Data Processing Addendum

Enterprise data processing terms for accountable AI workflows. Review how ZoikoVertex structures customer data processing, subprocessors, security commitments, international transfer support, deletion and return, audit assistance, and privacy-rights cooperation for enterprise deployments.

DOCUMENTZV-DPA-001
VERSIONv1.0 • [TBC — legal review]
EFFECTIVE[Date — TBC by legal]
ENTITYZoiko Tech Inc. • Zoiko Group

Pre-publication notice for legal and product review. This DPA page reflects intended contractual positions and must be reviewed by counsel for all target jurisdictions before publication. Processing categories, subprocessors, transfer mechanisms, retention periods, and security commitments must reflect implemented practices. No legally binding obligation arises from this public page alone — the executed customer agreement and DPA govern.

DPA AT A GLANCE

Plain English, first.

Six things enterprise buyers, legal counsel, and privacy teams should know about the ZoikoVertex DPA before reading the full document.

WHO IS THE PROCESSOR

ZoikoVertex generally acts as processor or service provider for customer personal data processed through the service. Customers are generally the controller or business for customer content and user data.

WHAT DATA IS PROCESSED

Account data, user data, workflow content, prompts, outputs, approval records, audit logs, integration metadata, support data, and billing contact data depending on customer use and configuration.

SECURITY COMMITMENTS

Encryption in transit and at rest, role-based access, tenant isolation, audit logging, secure development, incident response, and business continuity safeguards are documented in the security schedule.

SUBPROCESSORS

Material subprocessors are listed, notification of changes is provided, customers may raise objections, and equivalent data protection terms bind each material subprocessor.

INTERNATIONAL TRANSFERS

Cross-border transfers are supported through Standard Contractual Clauses, UK transfer documentation, and transfer impact assessment support where applicable.

DELETION AND RETURN

Customers have a defined window to export data at termination. Deletion applies subject to backup cycles, legal holds, retention obligations, security logs, and dispute exceptions.

SECTION 01

DPA Package Overview

Legal package

The ZoikoVertex data processing legal package consists of several related documents. The core DPA governs the overall processor relationship. Schedules provide the specific processing terms, security measures, transfer documentation, and subprocessor list that supplement the master agreement.

Document hierarchy: Customer agreement → Data Processing Addendum → Security Schedule → Subprocessor List → International Transfer Schedule → Data Processing Schedule. Where documents conflict, the customer agreement and DPA take precedence over schedules unless otherwise specified.

Data Processing Addendum

Primary processor/service-provider agreement governing how ZoikoVertex processes customer personal data when providing the service.

Current v1.0

Data Processing Schedule

Defines processing subject matter, duration, nature, purpose, data categories, data subject categories, roles, and retention.

Versioned

Technical & Organizational Measures

Security schedule summarizing encryption, access control, audit logging, vulnerability management, incident response, and business continuity.

Current

Subprocessor List

Lists material subprocessors, their service purpose, data categories, region, and notification process. Maintained and versioned separately.

Versioned • Updatable

International Transfer Schedule

SCC, UK Addendum or IDTA pathway, and transfer impact assessment support materials for cross-border processing.

Enterprise available

Deletion & Return Procedure

Termination window, export process, deletion workflow, backup expiry, legal hold exceptions, and evidence record retention.

Requires review

How to execute the DPA: Download the DPA package using the button below, or contact the Privacy & Security team to initiate a formal enterprise review, negotiate jurisdiction-specific terms, or request a countersigned copy. The public page does not constitute a legally binding agreement.

SECTION 02

Processing Schedule

GDPR Article 28

The processing schedule defines the core parameters of ZoikoVertex's role as processor or service provider for customer personal data. This summary reflects the intended DPA position and must be confirmed by counsel before publication.

FIELDDESCRIPTION
Subject matterProvision of ZoikoVertex services for governed agentic workflows, approvals, integrations, analytics, evidence, auditability, and customer-configured workflow operations.
DurationTerm of the customer agreement plus any deletion, return, retention, backup, legal hold, and dispute periods specified in the DPA or customer contract.
Nature of processingHosting, storage, retrieval, transmission, organization, analysis, generation, logging, evidence preservation, workflow orchestration, support, security monitoring, and deletion/return.
Purpose of processingTo provide, secure, support, improve, troubleshoot, audit, and evidence ZoikoVertex services according to customer instructions and product configuration.
Customer roleGenerally controller or business for customer content and authorized user data, subject to the agreement and deployment model.
ZoikoVertex roleGenerally processor or service provider for customer personal data processed through the service. May act as controller for limited account, billing, security, and business operations data.

Data subjects and personal data categories

CATEGORYPERSONAL DATA INCLUDEDNOTES
Authorized usersName, work email, role, permissions, workspace membership, authentication status, activity logs, session metadata.Core product user data
Customer personnelContact information, organizational context, approver identity, support contacts, and administrative records.Account administration
Workflow and content dataCampaigns, prompts, AI outputs, messages, comments, approval records, workflow state, evidence records, audit trail references, files, and attachments included by customer.Customer-controlled scope
Integration metadataConnected platform identifiers, token status metadata (not raw tokens), API call logs, webhook metadata, external object IDs, and sync status.No raw credentials stored
Usage and telemetryFeature usage, performance metrics, error logs, agent execution metadata, session analytics.Service improvement; minimize where possible
Security and audit logsIP/session/device metadata, privileged action logs, failed access events, export records, retention actions.Security and legal defense
Billing and contract dataBilling contacts, subscription metadata, invoice records, tax and procurement records.Accounting and contractual obligations

Sensitive data: Customers should not submit sensitive personal data — including health, financial, biometric, or regulated-category data — unless expressly supported by the product scope, customer contract, applicable jurisdiction, and configured safeguards. The DPA will define the governing position.

SECTION 03

Customer Instructions

Processing boundaries

ZoikoVertex processes customer personal data according to documented customer instructions. Instructions are expressed through the agreement, product configuration, authorized user actions, support requests, and written instructions accepted by ZoikoVertex.

INSTRUCTION CHANNELHOW INSTRUCTIONS ARE EXPRESSED
Agreement and DPAPrimary written instructions and processing boundaries. Supersedes conflicting oral or informal instructions.
Workspace configurationCustomer-selected roles, retention settings, integrations, agent controls, approval workflows, evidence policies, and access permissions.
Authorized user actionsActions by authorized users within their permissions are treated as customer-directed use and are bound by the agreement.
Support requestsSupport instructions must be authenticated, logged, limited to service needs, and within the scope of the agreement and DPA.
Prohibited instructionsZoikoVertex will not accept instructions that violate applicable law, security obligations, third-party rights, product scope, or the terms of the agreement.

Processing outside instructions: If ZoikoVertex is required by applicable law to process customer personal data beyond customer instructions, ZoikoVertex will inform the customer unless prohibited by law.

SECTION 04

Security Commitments

TOMs

The ZoikoVertex Technical and Organizational Measures schedule documents the security controls applied to customer personal data. A high-level summary is provided below. Enterprise customers may request the full security schedule and third-party assessment documentation through the Privacy & Security team.

Encryption

Encryption in transit (TLS) and at rest for customer data. Implementation details in the security schedule.

Access control

Role-based access, least-privilege principles, MFA for privileged accounts, access logging, and access reviews.

Tenant isolation

Customer data is scoped to workspace and tenant boundaries. Customer records are logically separated.

Audit and logging

Audit Trail, Identity Ledger, Evidence Vault, export logs, and retention action records support security and legal obligations.

Secure development

Code review, vulnerability management, penetration testing, dependency security, and change management controls.

Incident response

Security event detection, triage, customer notification workflow, evidence preservation, and remediation tracking.

Business continuity

Regular backups, disaster recovery approach, service resilience measures, and recovery objectives where available.

Sub-vendor security

Material subprocessors are subject to written security and data protection requirements equivalent to or better than those in the DPA.

Assurance documentation

Security schedule, third-party assessments, and audit support documentation available to enterprise customers on request.

SECTION 05

Subprocessor Transparency

Vendor list

ZoikoVertex uses carefully selected subprocessors to provide hosting, infrastructure, security, analytics, communications, support, and payment-related services. Each material subprocessor is bound by written terms that protect customer personal data to an equivalent standard.

Subprocessor change notifications

ZoikoVertex provides advance notice of material subprocessor changes. Enterprise customers may subscribe to change notifications and raise objections through the process defined in the DPA. New subprocessors are not activated until the notice period has elapsed or the customer has consented.

SERVICE CATEGORYPURPOSEDATA CATEGORIESREGIONSTATUS
Cloud infrastructureHosting, compute, storage, CDN, and network deliveryAll customer data in scope[Confirm regions][Confirm vendor]
Database servicesStructured data storage, backups, and replicationWorkflow, account, and audit data[Confirm regions][Confirm vendor]
Security and monitoringThreat detection, vulnerability scanning, audit logging, SIEMSecurity and access log data[Confirm regions][Confirm vendor]
Authentication servicesIdentity verification, MFA, SSOAuthentication credentials and session metadata[Confirm regions][Confirm vendor]
Analytics (where applicable)Website analytics and product telemetryAnonymized or aggregated usage data[Confirm regions][Confirm vendor]
Support platformCustomer support ticketing and communicationSupport contact and case data[Confirm regions][Confirm vendor]
Payment processingBilling and subscription managementBilling contact and payment metadata[Confirm regions][Confirm vendor]
AI model providers (where applicable)AI-assisted workflow and generation featuresPrompt and workflow content where applicable[Confirm regions][Confirm vendor and data position]

Vendor list confirmation required before publication. The live page must only list confirmed, approved subprocessors. Categories above are illustrative. Enterprise customers requiring early access to the confirmed vendor list may contact the Privacy & Security team. Each listed vendor must be bound by a written data processing agreement before being added to the live list.

SECTION 06

International Data Transfers

Global assurance

Because ZoikoVertex is a global platform, customer data may be processed in multiple jurisdictions depending on deployment configuration, infrastructure locations, support model, and subprocessor geography. All cross-border transfers are governed by an approved transfer mechanism.

EU / EEA TRANSFERS

Standard Contractual Clauses (SCCs)

Where personal data is transferred from the EU/EEA to a country without an adequacy decision, ZoikoVertex relies on EU Standard Contractual Clauses as adopted by the European Commission.

UK TRANSFERS

UK Addendum or IDTA

Where personal data is transferred from the UK, ZoikoVertex uses the UK International Data Transfer Addendum or IDTA pathway as applicable and approved by the ICO.

ADEQUACY DECISIONS

Recognised adequacy

Where applicable adequacy decisions exist for the destination country, ZoikoVertex may rely on those decisions as the transfer mechanism in addition to contractual safeguards.

ENTERPRISE CUSTOMERS

Transfer impact support

Enterprise customers may request transfer impact assessment documentation, encryption position, subprocessor regional deployment details, and supplementary technical measures for their own TIA process.

Regional configuration: Enterprise customers may request regional hosting or transfer restrictions where commercially and technically available. Contact the Privacy & Security team to discuss deployment-specific transfer configuration and available documentation.

SECTION 07

Data Subject Rights Assistance

Privacy rights

ZoikoVertex assists customers in fulfilling their obligations to data subjects under applicable privacy laws, including GDPR Article 28(3)(e). Assistance is provided through product configuration, export capabilities, support processes, and defined cooperation workflows.

Access and portability

ZoikoVertex provides reasonable assistance to customers in exporting or locating relevant data where technically possible within the product.

Correction

Supported through customer-controlled configuration and support process. Append-only governance records may not be mutable where audit integrity requires it.

Deletion and erasure

Supported subject to retention obligations, legal holds, security logs, billing records, backup cycles, dispute needs, and applicable law.

Restriction and objection

ZoikoVertex assists where product configuration or the support workflow can restrict processing within the bounds of the agreement.

US state privacy requests

ZoikoVertex supports applicable customer obligations under CCPA/CPRA and similar laws through contract-defined assistance and configuration support.

Verification requirement

Requests require authenticated customer authorization and appropriate role permissions before ZoikoVertex actions any privacy rights assistance.

Not a data subject's direct contact point: ZoikoVertex is generally processor for customer data. Data subjects should direct access, deletion, and correction requests to the customer as data controller. ZoikoVertex assists customers in fulfilling those obligations through the mechanisms described above.

SECTION 08

Deletion, Return, and Retention

Data lifecycle

Customer data lifecycle is governed by the agreement, DPA, customer configuration, applicable law, retention obligations, backup cycles, and legal hold requirements.

STAGEZOIKOVERTEX POSITION
During service termCustomers may configure retention settings and export certain records subject to permissions, product capabilities, and the agreement.
At terminationCustomers are entitled to a defined window to export customer data before deletion procedures commence. The window and process are specified in the agreement or DPA.
DeletionDeletion applies to active systems subject to backup cycles, retention obligations, legal holds, security logs, billing records, tax requirements, dispute needs, and legal obligations.
BackupsBackups expire on a rolling schedule defined in the security schedule. They should not be treated as customer-accessible archives or as a substitute for active data exports.
Legal holdsRecords subject to legal hold, regulatory inquiry, security investigation, contractual preservation, or dispute must not be deleted until the hold is released through the defined process.
Evidence recordsCertain audit, evidence, and identity records may be retained as required for security, legal defense, compliance obligations, and contract administration beyond the standard deletion window.

Customer data minimization: ZoikoVertex's position is to retain customer personal data only as long as reasonably necessary for the stated purpose, security, legal obligations, dispute resolution, and the agreement. Customers may configure retention settings within product capabilities to align with their own data minimization obligations.

SECTION 09

Security Incident & Breach Support

Security

ZoikoVertex maintains an incident response capability and commits to cooperate with affected enterprise customers in the event of a confirmed personal data breach or security event affecting customer data.

  • Detection and assessment:Security events are detected, triaged, and assessed to determine whether a reportable personal data breach has occurred under applicable law.
  • Customer notification:Enterprise customers will be notified without undue delay after ZoikoVertex becomes aware of a confirmed breach affecting their personal data, in line with the DPA and applicable law. The DPA will define the applicable notification window — no fixed hour commitment is stated publicly without legal and operational confirmation.
  • Information provided:Nature of the incident, affected data categories where known, approximate number of data subjects where determinable, mitigation steps taken, recommended customer actions, and a designated point of contact.
  • Evidence preservation:Relevant audit, identity, access, and forensic records are preserved to support investigation, regulatory reporting, and legal defense.
  • Customer cooperation:ZoikoVertex provides reasonable assistance for regulatory notification, contractual reporting, and data subject notification obligations where required by the DPA or applicable law.

No fixed public notification window: ZoikoVertex does not state a fixed breach notification hour publicly unless operationally guaranteed and approved by legal. The DPA defines the applicable notification commitment. The 72-hour GDPR supervisory authority window applies to the customer as controller — ZoikoVertex's obligation to the customer as processor is defined contractually.

FAQ

Frequently Asked Questions

AEO

Contact the Privacy & Security Team

PRIVACY INQUIRIES AND DPA REQUESTS

[privacy@zoikovertex.com] · [TBC by legal]

SECURITY AND INCIDENT REPORTS

[security@zoikovertex.com] · [TBC by legal]

SUBPROCESSOR NOTIFICATIONS

[privacy@zoikovertex.com] · [TBC]

ENTERPRISE DPA EXECUTION

Contact alliances or your account team to initiate formal DPA review and countersignature.