Vizzybl LogoVizzybl LogoVizzybl

Data Processing Agreement

This Data Processing Agreement ("DPA") forms part of the Agreement between:

(1) YouGrow.AI Limited, a company incorporated in England and Wales under company number 16046092, whose registered office is at 10 Ardmore Way, Guildford, England, GU2 9RR, trading as "Vizzybl.ai" ("Processor", "we", "us"); and

(2) the customer entity identified in the Agreement ("Controller", "you").


1. Definitions

1.1 "Data Protection Law" means, as applicable: (a) the UK GDPR and the Data Protection Act 2018 ("UK GDPR"); and (b) Regulation (EU) 2016/679 ("EU GDPR") where the Controller's processing falls within its scope.

1.2 "Customer Personal Data" means personal data contained within Customer Content that we process on your behalf under the Agreement. It does not include account registration or billing data, in respect of which we act as an independent controller (see clause 11).

1.3 "Subprocessor" means any third party engaged by us to process Customer Personal Data.

1.4 "UK Addendum" means the International Data Transfer Addendum to the EU Commission Standard Contractual Clauses issued by the Information Commissioner under s.119A of the Data Protection Act 2018.

1.5 "EU SCCs" means the standard contractual clauses annexed to Commission Implementing Decision (EU) 2021/914.

1.6 Terms including "controller", "processor", "personal data", "processing", "data subject" and "personal data breach" have the meanings given in the UK GDPR.

2. Roles and scope

2.1 You are the controller and we are the processor in respect of Customer Personal Data.

2.2 We will process Customer Personal Data only for the purposes described in Annex I and in accordance with this DPA.

2.3 Each party will comply with its own obligations under Data Protection Law. You are responsible for ensuring you have a lawful basis for the processing you instruct, and for the accuracy and legality of Customer Content you upload.

3. Processing on documented instructions

3.1 We will process Customer Personal Data only on your documented instructions, including as to international transfers, unless required to do otherwise by law. Where we are required by law to process otherwise, we will inform you before processing unless that law prohibits it.

3.2 The Agreement, this DPA, and your configuration of the Services (including your choice of data region, enabled integrations, and configured notification channels) constitute your documented instructions.

3.3 Processing locations. Customer Personal Data may be processed in the countries in which we and our Subprocessors operate, as identified in Annex III, in each case subject to the transfer safeguards stated there. Where you select a storage region, that selection determines where Customer Personal Data is held at rest.

3.4 We will inform you if, in our opinion, an instruction infringes Data Protection Law.

4. Confidentiality

4.1 We will ensure that persons authorised to process Customer Personal Data are bound by an appropriate duty of confidentiality and have received appropriate data protection training.

4.2 We will limit access to Customer Personal Data to those personnel who require access to perform the Agreement.

5. Security

5.1 We will implement and maintain the technical and organisational measures set out in Annex II, taking into account the state of the art, costs of implementation, and the nature, scope, context and purposes of processing, as required by Article 32.

5.2 We may update those measures provided the level of protection is not materially reduced.

6. Subprocessors

6.1 You provide general written authorisation for us to engage Subprocessors. The Subprocessors authorised as at the date of this DPA are listed in Annex III.

6.2 We will give you at least thirty (30) days' notice before adding or replacing a Subprocessor, by email to the administrator contact registered on your account. You are responsible for keeping that contact address current and monitored.

6.3 You may object to a proposed Subprocessor on reasonable data protection grounds within that notice period. If we cannot accommodate your objection, you may terminate the affected Services without penalty as your sole remedy.

6.4 We will impose on each Subprocessor data protection obligations no less protective than those in this DPA, and we remain fully liable to you for each Subprocessor's performance.

7. Assistance to the Controller

7.1 Data subject rights. Taking into account the nature of the processing, we will assist you by appropriate technical and organisational measures, insofar as possible, to respond to data subject requests. Where we receive a request directly from a data subject relating to Customer Personal Data, we will not respond substantively and will refer them to you without undue delay.

7.2 Personal data breach. We will notify you without undue delay, and in any event within seventy-two (72) hours, after becoming aware of a personal data breach affecting Customer Personal Data, and will provide the information reasonably available to us to support your own notification obligations under Articles 33 and 34.

7.3 DPIAs and prior consultation. We will provide reasonable assistance with data protection impact assessments and prior consultation with a supervisory authority, taking into account the nature of processing and the information available to us.

8. International transfers

8.1 You authorise us to transfer Customer Personal Data to the countries identified in Annex III for the purposes described.

8.2 Where a transfer is a restricted transfer under UK GDPR, it is made under: (a) UK adequacy regulations where the destination is covered by them; or (b) the EU SCCs as amended by the UK Addendum, which are incorporated into this DPA by reference and deemed executed by the parties' execution of the Agreement.

8.3 Where a transfer is a restricted transfer under EU GDPR, it is made under: (a) an adequacy decision of the European Commission where one applies; or (b) the EU SCCs, incorporated by reference, with Module Two (controller to processor) applying between you and us and Module Three (processor to processor) applying between us and our Subprocessors.

8.4 For the purposes of the EU SCCs and UK Addendum:

8.5 Where we rely on a Subprocessor's own transfer safeguard (for example, certification under the EU-US Data Privacy Framework and its UK Extension), that safeguard is identified in Annex III.

9. Deletion and return

9.1 On termination or expiry of the Agreement, we will, at your election, delete or return all Customer Personal Data, and delete existing copies, unless retention is required by law.

9.2 You may export Customer Content through the Services at any time during the term. Absent an election under clause 9.1, we will delete Customer Personal Data within thirty (30) days of termination.

9.3 Following deletion under clause 9.1 or 9.2, residual copies of Customer Personal Data persist in our backup and disaster-recovery layers and are removed on a rolling cycle: point-in-time recovery within 7 days, scheduled database backups within 14 weeks (98 days), and cross-region disaster-recovery exports within 180 days. Those copies remain subject to the protections of this DPA until they are removed, are not accessible through the Services, and are not restored into live systems except in a disaster-recovery event.

10. Audit

10.1 We will make available to you the information necessary to demonstrate compliance with Article 28 and this DPA.

10.2 You may audit no more than once in any twelve (12) month period, on at least thirty (30) days' written notice, during business hours, subject to confidentiality obligations, and without access to the data or systems of any other customer. Additional audits may be conducted where required by a supervisory authority or following a personal data breach.

10.3 We may satisfy clauses 10.1 and 10.2 by providing a completed security questionnaire and, where one is available, a current third-party audit report or certification.

11. Data for which we act as controller

11.1 We act as an independent controller in respect of: account registration and administrator contact details; billing and payment data; website visitor data collected via our own website (including cookie consent records and analytics); and support correspondence initiated by your personnel.

11.2 Our processing of that data is described in our Privacy Notice at https://vizzybl.ai/privacy. The Subprocessors listed in Annex III do not include vendors used solely for that controller-side processing; those are identified separately in our Privacy Notice.

12. General

12.1 This DPA prevails over any conflicting term of the Agreement in respect of the processing of Customer Personal Data. In the event of a conflict between this DPA and the EU SCCs or UK Addendum, the SCCs or Addendum prevail.

12.2 Our aggregate liability under this DPA is subject to the limitations of liability in the Agreement, save to the extent Data Protection Law prohibits such limitation.

12.3 This DPA is governed by the laws of England and Wales, and the courts of England and Wales have exclusive jurisdiction, without prejudice to clauses 8.4 and 12.1.


Annex I — Description of processing

A. Parties

Data exporter (Controller): the customer entity identified in the Agreement. Data importer (Processor): YouGrow.AI Limited (company number 16046092), trading as Vizzybl.ai, 10 Ardmore Way, Guildford, England, GU2 9RR, United Kingdom. Processor's data protection contact: [email protected] EU Article 27 representative: where a representative is required under Article 27 EU GDPR, its identity is published in our Privacy Notice at https://vizzybl.ai/privacy.

B. Categories of data subjects

C. Categories of personal data

No special category data (Article 9) or criminal offence data (Article 10) is required by the Services. The Controller must not submit such data as Customer Content.

D. Nature and purpose of processing; processing locations

Hosting and operation of the Services, including storage, retrieval, indexing, analytics, AI-assisted analysis of Customer Content, notification delivery, and support.

Customer Content is held at rest in the storage region selected by the Controller: the European Union, the United States, or Asia Pacific. Processing is carried out in the locations of the Subprocessors identified in Annex III, subject to the transfer safeguards stated there.

E. Duration

For the term of the Agreement, plus the retention period in clause 9.2.

F. Competent supervisory authority

The UK Information Commissioner's Office (ICO). Where EU GDPR applies, the supervisory authority determined in accordance with Clause 13 of the EU SCCs.


Annex II — Technical and organisational measures

We implement and maintain technical and organisational security measures designed to protect Customer Personal Data against unauthorised or unlawful access, acquisition or disclosure, and against destruction, alteration, accidental loss, misuse or damage, in accordance with SOC 2, ISO 27001, NIST 800-53 or a substantially equivalent standard, and appropriate to the risk presented by the processing.

Those measures include:

We may update these measures from time to time provided the level of protection is not materially reduced.


Annex III — Authorised Subprocessors

Accurate as at 12 August 2026. Location is the Subprocessor's principal place of establishment; the transfer safeguard column states the mechanism relied upon.

SubprocessorPurposeLocationTransfer safeguard
Adobe Inc.Project management integrationUnited StatesData Privacy Framework and UK Extension; SCCs and UK Addendum
Anthropic, PBCAI model providerUnited StatesData Privacy Framework and UK Extension; SCCs and UK Addendum
Atlassian, Inc.Project management integrationUnited StatesData Privacy Framework and UK Extension; SCCs and UK Addendum
Bright Data Ltd.Data providerIsraelAdequacy decision (Israel)
Cloudflare, Inc.CDN and network security providerUnited StatesData Privacy Framework and UK Extension; SCCs and UK Addendum
DataForSEO OÜSearch data providerEstoniaNone required — processing within the EEA
Discord Inc.Notification deliveryUnited StatesData Privacy Framework, UK Extension and Swiss-US DPF
Google LLCCloud infrastructure and AI model providerUnited StatesData Privacy Framework and UK Extension; SCCs and UK Addendum
Intuit Inc.Transactional email providerUnited StatesData Privacy Framework and UK Extension; SCCs and UK Addendum
Microsoft CorporationNotification deliveryUnited States, or the Controller's own tenant regionData Privacy Framework and UK Extension; SCCs and UK Addendum
Perplexity AI, Inc.AI model providerUnited StatesData Privacy Framework and UK Extension; SCCs Modules 2 and 3
Salesforce, Inc.Customer support platform and notification deliveryUnited StatesData Privacy Framework and UK Extension; SCCs and UK Addendum
X.AI Corp.AI model providerUnited StatesSCCs Modules 2 and 3

Adobe Inc., Atlassian, Inc., Discord Inc. and Microsoft Corporation are engaged only where the Controller enables the relevant integration or a recipient elects the relevant notification channel.

Not listed above, by design. Google Analytics and Google Tag Manager, Termly Inc. (cookie consent management) and Stripe, Inc. (payment processing) process data for which we act as an independent controller under clause 11, not as your processor. They are disclosed in our Privacy Notice rather than in this Annex.