Data Processing Agreement

How we process personal data on your behalf, including the Standard Contractual Clauses.

This Data Processing Agreement (“Data Processing Agreement”, “DPA”), entered into by and between Customer as defined under the Terms of Service (hereinafter referred to as “Customer” or “you”) and Zeta AI, Inc., a Delaware corporation doing business under the commercial name of “Viktor”, located at 2810 N Church St, PMB 20589, Wilmington, Delaware 19802 (hereinafter referred to as “Zeta AI”, “us” or “we”) is effective as of the acceptance of Terms of Service, and is subject to their provisions available here.

Customer and Zeta AI are hereinafter jointly referred to as the “Parties” and individually as the “Party”. Capitalized terms not otherwise defined herein shall have the meaning given to them in the Terms of Service. This DPA applies generally to the Processing of Personal Data under the Agreement in respect of all Customers. To the extent that any provision of this Data Processing Agreement reflects, implements, or is intended to satisfy requirements under a specific Data Protection Law, including EU Data Protection Law, the California Consumer Privacy Act, as amended by the California Privacy Rights Act, or other applicable U.S. state privacy laws, such provision shall apply only where and to the extent that the relevant Data Protection Law applies to the applicable Processing.

1. Definitions

1.1. “Business Purposes” means the limited and specified purposes for which Zeta AI may Process Personal Information as a service provider under Cal. Civ. Code § 1798.100(d)(1), consisting of: (i) providing, operating, maintaining, and improving the Services pursuant to Customer’s documented instructions; (ii) executing Customer-authorized AI-driven tasks, workflows, and automations; (iii) integrating with and processing data from Customer’s Connected Platforms solely as directed by Customer; (iv) generating Outputs in response to Customer’s prompts and instructions; (v) monitoring, securing, and maintaining the performance and integrity of the Services, including detection and prevention of fraud, abuse, and unauthorized access; (vi) providing customer support and responding to Customer’s inquiries; (vii) performing analytics on de-identified or aggregated data to operate and improve the Services; and (viii) complying with applicable legal obligations. Zeta AI shall not Process Personal Information for any purpose other than the Business Purposes or as otherwise expressly permitted by this DPA and Applicable Data Protection Laws.

1.2. “CCPA” means the California Consumer Privacy Act of 2018, Cal. Civ. Code § 1798.100 et seq., as amended, supplemented or replaced from time to time, including by the California Privacy Rights Act of 2020, and any implementing regulations issued thereunder.

1.3. “Controller” or “Data Controller” means the entity that determines the purposes and means of the Processing of Personal Data.

1.4. “Data Protection Laws” means all laws, statutes, regulations and other binding legal requirements relating to privacy, data protection, cybersecurity, data security, breach notification, or the Processing of Customer Data under the Agreement, to the extent applicable to a Party and the relevant Processing, including, as applicable, the CCPA, the GDPR, the UK GDPR, the UK Data Protection Act 2018, the Swiss Federal Act on Data Protection (“FADP”), the Delaware Personal Data Privacy Act (“DPDA”), the Virginia Consumer Data Protection Act (“VCDPA”), the Colorado Privacy Act (“CPA”), the Connecticut Data Privacy Act (“CTDPA”), the Texas Data Privacy and Security Act (“TDPSA”), the Oregon Consumer Privacy Act (“OCPA”), and any other applicable U.S. state or federal data privacy laws.

1.5. “Data Subject” means the individual to whom Personal Data relates, including Authorized Users.

1.6. “GDPR” means Regulation (EU) 2016/679 of the European Parliament and the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (also known as “General Data Protection Regulation”).

1.7. “Personal Data” or “Personal Information” means any information that identifies, relates to, describes, is reasonably capable of being associated with, or could reasonably be linked, directly or indirectly, with an identified or identifiable natural person, household, device, or other individual identifier, and that is protected as personal data, personal information, personally identifiable information, or an equivalent term under applicable Data Protection Laws. For the purposes of EU Data Protection Law, Personal Data has the meaning given to it in Article 4(1) of the GDPR.

1.8. “Processing” means any operation or set of operations which is performed upon Personal Data, whether or not by automatic means, such as collection, recording, organization, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, blocking, erasure or destruction (“Process”, “Processes” and “Processed” shall have the same meaning).

1.9. “Processor” or “Data Processor” means the entity which Processes Personal Data on behalf of the Data Controller.

1.10. “Services” means services provided by Zeta AI in accordance with the Terms of Service.

1.11. “Standard Contractual Clauses” or “SCCs” means the standard contractual clauses for the transfer of personal data to third countries adopted by the European Commission pursuant to Article 46(2)(c) of the GDPR, as set out in Commission Implementing Decision (EU) 2021/914 of 4 June 2021, as amended, replaced or superseded from time to time.

1.12. “Sub-Processor” means any third party engaged by Zeta AI to Process Personal Data on behalf of Customer in connection with the Services.

1.13. “UK Addendum” means the International Data Transfer Addendum to the EU Commission Standard Contractual Clauses issued by the UK Information Commissioner under section 119A of the UK Data Protection Act 2018, as amended, replaced, or superseded from time to time.

1.14. “UK GDPR” means Regulation (EU) 2016/679 as it forms part of the law of England and Wales, Scotland, and Northern Ireland by virtue of the European Union (Withdrawal) Act 2018, as amended, supplemented, or replaced from time to time.

2. Processing Of Personal Data

2.1. Customer is the Controller of Personal Data Processed under this DPA, and Zeta AI Processes such Personal Data on behalf of Customer as Processor. Where Customer acts as a Processor on behalf of a third-party Controller, Zeta AI acts as Customer’s Sub-Processor. The terms of this DPA shall apply to either of the relations between the Parties regarding the Processing of Personal Data mentioned herein.

2.2. Within the scope of this DPA, Customer hereby engages Zeta AI to Process Personal Data on Customer’s behalf. Zeta AI will only Process Personal Data on your behalf and in accordance with your instructions (including via product settings, messaging-platform commands, and APIs), unless required by law. The instructions from the Customer to Process Personal Data are the following: (i) Processing shall be carried out in accordance with this DPA, the Terms of Service and pursuant to the features and limitations of the applicable Services which Zeta AI provides to Customer; and (ii) Processing shall be carried out in compliance with other reasonable instructions provided by the Customer, where such instructions are consistent with the Terms of Service. Zeta AI will be under no obligation to comply with instructions that Zeta AI deems as violating applicable laws. Processing outside the scope of this DPA (if any) will require: (i) prior written agreement between Customer and Zeta AI, and (ii) Customer’s additional instructions for processing. Zeta AI shall notify Customer if, in Zeta AI’s reasonable opinion, an instruction infringes or is likely to infringe applicable Data Protection Laws, unless Zeta AI is prohibited from doing so under applicable law.

2.3. Zeta AI Processes Personal Data solely to provide, maintain, support, secure, and improve the Services in accordance with the Terms of Service, this DPA, and Customer’s documented instructions. This includes Processing necessary to enable access to the Services, integrate the Services with Customer’s Connected Platforms, execute AI-driven tasks and workflows, generate Outputs, perform Customer-authorized actions, provide support, monitor Service performance and security, prevent abuse, fraud, unauthorized access, or misuse, and comply with applicable legal obligations. Zeta AI may also use aggregated, de-identified, or anonymized data derived from Customer’s use of the Services for testing, development, security, analytics, operation, and improvement of the Services, provided that such data does not identify and cannot reasonably be used to identify Customer, Authorized Users or any other individual. The Services constitute a business-to-business (B2B) platform made available exclusively to corporate customers and other legal entities for use in their internal business operations. The Services are not directed to, and are not intended for use by, natural persons acting as consumers within the meaning of any Applicable Data Protection Laws or automated decision-making technology (ADMT) regulations.

2.4. Zeta AI shall not, and shall ensure that its AI model providers do not, use Customer Personal Data to train general-purpose or generalized AI models, or for advertising, cross-context behavioral advertising, or similar profiling purposes.

2.5. Google API Services User Data Policy. To the extent Zeta AI accesses, receives, or Processes Google user data through Google APIs in connection with the Services, including data from Google Drive, Google Calendar, Gmail, Google Workspace, or other Google services, Zeta AI shall comply with the Google API Services User Data Policy, including the applicable Limited Use requirements. Without limiting the foregoing, Zeta AI shall: (i) use such Google user data only to provide, maintain, secure, or improve user-facing features of the Services that are disclosed to Customer or the relevant user; (ii) not allow human access to such Google user data except with the user’s affirmative consent, as necessary for security purposes, to comply with applicable law, or as otherwise permitted under the Google API Services User Data Policy; (iii) not sell such Google user data or use or transfer it for advertising, including retargeting, personalized advertising, interest-based advertising, or cross-context behavioral advertising; (iv) not use or transfer such Google user data to train generalized, non-personalized, or general- purpose AI or machine-learning models; and (v) delete Google-derived data following disconnection of the relevant Google integration, deletion of the applicable Customer account, or Customer’s documented instruction, in accordance with this DPA and applicable Data Protection Laws.

2.6. The Personal Data Processed by Zeta AI on behalf of Customer may include Personal Data contained in Customer Data or otherwise submitted to, generated by, or accessed through the Services, including Personal Data relating to Authorized Users, prompts, instructions, configurations, approval settings, Outputs, Connected Platform content, messages, files, workspace or channel information, account identifiers, usage data, logs, device and browser information, IP addresses, and authentication or authorization data.

2.7. Customer shall not submit, make available, or otherwise cause Zeta AI to Process any Regulated Data as defined in the Terms of Service, unless expressly agreed in writing between the Parties and subject to any additional safeguards, terms, or addenda required under applicable Data Protection Laws. Customer acknowledges that Regulated Data is not necessary for the standard use of the Services and that the Services are not designed, certified, or intended to process such data.

2.8. Customer is responsible for ensuring that its use of the Services complies with applicable Data Protection Laws, including the GDPR, the CCPA, and any other laws applicable to Customer’s use of the Services. To the extent required under Data Protection Laws, Customer shall provide appropriate notices to Data Subjects and obtain and document all consents, authorizations, permissions, or other legal bases required in connection with the Processing of Personal Data through the Services. In particular, Customer shall ensure that it is authorized to submit Customer Data to the Services, connect any Connected Platform, grant Zeta AI the relevant access permissions, and permit Zeta AI to Process Personal Data from such Connected Platforms on Customer’s behalf. Customer shall also ensure that Authorized Users and other relevant individuals are provided with appropriate privacy notices describing the Processing of their Personal Data through the Services, including the use of AI-driven functionality, integrations with Connected Platforms, and Customer-authorized actions or workflows, to the extent required by applicable Data Protection Laws.

2.9. Customer represents and warrants that it has all rights, permissions, authorizations, notices, consents, and legal bases required under applicable Data Protection Laws to instruct Zeta AI to Process Personal Data on Customer’s behalf in connection with the Services.

2.10. To the extent that Zeta AI Processes Personal Information subject to the CCPA on behalf of Customer, the Parties acknowledge and agree that Customer acts as a “business” and Zeta AI acts as a “service provider” or “contractor”, as applicable, within the meaning of the CCPA. Zeta AI shall not sell or share such Personal Information, retain, use, or disclose such Personal Information for any purpose other than the Business Purposes (as defined in Section 1 of this DPA) or as otherwise permitted by the CCPA, retain, use, or disclose such Personal Information for any commercial purpose other than such Business Purposes, or retain, use, or disclose such Personal Information outside the direct business relationship between Customer and Zeta AI, except as permitted by the CCPA. Zeta AI shall not combine Personal Information received from or on behalf of Customer with Personal Information received from another source or collected from Zeta AI’s own interaction with the relevant consumer, except as permitted by the CCPA. Zeta AI shall comply with applicable obligations under the CCPA and provide the same level of privacy protection as required by the CCPA. Zeta AI shall provide reasonable assistance to Customer in responding to verifiable consumer requests under the CCPA, to the extent Zeta AI Processes the relevant Personal Information on Customer’s behalf and such assistance is required for Customer to comply with the CCPA. Customer shall have the right to take reasonable and appropriate steps to ensure that Zeta AI uses Personal Information in a manner consistent with Customer’s obligations under the CCPA. Upon notice, Customer may take reasonable and appropriate steps to stop and remediate any unauthorized use of Personal Information by Zeta AI. Zeta AI shall notify Customer if it determines that it can no longer meet its obligations under the CCPA. Zeta AI certifies that it understands the restrictions set out in this Section and will comply with them.

3. Rights Of Data Subjects

3.1. Zeta AI shall notify Customer via e-mail promptly, and in any event within five (5) business days of receipt, if it receives a request from a Data Subject in the subject of access to, correction, amendment, deletion of or objection to the processing of that Data Subject’s Personal Data. Zeta AI shall not respond to any such Data Subject request without Customer’s prior written consent, except in order to confirm that the request relates to the Customer.

3.2. To the extent that Customer responds to any such Data Subject request, Zeta AI shall provide Customer, to the extent required by law, with commercially reasonable cooperation and assistance in relation to handling of a Data Subject’s request, to the extent legally permitted.

3.3. Zeta AI may charge additional fees for any assistance, cooperation, audit support, data export, consultation, or other actions requested by Customer in connection with this DPA, including where such activities require material time, resources, or involvement beyond Zeta AI’s standard self- service functionality, documentation, or ordinary-course compliance support, to the extent permitted under applicable Data Protection Laws and the Agreement.

4. Zeta Ai’S Obligations

4.1. Zeta AI shall ensure that any personnel authorized to Process Personal Data are informed of the confidential nature of such Personal Data, receive appropriate training regarding their responsibilities, and are bound by appropriate contractual or statutory obligations concerning confidentiality, data protection, and data security. Zeta AI shall ensure that such confidentiality obligations survive the termination of the relevant individual’s employment or other engagement with Zeta AI.

4.2. Zeta AI shall ensure that access to Personal Data is limited only to those members of personnel who require that access in order to fulfil Zeta AI’s obligations under the Terms of Service.

4.3. Zeta AI shall provide Customer with reasonable assistance, taking into account the nature of the Processing and the information available to Zeta AI, in ensuring compliance with Customer’s obligations under Articles 32 to 36 of the GDPR, including obligations relating to security of Processing, Personal Data breach notification, data protection impact assessments, and prior consultation with supervisory authorities, to the extent applicable.

4.4. Zeta AI shall implement and maintain appropriate technical and organizational measures designed to ensure a level of security appropriate to the risk, taking into account the nature, scope, context, and purposes of the Processing, as well as the risks to the rights and freedoms of natural persons.

4.5. Zeta AI maintains an information security program aligned with the AICPA Trust Services Criteria for Security, Confidentiality, Availability, and Privacy. As of 9 October 2025, the Viktor system has been subject to an independent SOC 2 examination (the “SOC 2 Report”). Subject to applicable confidentiality requirements, Zeta AI may make the SOC 2 Report or an executive summary thereof available to Customer upon reasonable written request.

4.6. Zeta AI maintains reasonable technical and organizational measures (“TOMs”) appropriate to the risk, designed to protect Customer Personal Data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to such data. These include: (i) encryption in transit and at rest; (ii) access controls and least-privilege authorization for personnel with a business need; (iii) logging and monitoring of production systems; (iv) processes to back up and recover data and to delete data in accordance with Section 9; and (v) risk-based security policies, procedures, and training, as further described in Annex II.

4.7. TOMs implemented by Zeta AI are described in Annex II to the SCCs and/or in Zeta AI’s applicable security documentation made available to Customer.

4.8. Zeta AI represents that, to its knowledge as of the effective date of this DPA, it has applied commercially reasonable efforts to ensure that the data and materials used to train the artificial intelligence models underlying the Services (“Training Data”) were sourced from providers that Zeta AI in good faith believed to be legally authorized to make such data available for use in training artificial intelligence models. EXCEPT AS EXPRESSLY STATED IN THIS SECTION 4.8, ZETA AI MAKES NO REPRESENTATION OR WARRANTY, EXPRESS OR IMPLIED, REGARDING THE COMPOSITION, PROVENANCE, LICENSING STATUS, OR INTELLECTUAL PROPERTY CLEARANCE OF ANY TRAINING DATA. Any liability of Zeta AI arising out of or in connection with Training Data shall be subject to the limitations set forth in Section 11 of this DPA. For clarity, Training Data does not include Customer Personal Data, which is not used to train general-purpose models under Section 2.4.

5. Audit Right

5.1. To the extent that the Data Protection Laws require you to be in a position to monitor the adequate Processing of Personal Data, you as the Customer have the right to request an audit from Zeta AI to the extent necessary to review whether we as Zeta AI and our Sub-Processors are compliant with the following regulations: (i) any provisions of the applicable Data Protection Law, (ii) the terms of this DPA, and (iii) Customer’s instructions.

5.2. Zeta AI maintains independent third-party assessments of its security, confidentiality, availability, and privacy controls, including a SOC 2 report or successor report covering substantially similar Trust Services Criteria. Upon Customer’s reasonable written request, and no more than once in any twelve (12)-month period unless required by applicable law or following a Security Breach (as defined in Section 6.1) materially affecting Customer Personal Data, Zeta AI will make available to Customer, subject to reasonable confidentiality obligations, a copy or executive summary of its then-current SOC 2 report and/or similar independent assessment reports.

5.3. Upon Customer’s reasonable written request, no more than once in any twelve (12)-month period unless required by applicable law, requested by a competent supervisory authority, or following a Security Breach (as defined in Section 6.1) materially affecting Customer Personal Data, Zeta AI shall make available information reasonably necessary to demonstrate compliance with this DPA. Such information may include security whitepapers, policy summaries, the then-current SOC 2 report, or similar independent assessment reports.

5.4. If Customer, acting reasonably and in good faith, determines that the information made available by Zeta AI is insufficient to demonstrate compliance with this DPA, or where required under applicable Data Protection Laws or requested by a competent supervisory authority, Customer may conduct a targeted audit, either itself or through an independent auditor bound by appropriate confidentiality obligations. Such audit shall be subject to at least thirty (30) days’ prior written notice, be conducted during normal business hours, and be carried out in a manner that protects confidentiality and security and does not unreasonably disrupt Zeta AI’s business, systems, or operations. Remote and document-based audits shall be preferred. Audits shall be conducted at Customer’s expense.

5.5. Nothing in this Section limits any audit or inspection rights granted to the data exporter or competent supervisory authority under the Standard Contractual Clauses, to the extent applicable.

6. Security Breach Management And Notification

6.1. If Zeta AI becomes aware of any accidental or unlawful destruction, loss, alteration, unauthorized disclosure of or access to any Personal Data transmitted, stored, or otherwise Processed on Zeta AI’s equipment or in Zeta AI’s facilities (“Security Breach”), Zeta AI will without undue delay, and in any event within seventy-two (72) hours of becoming aware of the Security Breach: (i) notify the Customer of the Security Breach; (ii) investigate the Security Breach and provide Customer with all relevant information about the Security Breach; and (iii) take all commercially reasonable steps to mitigate the effects and minimize any damage resulting from the Security Breach. Where the Security Breach constitutes a “breach of security” or similar term under applicable U.S. state data breach notification laws, Zeta AI shall provide notifications required of a data processor or service provider under such laws.

7. Subprocessing

7.1. Customer authorizes Zeta AI to appoint Sub-Processors in order to provide the Services. Where Article 28 of the GDPR applies, Zeta AI shall ensure that each Sub-Processor is bound by a written agreement satisfying the requirements of Article 28 of the GDPR, including obligations relating to appropriate technical and organizational measures under Article 32 of the GDPR. Zeta AI shall remain liable to Customer for the performance of each Sub-Processor’s data protection obligations.

7.2. Zeta AI may continue to use the Sub-Processors already engaged by Zeta AI according to this DPA.

7.3. It is acknowledged and agreed by the Customer that Zeta AI uses the Sub-Processors listed in Section 4 of the Privacy Policy (available at viktor.com/legal/privacy) and in Zeta AI’s Trust Center (trust.zetalabs.ai) for the purpose of providing its Services.

7.4. Zeta AI shall notify Customer of any intended addition or replacement of a Sub-Processor by email to Customer’s account administrator and by posting an update to Zeta AI’s legal notices page at viktor.com/legal. Customer may object to the proposed addition or replacement in writing within thirty (30) days from the date of such notice, provided that the objection is based on reasonable data protection grounds. If Customer objects within that period, Zeta AI shall not appoint the proposed Sub-Processor for the Processing of Customer Personal Data until Zeta AI has taken reasonable steps to address Customer’s objection and has provided Customer with a reasonable explanation of the steps taken. If the objection is not resolved within fifteen (15) days after Zeta AI’s receipt of the objection, Customer may terminate the affected Services without penalty, to the extent such Services require the use of the proposed Sub-Processor. Such termination shall not give rise to any liability for either Party, except for payment obligations accrued before the effective date of termination.

7.5. Zeta AI may, upon Customer’s instruction or authorization, enable integrations between the Services and third-party platforms, applications, or services designated, selected, or enabled by Customer (“Customer-Enabled Integrations”). Customer acknowledges that such third-party providers are not Sub-Processors of Zeta AI solely by virtue of such integration, unless they are expressly listed as Zeta AI’s Sub-Processors. To the extent any such third-party provider acts as Zeta AI’s Sub-Processor, Zeta AI shall ensure that such provider is included in the applicable list of Sub-Processors made available to Customer according to point 7.3. above. Customer is solely responsible for reviewing, approving, and managing its use of Customer-Enabled Integrations and for any Processing of Personal Data by such third-party providers outside Zeta AI’s control.

7.6. Where Customer connects, authorizes, or enables third-party tools, platforms, or services through the Services, any data flows initiated, configured, or authorized by Customer through such integrations are governed by Customer’s own relationship and agreements with the relevant third- party providers. Such providers shall not be deemed Zeta AI’s Sub-Processors solely because Customer connects or uses them through the Services. Certain such providers may also be listed as Zeta AI’s Sub-Processors where Zeta AI independently engages them to provide, operate, maintain, secure, or support the Services. In such case, the provider’s status as Zeta AI’s Sub-Processor applies only to Zeta AI’s own use of that provider’s services in connection with the Services, and not to Customer’s separate use of, or relationship with, that provider.

7.7. Notwithstanding the provisions above, you hereby authorize Zeta AI to subcontract the Processing to the Sub-Processors based outside of the European Economic Area (EEA) to the extent necessary to duly perform the Service(s), under the condition that the Sub-Processors will provide sufficient guarantees in relation to the required level of data protection, e.g. through a subcontracting agreement based on the Standard Contractual Clauses adopted by the European Commission or another applicable transfer mechanism under Data Protection Laws.

8. Transborder Data Transfers

8.1. Zeta AI stores and routinely Processes Customer Personal Data in environments located in the United States. Any transfer of Personal Data from the EEA, the United Kingdom, Switzerland, or any other jurisdiction requiring a transfer mechanism shall be governed by the applicable transfer mechanism set out in this DPA or otherwise permitted under applicable Data Protection Laws. Any multi-region redundancy, backup, or disaster recovery environment shall be limited to regions disclosed in this DPA, the applicable Sub-Processor list, Zeta AI’s security documentation, or otherwise permitted under applicable Data Protection Laws. Incidental cross-border transit of Personal Data may occur in the ordinary course of internet routing, network operations, or service delivery.

8.2. Due to the fact that the Zeta AI comes from a third country within the meaning of the GDPR, the Parties conclude Standard Contractual Clauses (the SCCs) in the wording given by Commission Implementing Decision (EU) 2021/914 of 4 June 2021 and supplemented as specified in this paragraph. Such amended SCCs constitute the integral part of the DPA. Module Two shall apply where Customer acts as Controller and Zeta AI acts as Processor. Module Three shall apply where Customer acts as Processor and Zeta AI acts as Sub-Processor.

8.3. With regard to Section 8.1. above, the Parties agree to incorporate the SCCs into this DPA as follows: (i) accept provisions of the clauses in Module 2 – Transfer controller to processor and Module 3 - Transfer processor to processor; (ii) delete the Clause 7 (Docking Clause); (iii) choose the following wording in the Clause 9 (Use of sub-processors): „GENERAL WRITTEN AUTHORISATION The data importer has the data exporter’s general authorization for the engagement of sub-processor(s) from an agreed list. The data importer shall specifically inform the data exporter in writing of any intended changes to that list through the addition or replacement of sub-processors at least 30 days in advance, thereby giving the data exporter sunicient time to be able to object to such changes prior to the engagement of the sub- processor(s). The data importer shall provide the data exporter with the information necessary to enable the data exporter to exercise its right to object.” (iv) delete optional provision in Clause 11 point (a) (Redress); (v) give the Clause 17 (Governing law) the following wording: “These Clauses shall be governed by the law of one of the EU Member States, provided such law allows for third- party beneficiary rights. The Parties agree that this shall be the law of Ireland.”; (vi) in Clause 18 (Choice of forum and jurisdiction) complete point (b) as below: “The Parties agree that those shall be the courts of Ireland”.

8.4. The Appendix to the SCCs, as completed in this DPA, forms an integral part of the SCCs and this DPA.

8.5. To the extent that a transfer of Personal Data under this DPA is subject to the UK GDPR and constitutes a restricted transfer from the United Kingdom to a third country not subject to an adequacy regulation under UK Data Protection Laws, the Parties agree that the UK Addendum shall apply and shall be incorporated into this DPA. The UK Addendum shall be completed by reference to the information set out in this DPA and the Appendix to the SCCs, including the details of the Parties, description of the transfer, technical and organisational measures, and selected modules of the SCCs. In the event of any conflict between the UK Addendum and this DPA, the UK Addendum shall prevail to the extent required for the relevant restricted transfer.

8.6. For the purposes of the UK Addendum, the selected SCCs shall be the SCCs incorporated into this DPA, as amended and completed in accordance with this Section. The Parties agree that the UK Addendum shall be completed as follows: (i) Table 1 - Parties. The start date shall be the effective date of this DPA. The data exporter shall be Customer, acting as Controller or Processor, as applicable. The data importer shall be Zeta AI, Inc., acting as Processor or Sub-Processor, as applicable, with the address and contact details set out in this DPA. (ii) Table 2 - Selected SCCs, Modules and Selected Clauses. The Addendum EU SCCs shall be the SCCs incorporated into this DPA, including Module Two where Customer acts as Controller and Zeta AI acts as Processor, and Module Three where Customer acts as Processor and Zeta AI acts as Sub-Processor. (iii) Table 3 - Appendix Information. The Appendix Information shall be completed by reference to the Appendix to the SCCs set out in this DPA, including the details of the Parties, description of the transfer, technical and organizational measures, and Sub-Processor information made available in accordance with this DPA. (iv) Table 4 - Ending this Addendum when the Approved Addendum changes. Neither Party may end the UK Addendum under Section 19 of the UK Addendum. (v) Governing Law and Jurisdiction. For the purposes of the UK Addendum, the governing law shall be the laws of England and Wales, and the courts of England and Wales shall have jurisdiction, unless otherwise required under the UK Addendum. (vi) Supervisory Authority. For the purposes of the UK Addendum and UK restricted transfers, the relevant supervisory authority shall be the UK Information Commissioner’s Office.

8.7. To the extent that a transfer of Personal Data under this DPA is subject to the Swiss Federal Act on Data Protection (“FADP”) and constitutes a transfer from Switzerland to a country that does not provide an adequate level of data protection under the FADP, the Parties agree that the SCCs shall apply to such transfer as amended by this Section. For Swiss transfers: (a) references in the SCCs to the GDPR shall be deemed to include the FADP to the extent applicable; (b) references to “Member State” or “EU Member State” shall be interpreted to include Switzerland where required to give effect to the SCCs for Swiss transfers; (c) references to the “competent supervisory authority” shall be deemed to refer to the Swiss Federal Data Protection and Information Commissioner (“FDPIC”) to the extent the relevant transfer is governed by the FADP; and (d) references to Personal Data shall include personal data protected under the FADP.

8.8. Data Subjects whose Personal Data is transferred from Switzerland may exercise and enforce their rights under the SCCs in Switzerland to the extent required under the FADP.

9. Term And Retention Period

9.1. This DPA automatically supplements the agreement concluded by and between you and Zeta AI under Zeta AI’s Terms of Service when you create your Zeta AI account.

9.2. This DPA shall remain in force for as long as Zeta AI Processes Personal Data on behalf of Customer in connection with the Services. Upon termination or expiry of the Agreement, deletion of Customer’s Zeta AI account, or otherwise after the end of the provision of the Services involving the Processing of Personal Data, Zeta AI shall, at Customer’s choice, return or delete Personal Data Processed on behalf of Customer, unless applicable law requires Zeta AI to retain such Personal Data or to the extent such Personal Data is subject to a reasonable legal hold imposed in connection with pending or reasonably anticipated litigation, regulatory investigation, or other legal proceedings. Customer may request the return, export, or deletion of Personal Data by documented written instruction, including during the term of this DPA, provided that deletion may affect the availability of the Services or Customer’s ability to access or recover such Personal Data. If Customer does not request the return or export of Personal Data within one (1) month following termination, expiry, or account deletion, Customer hereby instructs Zeta AI to delete such Personal Data, including existing copies, from Zeta AI’s systems in accordance with Zeta AI’s standard deletion procedures. After expiry of that period, Personal Data may no longer be available to Customer and may not be recoverable. Upon Customer's written request made within sixty (60) days of completion of such deletion, Zeta AI shall provide written confirmation that Customer Personal Data has been deleted from Zeta AI's systems in accordance with this Section 9.2. Zeta AI shall not be responsible for any loss of access to Personal Data resulting from deletion carried out in accordance with Customer’s documented instruction or this Section 9.2.

10. Notices And Contact

10.1. If you wish to make any inquiries about this DPA, please contact us at legal@viktor.com.

11. Indemnification And Limitation Of Liability

11.1. To the maximum extent permitted by applicable law, Customer shall indemnify and hold Zeta AI, its officers, directors, employees, contractors, and agents harmless from and against all claims, liabilities, administrative fines, suits, judgments, actions, investigations, settlements, penalties, fines, damages and losses, demands, costs, expenses, and fees including reasonable attorneys’ fees and expenses, arising out of or in connection with any claims, demands, investigations, proceedings, or actions brought by data subjects, legal persons (e.g., corporations and organizations), or supervisory authorities under the data protection laws that apply to Zeta AI in respect of processing of Personal Data on behalf of Customer through Services. It includes the ones arising from Customer’s breach of this DPA, Customer’s instructions, Customer’s violation of applicable Data Protection Laws, Customer’s failure to provide required notices or obtain required consents or legal bases, or Customer’s submission of Personal Data to the Services in violation of the Agreement or this DPA.

11.2. The liability of each party under this DPA shall be subject to the exclusions and limitations of liability set out in the Terms of Service.

12. Final Provisions

12.1. In the event of any conflict or inconsistency between this DPA, the Terms of Service, the applicable Standard Contractual Clauses, and, where applicable, the UK Addendum: (i) the applicable Standard Contractual Clauses shall prevail to the extent the conflict or inconsistency relates to international transfers of Personal Data governed by those clauses, including transfers from the EEA and, as amended for Swiss transfers, transfers subject to the Swiss FADP; (ii) the UK Addendum shall prevail to the extent the conflict or inconsistency relates to restricted transfers of Personal Data subject to the UK GDPR; (iii) subject to the foregoing, this DPA shall prevail over the Terms of Service with respect to the Processing of Personal Data; and (iv) the Terms of Service shall apply to all matters not expressly governed by this DPA, the applicable Standard Contractual Clauses, or the UK Addendum, as applicable.

Appendix to the Standard Contractual Clauses

Annex I

A. List of Parties

Data exporter(s):

  • Name: the Customer
  • Address: as provided in the Order Form
  • Contact person’s name, position and contact details: as provided in the Order Form
  • Activities relevant to the data transferred under these Clauses: as provided in the DPA.
  • Role: Controller or Processor of Personal Information.

Data importer(s):

  • Name: Zeta AI
  • Address: as provided in the DPA.
  • Contact person’s name, position and contact details: Contact details for the data importer are provided in the DPA.
  • Activities relevant to the data transferred under these Clauses: The data importer provides the Services to the data exporter in accordance with the DPA.
  • Role: Processor or Sub-Processor of Personal Data

B. Description of Transfer

Categories of data subjects whose personal data is transferred

As provided in the DPA.

Categories of personal data transferred

As provided in the DPA.

Sensitive data transferred (if applicable) and applied restrictions or safeguards

Sensitive data transferred (if applicable) and applied restrictions or safeguards that fully take into consideration the nature of the data and the risks involved, such as for instance strict purpose limitation, access restrictions (including access only for staff having followed specialised training), keeping a record of access to the data, restrictions for onward transfers or additional security measures.

Not applicable.

The frequency of the transfer

The frequency of the transfer (e.g. whether the data is transferred on a one-off or continuous basis). The data is transferred on a continuous basis until it is deleted in accordance with the terms of the DPA.

Nature of the processing

The data importer will Process Personal Data as described in the DPA and the Agreement, including accessing, storing, organizing, structuring, retrieving, consulting, using, analyzing, transmitting, disclosing, making available, deleting, and otherwise Processing Personal Data as necessary to provide the Services.

Purpose(s) of the data transfer and further processing

The data importer will Process Personal Data as necessary to provide the Services in accordance with the DPA and the Agreement, including by enabling integrations with Customer’s Connected Platforms, executing Customer-authorized tasks and workflows, generating Outputs, and maintaining, supporting, and securing the Services.

The period for which the personal data will be retained, or, if that is not possible, the criteria used to determine that period

Personal Data shall be retained for the duration of the Services and thereafter for the period necessary to allow Customer to retrieve or export Personal Data, unless earlier deletion is requested by Customer or retention is required by applicable law. If Customer does not request return or export within one (1) month following termination, expiry, or account deletion, Zeta AI shall delete Personal Data in accordance with this DPA and its standard deletion procedures, unless applicable law requires retention.

For transfers to (sub-) processors, also specify subject matter, nature and duration of the processing

As provided in section 7 of the DPA.

C. Competent Supervisory Authority – Irish Data Protection Commission

EU Representative (Art. 27 GDPR)

Paweł Siuciak, Zeta AI, Inc., pawel@zetalabs.ai, ul. Rondo Daszyńskiego 1, 00-843 Warsaw, Poland.

Annex II – Technical and Organisational Measures

The data importer implements and maintains the following technical and organisational measures: (i) encryption of personal data in transit (TLS 1.2 or higher) and at rest; (ii) role-based access controls applying least-privilege principles, with single sign-on and multi-factor authentication for personnel access; (iii) logging and monitoring of production systems; (iv) data backup, recovery, and deletion processes in accordance with Section 9 of this DPA; (v) personnel confidentiality obligations and security training; (vi) an information security program supported by an independent SOC 2 examination; and (vii) the further measures described in Zeta AI’s Trust Center at trust.zetalabs.ai, which forms part of Zeta AI’s security documentation referenced in Section 4.7.

General description of the technical and organisational measures implemented by the data importer(s) (including any relevant certifications) to ensure an appropriate level of security, taking into account the nature, scope, context and purpose of the processing, and the risks for the rights and freedoms of natural persons is provided here.

Get Started for Free