ZeroTB Back to zerotb.ai

Data Processing Addendum

ZeroTB, Inc. Version 2.0 · Last updated October 4, 2026 · Effective October 2026

This Data Processing Addendum (“DPA”) forms part of the agreement between ZeroTB, Inc. (“ZeroTB”) and the Customer for the ZeroTB Service, made up of the Terms of Service plus any Order Form (the “Agreement”). To request a countersigned copy, email compliance@zerotb.ai.

1. Definitions

2. Roles and Scope

The Customer is the controller (or a processor acting for its own controller) of Customer Personal Data, and ZeroTB is its processor (or sub-processor). Annex I describes the processing. Under the California Consumer Privacy Act, ZeroTB is a service provider and will not sell or share Customer Personal Data, or use it outside the direct business relationship with the Customer, except as that law permits.

3. Customer Instructions

ZeroTB processes Customer Personal Data only on the Customer’s documented instructions. The Agreement, this DPA, and the Customer’s use and configuration of the Service are those instructions. ZeroTB will tell the Customer if it believes an instruction breaks Data Protection Laws, and is not required to follow it. If the law requires other processing, ZeroTB will inform the Customer first unless the law prohibits it. The Customer is responsible for the lawfulness of the instructions and of the Customer Personal Data it provides.

4. Confidentiality

ZeroTB ensures that people authorized to process Customer Personal Data are bound by confidentiality obligations and access it only as needed to provide the Service.

5. Security

ZeroTB maintains the technical and organizational measures in Annex II. ZeroTB may update them, but will not materially reduce the overall level of protection.

6. Sub-processors

7. Data Subject Requests

Taking into account the nature of the processing, ZeroTB will help the Customer respond to requests from data subjects to exercise their rights. If ZeroTB receives a request directly that relates to Customer Personal Data, it will refer the data subject to the Customer and will not respond itself except to confirm the referral, unless the law requires otherwise.

8. Security Incidents

ZeroTB will notify the Customer without undue delay, and in any case within 72 hours, after confirming a Security Incident. The notice will describe, as far as then known, the nature of the incident, the categories and approximate number of data subjects and records affected, likely consequences, and the measures taken or proposed. ZeroTB will provide further information as it becomes available, take reasonable steps to contain the incident, and help the Customer meet its own notification obligations. Notice is not an admission of fault.

9. Impact Assessments

ZeroTB will give the Customer reasonable help with data protection impact assessments and prior consultations with supervisory authorities that relate to the Service, using information available to ZeroTB.

10. Deletion and Return

The Customer may export Customer Data before the Agreement ends. ZeroTB will delete Customer Personal Data within 30 days after the Agreement ends, except that audit records and evidence held under a storage lock are kept until the lock expires and then deleted, and backups expire on a rolling 30-day schedule. Data retained under this section remains protected by this DPA. ZeroTB may also keep data where the law requires it.

11. Audits

ZeroTB will make available the information reasonably needed to show compliance with this DPA, including security documentation and responses to security questionnaires. ZeroTB maintains independent third-party audit reports (such as a SOC 2 report) and will provide its most recent report to the Customer on request, under confidentiality. This satisfies the Customer’s audit rights unless Data Protection Laws or a supervisory authority require more. On-site audits are available only where Data Protection Laws or a supervisory authority require them, with at least 30 days’ written notice, during business hours, subject to confidentiality, and at the Customer’s cost.

12. International Transfers

Customer Personal Data is processed in the United States. Where a transfer from the EEA or Switzerland to ZeroTB is subject to Data Protection Laws, the SCCs are incorporated into this DPA by reference: Module 2 (controller to processor) where the Customer is a controller, and Module 3 (processor to processor) where the Customer is a processor. For those SCCs: clause 7 (docking) applies; clause 9 option 2 (general authorization) applies with the notice period in Section 6; the optional wording in clause 11 does not apply; clauses 17 and 18 select the law and courts of Ireland; and Annexes I and II are completed by this DPA. For transfers from the UK, the UK Addendum is incorporated and completed with the same information. For Switzerland, references to the GDPR include the Swiss Federal Act on Data Protection. If the SCCs or UK Addendum conflict with this DPA, they prevail.

13. Liability

Each party’s liability under this DPA is subject to the limitations of liability in the Terms of Service.

14. Order of Precedence

If documents conflict, the following order applies: the SCCs and UK Addendum (where they apply), then this DPA, then the Order Form (if any), then the Terms of Service.

15. Effective Date

This DPA takes effect when the Customer accepts the Terms of Service, or signs an Order Form or this DPA, and lasts as long as ZeroTB processes Customer Personal Data.

Annex I: Description of Processing

Annex II: Technical and Organizational Measures