This Data Processing Agreement (the “DPA”) forms part of the Terms of Service between ZenTalk and the customer that has agreed to those terms (“Customer”, “you”). It governs how ZenTalk processes personal data on your behalf when you use the ZenTalk chat widget, voice, email helpdesk, CRM, and related services (the “Services”). Where you are subject to the EU or UK General Data Protection Regulation (“GDPR”), the California Consumer Privacy Act as amended (“CCPA/CPRA”), or similar laws, this DPA applies to that processing. If any term here conflicts with the Terms of Service on the subject of data protection, this DPA controls.
If your organization requires a countersigned copy, or your own paper, contact legal@usezentalk.com and we will arrange it.
1. Roles of the parties
For personal data contained in the content you and your visitors submit through the Services (“Customer Personal Data”), you are the data controller (or business) and ZenTalk is the data processor (or service provider), acting only on your documented instructions. ZenTalk does not sell or share Customer Personal Data and does not retain, use, or disclose it for any purpose other than providing the Services to you.
2. Scope and instructions
ZenTalk processes Customer Personal Data only to provide, secure, and support the Services, as described in the Terms of Service, this DPA, and Annex I, and as further instructed by you through the Services or in writing. If ZenTalk is legally required to process data beyond your instructions, it will tell you first unless the law forbids that notice.
3. Confidentiality
ZenTalk ensures that personnel authorized to process Customer Personal Data are bound by confidentiality obligations and are granted access only on a need to know basis, scoped by role.
4. Security measures
ZenTalk implements and maintains the technical and organizational measures described in Annex II to protect Customer Personal Data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure, or access. ZenTalk regularly reviews and improves these measures and will not materially lower the overall level of protection during the term.
5. Sub processors
You authorize ZenTalk to engage the sub processors listed in our privacy policy to help deliver the Services. ZenTalk imposes data protection obligations on each sub processor no less protective than those in this DPA and remains responsible for their performance. ZenTalk will give you a way to learn of intended changes to sub processors and a reasonable opportunity to object on legitimate data protection grounds. If you object and the matter cannot be resolved, you may terminate the affected Service.
6. Assistance with data subject rights
The Services give you tools to access, correct, export, and delete Customer Personal Data yourself. Taking that into account, ZenTalk will provide reasonable assistance so you can respond to requests from data subjects to exercise their rights. If a data subject contacts ZenTalk directly about data ZenTalk processes on your behalf, ZenTalk will forward the request to you rather than answer it itself, unless you have authorized otherwise. A public data deletion form is available for visitors.
7. Personal data breach
ZenTalk will notify you without undue delay after becoming aware of a personal data breach affecting Customer Personal Data, and will provide the information you reasonably need to meet your own notification obligations, along with the steps ZenTalk is taking to investigate and contain it.
8. Data protection impact assessments
Taking into account the nature of processing and the information available to it, ZenTalk will provide reasonable assistance with data protection impact assessments and any prior consultation with a supervisory authority that you are required to carry out.
9. Return and deletion
On expiry or termination of the Services, ZenTalk will, at your choice, delete or return Customer Personal Data and delete existing copies, unless retention is required by law. You may also export your data at any time during the term through the Services. Backups are deleted on their ordinary rotation cycle.
10. Audits
ZenTalk will make available the information reasonably necessary to demonstrate compliance with this DPA and will allow for and contribute to audits, including inspections, conducted by you or an auditor you mandate, subject to reasonable notice, confidentiality, and frequency limits, and in a way that does not compromise the security of other customers.
11. International transfers
ZenTalk hosts Customer Personal Data on Google Cloud infrastructure. Where providing the Services involves transferring personal data out of the EEA, the UK, or Switzerland to a country without an adequacy decision, that transfer is governed by the European Commission's Standard Contractual Clauses (and the UK International Data Transfer Addendum where relevant), which are incorporated into this DPA by reference and completed with the details in Annex I.
12. Liability
Each party's liability arising out of or related to this DPA is subject to the limitations and exclusions of liability set out in the Terms of Service.
Annex I. Description of processing
Parties
Data exporter: the Customer, acting as controller. Data importer: ZenTalk, acting as processor.
Subject matter and duration
Provision of the ZenTalk Services for the duration of the subscription, plus any short wind down period for return or deletion.
Nature and purpose
Hosting and processing of business communications and CRM data so you can chat, call, email, capture leads, schedule, take payments, and manage your team and customers.
Categories of data subjects
- •Your website visitors and prospects
- •Your customers and their contacts
- •Your own agents, staff, and administrators
Categories of personal data
- •Identifiers such as name, email, phone, and IP address
- •Conversation content across chat, voice, and email
- •Lead, deal, appointment, and support records
- •Files and attachments you or your visitors upload
- •Account and usage data for your team members
You control what is collected. Please do not submit special category data (such as health or biometric data) except where the Services are expressly configured for it and appropriate safeguards are in place.
Annex II. Technical and organizational measures
- •Encryption in transit with TLS 1.3 and HSTS across the suite
- •Customer payment credentials sealed with AES 256 GCM under a hardware backed master key, stored outside the database
- •Role based access control, PII redaction by role, and TOTP two factor authentication for agents
- •Refresh token reuse detection that kills a session family the moment a revoked token is replayed
- •Antivirus, magic byte sniffing, and data loss checks on every file upload
- •Threat intelligence scoring on visitor sessions to reject high risk traffic
- •Append only audit logging of consequential actions, retaining the actor even after removal
- •Secrets held in a dedicated managed vault, not in application code or the database
- •Daily database backups with cross region replication and disk snapshots
- •Secure development practices aligned to the OWASP Top 10
Annex III. Sub processors
The current list of sub processors, including infrastructure, AI, voice, email delivery, and payment providers, together with what each one does, is maintained in our privacy policy. It is updated before any new sub processor begins processing Customer Personal Data.
Contact
Questions about this DPA, or to request a countersigned copy, contact legal@usezentalk.com.
