ALYT
Home Legal

Data Processing Addendum

Version 1.0 (starting-point template)  |  Published: September 6, 2026

What this page is, and is not. This is a starting-point Data Processing Addendum ("DPA") intended for a business customer or integration partner for whom Fizzify Inc. processes personal data on their behalf — for example, a property management company deploying ALYT across multiple units, or an organization building on ALYT's developer platform in a way that involves processing data as our customer's instructed processor. It is published as a reference and a basis for negotiation, not as a document that automatically applies to every ALYT user. A household using ALYT in their own home is a data subject and, typically, the controller of their own home's data under our standard Terms of Service and Privacy Policy — this DPA is not what governs that relationship. If you are a business customer who needs an executed DPA, contact us at the address below; we have not fabricated any Standard Contractual Clauses annex or specific execution details here, and a genuinely executed version will be negotiated and signed individually.

1. Definitions

Terms used in this DPA have the meaning given to them in the EU General Data Protection Regulation (GDPR) and the UK GDPR, as applicable, unless otherwise defined here. "Agreement" means the underlying commercial agreement between Fizzify Inc. and the Customer to which this DPA is attached. "Customer Personal Data" means personal data processed by Fizzify Inc. on behalf of the Customer in the course of providing the services described in the Agreement.

2. Roles of the Parties

Where the Customer determines the purposes and means of processing Customer Personal Data, and Fizzify Inc. processes it only on the Customer's documented instructions, Fizzify Inc. acts as processor and the Customer acts as controller, within the meaning of the GDPR. Where the parties' relationship instead makes each an independent controller of certain data (for example, ALYT's own account and billing data about the Customer's authorized users), that data is not subject to this DPA and is instead governed by our standard Privacy Policy.

3. Fizzify Inc.'s Obligations as Processor

Fizzify Inc. will:

  1. process Customer Personal Data only on the Customer's documented instructions, including regarding international transfers, unless required to do otherwise by applicable law (in which case Fizzify Inc. will inform the Customer of that legal requirement before processing, unless the law prohibits this);
  2. ensure that persons authorized to process Customer Personal Data are subject to a duty of confidentiality;
  3. implement appropriate technical and organizational measures to ensure a level of security appropriate to the risk, consistent with those described in our Security & Responsible Disclosure page;
  4. engage a subprocessor only with the Customer's general or specific authorization, and, where general authorization applies, notify the Customer of any intended change concerning the addition or replacement of a subprocessor, giving the Customer the opportunity to object on reasonable grounds — see our current Subprocessors list;
  5. impose the same data protection obligations set out in this DPA on any subprocessor, by way of a contract or other legal act;
  6. taking into account the nature of the processing, assist the Customer by appropriate technical and organizational measures, insofar as possible, in fulfilling the Customer's obligation to respond to requests from data subjects exercising their rights;
  7. assist the Customer in ensuring compliance with obligations relating to the security of processing, breach notification, data protection impact assessments, and consultation with supervisory authorities, taking into account the nature of processing and the information available to Fizzify Inc.;
  8. at the Customer's choice, delete or return all Customer Personal Data after the end of the provision of services relating to processing, and delete existing copies unless applicable law requires storage;
  9. make available to the Customer information reasonably necessary to demonstrate compliance with this DPA, and allow for and contribute to audits, including inspections, conducted by the Customer or an auditor mandated by the Customer, subject to reasonable notice and confidentiality.

4. Confidentiality and Security

Fizzify Inc. maintains the security measures described in our Security & Responsible Disclosure page, including encryption in transit, hashed and sealed storage of sensitive credentials, tenant isolation, access controls, and audit logging. Specific additional security commitments (a security questionnaire response, a penetration test summary, or similar) can be provided as part of DPA negotiation.

5. Subprocessors

The Customer provides general authorization for Fizzify Inc. to engage the subprocessors listed at alyt.com/legal/subprocessors.html, as updated from time to time, subject to the notice-and-objection process described in Section 3.4 above. Fizzify Inc. will notify Customers who have executed this DPA of a material change to that list through the contact method specified in their Agreement, or by email to the address on file.

6. Data Subject Requests

Where a data subject makes a request directly to Fizzify Inc. concerning Customer Personal Data, Fizzify Inc. will, unless legally prohibited from doing so, promptly notify the Customer and will not respond to the request itself, except to acknowledge receipt and redirect the data subject to the Customer, unless otherwise instructed by the Customer.

7. Personal Data Breach Notification

Fizzify Inc. will notify the Customer without undue delay after becoming aware of a personal data breach affecting Customer Personal Data, and will provide information reasonably available to it to assist the Customer in meeting its own breach notification obligations under applicable law. [LEGAL-VERIFY: a specific maximum notification window (e.g., "within 48 hours") is a negotiable term to be fixed in the executed version of this DPA with each Customer, and is not fabricated here as a fixed default.]

8. International Transfers

Where Customer Personal Data is transferred from the European Economic Area, the United Kingdom, or Switzerland to the United States or another country not deemed to provide an adequate level of data protection, the parties will rely on the European Commission's Standard Contractual Clauses (or the equivalent UK and Swiss transfer mechanisms) as the transfer safeguard, incorporated into the executed version of this DPA as an annex once agreed. [LEGAL-VERIFY: Fizzify Inc. has not, as of this document's publication date, completed formal execution of SCCs as a general matter across all subprocessors — see the equivalent note in our Privacy Policy, Section 25. This will be completed as part of finalizing any specific customer's DPA and should not be assumed to exist in advance of that.]

9. Return or Deletion of Data

Upon termination of the underlying Agreement, and at the Customer's written instruction, Fizzify Inc. will either return Customer Personal Data to the Customer in a commonly used, machine-readable format, or delete it, within a period to be specified in the executed DPA, except to the extent applicable law requires continued storage of some or all of it.

10. Annexes (To Be Completed Per Customer)

An executed DPA with a specific Customer will include annexes describing, specifically: (A) the categories of data subjects and categories of personal data processed; (B) the nature and purpose of processing; (C) the duration of processing; (D) the technical and organizational security measures in place; and (E), where applicable, the Standard Contractual Clauses or equivalent transfer mechanism. These are deliberately not pre-filled with invented specifics here, since they must accurately describe each Customer's actual use of ALYT.

11. Requesting an Executed DPA

If you are a business customer or integration partner and need a signed, customer-specific DPA, email privacy@alyt.co with a description of your intended use of ALYT and the categories of data involved. We will work with you (and, where appropriate, outside counsel) to complete and execute a version of this document specific to your relationship with us.

Contact

Fizzify Inc.
30 N Gould St STE N
Sheridan, WY 82801
United States

privacy@alyt.co


Last updated: September 6, 2026