authority of the requesting individual.

B.2 Verification

Before responding to a request, DataCurve may request information reasonably necessary to verify:

(a) the identity of the requesting individual;

(b) ownership of the applicable Account;

(c) authority of an authorized representative;

(d) authority of a parent or legal guardian;

(e) authority of another individual legally authorized to act on behalf of the User.

DataCurve may deny or defer requests where it cannot reasonably verify identity or authority, consistent with applicable law.

B.3 Types of Requests

Depending upon applicable law, DataCurve may receive requests relating to:

(a) access;

(b) correction;

(c) deletion;

(d) portability;

(e) restriction of processing;

(f) objection to processing;

(g) withdrawal of consent;

(h) limitation of Sensitive Personal Information processing;

(i) opt-out rights;

(j) appeals; or

(k) other rights recognized under applicable law.

B.4 Requests Involving Participating Organizations

The Platform supports numerous Participating Organizations, each of which may independently control certain Personal Information. Accordingly, requests involving information controlled by a Participating Organization may require coordination between DataCurve and the applicable Participating Organization.

Depending upon the applicable circumstances, DataCurve may:

(a) respond directly;

(b) forward the request to the applicable Participating Organization;

(c) coordinate a joint response;

(d) request additional information;

(e) decline the request where DataCurve lacks legal authority to respond independently; or

(f) otherwise respond in accordance with applicable law and contractual commitments.

Nothing in this Appendix modifies the allocation of responsibilities established by applicable agreements.

B.5 Response Timeframes

DataCurve seeks to respond to verified requests within the timeframes required by applicable law. Where permitted, response periods may be extended when reasonably necessary due to:

(a) request complexity;

(b) verification requirements;

(c) multiple requests;

(d) requests involving Participating Organizations;

(e) legal obligations; or

(f) other circumstances recognized by applicable law.

B.6 Appeals

Where applicable law provides a right to appeal, Users may submit an appeal using the same contact information used for the original request. Appeals will be reviewed by personnel who were not primarily responsible for the original determination where appropriate and practicable.

DataCurve will respond to appeals within the applicable legal timeframe.

B.7 Authorized Representatives

Authorized representatives may submit requests on behalf of Users where permitted by applicable law. DataCurve may require documentation demonstrating the representative's authority before responding to such requests.

B.8 No Fee

DataCurve generally does not charge a fee for responding to verified privacy requests. However, where permitted by applicable law, DataCurve may charge a reasonable fee or decline to act upon requests that are manifestly unfounded, excessive, repetitive, or otherwise permitted to be refused under applicable law.

B.9 Request Responsibility Matrix

Request Type Primary Responsibility DataCurve Role
Account Information DataCurve Respond directly
AURA ID DataCurve Respond directly
FanGraph Information DataCurve Respond directly, subject to applicable law
Digital Wallet DataCurve Respond directly
Rewards DataCurve and/or Participating Organization Respond or coordinate as appropriate
FanHub Activity DataCurve and/or Participating Organization Coordinate response where appropriate
Membership Information Participating Organization Coordinate or refer request
Ticketing Information Participating Organization Coordinate or refer request
Marketing Preferences DataCurve and/or Participating Organization Respond based on applicable controller relationship
Customer Support Records DataCurve Respond directly
Enterprise Customer Data Participating Organization Respond in accordance with the applicable MSA and DPA

B.10 Contact Information

Questions regarding this Appendix or DataCurve's privacy request procedures may be directed to:

Privacy Team

[email protected]

Legal Department

[email protected]