Data Processing Addendum
Last updated 9 August 2026
Forms part of the Terms of Service where Zealoop processes personal data on your behalf. You are the controller; we are the processor.
1. Roles
You are the controller of the personal data you put into a workspace and of the conversations your visitors have with the agent. Zealoop, Inc. is the processor. We process that data only on your documented instructions, which are: this addendum, the Terms, and the configuration you set in the dashboard.
Where we act as a controller — for your own account details — the Privacy Policy applies instead.
2. Subject matter and duration
Provision of an AI support agent, for as long as your workspace exists, plus the retention windows set out in the Privacy Policy.
3. Nature and purpose of processing
- Storing and indexing the documentation you supply, including deriving chunks and embeddings from it.
- Storing the customer records you upload, and looking one up for a verified end user.
- Transmitting a question and its retrieved context to a model provider in order to generate a reply.
- Storing conversations, replies and per-turn traces so you can review and audit them.
- Calling the endpoints you configure, with the arguments the agent supplies, subject to their guards.
4. Categories of data subject and personal data
| Data subjects | Personal data |
|---|---|
| Your end users | Email address, display name, verification status, message content, and whatever fields you place in a table row |
| Your team | Name, email address, role, activity within the workspace |
Special-category data is out of scope. Do not put it into a workspace without a separate written agreement with us — see Terms, section 4.
5. Our obligations
- Process personal data only on your documented instructions, including for transfers, unless law requires otherwise — in which case we will tell you first, unless that law forbids it.
- Ensure people authorised to process the data are bound by confidentiality.
- Implement the technical and organisational measures described on the Security page.
- Assist you, taking account of the nature of processing, with data subject requests and with your obligations under Articles 32–36 GDPR.
- Make available the information needed to demonstrate compliance, and allow for audits as set out in section 8.
- On termination, delete or return the data as described in the Privacy Policy.
6. Subprocessors
You give general authorisation for us to engage subprocessors. The current list is published at Subprocessors. We will give at least 30 days’ notice before adding or replacing one, and you may object on reasonable data-protection grounds — if we cannot resolve the objection, you may terminate the affected service without penalty.
Every subprocessor is bound by data protection obligations no less protective than these, and we remain liable for their performance.
Model providers are subprocessors
Generating a reply necessarily sends the question and retrieved context to a model provider. This cannot be disabled while the agent is in use. Providers are engaged under terms prohibiting training on data submitted via their APIs.
7. International transfers
Where we transfer personal data out of the EEA or the UK, we rely on the European Commission’s Standard Contractual Clauses (Decision 2021/914), with the UK International Data Transfer Addendum where the UK GDPR applies. Module Two (controller to processor) applies between you and us; Module Three (processor to processor) applies between us and our subprocessors.
8. Audits
We will respond to reasonable written information requests about our processing. You may audit no more than once in any 12-month period, on 30 days’ notice, during business hours, without disrupting the service, and subject to confidentiality. Where a third-party report or certification answers the question, providing it satisfies this obligation.
9. Personal data breach
We will notify you without undue delay, and in any event within 72 hours, of becoming aware of a personal data breach affecting your data. The notice will describe the nature of the breach, the categories and approximate volume affected, the likely consequences, and the measures taken. We will not delay a notice in order to make it complete — updates follow as the picture firms up.
10. Data subject requests
If we receive a request from one of your end users, we will not respond substantively; we will refer them to you and tell you promptly. The dashboard lets you find, export and delete a given end user’s conversations and rows directly, which is the fastest route for most requests.
11. Return and deletion
On termination you may export your data for 30 days. After that we delete it, subject to backup rotation and to any retention the law requires of us.
12. Precedence
Where this addendum conflicts with the Terms of Service on the processing of personal data, this addendum prevails. Where it conflicts with the Standard Contractual Clauses, the Clauses prevail.
13. Contact
privacy@zealoop.com — including to request a countersigned copy.