Skip to content
Ezra

Last updated: August 2026

Data processing

This page describes current practice in plain language. It is a statement of how Ezra operates, not legal advice to you. Where a signed agreement exists between Ezra and an agency, that agreement controls.

Purpose

This page summarises the data processing terms offered to pilot agencies. A signed agreement is provided before any client data is connected, and that signed agreement controls.

Roles

The agency is the controller, or business, for the client data it connects. Ezra acts as the processor, or service provider, and handles that data only on documented instructions from the agency.

Ezra does not retain, use, or disclose agency or client data for any purpose other than performing the services, and does not combine it with data from other sources except as permitted by the agreement.

Processing scope

Processing covers advertising performance data, agency messages directed at Ezra, workspace identity of the requester, and recorded decisions and approvals.

Data subjects are agency personnel and the named client contacts appearing in connected accounts. Processing lasts for the pilot term and any agreed wind down period.

Security and confidentiality

Data is encrypted in transit and at rest, access is scoped per agency workspace, administrative access is logged and reviewed, and personnel with access are bound by written confidentiality obligations that survive the engagement.

Ezra maintains technical and organisational measures appropriate to the risk, including least privilege access, secret management, dependency review, and audit logging of privileged actions.

Subprocessors

Subprocessors are listed on the subprocessors page. Agencies are notified before a new subprocessor is engaged and may object on reasonable data protection grounds, in which case the parties work in good faith toward an alternative.

Each subprocessor is bound by written terms no less protective than these.

Assistance, audit, and incidents

Ezra assists the agency with data subject requests, data protection impact assessments, and regulator enquiries, and makes available the information reasonably needed to demonstrate compliance.

Ezra notifies the agency without undue delay, and within seventy two hours of confirming a personal data breach affecting agency data, with the facts known at the time and the steps being taken.

International transfers

Processing takes place in the United States. Where data originates in the United Kingdom or the European Economic Area, transfers rely on the applicable standard contractual clauses and the United Kingdom addendum, together with supplementary measures where needed.

Return and deletion

On written request, or at the end of the pilot, Ezra returns or deletes agency and client data within thirty days, except where retention is required by law. Backup copies expire on their normal cycle.

Contact

Ezra is operated from the State of Michigan, United States. Postal address available on request. Written notices reach us at the address below and are answered in writing.

support@ezra.work

Full contact routes