Capitalised terms not defined here have the meaning given in the Terms of Service or the Privacy Policy.
1. Scope & Relationship
This DPA applies where Azonation processes Personal Data on behalf of Customer under the Service. Customer is the “Controller” (or “Business”) and Azonation is the “Processor” (or “Service Provider/Processor”) with respect to Customer Data containing Personal Data.
2. Definitions
- Applicable Data Protection Laws: GDPR, UK GDPR, Data Protection Act 2018, CCPA/CPRA and other US state privacy laws, and any similar laws worldwide.
- Personal Data: any information relating to an identified or identifiable natural person.
- Processing: any operation performed on Personal Data as defined by applicable law.
- Sub‑processor: any third party engaged by Azonation to process Personal Data for the Service.
3. Processing on Documented Instructions
Azonation will process Personal Data only on documented instructions from Customer, including as set out in this DPA, the Agreement, and Customer’s in‑product settings, except where required by law (in which case Azonation will inform Customer unless legally prohibited).
4. Confidentiality
Azonation ensures that personnel authorised to process Personal Data are bound by confidentiality obligations and receive appropriate data protection and security training.
5. Security (Technical & Organisational Measures)
Azonation implements and maintains appropriate technical and organisational measures (TOMs) designed to protect Personal Data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure or access, as described in Annex B.
6. Sub‑processors
- Customer provides a general authorisation for Azonation to engage Sub‑processors listed in Annex C (as updated over time).
- Azonation will impose on Sub‑processors data protection obligations no less protective than those in this DPA.
- Azonation will notify Customer of material Sub‑processor changes via the admin console or email and allow reasonable objection where required by law.
7. Assistance, Data Subject Requests & DPIAs
Taking into account the nature of processing, Azonation will assist Customer (through appropriate technical and organisational measures) in fulfilling obligations to respond to requests from data subjects and regulators, and in conducting data protection impact assessments and prior consultations where required.
8. Personal Data Breach Notification
Azonation will notify Customer without undue delay after becoming aware of a Personal Data Breach affecting Customer Data and will provide information reasonably available to assist Customer in meeting breach‑notification obligations.
9. Audits & Reports
Azonation will make available information necessary to demonstrate compliance with this DPA, including independent audit reports or certifications (where available), and will allow and contribute to audits conducted by Customer or an independent auditor mandated by Customer, subject to reasonable advance notice, confidentiality, frequency and scope limitations to protect security, privacy, and trade secrets.
10. International Transfers
Where Azonation or its Sub‑processors transfer Personal Data internationally, Azonation will implement appropriate safeguards. For transfers from the EEA/Switzerland, the EU Standard Contractual Clauses (SCCs) (Controller‑to‑Processor or Processor‑to‑Processor, as applicable) are incorporated by reference as set out in Annex D. For UK transfers, the UK International Data Transfer Addendum (IDTA) (or UK Addendum to SCCs) is incorporated.
11. Return & Deletion
Upon termination of the Service or upon Customer’s written request, Azonation will delete or return Personal Data (at Customer’s choice) and delete existing copies within a reasonable period, unless retention is required by law. Deletions from backups occur per standard backup cycles.
12. US State Privacy — Service Provider/Processor
For Customer Data subject to CCPA/CPRA or similar US state laws, Azonation acts as a “Service Provider”/“Processor” and will (a) process Personal Data solely to provide the Service; (b) not sell or share Personal Data; (c) not combine Personal Data with other data except as permitted by law or to provide the Service; and (d) enable Customer to meet consumer rights requests as described above.
13. Records & Cooperation
Azonation will maintain records of processing as required by law and will reasonably cooperate with competent supervisory authorities regarding the Service’s processing of Personal Data.
14. Liability & Priority
Each party’s liability arising out of or in connection with this DPA is subject to the limitations and exclusions of liability set forth in the Agreement. In the event of conflict between this DPA and the Agreement, this DPA prevails to the extent of the conflict with respect to data protection obligations. The SCCs/UK IDTA prevail over this DPA where applicable.
15. Term & Termination
This DPA takes effect on the date Customer accepts the Agreement and remains in force for the duration that Azonation processes Personal Data on behalf of Customer, and thereafter as necessary to wind down processing or comply with legal obligations.
Annex A — Details of Processing
Subject Matter: Provision of the Azonation SaaS platform and related services.
Duration: Subscription term and any data‑retention periods defined by the Agreement or law.
Nature & Purpose: Hosting, storage, backup, support, analytics, communications, and other processing necessary to deliver the Service.
Types of Personal Data: Names, emails, phone numbers, organisation details, user IDs, activity logs, membership IDs, attendance records, documents/media uploaded, billing data (processed by payment providers), and other data submitted by Customer.
Categories of Data Subjects: Customer’s representatives and end users (e.g., members, staff, volunteers, guests, attendees), and other individuals whose data Customer inputs.
Processing Activities: Collection, recording, organisation, structuring, storage, adaptation, retrieval, consultation, use, disclosure by transmission (to authorised parties), alignment, restriction, erasure, and destruction.
Annex B — Technical & Organisational Measures (TOMs)
- Governance & Policies: Documented security and privacy policies; personnel training; least‑privilege access.
- Access Controls: Authentication, role‑based access, MFA for privileged operations, session management.
- Encryption: TLS for data in transit; industry‑standard encryption at rest for primary data stores and backups.
- Network Security: Firewalls, VPC isolation, endpoint hardening, vulnerability management, patching cadence.
- Application Security: Secure SDLC, code review, dependency scanning, secrets management, logging.
- Operational Security: Monitoring, alerting, audit logs, anti‑abuse and rate‑limit controls.
- Data Management: Segregation/tenant isolation, backup/restore procedures, tested DR plan, data minimisation.
- Incident Response: Defined triage, investigation and remediation; breach notification workflows.
- Physical Security: Cloud datacentres with access controls, CCTV, environmental safeguards (via hosting providers).
- Vendor Management: Risk assessment and contractual controls for Sub‑processors; periodic reviews.
Annex C — Sub‑processors
Azonation uses vetted Sub‑processors for infrastructure, storage, analytics, payments, and support. A current list is available in the admin console or on request from privacy@azonation.com. Typical categories include:
- Cloud infrastructure and CDN providers
- Database, queue, cache, and search services
- Email delivery and support ticketing
- Analytics/monitoring services
- Payment gateways (e.g., Stripe, PayPal, SSLCommerz, Razorpay, Paytm, Alipay, WeChat Pay)
Annex D — Standard Contractual Clauses (SCCs) & UK IDTA
For transfers of Personal Data from the EEA/Switzerland to third countries without an adequacy decision, the EU Commission Standard Contractual Clauses (Module 2: Controller‑to‑Processor and Module 3: Processor‑to‑Processor) are incorporated by reference between Customer (data exporter) and Azonation (data importer) as applicable.
For UK transfers, the International Data Transfer Addendum (IDTA) or the UK Addendum to the SCCs is incorporated by reference. The parties agree that: (i) the SCCs/Addendum apply solely to the extent required by law; (ii) the details of processing in Annex A and the TOMs in Annex B fill the relevant appendices; (iii) the competent supervisory authority is determined by the exporter’s location (for UK, the ICO); and (iv) the governing law and forum are those required by the SCCs/IDTA.
If there is conflict between this DPA and the SCCs/UK IDTA, the SCCs/UK IDTA prevail for cross‑border transfers.
This DPA forms part of and is subject to the Terms of Service. For additional information, see our Privacy Policy.