Snapshot 18734
Normalized text
Scripts and page chrome removed; this is what change detection compares.
This DATA PROCESSING AGREEMENT (this “DPA“) is entered into between: The customer agreeing to these terms (“Customer“); and ZERO TECHNOLOGIES OY (3451848-1), a private limited company incorporated under the laws of Finland with address at PO Box 1188, FI-00101 Helsinki, Finland (“Supplier“). (1) and (2) hereinafter referred to individually as a “Party“ and collectively as the “Parties“. 1. Background 1.1 The Parties have entered into an agreement regarding the Supplier’s provision of the Service (as specified in the Terms of Service) (the “Main Agreement“). The Service will include processing of Customer’s Data by the Supplier on behalf of the Customer. 1.2 This DPA governs the Customer’s rights and obligations as a controller and the Supplier’s rights and obligations as a processor when the Supplier processes personal data on behalf of the Customer. 1.3 This DPA shall be deemed to form part of the Main Agreement. In the event of inconsistencies between the provisions of the Main Agreement and this DPA, this DPA shall prevail with respect to data protection matters. 2. Definitions 2.1 Unless otherwise stated, terms and expressions in this DPA shall be interpreted in accordance with the EU General Data Protection Regulation (2016/679) (“GDPR”). 2.2 Terms and expressions used in this DPA, but not defined herein, shall be defined in accordance with the Main Agreement. 3. Processing of Personal Data 3.1 The Supplier undertakes to process personal data only in accordance with documented instructions from the Customer and applicable data protection legislation. The Supplier’s obligations regarding the processing activities are set out in Appendix 1. 3.2 The Supplier shall implement appropriate technical and organizational security measures as specified in our Data Security page to protect personal data processed under this DPA. 3.3 The Supplier shall ensure that persons authorized to process personal data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality. 4. Sub-processors and International Transfers 4.1 The Customer authorizes the Supplier to engage sub-processors for the processing of personal data. The current list of sub-processors is available in Appendix 2 of this DPA. 4.2 The Supplier shall inform the Customer of any intended changes concerning the addition or replacement of sub-processors at least 30 days in advance, giving the Customer the opportunity to object to such changes. 4.3 The Supplier shall ensure that its sub-processors are bound by written agreements that impose data protection obligations no less protective than those in this DPA. 4.4 For transfers of personal data outside the EU/EEA, the Supplier shall ensure appropriate safeguards in accordance with GDPR Chapter V, including where applicable: EU Standard Contractual Clauses Adequacy decisions by the European Commission Other legally recognized transfer mechanisms 5. Security and Data Breaches 5.1 The Supplier shall notify the Customer without undue delay after becoming aware of a personal data breach. 5.2 The Supplier shall provide reasonable assistance to the Customer in: Ensuring compliance with security obligations Documenting and notifying personal data breaches Conducting data protection impact assessments Prior consultations with supervisory authorities 6. Audit Rights 6.1 The Customer shall have the right to audit the Supplier’s compliance with this DPA, including by conducting inspections, with reasonable notice. 6.2 The Supplier shall contribute to audits by providing available documentation and reasonable assistance, subject to confidentiality obligations. 7. Term and Termination 7.1 This DPA shall remain in effect as long as the Supplier processes personal data on behalf of the Customer. 7.2 Upon termination of processing services, the Supplier shall, at the Customer’s choice, delete or return all personal data and delete existing copies unless legally required to retain such data. 8. Liability 8.1 Each Party’s liability under this DPA shall be subject to the limitations set forth in the Main Agreement. 9. Governing Law and Jurisdiction 9.1 This DPA shall be governed by the laws of Finland. 9.2 Any disputes shall be resolved in accordance with the dispute resolution provisions of the Main Agreement. Appendix 1: Details of Processing Nature and purpose of processing Processing customer relationship management data as part of providing the Service Analytics and service improvement Technical support and problem resolution Service administration Categories of data subjects Customer’s employees Customer’s clients and prospects Customer’s business partners Types of personal data Basic contact information (names, email addresses, phone numbers) Business relationship data Communication history Other data submitted by the Customer through the Service Duration of processing For the duration of the Main Agreement plus any additional period required by law or as needed to fulfill the purposes specified above Appendix 2: Sub-processors Updated as of June 1st 2026. Sub-processors Sub-processor Purpose for processing Location of processing Google, LLC Hosting Belgium Aiven Oy Database hosting Belgium PostHog, Inc. Product analytics Europe Astrodon Corporation (also known as Loops) Email marketing United States Resend Labs, Inc. Transactional emails from the Zero app. United States Slack Technologies, LLC Customer communications United States & Europe GitHub, Inc. Code Repository United States Cloudinary, Inc. Provision of cloud-based media management services, including secure storage, automated image/video transformation (resizing, cropping, optimization), and global content delivery (CDN) United States Stripe, Inc. Payment processing United States Not Just Tickets Ltd. (trading as Plain) Provision of a B2B customer support platform Europe Vercel, Inc. Provision of cloud hosting and deployment services for web applications, including frontend hosting Global Linear Orbit, Inc. Provision of a software-as-a-service (SaaS) platform for team collaboration, project planning, issue tracking, and product roadmapping. Europe Notion Labs, Inc. Provision of a unified workspace for internal documentation. United States Daytona Platforms Inc (daytona.io) Daytona provides ephemeral cloud sandboxes used by Zero’s AI assistant to execute code and process user-provided chat files for data analysis and file generation. EU AI sub-processors AI sub-processors Sub-processor Purpose for processing Data processed Location of processing Transfer mechanism OpenAI, LLC AI analysis of customer-provided data for organization specific insights Content from emails, calendar events, and other data when AI features are enabled United States & Europe Standard Contractual Clauses Anthropic, PBC AI analysis of customer-provided data for organization-specific insights Content from files attached to Zero, and other data when AI features are enabled United States Standard Contractual Clauses Gemini (Google) AI analysis of customer-provided data for organization-specific insights Content from files attached to Zero, and other data when AI features are enabled United States & Europe Standard Contractual Clauses Cerebras AI analysis of customer-provided data for organization-specific insights Content from files attached to Zero, and other data when AI features are enabled United States Standard Contractual Clauses Changes to this sub-processor list will be notified to Customers in accordance with Section 4.2 of this DPA. Other legal documents Terms of Service Privacy Policy Subscription Terms Data Security