Data Processing Addendum
Last updated: August 17, 2026
This Data Processing Addendum (DPA) describes how Lizrd, Inc. processes personal data on behalf of your organization when we act as your processor under the GDPR. A signable version will be provided before general availability.
Roles
You are the controller of the personal data in your workspace; Lizrd is the processor. We process it only on your documented instructions to provide the service.
Scope of processing
Subject matter: providing cloud cost visibility and optimization guidance. Data subjects: your authorized users and any individuals identifiable in the infrastructure metadata you connect (for example, owner tags).
Security
We maintain technical and organizational measures appropriate to the risk — encryption in transit and at rest, per-customer isolation, access controls, and MFA. See our security page.
Sub-processors
We use the sub-processors listed on our sub-processors page and will give notice of material changes so you can object.
International transfers
EU customer data is hosted in the EU. Any transfer outside the EEA relies on appropriate safeguards such as Standard Contractual Clauses.
Your rights & assistance
We assist you in responding to data-subject requests and, on termination, delete or return personal data except where retention is legally required.
Contact
To request a signed DPA or ask questions: hello@lizrd.ai.