Skip to main content
ZNYX AI
DPA

Data Processing Agreement

A summary of the DPA Zitrino offers for the hosted ZNYX console and other Zitrino-operated services. This page supports legal and procurement review and is not a substitute for the executed agreement.

1. Purpose and overview

This page summarizes the Data Processing Agreement ("DPA") that Zitrino ("Zitrino", "we") makes available to commercial customers who use the hosted ZNYX console or other Zitrino-operated services. The DPA supplements the main services agreement and governs the processing of personal data carried out on the customer’s behalf.

This summary is provided for legal and procurement review. It is not the contract itself; the executed DPA controls in the event of any conflict with this page.

2. Definitions

Capitalized terms such as "personal data", "processing", "controller", "processor", "data subject", and "subprocessor" have the meanings given in applicable data protection law, including the GDPR and UK GDPR where relevant.

3. Roles of the parties

For customer personal data processed through the hosted console, the customer is the controller (or processor acting for its own customers) and Zitrino is the processor (or subprocessor). Zitrino processes personal data only on documented instructions from the customer, including those set out in the agreement and DPA.

4. Subject matter and scope

The DPA covers processing within the hosted service boundary, which typically includes:

  • Account administration data (users, roles, authentication).
  • Organization and project metadata.
  • Operational trace metadata (decisions, detector summaries, latency, identifiers).
  • Support communications related to the service.
  • Any other customer personal data expressly covered by the commercial service.

5. Duration of processing

Zitrino processes personal data for the duration of the services agreement and for any additional period required to fulfill legal obligations or to complete deletion or return of data after termination.

6. Processing instructions

Zitrino will process personal data only to provide the services and on the customer’s documented instructions, unless required to do otherwise by law - in which case Zitrino will inform the customer unless legally prohibited.

7. Confidentiality

Personnel authorized to process personal data are bound by appropriate confidentiality obligations and receive guidance on their data-protection responsibilities.

8. Security measures

Zitrino maintains technical and organizational measures appropriate to the risk, including encryption in transit, access controls, audit logging, environment isolation, and least-privilege operations. The specific measures in force are detailed in the executed DPA and supporting documentation.

9. Subprocessors

Zitrino engages vetted subprocessors (for example, cloud hosting, payment processing, and email delivery) under written terms that impose data-protection obligations equivalent to those in the DPA. A current subprocessor list is available on request, and the DPA describes how customers are notified of changes and may object.

10. International transfers

Where personal data is transferred across borders (including between the UK, US, and India), the DPA relies on appropriate transfer mechanisms such as standard contractual clauses or equivalent safeguards required by applicable law.

11. Data subject requests

Taking into account the nature of the processing, Zitrino provides reasonable assistance to help the customer respond to data subject requests (access, rectification, erasure, restriction, portability, and objection). Requests received directly by Zitrino are routed to the relevant controller.

12. Personal data breach notification

Zitrino will notify the customer without undue delay after becoming aware of a personal data breach affecting the customer’s data, and will provide information reasonably required to support the customer’s own notification obligations.

13. Deletion and return of data

On termination or expiry of the services, Zitrino will delete or return customer personal data in accordance with the agreement, except where retention is required by law.

14. Audits

Zitrino makes available information necessary to demonstrate compliance with the DPA and allows for and contributes to audits, including inspections, conducted by the customer or an auditor mandated by the customer, subject to reasonable confidentiality and scheduling terms.

15. Deployment-dependent responsibilities

Customers who self-host the ZNYX runtime (optionally with the in-boundary inference sidecar, so detection and judge models also run in their environment) remain responsible for the personal data processed there, including policies, retention, and logging. In that topology, prompt and response payloads stay inside the customer boundary and only trace metadata reaches the optional hosted control plane. Enterprise customers who also self-host the control plane move the entire processing boundary into their own infrastructure, which is reflected in the scope of the DPA.

16. Request the current DPA

To request the current DPA form as part of procurement or legal review, email [email protected] for procurement requests or [email protected] for privacy and data-protection review.

Secure every prompt, agent, and tool call, in your boundary.

Pull the open-source runtime, drop it into your stack, and start enforcing policy in minutes, free, forever. Add the hosted control plane when you want centralized policies, evidence, traces, and team workflows.