Phaze

Phaze Data Processor Agreement

Updated August 25, 2026

Phaze Data Processing Addendum

This Data Processing Addendum (this “DPA”) forms part of the Phaze Terms Of Service (the “Agreement”), between Phaze, Inc. (“Phaze”) and Customer (each a “Party,” and collectively the “Parties”) for Partner’s purchase and use of Phaze services (“Services”). In the event of a conflict between the provisions of this DPA and the Agreement, this DPA shall control solely with respect to the subject matter herein.

The Parties agree as follows:

  1. DEFINITIONS
    1. Data Privacy Laws” means applicable state or federal consumer protection or privacy or data protection or privacy laws and regulations that govern the collection, use, disclosure, or Processing of Personal Data.
    2. Data Incident” means a known or reasonably suspected unauthorized or unlawful access to, disclosure, modification, destruction, deletion, loss of, or disruption or loss of access to Controller Personal Data.
    3. Personal Data” shall have the same meaning as “personal data” and “personal information” under Data Privacy Laws. “Controller Personal Data” means Personal Data provided by Controller to Phaze, collected by Phaze on behalf of Controller, or otherwise Processed by Phaze, pursuant to the Agreement.
    4. Process,” “Processed” or “Processing” means any operation or set of operations that are performed on Personal Data or on sets of Personal Data, including by automated means, and pursuant to the instructions set forth herein.
    5. Specified Purpose” has the meaning set forth in Section 2.b).
    6. Capitalized terms that are not defined herein shall have the same meaning as in Data Privacy Laws.
  2. PROCESSING RIGHTS AND REQUIREMENTS
    1. General Obligations. Phaze will Process Controller Personal Data in compliance with applicable laws, including Data Privacy Laws, at all times and in compliance with this DPA. Phaze is a “service provider,” “contractor,” or “processor” or similar applicable term defined under Data Privacy Laws.
    2. Scope of the Processing. Phaze shall only Process the types of Controller Personal Data for the Specified Purpose, as set forth below, except to the extent additional Processing purposes are permitted by Data Privacy Laws.
      1. Types of Personal Data Processed to Provide Services: Name, email address, billing address, account name and password, IP address, payment information, device and browser type and other electronic information required to provide the Services;
      2. Nature and Purpose of the Processing: to deliver remote access services and related services as described in the Agreement (“Specified Purpose”);
      3. Duration of the Processing: For the duration of the Agreement
    3. Prohibited Uses. Phaze is prohibited from and represents and certifies its understanding that it is prohibited from:
      1. Selling, Sharing, or otherwise disclosing Controller Personal Data to any third party;
      2. using, retaining, or disclosing Controller Personal Data for any purpose other than the Specified Purpose or engaging a Sub-processor in compliance with the DPA, or as otherwise permitted by Data Privacy Laws;
      3. using, retaining, or disclosing Controller Personal Data outside of the direct relationship between Controller and Phaze, unless expressly permitted by Data Privacy Laws;
      4. using, retaining, or disclosing Controller Personal Data against Controller’s instructions; and
      5. combining or updating Controller Personal Data with Personal Data received from another source, including Phaze’s own direct interaction with the consumer, unless expressly permitted by Data Privacy Laws.
  3. PROCESSING OBLIGATIONS
    1. Cooperation.
      1. Phaze shall make available to Controller all information necessary to comply with and demonstrate Phaze’s compliance with Data Privacy Laws.
    2. Data Subject Requests.
      1. Phaze shall cooperate with, and provide all reasonable support to cause Controller to comply with Controller’s obligations to data subjects under Data Privacy Laws, including responding to data subject requests. At Controller’s direction, Phaze shall provide Controller Personal Data to Controller or delete Controller Personal Data as necessary to respond to such requests.
      2. In the event that any individual rights request from a data subject is made directly to Phaze concerning Controller Personal Data, Phaze shall promptly forward the request to Controller. Phaze shall not respond to the request without Controller’s prior authorization.
      3. In the event that any request from applicable legal or regulatory authorities is made directly to Phaze, Phaze shall promptly forward the request to Controller, to the extent legally permitted to do so. Phaze shall not respond to such communication directly without Controller’s prior authorization other than to inform the requestor that Phaze is not authorized to directly respond to a request. If Phaze is legally required to directly respond to such a request, Phaze will promptly notify Controller and provide it with a copy of the request unless legally prohibited from doing so.
    3. Data Processing Assessments. Phaze shall provide information to Controller necessary to enable Controller to conduct and document any data processing or data protection assessments.
    4. Data Retention and Deletion/Return. Phaze will retain Personal Data for the duration of the Agreement. Except as required under applicable law and unless otherwise instructed by Controller, Phaze shall delete all Controller Personal Data within 60 days of the termination or expiration of the Agreement.
    5. Confidentiality. Phaze shall ensure that Phaze personnel that Process Controller Personal Data keep the Controller Personal Data confidential, are subject to confidentiality obligations that are at least as strict as the requirements Phaze has to protect its own confidential information, and are consistent with confidentiality provisions in the Agreement.
    6. Notification of Inability to Comply. If Phaze becomes aware or makes a determination that it can no longer meet its obligations under this DPA or Data Privacy Laws, it shall promptly notify Controller.
  4. SUB-PROCESSORS
    1. The Sub-processors that, as of the date of execution of the Agreement, Phaze has engaged to assist it in providing its Services are listed on https://phaze.app/subprocessors. Phaze has entered into a written agreement with each Sub-processor that requires them to comply with the terms of this DPA that are applicable to Phaze.
    2. Partner hereby consents to the use of these Sub-processors under the Agreement.
    3. Phaze will notify Partner by email, or by updating https://phaze.app/subprocessors, before authorizing any new Sub-processor to process Controller Personal Data under the Agreement. Controller shall have the right to reasonably object to the use of new Sub-processors within 10 business days of receipt of such notification. If Controller objects, the Parties shall work in good faith to resolve the basis for Controller’s objection. If such resolution cannot be timely made, either Party may terminate the Agreement upon written notice.
    4. Processor shall be liable for the acts and omissions of its Sub-processors to the same extent Processor would be liable under the terms of the Agreement.
  5. AUDITS Phaze grants Controller the right to take reasonable and appropriate steps to ensure that Phaze uses Controller Personal Data in a manner consistent with Controller’s obligations under the Data Privacy Laws. Upon notice, Controller shall have the right to take, and Phaze shall comply with, reasonable and appropriate steps to remediate or stop any unauthorized Processing of Controller Personal Data.
  6. INFORMATION SECURITY AND DATA INCIDENTS
    1. Phaze implements and maintains technical and organizational security measures to protect the security, confidentiality, and integrity of Personal Data and to ensure a level of security appropriate to the risk.
    2. If Phaze becomes aware of a Data Incident, it shall promptly, but in no more than 48 hours notify Controller. Phaze shall reasonably cooperate with Controller to support any investigation, and any Controller reporting or notification obligations.