Legal
Data Processing Addendum
Data processing terms satisfying GDPR Article 28 and Egyptian PDPL requirements for FurnViz customers.
This page is a plain-language summary for general information and is not legal advice.
Last updated: June 29, 2026
1. Introduction and Scope
This Data Processing Addendum ("DPA") forms part of the FurnViz Terms of Service (the "Agreement") between FurnViz ("Processor") and the Customer ("Controller"). This DPA applies to all processing of personal data carried out by FurnViz on behalf of the Customer in connection with the provision of the Service. In the event of any conflict between this DPA and the Agreement, the terms of this DPA shall prevail with respect to data protection matters. This DPA is intended to satisfy the requirements of Article 28 of the General Data Protection Regulation (EU) 2016/679 ("GDPR") and the applicable provisions of the Egyptian Personal Data Protection Law No. 151 of 2020 ("PDPL").
2. Roles and Relationship
The parties acknowledge that: (a) the Customer acts as the Data Controller, determining the purposes and means of processing personal data through the Service; and (b) FurnViz acts as the Data Processor, processing personal data solely on behalf of and under the documented instructions of the Controller.
3. Details of Processing
- Subject matter: Provision of the FurnViz cloud-based furniture and interior visualization SaaS platform to the Customer.
- Duration: For the term of the Customer's active Subscription, plus the 90-day post-termination retention period.
- Nature of processing: Collection, storage, organization, structuring, retrieval, rendering, display, transmission, and deletion of personal data as required to deliver the Service.
- Categories of data subjects: Customer's employees, contractors, and authorized platform Users; end-clients of the Customer whose data is uploaded or processed through the Service.
- Types of personal data: Names, business email addresses, phone numbers, job titles, IP addresses, platform usage data, floor plan and architectural data, project notes, and any personal data included in uploaded content by the Customer.
- Special categories: FurnViz does not intentionally process special categories of personal data (as defined in Article 9 GDPR). The Customer warrants that it will not upload such data to the Service.
4. FurnViz's Processor Obligations
FurnViz shall, in its capacity as Processor:
- Process only on instructions: Process personal data only on the documented instructions of the Controller, unless required to do so by applicable law.
- Ensure confidentiality: Ensure that all personnel authorized to process personal data are bound by appropriate confidentiality obligations.
- Implement security measures: Implement the technical and organizational measures described in Section 6 of this DPA, in accordance with Article 32 of the GDPR.
- Sub-processor management: Not engage any new sub-processor without providing the Controller with at least 14 days' prior written notice. FurnViz will impose data protection obligations on sub-processors equivalent to those in this DPA.
- Data subject rights assistance: Assist the Controller in fulfilling its obligations to respond to data subject requests (including access, rectification, erasure, restriction, portability, and objection).
- Deletion or return on termination: Upon termination or expiration of the Agreement, and at the Controller's election, securely delete or return all personal data within 90 days, unless applicable law requires continued retention.
- Audit rights: Make available all information necessary to demonstrate compliance with this DPA. FurnViz may satisfy this obligation by providing a third-party audit report (e.g., SOC 2 Type II or equivalent).
5. Controller's Obligations
The Controller warrants and undertakes to: (a) ensure it has a valid legal basis under applicable law for each processing activity it instructs FurnViz to perform; (b) provide FurnViz with accurate and complete processing instructions; (c) ensure it has provided all required notices and obtained all required consents from data subjects whose personal data is uploaded to the Service.
6. Technical and Organizational Measures (TOMs)
FurnViz implements and maintains the following security measures:
- Encryption at rest: All customer data is encrypted using AES-256.
- Encryption in transit: All data transmitted between clients and FurnViz servers is protected using TLS 1.3. Older protocols are disabled.
- Access controls: Role-based access control (RBAC) with principle of least privilege.
- Multi-factor authentication (MFA): Available for all user accounts and enforced for all FurnViz internal system access.
- Physical security: Data hosted in ISO 27001-certified or equivalent data centers with 24/7 physical security.
- Vulnerability management: Regular internal and third-party penetration tests and vulnerability scans.
- Business continuity: Daily automated backups with geographic redundancy. RPO: less than 24 hours. RTO: less than 4 hours.
7. Authorized Sub-Processors
The Controller authorizes FurnViz to engage the following categories of sub-processors:
- Cloud infrastructure provider (AWS or GCP class): Compute, storage, database, and networking services in SOC 2 Type II certified data centers.
- Content Delivery Network (CDN): Accelerates delivery of static assets and visualization outputs globally.
- Payment processor: Processes subscription payment card transactions under PCI-DSS compliance.
- Transactional email delivery service: Sends system-generated emails such as invoices, account notifications, and security alerts.
An up-to-date list of specific sub-processor entities is available upon request at [email protected]. FurnViz will notify the Controller of any intended changes with at least 14 days' notice.
8. International Data Transfers
Where personal data is transferred from the EEA or Egypt to a country not recognized as providing adequate data protection, FurnViz will ensure such transfers are carried out under appropriate safeguards, including Standard Contractual Clauses (SCCs) as approved by the European Commission for GDPR transfers, or equivalent mechanisms under the Egyptian PDPL.
9. Personal Data Breach Notification
FurnViz shall notify the Controller without undue delay — and in any event within 72 hours — of becoming aware of a personal data breach affecting Customer personal data. Such notification will include: a description of the nature of the breach; contact details of FurnViz's DPO; a description of likely consequences; and a description of measures taken or proposed to address the breach.
10. Governing Law
This DPA shall be governed by the laws of the Arab Republic of Egypt. Where the GDPR applies to the Customer's processing activities, the GDPR provisions incorporated herein shall be interpreted consistently with GDPR requirements.
11. Contact
For all DPA-related inquiries: [email protected] | FurnViz, Giza, Egypt.