Bitte fuehren Sie diese kurze Ueberpruefung durch, um Ihre Anfrage zu senden. Dies hilft uns, Spam zu verhindern.
Version 0.1 (initial draft), published 5 October 2026.
This Data Processing Addendum (the "DPA") forms part of the Master Services Agreement dated [date] (the "MSA") between TheNewPush, LLC, a Colorado limited liability company with offices at 3700 O'Donnell Street, Suite 200, Baltimore, Maryland 21224 ("NewPush"), and [Client legal name, entity type and jurisdiction], with offices at [address] ("Client"). In this DPA, "Party" and "Parties" have the meanings given in the MSA.
1.1 Purpose. This DPA sets out the terms on which NewPush processes Client Personal Data on Client's behalf in providing the Services. It is intended to meet Article 28(3) GDPR, Article 28(3) UK GDPR, the Swiss Federal Act on Data Protection ("FADP"), the CCPA and the processor-contract requirements of the other Data Protection Laws.
1.2 Scope. This DPA applies only where, and to the extent that, NewPush processes Client Personal Data as a processor or service provider for Client. It does not apply to personal information that NewPush processes as an independent controller or business, such as Client contact and account details used for billing, account administration, legal compliance and security of NewPush's own systems.
1.3 Order of precedence. If this DPA conflicts with the MSA or an Order Document on the processing of Client Personal Data, this DPA prevails. If this DPA conflicts with any Transfer Mechanism incorporated under Section 11, the Transfer Mechanism prevails. In all other respects the MSA continues to apply.
1.4 Survival. This DPA stays in force for as long as NewPush or any Sub-processor holds Client Personal Data, even after the MSA ends.
Capitalised terms not defined in this DPA have the meanings given in the MSA. In this DPA:
"CCPA" means the California Consumer Privacy Act of 2018, as amended by the California Privacy Rights Act of 2020 (Cal. Civ. Code §1798.100 et seq.), and its implementing regulations (11 CCR §7000 et seq.).
"Client Personal Data" means the Personal Information, including "personal data" and "personal information" as defined in the Data Protection Laws, that forms part of Client Data and that NewPush processes on Client's behalf in providing the Services.
"controller", "processor", "data subject", "personal data", "processing" and "supervisory authority" have the meanings given in the GDPR. "Business", "service provider", "contractor", "consumer", "business purpose", "sell" and "share" have the meanings given in the CCPA. Equivalent terms in other Data Protection Laws (for example "controller" and "processor" under Virginia or Colorado law) are to be read accordingly.
"Data Protection Laws" means all data protection and privacy laws that apply to the processing of Client Personal Data under the MSA, as amended or replaced from time to time. This includes, where applicable: (a) the GDPR; (b) the UK GDPR and the UK Data Protection Act 2018; (c) the FADP; (d) the CCPA; (e) the other US state comprehensive consumer privacy laws, including those of Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana, Iowa, Delaware, New Hampshire, New Jersey, Nebraska, Tennessee, Minnesota, Maryland, Indiana, Kentucky and Rhode Island; and (f) any other national or state law listed in Schedule 1.
"Data Security Breach" has the meaning given in the MSA. For Client Personal Data it includes any "personal data breach" as defined in the GDPR and any breach of security under applicable US state breach-notification laws.
"GDPR" means Regulation (EU) 2016/679.
"Restricted Transfer" means a transfer of Client Personal Data that would be prohibited under the Data Protection Laws without a Transfer Mechanism.
"Sub-processor" means any third party, including a NewPush Affiliate, that NewPush engages to process Client Personal Data on Client's behalf.
"Transfer Mechanism" means the EU SCCs, the UK Addendum, the UK IDTA, the Swiss adaptations or another lawful transfer tool, as described in Section 11 and Schedule 4.
"UK GDPR" means the GDPR as it forms part of the law of the United Kingdom, as amended (including by the Data (Use and Access) Act 2025).
3.1 Roles. For Client Personal Data, Client is the controller (and a business under the CCPA) and NewPush is the processor (and a service provider or contractor under the CCPA). Where Client is itself a processor for a third-party controller, Client warrants that its instructions, including its appointment of NewPush as a Sub-processor, have been authorised by that controller. In that case NewPush acts as Client's sub-processor.
3.2 Details of processing. The subject matter, duration, nature and purpose of the processing, the types of Client Personal Data and the categories of data subjects are set out in Schedule 1 and the relevant Order Document.
4.1 Lawful instructions and lawful basis. Client shall make sure that: (a) its instructions comply with the Data Protection Laws; (b) it has a lawful basis for the processing, and has given any notices and obtained any consents the Data Protection Laws require, so that NewPush may lawfully process Client Personal Data under this DPA; and (c) it has the right to transfer, or give NewPush access to, Client Personal Data.
4.2 Data minimisation. Client shall provide NewPush with only the Client Personal Data that the Services need. Unless an Order Document expressly allows it and Schedule 1 lists it, Client shall not provide special category data, criminal offence data, payment card data, protected health information, or children's personal data.
4.3 Client security responsibilities. Client is responsible for the security of its own systems and accounts and for the matters MSA Exhibit A and the Order Document assign to Client. This includes managing Client User credentials and access and configuring any security settings that Client controls.
4.4 Data subject and regulator relationships. Client is responsible for responding to data subjects, consumers and supervisory authorities about processing it controls. NewPush assists under Sections 7 and 8.
5.1 Documented instructions. NewPush shall process Client Personal Data only on Client's documented instructions, including instructions on Restricted Transfers. The exception is processing required by law that applies to NewPush. In that case NewPush shall tell Client about the legal requirement before processing, unless the law prohibits this on important grounds of public interest. Client's instructions consist of the MSA, this DPA, the Order Document, Client's configuration and use of the Services, and any further written instructions the Parties agree. An instruction outside the scope of the Services may be handled as a change order under MSA s.3.3.
5.2 Unlawful instructions. NewPush shall tell Client promptly if, in its opinion, an instruction infringes the Data Protection Laws. NewPush may suspend the affected processing until Client confirms or changes the instruction. NewPush is not obliged to give legal advice.
5.3 Confidentiality. NewPush shall make sure that every person it authorises to process Client Personal Data, including employees, contractors and Sub-processor personnel, is bound by a written duty of confidentiality or an appropriate statutory duty. NewPush shall limit access to those who need it to perform the Services.
5.4 Security (Article 32). NewPush shall implement and maintain appropriate technical and organisational measures to give Client Personal Data a level of security appropriate to the risk. In doing so it shall take into account the state of the art, the costs of implementation, the nature, scope, context and purposes of the processing, and the risks to individuals. As a minimum, NewPush shall implement the measures described in Schedule 2 and MSA s.8.1. NewPush may update those measures, provided that no update materially reduces the overall level of protection.
5.5 Assistance with compliance. Taking into account the nature of the processing and the information available to it, NewPush shall give Client reasonable assistance in meeting its obligations under: Articles 32–36 GDPR and UK GDPR (security, breach notification, data protection impact assessments and prior consultation); the CCPA (including, where applicable, Client's cybersecurity audits, risk assessments and automated decision-making technology obligations under 11 CCR Articles 9–11); and equivalent provisions of other Data Protection Laws (for example data protection assessments under the Virginia and Colorado laws). Assistance beyond NewPush's standard documentation and reports may be charged at NewPush's then-current rates.
5.6 Records. NewPush shall keep the records of processing activities that Article 30(2) GDPR and UK GDPR require, where they apply to NewPush. It shall make them available to Client or a supervisory authority on request.
5.7 Notice of inability to comply. NewPush shall tell Client without undue delay, and in any event within [five (5)] business days, if it decides that it can no longer meet its obligations under this DPA or the Data Protection Laws.
5.8 Legally binding requests. Unless the law prohibits it, NewPush shall promptly tell Client of any legally binding request from a public authority for disclosure of Client Personal Data. NewPush shall disclose no more than the minimum the law requires and shall use reasonable efforts to challenge any request it considers unlawful or overbroad.
6.1 Business purpose. Client discloses Client Personal Data to NewPush only for the limited and specified business purposes set out in Schedule 1 (the "Business Purposes"), namely to provide the Services described in the MSA and the Order Document.
6.2 Restrictions. For Client Personal Data subject to the CCPA, NewPush shall not:
(a) sell or share it;
(b) retain, use or disclose it for any purpose other than the Business Purposes, including any commercial purpose other than the Business Purposes, unless the CCPA permits it;
(c) retain, use or disclose it outside the direct business relationship between NewPush and Client;
(d) combine or update it with personal information that NewPush receives from or on behalf of another person, or collects from its own interaction with the consumer, unless the CCPA and its regulations permit this (for example under 11 CCR §7050(a)); or
(e) use it for cross-context behavioural advertising or to build or change a consumer profile for that purpose.
6.3 Same level of protection. NewPush shall comply with the obligations that apply to it under the CCPA and shall give Client Personal Data the same level of privacy protection that the CCPA requires of businesses.
6.4 Client rights to verify and remediate. Client may take reasonable and appropriate steps to make sure NewPush uses Client Personal Data in a way consistent with Client's CCPA obligations. These steps are the audit and information rights in Section 10. On notice, Client may also take reasonable and appropriate steps to stop and remediate unauthorised use of Client Personal Data.
6.5 Consumer requests. NewPush shall cooperate with Client in responding to consumer requests under the CCPA as set out in Section 7. Client shall tell NewPush of any consumer request that NewPush must act on and shall provide the information NewPush needs to do so.
6.6 Subcontracting. NewPush shall tell Client of any Sub-processor that will process Client Personal Data (Section 9) and shall bind each one by a written contract that complies with 11 CCR §7051.
6.7 Certification. NewPush certifies that it understands the restrictions in this Section 6 and will comply with them.
6.8 Other US state laws. To the extent other US state comprehensive privacy laws apply, NewPush shall act as Client's "processor" under those laws. NewPush shall: (a) process Client Personal Data only on Client's instructions; (b) bind its personnel to confidentiality; (c) delete or return Client Personal Data at the end of the Services (Section 12); (d) make available the information Client reasonably needs to demonstrate compliance; (e) allow and contribute to reasonable assessments (Section 10); (f) bind Sub-processors by written contract and give Client an opportunity to object (Section 9); and (g) help Client carry out data protection assessments and respond to consumer requests.
7.1 If NewPush receives a request from a data subject or consumer to exercise rights under the Data Protection Laws in relation to Client Personal Data, NewPush shall promptly, and in any event within [five (5)] business days, pass the request to Client. NewPush shall not respond to the request itself, other than to direct the requester to Client, unless Client instructs it to or the law requires it.
7.2 Taking into account the nature of the processing, NewPush shall assist Client by appropriate technical and organisational measures, so far as possible, in meeting Client's obligation to respond to such requests (including access, rectification, erasure, restriction, portability, objection, and the CCPA rights to know, delete, correct and opt out). Where Client can meet a request using the Services' own functions, Client shall do so.
8.1 Notification. NewPush shall notify Client in writing without undue delay, and in any event no later than forty-eight (48) hours after becoming aware of a Data Security Breach affecting Client Personal Data. This matches MSA s.8.2. For breaches arising in or from Third-Party Software, MSA s.8.2A–8.2C apply.
8.2 Content. As far as the information is available, the notice (or follow-up notices, as information becomes available) shall describe: (a) the nature of the breach, including the categories and approximate number of data subjects and records concerned; (b) the name and contact details of NewPush's point of contact; (c) the likely consequences; and (d) the measures taken or proposed to address the breach and mitigate its effects.
8.3 Cooperation. NewPush shall take reasonable steps to contain, investigate and remediate the breach. It shall cooperate with Client so that Client can meet its obligations to notify supervisory authorities, affected individuals and others (including the 72-hour regulator notice under Article 33 GDPR where it applies). Unless the law requires it, NewPush shall not notify regulators or affected individuals about Client Personal Data without Client's prior written approval, except to identify itself as Client's processor.
8.4 No admission. NewPush's notification of, or response to, a Data Security Breach is not an admission of fault or liability.
9.1 General authorisation. Client gives NewPush general written authorisation to engage Sub-processors. This covers the Sub-processors listed in Schedule 3 or the Order Document at the date of the Order Document, subject to this Section 9.
9.2 Sub-processor list on request. NewPush shall keep an up-to-date list of its Sub-processors for the Services. The list shall give each Sub-processor's name, location, the processing it carries out and the transfer mechanism (if any). NewPush shall give Client the current list within ten (10) business days of Client's written request.
9.3 Notice of changes. NewPush shall give Client at least [thirty (30)] days' prior written notice of any intended addition or replacement of a Sub-processor. This notice also satisfies MSA s.3.5(i).
9.4 Objection. Client may object to a new Sub-processor on reasonable data protection grounds by written notice within [fifteen (15)] days of NewPush's notice. If Client objects, the Parties shall discuss the concern in good faith. NewPush may offer a commercially reasonable alternative, such as a different Sub-processor or a change to the Services that avoids the objected-to Sub-processor. If the Parties cannot resolve the objection within [thirty (30)] days, Client may terminate the affected Order Document, or the affected part of the Services, by written notice without termination charges. Client remains liable for Fees for Services performed up to the termination date. If Client does not object within the objection period, the new Sub-processor is treated as authorised.
9.5 Emergency replacement. If NewPush must replace a Sub-processor urgently for reasons outside its reasonable control (for example the Sub-processor's insolvency, a security issue or the end of a service), NewPush may do so straight away. It shall then notify Client as soon as practicable, and Client's objection rights under Section 9.4 shall apply.
9.6 Flow-down. NewPush shall bind each Sub-processor by a written contract that imposes data protection obligations no less protective than those in this DPA. This includes sufficient guarantees to implement appropriate technical and organisational measures, and, where the CCPA applies, the terms required by 11 CCR §7051.
9.7 Responsibility. NewPush remains fully liable to Client for the performance of each Sub-processor's data protection obligations, as required by Article 28(4) GDPR and MSA s.3.5(iii). This liability is subject to Section 13.
9.8 Third-Party Software vendors. Where the Services include Third-Party Software supplied on a pass-through or reseller basis, the vendor may process Client Personal Data: (a) as NewPush's Sub-processor under NewPush's own agreement and data processing addendum with that vendor; or (b) as Client's direct processor under the Third-Party EULA. Schedule 3 shall identify which applies for each vendor. In case (a), Section 9.7 applies, subject to MSA s.11.3. In case (b), the vendor is not NewPush's Sub-processor.
10.1 Information. On Client's written request, NewPush shall make available all information reasonably necessary to demonstrate its compliance with this DPA and Article 28 GDPR. This includes its most recent SOC 1 and SOC 2 Type 2 reports or equivalent third-party certifications (MSA s.8.4), summaries of relevant policies, and responses to reasonable security questionnaires. Client agrees that this information will normally satisfy its audit rights.
10.2 Audits. If the information under Section 10.1 is not enough to demonstrate compliance, or a supervisory authority requires it, or after a Data Security Breach, Client (or an independent auditor it mandates who is bound by confidentiality and is not a NewPush competitor) may audit NewPush's compliance with this DPA, including by inspection. Such audits are subject to the following:
(a) at least [thirty (30)] days' written notice, except after a Data Security Breach or where a regulator requires shorter notice;
(b) no more than once in any twelve-month period, except after a Data Security Breach or where a regulator requires it;
(c) during normal business hours, without unreasonable disruption to NewPush's operations, and subject to NewPush's reasonable security and confidentiality requirements, including protection of other customers' data;
(d) a scope agreed in advance; and
(e) at Client's cost. If the audit reveals a material breach of this DPA by NewPush, NewPush bears its own costs of the audit and remediation.
10.3 Findings. NewPush shall promptly remedy any material non-compliance an audit identifies. Audit reports and findings are NewPush's Confidential Information.
10.4 Sub-processors. Where Client's audit rights reach a Sub-processor, NewPush may meet them by providing that Sub-processor's own third-party audit reports or certifications.
11.1 Locations. Client Personal Data may be processed in the locations listed in Schedule 1 and Schedule 3. NewPush shall not make, or allow a Sub-processor to make, a Restricted Transfer unless it complies with the Data Protection Laws and with this Section 11.
11.2 EU / EEA. Where a Restricted Transfer of Client Personal Data is subject to the GDPR, and the importer is in a country without an adequacy decision (or the transfer is not covered by an adequacy decision such as the EU–US Data Privacy Framework for a certified importer), the Parties agree to the standard contractual clauses annexed to Commission Implementing Decision (EU) 2021/914 (the "EU SCCs"), incorporated by reference, as follows:
(a) Module Two (controller to processor) where Client is a controller, and Module Three (processor to processor) where Client is a processor;
(b) Clause 7 (docking clause): [applies / does not apply];
(c) Clause 9: Option 2 (general written authorisation), with the notice period in Section 9.3;
(d) Clause 11: the optional redress wording does not apply;
(e) Clauses 17 and 18: the law and courts of [Ireland / the EU Member State in which Client is established];
(f) Annexes I to III: completed by Schedules 1, 2 and 3 of this DPA respectively; and
(g) Annex I.C (competent supervisory authority): as stated in Schedule 4.
11.3 United Kingdom. Where a Restricted Transfer is subject to the UK GDPR, the EU SCCs shall apply as amended by the ICO's International Data Transfer Addendum to the EU Commission Standard Contractual Clauses (version B1.0, in force 21 March 2022, or any version the ICO later issues) (the "UK Addendum"). Tables 1 to 3 of the UK Addendum shall be completed with the information in this DPA and its Schedules. For Table 4, [either Party] may end the UK Addendum as allowed by its Section 19. Alternatively, where the Parties choose in Schedule 4, the ICO International Data Transfer Agreement (the "UK IDTA") shall apply. A transfer to a US importer certified to the UK Extension to the EU–US Data Privacy Framework may instead rely on UK adequacy regulations.
11.4 Switzerland. Where a Restricted Transfer is subject to the FADP, the EU SCCs shall apply with these adaptations: (a) references to the GDPR are to be read as references to the FADP where the transfer is subject to it; (b) the competent supervisory authority is the Swiss Federal Data Protection and Information Commissioner (FDPIC) for those transfers; (c) "Member State" shall not be read so as to stop data subjects in Switzerland from enforcing their rights in their place of habitual residence; and (d) the governing law and forum shall be as set out in Schedule 4. A transfer to a US importer certified to the Swiss–US Data Privacy Framework may instead rely on Switzerland's adequacy recognition.
11.5 Other jurisdictions. Where other Data Protection Laws require a transfer mechanism, the Parties shall agree it in Schedule 4 or in the Order Document.
11.6 Transfer risk assessment. NewPush shall give Client the information reasonably needed for a transfer impact assessment, including information about laws on public-authority access in the importer's country. It shall implement any supplementary measures listed in Schedule 2.
11.7 Alternative mechanisms. If a Transfer Mechanism is invalidated, amended or replaced (including any outcome of the pending CJEU appeal on the EU–US Data Privacy Framework, or adoption by the European Commission of new SCCs for importers directly subject to the GDPR), the Parties shall cooperate in good faith to put in place a valid alternative without undue delay.
12.1 When the Services relating to the processing end, NewPush shall, at Client's choice notified in writing within [thirty (30)] days of termination or expiry, return Client Personal Data to Client in a mutually agreed format (or let Client export it) and/or delete it. Deletion includes existing copies, and NewPush shall complete it within [thirty (30)] days after the end of that election period. This matches MSA s.5.5(f). If Client makes no election, NewPush shall delete the Client Personal Data.
12.2 NewPush may keep Client Personal Data only where the law requires it to be stored. NewPush may also keep it in backups that are overwritten in the ordinary course within [ninety (90)] days. In both cases this DPA continues to apply to the retained data, and NewPush shall process it only for the purpose of storage as required.
12.3 On request, NewPush shall certify deletion in writing. Return and deletion of content held by Third-Party Software vendors are subject to MSA Schedule 2 (for example clause K6.3) or the applicable Third-Party EULA.
13.1 Each Party's liability arising out of or relating to this DPA, whether in contract, tort or otherwise, is subject to the exclusions and limitations of liability in Section 11 (Limitation of Liability) of the MSA, including the Third-Party Software sub-cap in MSA s.11.3. Any reference in the MSA to liability under the MSA includes liability under this DPA. This DPA does not create a separate or additional cap.
13.2 Nothing in this DPA limits either Party's liability to data subjects under the Data Protection Laws (including Article 82 GDPR) or under the third-party beneficiary rights in any Transfer Mechanism, to the extent such limitation is not permitted.
14.1 Term. This DPA starts on the effective date of the MSA or, if later, the date it is signed. It continues for as long as NewPush processes Client Personal Data.
14.2 Changes in law. If a change in the Data Protection Laws requires a change to this DPA, the Parties shall negotiate in good faith to make the minimum change needed to comply.
14.3 Governing law. Except where a Transfer Mechanism requires otherwise, this DPA is governed by the governing law and dispute-resolution provisions of the MSA (Sections 14 and 15).
14.4 Notices. Notices under this DPA follow MSA Section 19. Data Security Breach notices may be given by email to the contacts in Schedule 1. NewPush's privacy contact is [[email protected] – to be confirmed].
14.5 Counterparts. MSA Section 22 applies.
| TheNewPush, LLC | [Client legal name] |
|---|---|
| Signature: ____________ | Signature: ____________ |
| Name: Balázs Nagy | Name: ____________ |
| Title: Chief Executive Officer | Title: ____________ |
| Date: ____________ | Date: ____________ |
| Subject matter | Processing of Client Personal Data to provide the Services under the MSA and Order Document [to be completed per Order Document] |
| Duration | The Term of the MSA and applicable Order Document, plus the return/deletion period in Section 12 [to be completed per Order Document] |
| Nature of processing | [e.g. hosting, storage, backup, endpoint management and monitoring, security operations / SOC, identity and access reviews, software development and support, data migration, help-desk] [to be completed per Order Document] |
| Purpose(s) / Business Purposes (CCPA) | [e.g. providing, securing, supporting and maintaining the Services; detecting security incidents; debugging] [to be completed per Order Document] |
| Categories of data subjects | [e.g. Client employees and contractors (Client Users); Client's customers, students, patients or end users; Client's suppliers' contacts] [to be completed per Order Document] |
| Types of Client Personal Data | [e.g. names, business contact details, user IDs and credentials, device identifiers, IP addresses, logs and telemetry, email content, HR/user-access data] [to be completed per Order Document] |
| Sensitive data / special categories (and safeguards) | [None / specify, with additional safeguards such as restricted access, extra encryption, specialised training] [to be completed per Order Document] |
| Frequency of transfer | [Continuous / one-off / periodic] [to be completed per Order Document] |
| Processing locations | [e.g. United States; Hungary (EU); cloud regions] [to be completed per Order Document] |
| Retention | As set out in Section 12, or [specific retention period] [to be completed per Order Document] |
| Applicable Data Protection Laws | [GDPR / UK GDPR / FADP / CCPA / other states / other] [to be completed per Order Document] |
| Breach-notice contacts | Client: [name, email, phone]; NewPush: [name, email, phone] [to be completed per Order Document] |
C. Competent supervisory authority: [see Schedule 4] [to be completed per Order Document]
The measures below describe NewPush's baseline programme, aligned with its SOC 1 and SOC 2 Type 2 audited controls (MSA s.8.1). Engagement-specific measures are [to be completed per Order Document].
The current list is available on request and will be provided within ten (10) business days (Section 9.2). Sub-processors authorised at the date of the Order Document:
| Sub-processor | Location | Processing performed | Transfer mechanism | NewPush sub-processor or Client's direct vendor (Section 9.8) |
|---|---|---|---|---|
| [NewPush Europe Kft., Budapest, Hungary – if applicable] | Hungary (EU) | [Engineering / support personnel] | [Intra-group agreement / SCCs as applicable] | NewPush sub-processor |
| [Cloud hosting provider] | [ ] | [ ] | [ ] | [ ] |
| [to be completed per Order Document] | ||||
| EU SCCs module(s) | [Module 2 / Module 3] [to be completed per Order Document] |
| Clause 7 docking clause | [Applies / Does not apply] |
| Clause 13 / Annex I.C supervisory authority | [Authority of the Member State where Client is established, or of its Art. 27 representative] |
| Clause 17 governing law | [Ireland / Member State] |
| Clause 18 forum | [Courts of Ireland / Member State] |
| UK mechanism | [UK Addendum to EU SCCs / UK IDTA / UK–US data bridge (DPF-certified importer) / not applicable] |
| UK Addendum Table 4 (ending the Addendum) | [Importer / Exporter / Neither] |
| Swiss mechanism | [EU SCCs with Swiss adaptations / Swiss–US DPF (certified importer) / not applicable]; Swiss governing law and forum [Switzerland / per EU SCCs where permitted] |
| Other jurisdictions | [e.g. Canada (PIPEDA / provincial law) – contractual safeguards only; specify] |
| Supplementary measures | [Per Schedule 2, item 13] |
*End of DPA template.*