Master Service Terms, Platform Governance & Incorporated Data Processing Addendum (DPA)
Domain / Service: Rizlytics.com
Effective Date: September 27, 2026
Entity Name: Rizlytics LLC
Applicable Laws: GDPR, CCPA/CPRA, BIPA, HIPAA, PECA
Part I: Terms of Service
1. Acceptance & Scope of Services
1.1 Binding Agreement: These Terms of Service (“Terms”) govern access to and use of Rizlytics.com, including its platform, cloud infrastructure, AI models, datasets, APIs, and operational services (“Services”), provided by Rizlytics LLC (“Company”). By accessing the platform, creating an account, or purchasing dataset services, Customer agrees to be bound by these Terms and the incorporated Data Processing Addendum (DPA).
1.2 Scope of Platform Services: Services include access to multimodal AI dataset collection pipelines, 4K/HD video footage, ambient audio, 200Hz IMU sensor streams, facial keypoints, skeletal tracking meshes, JSON sidecars, annotation tools, and algorithmic evaluation platforms.
2. Intellectual Property & Proprietary Data
2.1 Company Ownership: All software, algorithms, spatial keypoints, video footage, telemetry logs, neural network weights, data annotations, and AI model artifacts provided via Rizlytics.com remain the sole intellectual property of Rizlytics.
2.2 Enterprise Usage License: Customer is granted a non-exclusive, non-transferable license to access and process licensed Data solely for AI model training, fine-tuning, and evaluation, in accordance with the Permitted Use terms of the applicable order. This license is irrevocable with respect to Data already delivered to Customer, provided Customer remains in compliance with this Agreement. Rizlytics reserves the right to decline to deliver additional Data, decline to renew a subscription, or discontinue a relationship with Customer, without affecting Customer’s rights to Data already delivered as of the date of any such decision.
3. Account Security & Acceptable Use
3.1 System Security & Restrictions: Customer shall maintain the security of API credentials and account passwords. Customer shall not attempt to reverse engineer platform infrastructure, extract un-anonymized raw dataset files outside authorized endpoints, or use platform outputs for unlawful surveillance or biometric profiling outside consented frameworks.
4. Governing Law & Dispute Resolution
4.1 Governing Law: This Agreement shall be governed by and construed in accordance with the laws of the State of New York, United States of America, without regard to its conflict-of-laws principles, without prejudice to any mandatory data protection or biometric privacy obligations imposed by GDPR, CCPA/CPRA, BIPA, HIPAA, or PECA that apply based on the location of data subjects, Customer, or Rizlytics’s operations.
4.2 Dispute Resolution: Any dispute arising out of or relating to this Agreement shall be resolved through the exclusive jurisdiction of the state and federal courts located in New York County, New York, and each party consents to personal jurisdiction and venue therein.
Part II: Data Processing Addendum (DPA)
5. Purpose, Roles & Processing Instructions
5.1 Scope & Designation of Roles: This Data Processing Addendum (“DPA”) forms an integral part of the Rizlytics.com Terms of Service. To the extent Customer processes personal data, biometric identifiers, or spatial telemetry via Rizlytics.com, Customer acts as the Data Controller (or Processor) and Rizlytics acts as the Data Processor (or Subprocessor).
5.2 Processing Compliance: Rizlytics shall process personal data solely in accordance with Customer’s documented instructions, these Terms, and applicable data protection regulations (including EU GDPR, UK GDPR, CCPA/CPRA, BIPA, HIPAA, and PECA).
6. Biometric Data & Sensory Telemetry Processing
6.1 Data Modalities Handled: The scope of processing includes multimodal data capture and vectorization: 4K/HD video streams, audio recordings, 200Hz IMU telemetry, facial geometry keypoints, skeletal tracking vectors, gaze coordinates, and JSON metadata sidecars.
6.2 Biometric & Spatial Governance: In compliance with BIPA, GDPR, and global biometric laws, all biometric data extracted for AI training is processed strictly under verified subject consent frameworks. Data is encrypted in transit and at rest.
7. Cross-Border Transfers & Subprocessors
7.1 Cross-Border Transfer Mechanisms: Customer acknowledges and consents that personal data and dataset telemetry may be transferred, stored, and processed across operational centers in Pakistan, cloud infrastructure (AWS/GCP) in the United States, and enterprise client environments across the European Union, United Kingdom, and globally.
7.2 Safeguards & Technical Measures: Company shall maintain industry-standard security measures, including Standard Contractual Clauses (SCCs), dynamic facial blurring, and PHI stripping for third parties captured incidentally in field datasets.
8. Incident Notification & Data Subject Rights
8.1 Security Incidents & Rights Assistance: Rizlytics shall notify Customer without undue delay upon becoming aware of a confirmed personal data breach affecting Customer data. Company shall provide reasonable assistance to fulfill data subject deletion or access requests in accordance with statutory retention policies for validated AI model training sets.
9. Customer Indemnification Obligations
9.1 Indemnification: Customer shall defend, indemnify, and hold harmless Rizlytics, its parent companies, subsidiaries, affiliates, and their respective officers, directors, employees, agents, and successors (“Rizlytics Indemnitees”) from and against any and all claims, demands, actions, proceedings, liabilities, losses, damages, judgments, costs, and expenses (including, without limitation, reasonable attorneys’ fees, expert witness fees, and legal litigation costs) asserted against or incurred by any Rizlytics Indemnitee, arising out of or related to any third-party claim, suit, or demand resulting from:
- (a) Customer’s breach of any representations, warranties, or covenants under this Agreement, including the Permitted Use restrictions in Section 2.2;
- (b) product liability or personal injury claims associated with Customer’s downstream use or deployment of Rizlytics datasets, software, or sensor feeds; or
- (c) Customer’s violation of applicable global privacy, biometric, or data protection laws.