Vizibly

    Data Protection Agreement

    Last updated February 2026

    1. Scope and Application of this DPA

    This Data Protection Agreement ("DPA") forms part of the Agreement and applies where, and to the extent that, Vizibly Processes Personal Data that is otherwise subject to Data Protection Laws as a Processor for You when providing Vizibly Offers under the Agreement. You agree to this DPA by accessing or using a Vizibly Offer, finalizing Your Order, or through Your express agreement, whichever happens first.

    2. Processing of Personal Data

    2.1 Roles of the Parties. You are the Controller and Vizibly will be the Processor and/or You are the Processor and Vizibly will be a further Processor.

    2.2 Processing of Personal Data. Vizibly processes Personal Data as part of this DPA as follows:

    (a) The duration of the Processing is determined by You and as set forth in the Agreement.

    (b) The purpose of the Processing is the provision of the Vizibly Offers by Vizibly to You as specified in the Agreement.

    2.3 Your Obligations. You will:

    (a) use the Vizibly Offers in compliance with all applicable Data Protection Laws;

    (b) ensure all instructions given by You to Vizibly in respect of the Processing of Personal Data are at all times in accordance with Data Protection Laws;

    (c) ensure all Personal Data provided to Vizibly has been collected in accordance with Data Protection Laws and that You have all authorizations and/or consents necessary to provide such Personal Data to Vizibly;

    (d) keep the amount of Personal Data provided to Vizibly to the minimum necessary for the provision of Vizibly Offers; and

    (e) when acting as a Processor, be responsible for passing on to the Controller all information, assistance, and notices needed to comply with its obligations as a Controller under Data Protection Laws, given that You are the party having a direct relationship with the Controller; and be responsible for passing on to Vizibly all of the Controller's requests and instructions related to the Processing of Personal Data under this DPA.

    2.4 Vizibly's Obligations. Vizibly will:

    (a) only Process Personal Data in accordance with Data Protection Laws and this DPA, and any other of Your agreed documented instructions;

    (b) promptly notify You if Vizibly reasonably believes that any of Your instructions are inconsistent with Data Protection Laws;

    (c) ensure its applicable Representatives who may Process Personal Data have written contractual obligations in place with Vizibly to keep the Personal Data confidential or are under an appropriate statutory obligation of confidentiality;

    (d) assist You as reasonably needed to respond to requests from supervisory authorities, Data Subjects, customers, or others to provide information related to Vizibly's Processing of Personal Data;

    (e) if required by Data Protection Laws, court order, subpoena, or other legal or judicial process to Process Personal Data other than in accordance with Your instructions, notify You without undue delay of any such requirement before Processing the Personal Data (unless mandatory applicable law prohibits such notification, in particular on important grounds of public interest);

    (f) maintain records of the Processing of any Personal Data received from You under the Agreement;

    (g) not lease, sell, distribute, or otherwise encumber Personal Data unless mutually agreed to by the Parties in a separate agreement;

    (h) not combine Personal Data received from or on behalf of You and Personal Data collected by Vizibly's own interactions with the Data Subject other than as provided in the Agreement or as otherwise permitted by Data Protection Laws;

    (i) provide such assistance as You reasonably require, and Vizibly or a Representative is able to provide, to meet any applicable filing, approval or similar requirements in relation to Data Protection Laws;

    (j) on termination of this DPA for whatever reason, cease to Process Personal Data, and upon Your written request and without undue delay, (i) return, or make available for return, Personal Data in its possession or control, or (ii) securely delete or permanently render unreadable or inaccessible existing copies of the Personal Data.

    3. Data Subject Rights

    To the extent legally permitted, Vizibly will promptly redirect Data Subjects to send their requests to You or notify You if it receives a Data Subject request. Unless required by Data Protection Laws, Vizibly will not respond to any Data Subject request without Your prior written consent except to redirect the Data Subject request to You. Vizibly will provide such information and cooperation and take such action as You reasonably request in relation to a Data Subject request.

    4. Your Audit Rights

    Upon Your written request no more frequently than once per calendar year, and subject to the confidentiality obligations set forth in the Agreement, Vizibly will make available to You reasonably necessary information to demonstrate Vizibly's compliance with the obligations of this DPA and Data Protection Laws. Although the Parties intend to rely on the provision of the above information to verify Vizibly's compliance with this DPA, Vizibly will permit an internationally-recognized independent auditor selected by You to conduct audits to verify compliance with its obligations under this DPA. You must submit audit requests pursuant to Section 12.10 (Notice) of the General Terms. Upon receipt of Your request, the Parties will discuss and agree in advance on the reasonable start date, scope, duration, and applicable security and confidentiality controls for the audit. You will be responsible for all costs associated with the audit. You acknowledge and agree that your audit rights under this Section can be exercised (i) if and to the extent required by a competent data protection authority; (ii) if and to the extent an audit is necessary due to a Data Breach; and (iii) no more than once in a calendar year. Your audit or inspection cannot include actions or access, physically or electronically, that could potentially violate Vizibly's privacy or compliance obligations including with respect to other customers, Affiliates, or Representatives.

    5. Security

    Vizibly will implement and maintain appropriate, industry-standard technical and organizational measures to ensure that Processing within its area of responsibility is in accordance with the requirements of Data Privacy Laws and to protect Personal Data, including protection against Data Breaches. The measures to be taken are, among others, measures (i) of data security and (ii) to guarantee a protection level appropriate to the risk concerning confidentiality, integrity, availability, and resilience of the systems.

    6. Subprocessing

    6.1 Appointment of Subprocessors. Where Vizibly appoints a Subprocessor, Vizibly will execute a written agreement with the Subprocessor containing terms at least as protective as this DPA to the extent applicable to the nature of the services provided by the Subprocessor. Vizibly will be liable for the acts or omissions of Subprocessors to the same extent it is liable for its own actions or omissions under this DPA.

    6.2 Current Subprocessor List. Current Subprocessors are listed in Schedule 1 to this DPA. You authorize the Subprocessor List as of the beginning of Your Use Term.

    6.3 Change of Subprocessors. Vizibly may update the Subprocessor list from time to time to reflect changes in Subprocessors. Vizibly will provide You thirty (30) days' prior written notice via email or in-App notification. You may object in writing to Vizibly's appointment of a new Subprocessor within ten (10) calendar days of such notice, provided that Your objection is based on reasonable grounds that the Subprocessor does not or cannot comply with the requirements set forth in this DPA. In such event, the Parties will discuss the concerns in good faith with a view to achieving resolution. Failure to object to a new Subprocessor in writing within the deadline will be deemed as Your acceptance of the new Subprocessor.

    7. Notification and Communication

    7.1 Notification. Vizibly will notify You within forty-eight (48) hours of confirmation of a Data Breach relating to Your Personal Data pursuant to Section 12.10 (Notice) of the General Terms. Vizibly will provide all such timely information and cooperation as You may reasonably require to fulfill Your Data Breach reporting obligations under (and in accordance with the timescales required by) Data Protection Laws. Vizibly will further take such measures and actions as it considers necessary or appropriate to remedy or mitigate the effects of the Data Breach and will keep You informed in connection with the Data Breach.

    7.2 Information Security Communication. Except as required by mandatory applicable law, Vizibly agrees that it will not inform any third party of a Data Breach referencing or identifying You, without Your prior written consent. Vizibly will reasonably cooperate with You and law enforcement authorities concerning a Data Breach. Vizibly will retain, for an appropriate period of time, all information and data within Vizibly's possession or control that is directly related to any Data Breach. If disclosure of the Data Breach referencing or identifying You is required by mandatory applicable law, Vizibly will work with You regarding the timing, content, and recipients of such disclosure.

    7.3 Post-incident. Vizibly will reasonably cooperate with You in any post-incident investigation, remediation, and communication efforts. Vizibly may claim compensation for support services that are not included in Vizibly's provision of the Vizibly Offer and that are not attributable to failures on the part of Vizibly.

    7.4 Complaints or notices related to Personal Data. If Vizibly receives any official complaint, notice, or communication that relates to Vizibly's Processing of Personal Data or either Party's compliance with Data Protection Laws in connection with Personal Data, to the extent legally permitted, Vizibly will promptly notify You and, to the extent applicable, Vizibly will provide You with commercially reasonable cooperation and assistance in relation to any such complaint, notice, or communication.

    8. Liability

    Each Party's respective direct liability to Data Subjects or applicable supervisory data protection authorities which cannot be limited or excluded by mandatory applicable law will be unlimited. Except for any liability which cannot be limited or excluded under mandatory applicable law, the aggregate liability of Vizibly for all Data Breaches and any breach of this DPA (whether for breach of contract, misrepresentations, negligence, strict liability, other torts or otherwise) is as set forth in the General Terms. Where a Data Breach and/or breach of this DPA is also a breach of any confidentiality or non-disclosure obligations in the Agreement, the liability cap in the General Terms will apply.

    Notwithstanding anything to the contrary in the Agreement, including this DPA, Vizibly will not be liable for any claim made by an authority, court, or a Data Subject arising from or related to Vizibly's or any of its Affiliates' acts or omissions, to the extent that Vizibly was acting in accordance with Your instructions. You acknowledge that any use, exporting or sharing of data accessed through Your Vizibly Offers by You or your employees, agents, or any other individuals or entities acting on Your behalf is beyond the control and responsibility of Vizibly. Vizibly will have no liability whatsoever for any such use, exporting or sharing of data whether negligent, instructed, or unauthorized.

    9. Miscellaneous

    9.1 Governing Law and Venue. The Parties agree to the governing law and venue stated in Section 12.9 (Governing Law and Venue) of the General Terms.

    9.2 Severability. If any term in this DPA is invalid or unenforceable, the rest of these terms will continue with full force and effect to the extent possible.

    9.3 Order of Precedence. In the event of any conflict or inconsistency between the General Terms and this DPA, the General Terms will prevail, except for matters strictly related to the processing and protection of Personal Data. In such cases this DPA will take precedence, provided that the provisions related to limitation of liability and indemnification as set forth in the General Terms will continue to govern.

    9.4 Capitalized Terms. All capitalized terms not defined in Section 10 (Definitions) or otherwise in this DPA will have the meanings set forth in the General Terms.

    10. Definitions

    TermMeaning
    AgreementThe written or electronic agreement between You and Vizibly for the provision of the Vizibly Offer(s) to You or any other terms where the Parties expressly agree to this document (e.g., Your Order, the Vizibly General Terms ("General Terms") accessible at www.vizibly.io/general-terms).
    CCPACalifornia Consumer Privacy Act (Cal. Civ. Code §§ 1798.100 to 1798.199) as amended by the California Privacy Rights Act ("CPRA"), and any related regulations or guidance provided by the applicable regulators.
    ControllerAn entity that determines the purposes and means of the processing of Personal Data. It will have the same meaning ascribed to "Business" in the CCPA and other equivalent terms under other applicable Data Protection Laws.
    Data BreachA breach leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to Personal Data, provided that it was caused by Vizibly's failure to comply with its obligations under the Agreement.
    Data Protection LawsAll applicable laws that apply to the Processing of Personal Data under the General Terms and this DPA.
    ProcessingAny operation or set of operations that is performed upon Personal Data, whether or not by automatic means, such as collection, recording, securing, organization, storage, adaptation or alteration, access to, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, blocking, erasure, or destruction. "Processes" and "Process" will be construed accordingly.
    ProcessorAn entity that processes Personal Data on behalf of a Controller. It will have the same meaning ascribed to "Service Provider" in the CCPA and other equivalent terms under other applicable Data Protection Laws.
    RepresentativesEither Party's (including its Affiliates') officers, directors, employees, agents, contractors, temporary personnel, subcontractors and consultants.
    SubprocessorAnother Processor engaged by Vizibly to carry out Processing of Your Personal Data.

    Schedule 1: Subprocessor List

    SubprocessorServices ProvidedLocation
    Amazon Web ServicesCloud hosting and data storageOhio, US

    Related Documents