Data Processing Agreement

Version 1.0  ·  Effective Date: [DATE]  ·  ZantIQ, Inc.

Recitals. This Data Processing Agreement ("DPA") forms part of the Terms of Service or other written agreement between ZantIQ, Inc. ("ZantIQ," "Processor") and the entity identified as Customer ("Controller") (together the "Parties"). It applies where ZantIQ processes Personal Data on behalf of Customer in connection with ZantIQ's contract intelligence services. The Parties agree as follows.
To execute a signed DPA: Email [email protected] with subject line "DPA Request — [Company Name]." We will return a countersigned copy within 5 business days. Enterprise customers may request custom DPA terms.

1. Definitions

Capitalized terms have the meanings below. Where not defined here, terms have the meanings in the Terms of Service.

  1. "Controller" means the Customer entity that determines the purposes and means of processing Personal Data.
  2. "Processor" means ZantIQ, Inc., which processes Personal Data on behalf of the Controller.
  3. "Personal Data" means any information relating to an identified or identifiable natural person that is contained in Customer Data and processed by ZantIQ under this DPA.
  4. "Customer Data" means contracts, documents, and other content uploaded or transmitted to the ZantIQ platform by Customer or on Customer's behalf, including any Personal Data therein.
  5. "Processing" (and "Process") means any operation performed on Personal Data, including collection, storage, use, analysis, disclosure, or deletion.
  6. "Data Subject" means the natural person to whom Personal Data relates.
  7. "Sub-processor" means a third-party processor engaged by ZantIQ to process Personal Data in connection with the Services.
  8. "Security Incident" means a confirmed breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to Personal Data.
  9. "Applicable Data Protection Law" means the EU General Data Protection Regulation (EU 2016/679) ("GDPR"), the UK GDPR, the California Consumer Privacy Act as amended by CPRA ("CCPA/CPRA"), and any other applicable data protection or privacy law binding on the Parties with respect to Customer Personal Data.
  10. "SCCs" means the Standard Contractual Clauses for the transfer of Personal Data to third countries adopted by the European Commission under Implementing Decision 2021/914 of 4 June 2021.
  11. "Services" means the contract intelligence software-as-a-service provided by ZantIQ under the Terms of Service.

2. Scope and Role of the Parties

  1. Controller and Processor. The Parties acknowledge that: (a) Customer is the Controller of Personal Data contained in Customer Data; and (b) ZantIQ is the Processor, processing such Personal Data solely on behalf of and under the instructions of Customer.
  2. Independent Controllers. To the extent ZantIQ processes Personal Data as an independent controller (e.g., account registration data for service administration, billing, and fraud prevention), such processing is governed by ZantIQ's Privacy Policy and not by this DPA.
  3. Compliance Responsibility. Customer is responsible for ensuring its instructions to ZantIQ comply with Applicable Data Protection Law, including that Customer has a lawful basis for processing and has made required disclosures to Data Subjects.

3. Details of Processing (Article 28(3) GDPR)

The subject matter, nature, purpose, duration, types of Personal Data, and categories of Data Subjects are set out in Annex I to this DPA.

4. ZantIQ's Obligations as Processor

ZantIQ shall:

  1. Instructions. Process Personal Data only on documented instructions from Customer, including as set out in the Terms of Service and this DPA, unless required to do so by applicable law (in which case ZantIQ shall, to the extent permitted by law, inform Customer before such processing).
  2. Confidentiality. Ensure that all personnel authorized to process Personal Data are subject to binding confidentiality obligations.
  3. Security. Implement and maintain the technical and organizational measures described in Annex II to protect Personal Data against unauthorized or unlawful processing and accidental loss, destruction, or damage.
  4. Sub-processing. Not engage Sub-processors except in accordance with Section 6 of this DPA.
  5. Data Subject Rights. Taking into account the nature of the processing, assist Customer by appropriate technical and organizational measures, insofar as reasonably possible, to fulfill Customer's obligation to respond to requests from Data Subjects exercising their rights under Applicable Data Protection Law.
  6. Compliance Assistance. Assist Customer in ensuring compliance with its obligations under Articles 32–36 GDPR (security, breach notification, DPIAs, prior consultation) taking into account the nature of processing and information available to ZantIQ.
  7. Deletion or Return. At Customer's election, upon termination or expiry of the Terms of Service, delete or return all Personal Data as set out in Section 10 of this DPA.
  8. Audit. Make available to Customer all information necessary to demonstrate compliance with this DPA and allow for and contribute to audits and inspections as set out in Section 11 of this DPA.
  9. Notification of Unlawful Instructions. Immediately inform Customer if, in ZantIQ's opinion, an instruction from Customer infringes Applicable Data Protection Law. ZantIQ shall not be obligated to follow an instruction that violates applicable law.

5. Customer's Obligations as Controller

Customer shall:

  1. Ensure it has a valid lawful basis for processing Personal Data and has complied with all applicable notice and consent requirements before uploading Personal Data to the Services.
  2. Ensure that the Personal Data it provides to ZantIQ is accurate, current, and complete.
  3. Only instruct ZantIQ to process Personal Data in a manner that is consistent with Applicable Data Protection Law.
  4. Promptly notify ZantIQ if Customer becomes aware of any actual or suspected Security Incident involving Customer Data held by ZantIQ.
  5. Be responsible for the use of the Services by Customer's authorized users.

6. Sub-processors

  1. General Authorization. Customer provides general written authorization for ZantIQ to engage the Sub-processors listed in Annex III. ZantIQ may update the Sub-processor list from time to time in accordance with Section 6.2.
  2. Change Notice. ZantIQ shall give Customer at least thirty (30) days' prior written notice (by email to the address registered for the account, or by update to zantiq.ai/legal/subprocessors) before adding or replacing a Sub-processor. If Customer has reasonable, documented objections to a new Sub-processor on data protection grounds, Customer shall notify ZantIQ within fourteen (14) days of the notice. The Parties shall work in good faith to resolve the objection. If the objection cannot be resolved, Customer may terminate the relevant Service on written notice.
  3. Sub-processor Obligations. ZantIQ shall impose on each Sub-processor data protection obligations substantially equivalent to those in this DPA, in particular providing sufficient guarantees to implement appropriate technical and organizational measures. ZantIQ remains responsible to Customer for the performance of each Sub-processor.
  4. AI Sub-processors. Customer specifically acknowledges that ZantIQ uses Google Cloud (Vertex AI) to power AI-based contract extraction, analysis, and search features. Google Cloud processes Personal Data solely to provide inference results at ZantIQ's request and does not use Customer Data to train or improve Google's AI models.

7. International Data Transfers

  1. Processing Location. ZantIQ stores and processes Customer Data in the United States (GCP us-central1) by default. Enterprise customers may request EU data residency (GCP europe-west4). Contact [email protected] to configure this.
  2. Transfer Mechanism. Where Personal Data originating in the European Economic Area ("EEA"), the United Kingdom, or Switzerland is transferred to ZantIQ in the United States, such transfers are governed by the SCCs, which are hereby incorporated into and form part of this DPA. For the purpose of the SCCs:
  3. UK Transfers. For transfers from the United Kingdom, the UK Addendum to the EU SCCs (as issued by the Information Commissioner's Office) supplements the SCCs. The "Exporter" is Customer and the "Importer" is ZantIQ. Table 1 of the UK Addendum is completed with the details in Annex I of this DPA.
  4. Other Transfers. For transfers from other jurisdictions, ZantIQ shall implement appropriate transfer mechanisms as required by Applicable Data Protection Law.

8. Security Incident Notification

  1. Notification. ZantIQ shall notify Customer of a confirmed Security Incident without undue delay and, where feasible, no later than seventy-two (72) hours after ZantIQ becomes aware of the Security Incident, by email to the account's registered email address and to [email protected] (marked URGENT).
  2. Content of Notification. To the extent known at the time, the notification shall include: (a) the nature of the Security Incident including the categories and approximate number of Data Subjects and Personal Data records concerned; (b) likely consequences of the Security Incident; (c) measures taken or proposed to address the Security Incident, including mitigation measures.
  3. Updates. If information is not available at the time of initial notification, ZantIQ shall provide it in phases as it becomes available.
  4. No Acknowledgment of Fault. ZantIQ's notification of or response to a Security Incident under this Section shall not be construed as an acknowledgment of fault or liability.
  5. Customer Responsibility. Customer is solely responsible for determining whether to notify relevant supervisory authorities or Data Subjects, and for making such notifications in compliance with Applicable Data Protection Law.

9. Data Subject Rights

  1. Forwarding Requests. ZantIQ shall promptly forward to Customer any Data Subject request received by ZantIQ and shall not respond to any such request without Customer's prior written authorization, except to confirm that the request is being forwarded to Customer.
  2. Technical Assistance. Taking into account the nature of the processing, ZantIQ shall provide reasonable assistance to Customer in fulfilling its obligations to respond to Data Subject requests, including access, rectification, erasure, restriction, portability, and objection, by:
  3. Fees. ZantIQ reserves the right to charge a reasonable fee for assistance under Section 9.2 that exceeds reasonable effort, provided ZantIQ informs Customer of the estimated fee before commencing such assistance.

10. Retention and Deletion

  1. During the Term. ZantIQ retains Customer Data for the duration of the subscription term plus a thirty (30)-day grace period to allow data export.
  2. Upon Termination. Following the termination or expiry of the Terms of Service and the expiry of any applicable export period, ZantIQ shall, at Customer's election communicated in writing prior to termination, either:
  3. Retention for Legal Purposes. Notwithstanding the above, ZantIQ may retain Personal Data to the extent and for the period required by applicable law, provided such data is processed only as required by that law and ZantIQ notifies Customer of any such requirement (to the extent legally permissible).
  4. Certification. Upon Customer's written request following deletion, ZantIQ shall provide a written certification that deletion has been completed.

11. Audit Rights

  1. Information. ZantIQ shall make available on request all information reasonably necessary to demonstrate its compliance with this DPA.
  2. Certifications and Reports. ZantIQ shall, upon request, provide Customer with copies of its then-current third-party certifications and audit reports (e.g., SOC 2 Type II, ISO 27001) that are relevant to ZantIQ's processing of Personal Data, subject to confidentiality obligations.
  3. On-Site Audits. To the extent required by Applicable Data Protection Law and where Customer cannot satisfy its audit obligations through the measures in Sections 11.1 and 11.2 alone, ZantIQ shall permit Customer (or Customer's designated third-party auditor who is not a competitor of ZantIQ and has signed a confidentiality agreement) to conduct an on-site audit of ZantIQ's processing activities, subject to:

12. CCPA / CPRA Provisions

  1. Service Provider. To the extent CCPA/CPRA applies, ZantIQ is a "Service Provider" (as defined in Civil Code § 1798.140) with respect to the Personal Information it processes on behalf of Customer. ZantIQ shall not:
  2. Certification. ZantIQ certifies that it understands and will comply with the restrictions in Section 12.1.
  3. Assistance. ZantIQ shall assist Customer in responding to verifiable Consumer requests under CCPA/CPRA by making available the data portability and deletion mechanisms described in Sections 9 and 10.

13. Liability and Indemnification

  1. Each Party shall be liable to the other for damages caused by processing that violates this DPA or Applicable Data Protection Law to the extent of that Party's responsibility for such violation.
  2. The aggregate liability of each Party under this DPA shall be subject to the limitations and exclusions set forth in the Terms of Service, except to the extent such limitations are prohibited by Applicable Data Protection Law.
  3. Nothing in this DPA limits either Party's liability to Data Subjects or supervisory authorities under Applicable Data Protection Law.

14. Term and Termination

  1. This DPA is effective as of the Effective Date set forth above (or, if earlier, the date of Customer's acceptance of the Terms of Service) and remains in force for the duration of ZantIQ's processing of Personal Data on behalf of Customer.
  2. This DPA automatically terminates upon the later of: (a) expiry or termination of all Terms of Service under which ZantIQ processes Customer Personal Data; or (b) ZantIQ's completion of deletion or return obligations under Section 10.
  3. Sections 7, 8, 10, 11, 12, and 13 of this DPA survive termination.

15. General Provisions

  1. Order of Precedence. In the event of a conflict between this DPA and the Terms of Service with respect to the subject matter of this DPA, this DPA shall control. In the event of a conflict between this DPA and the SCCs, the SCCs shall control.
  2. Governing Law. This DPA is governed by the laws of the State of California, without regard to its conflict of law provisions, except to the extent overridden by the SCCs or applicable EU/UK data protection law.
  3. Entire Agreement. This DPA, together with the Terms of Service and the Annexes attached hereto, constitutes the entire agreement between the Parties with respect to the processing of Personal Data, and supersedes all prior agreements and understandings on that subject matter.
  4. Amendment. ZantIQ may update this DPA to reflect changes in Applicable Data Protection Law, supervisory authority guidance, or changes to ZantIQ's Sub-processors (in accordance with Section 6). ZantIQ will provide at least thirty (30) days' notice of material updates. Continued use of the Services after the notice period constitutes acceptance.
  5. Severability. If any provision of this DPA is held invalid or unenforceable, the remaining provisions shall remain in full force.
  6. Counterparts and Electronic Signature. This DPA may be executed in counterparts. Electronic signatures are valid and binding.

Signature

ZantIQ, Inc.
a California limited liability company
(Processor)
Signature

Printed Name & Title

Date
Customer

(Controller)
Signature

Printed Name, Title & Company

Date
ANNEX I — Description of Processing Activities

A. List of Parties

FieldData Exporter (Controller / Customer)Data Importer (Processor / ZantIQ)
Name[Customer full legal name]ZantIQ, Inc.
Address[Customer address]California, United States
Contact[Customer DPO or privacy contact][email protected]
RoleControllerProcessor
Activities relevant to transferUploading and managing contracts through the ZantIQ platformProviding AI-powered contract intelligence services
Signature and accession dateAs set out on the signature page of this DPA

B. Description of Transfer

FieldDetail
Categories of Data SubjectsEmployees, contractors, officers, and counterparties of Customer whose personal data appears in uploaded contract documents (names, titles, contact information, and other identifying information contained in contracts and related documents).
Categories of Personal DataNames, job titles, email addresses, telephone numbers, postal addresses, signatures, compensation or payment terms associated with individuals, and any other personal data voluntarily included by Customer in contract documents uploaded to the Services.
Special Categories of Data (if applicable)None expected. Customer must not upload special category data (health, biometric, religious, etc.) unless expressly agreed in writing with ZantIQ in advance.
Frequency of TransferContinuous, for the duration of the Services.
Nature of ProcessingStorage, AI-powered extraction, analysis, semantic search, obligation detection, risk scoring, and retrieval of contract documents and the Personal Data therein.
Purpose of ProcessingTo provide ZantIQ's contract intelligence platform features, including document ingestion, AI extraction, obligation tracking, breach prediction, and reporting.
Duration of ProcessingFor the duration of Customer's subscription, plus a 30-day export period, plus any applicable legal retention period.
RetentionAs specified in Section 10 of the DPA and ZantIQ's Privacy Policy.

C. Competent Supervisory Authority (for GDPR transfers)

The competent supervisory authority shall be determined in accordance with the GDPR based on Customer's establishment in the EEA. If Customer is not established in the EEA, the Irish Data Protection Commission shall serve as the lead supervisory authority given ZantIQ's designation of Irish law under the SCCs.

ANNEX II — Technical and Organizational Security Measures

ZantIQ implements and maintains the following technical and organizational measures ("TOMs") to protect Personal Data. These measures represent the baseline standard; ZantIQ reviews and updates them at least annually.

Access Controls

Encryption

Network Security

Application Security

Organizational Measures

Backup and Availability

Monitoring and Logging

ANNEX III — Authorized Sub-processors
Sub-processor Country of Processing Purpose / Role Data Protection Measures
Google Cloud Platform (incl. Vertex AI) United States (us-central1); EU option available (europe-west4) Cloud infrastructure, compute, storage, managed database, caching, AI inference (Gemini/Vertex AI), secret management Google Cloud DPA; SCCs; ISO 27001; SOC 2; no training on customer data
Stripe, Inc. United States Payment processing and subscription billing Stripe DPA; SCCs; PCI DSS Level 1; ISO 27001
[Email Delivery Provider — TBD] [TBD] Transactional email delivery (receipts, alerts, invitations) [DPA; SCCs; SOC 2]
[Analytics Provider — TBD] [TBD] Product analytics (usage data only, consent-gated) [DPA; SCCs; SOC 2]
[Error Tracking — TBD] [TBD] Application error monitoring [DPA; SCCs; SOC 2]
[Support Tool — TBD] [TBD] Customer support communications [DPA; SCCs; SOC 2]

Note: Sub-processors marked [TBD] must be confirmed and named before this DPA is published. ZantIQ will provide 30 days' notice to Customers of any additions or replacements to this list.