Data Protection Addendum
Last Modified – September 23, 2026
Jump to Section
This Data Protection Addendum (“Addendum”) is incorporated into and subject to the Online Customer Terms & Conditions (the “Customer Terms”) between Customer and Lyzr, Inc. (“LYZR”) (each a “Party” and collectively the “Parties”).
All capitalized terms not defined in this Addendum shall have the meanings set forth in the Customer Terms. This Addendum reflects the Parties’ agreement with respect to the terms governing LYZR’s processing of Personal Data protected by Data Privacy Laws. For any other data, including admin account information, this Addendum shall not apply.
In the event of any conflict or inconsistency between the terms of the Customer Terms and this Addendum, the terms of this Addendum shall take precedence over the Customer Terms and any other associated contractual document between the Parties, to the extent of any such conflict.
The Parties agree as follows:
Definitions
For purposes of this Addendum:
- (a)“Applicable SCCs” means the Standard Contractual Clauses (i.e. EU SCCs and/or UK SCCs) that apply to Personal Data processed pursuant to this Addendum.
- (b)“Data Privacy Laws” means all data protection laws and regulations applicable to a Party’s Processing of Personal Data, including and as applicable but not limited to:
- (i)The California Consumer Privacy Act, Cal. Civ. Code § 1798.100 et seq., including its regulations and the amendments made by the California Privacy Rights Act of 2020 (“CCPA”);
- (ii)all other applicable U.S. state and federal data privacy and data protection laws and regulations; and
- (iii)EU Data Privacy Laws; in each case as amended, superseded or updated from time to time.
- (c)“Data Subject” means an identified or identifiable natural person about whom Personal Data relates.
- (d)“EEA” means, for the purposes of this Addendum, the European Union, Iceland, Liechtenstein, and Norway.
- (e)“EU Data Privacy Laws” means all data protection laws and regulations applicable to the EEA, including:
- (i)General Data Protection Regulation (EU) 2016/679 (“GDPR”) and any applicable national implementations of the GDPR;
- (ii)in respect of the United Kingdom, the Data Protection Act 2018 and any applicable national legislation that replaces or converts in domestic law the GDPR or any other law relating to data and privacy as a consequence of the United Kingdom leaving the European Union; and
- (iii)in respect of Switzerland, The Federal Act on Data Protection of 19 June 1992 and its Ordinances.
- (f)“EU SCCs” means the Standard Contractual Clauses issued pursuant to Commission Implementing Decision (EU) 2021/914 of 4 June 2021 on standard contractual clauses for the transfer of personal data to third countries pursuant to Regulation (EU) 2016/679 of the European Parliament and of the Council, completed as set forth in Schedule A to this Addendum. To the extent that the Processing of Personal Data is subject to the Swiss Federal Act on Data Protection ("Swiss FADP"), the EU SCCs shall also apply to such Processing, subject to the following modifications:
- (i)references to “Regulation (EU) 2016/679” and the “GDPR” shall be interpreted as references to the Swiss FADP;
- (ii)references to “EU,” “Union,” and “Member State” shall be interpreted to include Switzerland;
- (iii)the competent supervisory authority under Clause 13 of the EU SCCs shall be the Swiss Federal Data Protection and Information Commissioner; and
- (iv)the EU SCCs shall be governed by the laws of Switzerland to the extent the transfer is subject solely to the Swiss FADP.
- (g)“Personal Data” includes any Customer Data that is protected as “personal data,” “personal information,” or “personally identifiable information,” under Data Privacy Laws and Processed by LYZR on behalf of Customer via the Products in connection with the Products, as more particularly described in Schedule A of this Addendum.
- (h)“Process” and “Processing” mean any operation or set of operations performed on Personal Data or on sets of Personal Data, whether or not by automated means, such as collection, recording, organization, creating, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure, or destruction.
- (i)“Security Breach” means any breach of security that leads to the accidental or unlawful acquisition, destruction, loss, alteration, unauthorized disclosure of, or access to, Personal Data transmitted, stored or otherwise processed by LYZR and/or its Sub-processors in connection with the provision of the Products. “Security Breach” shall not include unsuccessful attempts or activities that do not compromise the security of Personal Data, including unsuccessful log-in attempts, pings, port scans, denial of service attacks, and other network attacks on firewalls or networked systems.
- (j)“Sub-processor” means any processor engaged by LYZR or its Affiliates to assist in fulfilling its obligations with respect to providing the Products pursuant to the Customer Terms or this Addendum. Sub-processors may include third parties or Affiliates of LYZR but shall exclude any LYZR employee, contractor or consultant.
- (k)“UK SCCs” means the International Data Transfer Addendum to the EU Commission Standard Contractual Clauses (available as of the Effective Date at https://ico.org.uk/for-organisations/guide-to-data-protection/guide-to-the-generaldata-protection-regulation-gdpr/international-data-transfer-agreement-andguidance/), completed as set forth in this Addendum.
- (l)The terms “controller”, “personal data”, and “processor” shall have the meanings given to them in GDPR and the terms “personal information”, “business”, “business purpose”, “commercial purpose”, “collect”, “consumer”, “service provider” and “sell” shall have the meanings given to them in the CCPA.
Scope and Purposes of Processing
- (a)This Addendum applies to the extent LYZR Processes, as a processor or service provider (as applicable), any Personal Data protected by Data Privacy Laws in connection with the Products. LYZR will only Process Personal Data as set forth in this Addendum and in compliance with Data Privacy Laws.
- (b)The Parties acknowledge and agree that Customer is a controller or business (as applicable) with respect to the Processing of Personal Data, and LYZR will Process Personal Data only as a processor or service provider (as applicable) on behalf of Customer in connection with the Products, as further described in Schedule A of this Addendum.
- (c)As a processor or service provider, LYZR shall Process Personal Data only for the purposes described in this Addendum and only in accordance with Customer’s written lawful instructions. The Parties agree that the Customer Terms (including this Addendum) sets out the Customer’s complete and final instructions to LYZR in relation to the Processing of Personal Data and Processing outside the scope of these instructions (if any) shall require prior written agreement between the Parties.
- (d)Without prejudice to Section 3 (Customer Responsibilities), LYZR shall immediately notify Customer in writing, unless prohibited from doing so under Data Privacy Law, if it becomes aware or believes that any Processing instructions from Customer violates EU Data Privacy Laws.
- (e)The Parties acknowledge that Personal Data that has been de-identified is not “personal information” (within the meaning of Data Privacy Laws). LYZR may de-identify Personal Data only if it: (i) has implemented technical safeguards that prohibit re-identification of the Data Subject to whom the information may pertain; (ii) has implemented business processes that specifically prohibit re-identification of the information; (iii) has implemented business processes to prevent inadvertent release of de-identified information; and (iv) makes no attempt to re-identify the information.
Customer Responsibilities
- (a)Customer shall have sole responsibility for the accuracy, quality, and legality of Personal Data and the means by which Customer acquired Personal Data.
- (b)Customer represents and warrants that:
- (i)it has provided, and will continue to provide, all notices and has obtained, and will continue to obtain, all consents, permissions and rights necessary under applicable laws, including Data Privacy Laws, for LYZR to lawfully Process Personal Data for the purposes contemplated by the Customer Terms (including this Addendum);
- (ii)it has complied with all applicable laws, including Data Privacy Laws in the collection and provision to LYZR of such Personal Data; and
- (iii)it shall ensure its Processing instructions comply with applicable laws (including Data Privacy Laws) and that the processing of Personal Data by LYZR in accordance with Customer’s instructions will not cause LYZR to be in breach of applicable Data Privacy Laws.
CCPA Processing
- (a)To the extent LYZR Processes Personal Data that is protected by the CCPA, the terms in this Section 4 shall apply in addition to the terms in the remainder of the Addendum. In the event of any conflict or ambiguity between the terms in this Section 4 and any other terms in this Addendum, the terms in this Section 4 shall take precedence but only to the extent they apply to the Personal Data in question.
- (b)LYZR will Process Personal Data solely (1) to fulfill its obligations to Customer under the Customer Terms, including this Addendum; (2) on Customer’s behalf; and (3) in compliance with Data Privacy Laws. Except as explicitly authorized under Data Privacy Laws, LYZR will:
- (i)not retain, use, or disclose the Personal Data outside of the direct business relationship between Customer and LYZR;
- (ii)not “sell” or “share” any Personal Data, as such terms are defined in the CCPA and other applicable U.S. state privacy laws, to any third party;
- (iii)not attempt to (1) re-identify any pseudonymized, anonymized, aggregate, or de-identified Personal Data, or (2) link, identify, or otherwise create a relationship between Personal Data and non-Personal Data or any other data, without Customer’s express written permission;
- (iv)comply with any applicable restrictions under Data Privacy Laws on combining the Personal Data with personal data that LYZR receives from, or on behalf of, another person or persons, or that LYZR collects from any interaction between it and any individual; and
- (v)not otherwise engage in any Processing of the Personal Data that is prohibited or not permitted by Processors or Service Providers under Data Privacy Laws.
- (c)LYZR shall provide the same level of privacy protection for the Personal Data as is required under the CCPA.
- (d)LYZR shall notify Customer if it determines it can no longer meet its obligations under the CCPA.
- (e)Customer retains the right, upon notice, to take reasonable and appropriate steps to stop and remediate unauthorized use of Personal Data, including any use of Personal Data not expressly authorized in this Addendum.
- (f)Sub-Processors.
- (i)Customer provides general written authorization to LYZR to engage Sub-processors to Process Personal Data on Customer’s behalf in connection with the Products. LYZR shall maintain a current list of its Sub-processors at a URL designated by LYZR (“Sub-processor List”), which shall identify the name, location, and processing activities of each Sub-processor.
- (ii)LYZR shall notify Customer of any intended changes to the Sub-processor List (including the addition or replacement of Sub-processors) at least fifteen (15) days prior to engaging any new Sub-processor. Customer may subscribe to notifications of Sub-processor changes through the mechanism specified on the Sub-processor List page.
- (iii)If Customer has a reasonable, documented basis for objecting to a new Sub-processor on data protection grounds, Customer shall notify LYZR in writing within fifteen (15) days of receiving notice of the proposed change. LYZR shall use commercially reasonable efforts to make available to Customer a change in the Products or recommend a commercially reasonable change to Customer’s use of the Products to avoid Processing of Personal Data by the objected-to Sub-processor. If LYZR is unable to provide such alternative within a reasonable period of time, Customer may terminate the applicable Order Form with respect to the affected Products by providing written notice to LYZR, and LYZR shall refund to Customer any prepaid fees covering the remainder of the term following the effective date of such termination.
- (iv)LYZR shall impose data protection obligations on each Sub-processor by way of a written contract that provides at least the same level of protection for Personal Data as those set out in this Addendum. LYZR shall remain fully liable to Customer for the performance of each Sub-processor’s obligations.
Data Subject Rights and Cooperation
- (a)LYZR will promptly notify Customer of: (i) any third-party or individual (e.g. on Customer’s behalf; or (ii) any government or Data Subject requests for access to or information about LYZR’s Processing of Personal Data on Customer’s behalf (each a “Communication”), unless prohibited by Data Privacy Laws. In the event LYZR receives such Communication directly, LYZR will not respond to such Communication except as appropriate (for example, to direct the Data Subject to contact Customer) or where legally required, without Customer’s prior authorization.
- (b)Taking into account the nature of the Processing and upon written request of Customer, LYZR will provide all reasonable cooperation to assist Customer, by appropriate technical and organizational measures, in so far as is possible, to respond to Communications.
- (c)To the extent required under applicable Data Privacy Laws and taking into account the nature of the Processing and the information available to LYZR, LYZR will provide all reasonably requested information regarding the Products to enable Customer to carry out a data protection impact assessment or prior consultation with supervisory authorities, as required by Data Privacy Laws. LYZR shall comply with the foregoing by:
- (i)complying with Section 8 (Audits);
- (ii)providing the information contained in the Customer Terms, including this Addendum; and
- (iii)if the foregoing sub-sections (i) and (ii) are insufficient for Customer to comply with such obligations, upon request, providing additional reasonable assistance (at Customer’s expense).
Data Security
- (a)LYZR will:
- (i)implement appropriate and reasonable administrative, technical, physical, and organizational measures designed to protect Personal Data from Security Breaches and to preserve the security and confidentiality of Personal Data (“Security Measures”); and
- (ii)ensure that any person it authorizes to Process the Personal Data is under an appropriate obligation of confidentiality (whether statutory or contractual).
- (b)Customer acknowledges that the Security Measures are subject to technical progress and development and that LYZR may update or modify the Security Measures from time to time, provided that such updates and modifications do not result in the degradation of the overall security of the Products provided to Customer.
- (c)Notwithstanding the above, Customer agrees that except as provided by this Addendum, Customer is responsible for its secure use of the Products, including securing its account authentication credentials, protecting the security of Customer Data when in transit to and from the Products, and taking any appropriate steps to securely encrypt or backup any Customer Data uploaded to the Products.
Security Breach
- (a)Upon becoming aware of a Security Breach, LYZR will:
- (i)notify Customer promptly, and where feasible, within 48 hours of becoming aware of any Security Breach;
- (ii)provide timely information relating to the Security Breach as it becomes known or as is reasonably requested by Customer; and
- (iii)promptly take reasonable steps to contain and investigate any Security Breach.
- (b)LYZR’s notification of or response to a Security Breach under this Section 7 shall not be construed as an acknowledgment by LYZR of any fault or liability with respect to the Security Breach.
Audits
- (a)Upon Customer’s request, LYZR will make available to Customer all information reasonably necessary to demonstrate compliance with this Addendum and will allow for and contribute to audits, including inspections, conducted by Customer or another auditor mandated by Customer in order to assess compliance with this Addendum. Customer acknowledges and agrees that it shall exercise its audit rights under this Addendum (including this Section 8(a) and, where applicable, the Applicable SCCs) and any audit rights granted under Data Privacy Laws, by instructing LYZR to comply with the audit measures described in Section 8(b) below.
- (b)Upon written request, LYZR will supply (on a confidential basis) to Customer a summary copy of its most current audit report(s) (“Audit Report”) prepared by third-party security professionals at LYZR’s selection and expense. In addition to the Audit Report, LYZR shall respond to all reasonable requests for information made by Customer to confirm LYZR’s compliance with this Addendum, including responses to information security, due diligence, and audit questionnaires, by making additional information available regarding its information security program upon Customer’s written request provided that Customer shall not exercise this right more than once per calendar year.
- (c)Nothing herein will require LYZR to disclose or make available:
- (i)any data of any other customer of LYZR;
- (ii)LYZR’s internal accounting or financial information;
- (iii)any trade secret of LYZR;
- (iv)any information that, in LYZR’s reasonable opinion, could (y) compromise the security of LYZR systems or premises or (z) cause LYZR to breach its obligations under Data Privacy Laws or its security and/or privacy obligations to any third party; or
- (v)any information sought for any reason other than the good faith fulfillment of Customer’s obligations under Data Privacy Laws.
Return or Destruction of Personal Data
Upon termination or expiry of the Customer Terms, LYZR will, at the choice and written request of Customer, return to Customer and/or securely destroy all Personal Data in its possession or control in accordance with the Customer Terms, save that this requirement shall not apply to the extent LYZR is required by applicable law to retain some or all of the Personal Data, or to Personal Data it has archived on backup systems, which data LYZR shall securely isolate and protect from any further Processing and delete in accordance with its deletion practices.
Limitation of Liability
LYZR’s liability arising out of or in connection with this Addendum is subject to the limitations and exclusions of liability stated in the Customer Terms.
Term
The effective date of this Addendum is the date of the latest signature of a Party.
Survival
The provisions of this Addendum survive the termination or expiration of the Customer Terms for so long as LYZR or its Sub-processors Process Personal Data.
Schedule A — Annex I
A. List of Parties
Data Exporter
Identity and contact details of the data exporter(s) and, where applicable, of its/their data protection officer and/or representative in the European Union.
- Name
- Set forth in the Order Form
- Address
- Set forth in the Order Form
- Contact person’s name, position and contact details
- Set forth in the Order Form
- Activities relevant to the data transferred under these Clauses
- As described in the Customer Terms and Order Form.
- Role (controller/processor)
- Controller
Data Importer
Identity and contact details of the data importer(s), including any contact person with responsibility for data protection.
- Name
- LYZR, Inc.
- Address
- 525, Washington Blvd, 2410, Jersey City, NJ 07310
- Contact person’s name, position and contact details
- —
- Activities relevant to the data transferred under these Clauses
- Data importer will process the data in order to provide the Products pursuant to the Customer Terms.
- Role (controller/processor)
- Processor
B. Description of Transfer
Data subjects include the individuals about whom data is provided to LYZR via the Products by (or at the direction of) Customer or its Authorized Users.
The categories of Personal Data are determined by Customer in its sole discretion and include data relating to individuals provided to LYZR via the Products, by (or at the direction of) Customer or its Authorized Users.
LYZR does not intentionally collect or Process any special categories of Personal Data.
The Personal Data shall be transferred continuously for as long as LYZR provides the Products pursuant to the Customer Terms.
The nature of the processing consists of collecting, storing and transferring Personal Data to facilitate LYZR’s provision of the Products to Customer as further described in the Customer Terms.
The purposes of the data transfer is so that LYZR can provide the Products to Customer as further described in the Customer Terms. There is no processing other than as set forth above.
The Personal Data shall be retained as directed by LYZR as needed to provide the Products pursuant to the Customer Terms.
Same as above.
C. Competent Supervisory Authority
Identify the competent supervisory authority/ies in accordance with Clause 13: Irish Data Protection Commission for data transfers from the EEA; Information Commissioner’s Office for data transfers from the United Kingdom.
Annex II — Technical and Organisational Measures
Technical and organisational measures including technical and organisational measures to ensure the security of the data.
Governance
Assign to an individual or a group of individuals appropriate roles for developing, coordinating, implementing, and managing Vendor’s administrative, physical, and technical safeguards designed to protect the security, confidentiality, and integrity of Personal Data.
- a.Use of data security personnel that are sufficiently trained, qualified, and experienced to be able to fulfill their information security-related functions.
Risk Assessment
Conduct periodic risk assessments designed to analyze existing information security risks, identify potential new risks, and evaluate the effectiveness of existing security controls.
- a.Maintain risk assessment processes designed to evaluate likelihood of risk occurrence and material potential impacts if risks occur.
- b.Document formal risk assessments.
- c.Review formal risk assessments by appropriate managerial personnel.
Information Security Policies
Create information security policies, approved by management, published and communicated to all employees and relevant external parties.
- a.Review policies at planned intervals or if significant changes occur to ensure its continuing suitability, adequacy, and effectiveness.
Human Resources Security
Maintain policies requiring reasonable background checks of any new employees who will have access to Vendor systems, subject to local law.
- a.Regularly and periodically train personnel on information security controls and policies that are relevant to their business responsibilities and based on their roles within the organization.
Asset Management
Maintain policies establishing data retention and secure destruction requirements.
Access Controls
Maintain controls designed to limit access to Personal Data.
- a.Review personnel access rights on a periodic basis.
- b.Maintain policies requiring termination of physical and electronic access to Personal Data and Vendor systems after termination of an employee.
- c.Implement access controls designed to authenticate users and limit access to Personal Data and Services.
- d.Implement policies restricting access to the data center facilities hosting Services to approved data center personnel and limited and approved Vendor personnel.
- e.Maintain dual layer access authentication processes for Vendor personnel with administrative access rights to the Services.
Cryptography
Encrypt sensitive data using a minimum of AES-128 bit ciphers in transit.
Physical Security
- a.Maintain high assurance physical security controls including manned security stations, mantraps, and biometric or badge-based access control.
Operations Security
Perform periodic network and application vulnerability testing using qualified internal or 3rd party resources.
- a.Contract with qualified independent 3rd parties to perform periodic penetration testing.
- b.Implement procedures to document and remediate vulnerabilities discovered during vulnerability and penetration tests.
Communications Security
Maintain a secure boundary using firewalls and network traffic filtering.
- a.Require segmentation to isolate production systems from development systems.
- b.Require periodic reviews and testing of network controls.
System Acquisition, Development, and Maintenance
Assign responsibility for system security, system changes and maintenance.
- a.Test, evaluate and authorize major system components prior to implementation.
Supplier Relationship
Periodically review available security assessment reports of Sub-processors hosting the Products to assess their security controls and analyze any exceptions set forth in such reports.
Information Security Incident Management
Monitor the access, availability, capacity and performance of the Products, and related system logs and network traffic.
- a.Maintain incident response procedures for identifying, reporting, and acting on Information Security Incidents.
- b.Establish a cross-disciplinary Security Incident response team.
Business Continuity Management
Design customer portal infrastructure with goal of 99.5% uptime.
- a.Implement a tiered data architecture with operational diversity to allow rapid recovery in the event a service impacting incident.
- b.Establish procedures designed to ensure all applicable statutory, regulatory and contractual requirements are adhered to.