Data Protection Addendum

We are dedicated to safeguarding the privacy of our clients, their associates, customers, employees, and all users of our website, platforms, and services.

1. Introduction

At Improzo Inc. (“Improzo”, “Us”, “We”, “Our”, or the “Company”), we value your privacy and the importance of protecting your data. This Data Protection Addendum (“DPA”) describes our current data protection and privacy practices for the activities set out below. It explains how we collect, store, access, transfer, and otherwise process Customer Personal Data on behalf of our customers. This DPA forms part of the agreement between Improzo and the Customer governing access to and use of our products, services, websites, software, analytics platforms, support systems, AI-enabled tools, and related offerings. We take privacy and data security seriously and believe in transparency. We are committed to protecting personal data in accordance with the highest standards of privacy regulations. Accordingly, we follow obligations under applicable laws including:

  • General Data Protection Regulation (GDPR)
  • UK GDPR
  • Swiss Federal Data Protection Act
  • California Consumer Privacy Act (CCPA/CPRA)
  • Other applicable privacy, cybersecurity, and data protection laws

Last Updated: April 2026

2. Scope of This DPA

This DPA applies to all Improzo websites, domains, services, software, products, cloud platforms, support channels, integrations, and business operations where Customer Personal Data is processed. This DPA does not apply to third-party applications, products, or websites that may be linked through our services. Such third parties operate independently and maintain their own privacy practices.

3. Processing Activities

This DPA applies when you interact with Improzo by doing any of the following:

  • Using our services as an authorized customer or user
  • Visiting any Improzo website linked to this DPA
  • Receiving communications from us, including email, newsletters, support updates, or calls
  • Submitting data through our platforms or integrations
  • Using AI-enabled or automated service features

4. Roles and Responsibilities

For purposes of applicable privacy laws:

  • Customer acts as the Controller / Business
  • Improzo Inc. acts as the Processor / Service Provider

The Customer determines why and how personal data is collected. Improzo processes data only:

  • Under documented customer instructions
  • To provide contracted services
  • To comply with legal obligations
  • To maintain system security and integrity
  • To improve service functionality

5. Personal Data We May Process

Depending on the services used, we may process:

Basic Identity Data

  • Full name
  • Work email address
  • Username or account ID
  • Contact number

Customer Submitted Data

  • Postal address
  • Date of birth
  • Employment history
  • HR records
  • Uploaded documents
  • Business operational information

Technical Data

  • IP address
  • Browser type
  • Device information
  • Login activity
  • Usage logs
  • Security event logs

Sensitive Data: Improzo does not intentionally require sensitive or special category personal data unless expressly agreed in writing and legally permitted.

6. How We Use Personal Data

We process Customer Personal Data only for legitimate business purposes such as:

  • Delivering contracted services
  • User authentication and Single Sign-On (SSO)
  • Managing customer accounts
  • Technical support
  • Analytics and reporting
  • Security monitoring and fraud prevention
  • Service improvement and debugging
  • AI-enabled features related to service delivery
  • Backup and disaster recovery
  • Compliance with legal or regulatory obligations

7. Security Measures

We implement administrative, technical, and physical safeguards designed to protect Customer Personal Data.

Organizational Controls

  • Security governance and ownership
  • Employee confidentiality commitments
  • Background verification where permitted by law
  • Security awareness training
  • Internal policy reviews
  • Vendor risk management

Access Controls

  • Least privilege access model
  • Unique user IDs
  • Strong password controls
  • Multi-Factor Authentication (MFA)
  • Periodic access reviews
  • Logged administrative activity

Infrastructure Security: Improzo uses secure cloud environments including Amazon Web Services infrastructure with:

  • Multi-zone resiliency
  • Backup restoration testing
  • Disaster recovery planning
  • Vulnerability management
  • Security logging and monitoring
  • Patch management

Encryption

  • HTTPS / TLS encryption in transit
  • Encryption protections for stored data where applicable

8. International Data Transfers

As a global business, personal data may be transferred to jurisdictions outside the customer’s home country. Where required, Improzo uses lawful transfer mechanisms such as:

  • EU Standard Contractual Clauses (SCCs)
  • UK International Data Transfer Addendum
  • Other approved safeguards under applicable laws

Where necessary, additional supplementary protections may be implemented.

9. AI & Automated Processing

Improzo may use AI and machine learning technologies to support contracted services. Where applicable:

  • AI processing is limited to authorized service delivery purposes
  • Processing remains governed by this DPA
  • Privacy and security safeguards continue to apply
  • Certain workloads may operate in Frankfurt, Germany region infrastructure

10. Data Subject Rights

Where required by law, Improzo supports Customers in responding to requests involving:

  • Access to personal data
  • Correction of inaccurate information
  • Deletion requests
  • Restriction of processing
  • Data portability
  • Objection requests
  • Privacy complaints
  • Withdrawal of consent where applicable

11. Security Incidents

If Improzo becomes aware of a confirmed personal data breach affecting Customer Personal Data, we will notify the Customer without undue delay and provide available information reasonably required to support legal and regulatory obligations.

12. Retention & Deletion

We retain Customer Personal Data only for as long as necessary to:

  • Deliver services
  • Meet contractual obligations
  • Resolve disputes
  • Meet legal requirements
  • Enforce agreements

Upon termination of services, data will be returned or securely deleted where contractually or legally required.

13. External Links

Our websites or services may contain links to third-party websites. We are not responsible for the privacy practices, content, or security controls of external sites. We encourage users to review third-party privacy notices before sharing personal data.

14. Updates to This DPA

We reserve the right to update this DPA from time to time to reflect operational, legal, or regulatory changes. The latest version will always be available on our official website. Continued use of our services after updates constitutes acceptance of the revised version.

15. Contact Our Data Protection Officer

If you have any questions, privacy concerns, complaints, or requests regarding this DPA or your personal data, please contact us: Email: dpo@improzo.com Address: 1 Broadway | Cambridge, MA 02142 | USA

16. Authorized Sub-Processors

To optimally provide our Services, Improzo engages the following third-party entities (“Sub-processors”) to process Personal Data. We impose data protection terms on these Sub-processors that are no less protective than those contained in this DPA:

Sub-Processors Overview

Improzo may engage the following categories of sub-processors to provide, maintain, secure, and support its services. Each sub-processor is granted access only to the minimum amount of information necessary to perform its designated function and is subject to appropriate contractual, confidentiality, security, and data protection obligations.

Sub-processorBrief Description of ProcessingLocation(s)
Amazon Web Services, Inc.Cloud hosting and technology servicesUnited States
Microsoft CorporationCloud infrastructure, hosting, networking, computing, storage, security services, backup, disaster recovery, and AI platform infrastructureUnited States
Snowflake, Inc.Data warehousing, hosting and storage servicesUnited States
Authentik, Inc.Identity management and authenticationUnited States
Atlassian, Inc.Technology and services related to code management, documentation, planning, collaboration, customer support, and issue managementUnited States
Anthropic, PBCAI inference and processing services for AI-powered functionality under customer-authorized configurationsUnited States

Categories of Sub-Processors

  • Improzo Subsidiaries and Affiliates: Purpose: Operational support, service delivery, administration, customer success, compliance, and business operations.
  • Cloud Infrastructure Providers: Examples: Microsoft Azure, Amazon Web Services (AWS). Purpose: Hosting, networking, computing, storage, security services, AI platform infrastructure, backup, disaster recovery, and other solution-related services.
  • Large Language Model (LLM) Providers: Examples: Anthropic Claude (or other customer-authorized providers). Purpose: AI inference and processing services required to deliver AI-powered functionality under the applicable customer licensing arrangement.
  • Identity and Access Management Providers: Examples: Okta and customer-designated identity providers. Purpose: User authentication, authorization, access control, single sign-on (SSO), and identity management.
  • Customer Support and Issue Management Providers: Examples: Jira and related support platforms. Purpose: Management, tracking, investigation, and resolution of customer support requests and service incidents.

Data Flows and Processing Activities

  • Cloud Infrastructure Providers (e.g., Azure, AWS): Receive customer data for hosting, networking, computing, storage, security services, backup, and operation of the AI services platform and related solution offerings.
  • LLM Model Providers (e.g., Claude): Receive limited data payloads at inference time, where required, to perform specific AI tasks in accordance with the customer’s licensed configuration and instructions.
  • Identity and Access Management Providers (e.g., Okta): Receive authentication and authorization information necessary to verify user identities, manage access permissions, and secure platform access.
  • Customer Support Systems (e.g., Jira): Receive only the information necessary to investigate, manage, and resolve support cases, service requests, and operational incidents.
  • Improzo Subsidiaries and Affiliates: May access customer information solely where necessary to support platform operations, service delivery, compliance, customer success, and related business functions, subject to appropriate governance controls.

Security and Data Protection Safeguards

Improzo requires all sub-processors to maintain appropriate technical and organizational measures designed to protect customer data. In particular:

  • Sub-processors receive only the minimum data necessary to perform their designated services.
  • Data transfers and communications are encrypted using industry-standard security protocols.
  • Access to customer data is restricted based on role, business need, and least-privilege principles.
  • Customer data is processed pursuant to contractual data protection and confidentiality obligations.
  • Personally Identifiable Information (PII) and Protected Health Information (PHI) are minimized, masked, or de-identified wherever reasonably feasible.
  • Customer data is not used to train public or shared AI models unless expressly authorized by the customer.
  • Sub-processors are required to comply with applicable data protection and security requirements.