Legal
Data Compliance and Acceptable Data Use
Effective date: July 25, 2026 · Last updated: July 25, 2026. Requirements for customers, users, consultants, brokers, campaigns, organizations, and agencies that upload, license, obtain, process, or use data through Plavidian.
1. Purpose
This Data Compliance and Acceptable Data Use Policy establishes requirements for customers, users, consultants, brokers, campaigns, organizations, and agencies that upload, license, obtain, process, or use data through Plavidian.
2. Roles of the parties
Plavidian provides print, mail, data-processing, analytical, production, fulfillment, and distribution-platform services. Depending on the project: a customer may supply its own data; an independent data provider may make a licensed data product available; Plavidian may retrieve a count or licensed file through the provider's system; Plavidian may normalize, suppress, merge, segment, analyze, or prepare data; Plavidian may use the resulting data to produce or mail the customer's communication; and Plavidian may return reports or permitted outputs to the customer.
Unless expressly agreed otherwise, Plavidian does not determine the original collection practices, source selection, substantive attributes, or consumer-request policies of an independent data compiler.
3. Customer certification
By supplying data to Plavidian or ordering licensed data, the customer represents and warrants that: it has lawful authority to obtain, disclose, and use the data; it has provided all notices and obtained all consents required by law; its instructions do not violate a person's privacy rights; it will use the data only for lawful and licensed purposes; it will maintain and apply required suppression and opt-out records; it will not use the data for unlawful discrimination or prohibited eligibility decisions; it will not use marketing data as a consumer report; it will comply with applicable election, advertising, telemarketing, email, text-message, postal, charitable-solicitation, and consumer-protection laws; it will protect the data against unauthorized access; it will restrict access to personnel with a legitimate need; it will delete or return data when required by the license, contract, or law; and information supplied to Plavidian is not unlawfully obtained.
4. Permitted processing by Plavidian
Subject to the applicable order, Plavidian may process data to: provide counts and availability information; format and standardize records; perform CASS, DPV, NCOA, ZIP+4, carrier-route, or other postal processing; deduplicate individuals, households, businesses, or addresses; apply customer or provider suppression files; segment records; append permitted attributes; perform geographic or demographic analysis; select records meeting customer criteria; prepare variable-data production files; print, address, insert, mail, ship, track, reconcile, and report; troubleshoot and correct production issues; create audit records; prevent fraud and unauthorized use; and satisfy legal, contractual, and postal obligations.
5. Prohibited data
Unless Plavidian expressly approves the project in writing and an appropriate agreement is in place, customers may not submit: Social Security numbers; complete financial-account credentials; payment-card security codes; medical records or protected health information; biometric identifiers; passwords or authentication secrets; highly sensitive precise-location histories; information unlawfully obtained from a breach; protected educational records; criminal-justice information subject to restricted access; information restricted by court order; data regulated by the Driver's Privacy Protection Act; consumer-report information regulated by the Fair Credit Reporting Act; or other information requiring controls not supported by the applicable service. Plavidian may reject, quarantine, delete, or require enhanced contractual and security measures for prohibited or unexpectedly sensitive data.
6. Sensitive and protected characteristics
Customers may not use Plavidian's services or data products to unlawfully discriminate on the basis of race, color, ethnicity, national origin, religion, sex, gender, gender identity, sexual orientation, disability, medical condition, genetic information, age, citizenship, military status, or another protected characteristic. Marketing selections involving potentially sensitive characteristics must be lawful, appropriate to the communication, and permitted by the data provider. No modeled characteristic should be represented as a verified fact about a specific individual.
7. Prohibited decisions and uses
Data obtained or processed through Plavidian may not be used to make or support decisions concerning credit eligibility; insurance eligibility or underwriting; employment; housing; health-care eligibility; educational admission; government-benefit eligibility; bail, sentencing, or criminal enforcement; or another significant decision about an individual, unless the particular data product and use are expressly authorized by law and by a separate written agreement. Standard marketing-list products are not consumer reports.
8. Suppression and privacy preferences
The customer is responsible for maintaining and applying legally required do-not-mail lists, customer-request suppression, donor or member preferences, opt-outs, deletion-related suppression, deceased-person suppression, internal compliance exclusions, and campaign, organization, or provider-specific exclusions. Plavidian will apply a suppression file only when it is supplied, available, and included in the order. A customer must not assume that purchasing or licensing a new list automatically incorporates the customer's internal opt-outs.
9. Consumer requests
A. Requests directed to the customer
The customer is responsible for receiving, authenticating, evaluating, and responding to requests concerning data the customer controls. When Plavidian holds relevant Customer Data as a service provider or contractor, Plavidian will provide reasonable assistance as required by law, contract, and technical feasibility.
B. Requests concerning provider data
Requests concerning an independent data provider's source database should be directed to that provider using the provider's privacy-request process. Plavidian may provide or facilitate provider contact information but does not make decisions concerning correction, deletion, opt-out, or access in a database controlled by the provider unless legally required.
C. Requests concerning Plavidian's own information
Requests concerning Plavidian's own account, transaction, website, or business-contact information may be submitted under the Privacy Notice.
10. Service-provider and contractor terms
When Plavidian processes personal information on behalf of a customer subject to the CCPA, the parties will enter into terms that: specify the limited and specific business purposes for processing; prohibit Plavidian from selling or sharing the information; prohibit retention, use, or disclosure outside the specified purposes and direct business relationship, except as legally permitted; require an appropriate level of privacy protection; require reasonable security; permit the customer to take reasonable steps to verify compliant use; require notice if Plavidian can no longer meet its obligations; permit steps to stop and remediate unauthorized use; address subprocessors; and enable the customer to respond to consumer requests. A general statement that Plavidian is a service provider is not a substitute for the written contractual terms required by applicable law.
11. Independent provider terms
The customer acknowledges that an independent data provider may impose single-use or limited-use restrictions, expiration dates, minimum-order quantities, restrictions on storage or redistribution, audit rights, seed or decoy records, source-identification requirements, suppression obligations, sector-specific restrictions, security requirements, and deletion or return obligations. The customer agrees to comply with all provider terms incorporated into the order.
12. Data security
Customers must: use secure transmission methods approved by Plavidian; avoid sending sensitive files through unencrypted ordinary email where a secure upload method is available; apply access controls; use strong authentication; limit downloads; protect exported reports; report suspected incidents promptly; and securely delete data when no longer authorized. Plavidian may require password protection, secure upload, multifactor authentication, encryption, or other controls based on the project.
13. Data incidents
A party discovering suspected unauthorized access, acquisition, use, disclosure, alteration, or loss involving project data must notify the other party without unreasonable delay. The parties will cooperate as reasonably necessary to investigate, contain the incident, preserve evidence, determine affected information, satisfy applicable notice obligations, communicate with providers, insurers, counsel, or authorities, and prevent recurrence. Responsibility for legally required notification will be determined by applicable law, the parties' roles, and the governing agreement.
14. Audits and verification
Plavidian may request information reasonably necessary to verify the customer's permitted use, legal authority to use supplied data, compliance with a provider license, deletion of expired data, application of required suppression, user authorization, or protection of sensitive information. Plavidian may suspend data access or production when it reasonably believes data is being used unlawfully or outside the applicable license.
15. Retention and destruction
Customer and licensed data will be retained only as reasonably necessary for the authorized services, legal obligations, backups, dispute resolution, or another permitted purpose. Single-use data must not be reused unless separately licensed. At the end of the applicable retention or license period, data will be deleted, returned, deidentified, or made inaccessible as required by the agreement, subject to legally permitted backups and records.
16. No transfer of compliance responsibility
Plavidian's performance of data processing, postal processing, list acquisition, suppression, or production does not transfer the customer's legal obligations to Plavidian. The customer remains responsible for the lawful purpose of the campaign, required consumer notices, privacy-request intake and decisions, opt-out compliance, campaign and advertising disclaimers, content legality, audience-selection legality, and adherence to the customer's own published privacy promises.
17. Contact
Data Compliance — Plavidian, 2210 E Vista Way Ste 6, Vista, CA 92084 · info@plavidian.com · 760-666-3130.
