1. Scope and roles
This Data Processing Addendum (“DPA”) forms part of the agreement between the business accepting it (“Customer”) and Bizrie for use of the Service. It applies when Bizrie processes personal data contained in Customer Content on Customer's behalf. Customer is the controller and Bizrie is the processor, except where Customer acts as a processor for another controller, in which case Bizrie is Customer's subprocessor.
Bizrie remains an independent controller for account administration, billing, security, fraud prevention, support, and its own legal obligations as described in the Privacy Policy.
2. Processing instructions
Bizrie will process Customer Personal Data only on Customer's documented instructions, including the agreement, this DPA, Customer's use and configuration of the Service, and support requests, unless law requires otherwise. If Bizrie believes an instruction violates applicable data-protection law, it will notify Customer where legally permitted.
3. Processing details
- Subject: providing Bizrie's business-video creation, publishing, playback, billing, and support services.
- Duration: the subscription term plus the limited retention and deletion period described below.
- Activities: collection, hosting, organization, generation, transmission, retrieval, display, support, security, and deletion.
- People: Customer users, staff or representatives appearing in submitted media, and people whose information Customer includes in content.
- Data: contact and account data, business content, prompts and scripts, uploaded and generated media, likeness/voice footage, usage and device information, and support communications.
Customer must not submit protected health information, patient records, children's data, government identifiers, or other highly regulated data unless Bizrie expressly agrees in writing.
4. Confidentiality and security
Bizrie will ensure that people authorized to process Customer Personal Data are bound by confidentiality obligations and will maintain appropriate technical and organizational measures. Measures include access controls, encrypted transport, managed cloud infrastructure, least-privilege service access, authentication, logging, backups, vulnerability and dependency maintenance, and incident-response procedures appropriate to the risk.
5. Subprocessors
Customer gives general written authorization for Bizrie to use subprocessors. The current list and their functions appear on the Subprocessors page. Bizrie will impose data-protection obligations appropriate to each subprocessor's services and remains responsible for its processor obligations. Bizrie will provide notice of material new subprocessors at least 30 days before use when practicable. Customer may object on reasonable data-protection grounds by contacting support@bizrie.com.
6. Assistance and incidents
Taking into account the nature of processing and information available to it, Bizrie will reasonably assist Customer with data-subject requests, security obligations, breach notifications, impact assessments, and regulator consultations. Bizrie will notify Customer without undue delay after confirming a personal-data breach affecting Customer Personal Data and provide available information reasonably needed for Customer's obligations.
7. Deletion and return
During the subscription Customer may delete supported content or request assistance. After termination, Bizrie will delete or return Customer Personal Data within a commercially reasonable period unless law requires retention. Copies may remain temporarily in protected backups and will be isolated from ordinary use until deleted through the backup lifecycle. Custom likeness source footage follows the additional consent and deletion controls described in the Privacy Policy.
8. Audits
Bizrie will provide information reasonably necessary to demonstrate compliance with this DPA. No more than once annually, Customer may request an audit by an independent auditor under confidentiality obligations, at Customer's expense and with reasonable notice, unless a confirmed incident or regulator requires otherwise. Audits must not expose other customers' data or unreasonably disrupt the Service.
9. International transfers
For transfers of EEA personal data to a country without an adequacy decision, the parties incorporate the European Commission's 2021 Standard Contractual Clauses (“SCCs”) by reference. Module Two applies where Customer is a controller and Bizrie is a processor; Module Three applies where Customer is a processor and Bizrie is a subprocessor. The optional docking clause applies, general subprocessor authorization applies with the notice period above, and the supervisory authority, governing law, and courts are those of Ireland unless the parties' order form identifies another eligible EU Member State. Annex I and II are completed by the processing details and security measures in this DPA and the parties' account/order information. The official SCC text controls if this summary conflicts with it.
10. Customer obligations
Customer is responsible for its instructions, legal basis, required notices, data accuracy, access management, and all permissions for Customer Personal Data. Customer must obtain explicit, documented permission before submitting a person's image, voice, or likeness to create a Custom AI Team Member and must promptly notify Bizrie if that permission is withdrawn.
11. Contact
Questions or requests concerning this DPA may be sent to support@bizrie.com.
