Data Processing Addendum
This addendum applies where Zerovyn processes personal data on behalf of a client as part of an engagement. It is incorporated into the terms of service and is superseded only by a data processing agreement you have signed with Zerovyn directly.
1. Roles
The client is the controller: it determines the purpose and the means. Zerovyn is the processor: it processes on documented instruction only. Where Zerovyn determines any element of the means — which it does, for technical implementation choices — it does so within the client's stated purpose.
2. What is processed
Only the categories the engagement requires: typically contact records, data the client supplies for the system to operate on, system logs, and any personal data the delivered application itself processes. Zerovyn does not process special-category data, biometric data, or data about children unless the engagement specifically and lawfully requires it.
3. Purpose limitation
Data is processed for delivery of the engagement and nothing else. It is not used to train Zerovyn's own models, it is not aggregated into a benchmark, and it is not used for any marketing purpose.
4. Subprocessors
Zerovyn engages infrastructure and tooling providers. The current list, with what each does, is maintained on the privacy policy. A client may object to a specific subprocessor; the resolution is to discuss an alternative before the engagement starts, because some dependencies are structural to delivery.
5. Security measures
The measures actually in place are described on the security page. Where an engagement requires measures beyond those — encryption at rest under client-controlled keys, network isolation, named access lists — that is a scoping conversation, and it belongs in the proposal rather than assumed here.
6. Breach response
If Zerovyn becomes aware of a personal data breach affecting client data, the client is told without delay, with what is known, what is being done, and what the client may need to do for its own regulators and its own users. Zerovyn does not commit here to a fixed hour-count, because the honest commitment is immediacy and completeness, not a number.
7. Deletion and return
On the end of the engagement, the client's data is returned or deleted at the client's choice. Infrastructure-level backups expire on their normal retention cycle; that cycle is stated in the proposal. Zerovyn does not retain client data to hold it hostage or to train on it.
8. Audit
The client may audit Zerovyn's compliance with this addendum on reasonable notice. The audit is of the controls described on the security page. Where a client requires a formal attestation Zerovyn does not hold, that is raised before the engagement, not discovered during an audit.