Zaviro
What It DoesHow It WorksFor DevelopersPricingCompanyContactAsk your AI
Sign inSign upBook a demo
Ask any AI about Zaviro

We wrote it all down for your AI.

Zaviro puts everything your business knows behind every AI you use. Copy this prompt into whichever AI you already have open, and ask it anything about us.

Paste this into your AI Chat

Read Zaviro's complete public reference in full at zaviro.ai/llms. It's written to be read by AI assistants. Give me the short version of what Zaviro is and its capabilities, then answer my follow-ups using only the document, and say so if an answer isn't in it.

Claude
ChatGPT
Perplexity
Microsoft Copilot
Le Chat
Grok
Hermes Agent
OpenClaw

Data Processing Agreement

Zaviro Software Inc.
Last updated: September 11, 2026

This Data Processing Agreement ("DPA") forms part of the Zaviro Terms of Service between Zaviro Software Inc. ("Zaviro," the "processor" or "service provider") and the customer organization ("Customer," the "controller" or "business"). It applies wherever Zaviro processes personal data within Customer Content on the Customer's behalf, and it controls over the Terms for that processing.

1. Roles and scope

For personal data contained in Customer Content (defined in the Privacy Policy), the Customer is the controller and Zaviro is the processor (GDPR), and Zaviro acts as a service provider (CCPA/CPRA). For account, billing, and usage data, Zaviro is an independent controller as described in the Privacy Policy; that processing is outside this DPA. The details of processing — subject matter, duration, nature, purposes, data categories, and data subjects — are set out in Annex 1. Where the Customer itself acts as a processor for its own client (for example, one organization deployed per client), the Customer warrants that it holds that controller's authorization to engage Zaviro as a sub-processor on these terms, and Zaviro's obligations under this DPA run to the Customer.

2. Instructions

Zaviro processes Customer Content only on the Customer's documented instructions: the Terms, this DPA, and the Customer's configuration of the service (what it connects, uploads, publishes, corrects, and deletes) are those instructions. Zaviro will inform the Customer if, in its opinion, an instruction infringes applicable data-protection law, and may suspend the affected processing until the instruction is confirmed or changed. Zaviro will not sell or share Customer Content, retain, use, or disclose it for any purpose other than providing the service (including not for training AI models), or combine it with data from other sources except as needed to provide the service — and Zaviro certifies that it understands and will comply with these restrictions.

3. Confidentiality of personnel

Zaviro ensures that every person it authorizes to process Customer Content is bound by confidentiality obligations and accesses it only as needed to operate and support the service, per the access controls described in Annex 2.

4. Security

Zaviro implements and maintains the technical and organizational measures in Annex 2. Zaviro may update those measures over time provided the overall level of protection does not materially decrease.

5. Subprocessors

The Customer authorizes the subprocessors listed in Annex 3. Zaviro will give at least 30 days' notice before adding or replacing a subprocessor that processes Customer Content (by updating the published list and notifying account owners by email). The Customer may object on reasonable data-protection grounds within that window; if the objection cannot be resolved, the Customer may terminate the affected services and delete its organization, with unused prepaid time refunded automatically per the Terms. Zaviro imposes data-protection obligations on each subprocessor no less protective than this DPA and remains responsible for their performance.

6. Assistance with data-subject requests

Taking into account the nature of the processing, Zaviro assists the Customer in fulfilling data-subject requests (access, correction, deletion, portability, objection) concerning personal data in Customer Content — primarily through the service itself: search and retrieval to locate the data, per-document download of originals, in-product correction, and deletion with derived-knowledge subtraction. Requests received directly by Zaviro from individuals whose data appears in Customer Content are forwarded to the Customer without undue delay; Zaviro does not respond on the Customer's behalf beyond acknowledging receipt and referring the individual to the Customer.

7. Assistance with security, breach, and impact assessments

Zaviro assists the Customer, insofar as reasonably possible, with the Customer's obligations regarding security, breach notification, and data-protection impact assessments, given the nature of the processing and the information available to Zaviro. Zaviro answers reasonable written security questionnaires for business customers.

8. Personal-data breach notice

Zaviro notifies the Customer without undue delay, and no later than 72 hours after confirming a personal-data breach affecting Customer Content, providing (as it becomes available): the nature of the breach, the categories and approximate volume of data and data subjects concerned, likely consequences, and the measures taken or proposed. Zaviro's own incident-response procedure (containment, assessment, record-keeping) applies in parallel.

9. Deletion and return

On termination of the services, or earlier at the Customer's instruction through the service:

  • Deleting a document permanently removes the stored original and subtracts its contribution from derived knowledge.
  • Deleting the organization permanently deletes users, content, the knowledge base, and stored files after the 30-day recovery window, per the Terms and the Privacy Policy's retention schedule (which also lists the limited operational records that survive, and backup cycling windows).
  • Return of data: source connections are read-only, so the Customer's original systems retain their data at all times; originals stored in Zaviro can be downloaded per document, and each user can export their account data, before deletion executes.

10. Audit

Zaviro makes available the information reasonably necessary to demonstrate compliance with this DPA: this DPA, the Privacy Policy, the security information published on zaviro.ai, the subprocessor list, and written answers to reasonable audit questionnaires (at most annually, absent a breach or regulator requirement). Where a supervisory authority or applicable law requires more, Zaviro will cooperate with an independent audit under confidentiality, at the Customer's cost, scheduled reasonably. Zaviro is not yet independently certified (no SOC 2 / ISO 27001); controls are designed to support those obligations.

11. International transfers

Customer Content is stored in Canada and is transferred to the United States only for the AI processing performed by the subprocessors in Annex 3, under each subprocessor's data-processing terms. Where GDPR/UK GDPR applies to a transfer, the parties rely on the safeguards identified in Annex 3 for that subprocessor (standard contractual clauses incorporated in the subprocessor's data-processing terms, or an adequacy mechanism such as the EU-US Data Privacy Framework where the subprocessor is certified).

12. CCPA/CPRA service-provider terms

To the extent the CCPA/CPRA applies, Zaviro is the Customer's service provider; the disclosures of personal information to Zaviro are for a business purpose only; Zaviro complies with the CCPA's service-provider restrictions (§2 of this DPA states them); and Zaviro will notify the Customer if it can no longer meet its obligations, upon which the Customer may take reasonable steps to stop and remediate unauthorized use.

13. Liability and order of precedence

Liability under this DPA is subject to the limitations in the Terms of Service. If this DPA conflicts with the Terms regarding the processing of personal data in Customer Content, this DPA controls. This DPA is incorporated by reference into the Terms of Service for every business customer; a countersigned copy is available on request under an Enterprise agreement.

Annex 1 — Processing details

  • Subject matter and nature: hosting, text extraction, classification, knowledge-graph construction, indexing, retrieval, and citation of Customer Content, on the Customer's instructions, to serve the Customer's own AI tools and users; and the raising of alerts from facts extracted from Customer Content. Zaviro does not generate content for the Customer; it produces summaries and descriptions of Customer Content as part of learning it.
  • Purpose: providing the Zaviro service as described in the Terms.
  • Duration: the term of the services plus the deletion windows in the Privacy Policy's retention schedule.
  • Categories of data subjects: the Customer's users; and third parties whose personal data appears inside Customer Content (correspondents in connected mailboxes, contacts in connected business systems, individuals named in documents); and, where the Customer runs a public chatbot on its own website, the Customer's website visitors, whose questions are processed transiently by the AI subprocessors in Annex 3 and are not stored by Zaviro.
  • Categories of personal data: whatever the Customer's connected sources and uploads contain — typically names, contact details, business correspondence, and commercial records. The service is not to be used for data requiring a HIPAA business associate agreement or PCI cardholder data (Terms §4).

Annex 2 — Technical and organizational measures

As maintained and further described in the Privacy Policy §8 and the security information published on zaviro.ai:

  • Read-only source connections (least-privilege read-only OAuth scopes where the provider offers them); Zaviro issues no write, send, or delete call against any connected system.
  • Structural tenant isolation: the build fails if code queries customer data without tenant scoping; per-user personal scope with no administrator override.
  • Encryption: TLS in transit; encryption at rest including field-level application encryption of document text, email bodies, summaries, and derived descriptions; credentials and tokens encrypted or stored as hashes; API keys hashed, shown once, revocable.
  • Access control: content-bearing fields excluded from internal administration tools; staff administrative access behind two-factor authentication; activity telemetry content-redacted at rest in deployed environments.
  • Account security for Customer users: two-factor authentication, passkeys, organization-wide 2FA enforcement, session management, security activity log, re-authentication for destructive actions.
  • Operational: continuous database backups with point-in-time recovery; deletion machinery that removes originals and subtracts derived knowledge; malware/spam screening on inbound email; content-based file validation.

Annex 3 — Authorized subprocessors (Customer Content)

Subprocessor
Location
Processing
Safeguard
Amazon Web Services
Canada
Hosting, storage, email delivery
AWS Data Processing Addendum
Anthropic
US
Language-model processing (extraction, knowledge graph, retrieval serving); no training on API data per commercial terms; retention up to 30 days unless zero-data-retention is in effect
Provider data-processing terms (standard contractual clauses / Data Privacy Framework where required)
OpenAI
US
Search embeddings; full processing on automatic failover (no-storage asserted on every such completion call); no training by default; retention up to 30 days unless zero-data-retention is in effect
Provider data-processing terms (standard contractual clauses / Data Privacy Framework where required)
Voyage AI
US
Search re-ranking (query + candidate passages); no training per API terms; retention per those terms
Provider data-processing terms (standard contractual clauses where required)

Providers that process only account, billing, or telemetry data (Stripe, Sentry, Twilio, PostHog, Webflow) are listed in the Privacy Policy §6 and are outside this Annex because they do not receive Customer Content.

Have questions?
Every message gets read and answered.
Contact us
Your AI brings the intelligence.
Zaviro brings your business.
start with zaviro
Start for freeBook a demo
Have questions? We’ll get you answers.
Main Pages
HomeWhat It DoesHow It WorksFor DevelopersPricingCompanyContact
Resources
Blog
Social links
LinkedIn
Zaviro
© 2026 Zaviro Software Inc. All rights reserved.
Terms of ServicePrivacy PolicyData Processing Agreement