Data Processing Agreement
Effective on account activation; supersedes any conflicting terms.
Need it signed?
Email [email protected] with your company name + legal entity. We countersign and return within one business day.
1. Roles
You are the Data Controller. Zenith Intelligence Technologies ("ZIT") is the Data Processor. This DPA governs any Personal Data you process through ZI² Verify.
2. Categories of data
- Email addresses submitted for verification.
- Verification metadata: MX host, DNS records, SMTP responses.
- Account holder identity (your team, not the emails you verify).
3. Sub-processors
- Stripe, Inc. — payment processing (US, PCI-DSS L1).
- Cloudflare, Inc. — CDN + DDoS (global anycast).
30 days' notice before adding sub-processors. You may terminate for cause if you object.
4. Security measures
TLS 1.2+ in transit; argon2id for passwords; sha256 for API keys + wise tokens; HMAC-SHA256-chained credit ledger; Postgres RLS on tenant tables; least-privilege IAM. See /security for full details.
5. International transfers
Primary data region: US. EU-only data residency available on Enterprise plans on request. Standard Contractual Clauses (2021/914) apply to any EU-to-US transfer.
6. Data-subject rights
Access, correction, deletion, restriction, portability — you can execute all of them via the dashboard's Data Export + Delete Account controls. On request, we assist within 30 days.
7. Breach notification
Within 72 hours of confirmed breach, we notify you with impact scope, affected records, mitigations taken, and any required steps on your side.
8. Audit
You may audit our compliance annually (30 days' notice, at your cost). Our SOC 2 report — once available — satisfies most annual audit requirements.
9. Deletion on termination
Within 30 days of account termination, we delete all Personal Data except audit-log entries required for financial regulation (7 years).