Couldn't load this page.

Data Processing Addendum

Last updated October 3, 2026

This Data Processing Addendum ("DPA") is entered into between Dragon Labs LLC, doing business as Lizard ("Lizard", "we", "us"), and the customer named on the signature page ("Customer", "you"). It forms part of the Lizard Terms of Service, or any other written agreement for the Services, between the parties (the "Agreement").

This DPA takes effect on the date the last party signs it (the "Effective Date") and applies whenever Lizard processes Customer Personal Data on Customer's behalf.

How to sign. Download the template at the bottom of this page, complete and sign the signature page, and email it to team@lizard.build. Lizard will countersign it and email a signed copy back. If you need changes to the text, tell us at the same address before you sign.

1. Definitions

Capitalized terms that this DPA does not define have the meaning given in the Agreement.

"Account Data" means personal data that Lizard needs to run Customer's account: names, email addresses and login identifiers of Customer's users, billing contacts, payment records and support messages.

"Customer Data" has the meaning given in the Agreement. It includes source code, application code, snapshots, build artifacts, runtime logs, environment variables, database content and any other data that Customer submits, stores or processes through the Services.

"Customer Personal Data" means personal data contained in Customer Data.

"Data Protection Laws" means all laws on privacy and personal data that apply to a party's processing of Customer Personal Data under the Agreement, including the GDPR, the UK GDPR, the UK Data Protection Act 2018, the Swiss Federal Act on Data Protection ("FADP") and US state privacy laws such as the California Consumer Privacy Act, as amended by the California Privacy Rights Act ("CCPA").

"GDPR" means Regulation (EU) 2016/679. "UK GDPR" means the GDPR as it forms part of UK law.

"Personal Data Breach" means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, Customer Personal Data that Lizard or its Sub-processors transmit, store or otherwise process.

"Restricted Transfer" means a transfer of Customer Personal Data from the European Economic Area ("EEA"), the United Kingdom or Switzerland to a country that the relevant authority has not found to provide an adequate level of protection.

"SCCs" means the standard contractual clauses annexed to Commission Implementing Decision (EU) 2021/914.

"UK Addendum" means the International Data Transfer Addendum to the EU Commission Standard Contractual Clauses issued by the UK Information Commissioner under section 119A of the Data Protection Act 2018, version B1.0.

"Sub-processor" means any third party that Lizard engages to process Customer Personal Data.

"System Data" has the meaning given in the Agreement.

The terms "controller", "processor", "data subject", "personal data", "processing" and "supervisory authority" have the meanings given in the GDPR. The terms "business", "service provider", "sell" and "share" have the meanings given in the CCPA.

2. Roles and scope

2.1 Customer is the controller of Customer Personal Data, or a processor acting for its own customers. Lizard is Customer's processor, or a sub-processor where Customer is itself a processor. Where Customer acts as a processor, Customer confirms that its controller has authorized Customer's instructions, including the appointment of Lizard.

2.2 Lizard processes Customer Personal Data only as Annex 1 describes.

2.3 Lizard is an independent controller of Account Data, of the personal data in System Data that Lizard needs to run, secure and bill for the Services, and of Customer Personal Data while Lizard uses it to improve the Services under Section 2.4. Lizard's Privacy Policy covers that processing. This DPA does not, except as Section 2.4 states.

2.4 Customer Personal Data remains Customer Personal Data when it appears in logs, metrics, traces or error reports. Lizard processes Customer Personal Data as a processor under this DPA to provide, secure and support the Services. Lizard may also use Customer Data, including Customer Personal Data in it, to improve the Services, as the Agreement allows; for that use Lizard acts as an independent controller. Lizard does not sell Customer Personal Data or use it for advertising.

3. Customer's instructions

3.1 Lizard processes Customer Personal Data only on Customer's documented instructions. The Agreement and this DPA are Customer's complete instructions when Customer accepts the Agreement. Customer gives further instructions by using and configuring the Services, for example by choosing a region, deploying or deleting a service, changing environment variables, running Lizard CLI commands or API calls, or asking support for help. Any other instruction requires the written agreement of both parties.

3.2 Lizard will tell Customer if it believes an instruction infringes Data Protection Laws. Lizard may suspend the processing concerned until Customer withdraws or changes the instruction.

3.3 Lizard may process Customer Personal Data where the law of the EU, an EU member state, the UK or another law that applies to Lizard requires it. In that case Lizard will inform Customer before processing, unless that law forbids it.

4. Customer's obligations

4.1 Customer is responsible for having a lawful basis to process Customer Personal Data, for giving data subjects the notices that Data Protection Laws require, for the accuracy and quality of Customer Personal Data, and for deciding whether the Services suit its data.

4.2 Customer controls its own applications and their configuration. Customer is responsible for:

  • (a) access control to its applications, databases, buckets, volumes and Sandboxes;
  • (b) keeping its API tokens, credentials and secrets confidential;
  • (c) deciding which endpoints are public;
  • (d) encrypting data within its applications where its risk calls for it; and
  • (e) keeping its own backups of Customer Data, as Sections 24 and 29 of the Terms of Service state.

4.3 Customer will not use the Services to process protected health information (Section 34 of the Terms of Service); Lizard does not sign Business Associate Agreements. Customer will not use the Services to process special categories of personal data (GDPR Article 9) or personal data relating to criminal convictions and offences (GDPR Article 10) unless Customer has assessed that the measures in Annex 2 are adequate for that data.

5. Lizard personnel

Lizard's personnel are its employees and the individual contractors who work under its direct authority. Lizard gives access to Customer Personal Data only to personnel who need it to provide, secure or support the Services and who are bound by a duty of confidentiality.

6. Security

6.1 Lizard implements and maintains the technical and organizational measures described in Annex 2. Lizard may change these measures over time, provided that the change does not lower the overall level of protection of Customer Personal Data.

6.2 Security is shared. Lizard secures the platform. Customer secures what it builds and runs on the platform, as Section 4.2 describes.

7. Sub-processors

7.1 Customer gives Lizard general authorization to engage Sub-processors. Annex 3 lists Lizard's Sub-processors on the date of this DPA. Lizard keeps the current list at lizard.build/subprocessors.

7.2 Lizard will:

  • (a) bind each Sub-processor by a written contract to data protection obligations no less protective than those in this DPA, to the extent they apply to the service that Sub-processor provides; and
  • (b) remain liable to Customer for the acts and omissions of its Sub-processors as for its own.

7.3 Lizard will tell Customer about an intended new Sub-processor by adding it to the list at lizard.build/subprocessors at least five (5) days before that Sub-processor starts processing Customer Personal Data. Customer may object in writing within those five (5) days on reasonable data protection grounds, and the parties will then discuss the objection in good faith. If Customer does not object within that period, Customer accepts the new Sub-processor. If they cannot resolve it, Customer's sole and exclusive remedy is to terminate the Agreement and stop using the Services.

7.4 Services that Customer chooses to connect to the Services, such as its GitHub repositories, AI model providers whose credentials Customer adds, or its own external databases, are not Sub-processors. Customer's own terms with those providers govern them.

8. Personal Data Breach

8.1 Lizard will notify Customer without undue delay after becoming aware of a Personal Data Breach. Lizard will send the notice to Customer's contact for notices named on the signature page and to the owner of Customer's account.

8.2 The notice will describe, as far as Lizard knows at that time:

  • (a) the nature of the Personal Data Breach, including the categories and approximate number of data subjects and records concerned;
  • (b) its likely consequences;
  • (c) the measures Lizard has taken or proposes to take to address it and limit its effects; and
  • (d) a contact point for more information.

Where Lizard cannot provide all of this at once, Lizard will provide it in phases as it becomes available.

8.3 Lizard will take reasonable steps to contain, investigate and remedy the Personal Data Breach, and will give Customer reasonable help to meet Customer's own obligations to notify supervisory authorities and data subjects under GDPR Articles 33 and 34.

8.4 Unsuccessful attempts or activities that do not compromise the security of Customer Personal Data, such as pings, port scans, failed login attempts and denial-of-service attacks that do not reach data, are not Personal Data Breaches. Lizard's notice of a Personal Data Breach is not an admission of fault or liability.

8.5 This Section 8 does not apply to incidents that Customer or its users cause, such as leaked credentials or a misconfigured application. Lizard will still give reasonable help on request.

9. Data subject requests

9.1 Customer controls its applications and data, and can access, correct, export and delete Customer Personal Data itself through the Services.

9.2 If Lizard receives a request from a data subject about Customer Personal Data and can identify Customer from it, Lizard will forward the request to Customer without undue delay. Lizard will not answer the request itself, except to tell the data subject to contact Customer, unless law requires otherwise.

9.3 Where Customer cannot fulfill a request through the Services, Lizard will give Customer reasonable help, taking into account the nature of the processing. If that help goes beyond what the Services normally provide, Lizard may charge Customer its reasonable costs.

10. Impact assessments and consultations

Lizard will give Customer reasonable help with data protection impact assessments and prior consultations with supervisory authorities under GDPR Articles 35 and 36, where Customer is required to carry them out. Lizard will do so using this DPA, its security documentation and other information reasonably available to it.

11. Audits

11.1 Lizard will make available to Customer the information reasonably necessary to show that it complies with this DPA and GDPR Article 28.

11.2 Lizard will answer one written security and privacy questionnaire from Customer per calendar year.

11.3 If the information under Sections 11.1 and 11.2 is not enough for Customer to meet its obligations under Data Protection Laws or the SCCs, Customer may audit Lizard's compliance with this DPA no more than once per calendar year, unless a supervisory authority requires otherwise. Such an audit:

  • (a) requires at least 30 days' written notice;
  • (b) follows a scope, timing and duration that the parties agree in advance;
  • (c) takes place during business hours and without unreasonable disruption to Lizard's operations;
  • (d) is performed by Customer or by an independent auditor that is bound by confidentiality and is not a competitor of Lizard;
  • (e) does not give access to other customers' data or to information whose disclosure would compromise the security of the Services; and
  • (f) is at Customer's cost, including reimbursement of the time Lizard spends on it.

Customer will share the audit report with Lizard at no charge.

11.4 Once Lizard holds an independent certification or attestation, such as a SOC 2 Type II report or ISO/IEC 27001 certification, Lizard may provide it instead of an audit, to the extent it covers the scope of the audit.

12. Data location and international transfers

12.1 Customer chooses the region for each service and Sandbox it creates. Annex 1 lists the regions available. Lizard runs Customer's services and Sandboxes, and stores the data held in Managed Postgres, Managed Redis, Persistent Volumes and Managed Object Storage, in the region that Customer selects. Lizard does not move that data to another region without Customer's instruction, except as Section 12.2 describes.

12.2 Lizard is established in the United States, and its control plane runs in the us-east-1 region, with a copy in eu-west-lim-a. Whatever region Customer selects, Lizard therefore processes the following in the United States: Account Data; project and deployment metadata; environment variables and secrets, which Lizard encrypts as Annex 2 describes; the names and metadata of objects in Managed Object Storage, but not their contents; short excerpts of build and crash logs; and data that Customer shares in support requests. Source code that Customer uploads with the Lizard CLI may pass through the region that receives the upload on its way to the build; Lizard does not keep it there. Lizard is a remote-first organization, and its personnel may access Customer Personal Data from outside the region Customer selects, subject to Sections 5 and 12.

12.3 EEA transfers. To the extent the transfer of Customer Personal Data from Customer to Lizard is a Restricted Transfer under the GDPR, the SCCs are incorporated into this DPA by reference and completed as follows:

  • (a) Module Two (controller to processor) applies where Customer is a controller, and Module Three (processor to processor) applies where Customer is a processor;
  • (b) the optional docking clause in Clause 7 does not apply;
  • (c) in Clause 9, Option 2 (general written authorization) applies, and Lizard informs Customer of intended changes in the way and at the time Section 7.3 describes;
  • (d) the optional wording in Clause 11 does not apply;
  • (e) in Clause 13, the competent supervisory authority is the one identified in Annex 1, Part C;
  • (f) in Clause 17, Option 1 applies, and the governing law is the law of Ireland;
  • (g) in Clause 18(b), disputes are resolved before the courts of Ireland;
  • (h) Annex I of the SCCs is completed by Annex 1 of this DPA, Annex II by Annex 2 and Annex III by Annex 3; and
  • (i) the parties agree that audits under Clause 8.9 are carried out as Section 11 describes, that the certification of deletion under Clauses 8.5 and 16(d) is provided only on Customer's written request, and that Lizard may remove commercial terms from copies of Sub-processor contracts it provides under Clause 9(c).

12.4 UK transfers. To the extent the transfer is a Restricted Transfer under the UK GDPR, the UK Addendum is incorporated into this DPA by reference and completed as follows: Table 1 is completed by Annex 1, Part A; Table 2 is completed by the SCCs as Section 12.3 completes them; Table 3 is completed by Annexes 1, 2 and 3; and in Table 4, the Importer may end the UK Addendum under its Section 19.

12.5 Swiss transfers. To the extent the transfer is a Restricted Transfer under the FADP, the SCCs apply as Section 12.3 completes them, with these changes: the Swiss Federal Data Protection and Information Commissioner is the competent supervisory authority for transfers governed by the FADP; references to the GDPR include the FADP; and the term "member state" in Clause 18(c) includes Switzerland, so that data subjects in Switzerland can bring claims where they habitually reside.

12.6 If the SCCs or the UK Addendum are replaced or ruled invalid, Lizard may adopt another lawful transfer mechanism, such as updated clauses or certification under the EU-US Data Privacy Framework, by notice to Customer.

12.7 Requests from public authorities. Lizard will not disclose Customer Personal Data to a public authority voluntarily. If Lizard receives a legally binding request for Customer Personal Data, Lizard will:

  • (a) try to redirect the authority to request the data from Customer directly;
  • (b) notify Customer promptly, unless law prohibits it;
  • (c) challenge the request where Lizard reasonably considers it unlawful; and
  • (d) disclose only the minimum data the request requires.

13. US state privacy laws

13.1 Where the CCPA or a similar US state law applies, Lizard acts as Customer's "service provider" or "processor". Lizard will not:

  • (a) sell or share Customer Personal Data;
  • (b) retain, use or disclose Customer Personal Data for any purpose other than the business purposes set out in the Agreement, including for any commercial purpose other than providing and improving the Services, as the CCPA permits;
  • (c) retain, use or disclose Customer Personal Data outside the direct business relationship between Lizard and Customer; or
  • (d) combine Customer Personal Data with personal information that Lizard receives from other sources, except as the CCPA permits.

13.2 Lizard will comply with the obligations that the CCPA places on service providers, will give Customer Personal Data the level of privacy protection the CCPA requires, and will notify Customer if it determines that it can no longer meet these obligations. Customer may take reasonable steps to stop and remedy any unauthorized use of Customer Personal Data. Lizard certifies that it understands and will comply with the restrictions in this Section 13.

14. Deletion and return

14.1 While the Agreement is in force, Customer can export Customer Data at any time through the Services, and can ask Lizard to delete Customer Data at any time by emailing team@lizard.build. Lizard then deletes all of the data concerned, including archived projects, logs, crash log excerpts and backups.

14.2 The end of the Agreement counts as Customer's instruction to delete Customer Personal Data. Lizard will delete it within a commercially reasonable timeframe, except where the law of the EU, an EU member state, the UK or another law that applies to Lizard requires Lizard to keep it. If Customer wants a copy, it can export its data before the Agreement ends or ask for one at team@lizard.build. Lizard keeps only the latest daily backup of each Managed Postgres and Managed Redis database, and deletes the backup of a deleted database within the same timeframe. Lizard will not process backups for any other purpose in the meantime. Lizard will confirm deletion in writing on Customer's request.

15. Liability

Each party's liability arising out of or relating to this DPA, and to the SCCs to the extent the law permits, is subject to the limitations and exclusions of liability in the Agreement. Nothing in this DPA limits either party's liability to data subjects where Data Protection Laws or the SCCs do not allow that liability to be limited.

16. General

16.1 Term. This DPA starts on the Effective Date and remains in force for as long as Lizard processes Customer Personal Data under the Agreement.

16.2 Order of precedence. If documents conflict, they apply in this order: (1) the SCCs and the UK Addendum; (2) this DPA; (3) the Agreement; (4) Lizard's Privacy Policy. In particular, this DPA prevails over Sections 24, 27, 29 and 35 of the Terms of Service as far as they concern Customer Personal Data.

16.3 Changes. Any change to this DPA requires the written agreement of both parties, except that Lizard may update Annex 2 as Section 6.1 allows and Annex 3 as Section 7 allows.

16.4 Governing law. This DPA is governed by the law that governs the Agreement, except where Data Protection Laws or the SCCs require otherwise.

16.5 Severability. If any provision of this DPA is held invalid or unenforceable, the rest of this DPA remains in effect.

16.6 Notices. Lizard sends notices under this DPA to Customer's contact for notices named on the signature page. Customer sends notices to Lizard at team@lizard.build.

Signatures

By signing below, the parties enter into this DPA and, where Section 12 applies, the SCCs and the UK Addendum as Section 12 completes them.

CustomerLizard
Legal nameDragon Labs LLC, doing business as Lizard
Address1336 NW Flanders St #312, Portland, OR 97209, United States
Print name
Title
Signature
Date
Contact for notices under this DPAteam@lizard.build

Annex 1. Details of processing

A. List of parties

Data exporter. Customer. Name, address and contact details: as on the signature page. Activities: use of the Services under the Agreement. Role: controller (Module Two) or processor (Module Three). Signature and date: as on the signature page.

Data importer. Dragon Labs LLC, doing business as Lizard, 1336 NW Flanders St #312, Portland, OR 97209, United States. Contact: team@lizard.build. Activities: providing the Services under the Agreement. Role: processor. Signature and date: as on the signature page.

B. Description of processing and transfer

Categories of data subjects. Determined by Customer. They typically include Customer's end users, customers, prospects, employees and contractors, and members of Customer's team whose data appears in Customer Data.

Categories of personal data. Determined by Customer. They may include identifiers and contact details, account credentials, IP addresses, device and usage data, content that users submit to Customer's applications, and any other personal data that Customer stores in databases, volumes, buckets, environment variables, logs, source code or Sandboxes.

Sensitive data. None intended (see Section 4.3). If Customer processes sensitive data, the measures in Annex 2 apply.

Frequency of transfer. Continuous, for the term of the Agreement.

Nature of processing. Hosting, storage, compute and networking, including: building and running Customer's code in containers and Sandboxes; storing data in Managed Postgres, Managed Redis, Managed Object Storage and Persistent Volumes; routing traffic to Customer's applications; collecting runtime and build logs and metrics; taking snapshots and backups where the Services provide them; providing support; and deleting data.

Purpose of processing. Providing, securing and supporting the Services under the Agreement.

Retention. For the term of the Agreement, followed by deletion as Section 14 describes.

Transfers to Sub-processors. As Annex 3 describes, for the term of the Agreement.

Processing locations.

RegionLocationProviderWhat runs there
eu-west-lim-aLimburg an der Lahn, GermanyOVH GmbHCustomer services, Sandboxes, Managed Postgres, Managed Redis, Managed Object Storage and Persistent Volumes created in this region; a copy of the control plane database
us-east-1Virginia, United StatesOVH US LLCCustomer services, Sandboxes, Managed Postgres, Managed Redis, Managed Object Storage and Persistent Volumes created in this region; Lizard's control plane for all regions
canary-franceGravelines, FranceOVH SASLizard's test infrastructure, connected to the production control plane. Not offered for customer workloads

C. Competent supervisory authority

Where Customer is established in an EU member state, the supervisory authority of that member state. Where Customer is not established in the EU but has appointed a representative under GDPR Article 27(1), the supervisory authority of the member state where the representative is established. Otherwise, the supervisory authority of the member state where the data subjects whose personal data is transferred are located.

Annex 2. Technical and organizational measures

Encryption in transit. Lizard serves public traffic to Customer's applications and to lizard.build over TLS, with certificates from Let's Encrypt. lizard.build sends HTTP Strict Transport Security headers. Traffic between Lizard regions runs over an encrypted WireGuard network. Managed Postgres accepts TLS connections.

Encryption of secrets. Lizard encrypts environment variables and secrets, managed database passwords and third-party access tokens with HashiCorp Vault's transit engine. Each region runs its own Vault.

Encryption at rest. The disks that hold databases, volumes and Managed Object Storage are encrypted with LUKS. Lizard also encrypts secrets, as described above, and all backups.

Isolation between customers. Each service runs in its own container. Network policies deny traffic by default and let a service receive traffic only from services in the same project and from Lizard's ingress. Customer workloads cannot reach Lizard's platform services, Vault or internal network. Containers run without privilege escalation, under the default seccomp profile and the Kubernetes "baseline" Pod Security standard, and without Kubernetes API credentials. Sandboxes run apart from services, with all Linux capabilities dropped. Each Sandbox is used once and then destroyed, and cannot reach private networks or Lizard's platform addresses.

Customer sign-in. Customers sign in with GitHub or Google and can protect their accounts with those providers' two-factor authentication.

Logging. Lizard keeps an audit log of changes to projects that records the user, the action and the time. Runtime logs are kept in a rolling buffer of about 20,000 lines per service and are cleared on redeploy.

Backups. Lizard backs up every Managed Postgres and Managed Redis database once a day at 00:00 UTC. Lizard keeps only the latest backup of each database, and all backups are encrypted. Backups are stored on a separate backup server in the same region as the database. Lizard does not back up Managed Object Storage or Persistent Volumes. Customer remains responsible for its own backups, as Sections 24 and 29 of the Terms of Service state.

Physical security. Lizard is a remote-first organization with no offices that hold Customer Data. Customer Data is stored in OVHcloud data centers, which control physical access to their facilities.

Data location. Customer chooses the region for its services and data, as Section 12 describes.

Security reviews. Lizard runs internal security reviews of the platform and tracks findings until they are fixed.

Incidents. Lizard handles Personal Data Breaches as Section 8 describes.

Personnel. Staff and contractors with access to Customer Personal Data are bound by confidentiality, as Section 5 describes.

Deletion. Lizard deletes Customer Personal Data on request, as Section 14 describes.

Sub-processors. Lizard reviews a Sub-processor's security before engaging it and binds it by contract, as Section 7 describes.

Annex 3. Sub-processors

A. Sub-processors of Customer Personal Data

Sub-processorPurposeLocation
OVH GmbHInfrastructure for eu-west-lim-a and the copy of the control plane databaseGermany
OVH US LLCInfrastructure for us-east-1 and the control planeUnited States
OVH SASTest infrastructure connected to the production control planeFrance
Railway CorporationHosting for Lizard's internal monitoring, which reads control plane data, including crash log excerptsUnited States (Virginia)
Proton AGEmail inbox for team@lizard.build, which receives support requestsSwitzerland

B. Providers that handle Account Data

Lizard acts as an independent controller for this data (Section 2.3), and Lizard's Privacy Policy governs it. We list these providers here so that Customer sees every party involved.

ProviderPurposeLocation
Stripe, Inc.Card payments and invoicesUnited States
Coinbase, Inc. (Coinbase Developer Platform)Crypto paymentsUnited States
Plus Five Five, Inc. (Resend)Account and billing emailsUnited States
GitHub, Inc.Sign-inUnited States
Google LLCSign-in; website analytics after consentUnited States
PostHog, Inc.Product analyticsUnited States
Ahrefs Pte. Ltd.Website analytics after consentSingapore

Sign this DPA

  1. Download the template. It has the same text as this page, with a blank signature page.
  2. Fill in and sign the Customer column on the signature page.
  3. Email the signed copy to team@lizard.build. We countersign it and send a copy back.
Download DPA template (.docx)

Need changes to the text? Tell us at team@lizard.build before you sign.

We use cookies for essential site functionality and analytics. See our Cookie Policy.