Data Processing Addendum
1. Definitions
Terms used in this DPA have the meaning given to them in the EU General Data Protection Regulation (GDPR) and the UK GDPR, as applicable, unless otherwise defined here. "Agreement" means the underlying commercial agreement between Fizzify Inc. and the Customer to which this DPA is attached. "Customer Personal Data" means personal data processed by Fizzify Inc. on behalf of the Customer in the course of providing the services described in the Agreement.
2. Roles of the Parties
Where the Customer determines the purposes and means of processing Customer Personal Data, and Fizzify Inc. processes it only on the Customer's documented instructions, Fizzify Inc. acts as processor and the Customer acts as controller, within the meaning of the GDPR. Where the parties' relationship instead makes each an independent controller of certain data (for example, ALYT's own account and billing data about the Customer's authorized users), that data is not subject to this DPA and is instead governed by our standard Privacy Policy.
3. Fizzify Inc.'s Obligations as Processor
Fizzify Inc. will:
- process Customer Personal Data only on the Customer's documented instructions, including regarding international transfers, unless required to do otherwise by applicable law (in which case Fizzify Inc. will inform the Customer of that legal requirement before processing, unless the law prohibits this);
- ensure that persons authorized to process Customer Personal Data are subject to a duty of confidentiality;
- implement appropriate technical and organizational measures to ensure a level of security appropriate to the risk, consistent with those described in our Security & Responsible Disclosure page;
- engage a subprocessor only with the Customer's general or specific authorization, and, where general authorization applies, notify the Customer of any intended change concerning the addition or replacement of a subprocessor, giving the Customer the opportunity to object on reasonable grounds — see our current Subprocessors list;
- impose the same data protection obligations set out in this DPA on any subprocessor, by way of a contract or other legal act;
- taking into account the nature of the processing, assist the Customer by appropriate technical and organizational measures, insofar as possible, in fulfilling the Customer's obligation to respond to requests from data subjects exercising their rights;
- assist the Customer in ensuring compliance with obligations relating to the security of processing, breach notification, data protection impact assessments, and consultation with supervisory authorities, taking into account the nature of processing and the information available to Fizzify Inc.;
- at the Customer's choice, delete or return all Customer Personal Data after the end of the provision of services relating to processing, and delete existing copies unless applicable law requires storage;
- make available to the Customer information reasonably necessary to demonstrate compliance with this DPA, and allow for and contribute to audits, including inspections, conducted by the Customer or an auditor mandated by the Customer, subject to reasonable notice and confidentiality.
4. Confidentiality and Security
Fizzify Inc. maintains the security measures described in our Security & Responsible Disclosure page, including encryption in transit, hashed and sealed storage of sensitive credentials, tenant isolation, access controls, and audit logging. Specific additional security commitments (a security questionnaire response, a penetration test summary, or similar) can be provided as part of DPA negotiation.
5. Subprocessors
The Customer provides general authorization for Fizzify Inc. to engage the subprocessors listed at alyt.com/legal/subprocessors.html, as updated from time to time, subject to the notice-and-objection process described in Section 3.4 above. Fizzify Inc. will notify Customers who have executed this DPA of a material change to that list through the contact method specified in their Agreement, or by email to the address on file.
6. Data Subject Requests
Where a data subject makes a request directly to Fizzify Inc. concerning Customer Personal Data, Fizzify Inc. will, unless legally prohibited from doing so, promptly notify the Customer and will not respond to the request itself, except to acknowledge receipt and redirect the data subject to the Customer, unless otherwise instructed by the Customer.
7. Personal Data Breach Notification
Fizzify Inc. will notify the Customer without undue delay after becoming aware of a personal data breach affecting Customer Personal Data, and will provide information reasonably available to it to assist the Customer in meeting its own breach notification obligations under applicable law. [LEGAL-VERIFY: a specific maximum notification window (e.g., "within 48 hours") is a negotiable term to be fixed in the executed version of this DPA with each Customer, and is not fabricated here as a fixed default.]
8. International Transfers
Where Customer Personal Data is transferred from the European Economic Area, the United Kingdom, or Switzerland to the United States or another country not deemed to provide an adequate level of data protection, the parties will rely on the European Commission's Standard Contractual Clauses (or the equivalent UK and Swiss transfer mechanisms) as the transfer safeguard, incorporated into the executed version of this DPA as an annex once agreed. [LEGAL-VERIFY: Fizzify Inc. has not, as of this document's publication date, completed formal execution of SCCs as a general matter across all subprocessors — see the equivalent note in our Privacy Policy, Section 25. This will be completed as part of finalizing any specific customer's DPA and should not be assumed to exist in advance of that.]
9. Return or Deletion of Data
Upon termination of the underlying Agreement, and at the Customer's written instruction, Fizzify Inc. will either return Customer Personal Data to the Customer in a commonly used, machine-readable format, or delete it, within a period to be specified in the executed DPA, except to the extent applicable law requires continued storage of some or all of it.
10. Annexes (To Be Completed Per Customer)
An executed DPA with a specific Customer will include annexes describing, specifically: (A) the categories of data subjects and categories of personal data processed; (B) the nature and purpose of processing; (C) the duration of processing; (D) the technical and organizational security measures in place; and (E), where applicable, the Standard Contractual Clauses or equivalent transfer mechanism. These are deliberately not pre-filled with invented specifics here, since they must accurately describe each Customer's actual use of ALYT.
11. Requesting an Executed DPA
If you are a business customer or integration partner and need a signed, customer-specific DPA, email privacy@alyt.co with a description of your intended use of ALYT and the categories of data involved. We will work with you (and, where appropriate, outside counsel) to complete and execute a version of this document specific to your relationship with us.
Contact
Fizzify Inc.
30 N Gould St STE N
Sheridan, WY 82801
United States
Last updated: September 6, 2026