This Data Processing Addendum (“DPA”) forms part of and is incorporated into the Terms and Conditions entered into between LEXZUR DWC-LLC (“LEXZUR”, “Processor”, “we”, “us”, or “our”) and the Customer (“Customer” or “Controller”) in connection with the Services provided by LEXZUR. This DPA applies where LEXZUR processes Personal Data on behalf of the Customer in the course of providing the Services.
To the extent of any conflict between this DPA and the Terms and Conditions, this DPA shall prevail solely with respect to the processing of Personal Data.
For the purposes of this DPA, the terms “Controller”, “Processor”, “Data Subject”, “Personal Data”, “Processing”, “Special Categories of Personal Data”, “Supervisory Authority”, and similar terms shall have the meanings assigned to them under the General Data Protection Regulation (EU) 2016/679 (“GDPR”) and any applicable data protection legislation.
The Parties acknowledge and agree that, with respect to the processing of Personal Data under this DPA, the Customer acts as the Controller and LEXZUR acts as a Processor solely for the purpose of providing the Services in accordance with the Agreement and the documented instructions of the Customer.
The Customer shall remain solely responsible for determining the purposes and means of processing Personal Data and for ensuring that such processing complies with Applicable Data Protection Law.
LEXZUR shall process Personal Data only on behalf of and in accordance with the Customer’s documented instructions as set out in the Agreement, this DPA, and the Customer’s use of the Services, unless otherwise required by applicable law. In such event, LEXZUR shall inform the Customer of that legal requirement before processing unless prohibited by law.
The Customer represents, warrants, and undertakes that it has obtained and shall maintain all necessary rights, permissions, consents, notices, and lawful bases required under Applicable Data Protection Law to collect, use, transfer, disclose, and otherwise process Personal Data through the Services and to authorize LEXZUR to process such Personal Data in accordance with the Agreement and this DPA.
The Customer shall remain solely responsible for the accuracy, quality, legality, reliability, and appropriateness of all Customer Data and for ensuring that the Customer’s use of the Services does not violate Applicable Data Protection Law or the rights of any third party.
The Customer shall not upload, store, or process any Special Categories of Personal Data through the Services unless such processing is necessary for the Customer’s permitted use of the Services and the Customer has implemented all required safeguards and lawful bases required under Applicable Data Protection Law.
The Customer acknowledges and agrees that it is solely responsible for configuring the Services, managing access rights, maintaining the confidentiality of credentials, and implementing appropriate security measures within its own systems and operations.
LEXZUR shall process Personal Data solely for the purpose of providing, maintaining, supporting, securing, and troubleshooting and operating the Services and performing its obligations under the Agreement.
LEXZUR shall ensure that any personnel authorized to process Personal Data are subject to appropriate confidentiality obligations and receive appropriate training relating to privacy and data protection.
LEXZUR shall not sell Customer Personal Data and shall not process Personal Data for advertising or marketing purposes unrelated to the provision of the Services.
Notwithstanding the foregoing, the Customer acknowledges and agrees that LEXZUR may use aggregated, anonymized, statistical, and de-identified data derived from the Customer’s use of the Services for analytics, benchmarking, service improvement, operational efficiency, security, research, and product enhancement purposes, provided that such data does not identify the Customer, any Authorized User, or any individual Data Subject.
LEXZUR may also process Personal Data where necessary to comply with applicable laws, regulations, governmental requests, court orders, subpoenas, or legal obligations, or where necessary to detect, prevent, or mitigate fraud, abuse, security threats, or technical issues affecting the Services.
To the extent AI Features are used in connection with the Services, LEXZUR may process Customer Data for purposes relating to retrieval, indexing, summarization, contextualization, classification, generation of outputs, operational monitoring, security, system improvement, and functionality enhancement in accordance with the Agreement, this DPA, and the Customer’s documented instructions.
Details of the categories of Personal Data, Data Subjects, and processing activities are set out in Appendix A.
Taking into account the state of the art, implementation costs, nature, scope, context, and purposes of processing, as well as the risks to Data Subjects, LEXZUR shall implement and maintain commercially reasonable technical and organizational security measures designed to protect Personal Data against unauthorized or unlawful access, disclosure, destruction, loss, alteration, or damage.
Such measures may include, where appropriate, access controls, authentication procedures, encryption technologies, network monitoring, vulnerability management, backup procedures, disaster recovery mechanisms, audit logging, system redundancy, personnel confidentiality obligations, and security incident response procedures.
LEXZUR may modify, update, or enhance its security measures from time to time provided that such modifications do not materially diminish the overall level of protection afforded to Customer Personal Data.
LEXZUR performs regular backups and maintains commercially reasonable business continuity and disaster recovery procedures in accordance with industry standards.
LEXZUR shall notify the Customer without undue delay, and where feasible within seventy-two (72) hours, after becoming aware of a confirmed Security Incident affecting Customer Personal Data processed by LEXZUR.
Such notification shall include, to the extent reasonably available at the time, information regarding the nature of the Security Incident, the categories of affected Personal Data, the likely consequences of the Security Incident, and the remedial measures taken or proposed by LEXZUR.
LEXZUR shall use commercially reasonable efforts to investigate, mitigate, and remediate the effects of any Security Incident and shall reasonably cooperate with the Customer in connection with the Customer’s compliance obligations under Applicable Data Protection Law.
Any notification or response by LEXZUR relating to a Security Incident shall not be construed as an admission of liability, fault, or wrongdoing by LEXZUR.
LEXZUR implements technical and organisational measures designed to support compliance with applicable data protection laws, including the GDPR where applicable. Where required, LEXZUR has appointed Prighter as its EU privacy representative. Customers and Data Subjects may exercise applicable GDPR rights through LEXZUR’s Public Privacy Dashboard or by contacting Prighter at:
Prighter, Maetzler Rechtsanwalts GmbH & Co KG, Attorneys at Law
c/o LEXZUR, Schellinggasse 3/10, 1010 Vienna, Austria
Quoting GDPR-REP ID: 19775994
Where the Customer enables or uses third-party plugins or integrations in connection with the Services, LEXZUR may process limited Personal Data necessary to enable and maintain such integrations. For example, where the Customer uses Google Calendar integration, LEXZUR may process calendar lists, meetings, attendees, and timing information for the purpose of enabling two-way synchronization between LEXZUR and Google Calendar. LEXZUR shall process such data only as necessary to provide the applicable integration and in accordance with this DPA.
The Customer acknowledges and agrees that LEXZUR may engage Subprocessors in connection with the provision of the Services.
LEXZUR shall ensure that any Subprocessor engaged by LEXZUR is subject to contractual obligations regarding the protection and processing of Personal Data that are substantially equivalent to those imposed on LEXZUR under this DPA.
LEXZUR may update or replace its Subprocessors from time to time and may make an updated list of Subprocessors available on its website or upon request.
Where required under Applicable Data Protection Law, LEXZUR shall provide commercially reasonable notice of material changes to Subprocessors through website publication, customer notification, or other reasonable means.
Customer acknowledges and agrees that Customer Data may be processed, hosted, transferred, accessed, or stored in jurisdictions where LEXZUR, its affiliates, subprocessors, hosting providers, infrastructure providers, or service providers operate, subject to the safeguards and protections set forth in this DPA and applicable data protection laws.
LEXZUR may offer region-specific hosting or data residency options, including hosting environments located in the Kingdom of Saudi Arabia, the United Arab Emirates, the European Union, or other jurisdictions made available by LEXZUR from time to time. The applicable operational, regulatory, privacy, security, support, and data processing requirements may vary depending on the hosting region or deployment model selected by the Customer.
Where Personal Data is transferred outside a jurisdiction requiring an approved transfer mechanism under Applicable Data Protection Law, LEXZUR shall implement appropriate safeguards, including where applicable, the European Commission’s Standard Contractual Clauses or any other lawful transfer mechanism recognized under Applicable Data Protection Law.
Taking into account the nature of the processing and the information available to LEXZUR, LEXZUR shall provide commercially reasonable assistance to the Customer in connection with the Customer’s obligations relating to Data Subject requests, data protection impact assessments, consultations with Supervisory Authorities, breach notifications, and other obligations arising under Applicable Data Protection Law.
If LEXZUR receives a request, complaint, or communication directly from a Data Subject relating to Customer Personal Data, LEXZUR may notify the Customer and shall not respond to such request except on the Customer’s documented instructions or as required by applicable law.
The Customer acknowledges and agrees that any assistance requested by the Customer beyond the standard functionality of the Services may be subject to additional fees at LEXZUR’s then-current professional service rates.
Upon reasonable prior written request and not more than once annually, except where required by applicable law or following a material Security Incident, LEXZUR shall make available information reasonably necessary to demonstrate compliance with this DPA.
Any audit or inspection conducted by or on behalf of the Customer shall be conducted during normal business hours, upon prior written notice, subject to reasonable confidentiality obligations, and in a manner that does not unreasonably interfere with LEXZUR’s operations, systems, security, personnel, or other customers.
LEXZUR may satisfy its audit obligations by providing existing third-party audit reports, certifications, security assessments, summaries, questionnaires, or other documentation in lieu of permitting direct inspections where appropriate.
Any access to facilities, systems, or records shall be limited solely to those relevant to the Services provided to the Customer and shall remain subject to LEXZUR’s security, confidentiality, and access control policies.
The Customer shall bear all costs and expenses associated with any audit conducted under this DPA.
LEXZUR may disclose Personal Data required by applicable law, regulation, court order, subpoena, governmental authority, regulatory authority, or other legal process.
Where legally permitted and reasonably practicable, LEXZUR shall use commercially reasonable efforts to notify the Customer prior to such disclosure.
Upon termination or expiration of the Agreement, LEXZUR shall delete or return Customer Personal Data in accordance with the Agreement and LEXZUR’s standard retention procedures, unless retention of such data is required by applicable law, regulatory obligations, legal process, dispute resolution requirements, enforcement of legal rights, or legitimate internal compliance purposes.
The Customer acknowledges and agrees that residual copies of Customer Personal Data may remain temporarily in backup systems, disaster recovery environments, or archived systems until deleted in the ordinary course pursuant to LEXZUR’s backup and retention procedures.
Any retained Customer Personal Data shall remain subject to the confidentiality and security obligations set forth in this DPA.
The liability of each Party arising out of or relating to this DPA shall be subject to the exclusions and limitations of liability set out in the Terms and Conditions Agreement.
Nothing in this DPA shall exclude or limit either Party’s liability to the extent such limitation or exclusion is prohibited under Applicable Data Protection Law.
This DPA shall remain in effect for as long as LEXZUR processes Personal Data on behalf of the Customer in connection with the Services.
Termination or expiration of the Agreement shall automatically terminate this DPA, except for those provisions which by their nature are intended to survive termination.
The processing of Personal Data by LEXZUR on behalf of the Customer under the Data Processing Addendum.
The subject matter of the processing is the provision of the Services by LEXZUR to the Customer under the Agreement.
Personal Data shall be processed for the duration of the Agreement and for any additional period required under applicable law, regulatory obligations, or the Agreement.
LEXZUR processes Personal Data solely for the purposes of:
Data subjects may include:
Personal Data processed may include:
The Services are not intended for the processing of Special Categories of Personal Data unless expressly agreed in writing by the Parties. To the extent the Customer elects to process such data through the Services, the Customer shall be solely responsible for ensuring that such processing complies with Applicable Data Protection Laws and that appropriate legal bases and safeguards are implemented.