Data processing agreement

Terms for processing personal data on behalf of customers.

The Byt-Wyze data processing agreement for customers acting as controllers.

Where a customer submits personal data to Byt-Wyze products or APIs, the customer is the controller and Byt-Wyze is the processor acting on the customer's documented instructions. For our own account, billing, marketing and website analytics data, Byt-Wyze is the controller and our Privacy Policy applies.

Processing is limited to what is necessary to provide the contracted services and continues for the term of the customer's subscription or API licence, plus any period required by law.

The customer grants general authorisation to the sub-processors listed on our Sub-processors page. We impose data-protection obligations on each sub-processor no less protective than those in this agreement and remain liable for their performance. We will give notice of intended changes so that the customer may object on reasonable data-protection grounds.

We will notify the customer without undue delay, and in any event within 72 hours of becoming aware of a personal data breach affecting their data, providing the information reasonably available to assist the customer's own notification duties.

Where personal data is transferred outside the UK or EEA, the transfer is made under an adequacy decision or the EU Standard Contractual Clauses together with the UK International Data Transfer Addendum, supported by a transfer risk assessment. Hosting regions for our backend and API infrastructure are being confirmed and will be listed on the Sub-processors page.

On termination, and at the customer's election, we will delete or return personal data processed on their behalf within 30 days, except where retention is required by law.

  • Data Processing Agreement
  • Hosting and operating the customer's account and API keys.
  • Executing analytical, verification and modelling requests submitted by the customer.
  • Recording usage for quota enforcement, billing and abuse prevention.
  • Providing support in response to customer requests.
  • Process personal data only on the customer's documented instructions, unless legally required otherwise.
  • Ensure that personnel with access are bound by confidentiality.
  • Implement appropriate technical and organisational measures, as described in our Security Policy.
  • Assist the customer with data-subject requests, impact assessments and regulator engagement, taking account of the nature of processing.