Data Processing Agreement
Version 1.0 · Effective Date: [DATE] · ZantIQ, Inc.
Recitals. This Data Processing Agreement ("DPA") forms part of the Terms of Service or other written agreement between ZantIQ, Inc. ("ZantIQ," "Processor") and the entity identified as Customer ("Controller") (together the "Parties"). It applies where ZantIQ processes Personal Data on behalf of Customer in connection with ZantIQ's contract intelligence services. The Parties agree as follows.
To execute a signed DPA: Email
[email protected] with subject line "DPA Request — [Company Name]." We will return a countersigned copy within 5 business days. Enterprise customers may request custom DPA terms.
1. Definitions
Capitalized terms have the meanings below. Where not defined here, terms have the meanings in the Terms of Service.
- "Controller" means the Customer entity that determines the purposes and means of processing Personal Data.
- "Processor" means ZantIQ, Inc., which processes Personal Data on behalf of the Controller.
- "Personal Data" means any information relating to an identified or identifiable natural person that is contained in Customer Data and processed by ZantIQ under this DPA.
- "Customer Data" means contracts, documents, and other content uploaded or transmitted to the ZantIQ platform by Customer or on Customer's behalf, including any Personal Data therein.
- "Processing" (and "Process") means any operation performed on Personal Data, including collection, storage, use, analysis, disclosure, or deletion.
- "Data Subject" means the natural person to whom Personal Data relates.
- "Sub-processor" means a third-party processor engaged by ZantIQ to process Personal Data in connection with the Services.
- "Security Incident" means a confirmed breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to Personal Data.
- "Applicable Data Protection Law" means the EU General Data Protection Regulation (EU 2016/679) ("GDPR"), the UK GDPR, the California Consumer Privacy Act as amended by CPRA ("CCPA/CPRA"), and any other applicable data protection or privacy law binding on the Parties with respect to Customer Personal Data.
- "SCCs" means the Standard Contractual Clauses for the transfer of Personal Data to third countries adopted by the European Commission under Implementing Decision 2021/914 of 4 June 2021.
- "Services" means the contract intelligence software-as-a-service provided by ZantIQ under the Terms of Service.
2. Scope and Role of the Parties
- Controller and Processor. The Parties acknowledge that: (a) Customer is the Controller of Personal Data contained in Customer Data; and (b) ZantIQ is the Processor, processing such Personal Data solely on behalf of and under the instructions of Customer.
- Independent Controllers. To the extent ZantIQ processes Personal Data as an independent controller (e.g., account registration data for service administration, billing, and fraud prevention), such processing is governed by ZantIQ's Privacy Policy and not by this DPA.
- Compliance Responsibility. Customer is responsible for ensuring its instructions to ZantIQ comply with Applicable Data Protection Law, including that Customer has a lawful basis for processing and has made required disclosures to Data Subjects.
3. Details of Processing (Article 28(3) GDPR)
The subject matter, nature, purpose, duration, types of Personal Data, and categories of Data Subjects are set out in Annex I to this DPA.
4. ZantIQ's Obligations as Processor
ZantIQ shall:
- Instructions. Process Personal Data only on documented instructions from Customer, including as set out in the Terms of Service and this DPA, unless required to do so by applicable law (in which case ZantIQ shall, to the extent permitted by law, inform Customer before such processing).
- Confidentiality. Ensure that all personnel authorized to process Personal Data are subject to binding confidentiality obligations.
- Security. Implement and maintain the technical and organizational measures described in Annex II to protect Personal Data against unauthorized or unlawful processing and accidental loss, destruction, or damage.
- Sub-processing. Not engage Sub-processors except in accordance with Section 6 of this DPA.
- Data Subject Rights. Taking into account the nature of the processing, assist Customer by appropriate technical and organizational measures, insofar as reasonably possible, to fulfill Customer's obligation to respond to requests from Data Subjects exercising their rights under Applicable Data Protection Law.
- Compliance Assistance. Assist Customer in ensuring compliance with its obligations under Articles 32–36 GDPR (security, breach notification, DPIAs, prior consultation) taking into account the nature of processing and information available to ZantIQ.
- Deletion or Return. At Customer's election, upon termination or expiry of the Terms of Service, delete or return all Personal Data as set out in Section 10 of this DPA.
- Audit. Make available to Customer all information necessary to demonstrate compliance with this DPA and allow for and contribute to audits and inspections as set out in Section 11 of this DPA.
- Notification of Unlawful Instructions. Immediately inform Customer if, in ZantIQ's opinion, an instruction from Customer infringes Applicable Data Protection Law. ZantIQ shall not be obligated to follow an instruction that violates applicable law.
5. Customer's Obligations as Controller
Customer shall:
- Ensure it has a valid lawful basis for processing Personal Data and has complied with all applicable notice and consent requirements before uploading Personal Data to the Services.
- Ensure that the Personal Data it provides to ZantIQ is accurate, current, and complete.
- Only instruct ZantIQ to process Personal Data in a manner that is consistent with Applicable Data Protection Law.
- Promptly notify ZantIQ if Customer becomes aware of any actual or suspected Security Incident involving Customer Data held by ZantIQ.
- Be responsible for the use of the Services by Customer's authorized users.
6. Sub-processors
- General Authorization. Customer provides general written authorization for ZantIQ to engage the Sub-processors listed in Annex III. ZantIQ may update the Sub-processor list from time to time in accordance with Section 6.2.
- Change Notice. ZantIQ shall give Customer at least thirty (30) days' prior written notice (by email to the address registered for the account, or by update to zantiq.ai/legal/subprocessors) before adding or replacing a Sub-processor. If Customer has reasonable, documented objections to a new Sub-processor on data protection grounds, Customer shall notify ZantIQ within fourteen (14) days of the notice. The Parties shall work in good faith to resolve the objection. If the objection cannot be resolved, Customer may terminate the relevant Service on written notice.
- Sub-processor Obligations. ZantIQ shall impose on each Sub-processor data protection obligations substantially equivalent to those in this DPA, in particular providing sufficient guarantees to implement appropriate technical and organizational measures. ZantIQ remains responsible to Customer for the performance of each Sub-processor.
- AI Sub-processors. Customer specifically acknowledges that ZantIQ uses Google Cloud (Vertex AI) to power AI-based contract extraction, analysis, and search features. Google Cloud processes Personal Data solely to provide inference results at ZantIQ's request and does not use Customer Data to train or improve Google's AI models.
7. International Data Transfers
- Processing Location. ZantIQ stores and processes Customer Data in the United States (GCP us-central1) by default. Enterprise customers may request EU data residency (GCP europe-west4). Contact [email protected] to configure this.
- Transfer Mechanism. Where Personal Data originating in the European Economic Area ("EEA"), the United Kingdom, or Switzerland is transferred to ZantIQ in the United States, such transfers are governed by the SCCs, which are hereby incorporated into and form part of this DPA. For the purpose of the SCCs:
- Module Two (Controller to Processor) applies where Customer is the Controller and ZantIQ is the Processor.
- Customer is the "data exporter" and ZantIQ is the "data importer."
- The optional Clause 7 docking clause is included.
- Clause 11 (Redress) optional language is not included.
- Under Clause 17, the SCCs are governed by the law of the Republic of Ireland.
- Under Clause 18(b), disputes shall be resolved before the courts of the Republic of Ireland.
- Annex I (Description of Transfer), Annex II (Technical and Organizational Measures), and Annex III (Sub-processors) of this DPA serve as Annexes I, II, and III of the SCCs respectively.
- UK Transfers. For transfers from the United Kingdom, the UK Addendum to the EU SCCs (as issued by the Information Commissioner's Office) supplements the SCCs. The "Exporter" is Customer and the "Importer" is ZantIQ. Table 1 of the UK Addendum is completed with the details in Annex I of this DPA.
- Other Transfers. For transfers from other jurisdictions, ZantIQ shall implement appropriate transfer mechanisms as required by Applicable Data Protection Law.
8. Security Incident Notification
- Notification. ZantIQ shall notify Customer of a confirmed Security Incident without undue delay and, where feasible, no later than seventy-two (72) hours after ZantIQ becomes aware of the Security Incident, by email to the account's registered email address and to [email protected] (marked URGENT).
- Content of Notification. To the extent known at the time, the notification shall include: (a) the nature of the Security Incident including the categories and approximate number of Data Subjects and Personal Data records concerned; (b) likely consequences of the Security Incident; (c) measures taken or proposed to address the Security Incident, including mitigation measures.
- Updates. If information is not available at the time of initial notification, ZantIQ shall provide it in phases as it becomes available.
- No Acknowledgment of Fault. ZantIQ's notification of or response to a Security Incident under this Section shall not be construed as an acknowledgment of fault or liability.
- Customer Responsibility. Customer is solely responsible for determining whether to notify relevant supervisory authorities or Data Subjects, and for making such notifications in compliance with Applicable Data Protection Law.
9. Data Subject Rights
- Forwarding Requests. ZantIQ shall promptly forward to Customer any Data Subject request received by ZantIQ and shall not respond to any such request without Customer's prior written authorization, except to confirm that the request is being forwarded to Customer.
- Technical Assistance. Taking into account the nature of the processing, ZantIQ shall provide reasonable assistance to Customer in fulfilling its obligations to respond to Data Subject requests, including access, rectification, erasure, restriction, portability, and objection, by:
- Providing Customer with the ability to export Contract Data in machine-readable format via the ZantIQ platform.
- Deleting or anonymizing specified Customer Data upon Customer's written instruction.
- Fees. ZantIQ reserves the right to charge a reasonable fee for assistance under Section 9.2 that exceeds reasonable effort, provided ZantIQ informs Customer of the estimated fee before commencing such assistance.
10. Retention and Deletion
- During the Term. ZantIQ retains Customer Data for the duration of the subscription term plus a thirty (30)-day grace period to allow data export.
- Upon Termination. Following the termination or expiry of the Terms of Service and the expiry of any applicable export period, ZantIQ shall, at Customer's election communicated in writing prior to termination, either:
- Return Customer Data to Customer in a standard machine-readable format (JSON or CSV) via secure download; or
- Securely delete or anonymize all Customer Data in ZantIQ's systems and, to the extent technically feasible, instruct Sub-processors to do the same.
- Retention for Legal Purposes. Notwithstanding the above, ZantIQ may retain Personal Data to the extent and for the period required by applicable law, provided such data is processed only as required by that law and ZantIQ notifies Customer of any such requirement (to the extent legally permissible).
- Certification. Upon Customer's written request following deletion, ZantIQ shall provide a written certification that deletion has been completed.
11. Audit Rights
- Information. ZantIQ shall make available on request all information reasonably necessary to demonstrate its compliance with this DPA.
- Certifications and Reports. ZantIQ shall, upon request, provide Customer with copies of its then-current third-party certifications and audit reports (e.g., SOC 2 Type II, ISO 27001) that are relevant to ZantIQ's processing of Personal Data, subject to confidentiality obligations.
- On-Site Audits. To the extent required by Applicable Data Protection Law and where Customer cannot satisfy its audit obligations through the measures in Sections 11.1 and 11.2 alone, ZantIQ shall permit Customer (or Customer's designated third-party auditor who is not a competitor of ZantIQ and has signed a confidentiality agreement) to conduct an on-site audit of ZantIQ's processing activities, subject to:
- At least sixty (60) days' prior written notice;
- Limitation to business hours and not more than once per calendar year unless a Security Incident has occurred;
- Agreement on scope and a reasonable audit plan in advance; and
- Customer bearing all costs of the audit unless the audit reveals a material breach of this DPA by ZantIQ.
12. CCPA / CPRA Provisions
- Service Provider. To the extent CCPA/CPRA applies, ZantIQ is a "Service Provider" (as defined in Civil Code § 1798.140) with respect to the Personal Information it processes on behalf of Customer. ZantIQ shall not:
- Sell or share Personal Information (as defined under CCPA/CPRA);
- Retain, use, or disclose Personal Information for any purpose other than providing the Services;
- Retain, use, or disclose Personal Information outside the direct business relationship between the Parties; or
- Combine Personal Information received from Customer with Personal Information from other sources, except as permitted by CCPA/CPRA.
- Certification. ZantIQ certifies that it understands and will comply with the restrictions in Section 12.1.
- Assistance. ZantIQ shall assist Customer in responding to verifiable Consumer requests under CCPA/CPRA by making available the data portability and deletion mechanisms described in Sections 9 and 10.
13. Liability and Indemnification
- Each Party shall be liable to the other for damages caused by processing that violates this DPA or Applicable Data Protection Law to the extent of that Party's responsibility for such violation.
- The aggregate liability of each Party under this DPA shall be subject to the limitations and exclusions set forth in the Terms of Service, except to the extent such limitations are prohibited by Applicable Data Protection Law.
- Nothing in this DPA limits either Party's liability to Data Subjects or supervisory authorities under Applicable Data Protection Law.
14. Term and Termination
- This DPA is effective as of the Effective Date set forth above (or, if earlier, the date of Customer's acceptance of the Terms of Service) and remains in force for the duration of ZantIQ's processing of Personal Data on behalf of Customer.
- This DPA automatically terminates upon the later of: (a) expiry or termination of all Terms of Service under which ZantIQ processes Customer Personal Data; or (b) ZantIQ's completion of deletion or return obligations under Section 10.
- Sections 7, 8, 10, 11, 12, and 13 of this DPA survive termination.
15. General Provisions
- Order of Precedence. In the event of a conflict between this DPA and the Terms of Service with respect to the subject matter of this DPA, this DPA shall control. In the event of a conflict between this DPA and the SCCs, the SCCs shall control.
- Governing Law. This DPA is governed by the laws of the State of California, without regard to its conflict of law provisions, except to the extent overridden by the SCCs or applicable EU/UK data protection law.
- Entire Agreement. This DPA, together with the Terms of Service and the Annexes attached hereto, constitutes the entire agreement between the Parties with respect to the processing of Personal Data, and supersedes all prior agreements and understandings on that subject matter.
- Amendment. ZantIQ may update this DPA to reflect changes in Applicable Data Protection Law, supervisory authority guidance, or changes to ZantIQ's Sub-processors (in accordance with Section 6). ZantIQ will provide at least thirty (30) days' notice of material updates. Continued use of the Services after the notice period constitutes acceptance.
- Severability. If any provision of this DPA is held invalid or unenforceable, the remaining provisions shall remain in full force.
- Counterparts and Electronic Signature. This DPA may be executed in counterparts. Electronic signatures are valid and binding.
Signature
ZantIQ, Inc.
a California limited liability company
(Processor)
Signature
Printed Name & Title
Date
Customer
(Controller)
Signature
Printed Name, Title & Company
Date
ANNEX I — Description of Processing Activities
A. List of Parties
| Field | Data Exporter (Controller / Customer) | Data Importer (Processor / ZantIQ) |
| Name | [Customer full legal name] | ZantIQ, Inc. |
| Address | [Customer address] | California, United States |
| Contact | [Customer DPO or privacy contact] | [email protected] |
| Role | Controller | Processor |
| Activities relevant to transfer | Uploading and managing contracts through the ZantIQ platform | Providing AI-powered contract intelligence services |
| Signature and accession date | As set out on the signature page of this DPA |
B. Description of Transfer
| Field | Detail |
| Categories of Data Subjects | Employees, contractors, officers, and counterparties of Customer whose personal data appears in uploaded contract documents (names, titles, contact information, and other identifying information contained in contracts and related documents). |
| Categories of Personal Data | Names, job titles, email addresses, telephone numbers, postal addresses, signatures, compensation or payment terms associated with individuals, and any other personal data voluntarily included by Customer in contract documents uploaded to the Services. |
| Special Categories of Data (if applicable) | None expected. Customer must not upload special category data (health, biometric, religious, etc.) unless expressly agreed in writing with ZantIQ in advance. |
| Frequency of Transfer | Continuous, for the duration of the Services. |
| Nature of Processing | Storage, AI-powered extraction, analysis, semantic search, obligation detection, risk scoring, and retrieval of contract documents and the Personal Data therein. |
| Purpose of Processing | To provide ZantIQ's contract intelligence platform features, including document ingestion, AI extraction, obligation tracking, breach prediction, and reporting. |
| Duration of Processing | For the duration of Customer's subscription, plus a 30-day export period, plus any applicable legal retention period. |
| Retention | As specified in Section 10 of the DPA and ZantIQ's Privacy Policy. |
C. Competent Supervisory Authority (for GDPR transfers)
The competent supervisory authority shall be determined in accordance with the GDPR based on Customer's establishment in the EEA. If Customer is not established in the EEA, the Irish Data Protection Commission shall serve as the lead supervisory authority given ZantIQ's designation of Irish law under the SCCs.
ANNEX II — Technical and Organizational Security Measures
ZantIQ implements and maintains the following technical and organizational measures ("TOMs") to protect Personal Data. These measures represent the baseline standard; ZantIQ reviews and updates them at least annually.
Access Controls
- Role-based access control (RBAC) enforced at application and infrastructure level
- Principle of least privilege for all personnel accessing customer environments
- Multi-factor authentication (MFA) required for all internal ZantIQ systems and GCP console access
- Unique user accounts; shared credentials prohibited
- Access reviews conducted quarterly; access revoked immediately upon personnel departure
Encryption
- Data in transit: TLS 1.2 or higher enforced on all external connections; TLS enforced on all internal service-to-service communication
- Data at rest: AES-256 encryption for all data stored in Cloud SQL, Cloud Storage, and Redis (via Google Cloud default encryption with Customer Managed Encryption Key option available for Enterprise)
- Database credentials and API keys stored in GCP Secret Manager; never stored in source code or environment files
Network Security
- Private VPC with no public IPs on database or cache tiers
- Cloud Run services accessed via HTTPS only; HTTP redirected to HTTPS
- Cloud Armor WAF protecting public endpoints
- GCP VPC firewall rules restricting inter-service traffic to required ports only
Application Security
- Tenant data isolation enforced at application and database row level (tenant_id scoping on all queries)
- Input validation and output encoding applied throughout the application
- API rate limiting implemented to prevent abuse
- Dependency scanning in CI/CD pipeline; critical CVEs patched within 72 hours
- Security vulnerability assessment completed prior to launch
Organizational Measures
- All personnel with access to Personal Data bound by written confidentiality obligations
- Security awareness training conducted annually and upon onboarding
- Incident response plan maintained and tested annually
- Background checks conducted for personnel with access to production systems (where legally permissible)
Backup and Availability
- Cloud SQL automated daily backups with 7-day retention; point-in-time recovery enabled
- Cloud Storage versioning enabled
- Production Cloud SQL and Redis deployed in high-availability configuration
- Cloud Run auto-scaling to maintain availability during demand spikes
Monitoring and Logging
- GCP Cloud Monitoring alerts on error rates, latency, and security anomalies
- Access logs retained for security review; audit logs retained for compliance
- Centralized log management with tamper-evident storage
ANNEX III — Authorized Sub-processors
| Sub-processor |
Country of Processing |
Purpose / Role |
Data Protection Measures |
| Google Cloud Platform (incl. Vertex AI) |
United States (us-central1); EU option available (europe-west4) |
Cloud infrastructure, compute, storage, managed database, caching, AI inference (Gemini/Vertex AI), secret management |
Google Cloud DPA; SCCs; ISO 27001; SOC 2; no training on customer data |
| Stripe, Inc. |
United States |
Payment processing and subscription billing |
Stripe DPA; SCCs; PCI DSS Level 1; ISO 27001 |
| [Email Delivery Provider — TBD] |
[TBD] |
Transactional email delivery (receipts, alerts, invitations) |
[DPA; SCCs; SOC 2] |
| [Analytics Provider — TBD] |
[TBD] |
Product analytics (usage data only, consent-gated) |
[DPA; SCCs; SOC 2] |
| [Error Tracking — TBD] |
[TBD] |
Application error monitoring |
[DPA; SCCs; SOC 2] |
| [Support Tool — TBD] |
[TBD] |
Customer support communications |
[DPA; SCCs; SOC 2] |
Note: Sub-processors marked [TBD] must be confirmed and named before this DPA is published. ZantIQ will provide 30 days' notice to Customers of any additions or replacements to this list.