Legal

Data Processing Addendum

Zariz Technologies Inc.Last updated October 8, 202615 sections

1.Definitions

“Personal Data” means any information relating to an identified or identifiable natural person, as defined by Applicable Data Protection Laws.

“Applicable Data Protection Laws” include GDPR, UK GDPR, CCPA/CPRA (to the extent applicable), and other laws governing Personal Data processing.

“Controller” means the entity that determines purposes and means of processing Personal Data.

“Processor” means the entity that processes Personal Data on behalf of the Controller.

“Service Data” means event-level data and metadata transmitted by Customer to GoKart in connection with the Services.

“Subprocessor” means any third party engaged by GoKart to process Personal Data.

“Standard Contractual Clauses (SCCs)” means the EU Commission’s 2021 SCCs, or UK Addendum/Transfer Mechanism where applicable.

2.Scope and Roles

  • Customer is the Controller.
  • GoKart (Zariz Technologies Inc.) is the Processor.
  • GoKart processes only the Personal Data that Customer transmits through APIs, SDKs, or platform integrations, and only for the limited purposes described in this DPA and the Agreement.
  • GoKart does not determine the purposes or means of processing the data.

3.Types of Data Processed

GoKart may process the following categories of Personal Data, depending on Customer configuration:

  • IP address
  • Device metadata (e.g., user agent, device/browser type)
  • Customer-defined user identifiers (e.g., user_id, hashed IDs)
  • Device IDs (IDFA/GAID), if provided by Customer
  • City, region, and country (derived or supplied)
  • Event data (offer views, clicks, conversions, timestamps)
  • Fraud and risk-scoring metadata related to events

GoKart does not collect or store:

  • Email addresses
  • Names
  • Direct identifiers of end users

4.Purpose and Nature of Processing

GoKart processes Personal Data strictly for:

  • Providing and maintaining the GoKart Services
  • Offer-wall functionality and event processing
  • Fraud detection and prevention
  • Platform analytics and reporting
  • Reliability, performance monitoring, and troubleshooting
  • Customer support
  • Compliance with applicable law

GoKart will never sell Personal Data or use it for advertising unrelated to Customer.

5.Customer Obligations

Customer agrees to:

  • Provide Personal Data only as necessary for use of the Services
  • Ensure it has a lawful basis for transmitting Personal Data
  • Not provide sensitive or special-category data
  • Implement required end-user privacy notices
  • Ensure identifiers are configured in a privacy-compliant manner
  • Respond to data subject rights requests where applicable

6.Processor Obligations

6.1Processing on Documented Instructions

GoKart processes Personal Data only:

  • On documented instructions from Customer;
  • As required to deliver the Services; or
  • As required by law.

6.2Confidentiality

GoKart ensures that all personnel with access to Personal Data are subject to confidentiality obligations.

6.3Security Measures

GoKart maintains technical and organizational measures appropriate to the risk, including:

  • Encryption in transit and at rest
  • Multi-factor authentication for internal systems
  • Role-based production access controls
  • Logging and monitoring of system access and activity
  • Vulnerability scanning and secure SDLC practices
  • DDoS/WAF protections via Cloudflare
  • Separation of environments and least-privilege access

A high-level description of GoKart's security measures is available upon request.

6.4Subprocessors

GoKart may engage the subprocessors listed in Appendix A.

GoKart will:

  • Use subprocessors bound by written agreements requiring equivalent protections
  • Remain responsible for subprocessor obligations
  • Notify Customer of changes to subprocessors when required

6.5Assistance

GoKart will provide reasonable assistance to:

  • Respond to data subject rights requests (where feasible)
  • Address Personal Data Breaches
  • Support Customer's data protection impact assessments (DPIAs) or transfer impact assessments (TIAs), limited to GoKart's role and the information reasonably available

6.6Data Location

Unless otherwise agreed, Personal Data is processed and stored in U.S. cloud regions.

7.Data Subject Requests

Because GoKart does not store end-user identifiers capable of uniquely identifying individuals:

  • GoKart cannot fulfill data subject access, deletion, or correction requests independently.
  • If GoKart receives a request directly, we will promptly notify Customer and forward the request.
  • Customer is responsible for fulfilling the request.

8.Security Incidents

In the event of a confirmed Personal Data Breach, GoKart will:

  • Notify Customer without undue delay
  • Provide details reasonably available, including:
    • the nature of the breach
    • the categories of data affected
    • mitigation steps
  • Cooperate with Customer's incident response obligations

Notification is not required for blocked or unsuccessful security events or for events not involving Personal Data.

9.International Transfers

If Customer is subject to the GDPR, UK GDPR, or similar laws, the following applies:

  • GoKart (a U.S.-based Processor) relies on the Standard Contractual Clauses (2021) as the transfer mechanism.
  • The SCCs (Module 2: Controller to Processor) are incorporated by reference.
  • The Annexes of the SCCs map to:
    • Annex I: Parties, roles, and purposes (reflected in Sections 1–4)
    • Annex II: Security measures (Section 6.3)
    • Annex III: Subprocessors (Appendix A)
  • GoKart will support Customer's Transfer Impact Assessment (TIA) with information reasonably available.
  • For UK transfers, the UK Addendum to the SCCs applies.
  • For Swiss transfers, the SCCs apply with Swiss-specific variations.

10.Return or Deletion of Data

Upon termination or Customer request:

  • GoKart will delete Personal Data from active systems.
  • Backups expire on their standard retention cycle.
  • Customer may request written confirmation of deletion.
  • GoKart may retain minimal data required for legal obligations (e.g., audit logs).

11.Audits and Compliance

GoKart will:

  • Provide security documentation, policies, or third-party reports (e.g., penetration tests, scans) on request
  • Complete reasonable security questionnaires
  • Permit document-based audits (SOC-friendly)

On-site audits are not permitted unless required by law or mutually agreed in writing.

12.Subprocessors

Customer authorizes GoKart to use the subprocessors listed in Appendix A.

GoKart will:

  • Maintain an updated list
  • Notify Customer of material changes (via dashboard, website, or email)

13.Governing Law

This DPA is governed by the laws of the State of California, without regard to its conflict-of-laws principles. The exclusive venue for any dispute arising out of or relating to this DPA is the state or federal courts located in Los Angeles County, California, and each party consents to personal jurisdiction and venue in those courts. However, where the SCCs apply, they are governed by the law and courts specified in the SCCs, to the extent the SCCs require.

14.Order of Precedence

If this DPA conflicts with the Agreement, this DPA controls to the extent required by Applicable Data Protection Laws.

15.Liability

Liability is governed by the Agreement, except where prohibited under Applicable Data Protection Laws.

Appendix A: Subprocessor List

The following subprocessors may process Personal Data when providing services to GoKart.

Contents
1. Definitions 2. Scope and Roles 3. Types of Data Processed 4. Purpose and Nature of Processing 5. Customer Obligations 6. Processor Obligations 7. Data Subject Requests 8. Security Incidents 9. International Transfers 10. Return or Deletion of Data 11. Audits and Compliance 12. Subprocessors 13. Governing Law 14. Order of Precedence 15. Liability Appendix A: Subprocessor List