Vizibly

    Data Protection Agreement

    Effective August 9, 2026

    1. Scope and Application of this DPA

    This Data Protection Agreement ("DPA") forms part of the Agreement and applies where and to the extent that Vizibly Processes Personal Data as a Processor for You when providing Vizibly Offers under the Agreement, and only to the extent that such Processing is subject to Applicable Data Protection Laws. You agree to this DPA by accessing or using a Vizibly Offer, finalizing Your Order, or through Your express agreement, whichever happens first. This DPA commences on the Effective Date of Your Order and terminates upon expiration or termination of Your Order (or, if later, the date on which Vizibly has ceased all Processing of Personal Data).

    2. Processing of Personal Data

    2.1 Roles of the Parties. You are the Controller and Vizibly will be the Processor and/or You are the Processor and Vizibly will be a further Processor.

    2.2 Processing of Personal Data. Vizibly will Process Your Personal Data as a Processor pursuant to this DPA only (i) in accordance with Your Instructions or (ii) to comply with Vizibly's obligations under applicable laws, including Applicable Data Protection Laws, subject to any notice requirements under Applicable Data Protection Laws. The purpose of the Processing is the provision of the Vizibly Offer(s) by Vizibly to You as specified in the Agreement. The duration of the Processing is determined by You and as set forth in the Agreement.

    2.3 Your Obligations.

    (a) Pursuant to Section 2.3 (Usage Rules) of the General Terms, You represent and warrant to Vizibly that Customer Data does not and will not contain Sensitive Data. You further represent and warrant to Vizibly that Customer Data does not and will not contain any Personal Data relating to any Data Subjects located outside of the United States.

    (b) You will comply with all Applicable Data Protection Laws in issuing Instructions to Vizibly and using a Vizibly Offer. Notwithstanding anything to the contrary in the Agreement, Vizibly will not be liable for any claim or proceeding brought by an authority, court, or a Data Subject arising from or related to Vizibly's acts or omissions, to the extent that Vizibly was acting in accordance with Your Instructions. You acknowledge that any use, export, or sharing of Data accessed through Vizibly Offers by You, or by Your Authorized Users, Representatives, or other entities acting on Your behalf, is beyond the control and responsibility of Vizibly and Vizibly will have no liability whatsoever for any such use, export, or sharing.

    (c) You will ensure (and You are solely responsible for ensuring) that all Personal Data provided to Vizibly has been collected in accordance with Applicable Data Protection Laws and that You have established all necessary lawful bases under Applicable Data Protection Laws to enable Vizibly to lawfully Process Personal Data for the purposes contemplated under the Agreement, including, as applicable, by obtaining all necessary consents from and giving all necessary notices to Data Subjects.

    (d) You agree to keep the amount of Personal Data provided to Vizibly to the minimum necessary for the provision of Vizibly Offers.

    (e) When acting as a Processor, You will be responsible for passing on to the Controller all information, assistance, and notices needed for the Controller to comply with its obligations as a Controller under Applicable Data Protection Laws, given that You are the party having a direct relationship with the Controller. You will be responsible for passing on to Vizibly all of the Controller's requests and instructions related to the Processing of Personal Data pursuant to Your Order.

    2.4 Vizibly's Obligations. Vizibly will:

    (a) promptly notify You if Vizibly reasonably believes that any of Your Instructions are inconsistent with Applicable Data Protection Laws;

    (b) assist You as reasonably needed to respond to requests from regulatory authorities related to Vizibly's Processing of Personal Data or to meet any applicable filing, approval, or similar requirements in relation to Applicable Data Protection Laws;

    (c) if required by Applicable Data Protection Laws, or by a court order, subpoena, or other legal or judicial process, to Process Personal Data other than in accordance with Your Instructions, notify You without undue delay of any such requirement before Processing the Personal Data (unless applicable law prohibits such notification, in particular on important grounds of public interest);

    (d) not lease, sell, distribute, share, or otherwise encumber Personal Data;

    (e) not combine Personal Data received from or on behalf of You and Personal Data collected through Vizibly's own interactions with the Data Subject other than as provided in the Agreement or as otherwise permitted by Applicable Data Protection Laws; and

    (f) notify You if it can no longer meet its obligations under Applicable Data Protection Laws. Vizibly acknowledges that You have the right, upon reasonable notice, to take reasonable and appropriate steps to stop and remediate any unauthorized use of Personal Data.

    3. Data Subject Rights

    3.1 Assisting You. Upon Your request and taking into account the nature of the applicable Processing, Vizibly will assist You as reasonably necessary and technically feasible in complying with Your obligations concerning requests from Data Subjects to exercise their rights under Applicable Data Protection Laws, provided that You cannot reasonably fulfill such requests independently, including through use of any Vizibly Offer.

    3.2 Data Subject Requests. If Vizibly receives a request from a Data Subject in relation to the Data Subject's Personal Data, to the extent legally permitted, Vizibly will notify You and advise the Data Subject to submit the request to You. Vizibly will not otherwise communicate with the Data Subject regarding the request except as may be required by Applicable Data Protection Laws. You will be responsible for responding to any such request.

    4. Your Audit Rights

    4.1 Your Audit Rights, Generally. You may audit Vizibly's compliance with its obligations under this DPA up to once per calendar year and on such other occasions as may be required by Applicable Data Protection Laws solely to the extent You are legally required to conduct such additional audit or a competent regulatory authority with jurisdiction over You requires it, in each case upon Your written request providing reasonable detail and, where available, supporting documentation of the applicable requirement. Vizibly will contribute to such audits by providing You with the information and assistance reasonably necessary to conduct the audit. Any audit must be conducted by an independent third party mutually agreed to by the parties. The auditor must sign a customary non-disclosure agreement mutually acceptable to the parties (such acceptance not to be unreasonably withheld) providing for the confidential treatment of all information exchanged in connection with the audit and any reports regarding the results or findings thereof.

    4.2 Audit Request Procedure. To request an audit, You must submit a proposed audit plan to Vizibly at least two weeks in advance of the proposed audit date. The proposed audit plan must describe the scope, duration, and start date of the audit. Vizibly will review the proposed audit plan and provide You with any concerns or questions (for example, regarding any request for information that could compromise Vizibly's security, privacy, employment, or other relevant policies). You and Vizibly agree to work cooperatively to agree on a final audit plan. Nothing in this Section will require Vizibly to breach any duties of confidentiality.

    4.3 Audit Parameters. The audit must be conducted during regular business hours, subject to the agreed final audit plan and Vizibly's security or other relevant policies, and may not unreasonably interfere with Vizibly's business activities. You will promptly notify Vizibly of any non-compliance discovered during the course of an audit and provide Vizibly with any audit reports generated in connection with any audit unless prohibited by Applicable Data Protection Laws. You may use the audit reports only for the purposes of meeting Your regulatory audit requirements and/or confirming compliance with the requirements of this DPA. Any audits are at Your sole expense. You will reimburse Vizibly for any reasonable, documented costs (including reasonable internal time expended by Vizibly and any third parties in connection with any audits or inspections under this Section at Vizibly's then-current professional services rates, which will be made available to You upon request). You will be responsible for any fees charged by any auditor appointed by You to execute any such audit.

    4.4 Third-Party Compliance Program. If the controls or measures to be assessed in the requested audit are addressed in a SOC 2 Type 2 or similar audit report issued by a qualified third party within 12 months of Your audit request and Vizibly has confirmed there have been no known material changes in the controls audited since the date of such report, You agree to accept such report in lieu of requesting an audit of such controls or measures.

    5. Security

    5.1 Security Measures. Vizibly will implement and maintain industry-standard technical and organizational measures that are designed to protect the security, confidentiality, integrity, and availability of Personal Data and protect against Information Security Incidents, as appropriate to the nature of the Personal Data and the risks to Data Subjects, in accordance with Vizibly's Security Measures further described in Schedule 2 (Security Measures) (the "Security Measures"). Vizibly will regularly monitor compliance with its Security Measures and may update its Security Measures from time to time, including to maintain or improve security or address changes in Applicable Data Protection Laws, so long as the updated measures do not materially decrease the overall protection of Personal Data.

    5.2 Security Compliance by Vizibly Representatives. Vizibly will ensure that each Representative who may Process Personal Data is subject to written contractual obligations in place with Vizibly to keep Personal Data confidential or is under an appropriate statutory obligation of confidentiality.

    5.3 Information Security Incidents.

    (a) Notification and Response. Vizibly will notify You within forty-eight (48) hours of confirmation of an Information Security Incident relating to Your Personal Data. You acknowledge that Vizibly's notification of or response to an Information Security Incident is not an acknowledgment by Vizibly of any fault or liability. Upon Your request and taking into account the nature of the applicable Processing, Vizibly will assist You by providing, when available and to the extent within Vizibly's control, information reasonably necessary for You to meet Your Information Security Incident notification obligations pursuant to Applicable Data Protection Laws.

    (b) Your Responsibilities.

    (i) You are solely responsible for complying with Information Security Incident notification laws applicable to You and fulfilling any third-party notification obligations related to any Information Security Incident. If You determine that an Information Security Incident must be notified to any regulatory authority, any Data Subjects, the public, or others under Applicable Data Protection Laws, to the extent such notice directly or indirectly refers to or identifies Vizibly, where permitted by Applicable Data Protection Laws, You agree to notify Vizibly in advance, consult with Vizibly in good faith, and consider any clarifications or corrections Vizibly may reasonably request, provided that nothing in this Section will delay or prevent Your compliance with any notification deadline imposed under Applicable Data Protection Laws.

    (ii) You agree that You are solely responsible for Your (and Your Authorized Users') use of Vizibly Offers, including (A) making appropriate use of Vizibly Offers to ensure a level of security appropriate to the risk in respect of the Personal Data; (B) securing account authentication credentials, systems, and devices You and Your Authorized Users use to access Vizibly Offers; (C) securing Your systems and devices that You provide or make available for Vizibly to access in order to provide the Vizibly Offers; and (D) backing up Personal Data, as applicable.

    (c) Your Security Assessment. You acknowledge that You have evaluated the Vizibly Offer(s), the Security Measures, and Vizibly's commitments under this DPA and, based on information made available by Vizibly, determined that they are adequate to meet Your needs, including with respect to any security obligations applicable to You under Applicable Data Protection Laws, and provide a level of security appropriate to the risk in respect of the Personal Data.

    6. Subprocessors

    6.1 Consent to Subprocessor Engagement. You authorize Vizibly to engage Subprocessors in accordance with Section 6 (Subprocessors).

    6.2 Use of Subprocessors. When engaging any Subprocessor, Vizibly will execute a written agreement with the Subprocessor containing data protection obligations that, to the extent applicable to the nature of the services provided by the Subprocessor, are not less protective than those in this DPA with respect to Personal Data. Vizibly will remain liable for compliance with the obligations of this DPA and for any acts or omissions of a Subprocessor that cause Vizibly to breach any of its obligations under this DPA.

    6.3 Subprocessor List. Current Subprocessors, including their functions and locations, are listed in Schedule 1 (Subprocessor List) to this DPA. Vizibly may continue to engage those Subprocessors already engaged by Vizibly as of the Effective Date of Your Order.

    6.4 Change of Subprocessors. If Vizibly engages a new Subprocessor, Vizibly will provide You with written notice by e-mail or by posting within Vizibly Offers. You may object in writing to Vizibly's appointment of a new Subprocessor within 30 calendar days of such notice, provided that Your objection is based on reasonable data protection concerns that a Subprocessor does not or cannot comply with the requirements set forth in this DPA. In such event, the parties will discuss the concerns. If the parties are unable to reach a mutually acceptable resolution, You may, as Your sole and exclusive remedy, terminate Your Order for the affected Vizibly Offer by providing written notice to Vizibly and paying Vizibly all amounts due and owing under the Agreement as of the date of termination. You agree that this Section 6.4 (Change of Subprocessors) satisfies Vizibly's obligation under Applicable Data Protection Laws to give notice of and an opportunity to object to Subprocessor engagements.

    7. Return and Deletion

    7.1 During Order Term. During the term of Your Order, You may, through the features of a Vizibly Offer, access, return to Yourself, or delete Personal Data.

    7.2 Effect of Termination. Upon termination or expiration of Your Order, Vizibly will cease to Process Personal Data for any purpose other than for storage and Processing necessary to effect the return, deletion, or anonymization of such Personal Data, or as otherwise permitted or required under this DPA or Applicable Data Protection Laws. Upon Your written request, Vizibly will (i) return or make available for return, Personal Data in its possession or control, or (ii) securely delete or permanently render unreadable or inaccessible existing copies of the Personal Data. Deletion will be in accordance with industry-standard secure deletion practices. At Your request, Vizibly will give You written confirmation that it has fully complied with this Section or provide a justification as to why such compliance is not feasible.

    7.3 Data Retention. Notwithstanding the foregoing, Vizibly may retain Personal Data (i) to the extent permitted or required by applicable law for no longer than such applicable law requires or (ii) in accordance with its standard backup or record retention policies, provided that, in either case, Vizibly will (x) maintain the confidentiality of, and otherwise comply with the applicable provisions of this DPA with respect to retained Personal Data, and (y) not further Process retained Personal Data except for such purpose(s) and duration specified in the applicable law permitting or requiring such retention. Vizibly will delete or anonymize such Personal Data once it is no longer permitted or required to be retained under applicable law.

    8. Artificial Intelligence and Automated Processing

    8.1 Artificial Intelligence. Vizibly will not use Personal Data to train, fine-tune, develop, or improve any artificial intelligence or machine learning model, whether Vizibly's own or a third party's, unless such use is (a) reasonably necessary to provide the Vizibly Offer in accordance with Your documented Instructions, or (b) expressly authorized by You in writing. Vizibly will prohibit its Subprocessors, including any artificial intelligence model providers, from using Personal Data for their own model training, fine-tuning, development, or improvement purposes, except as expressly authorized by You in writing.

    8.2 Automated Processing. If any Vizibly Offer involves automated decision-making that produces legal or similarly significant effects on Data Subjects, Vizibly will: (a) disclose the existence of such Processing to You; (b) to the extent reasonably available to Vizibly, provide meaningful information about the logic involved without requiring disclosure of Vizibly's trade secrets or confidential information; and (c) reasonably cooperate with You, as required by Applicable Data Protection Laws, to enable Data Subjects to exercise applicable rights under such laws relating to automated decision-making.

    9. Miscellaneous

    9.1 Severability. If any term in this DPA is invalid or unenforceable, the rest of these terms will remain in full force and effect to the extent possible.

    9.2 Capitalized Terms. All capitalized terms not defined in Section 10 (Definitions) or otherwise in this DPA will have the meanings set forth in the General Terms.

    10. Definitions

    TermMeaning
    AgreementThe agreement between You and Vizibly for the provision of the Vizibly Offer(s) pursuant to Your Order, incorporating the Vizibly General Terms accessible at www.vizibly.io/general-terms ("General Terms") and this DPA.
    Applicable Data Protection LawsAll United States federal and state laws and regulations applicable to the Processing of Personal Data under the General Terms and this DPA pursuant to Your Order, including, as applicable, the California Consumer Privacy Act (Cal. Civ. Code §§ 1798.100 to 1798.199) as amended by the California Privacy Rights Act ("CPRA"), and any related regulations or guidance provided by the applicable regulators (the "CCPA").
    ControllerAn entity that determines the purposes and means of the processing of Personal Data. Controller has the same meaning as corresponding terms under Applicable Data Protection Laws (e.g., "Business" in the CCPA).
    Data SubjectAn identified or identifiable natural person to whom Personal Data relates.
    Instructions(i) Your documented direction to Vizibly regarding Processing to provide any Vizibly Offer and perform Vizibly's obligations in the Agreement, and (ii) Your other reasonable, documented instructions consistent with the terms of the Agreement.
    ProcessingAny operation or set of operations that is performed upon Personal Data, whether or not by automatic means, such as collection, recording, securing, organization, storage, adaptation or alteration, access, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, blocking, erasure, or destruction. "Processes" and "Process" will be construed accordingly.
    ProcessorAn entity that Processes Personal Data on behalf of a Controller. Processor has the same meaning as corresponding terms under Applicable Data Protection Laws (e.g., "Service Provider" in the CCPA).
    RepresentativesThe officers, directors, employees, agents, contractors, temporary personnel, subcontractors, and consultants of either party and its Affiliates.
    Information Security IncidentA breach of Vizibly's security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to Personal Data in Vizibly's possession, custody, or control. Information Security Incidents do not include unsuccessful attempts or activities that do not compromise the security of Personal Data, including unsuccessful login attempts, pings, port scans, denial-of-service attacks, or other network attacks on firewalls or networked systems.
    Security MeasuresDefined in Section 5.1 (Security Measures).
    SubprocessorA third party that Vizibly engages to Process Personal Data in relation to Vizibly Offers.

    Schedule 1: Subprocessor List

    SubprocessorServices ProvidedLocation
    Amazon Web ServicesCloud hosting and data storageOhio, US

    Schedule 2: Security Measures

    1. Organizational management and personnel with assigned responsibility for developing, implementing, and maintaining Vizibly's information security program.
    2. Audit and risk assessment procedures for the purposes of periodic review and assessment of risks to Vizibly's organization, monitoring and maintaining compliance with Vizibly's policies and procedures, and reporting the condition of its information security and compliance to internal senior management.
    3. Data security controls which include, at a minimum, logical segregation of data, restricted (e.g., role-based) access and monitoring, and utilization of commercially available industry-standard encryption technologies (or materially equivalent safeguards) for Personal Data when transmitted over public networks (i.e., the Internet) or when transmitted wirelessly or at rest or stored on portable or removable media (i.e., laptop computers, USB drives).
    4. Logical access controls designed to manage electronic access to data and system functionality based on authority levels and job functions (e.g., granting access on a need-to-know and least-privilege basis, use of unique user IDs and appropriate authentication credentials for all users, and periodic review and revoking/changing access promptly when employment terminates or changes in job functions occur).
    5. Password controls designed to manage and control password strength, expiration, and usage including prohibiting users from sharing passwords and requiring that Vizibly maintain password controls for its employees that are consistent with generally accepted industry standards and appropriate to the risk, including: (i) minimum password length and use of multi-factor authentication as appropriate; (ii) not being stored in readable format on Vizibly's computer systems (e.g., stored using industry-standard hashing and salting); (iii) appropriate complexity or other compensating controls; (iv) having a history threshold to prevent reuse of recent passwords; and (v) newly issued or reset passwords being changed after first use.
    6. System audit or event logging and related monitoring procedures to proactively record user access and system activity.
    7. Operational procedures and controls to provide for the secure configuration, monitoring, and maintenance of technology and information systems, including secure disposal of systems and media in accordance with commercially reasonable industry standards to render all information or data contained therein unreadable and, to the extent technically feasible, unrecoverable prior to final disposal or release from Vizibly's possession.
    8. Change management procedures and tracking mechanisms designed to test, approve, and monitor all material changes to Vizibly's technology and information assets that may affect the security of Personal Data.
    9. Incident management procedures designed to allow Vizibly to investigate, respond to, mitigate, and provide notifications in accordance with this DPA regarding events related to Vizibly's technology and information assets.
    10. Network security controls designed to protect systems from intrusion and limit the scope of any successful attack, including the use of firewalls and network segmentation, and intrusion detection and prevention, monitoring, and traffic and event correlation procedures.
    11. Vulnerability assessment, patch management, and threat protection technologies, and scheduled monitoring procedures designed to identify, assess, mitigate, and protect against identified security threats, viruses, and other malicious code.
    12. Business resilience/continuity and disaster recovery procedures designed to maintain service and support recovery from foreseeable emergencies or disasters.

    Related Documents