Legal
Data Processing Addendum
This addendum applies where Ryzion OS processes personal data on your behalf — the records you hold about your own clients and guests.
Last updated 11 August 2026
1. Scope and roles
This addendum forms part of the Terms of Service between you ("Customer") and Riyazat Jaffar Kazarani, trading as Ryzion OS ("Ryzion OS"). Where it conflicts with those terms on the subject of data protection, this addendum prevails.
For workspace content, the Customer is the controller and Ryzion OS is the processor. Ryzion OS acts as a controller only for its own account, billing and service-usage data, which is governed by the Privacy Policy rather than this addendum.
2. Details of processing
- Subject matter. Provision of the Ryzion OS event business operating system.
- Duration. For the term of the Customer's subscription, plus the retention periods set out in the Privacy Policy.
- Nature and purpose. Hosting, storage, organisation, retrieval, transmission and deletion of Customer data in order to operate the service.
- Categories of data subject. The Customer's clients, event guests, team members and vendors.
- Categories of personal data. Names, contact details, event details, guest lists and RSVP responses, photographs and video, financial records such as invoices and payments, and correspondence.
- Special category data. Not requested by the service. The Customer should not upload special category data except where it has a lawful basis to do so.
3. Ryzion OS obligations
Ryzion OS will:
- process personal data only on the Customer's documented instructions, including as to international transfers, unless required otherwise by law — in which case it will inform the Customer first, where the law permits;
- ensure personnel authorised to process personal data are bound by confidentiality obligations;
- implement appropriate technical and organisational measures, as described in the security overview;
- assist the Customer, taking account of the nature of processing, in responding to data subject requests and in meeting its obligations on security, breach notification and impact assessments;
- notify the Customer without undue delay after becoming aware of a personal data breach affecting Customer data;
- on termination, delete or return Customer data at the Customer's election, save where law requires retention.
4. Sub-processors
The Customer gives general authorisation for Ryzion OS to engage sub-processors to provide cloud infrastructure, storage, content delivery, database, email, SMS, payment and analytics services. Ryzion OS imposes data protection obligations on each sub-processor no less protective than this addendum, and remains liable for their performance.
A current list of sub-processors is available on request from hello@ryzionos.com. Ryzion OS will give at least 30 days notice before adding or replacing one, during which the Customer may object on reasonable data protection grounds.
5. International transfers
Where processing involves transferring personal data outside the UK or EEA, the parties rely on the Standard Contractual Clauses, or the UK Addendum to them, which are incorporated into this addendum by reference and completed as follows: Ryzion OS is the data importer; the Customer is the data exporter; and the description of processing is as set out in section 2 above.
6. Audits
Ryzion OS will make available the information reasonably necessary to demonstrate compliance with this addendum, and will allow for and contribute to audits conducted by the Customer or an independent auditor it mandates. Audits are limited to once per year unless required by a supervisory authority, must be requested with reasonable notice, and must not unreasonably disrupt the service.
7. Acceptance
This addendum takes effect automatically for Customers subject to GDPR, UK GDPR or a comparable regime, on acceptance of the Terms of Service. A countersigned copy for procurement purposes can be requested from hello@ryzionos.com.