Legal

Data Processing Agreement

Last updated October 2026

This Data Processing Agreement (the “DPA”) forms part of the Zyberon Terms of Service. It applies whenever Zyberon processes personal data on behalf of a customer, and it follows the structure of the standard contractual clauses for controllers and processors that the European Commission adopted in Implementing Decision (EU) 2021/915. This is version 2026-10.

01Parties and scope

The controller is the customer that holds a Zyberon workspace and accepts this DPA (“you”). The processor is Zyberon (“we”, “us”), identified in Annex I. Where you are yourself a processor for your own clients, we act as your sub-processor and this DPA applies in the same way.

This DPA covers all personal data that we process on your behalf while providing the Zyberon platform (the “Service”). It does not cover personal data for which we are the controller ourselves, such as your account and billing details; our Privacy Policy describes that processing.

If this DPA conflicts with the Terms of Service, this DPA prevails for everything that concerns the protection of personal data. Nothing in this DPA limits the rights of data subjects or the obligations of either party under the General Data Protection Regulation (the “GDPR”).

02Acceptance, version and duration

You accept this DPA on behalf of your organization when you accept the Terms of Service, when you create a workspace, or when an owner or admin accepts it in the workspace settings. We record for every workspace which version was accepted, when, and by whom.

This is version 2026-10. It applies for as long as we process personal data on your behalf, and it ends once all such data has been deleted or returned as described in section 11.

We may update this DPA when the law or the Service changes. We announce a material change at least 30 days before it takes effect, and an update never lowers the level of protection that this version gives.

03Processing on your documented instructions

We process personal data only on your documented instructions. Your instructions are this DPA, the Terms of Service, the settings you choose in your workspace and the actions you take in the Service, such as connecting a store, enabling an AI tool or sending a reply.

We do not process the data for our own purposes, we do not sell it, and we do not use it to train AI models. We process it beyond your instructions only when European Union or Member State law requires us to; in that case we tell you first, unless that law forbids it.

If we believe that an instruction infringes the GDPR or other data protection law, we tell you immediately, and we may suspend that instruction until you confirm or change it.

04Confidentiality

We give access to personal data only to people who need it to provide, secure or support the Service, and only to the extent they need. Everyone with that access is bound by a duty of confidentiality, by contract or by law.

05Security of processing

We apply the technical and organizational measures described in Annex III to protect personal data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure and unauthorized access. We review them regularly and may improve them, but we never lower the overall level of protection.

You are responsible for the security of the accounts and credentials you control, for the permissions you give your team, and for the data you choose to bring into the Service.

06Special categories of personal data

The Service is not designed for special categories of personal data or for data about criminal convictions, and you do not instruct it to process such data. If your use of the Service nevertheless involves it, you are responsible for the legal basis and you tell us, so that we can agree on additional safeguards.

07Sub-processors

You give us general authorization to engage the sub-processors listed on our sub-processor page, which forms Annex IV of this DPA.

We inform you of any intended addition or replacement of a sub-processor at least 30 days in advance, by email to the owner of each workspace and by updating that page. Within that period you can object on reasonable data protection grounds by writing to hello@zyberon.ai. If we cannot resolve your objection, you may end the affected part of the Service before the change takes effect, without penalty.

We engage every sub-processor under a written contract that imposes data protection obligations at least as protective as this DPA, and we remain fully responsible to you for how they perform those obligations.

Services you connect yourself, such as your store platform, your advertising accounts, your mailbox or your email marketing platform, are not our sub-processors. We exchange data with them on your instructions, and your own agreement with each of those providers governs what they do with it.

08International transfers

The servers that hold your data are in the European Union. Some sub-processors, in particular the AI providers, process data in the United States or elsewhere outside the European Economic Area. We transfer personal data outside the EEA only in compliance with Chapter V of the GDPR, for example on the basis of an adequacy decision such as the EU-US Data Privacy Framework, or of the standard contractual clauses of the European Commission together with supplementary measures where needed.

09Assistance to you

We promptly forward to you any request we receive from a data subject about personal data we process on your behalf, and we do not answer it ourselves unless you authorize us to. Taking into account the nature of the processing, we help you answer such requests, in particular through the export, correction and deletion functions of the Service.

Taking into account the information available to us, we also help you with data protection impact assessments, with prior consultation of a supervisory authority, and with your obligations on security and on the notification of breaches.

10Personal data breaches

We notify you without undue delay, and in any case within 48 hours, after we become aware of a personal data breach that affects personal data we process on your behalf. We send the notification by email to the owner of each affected workspace.

The notification describes, as far as is then known, the nature of the breach, the categories and approximate number of data subjects and records concerned, the likely consequences, the measures we have taken or propose to take, and a contact point for more information. Where we cannot give everything at once, we give it in phases without further undue delay.

We take the measures needed to contain the breach and limit its consequences, we keep a record of every breach, and we cooperate with you so that you can meet your own obligation to notify the supervisory authority and, where required, the data subjects.

11Deletion or return at the end of the Service

You can export your data and delete your workspace from your dashboard at any time. When you delete your workspace or account, or when the Service ends, we delete the personal data we process on your behalf within 30 days, unless European Union or Member State law requires us to keep it. Encrypted backups expire on their own schedule within 90 days.

If you want a copy returned before deletion, use the export functions of the Service, or ask us at hello@zyberon.ai before you delete your workspace.

12Information and audits

We make available to you the information needed to demonstrate compliance with this DPA and Article 28 GDPR. On request we provide a description of our security measures, the current list of sub-processors and, once available, the results of independent audits.

You may audit our compliance, yourself or through an independent auditor bound by confidentiality, once a year, or more often when a breach or a supervisory authority gives reason to. You give at least 30 days of notice, the audit takes place during business hours, and it may not disrupt the Service or expose the data of other customers. Each party bears its own costs, unless the audit shows a material breach of this DPA by us.

13Liability and termination

Each party’s liability under this DPA is subject to the limitations in the Terms of Service, except where the GDPR does not allow such a limitation.

If we breach this DPA and do not remedy it within a reasonable period, you may suspend our processing of your data and end the affected part of the Service.

14Governing law

This DPA is governed by the law of the Netherlands, and disputes are submitted to the competent court in the Netherlands, in line with the Terms of Service.

Annex I: the parties

Controller: the customer that holds the Zyberon workspace, as identified by the details in its account. Contact: the owner of the workspace.

Processor: Zyberon, with the company details below. Contact for data protection: hello@zyberon.ai. Contact for security: security@zyberon.ai.

Company details

Privacy and data protection: hello@zyberon.ai

Security and vulnerability reports: security@zyberon.ai

Annex II: description of the processing

Categories of data subjects

  • Your customers and the visitors of your store, your funnels and your landing pages
  • People who contact your customer support by email, chat, social media or forms
  • Your suppliers and their contacts
  • Your team members who use the Service
  • People who appear in the content you upload or generate, such as product photos and videos

Categories of personal data

  • Identification and contact details, such as name, email address, phone number and shipping address
  • Order, payment status and shipping details, such as order contents, totals and tracking numbers, but never full card numbers
  • Communications, such as support emails, social media messages and comments, and the replies generated with AI
  • Online identifiers and technical data, such as IP address, user agent, cookie identifiers and ad click identifiers, part of which is hashed before it is sent to advertising platforms
  • Marketing and consent data, such as newsletter subscriptions and quiz answers
  • Images, video and text that you upload or generate, which can show or name people
  • Team member data, such as names, roles, activity and performance notes

Special categories of personal data: none intended (see section 6).

Nature of the processing: collection through the integrations you connect and the pages you publish, storage, organization, analysis, generation of content with AI, transmission to the services you connect, and deletion.

Purpose: providing the parts of the Service you enable, such as customer support, product pages and funnels, advertising creative and measurement, email marketing, analytics and research, and the operations that keep them running.

Duration: for as long as your workspace exists, followed by deletion under section 11. Operational records are deleted earlier on fixed schedules, as described in our Privacy Policy.

Frequency: continuous while the Service is in use.

Annex III: technical and organizational measures

These measures describe how the Service operates today. We update this annex when a measure changes, and never in a way that lowers the overall level of protection.

Workspace isolation and access control

  • Every record that belongs to a workspace carries the identifier of that workspace, and every query is limited to the workspace of the signed in user, which is taken from the session and never from the request.
  • Row level security is enabled on the database tables, as a second barrier behind the application.
  • Roles and per feature permissions decide what each team member can see and do, and two step verification is available for every account.
  • Our own administrative console uses separate credentials, two step verification and an allowlist of named staff.

Encryption

  • All traffic to the Service is encrypted in transit with TLS.
  • Access tokens, API keys and passwords for the services you connect are stored encrypted in a dedicated secrets vault, and are never shown again after you save them.
  • Database backups are encrypted before they leave the database server.
  • Contact details sent to advertising platforms for conversion measurement are hashed with SHA-256 before they leave our servers, wherever the platform supports it.

Infrastructure and environments

  • The production database, file storage and background processing run on servers in data centers in the European Union.
  • Administrative access to the servers uses SSH keys.
  • Production and the test environment use separate databases, storage and background workers. When the test environment is refreshed with production data, an automated scrub removes the stored access credentials of customer workspaces.

Availability and recovery

  • The production database is backed up every day. Backups are encrypted, kept for up to 90 days and copied to a second data center location.
  • The servers also carry image backups at the hosting provider.
  • Automated health checks run every 15 minutes, a watchdog checks the platform every two minutes, and a failure alerts the operations team immediately.

Logging and monitoring

  • Administrative actions are recorded in an audit trail. Application logs are kept for 30 days and error records for 90 days.
  • Errors are recorded and grouped in our own database rather than in an outside error tracking service.

Secure development and change management

  • Every change passes automated type checks, linting, tests and dependency vulnerability checks before it is released.
  • Every change is validated in a separate test environment first, and a production release needs the explicit approval of the product owner.
  • Dependencies are monitored for known vulnerabilities and updated through automated pull requests.

Data minimization and retention

  • Each AI provider receives only the data a task needs, never a whole database.
  • Operational records are deleted automatically on fixed schedules, as described in our Privacy Policy, and workspace data is deleted within 30 days after the workspace is deleted.

Incident response

  • We follow a documented procedure for incidents and personal data breaches, with severity levels, named roles, preservation of evidence and the notification deadline of section 10.
  • Security researchers can report vulnerabilities through our vulnerability disclosure policy.

People and suppliers

  • Access to production systems is limited to the people who need it to run the Service.
  • Sub-processors are selected for their security and data protection guarantees and are bound by written data processing terms.

Annex IV: sub-processors

The current sub-processors, with the purpose and location of each, are listed below and on our sub-processor page, which also shows the date of the last change.

Hosting and infrastructure

  • Hetzner Online GmbH

    Purpose:
    Servers for the web application, the database, file storage, background processing, backups and build pipelines.
    Data:
    All data held in the Service.
    Location:
    Germany and Finland (EU)
  • Contabo GmbH

    Purpose:
    A server our engineering team uses to build, test and operate the Service, with administrative access to the production systems.
    Data:
    Data that is read while the Service is operated and supported.
    Location:
    Germany (EU)
  • Cloudflare, Inc.

    Purpose:
    Delivery and protection of the custom tracking domains of stores, and bot protection on sign up and sign in.
    Data:
    IP address, browser details and the tracking events that pass through a custom domain.
    Location:
    Global network; Cloudflare, Inc. is based in the United States

AI processing

  • OpenAI

    Purpose:
    Text and image generation.
    Data:
    The content of a task: prompts, store and product details, customer messages when you use the support tools, and images.
    Location:
    United States
  • Anthropic PBC

    Purpose:
    Text generation, and AI assisted engineering and operations, including the analysis of error reports.
    Data:
    The content of a task, and error details that can contain workspace data.
    Location:
    United States
  • Google (Gemini)

    Purpose:
    Text and image generation, and image analysis, with the Gemini models.
    Data:
    The content of a task: prompts, store and product details, customer messages when you use the support tools, and images.
    Location:
    United States and other Google locations
  • Higgsfield AI

    Purpose:
    Video and image generation.
    Data:
    Prompts, product images and the media that is generated.
    Location:
    United States

Payments, email and operations

  • Mollie B.V.

    Purpose:
    Subscription payments.
    Data:
    Name, email address, payment details and payment status of the account holder.
    Location:
    Netherlands (EU)
  • Resend

    Purpose:
    Email from Zyberon itself, such as invitations, notifications and service messages.
    Data:
    Recipient email address and the content of the message.
    Location:
    United States
  • Slack Technologies

    Purpose:
    Our internal operational alerts, and notifications to our sales team about new sales enquiries.
    Data:
    Error and alert details, and the name, company, email address and phone number of people who ask us for a sales call.
    Location:
    United States

Our own sales and marketing

  • Calendly LLC

    Purpose:
    Booking sales calls from our own website.
    Data:
    Name, email address and the details given when booking.
    Location:
    United States
  • Meta Platforms Ireland Ltd.

    Purpose:
    Measuring our own advertising on our campaign pages, only after a visitor accepts tracking. Meta and Zyberon are joint controllers for this collection.
    Data:
    Hashed contact details, IP address, browser details and Meta cookie identifiers.
    Location:
    Ireland (EU) and the United States

Research data

  • Apify Technologies s.r.o.

    Purpose:
    Collecting public web pages and public ad library data for the research features.
    Data:
    Publicly available content, which can show or name people.
    Location:
    Czech Republic (EU) and the United States
  • DataForSEO

    Purpose:
    Keyword and search data for the SEO features.
    Data:
    Search terms and website addresses. No personal data is sent by design.
    Location:
    Not applicable: no personal data is sent
  • Proxy4U

    Purpose:
    Network exit for collecting public web pages.
    Data:
    Encrypted connections to public websites, whose content the provider cannot read.
    Location:
    Not applicable: no readable personal data

Questions about this document? Email hello@zyberon.ai.