Dazr Suite data processing agreement

1. Definitions

Terms used here have the meaning they have in Regulation (EU) 2016/679 (the GDPR). “Customer Personal Data” means personal data that the organisation, or its members acting for it, store in Dazr Suite: the content of files, documents, spreadsheets and presentations, their names, versions and comments, the activity of an organisation space, and the share links created for its files.

2. Subject matter, duration, nature and purpose

3. Dazr’s obligations

  1. We process Customer Personal Data only on the documented instructions of the organisation. Using the functions of Dazr Suite is such an instruction. If we believe an instruction breaks the GDPR or other EU or Member State data protection law, we tell the organisation.
  2. Everyone at Dazr who can access Customer Personal Data is bound to confidentiality.
  3. We take the measures required by Article 32 GDPR; section 7 describes them.
  4. We engage sub-processors only as section 6 describes.
  5. Taking into account the nature of the processing, we help the organisation answer requests from data subjects and meet its obligations on security, breach notification, data protection impact assessments and prior consultation (Article 28(3)(e) and (f) GDPR).
  6. When the processing ends, we delete Customer Personal Data as section 12 describes, unless EU or Member State law requires us to keep it.
  7. We make available the information needed to show that we meet Article 28 GDPR, and allow and contribute to audits as section 9 describes.

4. The organisation’s obligations

5. Where data is stored

We store personal data in the European Union. Vercel, Upstash and Resend are companies based in the United States. Where one of our providers can access personal data from outside the European Economic Area, the transfer is covered by the European Commission’s Standard Contractual Clauses or by an adequacy decision of the European Commission.

6. Sub-processors

  1. The organisation authorises Dazr to engage these sub-processors: Vercel (hosting, server functions and file storage), Upstash (the database for accounts and records) and Resend (sending emails such as sign-in codes and notifications). Their locations and the data they handle are listed in the Dazr Files trust centre.
  2. We inform organisations at least 30 days before we add or replace a sub-processor, on this page and by email to the owner of each organisation.
  3. The organisation may object on reasonable data protection grounds. If we cannot meet the objection, the organisation may stop using Dazr Suite and take its files with it (section 12).
  4. Every sub-processor is bound by a written contract with data protection obligations no less protective than this agreement, and we remain responsible to the organisation for its work.

7. Security measures (Article 32 GDPR)

8. Personal data breaches

If we become aware of a personal data breach that affects Customer Personal Data, we notify the owner of the organisation without undue delay and no later than 72 hours after becoming aware of it. The notification describes, as far as known, the nature of the breach, its likely consequences, the measures taken or proposed, and a contact for more information. We help the organisation meet its own obligations under Articles 33 and 34 GDPR.

9. Audits

The organisation, or an auditor it appoints, may audit our compliance with this agreement once every twelve months, with at least 30 days’ written notice, during business hours, without unreasonable disruption and while respecting the confidentiality of other customers’ data. Where the information on our trust centre pages or a third-party report we hold answers the question, we provide that first.

10. Liability

Each party’s liability under this agreement follows the limits in the terms of use. Those limits do not restrict the rights of data subjects under Article 82 GDPR.

11. Term

This agreement applies for as long as we process Customer Personal Data, and sections 8, 9 and 12 continue after the organisation stops using Dazr Suite, for as long as we hold any of its data.

12. Return and deletion

The organisation can download all files of its space at any time as one .zip file (Storage, Download all files), and any single file with all its versions. Files deleted for good, an organisation that is deleted and its space, and an account that is deleted with its own files are removed from the live service at once. File contents are not part of our backups; the file records in the encrypted database backups expire after at most 12 months. Records that the law requires us to keep are kept only for that period.

13. Order of precedence

Where this agreement and the terms of use or the privacy notice differ on data protection, this agreement applies. Standard Contractual Clauses that apply to a transfer take precedence over both for the matters they cover.

14. Notices