Data Processing Addendum
Effective date: 2026-10-07 · Last updated: 2026-10-07
This Data Processing Addendum ("DPA") forms part of the Terms of Service or other written agreement (the "Agreement") between Zyverna, Inc. ("Zyverna", "Processor") and the customer identified in the Agreement ("Customer", "Controller"). It reflects the parties' agreement with respect to the processing of Personal Data by Zyverna on behalf of Customer in connection with the Service.
This DPA applies automatically to all Customers to the extent Data Protection Laws apply to the processing of Customer Personal Data. Customers who require a countersigned copy may request one at [email protected].
1. Definitions
- "Data Protection Laws" means all laws applicable to the processing of Personal Data under the Agreement, including the EU General Data Protection Regulation 2016/679 ("GDPR"), the UK GDPR and Data Protection Act 2018, the Swiss Federal Act on Data Protection ("FADP"), the California Consumer Privacy Act as amended by the CPRA ("CCPA"), other US state privacy laws, and Canada's PIPEDA.
- "Customer Personal Data" means Personal Data contained in Customer Content that Zyverna processes on behalf of Customer.
- "Personal Data", "Controller", "Processor", "Data Subject", "Processing", "Supervisory Authority" and "Personal Data Breach" have the meanings given in the GDPR; "Business", "Service Provider", "Sell" and "Share" have the meanings given in the CCPA.
- "Standard Contractual Clauses" or "SCCs" means the clauses approved by European Commission Implementing Decision (EU) 2021/914, and "UK Addendum" means the International Data Transfer Addendum issued by the UK Information Commissioner.
- "Subprocessor" means a third party engaged by Zyverna to process Customer Personal Data.
2. Roles and scope
2.1 Customer is the Controller (or a Processor acting on behalf of a third-party Controller) and Zyverna is the Processor of Customer Personal Data. Zyverna is an independent Controller for account, billing and usage data as described in the Privacy Policy.
2.2 Details of the processing are set out in Annex I.
3. Processor obligations
Zyverna shall:
(a) process Customer Personal Data only on documented instructions from Customer, including as set out in the Agreement and as given through Customer's use of the Service, unless required by law, in which case Zyverna will inform Customer before processing unless prohibited;
(b) ensure that persons authorized to process Customer Personal Data are bound by confidentiality obligations;
(c) implement the technical and organizational measures described in Annex II;
(d) engage Subprocessors only in accordance with Section 5;
(e) taking into account the nature of the processing, assist Customer by appropriate technical and organizational measures in fulfilling Customer's obligation to respond to Data Subject requests;
(f) assist Customer in ensuring compliance with its obligations regarding security, breach notification, data protection impact assessments and prior consultation, taking into account the information available to Zyverna;
(g) at Customer's choice, delete or return all Customer Personal Data after the end of the provision of the Service, and delete existing copies unless retention is required by law;
(h) make available all information necessary to demonstrate compliance with this DPA and allow for and contribute to audits in accordance with Section 7;
(i) immediately inform Customer if, in its opinion, an instruction infringes Data Protection Laws.
4. Customer obligations
Customer shall (a) ensure it has a lawful basis for the processing and has provided all required notices and obtained all required consents; (b) not submit Personal Data of special categories (Art. 9 GDPR), criminal conviction data, payment card data, or data about children under 16 unless expressly agreed in writing; (c) provide instructions that comply with Data Protection Laws; and (d) be responsible for the accuracy and legality of Customer Personal Data.
5. Subprocessors
5.1 Customer provides general written authorization for Zyverna to engage the Subprocessors listed at /legal/subprocessors.
5.2 Zyverna will notify Customer at least 30 days before authorizing a new Subprocessor by updating that page and, for Customers who subscribe to notifications, by email. Customer may object on reasonable data-protection grounds within that period. If the parties cannot resolve the objection, Customer may terminate the affected Service and receive a pro-rated refund of prepaid fees.
5.3 Zyverna will impose data protection obligations on Subprocessors no less protective than those in this DPA and remains liable for their performance.
6. Security and Personal Data Breaches
6.1 Zyverna maintains the measures in Annex II and may update them provided the overall level of security is not reduced.
6.2 Zyverna will notify Customer without undue delay and in any event within 48 hours after becoming aware of a Personal Data Breach affecting Customer Personal Data, providing information reasonably available to help Customer meet its own notification obligations, and will provide updates as the investigation progresses.
7. Audits
7.1 Zyverna will make available, on request and under confidentiality, its most recent third-party audit reports or certifications (e.g., SOC 2 Type II, once obtained), penetration test summaries and responses to reasonable security questionnaires.
7.2 Where these are insufficient to demonstrate compliance under Data Protection Laws, Customer (or an independent auditor bound by confidentiality) may audit Zyverna's relevant facilities and records once per 12 months, on 30 days' notice, during business hours, in a manner that does not disrupt operations or compromise other customers' data. Customer bears the audit's costs unless it reveals a material breach.
8. Data Subject requests
Zyverna will promptly notify Customer if it receives a request from a Data Subject relating to Customer Personal Data and will not respond except to acknowledge receipt or as required by law. The Service provides self-serve tools to access, export and delete Customer Content.
9. International transfers
9.1 Customer authorizes Zyverna to transfer Customer Personal Data to the United States and other countries where Zyverna or its Subprocessors operate, subject to this Section.
9.2 EEA transfers. The SCCs are incorporated by reference and apply as follows: Module Two (controller-to-processor) or Module Three (processor-to-processor) as applicable; Clause 7 (docking) applies; Clause 9 Option 2 (general authorization) with the notice period in Section 5.2; Clause 11 optional language does not apply; Clause 13 — the competent Supervisory Authority is that of the EU Member State where Customer is established; Clause 17 Option 1 — Irish law; Clause 18 — courts of Ireland. Annexes I, II and III of the SCCs are populated by Annexes I, II and the Subprocessors page respectively.
9.3 UK transfers. The UK Addendum applies, with Table 1 populated by the parties' details, Table 2 by the SCCs as configured above, Table 3 by Annexes I and II, and Table 4 allowing either party to terminate the Addendum as set out therein.
9.4 Swiss transfers. The SCCs apply with the modifications required by the Swiss Federal Data Protection and Information Commissioner, including references to the FADP and Swiss competent authority.
9.5 Where a recipient is certified under the EU-US or Swiss-US Data Privacy Framework or UK Extension, Zyverna may rely on that certification as an alternative mechanism.
10. CCPA terms
To the extent CCPA applies, Zyverna acts as a Service Provider. Zyverna shall not (a) Sell or Share Customer Personal Data; (b) retain, use or disclose it outside the direct business relationship or for any purpose other than the business purposes in the Agreement; or (c) combine it with Personal Data from other sources except as permitted by the CCPA. Zyverna certifies that it understands and will comply with these restrictions and will notify Customer if it can no longer meet them. Customer may take reasonable steps to stop and remediate unauthorized use.
11. Liability
Each party's liability under this DPA is subject to the limitations and exclusions of liability in the Agreement. Nothing in this DPA limits either party's liability to Data Subjects under the SCCs.
12. Term and precedence
This DPA remains in effect for as long as Zyverna processes Customer Personal Data. In case of conflict, the SCCs prevail over this DPA, which prevails over the Agreement.
Annex I — Details of processing
A. Parties Data exporter: Customer (details as in the Agreement). Role: Controller or Processor. Data importer: Zyverna, Inc., [Registered Agent Address — provided by Stripe Atlas], Wilmington, DE 19801, United States, [email protected]. Role: Processor.
B. Description of processing
| Item | Description |
|---|---|
| Subject matter | Provision of the Zyverna AI workspace, agent and API |
| Duration | Term of the Agreement plus the deletion period in Section 3(g) |
| Nature and purpose | Hosting, storage, transmission to model providers, generation of output, display and export of Customer Content, support and security |
| Categories of Data Subjects | Customer's employees, contractors and end users; individuals whose data appears in code, files or prompts submitted by Customer |
| Categories of Personal Data | Identifiers (names, emails, usernames), professional information, content of communications, technical data (IPs, logs), any Personal Data Customer chooses to include in Customer Content |
| Special categories | None intended; prohibited unless agreed in writing |
| Frequency | Continuous, as initiated by Customer |
| Retention | As set out in the Privacy Policy retention schedule; Privacy Mode: zero retention at model providers |
C. Competent Supervisory Authority Determined under Clause 13 of the SCCs.
Annex II — Technical and organizational measures
- Encryption. TLS 1.2+ in transit; AES-256 at rest for databases, object storage and backups; secrets stored in a managed KMS.
- Access control. Single sign-on with hardware-backed MFA for staff; role-based, least-privilege access; quarterly access reviews; production access logged and time-limited; customer content access requires a support ticket and customer permission.
- Infrastructure security. Hardened cloud infrastructure in SOC 2 / ISO 27001 certified data centers; network segmentation; WAF and DDoS protection; infrastructure as code with peer review.
- Application security. Secure SDLC, dependency scanning, static analysis, mandatory code review, annual third-party penetration tests, responsible disclosure program.
- Sandboxing. Agent code execution occurs in isolated, ephemeral, network-restricted sandboxes with CPU, memory and time limits.
- Logging and monitoring. Centralized audit logs retained 12 months; alerting on anomalous access; 24/7 on-call.
- Resilience. Multi-AZ deployments; encrypted daily backups with 35-day retention; tested disaster-recovery plan; RPO 24h, RTO 8h targets.
- Data minimization and segregation. Logical tenant isolation; prompts not retained by model providers in Privacy Mode; data minimization in logs (no code content in logs).
- Personnel. Background checks where legally permitted; confidentiality agreements; annual security and privacy training.
- Incident response. Documented IR plan; breach notification within 48 hours as per Section 6.2; post-incident reviews.
- Vendor management. Due diligence on Subprocessors; DPAs with all Subprocessors; annual review.
- Deletion. Self-serve deletion; account data deleted within 30 days of closure; crypto-shredding of backups on rotation.
Annex III — Subprocessors
See the current list at /legal/subprocessors.