Data Processing Addendum
This Data Processing Addendum (“DPA”) forms part of the Master Services Agreement or Terms of Service (“Principal Agreement”) between Vazura LLC (dba RapidViz) and the Customer (identified in the Principal Agreement or Order Form) acting as a “Controller”.
Definitions
All capitalized terms not defined herein shall have the meaning set forth in the Principal Agreement.
- “Data Protection Laws” means all applicable worldwide legislation relating to data protection and privacy which applies to the respective party in the role of Processing Personal Data under the Principal Agreement, including without limitation the European General Data Protection Regulation (“GDPR”), the UK Data Protection Act 2018, and the California Consumer Privacy Act (“CCPA”).
- “Personal Data” means any information relating to an identified or identifiable individual where such information is contained within Customer Data and is protected as personal data, personal information, or personally identifiable information under applicable Data Protection Laws.
- “Sub-processor” means any third-party processor engaged by Vazura to Process Personal Data in order to provide the Services.
Roles and Scope of Processing
2.1 Role of Parties
The parties acknowledge and agree that with regard to the Processing of Personal Data, Customer is the Controller and Vazura is the Processor.
2.2 Scope
Vazura shall Process Personal Data only for the purposes described in this DPA and only in accordance with Customer’s documented lawful instructions (which include the Principal Agreement and the specific configurations/prompts selected by Customer in the Service).
2.3 Nature of Processing
The processing operations include the ingestion of User Content (images, 360-degree animations, text prompts), processing via Artificial Intelligence models for image and video generation (including using previously generated assets as inputs for subsequent video generation capabilities), storage, and retrieval as described in the Service documentation.
Sub-processing
3.1 Authorized Sub-processors
Customer provides general authorization for Vazura to engage Sub-processors to Process Personal Data. Customer specifically authorizes the engagement of the following core Sub-processors:
- Google LLC (Gemini, Veo, and related AI APIs): For AI image generation, video generation, and analysis.
- Hosting Providers: (e.g., AWS, AWS Lightsail, or similar as used by Vazura).
3.2 Liability
Vazura shall be liable for the acts and omissions of its Sub-processors to the same extent Vazura would be liable if performing the services of each Sub-processor directly under the terms of this DPA.
International Data Transfers (SCCs)
4.1 Applicability
If the Processing of Personal Data involves a transfer from the European Economic Area (“EEA”), Switzerland, or the United Kingdom to Vazura (located in the United States), such transfers shall be governed by the Standard Contractual Clauses (SCCs) approved by the European Commission (Implementing Decision (EU) 2021/914 of 4 June 2021).
4.2 Incorporation of SCCs
The SCCs are hereby incorporated by reference into this DPA as follows:
- Module Two (Controller to Processor) applies.
- Clause 7 (Docking Clause): Optional.
- Clause 9 (Use of Sub-processors): Option 2 (General Written Authorization) applies.
- Clause 11 (Redress): The optional language does not apply.
- Clause 17 (Governing Law): Option 1 applies. The laws of Ireland shall govern.
- Clause 18 (Choice of forum and jurisdiction): The courts of Ireland shall have jurisdiction.
4.3 UK Transfers
For transfers from the UK, the “International Data Transfer Addendum to the EU Commission Standard Contractual Clauses” (UK Addendum) issued by the ICO shall apply, with the governing law being that of England and Wales.
Security Measures
Vazura shall implement and maintain appropriate technical and organizational measures to protect Personal Data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure, or access. These measures are detailed in Annex II.
Data Subject Rights
Taking into account the nature of the Processing, Vazura shall assist Customer by appropriate technical and organizational measures, insofar as this is possible, for the fulfillment of Customer’s obligation to respond to requests for exercising the data subject’s rights (e.g., right to erasure/Right to be Forgotten).
Audit Rights
Vazura shall make available to Customer all information necessary to demonstrate compliance with this DPA and allow for and contribute to audits, including inspections, conducted by Customer or an auditor mandated by Customer, subject to reasonable notice, confidentiality obligations, and limitation to once per year unless a data breach has occurred.
Deletion or Return of Data
Upon termination or expiration of the Principal Agreement, Vazura shall (at Customer’s election) delete or return all Personal Data to Customer, unless applicable law requires storage of the Personal Data. As stated in the Privacy Policy, Vazura reserves the right to flush project history; it is the Customer’s responsibility to download generated assets prior to termination.
Annex I: Details of Processing
A. List of Parties
- Data Exporter: The Customer (as defined in the Principal Agreement).
- Data Importer: Vazura LLC (Address: San Jose, California, United States).
B. Description of Transfer
- Categories of Data Subjects: Customer’s employees, authorized users, or individuals whose likeness may appear in uploaded User Content (e.g., portraits for style transfer).
- Categories of Personal Data:
- Contact Information (name, email, organization).
- User Content: Images, videos, 360-degree rotational sequences, and text prompts that may contain identifiable attributes. This includes generated images subsequently used as inputs for video generation.
- Technical Data: IP addresses, device identifiers.
- Frequency of Transfer: Continuous/On-demand (whenever the User utilizes the RapidViz platform).
- Nature of Processing: Uploading assets to cloud servers; transmitting assets to third-party AI APIs (Google Gemini, Veo, etc.) for analysis, image generation, and video generation; storing results.
- Purpose of Processing: To provide the RapidViz AI generation and visualization services.
- Retention Period: For the duration of the Principal Agreement or until deleted by the User, subject to the storage policies outlined in the Terms of Service.
C. Competent Supervisory Authority
The Data Protection Commission of Ireland (DPC).
Annex II: Technical & Organizational Measures
Vazura LLC implements the following security measures to ensure a level of security appropriate to the risk:
- Encryption:
- In Transit: All data transmitted between the Customer’s browser and RapidViz servers, and between RapidViz servers and Google APIs, is encrypted using TLS 1.2 or higher (HTTPS).
- At Rest: User Content stored in databases and file storage buckets is encrypted at rest using industry-standard encryption protocols (e.g., AES-256).
- Access Control:
- Access to production data is restricted to authorized Vazura engineering personnel on a strictly need-to-know basis.
- Multi-Factor Authentication (MFA) is required for administrative access to cloud infrastructure.
- Third-Party AI Isolation:
- Vazura utilizes the Enterprise/Paid tiers of Google AI services (including Gemini and video models like Veo).
- Input Privacy: Per Google’s specific terms for paid tiers, Customer prompts, images, and video inputs are not used to train Google’s foundation models.
- Data Segregation: Customer data is processed logically separate from other tenants within the cloud environment.
- Vulnerability Management:
- Regular security patches and updates to server operating systems (e.g., Plesk/Linux environments) and WordPress/Application frameworks.
Annex III: List of Sub-Processors
The Controller authorizes the use of the following Sub-processors:
| Sub-processor Name | Service Provided | Location of Processing |
|---|---|---|
| Google LLC | Artificial Intelligence (Gemini API, Veo API, and related video models) & Cloud Services | United States |
| Amazon Web Services (AWS) | Cloud Hosting & Storage (if applicable) | United States |
(Additional sub-processors may be added via notification to the Customer)
Signature Block for Enterprise Customers
To execute this DPA, the Customer must sign and return this document to info@vazura.ai.
Name:
Title:
Date:
Signature:
Name: [Authorized Rep]
Title: Authorized Representative
Date: December 12, 2025
Signature: