Privacy Addendum

    Last updated: April 2, 2026

    1. Data Processing Agreement

    This Privacy Addendum supplements the Inzata Privacy Policy and constitutes a Data Processing Agreement (DPA) as required by applicable data protection laws including GDPR, CCPA, and other regional regulations.

    2. Roles and Responsibilities

    For the purposes of data protection laws, the customer is the Data Controller and Inzata acts as the Data Processor. Inzata processes personal data only on documented instructions from the customer.

    3. Sub-processors

    Inzata may engage sub-processors to assist in providing the services. A current list of sub-processors is available upon request. Customers will be notified of changes to sub-processors with 30 days' advance notice.

    4. Data Subject Rights

    Inzata will assist customers in responding to data subject requests including access, rectification, erasure, portability, and restriction of processing, to the extent required by applicable law.

    5. Data Transfers

    Where personal data is transferred outside the European Economic Area, Inzata ensures adequate safeguards through Standard Contractual Clauses (SCCs) or other approved transfer mechanisms.

    6. Data Retention and Deletion

    Upon termination of the service agreement, Inzata will delete or return all customer personal data within 90 days, unless retention is required by applicable law.

    7. Security Measures

    Inzata implements appropriate technical and organizational measures to protect personal data, as described in our Security Policies. These measures are regularly reviewed and updated.

    8. Breach Notification

    In the event of a personal data breach, Inzata will notify the customer without undue delay and no later than 72 hours after becoming aware of the breach.