Legal

Data Processing Agreement

Version 1.0 · Last updated: 2026-08-24

This Data Processing Agreement ("DPA") forms part of the Terms of Service between Zotniq and Customer (each a "Party", together the "Parties"). It governs Zotniq's processing of Customer Personal Data on behalf of Customer under the EU General Data Protection Regulation 2016/679 ("GDPR"), the UK Data Protection Act 2018 / UK GDPR ("UK GDPR"), and the California Consumer Privacy Act ("CCPA"). Acceptance is recorded when Customer accepts the Terms of Service at signup.

1. Definitions

  • Customer Personal Data means personal data processed by Zotniq on behalf of Customer under the Terms of Service, as further described in Annex A.
  • Data Protection Laws means GDPR, UK GDPR, CCPA, and any other applicable privacy or data protection laws.
  • Sub-processor means any third party engaged by Zotniq to process Customer Personal Data. The current list is in Annex B and at zotniq.ai/legal/subprocessors.
  • Other capitalised terms have the meaning given in the applicable Data Protection Law.

2. Roles and scope

Customer is the "controller" (or "business" under CCPA) of Customer Personal Data. Zotniq is the "processor" (or "service provider"). Zotniq processes Customer Personal Data only on documented instructions from Customer, including the instructions contained in the Terms of Service, this DPA, and the configuration Customer sets through the Zotniq console (rules, storage mode, region, retention).

Zotniq does not sell Customer Personal Data. Zotniq does not use Customer Personal Data for its own purposes, including for training AI models. Any change to this posture would require Customer's prior written consent.

3. Zotniq's obligations

  • Process Customer Personal Data only on Customer's documented instructions.
  • Ensure that personnel authorised to process Customer Personal Data are bound by confidentiality obligations.
  • Implement and maintain the technical and organisational security measures described in Annex C.
  • Assist Customer, to the extent reasonably possible, in fulfilling data-subject requests (access, deletion, rectification, portability) and in responding to supervisory-authority inquiries.
  • Notify Customer without undue delay, and in any event within 72 hours, of any Personal Data Breach affecting Customer Personal Data, per GDPR Article 33.
  • At Customer's choice, delete or return all Customer Personal Data at the end of the service, and delete existing copies (unless retention is required by law).
  • Make available to Customer all information reasonably necessary to demonstrate compliance with this DPA, and allow for and contribute to audits, including inspections, conducted by Customer or a mandated auditor. Audit rights are subject to reasonable notice, confidentiality, and cost-recovery for repeated audits.

4. Sub-processors

Customer grants Zotniq general authorisation to engage the Sub-processors listed in Annex B. Zotniq will provide at least 30 days notice before engaging any new Sub-processor via the change-notification list at [email protected]. Customer may object to a new Sub-processor on reasonable grounds by written notice within that period; if the Parties cannot agree, Customer may terminate the affected service without penalty.

Zotniq imposes on each Sub-processor data-protection obligations that are no less protective than those in this DPA, and remains liable for the performance of each Sub-processor.

5. International data transfers

Where Customer Personal Data originating in the EEA, UK, or Switzerland is transferred to a country not recognised as providing an adequate level of protection, the Parties agree that the Standard Contractual Clauses issued by the European Commission (Commission Implementing Decision (EU) 2021/914 of 4 June 2021), Module 2 (controller to processor) and Module 3 (processor to processor), are incorporated into this DPA by reference and shall apply. Details and applicable Annexes are at zotniq.ai/legal/scc.

For UK-originating data, the UK International Data Transfer Addendum (IDTA) issued by the ICO applies as the transfer mechanism, incorporating the same SCCs.

6. Retention and deletion

Customer Personal Data is retained per the retention schedule Customer configures in the Zotniq console. On termination of the Terms of Service, Zotniq will delete all Customer Personal Data within 30 days of the end of the service, unless applicable law requires longer retention. Zotniq will provide written confirmation of deletion. Before termination, Customer may export findings and audit-log data as JSON or CSV through the console.

7. Governing law

This DPA is governed by the law specified in the Terms of Service or the Master Services Agreement between the Parties. Where the Standard Contractual Clauses apply, the governing law and jurisdiction specified in the SCCs prevail for the purposes of those clauses.

8. Acceptance and precedence

This DPA is accepted by Customer as part of accepting the Terms of Service at signup. In the event of a conflict between this DPA and the Terms of Service in respect of the processing of Customer Personal Data, this DPA prevails. Customers requiring a wet-signed or mutually negotiated DPA can contact [email protected].


Annex A — Details of processing

  • Subject matter. Provision of the Zotniq runtime AI data protection service.
  • Nature and purpose. Inspection of prompts sent by Customer's users to AI destinations, on-device redaction and enforcement of Customer's rules, and provision of the audit and analytics console.
  • Duration. For the duration of the Terms of Service, plus the retention period Customer configures.
  • Categories of data subjects. Customer's employees, contractors, and any other end-users whose prompts are inspected by the Zotniq agent installed on Customer-managed devices.
  • Categories of Customer Personal Data. Findings metadata (data-type detected, source app, timestamp), enforcement decisions (allow / mask / block), and, in the default storage mode, redacted snippets of the finding. In metadata-only storage mode, no snippet leaves the endpoint. Special-category data (health, biometric, criminal) may appear in prompts if Customer's users include it; Zotniq's role remains that of processor.
  • Frequency of processing. Continuous, driven by end-user AI usage on Customer-managed devices.
  • Processing location. US-east-1 or EU-west-1, per Customer's region selection at onboarding.

Annex B — Sub-processors

The full list is maintained at zotniq.ai/legal/subprocessors. As of 2026-08-24:

Sub-processorPurposeRegion
Amazon Web Services (AWS)Compute and storage for the Zotniq cloud (findings ingestion, dashboard, audit log)US-east-1 (US customers) · EU-west-1 (EU customers)
CloudflareDNS, edge network, WAF, TLS termination for public-facing endpointsGlobal (traffic served from the nearest edge)
KindeIdentity provider (SSO, session management for the Zotniq dashboard)US
PostgreSQL on Amazon RDSApplication database (org state, rules, audit log metadata)Per-org: US-east-1 or EU-west-1

Annex C — Security measures

  • On-device inspection. Prompt content is inspected on the endpoint in a userland helper. Sensitive fields are masked locally before any content leaves the device.
  • Encryption in transit. TLS 1.3 for all outbound connections from the Zotniq agent to Zotniq cloud.
  • Encryption at rest. Standard cloud-provider encryption on all persistent stores; access to encryption keys is restricted, least-privilege, and audited.
  • Access control. SSO for the Zotniq console via Customer's identity provider; role-based access within each organization; time-boxed break-glass access for Zotniq production engineers, logged and requiring second-engineer approval.
  • Network segmentation. Production infrastructure is segregated from development and corporate networks. Customer data is segregated per organization at the application layer.
  • Vulnerability management. Dependency scanning on every build; internal security review of releases; coordinated disclosure via [email protected] as documented on the Security page.
  • Incident response. Customer notification within 72 hours of a confirmed Personal Data Breach, with information sufficient for Customer to meet its own notification obligations.
  • Business continuity. Automated backups with per-region snapshots. Cached rules continue enforcing on the endpoint during any cloud outage.

Contact

Data-protection questions and DPA-related requests: [email protected]

Legal and contract questions: [email protected]

Security incidents: [email protected]