Data Processing Agreement
This page summarizes the standard Data Processing Agreement (DPA) Pzartech Ltd. offers to B2B customers whose use of a Pzartech product involves processing personal data on their behalf. The full executable DPA is available on request.
Last reviewed: 2026-05-27. The DPA template is reviewed quarterly and updated as the v2 standards mesh and sub-processor list evolve.
When the DPA applies
The DPA applies when you (the customer) are the controller of personal data, and Pzartech processes that data as a processor on your behalf through one of our products. Examples:
- You operate a workflow application built on Pzartech infrastructure that stores personal data about your customers, employees, or suppliers.
- You upload content to a Pzartech product that contains personal data and we process it to deliver the service.
- You connect Pzartech to your business systems and we receive personal data through those integrations to fulfil the service.
The DPA does not apply to (a) data Pzartech processes as a controller for its own purposes (security monitoring and statutory record-keeping) and (b) payment and billing processing performed separately through Pikood.
What the DPA covers
- Roles + scope — you as controller, Pzartech as processor; types of personal data and categories of data subjects per Annex I.
- Processor obligations — process only on documented instructions, confidentiality undertakings, security measures, assistance with data-subject requests, breach notification within 72 hours of awareness, deletion/return on termination.
- Sub-processors — listed in Trust + Sub-Processors and Annex III of the DPA. General authorization with 30-day prior notice for material additions; objection rights for customer.
- Security measures (Annex II) — corresponds to the Pzartech v2 standards mesh: access control, encryption in transit and at rest, audit logging, secure development lifecycle, incident response, vendor risk management.
- International transfers — EU SCCs where applicable; adequacy decisions where available (UK, Israel); supplementary measures consistent with Schrems II.
- Audit rights — customer may audit Pzartech's compliance with 30 days' prior notice, reasonable scope, no impact on other customers' confidentiality. Pzartech provides SOC 2 / ISO summary information from sub-processors where applicable.
- Term + termination — coterminous with the Service Agreement; survival of confidentiality, deletion / return, and audit-evidence retention obligations.
- Liability — as set out in the Service Agreement, subject to mandatory GDPR allocations.
Standard sub-processors
See Trust + Sub-Processors for the current list of third parties that process personal data on behalf of Pzartech across the product portfolio. Pzartech notifies active DPA-bound customers at least 30 days before adding or replacing a material sub-processor; customers may object in writing.
Cross-border transfers
Pzartech is established in Israel. Israel benefits from an EU adequacy decision for personal data flowing from EU/EEA to Israel. For transfers from Israel onward to sub-processors in other jurisdictions, Pzartech relies on:
- EU Standard Contractual Clauses (SCCs) Module 2 (controller-to-processor) for transfers to processors outside adequacy jurisdictions.
- EU-US Data Privacy Framework where applicable.
- UK International Data Transfer Addendum where UK personal data is involved.
- Schrems-II-consistent supplementary measures (encryption at rest, access scoping, purpose-limited engagement) on top of the contractual basis.
How to execute the DPA
- Email info@pzartech.com with subject "DPA request", your legal entity name, and the Pzartech product(s) you use.
- We send the executable PDF DPA and ask you to confirm the Annex I particulars (data categories, data subjects, retention).
- The DPA is countersigned electronically and stored alongside your account.
Most B2B onboardings complete the DPA exchange within 3 business days. Larger customer legal reviews typically complete within 10 business days.
For consumers (B2C)
If you are a consumer using a Pzartech product for personal purposes, the DPA does not apply — Pzartech acts as controller of the data we process about you. See Pzartech Ltd. Privacy Policy and, for German-speaking residents, Datenschutzerklärung.
Contact
DPA requests: info@pzartech.com