📝 Data Processing Agreement

Data Processing Agreement

This DPA governs the processing of personal data by WhizzAct Private Limited on behalf of business customers under GDPR Article 28 and DPDPA 2023.

📅 Effective: 1 July 2025 ⚖️ GDPR Art. 28 & DPDPA 2023 🏢 B2B Customers Only
🇪🇺 GDPR Article 28 🇮🇳 DPDPA 2023 — Data Processor Obligations
📌
Who needs this DPA? This agreement applies when you use WhizzMeet to process personal data of your own users, employees, or customers — making you the Data Controller / Data Fiduciary and WhizzAct Private Limited the Data Processor / Data Fiduciary's Processor. By accepting our Terms of Service, this DPA is incorporated by reference.

Table of Contents

  1. Parties & Definitions
  2. Scope of Processing
  3. WhizzAct's Obligations as Processor
  4. Customer's Obligations as Controller
  5. Sub-Processors
  6. International Data Transfers
  7. Security Measures
  8. Data Subject / Principal Rights
  9. Data Breach Notification
  10. Audit Rights
  11. Termination & Return of Data
  12. Liability
  13. Governing Law

1 Parties & Definitions

2 Scope of Processing

AttributeDetails
Subject matterVideo meeting and workspace management services provided via WhizzMeet
DurationDuration of the Customer's active subscription + applicable retention periods
Nature & purposeHosting, transmitting, storing and facilitating video meetings and related Workspace functions
Types of personal dataNames, email addresses, IP addresses, device identifiers, meeting metadata, and (if enabled) video/audio recordings
Categories of data subjectsCustomer's employees, contractors, clients, or any meeting participants
InstructionsCustomer's instructions as documented in the Terms of Service and Workspace configuration

3 WhizzAct's Obligations as Processor

WhizzAct Private Limited shall:

4 Customer's Obligations as Controller

The Customer shall:

5 Sub-Processors

The Customer grants WhizzAct a general authorisation to engage Sub-Processors. Current approved Sub-Processors are:

Sub-ProcessorFunctionLocation
Amazon Web Services (AWS)Cloud infrastructure & data storageIndia (ap-south-1)
Cashfree Payments India Pvt LtdPayment processingIndia
Email delivery provider (SMTP)Transactional email deliveryIndia / EU

WhizzAct will notify Customers of any intended changes (additions or replacements) to Sub-Processors at least 14 days in advance via email or dashboard notification. Customers may object to changes within this period; failure to object constitutes acceptance.

6 International Data Transfers

7 Security Measures

WhizzAct implements and maintains the following technical and organisational measures:

Technical Measures

Organisational Measures

8 Data Subject / Principal Rights

WhizzAct shall assist Customers in responding to data subject requests (GDPR Articles 15–22; DPDPA Sections 11–14) by:

Customers must submit data subject assistance requests to privacy@whizzact.com with sufficient information to identify the data subject and the nature of the request.

9 Data Breach Notification

10 Audit Rights

11 Termination & Return of Data

12 Liability

Each party's liability under this DPA is subject to the limitations set out in the Terms of Service. Where both parties are liable for a data breach, liability shall be apportioned according to their respective degree of fault. Neither party excludes liability to data subjects as required by applicable law.

13 Governing Law

This DPA is governed by the laws of India. For EEA/UK customers, GDPR provisions prevail to the extent of any conflict. Disputes shall be resolved per the dispute resolution process in the Terms of Service.

DPA Queries & Execution

Company
WhizzAct Private Limited