Data Processing Addendum

Last updated 9 August 2026

Forms part of the Terms of Service where Zealoop processes personal data on your behalf. You are the controller; we are the processor.

1. Roles

You are the controller of the personal data you put into a workspace and of the conversations your visitors have with the agent. Zealoop, Inc. is the processor. We process that data only on your documented instructions, which are: this addendum, the Terms, and the configuration you set in the dashboard.

Where we act as a controller — for your own account details — the Privacy Policy applies instead.

2. Subject matter and duration

Provision of an AI support agent, for as long as your workspace exists, plus the retention windows set out in the Privacy Policy.

3. Nature and purpose of processing

4. Categories of data subject and personal data

Data subjectsPersonal data
Your end usersEmail address, display name, verification status, message content, and whatever fields you place in a table row
Your teamName, email address, role, activity within the workspace

Special-category data is out of scope. Do not put it into a workspace without a separate written agreement with us — see Terms, section 4.

5. Our obligations

6. Subprocessors

You give general authorisation for us to engage subprocessors. The current list is published at Subprocessors. We will give at least 30 days’ notice before adding or replacing one, and you may object on reasonable data-protection grounds — if we cannot resolve the objection, you may terminate the affected service without penalty.

Every subprocessor is bound by data protection obligations no less protective than these, and we remain liable for their performance.

Model providers are subprocessors

Generating a reply necessarily sends the question and retrieved context to a model provider. This cannot be disabled while the agent is in use. Providers are engaged under terms prohibiting training on data submitted via their APIs.

7. International transfers

Where we transfer personal data out of the EEA or the UK, we rely on the European Commission’s Standard Contractual Clauses (Decision 2021/914), with the UK International Data Transfer Addendum where the UK GDPR applies. Module Two (controller to processor) applies between you and us; Module Three (processor to processor) applies between us and our subprocessors.

8. Audits

We will respond to reasonable written information requests about our processing. You may audit no more than once in any 12-month period, on 30 days’ notice, during business hours, without disrupting the service, and subject to confidentiality. Where a third-party report or certification answers the question, providing it satisfies this obligation.

9. Personal data breach

We will notify you without undue delay, and in any event within 72 hours, of becoming aware of a personal data breach affecting your data. The notice will describe the nature of the breach, the categories and approximate volume affected, the likely consequences, and the measures taken. We will not delay a notice in order to make it complete — updates follow as the picture firms up.

10. Data subject requests

If we receive a request from one of your end users, we will not respond substantively; we will refer them to you and tell you promptly. The dashboard lets you find, export and delete a given end user’s conversations and rows directly, which is the fastest route for most requests.

11. Return and deletion

On termination you may export your data for 30 days. After that we delete it, subject to backup rotation and to any retention the law requires of us.

12. Precedence

Where this addendum conflicts with the Terms of Service on the processing of personal data, this addendum prevails. Where it conflicts with the Standard Contractual Clauses, the Clauses prevail.

13. Contact

privacy@zealoop.com — including to request a countersigned copy.