This Data Processing Addendum ("DPA") supplements our Terms of Service and applies where DIZENZ LLC ("DIZENZ", "Processor") processes personal data on behalf of a customer ("Controller") subject to the GDPR, UK GDPR, or a substantially similar law, in connection with a Service.

Where the DPA conflicts with the Terms of Service on data-processing matters, the DPA controls.

01

1. Purpose and scope

This DPA reflects the parties’ agreement on the processing of personal data in connection with the Services, and forms part of the Terms of Service by reference for customers who require it.

02

2. Definitions

"Personal Data", "Processing", "Controller", "Processor", and "Data Subject" have the meanings given in the GDPR. "Subprocessor" means a third party engaged by DIZENZ to process Personal Data on the Controller’s behalf.

03

3. Processing instructions

DIZENZ will process Personal Data only on the Controller’s documented instructions, as necessary to provide the Service, comply with law, or as otherwise agreed in writing. DIZENZ will inform the Controller if, in its opinion, an instruction infringes applicable data protection law.

04

4. Confidentiality

DIZENZ ensures that personnel authorized to process Personal Data are bound by confidentiality obligations.

05

5. Security measures

DIZENZ implements appropriate technical and organizational measures to protect Personal Data, including:

  • Encryption of data in transit (TLS) between the Controller, the Service, and our hosting infrastructure.
  • Access controls limiting Personal Data access to personnel who need it to provide the Service.
  • Reliance on subprocessors that maintain industry-standard security certifications (e.g., SOC 2) where applicable.
06

6. Subprocessors

The Controller authorizes DIZENZ to engage the following subprocessors, and any others added under Section 6’s update process:

SubprocessorPurposeLocation
Stripe, Inc.Payment processing and subscription billingUnited States
ResendTransactional email deliveryUnited States
Vercel Inc.Application hosting and content deliveryUnited States
Google LLC (Google Analytics)Website usage analytics, where enabled and consented toUnited States

DIZENZ will provide notice of a new subprocessor by updating this page and, where reasonably practicable, notifying customers who have an active DPA. A Controller may object to a new subprocessor on reasonable data-protection grounds by contacting us within 15 days of the update.

07

7. Assistance with data subject requests

DIZENZ will assist the Controller, to a reasonable extent, in responding to requests from data subjects exercising their rights under applicable law, taking into account the nature of the processing.

08

8. International transfers

Where Personal Data is transferred outside the EEA, UK, or Switzerland, DIZENZ relies on appropriate safeguards, including Standard Contractual Clauses, to the extent required by applicable law.

09

9. Audits

On reasonable written request, and no more than once per year absent a security incident, DIZENZ will make available information reasonably necessary to demonstrate compliance with this DPA.

10

10. Liability

Each party’s liability under this DPA is subject to the limitations of liability set out in the Terms of Service.

11

11. Term and termination

This DPA remains in effect for as long as DIZENZ processes Personal Data on the Controller’s behalf under the Terms of Service.

Questions about this DPA can be sent to agus@dizenz.com.