Data Processing Addendum
This Data Processing Addendum (“DPA”) forms part of the agreement between ZeroTB, Inc. (“ZeroTB”) and the Customer for the ZeroTB Service, made up of the Terms of Service plus any Order Form (the “Agreement”). To request a countersigned copy, email compliance@zerotb.ai.
1. Definitions
- Data Protection Laws means laws on the processing of personal data that apply to a party’s processing under the Agreement, including the GDPR, the UK GDPR, and the California Consumer Privacy Act.
- Customer Personal Data means personal data in Customer Data that ZeroTB processes for the Customer under the Agreement.
- Sub-processor means a third party ZeroTB engages to process Customer Personal Data.
- Security Incident means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, Customer Personal Data.
- SCCs means the standard contractual clauses approved by the European Commission in Decision 2021/914. UK Addendum means the International Data Transfer Addendum issued by the UK Information Commissioner.
- “Controller,” “processor,” “data subject,” and “processing” have the meanings given in the GDPR. Other capitalized terms have the meanings given in the Terms of Service.
2. Roles and Scope
The Customer is the controller (or a processor acting for its own controller) of Customer Personal Data, and ZeroTB is its processor (or sub-processor). Annex I describes the processing. Under the California Consumer Privacy Act, ZeroTB is a service provider and will not sell or share Customer Personal Data, or use it outside the direct business relationship with the Customer, except as that law permits.
3. Customer Instructions
ZeroTB processes Customer Personal Data only on the Customer’s documented instructions. The Agreement, this DPA, and the Customer’s use and configuration of the Service are those instructions. ZeroTB will tell the Customer if it believes an instruction breaks Data Protection Laws, and is not required to follow it. If the law requires other processing, ZeroTB will inform the Customer first unless the law prohibits it. The Customer is responsible for the lawfulness of the instructions and of the Customer Personal Data it provides.
4. Confidentiality
ZeroTB ensures that people authorized to process Customer Personal Data are bound by confidentiality obligations and access it only as needed to provide the Service.
5. Security
ZeroTB maintains the technical and organizational measures in Annex II. ZeroTB may update them, but will not materially reduce the overall level of protection.
6. Sub-processors
- The Customer gives general authorization for ZeroTB to engage Sub-processors. The current list is on our Sub-processors page.
- ZeroTB will give at least 30 days’ notice of a new Sub-processor by updating that page and emailing Customer administrators. No amendment to the Agreement is needed for a new Sub-processor.
- The Customer may object on reasonable data-protection grounds within that notice period by emailing compliance@zerotb.ai. The parties will discuss the objection in good faith. If it cannot be resolved, the Customer may terminate the affected Service and receive a refund of prepaid fees for the unused period.
- ZeroTB imposes data-protection obligations on each Sub-processor that are no less protective than this DPA, and remains responsible for its Sub-processors’ performance.
7. Data Subject Requests
Taking into account the nature of the processing, ZeroTB will help the Customer respond to requests from data subjects to exercise their rights. If ZeroTB receives a request directly that relates to Customer Personal Data, it will refer the data subject to the Customer and will not respond itself except to confirm the referral, unless the law requires otherwise.
8. Security Incidents
ZeroTB will notify the Customer without undue delay, and in any case within 72 hours, after confirming a Security Incident. The notice will describe, as far as then known, the nature of the incident, the categories and approximate number of data subjects and records affected, likely consequences, and the measures taken or proposed. ZeroTB will provide further information as it becomes available, take reasonable steps to contain the incident, and help the Customer meet its own notification obligations. Notice is not an admission of fault.
9. Impact Assessments
ZeroTB will give the Customer reasonable help with data protection impact assessments and prior consultations with supervisory authorities that relate to the Service, using information available to ZeroTB.
10. Deletion and Return
The Customer may export Customer Data before the Agreement ends. ZeroTB will delete Customer Personal Data within 30 days after the Agreement ends, except that audit records and evidence held under a storage lock are kept until the lock expires and then deleted, and backups expire on a rolling 30-day schedule. Data retained under this section remains protected by this DPA. ZeroTB may also keep data where the law requires it.
11. Audits
ZeroTB will make available the information reasonably needed to show compliance with this DPA, including security documentation and responses to security questionnaires. ZeroTB maintains independent third-party audit reports (such as a SOC 2 report) and will provide its most recent report to the Customer on request, under confidentiality. This satisfies the Customer’s audit rights unless Data Protection Laws or a supervisory authority require more. On-site audits are available only where Data Protection Laws or a supervisory authority require them, with at least 30 days’ written notice, during business hours, subject to confidentiality, and at the Customer’s cost.
12. International Transfers
Customer Personal Data is processed in the United States. Where a transfer from the EEA or Switzerland to ZeroTB is subject to Data Protection Laws, the SCCs are incorporated into this DPA by reference: Module 2 (controller to processor) where the Customer is a controller, and Module 3 (processor to processor) where the Customer is a processor. For those SCCs: clause 7 (docking) applies; clause 9 option 2 (general authorization) applies with the notice period in Section 6; the optional wording in clause 11 does not apply; clauses 17 and 18 select the law and courts of Ireland; and Annexes I and II are completed by this DPA. For transfers from the UK, the UK Addendum is incorporated and completed with the same information. For Switzerland, references to the GDPR include the Swiss Federal Act on Data Protection. If the SCCs or UK Addendum conflict with this DPA, they prevail.
13. Liability
Each party’s liability under this DPA is subject to the limitations of liability in the Terms of Service.
14. Order of Precedence
If documents conflict, the following order applies: the SCCs and UK Addendum (where they apply), then this DPA, then the Order Form (if any), then the Terms of Service.
15. Effective Date
This DPA takes effect when the Customer accepts the Terms of Service, or signs an Order Form or this DPA, and lasts as long as ZeroTB processes Customer Personal Data.
Annex I: Description of Processing
- Parties: data exporter is the Customer (contact details in the Order Form, if any, or otherwise in the Customer’s account details). Data importer is ZeroTB, Inc., 2261 Market Street, STE 86549, San Francisco, CA 94114, United States, compliance@zerotb.ai.
- Subject matter and nature: hosting, storage, analysis, and display of Customer Data to provide the ZeroTB compliance platform, including AI-assisted features provided through third-party AI model providers.
- Purpose: to provide, secure, and support the Service for the Customer under the Agreement.
- Duration: the term of the Agreement, plus the deletion periods in Section 10.
- Frequency: continuous.
- Data subjects: the Customer’s employees, contractors, and other users; guest users the Customer invites, such as auditors, consultants, or advisors; and individuals named in documents the Customer uploads.
- Categories of data: names, work emails, and roles; company profile; policies, documents, and evidence files; compliance program records; configuration, settings, user, and activity metadata from systems the Customer connects (such as cloud providers, code repositories, identity providers, and HR and ticketing tools); audit logs; support communications; and, if the Customer installs software we provide on its devices, device identifiers and hardware details, operating system and software versions, security configuration and patch status, installed software and known vulnerabilities in it, malware detections, and diagnostic logs. That software does not collect file contents, keystrokes, screenshots, or browsing history.
- Special categories: none intended. The Customer should not upload special-category data unless needed for its compliance program.
- Sub-processors: as listed on the Sub-processors page, for the purposes stated there.
- Competent supervisory authority: as determined under clause 13 of the SCCs.
Annex II: Technical and Organizational Measures
- Encryption: data is encrypted in transit and at rest.
- Isolation: each customer’s data is logically isolated.
- Access control: least-privilege access; multi-factor authentication required for all administrative access; secure user authentication; customer-controlled user and guest access.
- Logging and monitoring: tamper-resistant audit records in the Service; infrastructure logging and threat detection.
- Network protection: network protection in front of the Service.
- Hosting: cloud infrastructure in the United States.
- Integrations: access is granted by the Customer, limited to what the integration needs (read-only where the integration allows it), and revocable by the Customer at any time.
- AI: third-party AI model providers listed on the Sub-processors page; inputs are not used to train models.
- Security testing: regular testing and review of the Service’s security, including automated and AI-assisted testing.
- Resilience: automated backups kept on a rolling 30-day schedule.
- Personnel: personnel with access to Customer Personal Data are bound by confidentiality, and access is limited to those who need it.
- Incident response: breach notification as described in Section 8.