Data Processing Addendum
Last updated 2026-09-10
This Data Processing Addendum ("DPA") describes how Zetra, Inc. ("Processor") processes personal data on behalf of a customer workspace ("Controller") when the Controller uses Zetra to handle end users' personal data — for example, names, emails, or phone numbers collected through a lead-capture form or a conversation. It supplements our Terms of Service.
1. Subject matter and duration
Processing covers the personal data the Controller submits to the Service (directly, or via its own end users) for the duration the Controller maintains an active workspace, plus any period required for legitimate business or legal retention purposes.
2. Nature and purpose of processing
The Processor processes personal data to operate the Service as configured by the Controller: storing and retrieving uploaded content, generating AI responses grounded in that content, routing conversations to configured channels, and delivering notifications the Controller has set up (webhooks, Slack, email). The Processor does not use Controller data for its own independent purposes.
3. Subprocessors
The Controller authorizes the Processor to engage the subprocessors listed on our Subprocessors page to provide the Service. The Processor will update that page when subprocessors change and, for material changes, notify Controllers where required.
4. Security measures
The Processor implements the technical and organizational measures described on our Security & Trust page, including hashed credentials, signed sessions, tenant isolation enforced at the database query level, and HMAC-signed webhook delivery.
5. Assistance with data subject requests
The Processor will provide reasonable assistance to the Controller in responding to verified data subject requests (access, correction, deletion) relating to data processed through the Service, primarily through the account's existing self-service deletion tools and, for full-account deletion, a request to [email protected].
6. International transfers
[Placeholder — requires legal counsel] If personal data is transferred outside the country or region where it was collected (for example, to a subprocessor located elsewhere), an appropriate transfer mechanism — such as Standard Contractual Clauses — needs to be identified and attached here by counsel, based on where Zetra, Inc. and its subprocessors actually operate.
7. Breach notification
[Placeholder — requires legal counsel] A specific notification timeframe (e.g. "without undue delay and within 72 hours of becoming aware") should be set by counsel to match applicable law and any contractual commitments.
8. Audit rights
[Placeholder — requires legal counsel] The mechanics of any audit right (frequency, scope, use of third-party audit reports in lieu of an on-site audit) are a negotiated term — counsel should define these before this DPA is used as a binding contract with an enterprise customer.
9. Contact
Questions about this DPA can be sent to [email protected].