Data Protection

Data Processing Agreement

Last updated: February 20, 2025

DPA Summary: This agreement governs how we handle data on your behalf. As the Processor, SpendGuard describes the safeguards, processing limits, and assistance workflows available for customer privacy and data protection reviews.

1. Overview

This Data Processing Agreement ("DPA") forms part of the Terms of Service between ChaliseyZ Central L.L.C. ("Processor") and the Customer ("Controller"). It governs the processing of personal data by SpendGuard on behalf of its customers.

2. Scope of Processing

SpendGuard processes personal data only to the extent necessary to provide the Services as described in the Terms of Service and as instructed by the Customer. Categories of data include agent identifiers, transaction metadata, and account information.

3. Security Measures

SpendGuard implements technical and organizational measures intended to protect personal data, including encryption, access controls, internal review, and incident response procedures as detailed in our Security documentation.

4. Sub-Processors

SpendGuard may engage sub-processors to assist in providing the Services. A current list of sub-processors is available upon request. Customers will be notified of any changes to sub-processors with 30 days' notice.

5. Data Transfers

Data may be transferred to countries outside the European Economic Area. Such transfers are protected by Standard Contractual Clauses or other appropriate safeguards as required by applicable law.

6. Data Subject Rights

SpendGuard will assist the Customer in responding to data subject requests, including access, rectification, erasure, and portability requests, to the extent technically feasible.

7. Data Breach Notification

SpendGuard will notify the Customer of any personal data breach without undue delay and no later than 72 hours after becoming aware of the breach.

8. Contact Information

For DPA-related inquiries or to execute a formal DPA, please use the company contact page.