Data Processing Agreement
Last updated October 4, 2026
Effective October 4, 2026.
This Data Processing Agreement (the "DPA") is between IzzyOS LLC, a Wyoming limited liability company at 1309 Coffeen Avenue, Suite 1200, Sheridan, Wyoming 82801, USA ("IzzyOS"), and the customer named on the IzzyOS account that accepts or signs it ("Customer"). It forms part of the IzzyOS Terms of Service or other agreement between the parties for the IzzyOS service (the "Agreement").
1. What this DPA covers
1.1 This DPA applies when IzzyOS processes Customer Personal Data while providing the IzzyOS service (the "Service"). "Customer Personal Data" means personal data about Customer's contacts, leads, clients, staff and other people that Customer puts into the Service or that the Service collects for Customer.
1.2 For Customer Personal Data, Customer is the controller and IzzyOS is the processor. If Customer is itself a processor for someone else, IzzyOS is Customer's subprocessor, and Customer confirms that its own controller has approved this arrangement.
1.3 IzzyOS acts as a controller only for the data it needs to run Customer's account, such as login details, billing records and support emails. That data is covered by the IzzyOS Privacy Policy, not this DPA.
1.4 "Data Protection Laws" means the laws that apply to the processing, including the EU General Data Protection Regulation 2016/679 ("GDPR"), the GDPR as it applies in the United Kingdom ("UK GDPR") with the UK Data Protection Act 2018, the Swiss Federal Act on Data Protection, and US state privacy laws such as the California Consumer Privacy Act.
2. How IzzyOS processes Customer Personal Data
2.1 IzzyOS will process Customer Personal Data only on Customer's documented instructions. Customer's instructions are the Agreement, this DPA, and the way Customer sets up and uses the Service, including what Customer asks Kai and other features to do.
2.2 IzzyOS will tell Customer if it believes an instruction breaks Data Protection Laws. IzzyOS may then pause that instruction until Customer changes or confirms it.
2.3 If a law requires IzzyOS to process Customer Personal Data in another way, IzzyOS will tell Customer first, unless that law forbids it.
2.4 IzzyOS will not sell or share Customer Personal Data (including sharing for cross-context behavioral advertising), and will not use it for any purpose outside the business relationship with Customer. For US state privacy laws, IzzyOS acts as Customer's service provider or processor.
2.5 Customer is responsible for having a lawful basis for the processing, for the accuracy of the data, and for the notices and consents its contacts need, including consent for marketing messages and calls.
2.6 The details of the processing are in Annex I.
3. People who handle the data
3.1 IzzyOS will make sure everyone it allows to process Customer Personal Data is bound by a duty of confidentiality.
3.2 IzzyOS will give access only to people who need it to run, support or secure the Service.
4. Security
4.1 IzzyOS will use technical and organizational measures that are appropriate to the risk of the processing, as Article 32 of the GDPR requires. Annex II describes these measures.
4.2 IzzyOS may update these measures over time, as long as the update does not lower the overall level of protection.
5. Subprocessors
5.1 Customer gives IzzyOS general permission to use subprocessors to provide the Service. The current list, with what each one does and where it processes data, is published at izzyos.com/legal/sub-processors. That list is Annex III.
5.2 IzzyOS will have a written agreement with each subprocessor that protects Customer Personal Data at least as well as this DPA requires, to the extent the service the subprocessor provides allows.
5.3 IzzyOS will tell Customer at least 30 days before it adds or replaces a subprocessor, by updating the published list and emailing the account owner. If the change is needed urgently to keep the Service secure or running, IzzyOS will tell Customer as soon as it reasonably can.
5.4 Customer may object to a new subprocessor on reasonable data protection grounds by emailing privacy@izzyos.com within that notice period. The parties will talk in good faith about a solution. If they cannot agree, Customer may stop using the part of the Service that depends on that subprocessor, or end the Agreement, without an early termination fee.
5.5 IzzyOS remains responsible to Customer for the work of its subprocessors under this DPA.
5.6 Some services are used only when Customer connects them, such as Customer's own Google, Meta or Fathom account. Data that Customer sends to its own account at such a service is governed by Customer's agreement with that service.
6. Requests from individuals and other help
6.1 The Service lets Customer find, export, correct and delete a contact's data, and lets Customer's contacts unsubscribe from marketing. Customer should use these tools first.
6.2 If IzzyOS receives a request from a person about Customer Personal Data, it will pass the request to Customer and will not answer it, unless Customer asks IzzyOS to or a law requires it.
6.3 Where Customer cannot handle a request with the Service's tools, IzzyOS will give reasonable help so Customer can respond.
6.4 IzzyOS will give Customer reasonable help with data protection impact assessments and with consultations with a supervisory authority, using the information IzzyOS has about the processing.
6.5 IzzyOS may charge a reasonable fee for help under 6.3 and 6.4 that goes beyond the normal use of the Service. IzzyOS will tell Customer the fee before doing the work.
7. Security incidents
7.1 If IzzyOS becomes aware of a breach of security that leads to the accidental or unlawful destruction, loss, change, disclosure of, or access to Customer Personal Data (a "Security Incident"), it will tell Customer without undue delay and no later than 72 hours after becoming aware of it.
7.2 The notice will describe what happened, the kinds and rough amounts of data and people involved, the likely effects, and what IzzyOS is doing about it, as far as IzzyOS knows at the time. IzzyOS will send more information as it learns it.
7.3 IzzyOS will take reasonable steps to contain the Security Incident and limit its harm.
7.4 Telling Customer about a Security Incident is not an admission of fault.
8. Audits
8.1 IzzyOS will make available the information Customer reasonably needs to show that IzzyOS is meeting this DPA.
8.2 Once every 12 months, or after a Security Incident, Customer may send IzzyOS a written security questionnaire. IzzyOS will answer it within a reasonable time.
8.3 If a supervisory authority requires more, or the answers are not enough to show compliance, Customer or an independent auditor bound by confidentiality may carry out an audit. The parties will agree the scope, timing and cost in advance, with at least 30 days' notice, during normal business hours, and in a way that does not disrupt the Service or expose other customers' data.
9. International transfers
9.1 IzzyOS is based in the United States and stores Customer Personal Data in the United States. The places where IzzyOS and its subprocessors process data are listed at izzyos.com/legal/data-location and izzyos.com/legal/sub-processors.
9.2 EU transfers. When Customer Personal Data subject to the GDPR is transferred to IzzyOS, the Standard Contractual Clauses approved by the European Commission in Implementing Decision (EU) 2021/914 (the "EU SCCs") apply and are part of this DPA. Module Two (controller to processor) applies when Customer is a controller, and Module Three (processor to processor) applies when Customer is a processor. For the EU SCCs: (a) Customer is the data exporter and IzzyOS is the data importer; (b) the optional docking clause in Clause 7 applies; (c) under Clause 9, Option 2 (general written authorization) applies, with the notice period in section 5.3; (d) the optional wording in Clause 11 does not apply; (e) under Clause 13, the supervisory authority is the one that is competent for Customer; (f) under Clauses 17 and 18, the EU SCCs are governed by the law of Ireland and disputes go to the courts of Ireland; and (g) Annexes I, II and III of this DPA complete the annexes of the EU SCCs.
9.3 UK transfers. When Customer Personal Data subject to the UK GDPR is transferred to IzzyOS, the International Data Transfer Addendum to the EU SCCs issued by the UK Information Commissioner (version B1.0, in force from 21 March 2022) (the "UK Addendum") applies and is part of this DPA. For the UK Addendum: Table 1 is completed with the parties' details in this DPA; Table 2 refers to the EU SCCs as set out in section 9.2; Table 3 is completed by Annexes I, II and III; and for Table 4, either party may end the UK Addendum as set out in its Section 19.
9.4 Swiss transfers. When Customer Personal Data subject to the Swiss Federal Act on Data Protection is transferred to IzzyOS, the EU SCCs apply as set out in section 9.2, with these changes: the Swiss Federal Data Protection and Information Commissioner is the competent supervisory authority, references to the GDPR include the Swiss Act, and the term "member state" does not prevent people in Switzerland from bringing claims where they normally live.
9.5 If a transfer mechanism in this section stops being valid, the parties will work together in good faith to put a valid one in place.
9.6 If the EU SCCs or the UK Addendum conflict with the rest of this DPA or the Agreement, the EU SCCs or the UK Addendum control.
10. Deleting or returning data
10.1 While the Agreement is in force, Customer can export and delete Customer Personal Data using the Service, including the contact export and delete tools and the account export and account deletion tools in Settings.
10.2 When the Agreement ends, IzzyOS will delete or return Customer Personal Data, at Customer's choice. Customer may export its data for 30 days. After that, IzzyOS will delete Customer Personal Data from the Service, unless a law requires IzzyOS to keep some of it. Copies in backups are deleted as the backups expire on their normal cycle, and are kept protected and unused until then.
10.3 On Customer's written request, IzzyOS will confirm the deletion in writing.
11. Liability
Each party's liability under this DPA is subject to the limits and exclusions of liability in the Agreement. Nothing in this DPA limits a person's rights under the EU SCCs or the UK Addendum.
12. Order of precedence
If this DPA conflicts with the Agreement, this DPA controls for the processing of Customer Personal Data. Otherwise the Agreement controls, including its terms on governing law and disputes, except as section 9 says for the EU SCCs and the UK Addendum.
13. Changes
IzzyOS may update this DPA when the law or the Service changes. IzzyOS will give at least 30 days' notice of a change that reduces Customer's protection. A signed copy keeps the version Customer signed.
14. Contact
Questions, requests and objections: privacy@izzyos.com, or IzzyOS LLC, 1309 Coffeen Avenue, Suite 1200, Sheridan, Wyoming 82801, USA. Legal notices: legal@izzyos.com.
Annex I. Description of the processing
A. Parties. Data exporter: Customer, the controller (or processor), whose name and contact details are on its IzzyOS account. Activities: using the Service to run its marketing, sales and support. Data importer: IzzyOS LLC, the processor, contact privacy@izzyos.com. Activities: providing the Service.
B. Categories of data subjects (people whose data is processed): Customer's contacts, leads, prospects, clients, event and webinar attendees, website and funnel visitors, people who call or text Customer's numbers, and Customer's own staff and users.
C. Kinds of personal data: names, email addresses, phone numbers, postal addresses, company and job details, messages and emails, call audio and transcripts, meeting notes and recordings Customer imports, form answers, booking details, purchase and payment status (card details stay with Stripe), website and funnel activity, consent and unsubscribe records, and notes and summaries the Service creates about a contact.
D. Sensitive data: the Service is not designed for special category data, and Customer should not put such data into it. If Customer does, Customer is responsible for having a lawful basis, and the measures in Annex II apply.
E. How often: continuously, for as long as Customer uses the Service.
F. Nature and purpose: storing, organizing and analyzing data; sending emails, texts and calls on Customer's instructions; running AI features that read and write content for Customer; publishing Customer's pages and funnels; booking meetings; and supporting and securing the Service.
G. How long: for the term of the Agreement and the deletion period in section 10.
H. Subprocessors: as listed in Annex III, for the purposes and in the places listed there.
I. Competent supervisory authority: as set out in section 9.
Annex II. Technical and organizational measures
- Encryption: data is encrypted in transit with TLS and encrypted at rest by our database and hosting providers.
- Separation of customers: each customer's data is separated in the database with row-level security rules, so one account cannot read another account's data.
- Access control: production access is limited to the people who need it, using individual accounts. Secrets and API keys are kept in managed secret stores and never in source code.
- Monitoring: errors and unusual activity are monitored, and changes to sensitive account settings are logged.
- Change management: code changes go through review and automated tests before they reach production.
- Backups and recovery: the database is backed up by our database provider so that data can be restored after a failure.
- Vendor review: IzzyOS chooses subprocessors that publish their own security and data protection commitments, and lists them in Annex III.
- Help for individuals' rights: the Service includes tools to export, correct and delete a contact's data and to honor unsubscribes.
- AI providers: IzzyOS uses AI providers under business terms that do not allow them to train their models on the data IzzyOS sends, where the provider offers such terms.
Annex III. Subprocessors
The current list is published at izzyos.com/legal/sub-processors. It shows each subprocessor, what it does for IzzyOS, what personal data it handles, and where it processes data.