Draft — last updated July 16, 2026
This Addendum forms part of the agreement between your firm ("Customer") and MIZAN and applies to personal data MIZAN processes on Customer's behalf while operating the platform, including data about Customer's own SME clients.
Customer is the controller (or, for its clients' financial data, a joint/primary controller together with the client) for the personal data it submits. MIZAN acts as processor, processing personal data only on Customer's documented instructions and for the purposes of providing the platform.
MIZAN processes account, authentication, and operational/financial data for as long as Customer maintains an active subscription, plus any retention period required afterward by accounting, tax, or other applicable law.
Current sub-processors: Supabase (database, auth, storage — Singapore), our Odoo accounting-engine host (AWS, Frankfurt), Anthropic (AI-assisted analysis), Resend (transactional email), Vercel (web hosting), and Stripe (payments, once enabled). We'll update this list and notify Customer before adding a new sub-processor with access to Customer data.
Encryption in transit and at rest, row-level tenant isolation so one firm can never read another firm's data, role-based access control, audit logging of financial-record changes, and rate limiting on every public endpoint. See our Security page for detail.
MIZAN provides self-service data export and a tracked account-deletion request flow (Settings → Privacy) and will assist Customer in responding to data subject requests it receives directly.
Data currently resides outside the UAE/KSA (see our Privacy Policy §3) while we build toward a regional data center. We'll update this Addendum with the specific transfer safeguards that apply once our infrastructure or the applicable legal basis changes.