This Data Processing Agreement together with its attachments (the “Data Processing Agreement” or “DPA”) forms part of the Customer Terms and Conditions (the “Customer Terms”) to which it is annexed. Capitalized terms not defined herein shall have the meanings set forth in the Customer Terms.
This DPA reflects the Parties’ agreement with regard to the Processing of Personal Data of Customer in accordance with the requirements of Data Protection Laws and other applicable law. This DPA applies to the Services provided under the Customer Terms.
Lahzo’s Services are intended for use solely inside of the United States and Canada by United States and Canadian entities and individuals. Use outside of the United States and Canada is prohibited and Lahzo disclaims any liability for use of the Services by non-United States or Canadian entities and Data Subjects.
1. Subject Matter and Duration
1.1 Subject Matter. Whereas Customer may make available Customer Personal Data to Lahzo solely in connection with the Services. This DPA reflects the Parties’ commitment to abide by Data Protection Laws concerning the Processing of Customer Personal Data by Lahzo in connection with the Services. Lahzo hereby certifies that it understands and will comply with the restrictions listed in this DPA.
1.2 Duration and Survival. This DPA is effective as of the Effective Date of the Customer Terms and will apply to Customer Personal Data, whether Processed before, on, or after such date. Lahzo’s obligations and Customer’s rights under this DPA will continue in effect so long as Lahzo Processes Customer Personal Data.
2. Definitions
Capitalized terms not otherwise defined herein have the meanings assigned to such terms in the Customer Terms. The following terms, and those defined elsewhere within this DPA, apply:
2.1 “Processor” means “service provider,” “contractor,” or any similar term, such as “processor,” as defined under Data Protection Laws.
2.2 “Services” means the services to be provided by Lahzo pursuant to the Customer Terms, including services provided under Statements of Work, Order Forms, Advertising Order Forms, or other Ordering Documents.
2.3 “Sub-Processor” means a contractor, agent, vendor, or service provider engaged by Lahzo to Process Customer Personal Data on Lahzo’s behalf in connection with the Services.
3. Data Use and Processing
3.1 Documented Instructions. Lahzo shall be permitted to Process Customer Personal Data, and to share Customer Personal Data with its Sub-Processors, solely for the specific and limited purpose of, and to the extent necessary for, providing the Services to Customer in accordance with this DPA as a Processor. Lahzo may authorize its Sub-Processors to Process Customer Personal Data solely for such purpose. Lahzo shall comply with applicable obligations under Data Protection Laws and provide the same level of privacy protection required by Data Protection Laws. Lahzo will, unless legally prohibited from doing so, notify Customer in writing if it reasonably believes that there is a conflict between Customer’s instructions and Data Protection Laws or if Lahzo can no longer meet its obligations under Data Protection Laws. Customer may take reasonable and appropriate steps to help ensure that Lahzo uses Customer Personal Data in a manner consistent with Customer’s obligations under Data Protection Laws and, upon notice, to stop and remediate unauthorized use of Customer Personal Data.
3.2 Processing Information. The nature and purpose of Lahzo’s Processing of Customer Personal Data is to provide the Services to Customer in accordance with the Customer Terms, this DPA, and the applicable Ordering Documents. The instructions for Processing Customer Personal Data are set forth in the Customer Terms, this DPA, and the applicable Ordering Documents. The duration of Processing is the period during which Lahzo Processes Customer Personal Data in connection with the Services, including as further provided in Section 1.2 and Section 7 of this DPA. The types of Customer Personal Data subject to Processing may include Customer’s customer data, employee data, end user data, and other Personal Data Processed by Lahzo on behalf of Customer in connection with the Services, as applicable under the Customer Terms and the applicable Ordering Documents. For purposes of the CCPA, as amended, Lahzo Processes Customer Personal Data as a service provider or contractor, as applicable.
3.3 Prohibited Uses. Lahzo shall not, and shall ensure that its Sub-Processors do not,
3.3.1 “Sell” or “Share” Customer Personal Data, as such terms are defined by Data Protection Laws;
3.3.2 Retain, use, or disclose Customer Personal Data outside of the direct relationship between Customer and Lahzo, unless otherwise expressly permitted under Data Protection Laws for Processors;
3.3.3 Retain, use, make available, disclose, or transfer Customer Personal Data for any other purposes than specified in this DPA;
3.3.4 Disclose Customer Personal Data, or any Personal Data derived from Customer Personal Data, to any individual or entity other than to (a) Customer or (b) a Sub-Processor bound to data processing terms that comply with Data Protection Laws;
3.3.5 Combine Customer Personal Data that it receives pursuant to this DPA with Personal Data that it receives from or on behalf of another person or persons, or collects from its own interaction with the consumer, unless otherwise expressly permitted under Data Protection Laws for Processors;
3.3.6 Use Customer Personal Data to perform services on behalf of another person or customer.
3.4 Sub-Processors.
3.4.1 Customer authorizes Lahzo to engage the Sub-Processors identified on Lahzo’s then-current Sub-Processor List (presently available at http://data-vendors.lahzo.com/) to Process Customer Personal Data in connection with the Services. Lahzo shall maintain and update the Sub-Processor List from time to time and shall provide notice of any new Sub-Processor by updating the Sub-Processor List and making available a mechanism by which Customer may subscribe to receive notice of such updates. Customer is responsible for subscribing to such notices.
3.4.2 If Customer reasonably objects to a new Sub-Processor on grounds relating to the protection of Customer Personal Data, Customer shall provide Lahzo written notice of its objection within ten (10) business days after notice of the new Sub-Processor is provided. The Parties shall cooperate in good faith to address Customer’s concerns. As Customer’s sole and exclusive remedy, Lahzo shall use commercially reasonable efforts to make available a commercially reasonable change to the affected Services or Customer’s configuration or use of the affected Services to avoid Processing of Customer Personal Data by the objected-to Sub-Processor.
3.4.3 If Lahzo is unable to provide such alternative within sixty (60) days after receipt of Customer’s objection, Customer may terminate only the affected Services upon written notice to Lahzo, without penalty, and shall receive a pro rata refund of any prepaid fees attributable to the terminated portion of the affected Services. If Customer does not object within the foregoing ten (10) business day period, Customer shall be deemed to have approved the new Sub-Processor.
3.4.4 Lahzo shall (a) enter into a written agreement with Sub-Processors that imposes on such Sub-Processor (and their sub-processors) such data protection and security requirements for Customer Personal Data as are required by Data Protection Laws and this DPA; and (b) remain accountable and responsible for all actions by such Sub-Processor with respect to the disclosed or transferred Customer Personal Data.
3.5 Personal Data Inquiries and Requests. Lahzo shall, to the extent legally permitted, reasonably cooperate with the Customer, including through appropriate technical and organizational measures as reasonably requested, with respect to any action taken relating to any request, complaint, order, or other document from individuals exercising their rights granted to them under Data Protection Laws or from any regulator relating to the Processing of Customer Personal Data.
3.6 De-Identified Data. Where Lahzo processes De-Identified Data, Lahzo shall (a) take reasonable measures (but, where Data Protection Laws require a standard higher than “reasonable measures,” then Lahzo shall apply that higher standard) to ensure that the De-Identified Data cannot be associated with a natural person or otherwise be associated with any other information such that the De-Identified Data becomes Personal Data; and (b) ensure that De-Identified Data is not reidentified.
4. Information Security Program
4.1 Lahzo agrees to implement appropriate technical and organizational measures to protect Customer Personal Data (the “Information Security Program”) as set forth in Annex A-1.
5. Security Incidents
5.1 Security Incident Procedure. Lahzo will deploy and follow policies and procedures to detect, respond to, and otherwise address Security Incidents including but not limited to procedures to (a) identify and respond to Security Incidents, mitigate harmful effects of Security Incidents, and document Security Incidents and their outcomes; and (b) restore the availability or access to Customer Personal Data in a timely manner.
5.2 Notice. Upon its discovery that a Security Incident has taken place, Lahzo will provide written notice to Customer without undue delay and, in any event, no later than seventy-two (72) hours after such discovery, or sooner if required by Data Protection Laws. Lahzo may provide information concerning the Security Incident in phases as additional information becomes available.
5.3 Investigation. Customer has the right to participate in the investigation and response to each Security Incident and Lahzo shall provide reasonable assistance to Customer in the investigation, mitigation and remediation of each such Security Incident, and in the event of an investigation by any regulator or similar authority, if and to the extent that such investigation relates to Customer Personal Data. Such assistance shall be at Customer’s sole expense, except where such investigation was required due to Lahzo’s acts or omissions, in which case such assistance shall be at Lahzo’s sole expense.
6. Audits
6.1 Demonstrable Compliance. Lahzo agrees to keep records of its compliance with this DPA and Data Protection Laws.
6.2 Proof of Compliance. Upon Customer’s reasonable request, and subject to the confidentiality obligations set forth in the Customer Terms, Lahzo shall make available to Customer (or Customer’s independent, third-party auditor) such information as Lahzo (acting reasonably) considers appropriate in the circumstances to demonstrate Lahzo’s compliance with the obligations set forth in this DPA, which may be in the form of documentary evidence or third-party certifications.
6.3 Right to Audit. To the extent the documentary evidence made available by Lahzo is not sufficient in the circumstances to demonstrate Lahzo’s compliance with this DPA, Lahzo shall permit audits by such independent third-party inspection entity as Customer may appoint. Lahzo shall provide (a) reasonable assistance and cooperation of Lahzo’s relevant staff; and (b) reasonable facilities at Lahzo’s premises for the purpose of auditing Lahzo’s procedures relevant to the protection of Personal Data. Customer shall promptly notify Lahzo with information regarding any non-compliance discovered during the course of an audit. Customer shall give Lahzo no less than thirty (30) days prior written notice of any on-site audit and such audits shall occur no more than one (1) time in any year. Before the commencement of any on-site audit, Customer and Lahzo shall mutually agree upon the scope, timing, and duration of the audit in addition to the reimbursement rate for which Customer shall be responsible.
6.4 Reimbursements. Audits shall be at Customer’s sole expense and Customer shall reimburse Lahzo for any time expended for any on-site audit at Lahzo’s then-current professional services rates. All reimbursement rates shall be reasonable, considering the resources expended by Lahzo.
7. Data Deletion
With respect to Customer Personal Data, upon termination or expiration of the applicable Services, Lahzo shall cease Processing Customer Personal Data except to the extent retained as permitted under the Customer Terms, this DPA, or applicable law. To the extent technically feasible, Lahzo shall return, archive, delete, or destroy Customer Personal Data in accordance with the Customer Data return and deletion provisions set forth in the Customer Terms. Any retained Customer Personal Data shall remain subject to the confidentiality, security, and Processing restrictions applicable to Customer Personal Data under this DPA for so long as Lahzo Processes such Customer Personal Data.
8. Miscellaneous
8.1 Limitation of Liability. Lahzo’s liability toward the Customer with regard to any and all breaches of this DPA will be as set forth in the Customer Terms and only to the extent it is liable pursuant to applicable law.
8.2 Modification. No modification or amendment to this DPA shall be effective unless in writing and executed by a duly authorized representative of each Party.
8.3 Indemnity. Nothing in this DPA shall affect any indemnification provisions set forth in underlying agreements between the Parties, including the Customer Terms; nor shall this DPA create new obligations of indemnification from one Party to the other, except where expressly set forth herein.
8.4 Conflict. In the event of any conflict or inconsistency between this DPA and the Customer Terms, the provisions in this DPA shall prevail solely to the extent of such conflict or inconsistency.
Last Revision: September 15, 2026
Annex A-1
Security Addendum
1. Information Security Program
1.1 Lahzo agrees to implement appropriate administrative, technical, and organizational safeguards, including procedures and practices commensurate with the level of sensitivity of Customer Personal Data, to protect such data (the “Information Security Program”). At a minimum, such measures shall include:
1.1.1 De-Identification of Customer Personal Data where appropriate;
1.1.2 The ability to ensure the ongoing confidentiality, integrity, and availability of Lahzo’s Processing and Customer Personal Data;
1.1.3 Ensuring access to Customer Personal Data is being granted in a consistent manner aligned with the principle of least privilege;
1.1.4 Ensuring Customer Personal Data is used only in the manner set forth in the DPA and Customer Terms;
1.1.5 The ability to restore the availability and access to Customer Personal Data in the event of a physical or technical incident; and
1.1.6 A process for regularly evaluating and testing the effectiveness of Lahzo’s Information Security Program to ensure the security of Customer Personal Data from Security Incidents.
2. Data Security Controls
2.1 Lahzo safeguards for Customer Personal Data shall include:
2.1.1 Securing business facilities, data centers, physical files, back-up systems and all computing equipment (mobile devices, desktops, laptops, servers, etc.) and other equipment with information storage capability, which will include: limiting physical and remote access to all servers, network hardware, storage arrays, firewalls and backup media containing Customer Personal Data to only those that are required for efficient operations;
2.1.2 Logging access to secure facilities, ideally with electronic authentication;
2.1.3 Implementing network, device application, database and platform security;
2.1.4 Implementing secure safeguards for information transmission, storage and disposal;
2.1.5 Protecting against anticipated threats or hazards to secure the confidentiality and integrity of Customer Personal Data;
2.1.6 Implementing appropriate personnel security and integrity procedures and practices, including, but not limited to, conducting background checks of authorized personnel consistent with Data Protection Laws, and providing appropriate data protection, privacy and information security training to authorized personnel; and
2.1.7 Implementing procedures for the regular testing, inspection, assessment and evaluation of the effectiveness of the technical and organizational measures in order to ensure the security of the processing.
2.2 Personnel Access. Lahzo shall implement controls designed to manage its personnel’s access to systems supporting or providing the Services to be granted on a need-to-know basis consistent with assigned job responsibilities, which may include the use of role-based access controls to help ensure appropriate access rights, permissions, and segregation of duties. Lahzo’s personnel will not process Customer Personal Data without authorization. Personnel are obligated to maintain the confidentiality of any Customer Personal Data and this obligation continues even after their engagement ends.
2.3 Adjustment of Data Security Controls. Lahzo may adjust its data security controls as determined in its reasonable discretion.