LEGAL
Data Processing Agreement (template)
DRAFT — NOT FOR EXECUTION WITHOUT LEGAL REVIEW
Controller: Customer
Processor: ZyvorAI Labs Private Limited
Subject matter: Processing of personal data in connection with Hosted Services / support (if any) per MSA
Effective: ________
1. Roles¶
Where Zyvor processes personal data on Customer’s instructions, Zyvor acts as Processor (or sub-processor) and Customer as Controller, under GDPR-style definitions where applicable.
Self-hosted deployments where Customer does not transmit personal data to Zyvor may not require this DPA—mark N/A on Order Form.
2. Processing details¶
| Item | Description |
|---|---|
| Categories of data subjects | Customer’s employees, contractors, end users (as configured) |
| Categories of data | Account, contact, logs, telemetry (if enabled), support tickets |
| Purpose | Provide Software, Support, security, billing |
| Duration | Term of MSA + retention per Section 6 |
3. Processor obligations¶
Zyvor will: process only on documented instructions; ensure confidentiality; implement appropriate technical and organizational measures; assist with data subject requests where feasible; notify Customer of personal data breaches without undue delay; assist with DPIAs where required; delete or return data at termination unless law requires retention.
4. Sub-processors¶
Zyvor may use sub-processors (cloud hosting, email) listed at ____ or notified with thirty (30) days’ notice. Customer may object on reasonable grounds.
5. International transfers¶
Transfers outside EEA/UK/India use appropriate safeguards (SCCs, adequacy, or local law mechanisms)—to be specified by counsel.
6. Retention¶
Support data: ___ months. Telemetry: per Customer settings. Backups: rolling ___ days.
7. Audits¶
Customer may audit once per year on reasonable notice, or accept Zyvor’s SOC/ISO report if available.
8. Liability¶
Subject to MSA limitation of liability.
Annex: Technical and organizational measures (TOMs) — attach security whitepaper or fill per product.