This Data Processing Addendum ("DPA") supplements our Terms of Service and applies where DIZENZ LLC ("DIZENZ", "Processor") processes personal data on behalf of a customer ("Controller") subject to the GDPR, UK GDPR, or a substantially similar law, in connection with a Service.
Where the DPA conflicts with the Terms of Service on data-processing matters, the DPA controls.
1. Purpose and scope
This DPA reflects the parties’ agreement on the processing of personal data in connection with the Services, and forms part of the Terms of Service by reference for customers who require it.
2. Definitions
"Personal Data", "Processing", "Controller", "Processor", and "Data Subject" have the meanings given in the GDPR. "Subprocessor" means a third party engaged by DIZENZ to process Personal Data on the Controller’s behalf.
3. Processing instructions
DIZENZ will process Personal Data only on the Controller’s documented instructions, as necessary to provide the Service, comply with law, or as otherwise agreed in writing. DIZENZ will inform the Controller if, in its opinion, an instruction infringes applicable data protection law.
4. Confidentiality
DIZENZ ensures that personnel authorized to process Personal Data are bound by confidentiality obligations.
5. Security measures
DIZENZ implements appropriate technical and organizational measures to protect Personal Data, including:
- Encryption of data in transit (TLS) between the Controller, the Service, and our hosting infrastructure.
- Access controls limiting Personal Data access to personnel who need it to provide the Service.
- Reliance on subprocessors that maintain industry-standard security certifications (e.g., SOC 2) where applicable.
6. Subprocessors
The Controller authorizes DIZENZ to engage the following subprocessors, and any others added under Section 6’s update process:
| Subprocessor | Purpose | Location |
|---|---|---|
| Stripe, Inc. | Payment processing and subscription billing | United States |
| Resend | Transactional email delivery | United States |
| Vercel Inc. | Application hosting and content delivery | United States |
| Google LLC (Google Analytics) | Website usage analytics, where enabled and consented to | United States |
DIZENZ will provide notice of a new subprocessor by updating this page and, where reasonably practicable, notifying customers who have an active DPA. A Controller may object to a new subprocessor on reasonable data-protection grounds by contacting us within 15 days of the update.
7. Assistance with data subject requests
DIZENZ will assist the Controller, to a reasonable extent, in responding to requests from data subjects exercising their rights under applicable law, taking into account the nature of the processing.
8. International transfers
Where Personal Data is transferred outside the EEA, UK, or Switzerland, DIZENZ relies on appropriate safeguards, including Standard Contractual Clauses, to the extent required by applicable law.
9. Audits
On reasonable written request, and no more than once per year absent a security incident, DIZENZ will make available information reasonably necessary to demonstrate compliance with this DPA.
10. Liability
Each party’s liability under this DPA is subject to the limitations of liability set out in the Terms of Service.
11. Term and termination
This DPA remains in effect for as long as DIZENZ processes Personal Data on the Controller’s behalf under the Terms of Service.
Questions about this DPA can be sent to agus@dizenz.com.