Legal

Data Protection Addendum

Effective date: 25 January 2026

This Data Protection Addendum (“Addendum”) between Nexura Technologies Private Limited, operating as Wyzard (“Wyzard”, “we”, or “us”), and the Customer forms part of the Terms of Use or other written or electronic agreement governing Customer’s access to and use of the Services (the “Agreement”).

Customer enters into this Addendum on behalf of itself and any Affiliates authorized to use the Services under the Agreement who have not entered into a separate contractual arrangement with Wyzard. For this Addendum only, references to “Customer” include Customer and such Affiliates.

1. Definitions

  • Affiliate means an entity that owns or controls, is owned or controlled by, or is under common control with a party.
  • Client Personal Data means Personal Data provided by or made available by Customer to Wyzard, or collected by Wyzard on behalf of Customer, which is Processed to perform the Services.
  • Controller to Processor SCCs means the EU Commission standard contractual clauses of 4 June 2021, the UK International Data Transfer Addendum, Swiss FDPIC clauses, and any successor clauses.
  • Data Protection Laws means applicable privacy and data-protection law, including the EU GDPR, UK GDPR, Swiss FADP, and India’s Digital Personal Data Protection Act.
  • Services means the Wyzard platform and related services supplied under the Agreement.
  • Third Country means a country that has not received an adequacy decision where one is required.

“Controller”, “Processor”, “Data Subject”, “Personal Data”, “Personal Data Breach”, “Process”, “Subprocessor”, and “Supervisory Authority” have the meanings in applicable Data Protection Laws.

2. Formation

This Addendum is deemed agreed on the later of (i) the date Customer accepts it and (ii) the effective date of the Agreement.

3. Roles of the parties

For Client Personal Data, Customer is the Controller and Wyzard is the Processor, except where Wyzard processes personal data for its own purposes as described in the Privacy Policy, in which case Wyzard is an independent Controller.

4. Description of processing

Annex 1 sets out the Processing details required by Article 28(3) GDPR. Either party may make reasonable amendments to Annex 1 by written notice as reasonably necessary to meet those requirements.

5. Data processing terms

Customer shall comply with Data Protection Laws in connection with this Addendum and is solely responsible for the lawful collection and transfer of Client Personal Data to Wyzard. Customer agrees not to provide special categories of data under Article 9 GDPR unless agreed in writing.

Wyzard shall:

  • Process Client Personal Data only on documented instructions from Customer, including with regard to transfers to a Third Country, unless required by law; Wyzard shall inform Customer if an instruction infringes Data Protection Laws.
  • Ensure persons authorized to process Client Personal Data are bound by confidentiality.
  • Implement appropriate technical and organizational measures, including encryption, access control, resilience, and regular testing.
  • Engage subprocessors listed in Annex 2, remain liable for them, impose materially equivalent obligations, and notify Customer of intended changes. Customer may object on reasonable grounds within 30 days; the parties will then seek a commercially reasonable alternative, failing which either party may terminate the affected Services.
  • Promptly notify Customer of Data Subject or Supervisory Authority communications relating to Client Personal Data and assist with data-subject requests.
  • Notify Customer without undue delay after becoming aware of a Personal Data Breach involving Client Personal Data.
  • Provide reasonable assistance with Articles 32 to 36 GDPR, taking into account the nature of Processing and information available to Wyzard.
  • On termination or expiry, at Customer’s option return or delete Client Personal Data unless law requires storage.

Wyzard does not use Client Personal Data processed under this Addendum for Wyzard’s own marketing or advertising.

6. Restricted transfers

Where Wyzard processes EU Area Personal Data in a Third Country, the Controller to Processor SCCs are incorporated by reference. Appendix 1 is deemed populated with Annex 1, and Appendix 2 with the technical and organizational measures in this Addendum.

7. Precedence

This Addendum supplements the Agreement and prevails on data-protection matters if there is a conflict.

8. Data Protection Officer

Requests for access, correction, or erasure of Personal Data, and concerns or complaints related to Personal Data, may be sent to:

Name: Mohit Chaukikar
Role: Data Protection Officer
Email: mohit.chaukikar@wyzard.ai

9. Other processor commitments

Wyzard also commits to:

  • Privacy by design and by default
  • Security of processing appropriate to the risk
  • Notifying supervisory authorities, customers, and affected individuals of personal-data breaches as required by law
  • Assisting Customer with data-protection impact assessments and prior consultation where required
  • Informing Customer if, in Wyzard’s opinion, a processing instruction infringes applicable law
  • Deleting or de-identifying Client Personal Data after the applicable retention period
  • Informing Customer, where legally permitted, of legally binding requests for disclosure of personal data
  • Operating an information security programme aligned with ISO/IEC 27001:2022 and, where applicable, ISO/IEC 27701:2022 and EU GDPR

Annex 1 — Description of processing

Data exporter (Controller): Customer, as set out in the relevant Order Form.

Data importer (Processor): Nexura Technologies Private Limited (brand: Wyzard), 448A, 3rd Floor, ENKAY SQUARE, Phase V, Udyog Vihar, Sector 19, Gurugram, Haryana 122022, India. Contact: Mohit Chaukikar, Data Protection Officer, mohit.chaukikar@wyzard.ai.

Competent supervisory authority: as determined by Clause 13 of the EU SCCs.

Subject matter and duration: provision of the Services for the term of the Agreement.

Nature and purpose: hosting, storing, transmitting, and otherwise processing Client Personal Data as necessary to provide the Wyzard platform (including signal ingestion, enrichment, qualification, and outreach workflows).

Categories of data subjects: Customer’s employees, contractors, users, prospects, and other individuals whose data Customer submits to the Services.

Types of personal data: identity and contact data (name, email, phone, job title, company), usage and technical data, and other data Customer elects to submit. Special categories: none, unless separately agreed in writing.

Technical and organizational measures

  • Information security management aligned with ISO/IEC 27001:2022
  • Least-privilege access, unique user IDs, multi-factor authentication, and periodic access reviews
  • Personnel confidentiality undertakings and security training
  • Encryption in transit (TLS) and encryption at rest
  • Production hosting on Google Cloud Platform with logging, vulnerability management, and incident response
  • Logical isolation of customer data and secure disposal when no longer required

Annex 2 — Authorized subprocessors

NameProcessingLocation
Google Cloud PlatformHosting the production environmentSingapore
Google WorkspaceEmail and collaborationIndia
MongoDBDatabaseIndia
GitHubCode version controlIndia / United States
Scrut AutomationRisk management and governanceIndia
CloudflareCDN, DNS, and web application firewallGlobal

See also our Privacy Policy, Terms & Conditions, and Cookie Policy.