Data Processing Addendum
Enterprise data processing terms for accountable AI workflows. Review how ZoikoVertex structures customer data processing, subprocessors, security commitments, international transfer support, deletion and return, audit assistance, and privacy-rights cooperation for enterprise deployments.
Pre-publication notice for legal and product review. This DPA page reflects intended contractual positions and must be reviewed by counsel for all target jurisdictions before publication. Processing categories, subprocessors, transfer mechanisms, retention periods, and security commitments must reflect implemented practices. No legally binding obligation arises from this public page alone — the executed customer agreement and DPA govern.
Plain English, first.
Six things enterprise buyers, legal counsel, and privacy teams should know about the ZoikoVertex DPA before reading the full document.
ZoikoVertex generally acts as processor or service provider for customer personal data processed through the service. Customers are generally the controller or business for customer content and user data.
Account data, user data, workflow content, prompts, outputs, approval records, audit logs, integration metadata, support data, and billing contact data depending on customer use and configuration.
Encryption in transit and at rest, role-based access, tenant isolation, audit logging, secure development, incident response, and business continuity safeguards are documented in the security schedule.
Material subprocessors are listed, notification of changes is provided, customers may raise objections, and equivalent data protection terms bind each material subprocessor.
Cross-border transfers are supported through Standard Contractual Clauses, UK transfer documentation, and transfer impact assessment support where applicable.
Customers have a defined window to export data at termination. Deletion applies subject to backup cycles, legal holds, retention obligations, security logs, and dispute exceptions.
DPA Package Overview
Legal packageThe ZoikoVertex data processing legal package consists of several related documents. The core DPA governs the overall processor relationship. Schedules provide the specific processing terms, security measures, transfer documentation, and subprocessor list that supplement the master agreement.
Document hierarchy: Customer agreement → Data Processing Addendum → Security Schedule → Subprocessor List → International Transfer Schedule → Data Processing Schedule. Where documents conflict, the customer agreement and DPA take precedence over schedules unless otherwise specified.
Data Processing Addendum
Primary processor/service-provider agreement governing how ZoikoVertex processes customer personal data when providing the service.
Data Processing Schedule
Defines processing subject matter, duration, nature, purpose, data categories, data subject categories, roles, and retention.
Technical & Organizational Measures
Security schedule summarizing encryption, access control, audit logging, vulnerability management, incident response, and business continuity.
Subprocessor List
Lists material subprocessors, their service purpose, data categories, region, and notification process. Maintained and versioned separately.
International Transfer Schedule
SCC, UK Addendum or IDTA pathway, and transfer impact assessment support materials for cross-border processing.
Deletion & Return Procedure
Termination window, export process, deletion workflow, backup expiry, legal hold exceptions, and evidence record retention.
How to execute the DPA: Download the DPA package using the button below, or contact the Privacy & Security team to initiate a formal enterprise review, negotiate jurisdiction-specific terms, or request a countersigned copy. The public page does not constitute a legally binding agreement.
Processing Schedule
GDPR Article 28The processing schedule defines the core parameters of ZoikoVertex's role as processor or service provider for customer personal data. This summary reflects the intended DPA position and must be confirmed by counsel before publication.
| FIELD | DESCRIPTION |
|---|---|
| Subject matter | Provision of ZoikoVertex services for governed agentic workflows, approvals, integrations, analytics, evidence, auditability, and customer-configured workflow operations. |
| Duration | Term of the customer agreement plus any deletion, return, retention, backup, legal hold, and dispute periods specified in the DPA or customer contract. |
| Nature of processing | Hosting, storage, retrieval, transmission, organization, analysis, generation, logging, evidence preservation, workflow orchestration, support, security monitoring, and deletion/return. |
| Purpose of processing | To provide, secure, support, improve, troubleshoot, audit, and evidence ZoikoVertex services according to customer instructions and product configuration. |
| Customer role | Generally controller or business for customer content and authorized user data, subject to the agreement and deployment model. |
| ZoikoVertex role | Generally processor or service provider for customer personal data processed through the service. May act as controller for limited account, billing, security, and business operations data. |
Data subjects and personal data categories
| CATEGORY | PERSONAL DATA INCLUDED | NOTES |
|---|---|---|
| Authorized users | Name, work email, role, permissions, workspace membership, authentication status, activity logs, session metadata. | Core product user data |
| Customer personnel | Contact information, organizational context, approver identity, support contacts, and administrative records. | Account administration |
| Workflow and content data | Campaigns, prompts, AI outputs, messages, comments, approval records, workflow state, evidence records, audit trail references, files, and attachments included by customer. | Customer-controlled scope |
| Integration metadata | Connected platform identifiers, token status metadata (not raw tokens), API call logs, webhook metadata, external object IDs, and sync status. | No raw credentials stored |
| Usage and telemetry | Feature usage, performance metrics, error logs, agent execution metadata, session analytics. | Service improvement; minimize where possible |
| Security and audit logs | IP/session/device metadata, privileged action logs, failed access events, export records, retention actions. | Security and legal defense |
| Billing and contract data | Billing contacts, subscription metadata, invoice records, tax and procurement records. | Accounting and contractual obligations |
Sensitive data: Customers should not submit sensitive personal data — including health, financial, biometric, or regulated-category data — unless expressly supported by the product scope, customer contract, applicable jurisdiction, and configured safeguards. The DPA will define the governing position.
Customer Instructions
Processing boundariesZoikoVertex processes customer personal data according to documented customer instructions. Instructions are expressed through the agreement, product configuration, authorized user actions, support requests, and written instructions accepted by ZoikoVertex.
| INSTRUCTION CHANNEL | HOW INSTRUCTIONS ARE EXPRESSED |
|---|---|
| Agreement and DPA | Primary written instructions and processing boundaries. Supersedes conflicting oral or informal instructions. |
| Workspace configuration | Customer-selected roles, retention settings, integrations, agent controls, approval workflows, evidence policies, and access permissions. |
| Authorized user actions | Actions by authorized users within their permissions are treated as customer-directed use and are bound by the agreement. |
| Support requests | Support instructions must be authenticated, logged, limited to service needs, and within the scope of the agreement and DPA. |
| Prohibited instructions | ZoikoVertex will not accept instructions that violate applicable law, security obligations, third-party rights, product scope, or the terms of the agreement. |
Processing outside instructions: If ZoikoVertex is required by applicable law to process customer personal data beyond customer instructions, ZoikoVertex will inform the customer unless prohibited by law.
Security Commitments
TOMsThe ZoikoVertex Technical and Organizational Measures schedule documents the security controls applied to customer personal data. A high-level summary is provided below. Enterprise customers may request the full security schedule and third-party assessment documentation through the Privacy & Security team.
Encryption
Encryption in transit (TLS) and at rest for customer data. Implementation details in the security schedule.
Access control
Role-based access, least-privilege principles, MFA for privileged accounts, access logging, and access reviews.
Tenant isolation
Customer data is scoped to workspace and tenant boundaries. Customer records are logically separated.
Audit and logging
Audit Trail, Identity Ledger, Evidence Vault, export logs, and retention action records support security and legal obligations.
Secure development
Code review, vulnerability management, penetration testing, dependency security, and change management controls.
Incident response
Security event detection, triage, customer notification workflow, evidence preservation, and remediation tracking.
Business continuity
Regular backups, disaster recovery approach, service resilience measures, and recovery objectives where available.
Sub-vendor security
Material subprocessors are subject to written security and data protection requirements equivalent to or better than those in the DPA.
Assurance documentation
Security schedule, third-party assessments, and audit support documentation available to enterprise customers on request.
Subprocessor Transparency
Vendor listZoikoVertex uses carefully selected subprocessors to provide hosting, infrastructure, security, analytics, communications, support, and payment-related services. Each material subprocessor is bound by written terms that protect customer personal data to an equivalent standard.
Subprocessor change notifications
ZoikoVertex provides advance notice of material subprocessor changes. Enterprise customers may subscribe to change notifications and raise objections through the process defined in the DPA. New subprocessors are not activated until the notice period has elapsed or the customer has consented.
| SERVICE CATEGORY | PURPOSE | DATA CATEGORIES | REGION | STATUS |
|---|---|---|---|---|
| Cloud infrastructure | Hosting, compute, storage, CDN, and network delivery | All customer data in scope | [Confirm regions] | [Confirm vendor] |
| Database services | Structured data storage, backups, and replication | Workflow, account, and audit data | [Confirm regions] | [Confirm vendor] |
| Security and monitoring | Threat detection, vulnerability scanning, audit logging, SIEM | Security and access log data | [Confirm regions] | [Confirm vendor] |
| Authentication services | Identity verification, MFA, SSO | Authentication credentials and session metadata | [Confirm regions] | [Confirm vendor] |
| Analytics (where applicable) | Website analytics and product telemetry | Anonymized or aggregated usage data | [Confirm regions] | [Confirm vendor] |
| Support platform | Customer support ticketing and communication | Support contact and case data | [Confirm regions] | [Confirm vendor] |
| Payment processing | Billing and subscription management | Billing contact and payment metadata | [Confirm regions] | [Confirm vendor] |
| AI model providers (where applicable) | AI-assisted workflow and generation features | Prompt and workflow content where applicable | [Confirm regions] | [Confirm vendor and data position] |
Vendor list confirmation required before publication. The live page must only list confirmed, approved subprocessors. Categories above are illustrative. Enterprise customers requiring early access to the confirmed vendor list may contact the Privacy & Security team. Each listed vendor must be bound by a written data processing agreement before being added to the live list.
International Data Transfers
Global assuranceBecause ZoikoVertex is a global platform, customer data may be processed in multiple jurisdictions depending on deployment configuration, infrastructure locations, support model, and subprocessor geography. All cross-border transfers are governed by an approved transfer mechanism.
Standard Contractual Clauses (SCCs)
Where personal data is transferred from the EU/EEA to a country without an adequacy decision, ZoikoVertex relies on EU Standard Contractual Clauses as adopted by the European Commission.
UK Addendum or IDTA
Where personal data is transferred from the UK, ZoikoVertex uses the UK International Data Transfer Addendum or IDTA pathway as applicable and approved by the ICO.
Recognised adequacy
Where applicable adequacy decisions exist for the destination country, ZoikoVertex may rely on those decisions as the transfer mechanism in addition to contractual safeguards.
Transfer impact support
Enterprise customers may request transfer impact assessment documentation, encryption position, subprocessor regional deployment details, and supplementary technical measures for their own TIA process.
Regional configuration: Enterprise customers may request regional hosting or transfer restrictions where commercially and technically available. Contact the Privacy & Security team to discuss deployment-specific transfer configuration and available documentation.
Data Subject Rights Assistance
Privacy rightsZoikoVertex assists customers in fulfilling their obligations to data subjects under applicable privacy laws, including GDPR Article 28(3)(e). Assistance is provided through product configuration, export capabilities, support processes, and defined cooperation workflows.
Access and portability
ZoikoVertex provides reasonable assistance to customers in exporting or locating relevant data where technically possible within the product.
Correction
Supported through customer-controlled configuration and support process. Append-only governance records may not be mutable where audit integrity requires it.
Deletion and erasure
Supported subject to retention obligations, legal holds, security logs, billing records, backup cycles, dispute needs, and applicable law.
Restriction and objection
ZoikoVertex assists where product configuration or the support workflow can restrict processing within the bounds of the agreement.
US state privacy requests
ZoikoVertex supports applicable customer obligations under CCPA/CPRA and similar laws through contract-defined assistance and configuration support.
Verification requirement
Requests require authenticated customer authorization and appropriate role permissions before ZoikoVertex actions any privacy rights assistance.
Not a data subject's direct contact point: ZoikoVertex is generally processor for customer data. Data subjects should direct access, deletion, and correction requests to the customer as data controller. ZoikoVertex assists customers in fulfilling those obligations through the mechanisms described above.
Deletion, Return, and Retention
Data lifecycleCustomer data lifecycle is governed by the agreement, DPA, customer configuration, applicable law, retention obligations, backup cycles, and legal hold requirements.
| STAGE | ZOIKOVERTEX POSITION |
|---|---|
| During service term | Customers may configure retention settings and export certain records subject to permissions, product capabilities, and the agreement. |
| At termination | Customers are entitled to a defined window to export customer data before deletion procedures commence. The window and process are specified in the agreement or DPA. |
| Deletion | Deletion applies to active systems subject to backup cycles, retention obligations, legal holds, security logs, billing records, tax requirements, dispute needs, and legal obligations. |
| Backups | Backups expire on a rolling schedule defined in the security schedule. They should not be treated as customer-accessible archives or as a substitute for active data exports. |
| Legal holds | Records subject to legal hold, regulatory inquiry, security investigation, contractual preservation, or dispute must not be deleted until the hold is released through the defined process. |
| Evidence records | Certain audit, evidence, and identity records may be retained as required for security, legal defense, compliance obligations, and contract administration beyond the standard deletion window. |
Customer data minimization: ZoikoVertex's position is to retain customer personal data only as long as reasonably necessary for the stated purpose, security, legal obligations, dispute resolution, and the agreement. Customers may configure retention settings within product capabilities to align with their own data minimization obligations.
Security Incident & Breach Support
SecurityZoikoVertex maintains an incident response capability and commits to cooperate with affected enterprise customers in the event of a confirmed personal data breach or security event affecting customer data.
- Detection and assessment:Security events are detected, triaged, and assessed to determine whether a reportable personal data breach has occurred under applicable law.
- Customer notification:Enterprise customers will be notified without undue delay after ZoikoVertex becomes aware of a confirmed breach affecting their personal data, in line with the DPA and applicable law. The DPA will define the applicable notification window — no fixed hour commitment is stated publicly without legal and operational confirmation.
- Information provided:Nature of the incident, affected data categories where known, approximate number of data subjects where determinable, mitigation steps taken, recommended customer actions, and a designated point of contact.
- Evidence preservation:Relevant audit, identity, access, and forensic records are preserved to support investigation, regulatory reporting, and legal defense.
- Customer cooperation:ZoikoVertex provides reasonable assistance for regulatory notification, contractual reporting, and data subject notification obligations where required by the DPA or applicable law.
No fixed public notification window: ZoikoVertex does not state a fixed breach notification hour publicly unless operationally guaranteed and approved by legal. The DPA defines the applicable notification commitment. The 72-hour GDPR supervisory authority window applies to the customer as controller — ZoikoVertex's obligation to the customer as processor is defined contractually.
Frequently Asked Questions
AEOContinue your trust review
Privacy Policy
Personal data collection, use, sharing, retention, and rights for website visitors and customers.
Security
Technical and organizational security measures, access controls, audit logging, and certification posture.
Compliance & Governance
Enterprise governance posture, responsible AI, auditability, and framework alignment.
Cookie Preferences
Manage analytics, marketing, and tracking choices. Control consent and view the consent record.
Contact the Privacy & Security Team
[privacy@zoikovertex.com] · [TBC by legal]
[security@zoikovertex.com] · [TBC by legal]
[privacy@zoikovertex.com] · [TBC]
Contact alliances or your account team to initiate formal DPA review and countersignature.