Zenrows's Data Processing Agreement
This document lays out the responsibilities of Zenrows SL (Spain company number B10660298), hereafter referred to as Zenrows, to its customers with regards to data protection in general and the European Union's General Data Protection Regulation (GDPR) specifically.
01Zenrows as data processor, definitions
- Zenrows is a Data Processor operating on behalf of its customers.
- "Customers" means individuals or organizations paying to use the Zenrows service. Free trial users are not Customers.
- Zenrows's Customers are Data Controllers.
- "Personal data" means any information relating to an identified or identifiable person.
- "Data Protection Laws" means Regulation (EU) 2016/679 as transposed domestically and amended, including the GDPR and its implementing laws.
- "Services" means the Zenrows service (web app via browser UI, API) and professional services provided by Zenrows.
- "Sub-processor" means any Data Processor engaged by Zenrows.
- "Data Subject" means the individual to whom Personal Data relates.
02Processing of personal data
Use of the service implies Zenrows may process personal data on behalf of the Data Controller per Data Protection Laws. The Data Controller ensures instructions to their users comply with Data Protection Laws and has sole responsibility for the accuracy, quality, and legality of Personal Data and how it's acquired.
Data is stored in a centralised database, and may also be stored on other services where required for functionality. Zenrows publishes a full and accurate description of its data protection practices at /legal/gdpr, updated as practices change.
03Rights of data subjects
Zenrows ensures necessary consent is collected from Data Subjects. Zenrows will promptly notify the Data Controller, to the extent legally permitted, if it receives a Data Subject request for access or deletion; it will not respond without the Data Controller's prior written consent, except to confirm the request relates to the Data Controller. The Data Controller is solely responsible for completing such requests as required by law.
04Personnel
Zenrows personnel processing personal data are informed of confidentiality, trained on their responsibilities, and bound by confidentiality obligations that survive termination of their employment or engagement. Zenrows takes commercially reasonable steps to ensure personnel reliability; access is limited to those who require it to perform the Services.
We believe that, according to the GDPR, Zenrows does not require a data protection officer. However, you can contact us with data protection enquiries.
05Sub-processors
The Data Controller agrees Zenrows may engage third-party Sub-processors, and additional levels of Sub-processors, solely for the purposes they were retained for. Zenrows agrees to be liable for the acts and omissions of its Sub-processors to the same extent as if performing directly.
06Security
Zenrows agrees to implement and maintain administrative, technical, and physical safeguards for personal data stored via the Services.
07Security breach management and notification
If Zenrows becomes aware of unlawful or unauthorized access resulting in loss, disclosure, or alteration of the Data Controller's personal data (a "Security Breach"), it will promptly notify the Data Controller, investigate and provide known information, and follow its policies and procedures to mitigate effects and minimize damage.
Unsuccessful Security Breach attempts, pings, broadcast attacks on firewalls or edge servers, port scans, unsuccessful log-ons, denial-of-service attacks, packet sniffing not resulting in access beyond IP addresses or headers, and similar incidents, are not subject to this notification clause. Notifications are delivered to the Customer's business, technical, or administrative contacts by any means Zenrows selects, including email; the Customer is solely responsible for maintaining accurate contact information. Zenrows's report or response to a Security Breach is not an admission of fault or liability.
08Deletion of customer data
Zenrows agrees to delete Customer personal data per its procedures and Data Protection Laws. At the Customer's request, Zenrows will provide a certification of deletion.
09Legal effect
This agreement comes into effect from the 1st of June 2022 for all existing customers, or from the time of purchase of a Zenrows subscription. It expires with the cessation of the Customer's Zenrows subscription.