Skip to main content

Data Processing Agreement

Last updated: April 1, 2026

This Data Processing Agreement (“DPA”) forms part of the agreement between BizDash, Inc. (“Processor”) and the customer (“Controller”) for the provision of BizDash services. This DPA reflects the parties' commitment to comply with applicable data protection laws, including the General Data Protection Regulation (EU) 2016/679 (“GDPR”).

1. Definitions

  • Personal Data: Any information relating to an identified or identifiable natural person, as defined in Article 4(1) of the GDPR.
  • Processing: Any operation performed on Personal Data, including collection, storage, alteration, retrieval, use, disclosure, or erasure.
  • Data Subject: The identified or identifiable natural person to whom the Personal Data relates.
  • Sub-processor: Any third party engaged by the Processor to process Personal Data on behalf of the Controller.
  • Supervisory Authority: An independent public authority responsible for monitoring the application of data protection laws.

2. Processing Details

Subject Matter

The Processor processes Personal Data on behalf of the Controller to provide the BizDash platform and related services as described in the service agreement.

Duration

Processing will continue for the duration of the service agreement. Upon termination, Personal Data will be deleted or returned within 30 days, unless retention is required by law.

Nature and Purpose

The purpose of processing is to provide business management services including contact management, invoicing, scheduling, project management, and other functions enabled by the BizDash platform.

Categories of Data Subjects

  • Controller's employees and team members
  • Controller's customers, clients, and contacts
  • Controller's vendors and business partners

Types of Personal Data

  • Names, email addresses, phone numbers, and mailing addresses
  • Business contact information and job titles
  • Financial data related to invoicing and payments
  • Appointment and scheduling information
  • Communications and notes stored within the platform

3. Security Measures

The Processor implements appropriate technical and organizational measures, including:

  • Organization-scoped data access and application role checks
  • HTTPS for customer-facing production traffic
  • Governed provider credentials and fail-closed integration handling
  • Audit records for governed and consequential product actions
  • Backup, recovery, and retention terms as stated in the applicable signed order
  • Security assurance status as published on the current BizDash Security page

4. Sub-processors

The Controller authorizes the Processor to engage Sub-processors for the purpose of providing the services. The Processor maintains a current list of Sub-processors, available upon request. The Processor will provide 30 days' notice before engaging a new Sub-processor, allowing the Controller to object. Each Sub-processor is bound by data protection obligations no less protective than those in this DPA.

5. Data Subject Rights

The Processor will assist the Controller in fulfilling its obligations to respond to Data Subject requests under applicable data protection laws, including requests for access, rectification, erasure, restriction, portability, and objection. The Processor will promptly notify the Controller upon receiving any such request and will not respond directly unless authorized.

6. Audit Rights

The Controller has the right to audit the Processor's compliance with this DPA. The Processor will make available all information necessary to demonstrate compliance and allow for audits conducted by the Controller or a third-party auditor. Audits will be conducted with reasonable notice, during normal business hours, and no more than once per year unless required by a Supervisory Authority or in the event of a data breach.

7. Term and Termination

This DPA shall remain in effect for as long as the Processor processes Personal Data on behalf of the Controller. Upon termination or expiration of the service agreement, the Processor will:

  • Cease all processing of Personal Data
  • Delete or return all Personal Data within 30 days, at the Controller's election
  • Provide written certification of deletion upon request
  • Ensure all Sub-processors comply with these termination obligations

Provisions that by their nature should survive termination will remain in effect, including confidentiality obligations and liability limitations.

Contact

For questions regarding this DPA, please contact our Data Protection Officer:

  • Email: dpo@bizdash.ai
  • Mail: BizDash, Inc., Attn: Data Protection Officer, 123 Innovation Drive, Suite 400, San Francisco, CA 94105