Whyzr Sign in

Whyzr Data Processing Addendum

Last updated

This Data Processing Addendum (“DPA”) forms part of the Whyzr Terms of Service between StartupEdge LLC, doing business as Whyzr (“we”), and the Customer. It applies automatically whenever we process Customer Personal Data. Terms defined in the Terms of Service have the same meaning here.

1 Roles and scope

1.1 Definitions.

1.2 Roles. The Customer is the controller of Customer Personal Data and we are its processor. Where the Customer is a firm acting for its client companies, the firm may itself be a processor for each client; we are then the firm’s subprocessor. Each of us will comply with the Data Protection Laws that apply to it.

1.3 Firms. A firm confirms that it has its clients’ authorization to use Whyzr and the Subprocessors in Annex 3. The firm is our single point of contact for its clients, and its clients exercise their rights through the firm.

1.4 What this DPA does not cover. Personal data we control for our own purposes, such as account details, billing contacts and Usage Data, is covered by our Privacy Policy, not this DPA.

1.5 Order of precedence. On processing Customer Personal Data, this DPA controls over the Terms of Service. Any Standard Contractual Clauses incorporated under section 2.14 control over this DPA.

2 Our commitments

2.1 Instructions. We process Customer Personal Data only on the Customer’s documented instructions. Those instructions are the Terms of Service, this DPA, and the Customer’s use and configuration of the Service, including actions by its Authorized Users and agents. We will tell the Customer if we believe an instruction breaks Data Protection Laws. If the law requires other processing, we will tell the Customer first unless the law forbids it.

2.2 Customer’s responsibilities. The Customer is responsible for the lawfulness of its instructions and for giving the notices and obtaining the consents needed for the processing described in the Terms, including processing by AI.

2.3 De-identified data. The Customer authorizes us to create de-identified Benchmark Data from Customer Data under section 6 of the Terms, subject to its opt-out. Creating Benchmark Data is processing for the Customer; once created, it contains no personal data and we use it for our own purposes. Usage Data is not Customer Personal Data and is covered by our Privacy Policy.

2.4 US state privacy laws. Where those laws apply, we act as the Customer’s service provider or processor. We will not sell or share Customer Personal Data, or retain, use or disclose it outside our direct business relationship with the Customer or for any purpose other than providing the Service and the other business purposes the law permits, including de-identifying data under section 2.3. We will not combine it with personal data from other sources except as those laws permit. We will tell the Customer if we can no longer meet these obligations.

2.5 Our people. Only personnel who need access to provide the Service may access Customer Personal Data. They are bound by confidentiality duties, and each access through the Service is recorded in the Customer’s audit log. Access outside the Service, such as restoring a backup, is limited to emergencies and recorded in our internal records.

2.6 Security. We maintain at least the measures in Annex 2. We may update them, but will not reduce the overall level of protection.

2.7 AI processing. The Customer authorizes processing by the AI Subprocessors in Annex 3, as described in section 5 of the Terms. We will not use Customer Personal Data to train or fine-tune AI models. We will notify the Customer before turning on any feature that lengthens retention at an AI Subprocessor.

2.8 Subprocessors. The Customer authorizes the Subprocessors in Annex 3. We will give at least 14 days’ notice before adding or replacing one, by emailing the Owner of each customer workspace and updating whyzr.com/legal/subprocessors. If we must replace a Subprocessor urgently to protect security or keep the Service running, we may do so immediately and will give notice as soon as reasonably possible. The Customer may object on reasonable data protection grounds within the notice period, or within 14 days after notice of an urgent change. If we cannot resolve the objection, the Customer may end the affected subscription and receive a refund of prepaid fees for the rest of its term. We will bind each Subprocessor to data protection terms at least as protective as this DPA, and we remain responsible for its performance.

2.9 Requests from individuals. If someone contacts us to exercise their rights over Customer Personal Data, we will pass the request to the Customer and not answer it ourselves unless the Customer tells us to. We will help the Customer respond, mainly through Service features such as export and deletion.

2.10 Other assistance. We will give reasonable help with data protection impact assessments and consultations with regulators, taking into account the information available to us. We may charge for help beyond what the Service’s features provide.

2.11 Security Incidents. We will notify the Customer without undue delay, and in any case within 72 hours, after confirming a Security Incident. We will describe what happened, the data affected, the likely consequences and the steps taken, and update the Customer as we learn more. We will take reasonable steps to contain and fix it. Our notice is not an admission of fault.

2.12 Return and deletion. The Customer can export Customer Personal Data during its subscription and for 30 days after, once any overdue fees are paid (Terms 9.7). We delete it as described in section 11 of the Terms, and will confirm deletion in writing on request. Anything we must keep, such as data in backups awaiting overwrite or audit records, stays protected by this DPA and is not otherwise processed.

2.13 Audits. Once a year, on request, we will answer a reasonable security questionnaire and provide our security documentation, including our SOC 2 report once we have one. Where Data Protection Laws or a regulator require an on-site audit, the Customer may carry one out on 30 days’ notice, during business hours, at its own cost and under confidentiality obligations.

2.14 International transfers. We and our Subprocessors store and process Customer Personal Data in the United States. Our personnel and contractors may access it from other countries, under the same confidentiality and security obligations. For personal data from the EEA, UK or Switzerland, the EU Standard Contractual Clauses (Module 2 where the Customer is a controller, and Module 3 where it is a processor) and the UK Addendum are incorporated by reference. The Annexes to this DPA complete their annexes, and Clause 9 uses general authorisation with the notice period in section 2.8. The Clauses are governed by the law of Ireland, with disputes before the courts of Ireland. The UK Addendum is governed by the law of England and Wales, with disputes before its courts.

2.15 Liability. Each party’s liability under this DPA is subject to the limits in section 12 of the Terms, except where Data Protection Laws or the Standard Contractual Clauses do not allow it.

Annex 1: Details of processing

ItemDetail
Subject matterProviding the Whyzr reporting, forecasting and AI service under the Terms of Service
DurationThe term of the agreement, plus the deletion periods in section 11 of the Terms
Nature and purposeHosting, storing, importing, analysing, displaying, publishing and AI processing of Customer Data to produce reports, forecasts and answers for the Customer
Data subjectsThe Customer’s Authorized Users; people named in the Customer’s or its client companies’ records, such as customers, vendors, employees and contractors; people who open share links
Personal dataNames and business contact details; transaction details such as dates, amounts, invoice numbers and memos; pay amounts shown on payroll lines; headcount and salary assumptions in forecasts; AI chat content; audit records
Special categoriesNone intended. The Customer should not upload them
FrequencyContinuous

Annex 2: Security measures

Annex 3: Subprocessors

The current list is published at whyzr.com/legal/subprocessors and updated under section 2.8; that page controls. On the date of this DPA, it lists:

SubprocessorPurposeLocation
Vercel, Inc.Hosting and file storageUS
NeonDatabaseUS
Anthropic, PBCAI modelsUS
ResendEmail deliveryUS
SentryError monitoringUS
Google WorkspaceStaff email, including support messagesUS
Unified.toConnections to accounting and other systemsUS
InngestBackground jobs (record ids and counts only)US