Data Processing Agreement
Last updated: April 1, 2026
This Data Processing Agreement (“DPA”) forms part of the agreement between BizDash, Inc. (“Processor”) and the customer (“Controller”) for the provision of BizDash services. This DPA reflects the parties' commitment to comply with applicable data protection laws, including the General Data Protection Regulation (EU) 2016/679 (“GDPR”).
1. Definitions
- Personal Data: Any information relating to an identified or identifiable natural person, as defined in Article 4(1) of the GDPR.
- Processing: Any operation performed on Personal Data, including collection, storage, alteration, retrieval, use, disclosure, or erasure.
- Data Subject: The identified or identifiable natural person to whom the Personal Data relates.
- Sub-processor: Any third party engaged by the Processor to process Personal Data on behalf of the Controller.
- Supervisory Authority: An independent public authority responsible for monitoring the application of data protection laws.
2. Processing Details
Subject Matter
The Processor processes Personal Data on behalf of the Controller to provide the BizDash platform and related services as described in the service agreement.
Duration
Processing will continue for the duration of the service agreement. Upon termination, Personal Data will be deleted or returned within 30 days, unless retention is required by law.
Nature and Purpose
The purpose of processing is to provide business management services including contact management, invoicing, scheduling, project management, and other functions enabled by the BizDash platform.
Categories of Data Subjects
- Controller's employees and team members
- Controller's customers, clients, and contacts
- Controller's vendors and business partners
Types of Personal Data
- Names, email addresses, phone numbers, and mailing addresses
- Business contact information and job titles
- Financial data related to invoicing and payments
- Appointment and scheduling information
- Communications and notes stored within the platform
3. Security Measures
The Processor implements appropriate technical and organizational measures, including:
- Organization-scoped data access and application role checks
- HTTPS for customer-facing production traffic
- Governed provider credentials and fail-closed integration handling
- Audit records for governed and consequential product actions
- Backup, recovery, and retention terms as stated in the applicable signed order
- Security assurance status as published on the current BizDash Security page
4. Sub-processors
The Controller authorizes the Processor to engage Sub-processors for the purpose of providing the services. The Processor maintains a current list of Sub-processors, available upon request. The Processor will provide 30 days' notice before engaging a new Sub-processor, allowing the Controller to object. Each Sub-processor is bound by data protection obligations no less protective than those in this DPA.
5. Data Subject Rights
The Processor will assist the Controller in fulfilling its obligations to respond to Data Subject requests under applicable data protection laws, including requests for access, rectification, erasure, restriction, portability, and objection. The Processor will promptly notify the Controller upon receiving any such request and will not respond directly unless authorized.
6. Audit Rights
The Controller has the right to audit the Processor's compliance with this DPA. The Processor will make available all information necessary to demonstrate compliance and allow for audits conducted by the Controller or a third-party auditor. Audits will be conducted with reasonable notice, during normal business hours, and no more than once per year unless required by a Supervisory Authority or in the event of a data breach.
7. Term and Termination
This DPA shall remain in effect for as long as the Processor processes Personal Data on behalf of the Controller. Upon termination or expiration of the service agreement, the Processor will:
- Cease all processing of Personal Data
- Delete or return all Personal Data within 30 days, at the Controller's election
- Provide written certification of deletion upon request
- Ensure all Sub-processors comply with these termination obligations
Provisions that by their nature should survive termination will remain in effect, including confidentiality obligations and liability limitations.
Contact
For questions regarding this DPA, please contact our Data Protection Officer:
- Email: dpo@bizdash.ai
- Mail: BizDash, Inc., Attn: Data Protection Officer, 123 Innovation Drive, Suite 400, San Francisco, CA 94105