Background
Legal

Data Processing Agreement

This DPA governs how Chargezen processes personal data on behalf of our customers, in compliance with GDPR and other applicable data protection laws.

Effective: January 1, 2025GDPR CompliantIncludes SCCs

1. Definitions

For the purposes of this Data Processing Agreement ("DPA"):

  • "Controller" means the natural or legal person which determines the purposes and means of Processing of Personal Data.
  • "Processor" means the natural or legal person which Processes Personal Data on behalf of the Controller.
  • "Personal Data" means any information relating to an identified or identifiable natural person.
  • "Processing" means any operation performed on Personal Data, including collection, storage, use, disclosure, or deletion.
  • "Data Subject" means the individual to whom Personal Data relates.
  • "Sub-Processor" means any third party engaged by Chargezen to Process Personal Data.

2. Scope and Purpose

This DPA applies to the Processing of Personal Data by Chargezen (as Processor) on behalf of Customer (as Controller) in connection with the Services provided under the Terms of Service.

Chargezen will Process Personal Data only:

  • For the purpose of providing the Services
  • As necessary to comply with applicable law
  • As otherwise instructed by Customer in writing

3. Customer Obligations

Customer represents and warrants that:

  • It has all necessary rights and consents to provide Personal Data to Chargezen
  • It will comply with all applicable data protection laws
  • Its instructions for Processing will not violate any applicable law
  • It is responsible for the accuracy, quality, and legality of Personal Data

4. Chargezen Obligations

Chargezen agrees to:

  • Process Personal Data only on documented instructions from Customer
  • Ensure personnel authorized to Process Personal Data are bound by confidentiality obligations
  • Implement appropriate technical and organizational security measures
  • Assist Customer in responding to Data Subject requests
  • Assist Customer with data protection impact assessments and regulatory consultations
  • Delete or return Personal Data upon termination, at Customer's choice
  • Make available information necessary to demonstrate compliance

5. Security Measures

Chargezen maintains comprehensive security measures including:

  • Encryption: AES-256 encryption at rest, TLS 1.3 in transit
  • Access Control: Role-based access, MFA, SSO support
  • Monitoring: 24/7 security monitoring and threat detection
  • Infrastructure: SOC 2 Type II certified hosting providers
  • Vulnerability Management: Regular penetration testing and security audits
  • Incident Response: Documented incident response procedures

6. Sub-Processors

Customer authorizes Chargezen to engage Sub-Processors for Processing activities. Chargezen will:

  • Maintain a current list of Sub-Processors (available upon request)
  • Notify Customer of any intended changes to Sub-Processors
  • Enter into written agreements with Sub-Processors imposing equivalent data protection obligations
  • Remain liable for the acts and omissions of its Sub-Processors

Customer may object to a new Sub-Processor within 30 days of notification. If Customer's objection is not resolved, Customer may terminate the affected Services.

7. Data Transfers

Chargezen may transfer Personal Data outside the European Economic Area (EEA) in compliance with GDPR requirements, using:

  • Standard Contractual Clauses (SCCs): EU-approved model clauses for data transfers
  • Adequacy Decisions: Transfers to countries with adequate protection
  • Additional Safeguards: Encryption and access controls as supplementary measures

For transfers to the United States, Chargezen implements additional technical measures to protect against government access.

8. Data Subject Rights

Chargezen will assist Customer in fulfilling obligations to respond to Data Subject requests including:

  • Access to Personal Data
  • Rectification of inaccurate data
  • Erasure ("right to be forgotten")
  • Restriction of Processing
  • Data portability
  • Objection to Processing

Chargezen will notify Customer promptly if it receives a request from a Data Subject.

9. Data Breach Notification

In the event of a Personal Data breach, Chargezen will:

  • Notify Customer without undue delay (within 72 hours of becoming aware)
  • Provide information about the nature of the breach, categories of data affected, and likely consequences
  • Describe measures taken or proposed to address the breach
  • Cooperate with Customer's investigation and notification obligations

10. Audit Rights

Customer has the right to audit Chargezen's compliance with this DPA. Audits may be conducted:

  • By Customer or an independent third-party auditor (subject to confidentiality)
  • Upon reasonable notice (minimum 30 days)
  • No more than once per year (unless required by regulatory authority)
  • At Customer's expense (unless audit reveals material non-compliance)

Chargezen will also provide audit reports (e.g., SOC 2 Type II) upon request under NDA.

11. Term and Termination

This DPA remains in effect for the duration of the Services Agreement. Upon termination:

  • Chargezen will cease Processing Personal Data (except as required by law)
  • At Customer's election, Chargezen will delete or return all Personal Data within 30 days
  • Chargezen will certify deletion in writing upon request

12. Liability

Liability under this DPA is subject to the limitations in the Services Agreement. Each party is liable only for damages caused by Processing that violates:

  • This DPA
  • Applicable data protection laws
  • Customer's lawful instructions

Current Sub-Processors

The following third parties process personal data on Chargezen's behalf. This list is updated as sub-processors are added or removed.

Sub-ProcessorPurposeLocation
Amazon Web ServicesCloud infrastructureUS, EU
Google Cloud PlatformCloud infrastructureUS, EU
StripePayment processingUS
TelnyxSMS & VoiceUS
ResendEmail deliveryUS
ShopifyE-commerce platformCA
OpenAIAI featuresUS

Last updated: December 2025. To receive notifications of sub-processor changes, contact privacy@chargezen.com

Standard Contractual Clauses (SCCs)

For transfers of personal data from the EEA to countries without an adequacy decision, Chargezen incorporates the EU Standard Contractual Clauses (Module 2: Controller to Processor) as adopted by the European Commission on June 4, 2021.

Download SCCs Annex

Questions About Data Processing?

Our privacy team is available to discuss DPA requirements, execute custom agreements, and answer questions about how we handle your data.

Space, at your fingertips

What would you do with 22% more revenue?