FizzUp
← Legal Center

Version 1.0 · updated 2026-06-09

Data Processing Agreement (DPA) — FizzUp

1. Parties and relationship to the main agreement

  • Controller (Customer): (completed by the Customer in the Order Form)
  • Processor (Provider): DB 77 CUW Sp. z o.o.

The DPA is an annex to the enterprise agreement/Order Form.

2. Subject matter and duration

Processing of data for the purpose of providing the Service (AI coach / voice / reports), for the duration of the agreement and the period necessary to complete billing/data deletion.

3. Categories of data subjects and data

  • users (employees/associates),
  • company administrators,
  • account data, usage data, transcripts (if applicable), support data, logs.

4. Customer instructions

The Provider processes data only on the documented instructions of the Customer, including administrative settings and instructions given as part of support.

5. Confidentiality and security

The Provider ensures measures appropriate to risk, including encryption in

transit, least-privilege access, authentication, environment separation,

backups, vulnerability and incident handling, staff confidentiality and

periodic control review. The current TOM schedule is attached to the Order Form.

6. Subprocessors

The Provider may use subprocessors listed in the public register. It informs

the Customer at least 30 days before a material addition or replacement and

allows a reasoned data-protection objection. The Provider imposes equivalent

data-protection obligations and remains responsible for their performance.

7. Transfers outside the EEA

Transfers use an adequacy decision, including an applicable EU-US DPF

certification, or the Commission's current Standard Contractual Clauses with a

transfer assessment and supplementary measures. The applicable module and

annexes are identified in the Order Form or subprocessor register.

8. Assistance with data subject rights

The Provider assists with data-subject requests, security obligations, DPIAs

and regulator consultations, taking into account the nature of processing and

available information. It notifies the Customer of a confirmed personal-data

breach without undue delay and provides information reasonably required under

Articles 33–34 GDPR.

9. Termination and deletion/return of data

Upon termination of the agreement, the Provider deletes or returns the Customer's data, subject to legal obligations.

10. Audit and instructions

The Provider supplies information reasonably necessary to demonstrate Article

28 compliance and permits an audit no more than once yearly, plus after a

material incident, subject to confidentiality, reasonable notice and avoidance

of disruption. The Provider informs the Customer if an instruction appears to

infringe data-protection law and may suspend that instruction pending review.

FizzUp legal documents are published in English. This English version is the canonical reference; localized translations, where provided, are for convenience only.