This Data Processing Agreement ("DPA") forms part of the Zaviro Terms of Service between Zaviro Software Inc. ("Zaviro," the "processor" or "service provider") and the customer organization ("Customer," the "controller" or "business"). It applies wherever Zaviro processes personal data within Customer Content on the Customer's behalf, and it controls over the Terms for that processing.
For personal data contained in Customer Content (defined in the Privacy Policy), the Customer is the controller and Zaviro is the processor (GDPR), and Zaviro acts as a service provider (CCPA/CPRA). For account, billing, and usage data, Zaviro is an independent controller as described in the Privacy Policy; that processing is outside this DPA. The details of processing — subject matter, duration, nature, purposes, data categories, and data subjects — are set out in Annex 1. Where the Customer itself acts as a processor for its own client (for example, one organization deployed per client), the Customer warrants that it holds that controller's authorization to engage Zaviro as a sub-processor on these terms, and Zaviro's obligations under this DPA run to the Customer.
Zaviro processes Customer Content only on the Customer's documented instructions: the Terms, this DPA, and the Customer's configuration of the service (what it connects, uploads, publishes, corrects, and deletes) are those instructions. Zaviro will inform the Customer if, in its opinion, an instruction infringes applicable data-protection law, and may suspend the affected processing until the instruction is confirmed or changed. Zaviro will not sell or share Customer Content, retain, use, or disclose it for any purpose other than providing the service (including not for training AI models), or combine it with data from other sources except as needed to provide the service — and Zaviro certifies that it understands and will comply with these restrictions.
Zaviro ensures that every person it authorizes to process Customer Content is bound by confidentiality obligations and accesses it only as needed to operate and support the service, per the access controls described in Annex 2.
Zaviro implements and maintains the technical and organizational measures in Annex 2. Zaviro may update those measures over time provided the overall level of protection does not materially decrease.
The Customer authorizes the subprocessors listed in Annex 3. Zaviro will give at least 30 days' notice before adding or replacing a subprocessor that processes Customer Content (by updating the published list and notifying account owners by email). The Customer may object on reasonable data-protection grounds within that window; if the objection cannot be resolved, the Customer may terminate the affected services and delete its organization, with unused prepaid time refunded automatically per the Terms. Zaviro imposes data-protection obligations on each subprocessor no less protective than this DPA and remains responsible for their performance.
Taking into account the nature of the processing, Zaviro assists the Customer in fulfilling data-subject requests (access, correction, deletion, portability, objection) concerning personal data in Customer Content — primarily through the service itself: search and retrieval to locate the data, per-document download of originals, in-product correction, and deletion with derived-knowledge subtraction. Requests received directly by Zaviro from individuals whose data appears in Customer Content are forwarded to the Customer without undue delay; Zaviro does not respond on the Customer's behalf beyond acknowledging receipt and referring the individual to the Customer.
Zaviro assists the Customer, insofar as reasonably possible, with the Customer's obligations regarding security, breach notification, and data-protection impact assessments, given the nature of the processing and the information available to Zaviro. Zaviro answers reasonable written security questionnaires for business customers.
Zaviro notifies the Customer without undue delay, and no later than 72 hours after confirming a personal-data breach affecting Customer Content, providing (as it becomes available): the nature of the breach, the categories and approximate volume of data and data subjects concerned, likely consequences, and the measures taken or proposed. Zaviro's own incident-response procedure (containment, assessment, record-keeping) applies in parallel.
On termination of the services, or earlier at the Customer's instruction through the service:
Zaviro makes available the information reasonably necessary to demonstrate compliance with this DPA: this DPA, the Privacy Policy, the security information published on zaviro.ai, the subprocessor list, and written answers to reasonable audit questionnaires (at most annually, absent a breach or regulator requirement). Where a supervisory authority or applicable law requires more, Zaviro will cooperate with an independent audit under confidentiality, at the Customer's cost, scheduled reasonably. Zaviro is not yet independently certified (no SOC 2 / ISO 27001); controls are designed to support those obligations.
Customer Content is stored in Canada and is transferred to the United States only for the AI processing performed by the subprocessors in Annex 3, under each subprocessor's data-processing terms. Where GDPR/UK GDPR applies to a transfer, the parties rely on the safeguards identified in Annex 3 for that subprocessor (standard contractual clauses incorporated in the subprocessor's data-processing terms, or an adequacy mechanism such as the EU-US Data Privacy Framework where the subprocessor is certified).
To the extent the CCPA/CPRA applies, Zaviro is the Customer's service provider; the disclosures of personal information to Zaviro are for a business purpose only; Zaviro complies with the CCPA's service-provider restrictions (§2 of this DPA states them); and Zaviro will notify the Customer if it can no longer meet its obligations, upon which the Customer may take reasonable steps to stop and remediate unauthorized use.
Liability under this DPA is subject to the limitations in the Terms of Service. If this DPA conflicts with the Terms regarding the processing of personal data in Customer Content, this DPA controls. This DPA is incorporated by reference into the Terms of Service for every business customer; a countersigned copy is available on request under an Enterprise agreement.
As maintained and further described in the Privacy Policy §8 and the security information published on zaviro.ai:
Providers that process only account, billing, or telemetry data (Stripe, Sentry, Twilio, PostHog, Webflow) are listed in the Privacy Policy §6 and are outside this Annex because they do not receive Customer Content.