Outrizz Data Processing Addendum
This addendum is part of the Outrizz Terms of Service (https://www.outrizz.com/terms, or the order form) between Outrizz Inc ("Outrizz") and the customer organisation ("Customer"). It sets the terms on which Outrizz handles Customer Content as the Customer's service provider or processor.
1. Definitions
Customer Content — personal information that a Customer's users capture, upload, type or create in the Services, including photos, audio, transcripts, links, notes and the contact records derived from them, messages sent on the Customer's instruction, and the person records Outrizz produces on the Customer's order and the fact that they were the Customer's targets. Outrizz's own source corpus, which it builds per event independently of any Customer, is not Customer Content; Outrizz is its controller and may reuse it. Data Protection Laws — the US federal and state privacy laws that apply to the processing, including the California Consumer Privacy Act as amended (CCPA). Where they apply, also the EU and UK GDPR. Subprocessor — a third party Outrizz engages that processes Customer Content. Terms such as business, service provider, controller, processor, sell and share have the meanings given in the Data Protection Laws.
2. Roles
2.1 For Customer Content, the Customer is the business or controller, and Outrizz is its service provider or processor. 2.2 For account, billing, security and website data, Outrizz is an independent business or controller under its Privacy Policy. 2.3 The Customer is responsible for having a lawful basis and giving any notice required to capture and use information about the people its users meet. That includes honouring their opt-outs and not capturing sensitive information.
3. Instructions and limits on use
3.1 The Customer discloses Customer Content to Outrizz only for the limited and specified business purposes listed in Annex 1, and Outrizz processes it only for those purposes and under the Customer's documented instructions. The agreement, the Customer's use of the Services, and the settings its users choose (including the AI-processing permission) are those instructions. 3.2 Outrizz will not:
- (a) sell or share Customer Content;
- (b) retain, use or disclose it for any purpose other than the business purposes in the agreement, including any commercial purpose of its own;
- (c) retain, use or disclose it outside the direct business relationship with the Customer;
- (d) combine it with personal information Outrizz receives from or on behalf of another person or from its own interactions with consumers, except as the CCPA permits a service provider to do;
- (e) use it to train or improve AI models, or add it to any dataset Outrizz offers to anyone else. Outrizz will comply with the Data Protection Laws that apply to it as a service provider or processor and give Customer Content the level of privacy protection they require. The Customer may take reasonable and appropriate steps to ensure Outrizz uses Customer Content consistently with the Customer's own obligations. 3.3 Outrizz may create aggregated or de-identified information that cannot reasonably be linked to any person or Customer. It will publicly commit to keep it de-identified and will not try to re-identify it. 3.4 Outrizz will tell the Customer if it can no longer meet its obligations under the CCPA, or if it believes an instruction infringes Data Protection Laws. The Customer may then take reasonable steps to stop and remediate unauthorised use.
4. Confidentiality and personnel
Everyone at Outrizz with access to Customer Content is bound by confidentiality and gets access only as needed for their role.
5. Security
Outrizz maintains the measures in Annex 2 and keeps each Customer's workspace logically separate. It will notify the Customer without undue delay, and within 72 hours of becoming aware of a breach affecting Customer Content. The notice describes what is known and is updated as more becomes known. The notice includes the nature of the breach, the categories and approximate number of individuals and records concerned, the likely consequences, the measures taken or proposed, and a contact point.
6. Subprocessors
6.1 The Customer authorises the Subprocessors listed at https://www.outrizz.com/subprocessors. 6.2 Outrizz will give at least 30 days' notice of a new Subprocessor through that page and an email subscription. The Customer may object on reasonable data-protection grounds. If the parties cannot resolve the objection, the Customer may terminate the affected Services and receive a pro-rata refund. 6.3 Outrizz binds each Subprocessor by written contract to obligations no less protective than this addendum. That includes no training on Customer Content where the provider offers that term. Outrizz remains responsible for its Subprocessors.
7. Assistance
7.1 Requests from individuals. Outrizz will forward to the Customer, without undue delay, any request it receives about Customer Content. It will not answer such a request itself except to redirect it or as the law requires. It provides in-product tools to find, export, correct and delete records, and reasonable further help. When the Customer deletes Customer Content or instructs Outrizz to delete it, Outrizz deletes it and tells its Subprocessors to delete it. 7.2 Outrizz will reasonably help the Customer with risk assessments and regulatory inquiries that concern the Services.
8. Deletion and return
During the subscription the Customer can export and delete Customer Content in the product. Within 30 days after the subscription ends, Outrizz returns Customer Content in a common machine-readable format or deletes it, as the Customer chooses, and deletes any remaining copies (backups within a further 35 days) unless the law requires retention. Raw captures are deleted 3 months after capture as described in the Privacy Policy.
9. Audits
Outrizz will make available the information reasonably needed to show compliance, such as security documentation and Subprocessor terms. It will allow a reasonable audit or inspection by the Customer or an auditor it mandates once a year on 30 days' notice, at the Customer's cost, under confidentiality, where documentation does not answer the question.
10. International transfers
Customer Content is hosted in the United States, including the records of AI requests and results used for quality monitoring; messages sent from users' connected accounts pass through Unipile, which hosts its data in France. Where EU or UK GDPR applies, the EU Standard Contractual Clauses (Module 2 or 3) and the UK Addendum are incorporated by reference. Annex 1 is the description, and Annex 2 the technical and organisational measures.
11. Order of precedence
If this addendum conflicts with the agreement on the processing of Customer Content, this addendum prevails.
12. EU and UK
Where the EU or UK GDPR applies, Outrizz also (a) processes Customer Content, including transfers, only on documented instructions; (b) assists the Customer with Articles 32 to 36 GDPR, including impact assessments and prior consultation; and (c) relies on the EU Standard Contractual Clauses (Module 2, or Module 3 where the Customer is a processor), the UK Addendum and the Swiss amendments, or on Outrizz's certification under the EU–US Data Privacy Framework if it holds one.
Annex 1 — Description of processing
| Item | Description |
|---|---|
| Subject matter | Providing the Outrizz Services to the Customer |
| Purposes (§3.1) | 1. store and sync captures; 2. read captures with AI (extraction and transcription) when the user has allowed it; 3. match and de-duplicate records within the workspace; 4. display and export; 5. (web) find people on the Customer's order; 6. (web) send messages the user approved from the user's own accounts; 7. secure the Service and investigate incidents |
| Categories of individuals | people the Customer's users meet at professional events; the Customer's users |
| Categories of data | name, company, job title, business email, phone and address, professional profile links, photos and voice recordings in which they may appear or be mentioned, notes |
| Sensitive data | none intended; Customers are instructed not to capture it |
| Duration | the subscription, then §8 |
Annex 2 — Technical and organisational measures (summary)
TLS for data in transit; encryption at rest (provider-managed); every record tied to its workspace; least-privilege staff access; a private storage bucket for captures with short-lived signed URLs; an audit trail of actions; a breach-response procedure; deletion on request and on schedule.