Last updated June 2026
Data Processing Addendum
This Data Processing Addendum ("DPA") applies when Razen processes personal data on behalf of a business customer (the "Controller") in the course of providing the Service. It supplements our Terms of Service.
1. Roles
For data processed on behalf of the Controller, Razen is the Processor. For account data and billing data we process for our own purposes, Razen is the Controller.
2. Subject matter and duration
Razen processes Controller personal data only to provide the Service for the duration of the agreement.
3. Nature and purpose of processing
Storage, hosting, transmission, AI inference (LLM, TTS, STT), and analytics — all solely to operate the Service.
4. Sub-processors
Razen uses sub-processors listed at /legal/sub-processors. We will notify Controllers of changes at least 30 days before they take effect. Controllers may object in writing.
5. International transfers
Where personal data is transferred to a sub-processor outside the UK / EEA, Razen relies on the EU Standard Contractual Clauses (Commission Implementing Decision 2021/914) and the UK addendum, with appropriate supplementary measures.
6. Security
Razen implements appropriate technical and organisational measures including encryption in transit and at rest, row-level security, audit logging of administrative actions, principle of least privilege, and regular vulnerability management.
7. Data subject rights
Razen will assist the Controller in responding to data subject requests, using technical measures where possible. Standard self-service tools are available in the Service.
8. Breach notification
Razen will notify the Controller without undue delay (and in any event within 72 hours of becoming aware) of a personal data breach affecting Controller data.
9. Audit
Razen will, on reasonable notice and no more than once per year, make available to the Controller information necessary to demonstrate compliance, including security certifications and a brief annual security summary.
10. Return or deletion
On termination, Razen will, at the Controller's choice, return or delete Controller personal data within 30 days, except where law requires retention.
11. Contact
razenai@outlook.com