Snapshot 50429
Normalized text
Scripts and page chrome removed; this is what change detection compares.
ZINFI DATA PROCESSING ADDENDUM Exhibit D to the ZINFI License Terms and Conditions | Version 2026.1 | Last updated: July 1, 2026 This Data Processing Addendum, including its Annexes (“DPA”), is incorporated into and forms part of the agreement between ZINFI Technologies, Inc. (“ZINFI”) and the customer entity identified in the applicable Order Form (“Client”) governing Client’s use of the ZINFI Unified Partner Management (UPM) platform and related services (the “Agreement”), to reflect the Parties’ agreement with regard to the Processing of Personal Data. In the event of any conflict between this DPA and the Agreement with respect to the Processing of Client Personal Data, the order of precedence in Section 2.4 applies. By signing the Agreement (including any Order Form), Client enters into this DPA on behalf of itself and, to the extent required under applicable Data Protection Laws, in the name and on behalf of its Authorized Affiliates, if and to the extent ZINFI Processes Personal Data for which such Authorized Affiliates qualify as the Controller. For the purposes of this DPA only, and except where indicated otherwise, the term “Client” includes Client and its Authorized Affiliates. The term of this DPA follows the term of the Agreement, subject to Section 15.1. This DPA takes effect on the date Client signs an Order Form or otherwise accepts the Agreement incorporating this version of the DPA (the “Effective Date”). All capitalized terms not defined herein have the meanings set forth in the Agreement. ZINFI and Client may be individually referred to as a “Party” and collectively as the “Parties”. In the course of providing the Services to Client pursuant to the Agreement, ZINFI may Process Personal Data on behalf of Client, and the Parties agree to comply with the following provisions with respect to such Personal Data, each acting reasonably and in good faith. The Processor terms of this DPA apply solely to the extent that ZINFI is a Processor of Client Personal Data in connection with providing the Services to Client. DEFINITIONS “Affiliate” means any entity that directly or indirectly controls, is controlled by, or is under common control with the subject entity, where “control” means direct or indirect ownership or control of more than 50% of the voting interests of the subject entity. “Authorized Affiliate” means any Client Affiliate that is permitted to use the Services under the Agreement, has not signed its own agreement with ZINFI, and is a Controller of Client Personal Data. “Client Data” has the meaning given in the Agreement. “Client Personal Data” means Personal Data contained in Client Data that ZINFI Processes on behalf of Client under the Agreement. “Controller, Processor, Data Subject and Supervisory Authority” have the meanings given in the GDPR (or the equivalent terms under other applicable Data Protection Laws), and “Business”, “Service Provider”, “Contractor”, “Consumer”, “Sell” and “Share” have the meanings given in the CCPA. “CCPA” means the California Consumer Privacy Act of 2018, as amended by the California Privacy Rights Act of 2020 (Cal. Civ. Code § 1798.100 et seq.), together with its implementing regulations (Cal. Code Regs. tit. 11, § 7000 et seq.), including the regulations effective January 1, 2026. “Data Protection Laws” means all laws and regulations applicable to the Processing of Client Personal Data under the Agreement, including European Data Protection Laws and US State Privacy Laws, in each case as amended, superseded or replaced. “European Data” means Client Personal Data that is subject to European Data Protection Laws. “European Data Protection Laws” means, as applicable: (a) the GDPR; (b) the UK GDPR and the UK Data Protection Act 2018, as amended (including by the Data (Use and Access) Act 2025); (c) the Swiss Federal Act on Data Protection of 25 September 2020 and its ordinances (“FADP”); and (d) Directive 2002/58/EC and its national implementations, and the UK Privacy and Electronic Communications (EC Directive) Regulations 2003. “GDPR” means Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 (General Data Protection Regulation). “Personal Data” means any information relating to an identified or identifiable natural person, and any information defined as “personal data”, “personal information” or an equivalent term under applicable Data Protection Laws. “Personal Data Breach” means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, Client Personal Data transmitted, stored or otherwise Processed by ZINFI or its Sub-processors. Personal Data Breach does not include unsuccessful attempts or activities that do not compromise the security of Client Personal Data, such as pings, port scans, denial-of-service attempts and unsuccessful log-in attempts. “Processing” means any operation or set of operations performed on Personal Data, whether or not by automated means, such as collection, recording, organization, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction. “Process” and “Processed” are construed accordingly. “Restricted Transfer” means a transfer of European Data (a) from the European Economic Area to a country not subject to an adequacy decision of the European Commission; (b) from the United Kingdom to a country not covered by UK adequacy regulations made under the UK GDPR; or (c) from Switzerland to a country not recognized as providing adequate protection under the FADP. “Security Measures” means the technical and organizational measures described in Annex 2. “Services” means the ZINFI UPM subscription services and any professional or support services provided by ZINFI under the Agreement. “Standard Contractual Clauses“ means the standard contractual clauses annexed to European Commission Implementing Decision (EU) 2021/914 of 4 June 2021. “Sub-processor” means any third party, including any ZINFI Affiliate, engaged by ZINFI to Process Client Personal Data. Sub-processors do not include ZINFI employees or individual contractors acting under ZINFI’s direct supervision. “UK Addendum” means the International Data Transfer Addendum to the Standard Contractual Clauses issued by the UK Information Commissioner under section 119A(1) of the Data Protection Act 2018, as amended, superseded or replaced. “US State Privacy Laws” means all US state laws relating to the protection and Processing of Personal Data, including the CCPA and the comprehensive consumer privacy laws of Colorado, Connecticut, Delaware, Indiana, Iowa, Kentucky, Maryland, Minnesota, Montana, Nebraska, New Hampshire, New Jersey, Oregon, Rhode Island, Tennessee, Texas, Utah and Virginia, in each case as amended and as in effect from time to time. SCOPE, ROLES AND ORDER OF PRECEDENCE 2.1 Roles of the Parties. With respect to Client Personal Data, Client acts as a Controller (or as a Processor on behalf of a third-party Controller) and ZINFI acts as a Processor (or, where Client is a Processor, as Client’s sub-processor). For purposes of US State Privacy Laws, Client is a Business or controller and ZINFI is a Service Provider, Contractor or processor, as applicable. 2.2 Processor Only. ZINFI does not act as a Controller of Client Personal Data under this DPA. Personal Data that ZINFI processes for its own account-administration, billing, contracting and business-relationship purposes (for example, the business contact details of Client’s signatories and billing contacts) is not Client Personal Data and is handled in accordance with ZINFI’s Privacy Policy. 2.3 Details of Processing. The subject matter, duration, nature and purpose of the Processing, the types of Client Personal Data and the categories of Data Subjects are described in Annex 1. 2.4 Order of Precedence. With respect to the Processing of Client Personal Data, the following order of precedence applies in the event of conflict: (a) the Standard Contractual Clauses and the UK Addendum, where applicable; (b) this DPA; and (c) the remainder of the Agreement. In all other respects the Agreement governs. 2.5 Client Responsibilities. Client is responsible for (a) the accuracy, quality and legality of Client Personal Data and the means by which Client acquired it; (b) establishing a lawful basis for, and providing all notices and obtaining all consents required for, the Processing described in this DPA, including notice of Client’s use of ZINFI as a Processor; and (c) ensuring that its Instructions comply with Data Protection Laws. 2.6 Restricted Data. The Services are designed to Process business-contact and partner-relationship data. Unless expressly agreed in an Order Form that specifies additional safeguards, Client shall not submit to the Services (a) special categories of Personal Data or Personal Data relating to criminal convictions and offenses (GDPR Articles 9 and 10); (b) “sensitive personal information” or “sensitive data” under US State Privacy Laws; (c) government-issued identification numbers; (d) payment card data or financial-account login credentials (bank and remittance details submitted for incentive payouts are permitted); (e) health information; or (f) Personal Data of children under the age of 16 (together, “Restricted Data”). ZINFI has no liability for Restricted Data submitted in breach of this Section. PROCESSING INSTRUCTIONS 3.1 Documented Instructions. ZINFI shall Process Client Personal Data only on Client’s documented instructions (“Instructions”), including with regard to Restricted Transfers, unless required to do so by applicable law, in which case ZINFI shall inform Client of that legal requirement before Processing unless the law prohibits such notice on important grounds of public interest. 3.2 Complete Instructions. The Agreement (including this DPA), Client’s and its authorized users’ configuration and use of the Services, and any other written instructions of Client that are consistent with the Agreement together constitute Client’s complete Instructions. Instructions outside the scope of the Agreement require prior written agreement of the Parties, including as to any additional fees. 3.3 Unlawful Instructions. ZINFI shall promptly inform Client if, in ZINFI’s opinion, an Instruction infringes Data Protection Laws, or if ZINFI is unable to comply with an Instruction. In either case ZINFI may suspend the affected Processing (other than storage and maintaining the security of the affected Client Personal Data) until Client confirms, modifies or withdraws the Instruction, and ZINFI shall not be liable for any resulting failure to perform the affected Services during the suspension. 3.4 AI Features. Where Client enables artificial-intelligence features of the Services, ZINFI shall Process Client Personal Data through those features solely to provide them to Client. ZINFI shall not use Client Personal Data to train, fine-tune or otherwise improve any artificial-intelligence model, and shall contractually prohibit its artificial-intelligence Sub-processors from doing so. AI features are disabled unless enabled by Client’s administrator. Sub-processors that provide AI functionality are identified on the Sub-processor List, and any new AI Sub-processor is subject to Section 6. Additional terms governing AI features are set out in the ZINFI AI Addendum, which forms part of this DPA. ZINFI PERSONNEL 4.1 Confidentiality. ZINFI shall ensure that all personnel authorized to Process Client Personal Data are subject to written confidentiality obligations (or an appropriate statutory obligation of confidentiality) that survive the end of their engagement, and receive appropriate data protection and security training. 4.2 Access Limitation. ZINFI shall limit access to Client Personal Data to personnel who require access to perform the Services, provide support or comply with law, and shall take commercially reasonable steps to ensure the reliability of such personnel. 4.3 Privacy Contact. ZINFI’s privacy team may be contacted at [email protected]. Where ZINFI is required under Data Protection Laws to appoint a data protection officer or a representative in the European Union or the United Kingdom, ZINFI shall make the relevant contact details available on request. 4.4 Records of Processing. ZINFI shall maintain records of the Processing activities it carries out on behalf of Client, as required by Article 30(2) of the GDPR and equivalent Data Protection Laws. SECURITY 5.1 Security Measures. Taking into account the state of the art, the costs of implementation and the nature, scope, context and purposes of the Processing, as well as the risks to Data Subjects, ZINFI shall implement and maintain appropriate technical and organizational measures to protect Client Personal Data against Personal Data Breaches, including, as appropriate, the measures referred to in GDPR Article 32. Those measures are described in Annex 2. 5.2 Updates. ZINFI may update the Security Measures from time to time, provided that no update materially decreases the overall security of the Services during the Subscription Term. 5.3 Independent Assurance. ZINFI maintains a SOC 2 Type II attestation covering the Services, performed by an independent auditor. ZINFI’s hosting and infrastructure Sub-processors maintain their own certifications and attestations (which may include SOC 2 Type II and ISO/IEC 27001), as identified on the Sub-processor List. Those certifications are held by the relevant Sub-processors and not by ZINFI. 5.4 Client Security Responsibilities. Client is responsible for its secure use of the Services, including configuring user access and roles, protecting account credentials, enabling available security features such as single sign-on and multi-factor authentication, and securing Client Personal Data in transit from Client-controlled systems to the Services. SUB-PROCESSORS 6.1 General Authorization. Client grants ZINFI general written authorization to engage Sub-processors, including the Sub-processors listed at https://www.zinfi.com/list-of-sub-processors/ (the “Sub-processor List”) as of the Effective Date, subject to this Section 6. 6.2 Sub-processor Obligations. Before a Sub-processor Processes Client Personal Data, ZINFI shall enter into a written agreement with it imposing data protection obligations no less protective of Client Personal Data than those in this DPA, providing in particular sufficient guarantees to implement appropriate technical and organizational measures, as required by GDPR Article 28(4). 6.3 Notice of New Sub-processors. ZINFI shall notify Client at least thirty (30) days before authorizing any new Sub-processor to Process Client Personal Data, by email to the privacy contact Client designates (or, if none, Client’s administrative contact) and by updating the Sub-processor List. Client may designate or update its privacy contact by emailing [email protected]. 6.4 Right to Object. Client may object to a new Sub-processor on reasonable grounds relating to data protection by written notice to ZINFI within thirty (30) days after receiving ZINFI’s notice. If Client does not object within that period, the new Sub-processor shall be deemed authorized. If Client objects, the Parties shall discuss the objection in good faith, and ZINFI shall use reasonable efforts to offer a change in the Services or in Client’s configuration that avoids Processing by the objected-to Sub-processor. If ZINFI does not resolve the objection or offer a reasonable alternative within thirty (30) days after receiving Client’s objection and proceeds with the Sub-processor, Client may terminate the affected Services by written notice, and ZINFI shall refund any prepaid fees covering the remainder of the Subscription Term for the terminated Services. Such termination and refund are Client’s sole remedy for an objection under this Section. 6.5 Emergency Replacement. Where ZINFI must replace a Sub-processor urgently for reasons of security, legal compliance or service continuity outside ZINFI’s reasonable control, ZINFI shall notify Client as soon as reasonably practicable, and Client’s objection right under Section 6.4 shall apply from the date of that notice. 6.6 Copies of Sub-processor Terms. On Client’s written request, ZINFI shall provide the data protection terms of its agreements with Sub-processors, which ZINFI may redact to remove commercial information or clauses unrelated to data protection, including for purposes of Clause 9(c) of the Standard Contractual Clauses. 6.7 Liability. ZINFI remains responsible for the acts and omissions of its Sub-processors to the same extent ZINFI would be responsible if it performed the services of each Sub-processor directly under this DPA. PERSONAL DATA BREACH 7.1 Notification. ZINFI shall notify Client without undue delay, and in any event within forty-eight (48) hours, after becoming aware of a Personal Data Breach. 7.2 Content. ZINFI’s notice shall describe, to the extent then known: (a) the nature of the Personal Data Breach, including the categories and approximate number of Data Subjects and records concerned; (b) the likely consequences; (c) the measures taken or proposed to address the Personal Data Breach and mitigate its effects; and (d) a point of contact from whom more information can be obtained. Where information is not available at the time of notice, ZINFI shall provide it in phases as it becomes available. 7.3 Response and Cooperation. ZINFI shall promptly take reasonable steps to contain, investigate and remediate the Personal Data Breach to the extent within ZINFI’s reasonable control, and shall provide reasonable assistance to enable Client to meet its obligations to notify Supervisory Authorities, regulators and affected Data Subjects. Client shall bear the costs of any notifications to Supervisory Authorities, regulators and Data Subjects, except that ZINFI shall bear the reasonable, documented costs of notifications required by Data Protection Laws where the Personal Data Breach resulted from ZINFI’s breach of this DPA, subject to Section 14.3. 7.4 Third-Party Notices. Unless required by law, ZINFI shall not notify any Supervisory Authority, regulator or Data Subject of a Personal Data Breach affecting Client Personal Data without Client’s prior written approval, other than to identify Client where required. 7.5 No Admission. ZINFI’s notification of or response to a Personal Data Breach is not an acknowledgment of fault or liability. This Section 7 does not apply to incidents caused by Client, its authorized users or Client-controlled systems. ASSISTANCE 8.1 Data Subject Requests. If ZINFI receives a request from a Data Subject to exercise rights under Data Protection Laws in relation to Client Personal Data (a “Data Subject Request”), ZINFI shall, to the extent legally permitted, promptly forward it to Client and shall not respond to it other than to direct the Data Subject to Client. Taking into account the nature of the Processing, ZINFI shall assist Client by appropriate technical and organizational measures, insofar as possible, including the self-service functionality of the Services, to fulfill Client’s obligations to respond to Data Subject Requests. Where Client cannot address a Data Subject Request through the Services, ZINFI shall provide commercially reasonable additional assistance on Client’s written request. 8.2 Impact Assessments and Consultations. Taking into account the nature of the Processing and the information available to ZINFI, ZINFI shall provide reasonable assistance to Client with (a) data protection impact assessments and prior consultations with Supervisory Authorities under GDPR Articles 35 and 36 (and their UK and Swiss equivalents); and (b) risk assessments, cybersecurity audits and automated decision-making technology obligations under the CCPA regulations and equivalent assessment requirements under other US State Privacy Laws, in each case to the extent the required information is not otherwise available to Client. 8.3 Costs. Assistance under this Section 8 that is available through the self-service functionality of the Services is provided at no additional charge. Other assistance shall be charged at ZINFI’s then-current professional services rates, to the extent permitted by Data Protection Laws. DEMONSTRATION OF COMPLIANCE AND AUDITS 9.1 Information. ZINFI shall make available to Client all information reasonably necessary to demonstrate ZINFI’s compliance with GDPR Article 28 and this DPA. 9.2 Reports and Questionnaires. On Client’s written request, not more than once in any twelve (12)-month period, ZINFI shall provide (a) a copy of its most recent SOC 2 Type II report; and (b) written responses to a reasonable, industry-standard information security questionnaire. Such materials are ZINFI’s Confidential Information. 9.3 Audits and Inspections. To the extent the information provided under Sections 9.1 and 9.2 does not address a matter reasonably necessary to demonstrate ZINFI’s compliance with this DPA, where required by a Supervisory Authority, or following a Personal Data Breach affecting Client Personal Data, Client (or an independent auditor appointed by Client that is not a ZINFI competitor and is bound by written confidentiality obligations) may audit ZINFI’s compliance with this DPA, including through inspections. Audits shall (a) take place not more than once in any twelve (12)-month period, except where required by a Supervisory Authority or following a Personal Data Breach affecting Client Personal Data; (b) be requested on at least thirty (30) days’ written notice and conducted under a mutually agreed written scope, timing and duration; (c) not include any matter covered by ZINFI’s then-current SOC 2 Type II report, unless that report identifies a non-conformity relating to that matter; (d) be conducted during normal business hours and in a manner that minimizes disruption to ZINFI’s operations; and (e) not extend to data of other ZINFI customers or to facilities of Sub-processors, whose compliance ZINFI shall evidence through their own reports. Client shall bear all costs of any audit, including time spent by ZINFI personnel at ZINFI’s then-current professional services rates. Client shall provide ZINFI with a copy of any audit report, which shall be ZINFI’s Confidential Information. 9.4 Standard Contractual Clauses. The Parties agree that the audits described in Clauses 8.9(c) and (d) of the Standard Contractual Clauses shall be carried out in accordance with this Section 9. RETURN AND DELETION 10.1 Export During the Term. During the Subscription Term, Client may export Client Data, including Client Personal Data, using the export functionality of the Services. 10.2 Return and Deletion on Termination. On termination or expiration of the Agreement, ZINFI shall, at Client’s choice, make Client Personal Data available for export for thirty (30) days and thereafter delete it, and shall complete deletion from production systems within ninety (90) days after the end of that export period, unless applicable law requires further retention. 10.3 Backups and Retained Data. Client Personal Data held in backup systems shall be deleted in accordance with ZINFI’s standard backup rotation, not exceeding twelve (12) months. Any Client Personal Data that ZINFI retains under this Section 10 shall remain subject to this DPA, be isolated and protected from further Processing except as required by law, and be deleted when retention is no longer required. 10.4 Certification. On Client’s written request, ZINFI shall certify in writing that deletion under this Section 10 has been completed. 10.5 Switching. Where Regulation (EU) 2023/2854 (the EU Data Act) applies to the Services, the switching and data-export terms of the Agreement shall apply and this Section 10 shall be read consistently with them. INTERNATIONAL DATA TRANSFERS 11.1 Processing Locations. Client acknowledges that ZINFI and its Sub-processors may Process Client Personal Data in the United States and in the other countries identified on the Sub-processor List. ZINFI shall ensure that all Restricted Transfers comply with European Data Protection Laws. Client Personal Data is hosted in the region(s) identified on the Sub-processor List or, where applicable, in the Order Form. 11.2 EU Standard Contractual Clauses. Each Restricted Transfer of European Data subject to the GDPR from Client to ZINFI is governed by the Standard Contractual Clauses, which are incorporated into this DPA by reference and completed as follows: (a) Module Two (Controller to Processor) applies where Client is a Controller, and Module Three (Processor to Processor) applies where Client is a Processor; (b) the optional docking clause in Clause 7 applies; (c) in Clause 9, Option 2 (general written authorization) applies, and the time period for prior notice of Sub-processor changes is set out in Section 6.3; (d) in Clause 11, the optional language does not apply; (e) in Clause 13, the competent Supervisory Authority is determined in accordance with Annex 1, Part C; (f) in Clause 17, Option 1 applies and the Standard Contractual Clauses are governed by the laws of Ireland; (g) in Clause 18(b), disputes shall be resolved before the courts of Ireland; and (h) Annexes I, II and III of the Standard Contractual Clauses are completed by Annexes 1, 2 and 3 of this DPA respectively. 11.3 United Kingdom. Each Restricted Transfer of European Data subject to the UK GDPR is governed by the Standard Contractual Clauses as completed in Section 11.2 and amended by the UK Addendum, which is incorporated by reference. Tables 1 to 3 of the UK Addendum are completed with the information in Section 11.2 and Annexes 1 to 3 of this DPA, and in Table 4 neither Party may end the UK Addendum under its Section 19. If the UK Information Commissioner issues a revised or replacement addendum, or if another transfer mechanism approved under the UK GDPR becomes available for the transfer, the Parties shall rely on it to the extent required. 11.4 Switzerland. Each Restricted Transfer of European Data subject to the FADP is governed by the Standard Contractual Clauses as completed in Section 11.2, with the following modifications: (a) references to the GDPR are to be read as references to the FADP to the extent the transfer is subject to the FADP; (b) the Swiss Federal Data Protection and Information Commissioner is the competent Supervisory Authority for such transfers; and (c) the term “Member State” in Clause 18(c) shall not be interpreted so as to exclude Data Subjects in Switzerland from bringing claims in their place of habitual residence. 11.5 Onward Transfers. ZINFI shall ensure that any onward Restricted Transfer of Client Personal Data to a Sub-processor is protected by the Standard Contractual Clauses (Module Three), the UK Addendum or another transfer mechanism recognized under European Data Protection Laws. 11.6 Transfer Impact. ZINFI warrants that, as of the Effective Date, it has no reason to believe that the laws and practices applicable to its Processing of Client Personal Data in any destination country, including requirements to disclose Personal Data to public authorities, prevent it from fulfilling its obligations under this DPA or the Standard Contractual Clauses. ZINFI shall provide reasonable information to support Client’s transfer impact or transfer risk assessments. If ZINFI reasonably believes such laws or practices prevent it from fulfilling those obligations, ZINFI shall promptly notify Client, and the Parties shall identify appropriate supplementary measures. If no such measures can be implemented, Client may suspend the affected transfer and terminate the affected Services on written notice. Such termination is Client’s sole remedy and does not entitle Client to any refund of fees. 11.7 Government Access Requests. If ZINFI receives a legally binding request from a public authority for access to Client Personal Data, ZINFI shall, unless legally prohibited: (a) attempt to redirect the authority to request the data directly from Client; (b) promptly notify Client and provide a copy of the request; (c) review the legality of the request and challenge it where, after careful assessment, ZINFI concludes there are reasonable grounds to consider it unlawful; (d) disclose only the minimum Client Personal Data required to comply; and (e) document its assessment and response. ZINFI has not intentionally created back doors or similar mechanisms that could be used to access Client Personal Data. 11.8 Alternative Transfer Mechanisms. If a Restricted Transfer becomes covered by an adequacy decision or other transfer mechanism recognized under European Data Protection Laws, or if the Standard Contractual Clauses or UK Addendum are replaced, ZINFI may, on written notice to Client, rely on that mechanism, and Client shall take reasonable steps (including executing documents) to give effect to it. US STATE PRIVACY LAWS 12.1 Scope and Role. This Section 12 applies to Client Personal Data that is subject to US State Privacy Laws. ZINFI acts as Client’s Service Provider or Contractor under the CCPA and as Client’s processor under other US State Privacy Laws. 12.2 Business Purposes. ZINFI shall Process Client Personal Data only for the following limited and specified business purposes (the “Business Purposes”): (a) providing, maintaining, securing and supporting the Services in accordance with the Agreement; (b) performing professional services requested by Client; (c) detecting security incidents and protecting against malicious, deceptive, fraudulent or illegal activity; (d) debugging to identify and repair errors that impair intended functionality; (e) complying with applicable law; and (f) the internal uses permitted to service providers under Cal. Code Regs. tit. 11, § 7050(a), including building and improving the quality of the Services (excluding any use restricted by Section 3.4), provided that ZINFI does not use Client Personal Data to build or modify household or consumer profiles for use in providing services to another business, or to correct or augment data acquired from another source. 12.3 Prohibitions. ZINFI shall not: (a) Sell or Share Client Personal Data; (b) retain, use or disclose Client Personal Data for any purpose, including any commercial purpose, other than the Business Purposes, or outside the direct business relationship between ZINFI and Client; (c) combine Client Personal Data with Personal Data it receives from or on behalf of another person or collects from its own interactions with Consumers, except as permitted by US State Privacy Laws; or (d) use Client Personal Data for cross-context behavioral advertising or targeted advertising. 12.4 Compliance and Notice. ZINFI shall comply with the obligations applicable to it under US State Privacy Laws and provide the same level of privacy protection they require. ZINFI shall notify Client within five (5) business days if it determines that it can no longer meet those obligations. Upon such notice, or upon Client’s reasonable belief of unauthorized use, Client may take reasonable and appropriate steps to stop and remediate unauthorized use of Client Personal Data, including suspending the affected Processing. 12.5 Monitoring. Client may take reasonable and appropriate steps to ensure that ZINFI uses Client Personal Data in a manner consistent with Client’s obligations under US State Privacy Laws, including through the measures described in Section 9. 12.6 Subcontracting. ZINFI shall engage Sub-processors only under a written contract binding them to obligations consistent with this Section 12, and subject to Section 6. 12.7 Consumer Requests. ZINFI shall assist Client with Consumer requests in accordance with Section 8.1, and shall comply with Client’s instructions to delete or correct Client Personal Data in response to such requests. 12.8 Other State Requirements. The Parties intend Sections 3 (Instructions), 4 (Personnel confidentiality), 6 (Sub-processors), 8 (Assistance), 9 (Demonstration of Compliance) and 10 (Return and Deletion) to satisfy the processor contract requirements of US State Privacy Laws, and those Sections shall be construed accordingly. 12.9 Certification; No Sale. ZINFI certifies that it understands and will comply with the restrictions in this Section 12. The Parties agree that Client’s disclosure of Client Personal Data to ZINFI does not form part of any monetary or other valuable consideration exchanged between them. AUTHORIZED AFFILIATES 13.1 Contractual Relationship. By executing the Agreement, Client enters into this DPA (including, where applicable, the Standard Contractual Clauses) on behalf of itself and, as applicable, in the name and on behalf of its Authorized Affiliates, establishing a separate DPA between ZINFI and each Authorized Affiliate. Client represents that it is authorized to do so. An Authorized Affiliate is a party only to this DPA and not to the Agreement. 13.2 Communications and Remedies. The Client entity that is party to the Agreement shall coordinate all Instructions and communications with ZINFI under this DPA on behalf of its Authorized Affiliates and, except where Data Protection Laws require an Authorized Affiliate to act directly, shall exercise any right or remedy of an Authorized Affiliate under this DPA on a combined basis for itself and all of its Authorized Affiliates. 13.3 Combined Audits. Client shall combine, to the extent reasonably possible, audit requests made on behalf of itself and its Authorized Affiliates into a single audit under Section 9. LIABILITY 14.1 Limitation. Subject to Section 14.3, each Party’s liability, taken together with that of its Affiliates, arising out of or relating to this DPA and all DPAs with Authorized Affiliates is subject to the limitations of liability in the Agreement, which apply in the aggregate to all claims under the Agreement and all such DPAs and not severally to each Authorized Affiliate. 14.2 Exceptions. Nothing in this DPA or the Agreement limits either Party’s liability to Data Subjects under Clause 12 of the Standard Contractual Clauses, or any liability that cannot be limited under Data Protection Laws. As between ZINFI and Client (including its Authorized Affiliates), all liability arising out of or relating to this DPA, including under the Standard Contractual Clauses and the UK Addendum, is subject to the limitations and exclusions of liability in the Agreement and this Section 14. 14.3 Data Protection Cap. Notwithstanding the limitations of liability in the Agreement, each Party’s aggregate liability arising out of or relating to a breach of this DPA or a Personal Data Breach (“Data Protection Claims”) shall not exceed an amount equal to the fees paid or payable by Client under the Agreement in the twelve (12) months preceding the event giving rise to the claim (the “Data Protection Cap”). The Data Protection Cap is separate from, and in addition to, the general limitation of liability in the Agreement, and amounts paid under one shall not reduce the other. Reasonable, documented costs of notifications required by Data Protection Laws and of remediating a Personal Data Breach shall be treated as direct damages recoverable within the Data Protection Cap. The exclusion of indirect and consequential damages in the Agreement continues to apply to Data Protection Claims. GENERAL 15.1 Term. This DPA remains in effect for as long as ZINFI Processes Client Personal Data, and survives termination of the Agreement until all Client Personal Data has been returned or deleted in accordance with Section 10. 15.2 Amendments. This DPA may be amended only in writing signed by both Parties, except that ZINFI may update this DPA on at least thirty (30) days’ written notice solely to adopt replacement Standard Contractual Clauses or a replacement UK Addendum, or to the extent required by Data Protection Laws or a binding decision of a Supervisory Authority or court, provided that any such update does not materially reduce the protection afforded to Client Personal Data. 15.3 Severability. If any provision of this DPA is held invalid or unenforceable, the remaining provisions remain in full force and effect, and the affected provision shall be amended to the minimum extent necessary to make it valid and enforceable in a manner consistent with Data Protection Laws. 15.4 Governing Law. This DPA is governed by the law governing the Agreement, except that the Standard Contractual Clauses and UK Addendum are governed by the laws specified in Section 11, and except where Data Protection Laws require otherwise. 15.5 Notices. Notices under this DPA shall be given in accordance with the Agreement. Operational privacy notices (including Sub-processor notices and Data Subject Request referrals) may be sent by email to Client’s designated privacy contact and, for ZINFI, to [email protected]. Legal notices to ZINFI shall be copied to [email protected]. 15.6 Execution. This DPA does not require a separate signature. Execution of an Order Form referencing the Agreement, or other acceptance of the Agreement, constitutes execution of this DPA and, where applicable, the Standard Contractual Clauses and UK Addendum. Where Client requires a countersigned copy of this DPA, ZINFI will provide one on request, which may be executed in counterparts and by electronic signature. ANNEX 1: DETAILS OF THE PROCESSING A. List of Parties Data exporter: Client, as identified in the Order Form, and its Authorized Affiliates. Address and contact person: as set out in the Order Form. Activities relevant to the transfer: use of the ZINFI UPM Services under the Agreement. Role: Controller, or Processor on behalf of a third-party Controller. Signature and date: by execution of the Order Form. Data importer: ZINFI Technologies, Inc., 6200 Stoneridge Mall Road, Suite 300, Pleasanton, California 94588, USA. Contact: ZINFI Privacy Team, [email protected]. Activities relevant to the transfer: provision of the Services under the Agreement. Role: Processor. Signature and date: by execution of the Order Form. B. Description of the Processing and Transfer Categories of Data Subjects. As determined by Client in its use of the Services, which may include: employees, contractors and contacts of Client’s channel partners, resellers, distributors, agencies, system integrators, affiliates and alliance partners; Client’s employees, contractors and other individuals authorized by Client to use the Services; contacts at Client’s prospects and customers submitted through the Services (for example, through deal registration and lead distribution); and contacts at Client’s vendors and service providers. Categories of Personal Data. As determined by Client in its use of the Services, which may include: identification and business contact data: name, job title, employer, business email address, telephone number and business address; partner program data: program enrollment, tier, certifications, training and learning records, agreements and onboarding records; commercial activity data: deal registrations, leads, opportunities, marketing development fund and co-op claims, rebate and incentive records, and payout and remittance details where Client enables incentive payout functionality; account and usage data: user identifiers, roles, authentication data, IP address, device and browser information, log data and in-portal activity; content and communications: messages, uploaded files and other content submitted to the Services; and inputs to, and outputs of, AI features enabled by Client. Sensitive data. None intended. Restricted Data is excluded under Section 2.6 unless expressly agreed in an Order Form, in which case the Order Form shall describe the data and any restrictions and additional safeguards that apply. Frequency of transfer. Continuous for the duration of the Agreement, as determined by Client’s use of the Services. Nature of the Processing. Hosting, storage, organization, structuring, retrieval, analysis, transmission, display, backup, deletion and other Processing necessary to provide, secure and support the Services and any professional services requested by Client. Purpose of the Processing. Provision of the Services in accordance with the Agreement, including the Business Purposes set out in Section 12.2. Retention. For the Subscription Term and thereafter as set out in Section 10. Transfers to Sub-processors. Sub-processors Process Client Personal Data for the subject matter, nature and duration described in this Annex 1 and on the Sub-processor List, to the extent necessary for the services each Sub-processor provides to ZINFI. C. Competent Supervisory Authority For EU transfers: (a) where the data exporter is established in an EU Member State, the Supervisory Authority of that Member State; (b) where the data exporter is not established in the EU but has appointed a representative under GDPR Article 27(1), the Supervisory Authority of the Member State in which the representative is established; and (c) where the data exporter is not established in the EU and is not required to appoint a representative, the Irish Data Protection Commission. For UK transfers: the UK Information Commissioner’s Office. For Swiss transfers: the Swiss Federal Data Protection and Information Commissioner. ANNEX 2: TECHNICAL AND ORGANIZATIONAL SECURITY MEASURES ZINFI maintains an information security program designed to protect the confidentiality, integrity and availability of Client Personal Data, independently assessed through ZINFI’s SOC 2 Type II attestation. The measures below describe that program at a level appropriate for Annex II of the Standard Contractual Clauses. 1. Governance and Risk Management Documented information security policies, reviewed at least annually and approved by management. Designated security leadership with responsibility for the security program, and periodic risk assessments of systems Processing Client Personal Data. Security and privacy awareness training for personnel at onboarding and at least annually, and background checks where permitted by law. 2. Encryption and Pseudonymization Encryption of Client Personal Data in transit over public networks using TLS 1.2 or higher. Encryption of Client Personal Data at rest using AES-256 or an equivalent industry-standard algorithm. Managed cryptographic key storage with restricted access, and pseudonymization or masking of data in non-production environments where feasible. 3. Identity and Access Management Role-based access control within the Services, enabling Client to configure roles, permissions and partner-level visibility. Single sign-on (including SAML and OAuth) and multi-factor authentication available to Client users; multi-factor authentication required for ZINFI personnel accessing production systems. Least-privilege access for ZINFI personnel, formal provisioning and de-provisioning, periodic access reviews, and revocation of access to production systems within twenty-four (24) hours after termination of employment or engagement. Password requirements aligned with NIST SP 800-63B, including minimum length and screening against known-compromised passwords, without mandatory periodic rotation absent evidence of compromise. 4. Logical Separation Logical separation of each client’s data within the multi-tenant Services, enforced at the application and database layers. Separate development, test and production environments; production Client Personal Data is not used for development or testing without appropriate safeguards. 5. Secure Development and Vulnerability Management Secure software development practices, including code review, change management and approval before deployment to production. Regular vulnerability scanning, with critical and high-severity vulnerabilities remediated within documented timeframes. Penetration testing of the Services by an independent third party at least annually; an executive summary of the most recent test is available to Client annually on request. 6. Logging, Monitoring and Incident Response Logging of administrative actions, authentication events and access to production systems, with logs protected against tampering and retained for at least twelve (12) months. Monitoring and alerting for anomalous activity, and endpoint and network protection controls. A documented incident response plan, tested at least annually, supporting the notification obligations in Section 7 of this DPA. 7. Availability, Backup and Resilience Hosting on infrastructure designed for high availability and redundancy, supporting ZINFI’s 99.9% monthly uptime commitment under the Agreement. Daily encrypted backups stored in a separate location, with periodic restoration testing. A business continuity and disaster recovery plan, tested at least annually, which defines recovery point and recovery time objectives for the Services. 8. Physical Security The Services are hosted in data centers operated by ZINFI’s infrastructure Sub-processors, which maintain physical and environmental controls (including access control, surveillance and environmental protections) independently attested under their own SOC 2 Type II and ISO/IEC 27001 programs. ZINFI does not operate its own data centers. ZINFI offices apply badge-controlled access and visitor management. 9. Data Minimization, Retention and Deletion Processing limited to what is necessary to provide the Services; export, retention and deletion handled as described in Section 10 of this DPA. Secure deletion or destruction of media in accordance with industry standards. 10. Sub-processor Management Security and privacy due diligence before engaging a Sub-processor, written data protection terms consistent with Section 6 of this DPA, and periodic review of Sub-processor attestations. 11. Assistance to Client Self-service tools within the Services to access, correct, export and delete Client Personal Data, supporting Client’s responses to Data Subject Requests under Section 8 of this DPA. ANNEX 3: SUB-PROCESSORS Client authorizes the Sub-processors identified on the Sub-processor List at https://www.zinfi.com/list-of-sub-processors/, as updated in accordance with Section 6. The Sub-processor List identifies, for each Sub-processor, its name, the services it provides, its Processing locations and its independent certifications or attestations. The Sub-processor List, as so updated, constitutes Annex III of the Standard Contractual Clauses. Certifications and attestations shown on the Sub-processor List are held by the relevant Sub-processor. ZINFI’s own independent assurance is its SOC 2 Type II attestation, as described in Section 5.3. Questions about this DPA or ZINFI’s privacy practices may be directed to [email protected]. ZINFI’s Privacy Policy is available at https://www.zinfi.com/upm-privacy-policy/. ★★★★★ Rated 97/100 on G2 | A Leader in Customer Satisfaction Ready to Scale Your Partner Ecosystem? Join Fortune 100 companies and global enterprises using ZINFI to drive channel success and accelerate revenue Product Videos Demo Request Recent Posts Useful Links Site Search