IMPORTANT NOTICE TO CLIENTS
This Data Processing Agreement is incorporated into RizzDial’s Terms of Service available at https://rizzdial.com/terms and governs all data processing activities performed by RizzDial on behalf of its clients. This document is available for execution upon client request. MetaTech LLC, doing business as RizzDial, maintains a standardized data protection framework and generally does not accept client-requested modifications to this agreement. Clients requiring custom data processing terms should contact RizzDial’s legal department prior to execution.
ARTICLE 1: PURPOSE AND SCOPE OF AGREEMENT
1.1 Binding Agreement. This Data Processing Agreement, together with Schedules A, B, and C attached hereto (collectively, the “DPA”), constitutes a binding agreement between MetaTech LLC, doing business as RizzDial (“RizzDial,” “Processor,” or “we”), and the subscribing entity identified as Client (“Client,” “Controller,” or “you”). This DPA governs RizzDial’s Processing of Personal Information on behalf of Client in connection with RizzDial’s provision of telecommunications and customer engagement services.
1.2 Relationship to Service Agreement. This DPA operates in conjunction with and forms an integral part of the Master Service Agreement, Terms of Service, or other governing contract executed between RizzDial and Client (the “Service Agreement”). This DPA supplements and does not replace the Service Agreement.
1.3 Effective Date and Integration. This DPA becomes effective upon the earlier of: (i) execution by both parties’ authorized representatives, or (ii) the effective date specified in the Service Agreement or any related order form.
1.4 Precedence. In the event of any conflict or inconsistency between the terms of the Service Agreement and this DPA with respect to data protection matters, the provisions of this DPA shall control and supersede any conflicting or inconsistent provisions in the Service Agreement. This DPA supersedes and replaces any prior data processing agreement, data protection addendum, or similar document previously executed by the parties.
1.5 Regulatory Compliance Commitment. Both parties commit to full compliance with all applicable requirements of Data Protection Legislation in connection with their respective Processing activities under this DPA and the Service Agreement. This DPA establishes
minimum standards and does not limit, reduce, or replace either party’s independent obligations or rights under applicable Data Protection Legislation.
ARTICLE 2: ROLES AND RESPONSIBILITIES
2.1 RizzDial’s Role as Processor. For purposes of all applicable Data Protection Legislation, RizzDial acts exclusively as a Processor (or “service provider” under applicable U.S. privacy laws) with respect to Client Personal Information. RizzDial Processes Client Personal Information solely on behalf of Client and in accordance with Client’s documented instructions as set forth in this DPA.
2.2 Client’s Role. Client acts as either a Controller or Processor (or “business” under applicable U.S. privacy laws) with respect to the Personal Information it provides to RizzDial. Where Client acts as a Processor, Client represents that it has authority from the applicable Controller to enter into this DPA and to authorize RizzDial as a sub-processor.
2.3 Independent Compliance Obligations. Each party shall independently comply with its obligations under Data Protection Legislation. Nothing in this DPA shall relieve either party of its respective obligations under applicable laws or impose obligations on one party that properly belong to the other party under Data Protection Legislation.
ARTICLE 3: DEFINITIONS AND INTERPRETATION
3.1 Defined Terms. For purposes of this DPA, the following terms shall have the meanings specified below:
a. “CCPA” means the California Consumer Privacy Act of 2018, codified at California Civil Code Sections 1798.100 through 1798.199, as amended by the California Privacy Rights Act of 2020, together with all implementing regulations promulgated by the California Privacy Protection Agency.
b. “California Personal Information” means Personal Information that is subject to the protection and requirements of the CCPA.
c. “Client Personal Information” means any and all information relating to an identified or identifiable natural person where: (i) such information is contained within data provided by Client to RizzDial under the Service Agreement; and (ii) such information qualifies as personal data, personal information, or personally identifiable information protected under applicable Data Protection Legislation.
d. “Controller,” “Processor,” “Data Subject,” “Personal Data,” “Personal Data Breach,” “Process,” and “Processing” shall have the meanings ascribed to them (or to equivalent terms such as “business,” “service provider,” “consumer,” “personal information,” etc.) under applicable Data Protection Legislation.
e. “Data Protection Legislation” means all applicable laws, regulations, and binding regulatory guidance worldwide relating to the protection, privacy, security, and Processing of personal information, including but not limited to: (i) European Privacy Laws; (ii) the CCPA; (iii) other applicable U.S. federal and state privacy laws, including the Texas Data Privacy and Security Act; (iv) Canada’s Personal Information Protection and Electronic Documents Act (PIPEDA); and (v) all other applicable national, federal, state, provincial, or local data protection and privacy laws, in each case as amended, superseded, or replaced from time to time.
f. “Europe” means, collectively, the member states of the European Union, the member states of the European Economic Area, the United Kingdom of Great Britain and Northern Ireland, and Switzerland.
g. “European Personal Data” means Personal Information that is subject to the protection and requirements of European Privacy Laws.
h. “European Privacy Laws” means all data protection and privacy laws applicable in Europe, including: (i) Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data (the “GDPR”); (ii) the GDPR as it forms part of the domestic law of the United Kingdom by virtue of Section 3 of the European Union (Withdrawal) Act 2018, and as amended by the Data Protection, Privacy and Electronic Communications (Amendments etc.) (EU Exit) Regulations 2019 (the “UK GDPR”); (iii) the Swiss Federal Act on Data Protection of 25 September 2020 and its implementing ordinances (the “Swiss FADP”); (iv) Directive 2002/58/EC of the European Parliament and of the Council concerning the processing of personal data and the protection of privacy in the electronic communications sector; and (v) all national implementing legislation, regulations, and amendments to the foregoing, in each case as may be amended, superseded, or replaced.
i. “Personal Information” means any information relating to an identified or identifiable natural person, as defined under applicable Data Protection Legislation.
j. “Standard Contractual Clauses” means the standard contractual clauses for the transfer of personal data to third countries approved by the European Commission pursuant to Commission Implementing Decision (EU) 2021/914 of 4 June 2021, as currently available at https://ec.europa.eu/info/law/law-topic/data-protection/international-dimension-data-protection/standard-contractual-clauses-scc, and as may be amended, superseded, or replaced by the European Commission from time to time.
k. “Subprocessor” means any third-party Processor engaged by RizzDial to Process Client Personal Information on behalf of Client in connection with the provision of services under the Service Agreement.
l. “UK International Data Transfer Addendum” means the International Data Transfer Addendum to the EU Commission Standard Contractual Clauses, Version B1.0, issued by the Commissioner under Section 119A(1) of the Data Protection Act 2018 and in force 21 March 2022, as currently available at https://ico.org.uk/media/for-organisations/documents/4019539/international-data-transfer-adden dum.pdf, and as may be amended, superseded, or replaced.
3.2 Interpretation. References to “Articles,” “Sections,” and “Schedules” are to articles, sections, and schedules of this DPA unless otherwise specified. Headings are for convenience only and shall not affect interpretation. The words “including” and “include” shall be construed to mean “including without limitation.” References to statutory provisions include those provisions as amended, extended, or re-enacted from time to time.
ARTICLE 4: PROCESSING INSTRUCTIONS AND PARTICULARS
4.1 Documented Instructions. RizzDial shall Process Client Personal Information solely in accordance with Client’s documented instructions, except where Processing is required by applicable law, in which case RizzDial shall inform Client of such legal requirement before Processing (unless prohibited by law from doing so).
4.2 Scope of Instructions. The Service Agreement and this DPA constitute Client’s complete and final instructions to RizzDial regarding the Processing of Client Personal Information as of the effective date of this DPA. The parties may agree to additional or alternative Processing instructions through a subsequent written agreement signed by authorized representatives of both parties.
4.3 Instruction Compliance Assessment. If RizzDial reasonably determines that any instruction provided by Client would cause RizzDial to violate applicable Data Protection Legislation, RizzDial shall promptly inform Client of this assessment and shall not be required to comply with such instruction unless and until Client provides revised instructions that comply with applicable law or provides RizzDial with a legal opinion from qualified counsel confirming the instruction’s legality.
4.4 Processing Particulars. Schedule A to this DPA sets forth detailed information regarding: (i) the subject matter, nature, purpose, and duration of the Processing; (ii) the categories of Client Personal Information to be Processed; (iii) the categories of Data Subjects whose
Personal Information will be Processed; and (iv) the obligations and rights of Client as Controller or Processor.
ARTICLE 5: CLIENT RESPONSIBILITIES AND WARRANTIES
5.1 Legal Basis and Authority. Client represents, warrants, and covenants that:
a. Client has established all necessary legal bases under applicable Data Protection Legislation for the collection and Processing of all Client Personal Information, including but not limited to obtaining all required consents, providing all required privacy notices, conducting all required data protection impact assessments, and implementing all required safeguards;
b. Client has obtained all necessary rights, permissions, and authority to disclose, transfer, and provide Client Personal Information to RizzDial for Processing in accordance with this DPA and the Service Agreement;
c. Client’s instructions to RizzDial regarding the Processing of Client Personal Information, including the transfer of such information to RizzDial and RizzDial’s Processing in accordance with this DPA, comply with all applicable Data Protection Legislation;
d. Where Client acts as a Processor, Client has obtained all necessary authorization from the applicable Controller to engage RizzDial as a sub-processor and to enter into this DPA on the Controller’s behalf; and
e. Client shall maintain throughout the term of this DPA all legal bases, consents, notices, and authorizations necessary to permit the lawful Processing of Client Personal Information by RizzDial in accordance with this DPA.
5.2 Client Processing Obligations.
5.2 Client Processing Obligations. Client shall comply with all applicable requirements of Data Protection Legislation in its own Processing of Personal Information and in its use of RizzDial’s services. Client acknowledges that RizzDial has no control over and no responsibility for Client’s collection, disclosure, or other Processing of Personal Information prior to providing such information to RizzDial or after receiving such information back from RizzDial.
5.3 Indemnification.
5.3 Indemnification. Client agrees to indemnify, defend, and hold harmless RizzDial, its affiliates, and their respective officers, directors, employees, agents, successors, and assigns from and against any and all losses, damages, liabilities, costs, and expenses (including reasonable attorneys’ fees, expert fees, and litigation costs) arising out of or resulting from: (i) Client’s breach of any representation, warranty, or covenant in this Article 5; (ii) Client’s violation of applicable Data Protection Legislation in its collection, disclosure, or other Processing of Personal Information; (iii) Client’s failure to obtain or maintain necessary legal bases, consents,
notices, or authorizations; or (iv) any claim by a Data Subject or regulatory authority arising from Client’s Processing activities or instructions to RizzDial.
ARTICLE 6: RIZZDIAL SECURITY AND PROCESSOR OBLIGATIONS
6.1 Security Safeguards. RizzDial has implemented and shall maintain appropriate technical and organizational measures designed to protect Client Personal Information against accidental or unlawful destruction, loss, alteration, unauthorized disclosure, or unauthorized access. These security safeguards are described in detail in Schedule B to this DPA.
6.2 Security Standards. The security safeguards implemented by RizzDial are designed to provide a level of security appropriate to the risk presented by the Processing and the nature of the Client Personal Information, taking into account the state of the art, the costs of implementation, and the nature, scope, context, and purposes of Processing.
6.3 Right to Modify Security Measures. RizzDial reserves the right to modify, update, or enhance the security safeguards described in Schedule B at its sole discretion as necessary to maintain appropriate security in light of evolving threats, technological developments, and industry best practices, provided that any such modifications shall not result in a material degradation of the overall level of security provided to Client Personal Information.
6.4 Personnel Confidentiality. RizzDial shall ensure that all of its personnel, employees, contractors, and agents who are authorized to Process Client Personal Information: (i) are subject to appropriate confidentiality obligations, whether arising under contract, statute, common law, or professional codes of conduct; (ii) have received appropriate training on data protection and information security; and (iii) Process Client Personal Information only as necessary to perform their duties in connection with the Service Agreement and in accordance with RizzDial’s instructions.
6.5 Compliance Assistance. Taking into account the nature of the Processing and the information available to RizzDial, RizzDial shall provide reasonable assistance to Client (at Client’s expense and upon Client’s written request) to enable Client to comply with its obligations under Data Protection Legislation, including:
a. Assisting Client in responding to requests from Data Subjects exercising their rights under Data Protection Legislation (such as rights of access, rectification, erasure, data portability, restriction of processing, and objection to processing);
b. Assisting Client in ensuring compliance with obligations relating to the security of Processing, notification of Personal Data Breaches to supervisory authorities and Data Subjects, data protection impact assessments, and prior consultation with supervisory authorities;
c. Providing Client with information reasonably necessary to demonstrate compliance with RizzDial’s obligations under this DPA and under applicable Data Protection Legislation; and
d. With respect to European Personal Data, providing assistance in ensuring compliance with the obligations set forth in Articles 32 through 36 of the GDPR.
6.6 Audit Rights. Subject to the confidentiality obligations set forth in the Service Agreement, RizzDial shall, to the extent required by applicable Data Protection Legislation, make available to Client (or Client’s authorized third-party auditor) information reasonably necessary to demonstrate RizzDial’s compliance with its obligations under this DPA and permit and reasonably cooperate with audits and inspections conducted by Client or its authorized representatives.
a. Client shall provide RizzDial with at least thirty (30) days’ advance written notice of any requested audit or inspection, specifying the proposed scope, duration, and start date;
b. Audits and inspections shall be conducted during RizzDial’s regular business hours and in a manner that does not unreasonably interfere with RizzDial’s business operations;
c. Client shall be responsible for all costs and expenses associated with any such audit or inspection, including reasonable compensation for RizzDial’s time and resources;
d. Any third-party auditor engaged by Client must execute a confidentiality agreement acceptable to RizzDial prior to commencing any audit activities; and
e. Client may not conduct more than one (1) audit per calendar year unless required by a supervisory authority or in response to a Personal Data Breach.
6.7 Records and Documentation. RizzDial shall maintain records, logs, and documentation sufficient to demonstrate its compliance with the obligations set forth in this Article 6 and applicable Data Protection Legislation, and shall make such records available to Client upon reasonable request as provided in Section 6.6.
ARTICLE 7: SUBPROCESSORS
7.1 General Authorization. Client hereby provides general written authorization for RizzDial to engage third-party Subprocessors to Process Client Personal Information in connection with the provision of services under the Service Agreement, subject to the conditions set forth in this Article 7.
7.2 Subprocessor Requirements. RizzDial shall:
a. Ensure that any agreement between RizzDial and each Subprocessor imposes data protection obligations on the Subprocessor that are substantially equivalent to those imposed on RizzDial under this DPA and that provide a level of protection for Client Personal Information that is consistent with RizzDial’s obligations under this DPA and applicable Data Protection Legislation;
b. Ensure that each Subprocessor is capable of complying with applicable Data Protection Legislation and the obligations imposed under its agreement with RizzDial;
c. Conduct appropriate due diligence on each Subprocessor prior to engagement, including review of the Subprocessor’s security practices, certifications, and compliance capabilities; and
d. Supervise each Subprocessor’s Processing activities and ensure ongoing compliance with applicable obligations.
7.3 Current Subprocessors. Schedule C to this DPA identifies all Subprocessors currently authorized and engaged by RizzDial to Process Client Personal Information, along with their locations, descriptions of services provided, and contact information.
7.4 Changes to Subprocessors. RizzDial shall provide Client with at least thirty (30) days’ advance written notice before adding any new Subprocessor or replacing any existing Subprocessor listed in Schedule C. Notice may be provided by email to the address associated with Client’s account, through the RizzDial platform, or by updating a publicly available subprocessor list accompanied by notice to affected Clients. Such notice shall include the name of the proposed Subprocessor, its location, and a description of the Processing activities to be performed.
7.5 Objection Rights. If Client has a reasonable basis to believe that a proposed new or replacement Subprocessor will not be able to comply with applicable Data Protection Legislation or will create unacceptable data protection risks, Client may object to RizzDial’s use of such Subprocessor by providing written notice to RizzDial within fifteen (15) days of receiving RizzDial’s notification, setting forth in detail the specific reasons for the objection. RizzDial and Client shall work together in good faith to resolve the objection, which may include RizzDial implementing additional safeguards or Client terminating the affected services in accordance with the Service Agreement.
7.6 Liability for Subprocessors. RizzDial shall remain fully liable to Client for the performance of any Subprocessor’s obligations and for any acts, omissions, or breaches of such Subprocessor as if they were RizzDial’s own acts, omissions, or breaches. RizzDial’s use of Subprocessors shall not relieve RizzDial of any of its obligations under this DPA.
ARTICLE 8: DATA SUBJECT RIGHTS AND ASSISTANCE
8.1 Data Subject Requests. If RizzDial receives any request from a Data Subject seeking to exercise rights under applicable Data Protection Legislation with respect to that Data Subject’s Personal Information (including rights of access, rectification, restriction of processing, erasure, data portability, objection, or rights related to automated decision-making), RizzDial shall:
a. Promptly inform Client of the request, to the extent permitted by applicable law;
b. Not respond to the request directly without Client’s prior written authorization, except as required by applicable law; and
c. Provide reasonable assistance to Client, at Client’s expense and instruction, to enable Client to respond to the request in accordance with applicable Data Protection Legislation.
8.2 Assistance with Compliance. As described in Section 6.5, RizzDial shall provide reasonable assistance to Client (at Client’s expense) to enable Client to comply with its obligations under Data Protection Legislation. The nature and extent of such assistance shall be determined based on the nature of the Processing, the information available to RizzDial, and the feasibility of providing the requested assistance.
8.3 Self-Service Tools. To the extent feasible and as described in Schedule B, RizzDial makes available self-service tools through the RizzDial platform that enable Client administrators to respond to certain Data Subject requests directly, including tools to export, correct, and delete Client Personal Information.
ARTICLE 9: CALIFORNIA CONSUMER PRIVACY ACT COMPLIANCE
9.1 CCPA Applicability. To the extent that the CCPA applies to the Processing of Client Personal Information, the parties agree that Client qualifies as a “business” and RizzDial qualifies as a “service provider” within the meanings of those terms as defined in the CCPA.
9.2 Service Provider Obligations. Where RizzDial acts as a service provider under the CCPA, RizzDial certifies and agrees that:
a. RizzDial shall Process California Personal Information solely for the limited and specified purpose of performing the services set forth in the Service Agreement (the “Business Purpose”);
b. RizzDial shall not retain, use, or disclose California Personal Information for any purpose other than for the Business Purpose or as otherwise permitted by the CCPA, including the exceptions set forth in California Civil Code Section 1798.140(w);
c. RizzDial shall not retain, use, or disclose California Personal Information outside of the direct business relationship between RizzDial and Client except as permitted by the CCPA;
d. RizzDial shall not “sell” or “share” California Personal Information, as those terms are defined in California Civil Code Sections 1798.140(ad) and 1798.140(ah), respectively;
e. RizzDial shall not combine California Personal Information that RizzDial receives from or on behalf of Client with personal information that RizzDial receives from or on behalf of another person or persons, or collects from its own interaction with consumers, except to the extent necessary and proportionate to perform the Business Purpose or as otherwise permitted by the CCPA; and
f. RizzDial understands and shall comply with the restrictions and obligations imposed on service providers under the CCPA.
9.3 Compliance Certification. Upon Client’s reasonable written request, and no more than once per calendar year unless otherwise required by law, RizzDial shall provide Client with written certification or other reasonable evidence demonstrating RizzDial’s compliance with its obligations under this Article 9 and the CCPA.
9.4 Notice of Inability to Comply. If RizzDial determines that it can no longer meet its obligations under the CCPA or this Article 9, RizzDial shall promptly notify Client in writing and, unless prohibited by law, provide Client with reasonable information regarding the circumstances.
ARTICLE 10: INTERNATIONAL DATA TRANSFERS AND STANDARD CONTRACTUAL CLAUSES
10.1 Transfer Safeguards - General Obligation. RizzDial shall not transfer, or permit the transfer of, European Personal Data to any country, territory, or jurisdiction, or to any recipient, that has not been recognized by the relevant European supervisory authority or the European Commission as providing an adequate level of protection for personal data within the meaning of European Privacy Laws, unless RizzDial first implements appropriate safeguards to ensure that such transfer complies with European Privacy Laws.
10.2 Recognized Transfer Mechanisms. Appropriate safeguards for international data transfers may include, without limitation:
a. Transfers to recipients located in countries or territories covered by an adequacy decision issued by the European Commission, the UK Secretary of State, or the Swiss Federal Council, as applicable;
b. Transfers to recipients that have implemented binding corporate rules that have been authorized by the competent supervisory authority in accordance with European Privacy Laws;
c. Transfers pursuant to the Standard Contractual Clauses or other standard data protection clauses adopted or approved by the European Commission, the UK Information Commissioner’s Office, or the Swiss Federal Data Protection and Information Commissioner, as applicable;
d. Transfers pursuant to an approved certification mechanism combined with binding and enforceable commitments; or
e. Any other transfer mechanism recognized as valid under European Privacy Laws.
10.3 Incorporation of Standard Contractual Clauses. Client acknowledges that, in connection with the provision of services under the Service Agreement, RizzDial may receive and Process European Personal Data in the United States. To the extent a transfer is not covered by an applicable adequacy decision, certification framework, or other valid transfer mechanism, and subject to Section 10.9 below, the parties agree to incorporate the Standard Contractual Clauses by reference into this DPA and to comply with their respective obligations thereunder, as specified in Sections 10.4 through 10.8 below.
10.4 Standard Contractual Clauses - GDPR Transfers. With respect to European Personal Data that is subject to the GDPR and transferred from the European Economic Area to the United States, the Standard Contractual Clauses shall be incorporated as follows:
a. Parties. Client is the “data exporter” and RizzDial is the “data importer” for purposes of the Standard Contractual Clauses;
b. Module Selection. Module Two (Controller to Processor) of the Standard Contractual Clauses shall apply where Client acts as a Controller of European Personal Data, and Module Three (Processor to Processor) of the Standard Contractual Clauses shall apply where Client acts as a Processor of European Personal Data;
c. Clause 7 (Docking Clause). The optional docking clause set forth in Clause 7 of the Standard Contractual Clauses shall apply;
d. Clause 9 (Use of Sub-Processors). Option 2 (general written authorization) of Clause 9 of the Standard Contractual Clauses shall apply. Changes to Subprocessors shall be notified to Client in accordance with Article 7 of this DPA;
e. Clause 11 (Redress). The optional language in Clause 11 permitting Data Subjects to lodge complaints with an independent dispute resolution body is not selected and is deleted;
f. Clause 17 (Governing Law). The Standard Contractual Clauses shall be governed by the laws of the Republic of Ireland;
g. Clause 18 (Choice of Forum and Jurisdiction). Any dispute arising from the Standard Contractual Clauses shall be resolved by the courts of the Republic of Ireland;
h. Annexes. The Annexes to the Standard Contractual Clauses (Annex I.A, Annex I.B, Annex I.C, Annex II, and Annex III) shall be deemed completed with the information set forth in Schedules A, B, and C to this DPA; and
i. Conflict. To the extent of any conflict or inconsistency between any provision of this DPA and the Standard Contractual Clauses, the Standard Contractual Clauses shall prevail.
10.5 Standard Contractual Clauses - UK GDPR Transfers. With respect to European Personal Data that is subject to the UK GDPR and transferred from the United Kingdom to the United States, the Standard Contractual Clauses as modified in Section 10.4 above shall apply, with the following additional modifications:
a. UK Addendum Incorporation. The Standard Contractual Clauses shall be further modified and interpreted in accordance with the UK International Data Transfer Addendum, which is hereby incorporated by reference and forms an integral part of this DPA;
b. UK Addendum Tables. Table 1 (Parties), Table 2 (Selected SCCs, Modules and Selected Clauses), and Table 3 (Appendix Information) of the UK International Data Transfer Addendum shall be deemed completed with the information set forth in Schedules A, B, and C to this DPA. Table 4 (Ending this Addendum when the Approved Addendum Changes) shall be completed by selecting “neither party”;
c. UK Governing Law. References in the Standard Contractual Clauses to the “competent supervisory authority” and “competent courts” shall be interpreted to mean the UK Information Commissioner’s Office and the courts of England and Wales, respectively;
d. UK Addendum Conflicts. Any conflict or inconsistency between the terms of the Standard Contractual Clauses and the UK International Data Transfer Addendum shall be resolved in accordance with Section 10 (Precedence) and Section 11 (Amendments to this Addendum) of the UK International Data Transfer Addendum; and
e. UK GDPR Interpretation. References to the “GDPR” in the Standard Contractual Clauses shall be interpreted as references to the UK GDPR where the UK International Data Transfer Addendum applies.
10.6 Standard Contractual Clauses - Swiss FADP Transfers. With respect to European Personal Data that is subject to the Swiss FADP and transferred from Switzerland to the United States, the Standard Contractual Clauses as modified in Section 10.4 above shall apply, with the following additional modifications:
a. GDPR References. References to “Regulation (EU) 2016/679” and the “GDPR” shall be interpreted as references to the Swiss FADP;
b. Territorial References. References to “EU,” “Union,” “Member State,” and “Member State law” shall be interpreted as references to Switzerland and Swiss law, respectively;
c. Supervisory Authority and Courts. References to the “competent supervisory authority” shall be interpreted to mean the Swiss Federal Data Protection and Information Commissioner (FDPIC), and references to “competent courts” shall be interpreted to mean the competent courts in Switzerland;
d. Data Subject Rights. Data Subjects in Switzerland shall have the rights and means to enforce their rights under the Standard Contractual Clauses in Switzerland in accordance with Swiss FADP; and
e. Swiss Governing Law. Notwithstanding Section 10.4(f), the Standard Contractual Clauses as applied to Swiss transfers may be governed by Swiss law to the extent required by the Swiss FDPIC or Swiss courts.
10.7 Annexes to Standard Contractual Clauses. For purposes of completing the Annexes to the Standard Contractual Clauses (and, where applicable, the Tables of the UK International Data Transfer Addendum), the parties agree that:
a. Annex I.A (List of Parties) shall be completed using the information set forth in Section A of Schedule A to this DPA;
b. Annex I.B (Description of Transfer) shall be completed using the information set forth in Section B of Schedule A to this DPA;
c. Annex I.C (Competent Supervisory Authority) shall be completed using the information set forth in Section C of Schedule A to this DPA;
d. Annex II (Technical and Organisational Measures) shall be completed using the information set forth in Schedule B to this DPA; and
e. Annex III (List of Sub-Processors) shall be completed using the information set forth in Schedule C to this DPA.
10.8 Additional Transfer Mechanisms. Nothing in this Article 10 shall prevent the parties from relying on any other transfer mechanism recognized under European Privacy Laws for the transfer of European Personal Data, including adequacy decisions, binding corporate rules, derogations for specific situations under Article 49 of the GDPR, or any successor or replacement transfer mechanism that becomes available.
10.9 Suspension or Termination for Non-Compliance. If RizzDial is unable to comply with its obligations under the Standard Contractual Clauses, the UK International Data Transfer Addendum, or any other applicable transfer mechanism, or if RizzDial breaches any warranty under such mechanisms, and Client intends to suspend the transfer of European Personal Data to RizzDial or to terminate the applicable transfer mechanism:
a. Client shall provide RizzDial with reasonable advance written notice (not less than thirty (30) days unless a shorter period is required by a supervisory authority) specifying the nature of the non-compliance or breach;
b. Client shall provide RizzDial with a reasonable opportunity to cure such non-compliance or breach;
c. Client shall reasonably cooperate with RizzDial to identify and implement any additional safeguards, alternative transfer mechanisms, or other measures that may remedy the non-compliance or breach and permit the continued transfer of European Personal Data; and
d. If, after the foregoing efforts, RizzDial has not and cannot cure the non-compliance or breach, or if no alternative transfer mechanism is available, Client may suspend the transfer of European Personal Data to RizzDial or terminate the affected portion of the services under the Service Agreement, in each case without liability to either party (but without prejudice to any fees or expenses incurred by Client prior to such suspension or termination).
ARTICLE 11: PERSONAL DATA BREACH NOTIFICATION
11.1 Notification Obligation. RizzDial shall notify Client without undue delay, and in any event within seventy-two (72) hours, after becoming aware of any Personal Data Breach affecting Client Personal Information. Such notification shall be made to the contact person designated by Client in its account settings or as otherwise specified in writing by Client.
11.2 Breach Notification Content. To the extent the information is available to RizzDial at the time of notification, RizzDial’s Personal Data Breach notification to Client shall describe:
a. The nature of the Personal Data Breach, including, where possible, the categories and approximate number of Data Subjects affected and the categories and approximate number of Personal Information records affected;
b. The likely consequences of the Personal Data Breach;
c. The measures taken or proposed to be taken by RizzDial to address the Personal Data Breach, including, where appropriate, measures to mitigate its possible adverse effects; and
d. The name and contact details of RizzDial’s data protection officer or other point of contact from whom more information may be obtained.
11.3 Ongoing Updates. If it is not possible for RizzDial to provide all of the information required by Section 11.2 at the time of initial notification, RizzDial shall provide such information in phases as it becomes available, without undue further delay.
11.4 Investigation and Remediation. Upon becoming aware of a Personal Data Breach, RizzDial shall:
a. Promptly investigate the Personal Data Breach and take reasonable steps to remediate the cause of the breach and mitigate any potential harm;
b. Provide Client with reasonable cooperation and assistance in investigating the breach and assessing whether Client is required to notify any supervisory authorities, Data Subjects, or other third parties under applicable Data Protection Legislation;
c. Preserve evidence and maintain records relating to the Personal Data Breach as may be required to comply with applicable Data Protection Legislation or as may be reasonably requested by Client; and
d. Not make any public statements, press releases, or other public disclosures regarding the Personal Data Breach without Client’s prior written consent, except as required by applicable law.
11.5 No Acknowledgment of Liability. RizzDial’s notification of a Personal Data Breach under this Article 11 shall not be construed as an acknowledgment by RizzDial of any fault or liability with respect to the Personal Data Breach.
ARTICLE 12: TERM, TERMINATION, AND DATA RETURN
12.1 Term. This DPA shall commence on the effective date specified in Section 1.3 and shall continue in effect for so long as RizzDial Processes Client Personal Information on behalf of Client, or until earlier terminated in accordance with this Article 12 or the Service Agreement.
12.2 Effect of Service Agreement Termination. Upon termination or expiration of the Service Agreement for any reason, this DPA shall automatically terminate, subject to the provisions of Section 12.4 regarding return or deletion of Client Personal Information.
12.3 Survival. The obligations set forth in Articles 3 (Definitions), 5.3 (Indemnification), 11 (Breach Notification), 12.4 (Data Return and Deletion), and 13 (General Provisions), and any other provisions that by their nature should survive termination, shall survive any termination or expiration of this DPA.
12.4 Data Return and Deletion. Upon termination or expiration of the Service Agreement, and subject to Section 12.5 below, RizzDial shall, at Client’s election and written instruction:
a. Return Option. Return to Client, in a commonly used and machine-readable format, all Client Personal Information in RizzDial’s possession or control (including any Client Personal Information in the possession or control of RizzDial’s Subprocessors); or
b. Deletion Option. Securely delete or destroy all Client Personal Information in RizzDial’s possession or control (including any Client Personal Information in the possession or control of RizzDial’s Subprocessors) in accordance with RizzDial’s data retention and deletion policies and applicable industry standards.
12.5 Legal Retention Requirements. Notwithstanding Section 12.4, RizzDial may retain Client Personal Information to the extent and for such period as required by applicable law, regulation, or professional standards, or to the extent Client Personal Information has been backed up pursuant to RizzDial’s automatic archiving or backup procedures, provided that:
a. RizzDial shall isolate and protect such retained Client Personal Information from any further Processing except to the extent required by applicable law;
b. RizzDial shall continue to maintain the confidentiality and security of such retained Client Personal Information in accordance with this DPA; and
c. RizzDial shall securely delete or destroy such retained Client Personal Information in accordance with its data retention policies once the legal retention period expires, unless ongoing retention is required by law.
12.6 Certification of Deletion. Upon Client’s reasonable written request following deletion of Client Personal Information pursuant to Section 12.4(b), RizzDial shall provide Client with written certification signed by an authorized representative of RizzDial confirming that all Client Personal Information has been deleted or destroyed in accordance with this Article 12.
12.7 Fees for Data Return. Client acknowledges that returning Client Personal Information pursuant to Section 12.4(a) may require significant time and resources from RizzDial. If the effort required to return Client Personal Information exceeds ten (10) hours of work, RizzDial reserves the right to charge Client RizzDial’s then-current professional services rates for the time and resources required to complete the data return.
ARTICLE 13: MODIFICATIONS AND AMENDMENTS
13.1 Right to Modify. Notwithstanding any provision to the contrary in the Service Agreement, RizzDial reserves the right to modify, update, or amend this DPA, including the Schedules hereto, at any time and from time to time, for the following purposes:
a. To reflect changes in applicable Data Protection Legislation, including new privacy laws, amendments to existing laws, regulatory guidance, or court decisions;
b. To address changes in industry standards, best practices, or security requirements;
c. To reflect changes in RizzDial’s services, systems, infrastructure, or business operations;
d. To add, remove, or modify Subprocessors in accordance with Article 7;
e. To update or enhance the security safeguards described in Schedule B; or
f. To make clarifications or corrections that do not materially change the substance of this DPA.
13.2 Limitation on Modifications. Any modification, update, or amendment made by RizzDial pursuant to Section 13.1 shall not materially reduce the overall level of protection or security afforded to Client Personal Information under this DPA.
13.3 Notice of Modifications. RizzDial shall provide Client with reasonable advance notice of any material modification, update, or amendment to this DPA, which may be provided by email to the email address associated with Client’s account, by posting notice on RizzDial’s website, by making an updated version of this DPA available through the RizzDial platform, or by any other reasonable means.
13.4 Objection to Modifications. If Client reasonably objects to any material modification, update, or amendment to this DPA, Client’s sole remedy shall be to terminate the Service Agreement in accordance with its terms. Client’s continued use of RizzDial’s services following the effective date of any modification, update, or amendment shall constitute Client’s acceptance of such changes.
13.5 Mutual Amendments. Any modification, amendment, or waiver of any provision of this DPA not covered by Section 13.1 shall be effective only if agreed to in writing and signed by authorized representatives of both parties.
ARTICLE 14: GENERAL PROVISIONS
14.1 Entire Agreement. This DPA, together with the Service Agreement and any Schedules, exhibits, or other documents expressly incorporated by reference, constitutes the entire agreement between the parties with respect to the subject matter hereof and supersedes all prior or contemporaneous agreements, understandings, representations, and discussions, whether oral or written, relating to such subject matter.
14.2 Relationship to Service Agreement. This DPA is incorporated into and forms an integral part of the Service Agreement. Except as expressly modified by this DPA, all terms and conditions of the Service Agreement remain in full force and effect. In the event of any conflict between this DPA and the Service Agreement with respect to data protection matters, this DPA shall control.
14.3 No Third-Party Beneficiaries. Except as expressly provided in the Standard Contractual Clauses with respect to Data Subjects’ third-party beneficiary rights, this DPA does not and is
not intended to confer any rights or remedies upon any person or entity other than the parties hereto and their respective successors and permitted assigns.
14.4 Severability. If any provision of this DPA is held by a court of competent jurisdiction to be invalid, illegal, or unenforceable, the remaining provisions shall continue in full force and effect, and such invalid, illegal, or unenforceable provision shall be reformed and construed so as to most nearly approximate the intent of the parties as expressed in the original provision, to the extent permitted by law.
14.5 Waiver. No waiver of any provision of this DPA shall be effective unless in writing and signed by the party against whom such waiver is sought to be enforced. No failure or delay by either party in exercising any right, power, or remedy under this DPA shall operate as a waiver thereof, nor shall any single or partial exercise of any such right, power, or remedy preclude any other or further exercise thereof or the exercise of any other right, power, or remedy.
14.6 Governing Law and Jurisdiction. Except as otherwise expressly provided in this DPA (including with respect to the Standard Contractual Clauses), this DPA shall be governed by and construed in accordance with the laws specified in the Service Agreement for the governance of disputes, without regard to conflicts of law principles. Any dispute arising out of or relating to this DPA (other than disputes subject to the Standard Contractual Clauses) shall be subject to the exclusive jurisdiction of the courts specified in the Service Agreement.
14.7 Notices. All notices, requests, consents, and other communications under this DPA shall be in writing and shall be deemed to have been duly given: (i) when delivered personally; (ii) when sent by confirmed electronic transmission (email); (iii) one (1) business day after being sent by reputable overnight courier service; or (iv) three (3) business days after being mailed by first-class mail, postage prepaid, to the addresses specified in Schedule A or such other address as either party may designate by written notice to the other party.
14.8 Assignment. Neither party may assign or transfer this DPA, in whole or in part, without the prior written consent of the other party, except that either party may assign this DPA without consent in connection with a merger, acquisition, corporate reorganization, or sale of all or substantially all of its assets, provided that the assignee agrees in writing to be bound by the terms of this DPA. Any attempted assignment in violation of this Section shall be null and void.
14.9 Interpretation. This DPA shall be interpreted fairly in accordance with its terms and applicable law, without any presumption or rule requiring construction in favor of or against either party based solely on authorship. Headings are for convenience only and shall not limit the meaning or scope of any provision.
14.10 Counterparts and Electronic Signatures. This DPA may be executed in one or more counterparts, each of which shall be deemed an original and all of which together shall constitute one and the same instrument. Electronic signatures and electronically delivered signatures shall have the same force and effect as original signatures.
ARTICLE 15: EXECUTION AND ACKNOWLEDGMENT
BY EXECUTING THIS DATA PROCESSING AGREEMENT, THE AUTHORIZED REPRESENTATIVES OF EACH PARTY ACKNOWLEDGE AND CONFIRM THAT:
They have carefully read and fully understand all terms, conditions, obligations, and provisions contained in this DPA;
They have the full legal authority to execute this DPA on behalf of their respective organizations;
Their organization agrees to be legally bound by all terms of this DPA; and
This DPA constitutes a valid and binding obligation of their organization, enforceable in accordance with its terms.
SIGNATURES
METATECH LLC, doing business as RIZZDIAL
Signature: ___________________________________
Print Name: James Hill
Title: Founder
Date: ___________________________________
CLIENT
Signature: ___________________________________
Print Name: ___________________________________
Title: ___________________________________
Date: ___________________________________
SCHEDULE A
PROCESSING DETAILS AND PARTY INFORMATION
SECTION A: PARTIES TO THE DATA PROCESSING AGREEMENT
DATA EXPORTER (CLIENT):
Legal Name: As identified in the RizzDial Service Agreement or Order Form
Business Address: As specified in Client’s RizzDial account profile and billing information
Authorized Contact Person: As designated by Client in account settings or as otherwise communicated to RizzDial in writing
Contact Details: Email and telephone number as provided in Client’s account profile
Processing Activities Relevant to This DPA: Client, acting in the capacity of either a Controller or Processor, collects, stores, and manages Personal Information relating to its customers, prospective customers, business leads, and contacts for purposes of conducting its business operations, including sales, marketing, customer service, and customer relationship management activities.
Role Under Data Protection Legislation: Controller or Processor (as applicable based on Client’s relationship with Data Subjects)
DATA IMPORTER (RIZZDIAL):
Legal Name: MetaTech LLC, doing business as RizzDial
Principal Business Address: 14765 Ragsdale Lane, Roanoke, Texas 76262, United States of America
Authorized Representative: James Hill, Founder
Contact Email: support@rizzdial.com
Contact Telephone: +1 (480) 486-1869
Processing Activities Relevant to This DPA: RizzDial provides cloud-based telecommunications services, automated calling and dialing systems, customer engagement platforms, call recording and analytics, customer relationship management tools, and related services to Client pursuant to the Service Agreement. In providing these services, RizzDial Processes Client Personal Information on behalf of and in accordance with the instructions of Client.
Role Under Data Protection Legislation: Processor (or “service provider” under the CCPA and similar U.S. state privacy laws)
SECTION B: COMPREHENSIVE DESCRIPTION OF PROCESSING ACTIVITIES
B.1 Subject Matter of Processing
The subject matter of the Processing is the provision by RizzDial to Client of telecommunications services, automated calling and engagement platforms, call recording and management systems, customer data management tools, and related cloud-based services as more fully described in the Service Agreement.
B.2 Nature of Processing
RizzDial will perform the following categories of Processing operations on Client Personal Information:
Collection: Receiving Personal Information from Client or from Data Subjects at Client’s direction
Recording: Capturing voice communications, call metadata, and interaction data
Organization: Structuring and arranging Personal Information in databases and systems
Structuring: Organizing Personal Information according to predetermined criteria
Storage: Maintaining Personal Information in secure databases and storage systems
Adaptation or Alteration: Modifying Personal Information as instructed by Client
Retrieval: Accessing and providing Personal Information to Client or authorized users
Consultation: Enabling Client to view, access, and use Personal Information
Use: Employing Personal Information to provide services to Client
Disclosure by Transmission: Transferring Personal Information to authorized Subprocessors
Dissemination: Making Personal Information available to Client’s authorized users
Alignment or Combination: Integrating Personal Information from multiple sources as directed by Client
Restriction: Limiting Processing of Personal Information upon Client’s instruction
Erasure: Deleting Personal Information in accordance with Client’s instructions or legal requirements
Destruction: Permanently removing Personal Information from all systems
B.3 Purpose of Processing
The purposes for which RizzDial will Process Client Personal Information are:
To enable Client to conduct voice communications with its customers, leads, and contacts
To provide automated calling, dialing, and customer engagement services to Client
To record, store, and manage voice communications on behalf of Client
To provide call analytics, reporting, and performance metrics to Client
To facilitate Client’s customer relationship management activities
To enable Client to manage, track, and optimize its sales and marketing operations
To provide technical support and customer service to Client
To maintain, improve, and optimize the RizzDial platform and services
To comply with applicable legal obligations and respond to lawful requests
Any other purpose expressly authorized by Client in writing or through Client’s use of the RizzDial platform
B.4 Categories of Data Subjects
The Personal Information Processed by RizzDial may relate to the following categories of Data Subjects:
Current customers and clients of Client
Former customers and clients of Client
Prospective customers and sales leads of Client
Business contacts and representatives of Client’s customers or prospects
Individuals who communicate with Client via telephone or other means
Employees, contractors, or representatives of Client (to the extent their Personal Information is included in communications or records)
Any other individuals whose Personal Information is provided to RizzDial by Client or collected by RizzDial at Client’s direction
B.5 Categories of Personal Information Processed
RizzDial may Process the following categories of Client Personal Information, as determined and provided by Client:
Contact and Identification Information:
Full name (first name, last name, middle name)
Email addresses
Telephone numbers (mobile, home, business)
Mailing addresses (street address, city, state/province, postal code, country)
Social media profile identifiers and usernames
Job title and company name
Demographic Information:
Date of birth
Age or age range
Gender
Communication and Interaction Data:
Call recordings and transcripts
Call metadata (date, time, duration, phone numbers, call outcome)
Text messages and SMS communications
Communication preferences and consent records
Notes and comments added by Client’s users regarding interactions with Data Subjects
Customer Relationship Data:
Customer status (lead, prospect, active customer, former customer)
Purchase history and transaction records
Service usage data
Customer preferences and interests
Marketing and communication consent records
Technical and Device Information:
- IP addresses (where collected)
- Device identifiers
- Browser type and version
- Operating system information
Other Information:
- Any other Personal Information that Client chooses to input into the RizzDial platform or that is collected through Client’s use of RizzDial’s services
B.6 Sensitive Personal Data
The parties do not anticipate or intend that RizzDial will Process special categories of personal data (as defined in the GDPR), sensitive personal information (as defined under the CCPA and other U.S. privacy laws), or personal data relating to criminal convictions and offenses. Client shall not provide such information to RizzDial without RizzDial’s prior written consent and the implementation of appropriate additional safeguards. If Client inadvertently provides such information to RizzDial, Client shall promptly notify RizzDial and work with RizzDial to delete or de-identify such information.
B.7 Frequency and Duration of Processing
Frequency of Data Transfers: Continuous and ongoing throughout the term of the Service Agreement. Personal Information is transferred to RizzDial in real-time or near-real-time as Client and its authorized users utilize the RizzDial platform and services.
Duration of Processing: RizzDial will Process Client Personal Information for the entire duration of the Service Agreement and for such additional period as may be necessary to comply with legal obligations, resolve disputes, or as otherwise agreed by the parties in writing. Upon termination of the Service Agreement, Client Personal Information will be returned or deleted in accordance with Article 12 of the DPA.
Retention Period: Client Personal Information will be retained by RizzDial for as long as Client maintains an active account with RizzDial and continues to use the services. Following termination of the Service Agreement, Personal Information will be deleted or returned in accordance with Client’s instructions, except to the extent retention is required by applicable law. Specific retention periods may be configured by Client through the RizzDial platform settings or as otherwise agreed in writing.
SECTION C: COMPETENT SUPERVISORY AUTHORITY
For purposes of Clause 13 of the Standard Contractual Clauses (Module Two and Module Three), the competent supervisory authority shall be:
For transfers subject to the GDPR: The supervisory authority shall be determined in accordance with Article 55 of the GDPR based on Client’s establishment or the location where Client, as the data exporter, has its main establishment or single establishment within the European Economic Area. If Client has establishments in more than one Member State, the supervisory authority of the Member State of Client’s main establishment shall be competent. If Client has no establishment in the European Economic Area, the supervisory authority shall be determined in accordance with the criteria set forth in the Standard Contractual Clauses.
For transfers subject to the UK GDPR: The Information Commissioner’s Office (ICO) of the United Kingdom.
For transfers subject to the Swiss FADP: The Swiss Federal Data Protection and Information Commissioner (FDPIC).
Client shall inform RizzDial of the identity of the competent supervisory authority if it differs from the default supervisory authority identified above.
SCHEDULE B
TECHNICAL AND ORGANIZATIONAL SECURITY MEASURES
This Schedule describes the technical and organizational security measures implemented by RizzDial to protect Client Personal Information against accidental or unlawful destruction, loss, alteration, unauthorized disclosure, or unauthorized access, as required by Article 6 of the DPA and by applicable Data Protection Legislation, including Article 32 of the GDPR.
RizzDial has implemented and maintains a comprehensive information security program that includes administrative, technical, and physical safeguards designed to ensure a level of security appropriate to the risk presented by the Processing of Client Personal Information.
PART 1: TECHNICAL SECURITY MEASURES
1.1 Encryption and Cryptography
Data at Rest Encryption:
RizzDial uses encryption at rest for production databases and object storage that hold Client Personal Information where supported by the applicable service and system configuration.
Encryption and key-management controls are implemented using platform-provided and application-level controls, as applicable, with access limited to authorized personnel.
RizzDial applies access restrictions and other safeguards appropriate to the sensitivity and risk of Client Personal Information stored on systems that do not provide native storage-layer encryption.
Data in Transit Encryption:
Web application, administrative, and API traffic containing Client Personal Information is encrypted using Transport Layer Security (TLS) version 1.2 or higher when transmitted over public networks.
RizzDial employs valid SSL/TLS certificates issued by trusted certificate authorities for covered web services.
Voice calls, SMS messages, and other communications routed through public telephone networks, telecommunications carriers, or Client-directed third-party integrations are protected according to the protocols and capabilities of the applicable networks and providers and may not be end-to-end encrypted.
RizzDial configures supported services to reject or disable outdated or insecure encryption protocols where technically configurable.
Cryptographic Standards:
- RizzDial follows industry-standard cryptographic practices and regularly reviews and updates its encryption implementations to address evolving security threats and vulnerabilities.
1.2 Access Controls and Authentication
User Authentication:
Access to RizzDial’s systems and Client Personal Information requires user authentication using unique user credentials (username and password).
Password policies require passwords to meet minimum complexity requirements, including minimum length, use of uppercase and lowercase letters, numbers, and special characters.
Passwords are stored in hashed and salted format using industry-standard hashing algorithms.
RizzDial supports and encourages the use of multi-factor authentication (MFA) for Client users.
Role-Based Access Control (RBAC):
RizzDial implements role-based access control mechanisms that restrict access to Client Personal Information based on users’ roles and job functions.
Users are granted the minimum level of access necessary to perform their authorized duties (principle of least privilege).
Client administrators have the ability to define and manage user roles, permissions, and access levels within their RizzDial account.
Session Management:
User sessions are managed using encrypted session tokens with expiration times.
Inactive sessions are automatically terminated after a defined period of inactivity.
Users are required to re-authenticate after session expiration.
API Security:
Access to RizzDial’s application programming interfaces (APIs) is controlled through API keys, OAuth tokens, or similar authentication mechanisms.
API endpoints are protected against unauthorized access and abuse through rate limiting, authentication, and authorization checks.
1.3 Network Security and Perimeter Defense
Firewall Protection:
RizzDial’s systems are protected by network firewalls and security groups that restrict inbound and outbound network traffic based on predefined security rules.
Only necessary ports and protocols are opened, and all other network traffic is blocked by default (default-deny policy).
Intrusion Detection and Prevention:
RizzDial employs intrusion detection and prevention systems (IDS/IPS) to monitor network traffic for suspicious activity and potential security threats.
Security alerts are generated and reviewed by RizzDial’s security team.
Network Segmentation:
RizzDial’s network infrastructure is segmented to isolate production systems, development/test systems, and administrative systems.
Client Personal Information is processed and stored in segregated production environments with restricted access.
Distributed Denial of Service (DDoS) Protection:
- RizzDial uses network-layer distributed denial-of-service protection provided by DigitalOcean for applicable infrastructure resources, together with application-level rate limiting or other protective controls where appropriate.
1.4 Application Security
Secure Software Development:
- RizzDial follows secure software development practices, including security requirements analysis, secure coding standards, code reviews, and security testing.
- Application code is reviewed for common security vulnerabilities such as those identified in the OWASP Top 10.
Input Validation and Output Encoding:
RizzDial’s applications implement input validation to prevent injection attacks (such as SQL injection, cross-site scripting, and command injection).
Output encoding is applied to prevent cross-site scripting (XSS) vulnerabilities.
Vulnerability Management:
RizzDial conducts regular vulnerability assessments and penetration testing of its systems and applications.
Identified vulnerabilities are prioritized based on severity and are remediated in accordance with RizzDial’s vulnerability management procedures.
1.5 Data Backup and Disaster Recovery
Automated Backups:
- RizzDial maintains automated backups, snapshots, or replication for production systems based on system criticality and operational requirements.
- Backup frequency, retention, and geographic redundancy vary by system and are configured to support RizzDial’s continuity and recovery objectives.
- Backup data is access-controlled and not publicly accessible. Encryption is used where supported by the applicable backup service, with additional safeguards applied based on risk.
Point-in-Time Recovery:
- RizzDial maintains restoration capabilities appropriate to each production system, which may include point-in-time recovery, snapshots, or restoration from retained backups where supported.
Disaster Recovery Planning:
RizzDial maintains documented disaster recovery and business continuity plans that describe procedures for restoring systems and data in the event of a disaster or major service interruption.
Recovery time objectives (RTO) and recovery point objectives (RPO) are defined for critical systems.
Backup Testing:
- RizzDial periodically tests backup and recovery procedures to ensure that Client Personal Information can be successfully restored in the event of data loss or system failure.
1.6 Logging, Monitoring, and Incident Detection
Activity Logging:
RizzDial maintains logs of user activities, system events, authentication attempts, API access, and administrative actions performed on or within its systems.
Logs include information such as user identity, date and time of access, actions performed, and IP addresses.
Logs are retained for a reasonable period in accordance with RizzDial’s data retention policies and applicable legal requirements.
Security Monitoring:
RizzDial monitors the availability, performance, authentication events, and security-relevant activity of its systems using platform-provided and application-level monitoring and logging tools.
Monitoring systems generate alerts for suspicious activities, security incidents, system failures, performance degradation, and policy violations.
Security Information and Event Management (SIEM):
RizzDial aggregates and analyzes security logs and events to detect potential security incidents and anomalous behavior.
Security alerts are reviewed and investigated by RizzDial’s security and operations teams.
Uptime Monitoring:
RizzDial monitors the availability and performance of its services using uptime monitoring tools.
Automated alerts notify RizzDial’s operations team of service disruptions or degradation.
1.7 Malware Protection
Endpoint Protection:
RizzDial’s employee workstations and administrative systems are protected by endpoint security software, including anti-malware and anti-virus tools.
Endpoint protection software is configured to automatically update virus definitions and perform regular scans.
Email Security:
- Inbound email is scanned for malware, phishing attempts, and spam using email security filtering tools.
PART 2: ORGANIZATIONAL SECURITY MEASURES
2.1 Information Security Policies and Procedures
Security Policy Framework:
RizzDial maintains a comprehensive set of written information security policies and procedures that govern the protection of Personal Information and the security of RizzDial’s systems and infrastructure.
Security policies address topics including access control, encryption, data classification, incident response, vendor management, acceptable use, and physical security.
Policy Review and Updates:
- RizzDial’s security policies and procedures are reviewed and updated periodically to address changes in technology, business operations, regulatory requirements, and emerging security threats.
2.2 Personnel Security and Training
Confidentiality Obligations:
All RizzDial personnel (including employees, contractors, and agents) who have access to Client Personal Information are subject to binding confidentiality obligations, whether arising from employment agreements, contractor agreements, statutory obligations, or common law duties.
Confidentiality obligations survive the termination of employment or engagement.
Background Checks:
- RizzDial conducts appropriate background checks on personnel in accordance with applicable law and RizzDial’s hiring policies.
Security Awareness Training:
RizzDial provides regular security awareness training to all personnel who have access to Personal Information or RizzDial’s systems.
Training topics include data protection principles, security best practices, phishing awareness, password security, incident reporting, and compliance with security policies.
Access Termination:
- When personnel leave RizzDial’s employment or no longer require access to systems or Personal Information, their access credentials and privileges are promptly revoked.
2.3 Physical Security
Data Center Security:
RizzDial’s production infrastructure is hosted through DigitalOcean in data center regions selected by RizzDial.
DigitalOcean and its data center service providers maintain multiple layers of physical and environmental safeguards, including:
Restricted facility access, monitoring, and surveillance controls
Facility access controls managed by DigitalOcean and its data center service providers
Environmental controls, including fire suppression, climate control, and power redundancy
Physical barriers and perimeter security controls
DigitalOcean reports maintaining SOC 2 Type II and SOC 3 Type II certifications, and its underlying data center facilities maintain additional independently assessed controls and certifications.
Current information regarding DigitalOcean’s infrastructure security, certifications, data center service providers, and shared-responsibility model is available through DigitalOcean’s Trust Platform and security documentation.
Office Security:
RizzDial’s corporate offices implement physical access controls to restrict entry to authorized personnel.
Visitor access is logged and supervised.
2.4 Vendor and Subprocessor Management
Vendor Due Diligence:
- Prior to engaging any Subprocessor or third-party vendor that will have access to Client Personal Information, RizzDial conducts appropriate due diligence to assess the vendor’s security practices, data protection capabilities, and compliance with applicable laws.
Subprocessor Agreements:
RizzDial enters into written agreements with all Subprocessors that impose data protection and security obligations substantially equivalent to those set forth in this DPA.
Subprocessor agreements include provisions addressing confidentiality, security safeguards, data breach notification, data return or deletion, and compliance with applicable Data Protection Legislation.
Ongoing Oversight:
- RizzDial monitors Subprocessor performance and compliance with contractual obligations on an ongoing basis.
2.5 Incident Response and Management
Incident Response Plan:
- RizzDial maintains a written security incident response plan that defines procedures for detecting, responding to, investigating, and remediating security incidents, including Personal Data Breaches.
Incident Response Team:
RizzDial has designated an incident response team responsible for managing security incidents.
The incident response team includes representatives from security, operations, legal, and management functions.
Incident Detection and Escalation:
Security incidents are detected through monitoring systems, user reports, and other sources.
Incidents are classified by severity and escalated in accordance with defined procedures.
Breach Notification:
- In the event of a Personal Data Breach affecting Client Personal Information, RizzDial will notify Client without undue delay in accordance with Article 11 of the DPA.
Post-Incident Review:
Following resolution of security incidents, RizzDial conducts post-incident reviews to identify lessons learned and opportunities for improvement.
Remediation measures are implemented to prevent recurrence of similar incidents.
2.6 System Configuration and Change Management
Configuration Management:
RizzDial maintains documented standard configurations for servers, network devices, and applications.
System configurations are stored in version control systems to enable tracking of changes and rollback if necessary.
Patch Management:
- RizzDial applies security patches and updates to its systems, applications, and infrastructure in a timely manner based on the severity of vulnerabilities and risk to Client Personal
Information.
Critical security patches are prioritized and applied expeditiously.
Patch-management responsibilities follow the applicable shared-responsibility model. DigitalOcean manages the underlying cloud infrastructure and designated managed services; RizzDial manages operating systems, application code, dependencies, and configurations for customer-managed compute resources.
Change Control:
Changes to production systems and infrastructure are subject to a formal change control process that includes review, testing, approval, and documentation.
Emergency changes may be expedited when necessary to address critical security issues or service disruptions.
2.7 IT Governance and Management
IT Management Structure:
- RizzDial maintains an organized IT management structure with defined roles, responsibilities, and reporting lines.
Third-Party IT and Security Support:
- RizzDial may engage qualified third-party IT and security consultants, subject to appropriate confidentiality, access-control, and data-protection obligations, to support IT operations, infrastructure management, and information security.
Compliance and Audit:
RizzDial periodically assesses its compliance with this DPA, applicable Data Protection Legislation, and industry security standards.
RizzDial may engage third-party auditors to conduct independent security assessments or audits.
2.8 Data Minimization and Purpose Limitation
Data Minimization:
RizzDial collects and Processes only the minimum amount of Client Personal Information necessary to provide the services under the Service Agreement.
Many data fields in the RizzDial platform are optional, allowing Client to determine what information to provide.
Purpose Limitation:
RizzDial Processes Client Personal Information solely for the purposes described in this DPA and the Service Agreement, and in accordance with Client’s instructions.
RizzDial does not use Client Personal Information for its own purposes or for purposes incompatible with Client’s instructions, except as required by law.
2.9 Data Quality, Accuracy, and Updates
Data Accuracy:
- Client is responsible for ensuring the accuracy and quality of Client Personal Information provided to RizzDial.
- Client administrators have the ability to update, correct, and modify Personal Information through the RizzDial platform.
Data Integrity Monitoring:
- RizzDial implements monitoring and validation mechanisms to help ensure the integrity and consistency of data stored in its systems.
2.10 Data Retention and Deletion
Retention Configuration:
- Client administrators can configure data retention settings and policies through the RizzDial platform, including settings for automatic deletion of records after specified periods.
Data Deletion upon Termination:
- Upon termination of the Service Agreement and at Client’s written instruction, RizzDial will delete or return Client Personal Information in accordance with Article 12 of the DPA.
Secure Deletion:
- When Client Personal Information is deleted, RizzDial employs secure deletion methods designed to render the data irrecoverable, in accordance with industry best practices.
2.11 Data Portability and Erasure Capabilities
Data Export:
Client can export Client Personal Information from the RizzDial platform using available export features, data download tools, or APIs.
Exported data is provided in commonly used, machine-readable formats such as CSV, JSON, or Excel.
Data Erasure Requests:
- Upon Client’s written request, RizzDial will delete specific Personal Information or all Client
Personal Information in accordance with Article 12 of the DPA.
• Client administrators can also delete records directly through the RizzDial platform interface.
2.12 Accountability and Governance
Data Protection Officer (DPO):
• If required by applicable law, RizzDial will designate a data protection officer or equivalent role responsible for overseeing data protection compliance.
Accountability Measures:
• RizzDial maintains documentation and records sufficient to demonstrate compliance with its obligations under this DPA and applicable Data Protection Legislation.
• Documentation includes security policies, incident reports, audit logs, training records, and compliance assessments.
PART 3: CLIENT ASSISTANCE MECHANISMS
To assist Client in fulfilling its obligations under Data Protection Legislation, RizzDial provides the following tools and support mechanisms:
3.1 Self-Service Tools
• Data Access and Export: Client administrators can access and download Client Personal Information through the RizzDial platform interface using export tools and reporting features.
• Data Correction and Update: Client administrators can update, correct, and modify Personal Information directly through the platform.
• Data Deletion: Client administrators can delete individual records, data subjects, or entire datasets through the platform interface or by submitting deletion requests to RizzDial.
• Retention Settings: Client administrators can configure data retention periods and automated deletion rules through account settings.
• User and Access Management: Client administrators can manage user accounts, roles, permissions, and access controls through the platform’s administrative interface.
3.2 Customer Support and Assistance
Documentation and FAQs: RizzDial provides comprehensive product documentation, user guides, FAQs, and knowledge base articles accessible through the RizzDial website and platform.
Support Ticket System: Client can submit support requests, technical questions, and data subject access requests through RizzDial’s support ticket system at support@rizzdial.com.
Compliance Assistance: RizzDial’s support team can provide reasonable assistance with Data Subject access requests, deletion requests, breach investigations, and other compliance matters, as described in Article 6 and Article 8 of the DPA.
Response Times: RizzDial endeavors to respond to support requests in a timely manner based on the nature and urgency of the request and the level of support purchased by Client under the Service Agreement.
PART 4: CONTINUOUS IMPROVEMENT
RizzDial is committed to continuously improving its security posture and adapting to evolving threats, technologies, and regulatory requirements. RizzDial regularly reviews and updates the security measures described in this Schedule B and implements additional safeguards as necessary to maintain an appropriate level of protection for Client Personal Information.
SCHEDULE C
AUTHORIZED SUBPROCESSORS
The following third-party service providers are currently authorized by RizzDial to Process Client Personal Information as Subprocessors in connection with the provision of services under the Service Agreement. RizzDial has entered into appropriate data processing agreements with each Subprocessor that impose data protection obligations substantially equivalent to those set forth in this DPA.
Client hereby provides general written authorization for RizzDial to engage the Subprocessors listed below, and to make changes to this list in accordance with Article 7 of the DPA.
| Subprocess or Name | Services Provided | Principal Business Address | Location of Processing | Contact Information |
|---|
DigitalOcean, LLC | Cloud infrastructure services; virtual compute; object storage; networking; backup and recovery capabilities; monitoring and security services | 105 Edgeview Drive, Suite 425, Broomfield, Colorado 80021, United States | United States | Website: www.digitalocean.com Privacy Contact: privacy@digitalocean.com
Twilio Inc. | Voice telecommunications services; voice calling and telephony infrastructure; SMS messaging services; API services | 101 Spear Street, San Francisco, California 94105, United States | United States | Website: www.twilio.com Contact: www.twilio.com/help/contact Support: support@twilio.com
Plivo Inc. | Voice telecommunications services; voice calling and telephony infrastructure; telecommunications API services | 2125 O’Nel Drive, San Jose, California 95131, United States | United States | Website: www.plivo.com Contact: www.plivo.com/contact Support: support@plivo.com
Telnyx LLC Voice telecommunications services; voice calling and telephony infrastructure; telecommunications carrier services; API services 311 West Superior Street, Suite 504, Chicago, Illinois 60654, United States Website: telnyx.com Contact: telnyx.com/contact-us Support: support@telnyx.com
| Stripe, Inc. | Payment processing services; credit card and payment transaction processing; billing and invoicing services; financial services infrastructure | 510 Townsend Street, San Francisco, California 94103, United States | United States (primary); may process in other countries as disclosed in Stripe’s privacy policy | Website: stripe.com Contact: stripe.com/contact Support: support@stripe.com |
|---|
| SendGrid, Inc. (a Twilio company) | Email delivery services; transactional email infrastructure; email API services; email notifications and communications | 1801 California Street, Suite 500, Denver, Colorado 80202, United States | United States | Website: sendgrid.com Contact: support.sendgrid.com Support: support@sendgrid.com |
|---|
NOTES REGARDING SUBPROCESSORS:
1. Subprocessor Locations:
The locations listed above represent the principal business addresses of the Subprocessors.
Actual Processing of Client Personal Information may occur in data centers or facilities located in the same country or region, or in other locations as disclosed in each Subprocessor’s privacy documentation and data processing agreements. For DigitalOcean, RizzDial currently selects United States regions for covered infrastructure and storage services. DigitalOcean may engage its own subprocessors in other locations as disclosed in its DPA and public subprocessor list. For other Subprocessors, Processing typically occurs in the United States, but may occur in other locations in accordance with the Subprocessor’s infrastructure and as disclosed in their privacy policies.
2. Subprocessor Agreements:
RizzDial has entered into data processing agreements or addenda with each of the above Subprocessors that include appropriate data protection and security obligations, including:
Obligations to Process Personal Information only in accordance with RizzDial’s instructions
Appropriate technical and organizational security measures
Confidentiality obligations
Obligations to assist with Data Subject requests and security incidents
Obligations to delete or return Personal Information upon termination
Compliance with applicable Data Protection Legislation
3. International Data Transfers:
To the extent that any Subprocessor Processes European Personal Data outside of Europe, appropriate transfer mechanisms are in place, including:
DigitalOcean: DigitalOcean transfers personal data internationally under its certification to the EU-U.S. Data Privacy Framework, including the UK Extension and Swiss-U.S. Data Privacy Framework, with the EU Standard Contractual Clauses and UK International Data Transfer Addendum applying as fallback mechanisms under its Data Processing Agreement. See https://www.digitalocean.com/legal/data-processing-agreement
Twilio, Plivo, Telnyx, Stripe, SendGrid: These Subprocessors offer Standard Contractual Clauses or other legally recognized transfer mechanisms for transfers of European Personal Data to the United States.
4. Changes to Subprocessors:
RizzDial reserves the right to add new Subprocessors or replace existing Subprocessors in accordance with Article 7 of the DPA. Client will be notified at least thirty (30) days in advance of any such changes in accordance with Article 7 of the DPA.
5. Additional Subprocessors:
RizzDial may engage additional Subprocessors from time to time as necessary to provide or improve its services. Any new Subprocessors will be subject to appropriate due diligence and will be required to enter into data processing agreements that provide substantially equivalent protections to those set forth in this DPA.
6. Sub-Subprocessors:
The Subprocessors listed above may themselves engage sub-processors (sub-subprocessors)
to perform certain functions on their behalf. RizzDial ensures that its agreements with Subprocessors include provisions requiring the Subprocessors to impose data protection obligations on any sub-subprocessors that are substantially equivalent to the obligations imposed on the Subprocessor. Information regarding sub-subprocessors is available in each Subprocessor’s publicly available sub-processor lists:
DigitalOcean Subprocessors: https://www.digitalocean.com/trust/subprocessors
Twilio Sub-Processors: https://www.twilio.com/legal/sub-processors
Stripe Sub-Processors: https://stripe.com/service-providers/legal
SendGrid Sub-Processors: https://www.twilio.com/legal/sub-processors (SendGrid is owned by Twilio)
7. Contact Information:
For questions regarding RizzDial’s use of Subprocessors, to request additional information about Subprocessor data protection practices, or to opt in to receive advance notifications of Subprocessor changes, please contact RizzDial at:
Email: support@rizzdial.com Phone: +1 (480) 486-1869 Address: 14765 Ragsdale Lane, Roanoke, Texas 76262, United States
END OF SCHEDULE C
END OF RIZZDIAL DATA PROCESSING AGREEMENT
DOCUMENT COMPLETE AND READY FOR EXECUTION
This Data Processing Agreement, including Schedules A, B, and C, constitutes the complete and final agreement between MetaTech LLC d/b/a RizzDial and Client regarding the Processing of Personal Information and supersedes any prior data processing agreements or terms.
For questions or to request an executed copy of this DPA, please contact:
RizzDial Legal Department
Email: admin@rizzdial.com Phone: +1 (480) 486-1869 Address: 14765 Ragsdale Lane, Roanoke, Texas 76262, United States