This DPA governs the processing of personal data by WhizzAct Private Limited on behalf of business customers under GDPR Article 28 and DPDPA 2023.
| Attribute | Details |
|---|---|
| Subject matter | Video meeting and workspace management services provided via WhizzMeet |
| Duration | Duration of the Customer's active subscription + applicable retention periods |
| Nature & purpose | Hosting, transmitting, storing and facilitating video meetings and related Workspace functions |
| Types of personal data | Names, email addresses, IP addresses, device identifiers, meeting metadata, and (if enabled) video/audio recordings |
| Categories of data subjects | Customer's employees, contractors, clients, or any meeting participants |
| Instructions | Customer's instructions as documented in the Terms of Service and Workspace configuration |
WhizzAct Private Limited shall:
The Customer shall:
The Customer grants WhizzAct a general authorisation to engage Sub-Processors. Current approved Sub-Processors are:
| Sub-Processor | Function | Location |
|---|---|---|
| Amazon Web Services (AWS) | Cloud infrastructure & data storage | India (ap-south-1) |
| Cashfree Payments India Pvt Ltd | Payment processing | India |
| Email delivery provider (SMTP) | Transactional email delivery | India / EU |
WhizzAct will notify Customers of any intended changes (additions or replacements) to Sub-Processors at least 14 days in advance via email or dashboard notification. Customers may object to changes within this period; failure to object constitutes acceptance.
WhizzAct implements and maintains the following technical and organisational measures:
WhizzAct shall assist Customers in responding to data subject requests (GDPR Articles 15–22; DPDPA Sections 11–14) by:
Customers must submit data subject assistance requests to privacy@whizzact.com with sufficient information to identify the data subject and the nature of the request.
Each party's liability under this DPA is subject to the limitations set out in the Terms of Service. Where both parties are liable for a data breach, liability shall be apportioned according to their respective degree of fault. Neither party excludes liability to data subjects as required by applicable law.
This DPA is governed by the laws of India. For EEA/UK customers, GDPR provisions prevail to the extent of any conflict. Disputes shall be resolved per the dispute resolution process in the Terms of Service.