🦎 Lizrd is in private beta. Request early access →

Data Processing Addendum

Last updated: August 17, 2026

Draft — pending legal review. This document is an early placeholder written by the Lizrd team, not final legal text. It will be reviewed and overridden by privacy counsel before general availability. It does not yet create binding commitments.

This Data Processing Addendum (DPA) describes how Lizrd, Inc. processes personal data on behalf of your organization when we act as your processor under the GDPR. A signable version will be provided before general availability.

Roles

You are the controller of the personal data in your workspace; Lizrd is the processor. We process it only on your documented instructions to provide the service.

Scope of processing

Subject matter: providing cloud cost visibility and optimization guidance. Data subjects: your authorized users and any individuals identifiable in the infrastructure metadata you connect (for example, owner tags).

Security

We maintain technical and organizational measures appropriate to the risk — encryption in transit and at rest, per-customer isolation, access controls, and MFA. See our security page.

Sub-processors

We use the sub-processors listed on our sub-processors page and will give notice of material changes so you can object.

International transfers

EU customer data is hosted in the EU. Any transfer outside the EEA relies on appropriate safeguards such as Standard Contractual Clauses.

Your rights & assistance

We assist you in responding to data-subject requests and, on termination, delete or return personal data except where retention is legally required.

Contact

To request a signed DPA or ask questions: hello@lizrd.ai.