How Dzati processes personal data on your behalf as your processor.
This Data Processing Addendum ("DPA") forms part of the agreement between you ("Customer", the data controller) and Dzati ("Dzati", the data processor) and applies where Dzati processes personal data on the Customer's behalf in providing the Service. Where there is a conflict, this DPA prevails for data-protection matters.
The Customer determines the purposes and means of processing the personal data collected through the Service (the "Customer Data") and is the controller; Dzati processes Customer Data only on the Customer's documented instructions, including those set out in this DPA and the Service's configuration.
The Customer is responsible for having a lawful basis to collect Customer Data, for providing required notices to and (where applicable) obtaining consent from its visitors, and for the instructions it gives Dzati.
Dzati ensures that personnel authorised to process Customer Data are bound by confidentiality obligations.
Dzati implements appropriate technical and organisational measures, including: encryption of data in transit; hashed credentials; role-based access controls and least-privilege access; logically separated event storage; monitoring and backups; and secure development practices.
The Customer authorises Dzati to engage sub-processors (e.g. hosting/infrastructure providers, the payment processor, and email delivery) to process Customer Data. Dzati imposes data-protection terms on each sub-processor no less protective than this DPA and remains responsible for their performance. We will inform the Customer of material changes to our sub-processors and allow a reasonable opportunity to object.
Taking into account the nature of the processing, Dzati provides reasonable assistance (including appropriate technical measures) to help the Customer respond to data-subject requests to exercise their rights. If Dzati receives such a request directly, it will direct the data subject to the Customer.
Dzati will notify the Customer without undue delay after becoming aware of a personal data breach affecting Customer Data, and will provide reasonable information to help the Customer meet its breach-notification obligations.
Where Customer Data is transferred across borders, Dzati uses an appropriate transfer mechanism (such as the Standard Contractual Clauses) where required by applicable law.
Dzati makes available information reasonably necessary to demonstrate compliance with this DPA and allows for audits, conducted on reasonable notice, subject to confidentiality and not unreasonably disrupting Dzati's operations.
On termination of the Service, Dzati will delete or return Customer Data within a reasonable period, except where retention is required by law. The Customer can also delete sites and their data from the dashboard at any time.
To raise a data-protection matter or request a signed copy of this DPA, email admin@dzati.com.