1. Parties and scope
This Data Processing Agreement applies to personal data that Zephior LLC processes on documented instructions from a client under the Ziva Terms, the Service Terms, an order form or a statement of work. It does not apply to data for which Zephior independently determines the purposes and means of processing.
2. Processing details
Subject matter: delivery, operation, support and security of the contracted service.
Duration: the term of the service agreement plus the agreed export, backup and deletion period.
Data subjects: client personnel, prospects, buyers, suppliers, partners or other persons whose data the client submits.
Data: account identifiers, business contact details, documents, communications, project records, service inputs and outputs, and other data described in the order form.
3. Client instructions
Zephior will process personal data only on documented client instructions, including the service agreement and use of configured product functions, unless applicable law requires otherwise. Zephior will notify the client if an instruction appears to violate applicable data-protection law, unless prohibited from doing so.
4. Confidentiality and access
Personnel authorized to process client personal data are subject to confidentiality duties and receive access only where needed for their assigned role. Zephior maintains access-control and offboarding procedures appropriate to the service.
5. Security measures
Zephior maintains measures appropriate to risk, including encryption in transit, protected storage, authentication, role-based access, tenant or project separation where applicable, logging, backup, vulnerability management and incident-response procedures. Specific measures and residency commitments may be stated in the order form or security schedule.
6. Subprocessors
The client gives general authorization for Zephior to use subprocessors needed to provide the service. Zephior will impose data-protection obligations appropriate to the processing and remains responsible for its subprocessors as required by applicable law. Provider categories are described in the Privacy Policy. Current service-specific information is provided under the applicable agreement or on request.
Zephior will provide reasonable advance notice of a material new subprocessor. The client may raise a documented data-protection objection within the stated notice period.
7. International transfers
Where personal data is transferred to a country without an applicable adequacy finding, Zephior will use recognized safeguards such as standard contractual clauses and supplementary measures where required. Deployment-specific location commitments remain controlling.
8. Assistance
Taking account of the nature of processing, Zephior will provide reasonable assistance with data-subject requests, data-protection impact assessments and regulator consultations. The client is responsible for communicating with data subjects and authorities unless the parties agree otherwise.
9. Personal data incidents
Zephior will notify the client without undue delay after becoming aware of a personal data breach affecting client data. The notice will include information reasonably available to help the client meet its obligations. Zephior may provide information in phases as the investigation continues.
10. Return and deletion
On termination, Zephior will make client data available for export for the period stated in the applicable terms or order form, then delete or anonymize it unless law requires retention. Data may remain in protected backups until the relevant backup cycle expires.
11. Information and audit
Zephior will provide information reasonably necessary to demonstrate compliance. Audits require reasonable prior notice, must protect other clients and confidential systems, and should first use available documentation or independent assurance. On-site audits are limited to cases where those materials are insufficient or law requires otherwise.
12. Order of precedence
If this DPA conflicts with the service terms on personal-data processing, this DPA controls. A signed, client-specific data-processing schedule controls over this standard DPA to the extent of the conflict. Liability remains subject to the applicable service agreement unless mandatory law requires otherwise.