Home/Data Processing Agreement
Trust
Data Processing Agreement
The terms on which we process personal data on your behalf. A signable copy is provided on request.
| Document | Data Processing Agreement (DPA) |
|---|---|
| Applies to | Zeplinix Technologies Private Limited and all its products and services |
| Version | 1.0 |
| Effective date | 15 July 2026 |
| Review cycle | Annually, or on material change to processing or law |
| Owner | Data Protection Officer, Zeplinix Technologies Private Limited |
| Contact | hello@zeplinix.com |
| Incorporates | UK/EU Standard Contractual Clauses, Module Two (controller to processor) |
Contents
- Scope and roles
- Definitions and order of precedence
- Processing instructions
- Subject matter, duration, nature and purpose
- Categories of data and data subjects
- Processor obligations
- Confidentiality of personnel
- Security measures
- Subprocessors
- International transfers
- Assistance to the Controller
- Personal data breach
- Data subject requests
- Audit and evidence
- Deletion and return
- Liability
- Term
- Annex 1 — Processing details
- Annex 2 — Technical and organisational measures
- Annex 3 — Subprocessors
1Scope and roles
1.1
This DPA is entered into between the customer identified in the Order (the Controller) and Zeplinix Technologies Private Limited, registered office 310, Tower 1, World Trade Center, Kharadi, Pune 411014, Maharashtra, India (the Processor).
1.2
It applies to all personal data processed by the Processor on behalf of the Controller under the services agreement between the parties.
1.3
The Controller determines the purposes and means of processing. The Processor processes only on the Controller's documented instructions.
2Definitions and order of precedence
2.1
Terms defined in Applicable Law have the same meaning here. “Applicable Law” means the UK GDPR, the EU GDPR and the Digital Personal Data Protection Act, 2023 (India), as each applies to the processing.
2.2
In the event of conflict, the order of precedence is: (a) the Standard Contractual Clauses; (b) this DPA; (c) the Terms of Service; (d) the Order.
3Processing instructions
3.1
The Controller's instructions are: to perform the Services described in the Order, applying the validation rulebook configured with the Controller, and to return the Output to the Controller.
3.2
The Processor will inform the Controller if, in its opinion, an instruction infringes Applicable Law, and may suspend the affected processing until the instruction is confirmed or amended.
3.3
The Processor will not process personal data for any purpose of its own. Specifically, it will not add Controller data to its own database, use it to enrich any other customer's data, or sell, licence or share it.
4Subject matter, duration, nature and purpose
4.1
Subject matter: validation, verification, discovery, activation, automation and managed collection of business contact records.
4.2
Duration: for the term of the services agreement, plus the retention period in clause 15.
4.3
Nature and purpose: comparison of submitted records against live sources; correction, scoring and removal of records; appending verified fields; and return of results. Details are set out in Annex 1.
5Categories of data and data subjects
5.1
Data subjects: employees, officers and workers of the Controller's target organisations, in their professional capacity.
5.2
Categories: identity data, business contact data, employment and seniority data, organisation data, and location data. Full detail in Annex 1.
5.3
The parties do not intend for special category data, criminal offence data, payment data, government identifiers or children's data to be processed. The Controller will not submit such data.
6Processor obligations
6.1
The Processor will: process only on documented instructions; ensure the confidentiality of personnel; implement the measures in Annex 2; engage subprocessors only under clause 9; assist the Controller under clause 11; notify breaches under clause 12; and delete or return data under clause 15.
6.2
The Processor maintains a record of processing activities carried out on behalf of the Controller and makes it available on request.
6.3
The Processor will not transfer personal data outside the jurisdictions listed in Annex 3 without prior written notice.
7Confidentiality of personnel
7.1
Access to personal data is restricted to personnel who need it to deliver the Services, on a named, least-privilege basis, and is logged.
7.2
All personnel are bound by written confidentiality obligations that survive the end of their engagement, and receive data protection training on induction and annually.
8Security measures
8.1
The Processor implements and maintains the technical and organisational measures set out in Annex 2, having regard to the state of the art, the cost of implementation and the risks to data subjects.
8.2
The Processor may update the measures provided the level of protection is not reduced.
9Subprocessors
9.1
The Controller gives general written authorisation for the Processor to engage subprocessors. The current list is at Annex 3 and is provided in full on request.
9.2
The Processor imposes on each subprocessor data protection obligations no less protective than those in this DPA, and remains fully liable to the Controller for the subprocessor's performance.
9.3
The Processor gives the Controller 30 days written notice before adding or replacing a subprocessor. The Controller may object on reasonable data protection grounds within that period, in which case the parties will discuss in good faith; if no resolution is reached the Controller may terminate the affected Service without penalty.
10International transfers
10.1
Where the Processor processes personal data originating in the UK or the EEA, the transfer is made under the Standard Contractual Clauses, Module Two (controller to processor), which are incorporated into this DPA by reference and completed by Annexes 1 to 3.
10.2
For UK transfers, the UK International Data Transfer Addendum to the SCCs applies.
10.3
A transfer impact assessment is maintained by the Processor and provided to the Controller on request.
11Assistance to the Controller
11.1
The Processor will assist the Controller, at the Controller's cost where the assistance is material, in: responding to data subject requests; carrying out data protection impact assessments; consulting a supervisory authority; and demonstrating compliance.
11.2
The Processor will provide the information reasonably required for the Controller to meet its own accountability obligations.
12Personal data breach
12.1
The Processor will notify the Controller of a personal data breach affecting the Controller's data without undue delay and in any event within 24 hours of becoming aware of it.
12.2
The notification will include, so far as known: the nature of the breach, the categories and approximate number of records affected, the likely consequences, and the measures taken or proposed. Where information is not available at the time, it will be provided in phases without further undue delay.
12.3
The Processor will not make any public statement identifying the Controller in connection with a breach without the Controller's prior written consent, unless legally compelled.
13Data subject requests
13.1
Where the Processor receives a request from a data subject relating to the Controller's data, it will not respond substantively but will forward the request to the Controller without undue delay and in any event within 5 business days.
13.2
The Processor will assist the Controller in fulfilling the request, including by locating, exporting, correcting or deleting the relevant records.
14Audit and evidence
14.1
The Processor will make available the information necessary to demonstrate compliance. In the first instance this is provided as documentary evidence: the security overview, the current subprocessor list, completed security questionnaires, and the summary of the most recent vulnerability scan.
14.2
Where documentary evidence is not sufficient for the Controller's regulator or auditors, the Controller may audit once in any twelve-month period on 30 days written notice, at a time that does not unreasonably disrupt processing, with auditors bound by confidentiality and the reasonable cost of the Processor's participation borne by the Controller.
14.3
An additional audit may be requested following a personal data breach affecting the Controller's data, without regard to the annual limit.
15Deletion and return
15.1
The Processor deletes Controller personal data when the relevant campaign is removed, and in all cases within 90 days of receipt, whichever is earlier.
15.2
On termination of the services agreement, all remaining Controller personal data is deleted within 30 days, or returned in a commonly used format if the Controller so elects before that period expires.
15.3
Deletion extends to backups on their normal rotation, which completes within 35 days. The Processor confirms deletion in writing on request.
15.4
The Processor may retain data only where required by law, and in that case only for as long as required and only for that purpose.
16Liability
16.1
Each party's liability under this DPA is subject to the limitations and exclusions in the Terms of Service, save that those limitations do not apply where Applicable Law prohibits their application.
16.2
Nothing in this DPA limits a data subject's rights or remedies under Applicable Law.
17Term
17.1
This DPA takes effect on the earlier of the date of the Order and the date the first personal data is submitted, and continues until all Controller personal data has been deleted or returned.
17.2
A signable copy of this DPA is available on request from hello@zeplinix.com.
Processing details
| Item | Detail |
|---|---|
| Categories of data subject | Employees, officers and workers of the Controller's target organisations, in their professional capacity |
| Categories of personal data | Name; business email; business phone; business and office address; employer; job title; seniority; tenure; employment status; stated location of the individual |
| Special category data | None. Not permitted to be submitted |
| Frequency of processing | On submission of a file, or on a schedule set by the Controller for SFTP pulls |
| Nature of processing | Comparison against live sources; correction; scoring; removal; appending verified fields; delivery of three output files |
| Purpose | To enable the Controller to assess and improve the quality of its own contact records |
| Duration | Campaign duration, capped at 90 days; 30 days after termination |
Technical and organisational measures
| Control domain | Measure |
|---|---|
| Encryption | TLS 1.2 or above in transit. AES-256 at rest. Keys managed by the hosting provider's key management service |
| Tenancy isolation | A dedicated processing workspace per Controller. No shared processing tenancy. Controller data is not pooled |
| Access control | Named accounts only; least privilege; access reviewed quarterly; access logged and reviewable; no shared credentials |
| Authentication | Multi-factor authentication required for all administrative access |
| Credential handling | The Processor holds no credentials to any Controller system. File transfer is by Controller-initiated upload or Controller-provisioned SFTP |
| Change management | Peer-reviewed changes; version control; rollback capability |
| Vulnerability management | Annual vulnerability scanning; remediation prioritised by severity; dependency monitoring |
| Logging and monitoring | Access and processing logs retained 12 months; server and security logs retained 90 days |
| Backup and recovery | Encrypted backups; rotation completes within 35 days; restoration tested annually |
| Personnel | Written confidentiality obligations; data protection training on induction and annually; access removed on the last working day |
| Incident response | Documented procedure; Controller notified within 24 hours of awareness |
| Deletion | Campaign removal or 90-day cap; 30 days after termination; backups on rotation; written confirmation on request |
| Certification status | Controls built and documented against the SOC 2 Trust Services Criteria. A third-party audit has not been completed and no SOC 2 report is claimed |
Subprocessors
A3.1
The Processor engages a small number of
subprocessors, covering cloud hosting and compute, email delivery infrastructure, and run-time
address and telephone verification services.
A3.2
The current list — naming each legal
entity, the service it provides, the categories of data it processes and the country of
processing — is provided to the Controller on request and forms part of this Annex when
provided.
A3.3
The Processor gives 30 days written
notice before adding or replacing a subprocessor, and the Controller may object under clause
9.3.
Version 1.0 · effective 15 July 2026 · Zeplinix Technologies Private Limited · hello@zeplinix.com