Data Processing Agreement

EFFECTIVE DATE: June 23, 2023


THESE TERMS OF SERVICE (“TERMS”) CONSTITUTE A CONTRACT BETWEEN YOU AND ZYTE AND GOVERN THE USE OF AND ACCESS TO THE SERVICE AND SITE BY YOU AND YOUR AGENTS WHETHER IN CONNECTION WITH A PAID SUBSCRIPTION TO THE SERVICE, BETA TESTING, FREE TRIAL, OR ANY OTHER USE OF THE SERVICE.


By accepting these Terms, or by accessing or using the Service and/or Site, or authorizing or permitting any Agent to access or use the Service, You represent that You have read, understood, and agree to be bound by these Terms. If You are entering into these Terms on behalf of a company, organization or another legal entity (an “Entity”), You are agreeing to these Terms for that Entity and representing to Zyte that You have the authority to bind such Entity and its Affiliates to these Terms and all applicable laws, in which case the terms “Subscriber,” “You,” “Your” or related capitalized terms herein shall refer to such Entity and its Affiliates. If You do not have such authority, or if You do not agree with these Terms, You must not accept these Terms and may not use the Service.

  1. Definitions 


    The following definitions shall apply for the purposes of this DPA:


    1. “Agreement” means the Zyte Terms together with any document related to Your subscription to the Services together with any Zyte generated service invoices, statements of work, contracts and/or any other agreements executed or approved by You with respect to Your subscription to the Services.

    2. "Contact Data" means Personal Data provided by You to Zyte including names, usernames (Zyte login details, Slack and other communication software other user names), business email addresses, business phone numbers, job titles, and such other information as is specified in the Zyte Terms.

    3. “Controller”, “Data Subject”, “Personal Data”, “Personal Data Breach”, “Processing”, “Processor” and “Supervisory Authority” shall have the meanings set out in the GDPR (and related terms such as “Process” have corresponding meanings). 

    4. “Data Protection Laws” is defined as all legislation and regulations relating to the protection of Personal Data, including (without limitation), the Data Protection Acts 1988-2018, the GDPR, and all other statutory instruments, industry guidelines (whether statutory or non-statutory) or codes of practice or guidance issued by a relevant Supervisory Authority relating to the processing of Personal Data or privacy, each as amended, revised, modified or replaced from time to time.

    5. “GDPR” means the General Data Protection Regulation (EU) 2016/679 on the protection of natural persons regarding the Processing of Personal Data and on the free movement of such data.

    6. "Restricted Transfer" means an international transfer of Personal Data by us to You where such transfer would be prohibited by applicable Data Protection Laws in the absence of a Transfer Solution.

    7. “Security Event” means an incident which results in (or may result in) the accidental or unlawful destruction, loss, alteration or unauthorized disclosure of, or access to, Client’s Personal Data while in the custody or control of Zyte or a Sub-Processor.

    8. "Service Personal Data" means the Personal Data collected, processed, or transferred by and/or to Client using the Services.

    9. “Services” means the service(s) and/or product(s) provided by Zyte to You under the Terms and/or an applicable Agreement.

    10. “Standard Contractual Clauses” means (a) in respect of any Personal Data subject to the GDPR[A1] , the standard contractual clauses for the transfer of Personal Data to third countries pursuant to Regulation (EU) 2016/679 between (i) controllers and controllers (Module 1) ("Controller to Controller") and/or (ii) processors and controller (Module 4) ("Processor to Controller") as approved by the European Commission Implementing Decision (EU) 2021/914 of 4 June 2021 available at https://ec.europa.eu/info/sites/default/files/sccs_word.zip and the Addendum B.1.0 issued by the Information Commissioner's Office and laid before Parliament in accordance with s119A of the Data Protection Act 2018 on 2 February 2022 (incorporating the Mandatory Clauses of that Addendum) appended to the Standard Contractual Clauses.

    11. “Sub-Processor” means the third party sub-processors set out in Annex 3 to this DPA engaged by Zyte to process Personal Data as authorized by Client in accordance with this DPA. 

    12. “Third Country” means all countries that are not members of the European Economic Area (“EEA”) or which have not been recognised by the European Commission as providing an adequate level of protection for Personal Data.

    13.  "Transfer Solution" means the Standard Contractual Clauses or any other means or basis for permitting the transfer of Personal Data in accordance with applicable Data Protection Laws. 

    14. “TOMs” means technical and organizational measures.



“Zyte Terms” means Zyte’s Terms of Service and Privacy Policy.

  1. Data Protection Roles

    1. The Parties acknowledge that:

      1. they each shall be independent controllers in respect of the Contact Data: and 

      2. Zyte shall be a Processor and Client shall be a Controller in respect of the Service Personal Data. 

  1. Client Obligations

    1. Client represents and warrants that it will only use the Service Personal Data to process Personal Data if such processing is in compliance with the applicable Data Protection Laws.

  1. Zyte Obligations

    1. Zyte, as the Controller, will process Contact Data for the purposes of providing the Services to Client under the Terms and any applicable Agreement.

    2. Zyte, as the Processor, will process the Service Personal Data only on documented instructions from Client.

    3. Zyte warrants that all persons authorized by Zyte to Process Personal Data are subject to obligations of confidentiality or are under an appropriate statutory obligation of confidentiality to ensure that the Service Personal Data is kept safe and secure.

    4. At the choice of the Client, all Contact Data held by Zyte shall be deleted or returned to the Contact upon the termination of the Agreement, unless EU or Member State law otherwise requires such Contact Data to be retained by Zyte for a prescribed period.

    5. Zyte shall implement and maintain appropriate TOMs designed to meet the requirements of Article 32 of the GDPR to protect the Data Subject and the Personal Data against any misuse, accidental, unlawful or unauthorized destruction, loss, alteration, disclosure, acquisition or access.

    6. Zyte shall without undue delay, and in any event no later than seventy-two (72) hours, notify Client of a Security Event. Where, and insofar as, it is not possible to provide all information at the same time, the initial notification of a Security Event shall contain the information then available and further information shall be provided as it becomes available without undue further delay.

    7. Zyte will provide Client with information about:

      1. the details of a contact point where more information concerning the Security Event can be obtained;

      2. the nature of the Security Event including the categories and approximate number of Data Subjects and Personal Data records concerned;

      3. the likely consequences of the Security Event; and

      4. the steps Zyte has taken to address the Security Event.

    8. Zyte shall:

      1. take all necessary steps to mitigate the effects and to minimize any damage resulting from the Security Event and to prevent a recurrence of such Security Event; and

      2. provide such assistance and cooperation as Client requires in responding to the Security Event including in relation to notifying any relevant regulatory authority and/or Data Subject of the Security Event. 

  1. Sub-Processors

    1. Client agrees that Zyte may share Personal Data with the Sub-Processors listed in Annex III.  Zyte may remove or replace the current Sub-Processors from time to time as necessary to provide the Services and will notify You of any such changes. 

    2.  Zyte must ensure that a written contract is entered into with each Sub-Processor that is compliant with the Data Protection Laws. Zyte shall be responsible and liable for any acts or omissions of the Sub-Processor.

    3.  Instructions given by Zyte to any Sub-Processor must be within the scope of this DPA.

  1. Third Country Transfer of Personal Data

    1. The Parties acknowledge and agree Zyte may from time to time transfer Contact Data and Service Personal Data outside of the EEA.

    2. In the event of a Restricted Transfer, the Parties agree that the Standard Contractual Clauses will be incorporated by reference and form part of this DPA as follows:

      1. Client shall be the “data importer” and Zyte shall be the “data exporter”.

      2. In relation to Client’s contact information, Module One shall apply as the Parties are independent Controllers. In relation to data extracted using Zyte Services, Module Four shall apply as Client is the Controller and Zyte is the Processor.

      3. In Clause 7, the optional docking clause shall not apply

      4. In Clause 9, Option 2 shall apply with at least 7 days prior notice (including email).

      5. In Clause 11, the optional language shall not apply.

      6. In Clause 17, the law of Ireland shall apply.

      7. In Clause 18, the courts of Ireland shall apply.

      8. the Annex I and II to the Standard Contractual Clauses are set out in the Annex I and II to this DPA

    3. In the event of a change in any applicable Data Protection Laws relating to the country/countries where an adequate level of data protection exists requiring an alternative Transfer Solution to be implemented to permit the continued transfers of Personal Data anticipated in the Agreement, the Parties each agree to act reasonably to seek to agree an alternative Transfer Solution permitting the relevant Party to continue Processing the Personal Data in the relevant country/countries and the relevant international transfer(s) to continue.

    4.  In the event the European Commission issues any replacement or substitution of the Standard Contractual Clauses, upon receipt of written notice from a Party requiring the same, the Standard Contractual Clauses incorporated into this DPA pursuant to this clause 6.4 shall be deemed to be deleted and replaced with such replacement or substitution which each Party agrees shall be deemed to be incorporated into this Agreement in place of the Standard Contractual Clauses (and all references in this DPA shall be deemed to refer to such replacement or substitutions clauses accordingly).  To the extent necessary, each Party agrees to co-operate taking such other measures as may be necessary to give effect to such replacement or substitution of the Standard Contractual Clauses in order to comply with applicable Data Protection Laws and/or otherwise satisfy any administrative or documentary requirements relating to the same.

  1. General

    1. Nothing in this DPA reduces the Client's obligations under the Agreement in relation to the protection of Personal Data. 

    2. This DPA and any disputes or claims arising out of or in connection with it or its subject matter or formation (including non-contractual disputes or claims) shall be governed by, and construed, in accordance with, the laws of Ireland.

    3. The Parties irrevocably agree that in relation to any dispute or claim that arises out of or in connection with the DPA or its subject matter or formation (including non-contractual disputes or claims) the courts of Ireland shall have jurisdiction.

ANNEX I

A. LIST OF PARTIES

Data exporter(s):

Name:Zyte Group Ltd.
Address:Cuil Greine House, Ballincollig Commercial Park, Link Road, Ballincollig, Co. Cork, Ireland.
Contact person’s name, position and contact details:Sanaea Daruwalla, sanaea@zyte.com
Activities relevant to the data transferred under these Clauses:Providing Services to Client
Role (controller/processor):Module 1 Controller in relation to Contact Data.Module 4 Processor in relation to Service Personal Data.

Data importer(s):

Name:Client’s name as set out in an Agreement
Address:Client’s address as set out in an Agreement
Contact person’s name, position and contact details:As set out in an Agreement or as otherwise agreed with Zyte
Activities relevant to the data transferred under these Clauses:Using Zyte’s Services
Role (controller/processor):Module 1 Controller in relation to Contact Data.Module 4 Controller in relation to Service Personal Data.

B. DESCRIPTION OF TRANSFER

Categories of data subjects whose Personal Data is transferred:
Client staff information; other information as determined by Client
Categories of personal data transferred:
Names, usernames (Zyte login details, Slack and other communication software other user names), business email addresses, postal addresses, business phone numbers, job titles,and other information as specified in the Zyte Terms
Sensitive data transferred (if applicable) and applied restrictions or safeguards that fully take into consideration the nature of the data and the risks involved, such as for instance strict purpose limitation, access restrictions (including access only for staff having followed specialized training), keeping a record of access to the data, restrictions for onward transfers or additional security measures.
N/A
The frequency of the transfer (e.g. whether the data is transferred on a one-off or continuous basis).
Continuous
Nature of the processing
As specified in the Zyte Terms
Purpose(s) of the data transfer and further processing
Zyte will process the Personal Data as necessary to provide the Services
The period for which the personal data will be retained, or, if that is not possible, the criteria used to determine that period
As specified in the Zyte Terms
For transfers to (sub) processors, also specify subject matter, nature and duration of the processing
As described in in Annex III

C. COMPETENT SUPERVISORY AUTHORITY

Identify the competent supervisory authority/ies in accordance with Clause 13
Irish Data Protection Commission

ANNEX II


TECHNICAL AND ORGANIZATIONAL MEASURES INCLUDING TECHNICAL AND ORGANIZATIONAL MEASURES TO ENSURE THE SECURITY OF THE DATA

Security MeasureDescription of Zyte Process
Ensuring physical security of locations at which Personal Data is processedZyte services are hosted on data servers hosted by highly secure cloud providers. All of Zyte’s hosting providers are ISO 27001 certified.
Ensuring system event loggingZyte uses centralized log management, which logs system events. Zyte shall monitor these logs for success rates, availability, and response time.
Protection of data during transmissionAll data in transit is encrypted using Transport Layer Security (TLSv1.2) using RSA256 bit key signed using the algorithm SHA256withRSA.
Managing vulnerabilities on production environmentZyte has a vulnerability management program and performs advanced vulnerability scans using leading technology scanners on a daily basis.
Ensuring password securityStrong passwords are implemented on all applicable systems. Zyte has a password management policy following NIST standard security requirements.
Ensuring system configurationSetup on servers is automated using a configuration management and orchestration tool to provide the same configurations per role on all servers.
User identification and authorisationAdministrative privileges are restricted based on the concept of least privilege and defined roles-level access. Only very limited staff at Zyte have administrator access to Zyte systems.
Governance and risk managementZyte has a risk management program in accordance with the NIST Risk Management Framework.
Managing incidents that affect confidentiality, integrity, and availabilityAn Information Technology Infrastructure Library is used to manage the lifecycle of an incident. Zyte has an incident response progress and guide for escalation based on the severity of an incident.

ANNEX III

LIST OF SUB-PROCESSORS

The controller has authorized the use of the following sub-processors (including a clear delimitation of responsibilities in case several sub-processors are authorized) :

NameAddressDescription of processing
Amazon Web Services410 Terry Avenue North, Seattle, WA USAHosting provider
Atlassian350 Bush Street Floor 13 San Francisco, CA94104 USAProject management
Braintree222 W Merchandise Mart Plaza, Suite 800, Chicago, IL 60654 USAProcessing online payment
Breadwinner by Xero8 The Green, Suite #5978, Dover, DE 19901Managing financial reporting
Chargebee340 S. Lemon Avenue, Suite #1537, Walnut, CA 91789 USAManaging payments and subscriptions
Cinergix PtyLevel 17, 31, Queen St., Melbourne 3000, VIC, AustraliaCommunication and integration tool
Confluent899 West Evelyn Ave.Mountain View, CA 94041Code development system
Form Keeper by Zapier548 Market St. #62411. San Francisco, CA 94104 USAData management
Freshworks2950 S. Delaware Street, Suite 201, San Mateo, CA 94403 USAIssue reporting and tracking
Gainsight655 Montgomery St 7th Floor, San Francisco, CA 94111 USACustomer relationship management tool
Github88 Colin P Kelly Jr St, San Francisco, CA 94107 USADevelopment platform
Gong201 Spear St. 13th FloorSan Francisco, CA 94105 USACall recording and customer relationship management tool
Google1600 Amphitheatre Parkway Mountain View, CA 94043 USAHost email, documents, and workspace
Google Analytics1600 Amphitheatre Parkway Mountain View, CA 94043 USAAnalytics service
Heap Analytics225 Bush Street, Suite 200, San Francisco, CA 94104 USAAnalytics service
HetznerIndrustriestr. 25, 91710Gunzenhausen, GermanyHosting provider
HotjarDragonara Business Centre, 5th Floor, Dragonara Road, Paceville St Julian's STJ 3141 MaltaUser behavior analytics
Hubspot25 First Street, 2nd Floor Cambridge, MA 02141 USACustomer relationship management tool
Intercom3rd Floor, Stephens Ct., 18-21 St. Stephen’s Green, Dublin 2 IrelandCustomer support channel
Mail Chimp675 Ponce de Leon Ave NE, Suite 5000, Atlanta, GA 30308 USAEmail tool
Mail Gun112 E Pecan St #1135, San Antonio, TX 78205 USAEmail tool
ProductBoard333 Bush Street, 20th FloorSan Francisco, CA 94104 USACustomer feedback and support tool
Salesforce415 Mission Street Third Floor San Francisco, CA 94105 USACustomer relationship management tool
Servers.com2777 N Stemmons Fwy. Dallas, TX 75207, USHosting provider
Retently2650 W El Camino Real Suite 2218, Mountain View, CA 94040, USAAnalysis and customer feedback tool
Xero1615 Platte Street, Suite 400, Denver, CO 80202 USAInvoicing
Zapier548 Market St. #62411. San Francisco, CA 94104 USAIntegration with customer relationship management tool