Version 1.0 · updated 2026-06-09
Data Processing Agreement (DPA) — FizzUp
1. Parties and relationship to the main agreement
- Controller (Customer): (completed by the Customer in the Order Form)
- Processor (Provider): DB 77 CUW Sp. z o.o.
The DPA is an annex to the enterprise agreement/Order Form.
2. Subject matter and duration
Processing of data for the purpose of providing the Service (AI coach / voice / reports), for the duration of the agreement and the period necessary to complete billing/data deletion.
3. Categories of data subjects and data
- users (employees/associates),
- company administrators,
- account data, usage data, transcripts (if applicable), support data, logs.
4. Customer instructions
The Provider processes data only on the documented instructions of the Customer, including administrative settings and instructions given as part of support.
5. Confidentiality and security
The Provider ensures measures appropriate to risk, including encryption in
transit, least-privilege access, authentication, environment separation,
backups, vulnerability and incident handling, staff confidentiality and
periodic control review. The current TOM schedule is attached to the Order Form.
6. Subprocessors
The Provider may use subprocessors listed in the public register. It informs
the Customer at least 30 days before a material addition or replacement and
allows a reasoned data-protection objection. The Provider imposes equivalent
data-protection obligations and remains responsible for their performance.
7. Transfers outside the EEA
Transfers use an adequacy decision, including an applicable EU-US DPF
certification, or the Commission's current Standard Contractual Clauses with a
transfer assessment and supplementary measures. The applicable module and
annexes are identified in the Order Form or subprocessor register.
8. Assistance with data subject rights
The Provider assists with data-subject requests, security obligations, DPIAs
and regulator consultations, taking into account the nature of processing and
available information. It notifies the Customer of a confirmed personal-data
breach without undue delay and provides information reasonably required under
Articles 33–34 GDPR.
9. Termination and deletion/return of data
Upon termination of the agreement, the Provider deletes or returns the Customer's data, subject to legal obligations.
10. Audit and instructions
The Provider supplies information reasonably necessary to demonstrate Article
28 compliance and permits an audit no more than once yearly, plus after a
material incident, subject to confidentiality, reasonable notice and avoidance
of disruption. The Provider informs the Customer if an instruction appears to
infringe data-protection law and may suspend that instruction pending review.
FizzUp legal documents are published in English. This English version is the canonical reference; localized translations, where provided, are for convenience only.