LEGAL
Data Processing Agreement
Last updated: June 2, 2026
1. Overview
This Data Processing Agreement ("DPA") supplements the Terms of Servicebetween you (the "Controller") and Lookfar Analytics Inc., a British Columbia corporation operating under the Pricelyzer trade name (the "Processor," "Pricelyzer," "we"), and governs the processing of personal data carried out by Pricelyzer on your behalf. Enterprise customers requiring a countersigned DPA can request one by email (see §14). Until a countersigned DPA is in place, the terms of this page apply as the standard processing obligations of Pricelyzer.
2. Definitions
- Controller— the natural or legal person that determines the purposes and means of processing.
- Processor— Pricelyzer, which processes personal data on the Controller's behalf.
- Personal Data— any information relating to an identified or identifiable natural person.
- Processing— any operation performed on personal data, automated or not.
- Sub-processor— a third party engaged by Pricelyzer to process personal data on the Controller's behalf.
- Security Incident— a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal data.
- SCCs— the European Commission's Standard Contractual Clauses for international data transfers (Commission Implementing Decision 2021/914).
3. Subject matter, nature, and purpose of processing
Pricelyzer processes personal data to operate the Pricelyzer cockpit, including the currently-available tools: Searchpad, Bulk Sourcing, Ungate Checker, Brand Scanner, and the Pricelyzer Browser Extension. Processing includes lookup and computation operations, transactional emails, billing, and error monitoring. Processing continues for the duration of the Controller's use of the service and the retention windows described in the Privacy Policy.
4. Types of personal data and data subjects
- Types of personal data: account data, Amazon seller-account data accessed under OAuth, browser-extension page-read data, usage telemetry, billing data, support correspondence.
- Data subjects:the Controller's authorised users (typically the seller or the seller's authorised team members).
- Pricelyzer does not process special categories of personal data (GDPR Art. 9) or children's data in the ordinary course of providing the service.
5. Controller obligations
The Controller is responsible for ensuring that processing instructions given to Pricelyzer have a lawful basis, that any required notices have been provided to data subjects, and that the Controller's use of the service complies with applicable data-protection law.
6. Pricelyzer's obligations as Processor
- Process personal data only on the Controller's documented instructions, including for international transfers, unless required by law to do otherwise (in which case Pricelyzer will notify the Controller where legally permitted).
- Ensure personnel authorised to process personal data are bound by confidentiality.
- Implement appropriate technical and organisational security measures (see §7).
- Assist the Controller in responding to data-subject requests within 5 business days of receipt of a forwarded request.
- Assist the Controller with the obligations in GDPR Articles 32 to 36 (security, breach notification, data-protection impact assessments, prior consultation).
- At termination of the service, at the Controller's choice, delete or return all personal data processed on the Controller's behalf, save where retention is required by law.
- Make available to the Controller the information necessary to demonstrate compliance with this DPA.
7. Security measures
- TLS 1.2 or higher for all data in transit.
- AES-256 encryption at rest via the managed database provider.
- Multi-factor authentication on all privileged tooling.
- Incident detection via Sentry and the native audit trails of our hosting and database providers.
- Business continuity via Supabase managed daily backups with point-in-time recovery.
- See /security for the full posture.
8. Security incidents
Pricelyzer will notify the Controller of a Security Incident affecting the Controller's personal data without undue delay and, where feasible, within 72 hours of becoming aware of the incident, in accordance with GDPR Art. 33. The notice will describe, to the extent known: the nature of the incident, the categories and approximate number of data subjects affected, the likely consequences, and the measures taken or proposed to address the incident.
9. Sub-processors
The Controller grants Pricelyzer general authorisation to engage the sub-processors listed on the Sub-processors page. Pricelyzer will: enter into written agreements with each sub-processor imposing data-protection obligations no less protective than this DPA; remain liable to the Controller for the performance of each sub-processor; and notify the Controller at least 14 days before adding or replacing a sub-processor. The Controller may object to a new sub-processor within the notice period by emailing privacy@pricelyzer.com.
10. International data transfers
Where Pricelyzer transfers personal data from the EEA, UK, or Switzerland to a third country, the transfer relies on a valid transfer mechanism. EU→Canada transfers rely on the European Commission's adequacy decision for Canada's commercial sector under PIPEDA; no SCCs are required for those transfers. Transfers to the United States and other third countries rely on the EU Standard Contractual Clauses (Commission Implementing Decision 2021/914), supplemented where appropriate by additional technical and contractual safeguards.
11. Liability
Each party's liability under this DPA is subject to the limitations and exclusions of liability set out in the Terms of Service.
12. Order of precedence
In the event of a conflict between this DPA and any other agreement between the parties, this DPA prevails on data-protection matters and the Terms of Service prevails on all other matters.
13. Governing law
This DPA is governed by the laws of the Province of British Columbia and the federal laws of Canada applicable therein, matching the choice of law in the Terms of Service.
14. Requesting a countersigned DPA
Enterprise customers and any customer who requires a countersigned DPA may request one by emailing privacy@pricelyzer.com with subject "DPA request." Please include your organisation name, your account email, and any specific addendum requirements.
15. Contact
Data-protection inquiries: privacy@pricelyzer.com