Data Processing Agreement
Last updated: January 13, 2026
This Data Processing Agreement (“DPA”) supplements the Terms of Service governing the Customer’s use of services provided by eazyBackup Systems Ltd. (“eazyBackup”). It addresses personal data processed by eazyBackup on the Customer’s behalf. The Terms continue to govern commercial matters and allocation of risk, as expressly preserved in section 10.
1. Application and Roles
This DPA takes effect when incorporated into the parties’ service agreement or otherwise accepted by both parties in writing, including electronically. “Terms” means the Terms of Service at https://eazybackup.com/terms/ as validly applicable to the Customer. Other capitalized terms have the meanings given in the Terms.
“Customer Personal Data” means personal information contained in Customer Data that eazyBackup processes on the Customer’s behalf.
“Applicable Data Protection Law” means privacy and data protection laws legally applicable to that processing, including requirements applicable to the Customer’s appointment of a processor, service provider, contractor or subprocessor.
The Customer is the controller or equivalent responsible organization and eazyBackup is its processor or service provider. Where the Customer acts for its own clients, including as an MSP, the Customer is a processor and eazyBackup is its subprocessor. The Customer must have authority to give instructions and appoint eazyBackup for those clients. Agreements between the Customer and its clients do not bind eazyBackup.
The Privacy Policy at https://eazybackup.com/privacy/ governs personal information eazyBackup processes for its own account administration, billing and other independent purposes. Actual processing activities determine the parties’ respective legal roles.
This DPA does not constitute a Business Associate Agreement or other sector-specific agreement unless expressly agreed in writing.
2. Processing Details and Customer Responsibilities
The subject matter and purpose of processing are the backup, storage and recovery services ordered by the Customer. Processing operations may include collection, transfer, organization, storage, retrieval, restoration and deletion, together with associated support and security operations. Processing continues for the service term and any lawful return or deletion period under section 7.
The Customer determines the data submitted to the Services. Customer Personal Data may include contact details, identifiers, communications, employment information, financial information, health information and other personal information contained in selected files, mailboxes, databases and Customer Data.
Individuals whose personal information may be processed can include the Customer’s and its clients’ employees, customers, patients, suppliers and other persons represented in Customer Data. Sensitive personal information is included only where lawfully submitted for the selected Services.
The Customer determines the purposes of processing and lawful instructions, obtains any permissions or consents required for its processing, and selects appropriate Services and settings. The Customer’s responsibilities under the Terms for credentials, retention, independent backups and restore testing remain unchanged.
The Customer may exercise the instruction, assistance and return or deletion rights stated in this DPA. Each party remains responsible for its own obligations under Applicable Data Protection Law.
3. Instructions and Confidentiality
eazyBackup will process Customer Personal Data only on documented Customer instructions, including instructions concerning transfers, or where processing is required by law.
Documented instructions include this DPA, the applicable service agreement, the Customer’s configured settings and authorized service requests. Additional instructions outside the agreed Services require eazyBackup’s agreement unless otherwise required by Applicable Data Protection Law.
Where processing is required by law, eazyBackup will provide any notice to the Customer required by Applicable Data Protection Law unless prohibited by law.
Where required by Applicable Data Protection Law, eazyBackup will inform the Customer if it reasonably believes a Customer instruction infringes that law.
Access to Customer Personal Data by eazyBackup personnel will be limited to authorized persons who require access for their duties and who are subject to contractual or statutory confidentiality obligations.
eazyBackup will not sell Customer Personal Data or use it for advertising.
4. Security and Personal Data Incidents
eazyBackup will maintain technical and organizational safeguards appropriate to the nature and risks of the processing, including access restrictions, confidentiality controls and measures designed to protect processing systems.
Where applicable, eazyBackup will implement measures required by Article 32 of the EU GDPR or UK GDPR. These obligations require appropriate safeguards and do not constitute a guarantee that security incidents, service interruptions or data loss cannot occur.
eazyBackup will notify the Customer without undue delay after becoming aware of a breach of security leading to accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to Customer Personal Data processed by eazyBackup or its subprocessors.
eazyBackup will provide information reasonably available to it and reasonably necessary for the Customer’s legal response, with additional information provided as it becomes available. eazyBackup will take reasonable measures to contain and address the incident as required by Applicable Data Protection Law.
Notification of an incident does not constitute an admission of fault or liability.
Unsuccessful attempts that do not compromise Customer Personal Data do not trigger notification under this section unless Applicable Data Protection Law requires otherwise. Any shorter mandatory deadline or broader mandatory notification requirement applies only to the affected processing.
The Customer is responsible for notifications to its clients, affected individuals and regulators except where eazyBackup has an independent legal obligation to provide such notification.
5. Subprocessors
The Customer gives general written authorization for eazyBackup to appoint subprocessors as necessary to provide the Services.
eazyBackup will bind subprocessors by written obligations appropriate to their processing and, where required by Applicable Data Protection Law, obligations equivalent to the relevant requirements of this DPA.
Information identifying relevant subprocessors, their functions and processing locations will be made available on request.
Where Applicable Data Protection Law requires notice of a new or replacement subprocessor or provides the Customer with a right to object, eazyBackup will provide the required notice and a reasonable opportunity to object on substantiated data protection grounds.
The parties will seek a reasonable resolution to a legally valid objection. Any unresolved objection will be addressed as required by Applicable Data Protection Law.
eazyBackup remains responsible for subprocessor obligations to the extent required by Applicable Data Protection Law, subject to section 10 wherever legally permitted.
6. Assistance and Verification
To the extent required by Applicable Data Protection Law, eazyBackup will provide reasonable assistance to the Customer regarding individuals’ privacy rights and the Customer’s applicable data protection obligations, taking into account the nature of the Services and information available to eazyBackup.
eazyBackup will also provide information and permit verification or audits only to the extent required by Applicable Data Protection Law, subject to reasonable confidentiality, security and operational safeguards.
7. Return and Deletion
Upon termination of the applicable Services, the Customer may retrieve Customer Personal Data using functionality made available with the Services.
To the extent required by Applicable Data Protection Law, eazyBackup will thereafter delete or return Customer Personal Data, at the Customer’s choice, unless retention is required by applicable law.
Deletion is subject to eazyBackup’s normal deletion procedures and any retention, immutability or Object Lock settings configured by the Customer. Any Customer Personal Data retained during an applicable deletion or retention period will remain subject to this DPA.
Nothing in this section creates an obligation to provide a free data export service, extended service period or additional recovery functionality beyond the Services, except to the extent required by Applicable Data Protection Law.
8. Data Location
Customer Data stored as backup copies or objects in eazyBackup-hosted storage is hosted in Canada.
This data-location commitment does not apply to account, billing, support, email or other administrative or operational information, which may be processed by eazyBackup or its subprocessors in other jurisdictions.
9. Additional U.S. State Privacy Terms
Where applicable U.S. state privacy law applies to eazyBackup as a service provider, contractor or processor, eazyBackup will process Customer Personal Data only for the purposes described in section 2 and as otherwise permitted by applicable law.
eazyBackup will not sell or share such data, as those terms are defined by applicable U.S. state privacy law, or retain, use, disclose or combine it outside those purposes or the direct business relationship, except as permitted by applicable law.
Where required by such law, eazyBackup will notify the Customer if it determines that it can no longer meet the applicable requirements and will permit the reasonable verification and remediation rights required by law, subject to section 6.
Required subprocessor obligations will apply in accordance with section 5.
10. Relationship to Terms
To the maximum extent permitted by law, all warranty disclaimers, exclusions of damages, limitations of liability, indemnities and other allocations of risk in the Terms apply to this DPA and to all claims arising from or relating to it.
This DPA creates no separate indemnity, warranty, service level, recovery guarantee or additional liability.
All liability arising from or relating to this DPA is included within, and does not increase, the single aggregate limitation of liability under the Terms.
If this DPA conflicts with the Terms, this DPA controls only to the extent necessary to give effect to its applicable data-processing obligations. The Terms otherwise control, including with respect to liability, remedies, warranties, service availability, data loss, governing law and jurisdiction.
Nothing in this DPA limits any obligation or liability to the extent it cannot lawfully be limited.