Data Processing Agreement
Effective 2026-08-31 · Version 1.0
1. Purpose of the Agreement
This Data Processing Agreement (referred to as the "Data Processing Agreement" or "DPA") is entered into between Zyntra Digital, acting as the operator and service provider of the ZynReach platform (referred to as "ZynReach" or the "Processor"), and the Customer or organization subscribing to ZynReach's services (referred to as the "Customer" or the "Controller"). Each is referred to individually as a "Party" and collectively as the "Parties". This Agreement governs the processing of personal data that ZynReach carries out on behalf of the Customer in connection with the provision of the Services.
This Agreement aims to define:
- The nature of the processing of personal data.
- The purposes of processing.
- The duration of processing.
- The types of personal data.
- The categories of data subjects.
- The rights and obligations of the Parties.
- ZynReach's obligations as Processor.
- The Customer's obligations as Controller.
- The use of Sub-processors.
- Data security.
- Notification of security incidents.
- Audit rights.
- Deletion and return of data.
- International transfers.
- Handling data subject requests.
- The relationship between this Agreement and the principal commercial agreement.
2. Scope of the Agreement
This Agreement applies whenever ZynReach processes personal data on behalf of the Customer as part of:
This Agreement does not apply to data that ZynReach processes as Controller for its own purposes, such as website administration, direct marketing, and management of business relationships, which are governed by ZynReach's Privacy Policy and applicable law.
- The ZynReach platform.
- CRM services.
- Lead Management.
- Business Data.
- Marketing Automation.
- Sales Management.
- Customer Management.
- Support Services.
- Project Management.
- Document Management.
- AI-enabled features.
- Integrations.
- APIs.
- Enterprise services.
- Any other service agreed upon in writing.
3. Definitions
For the purposes of this Agreement, the following terms have the meanings set out below:
"Personal Data" — any information relating to an identified or identifiable natural person under applicable law.
"Controller" — the party that determines the purposes and means of processing personal data.
"Processor" — the party that processes personal data on behalf of the Controller.
"Data Subject" — the natural person to whom personal data relates.
"Processing" — any operation performed on personal data, including: collection, storage, organization, retrieval, use, transmission, modification, and deletion.
"Sub-processor" — any third party appointed by ZynReach to process personal data on behalf of the Customer.
"Security Incident" — any security event affecting the confidentiality, integrity, or availability of data or systems.
"Personal Data Breach" — a security breach that leads, or is likely to lead, to the destruction, loss, alteration, unauthorized disclosure of, or unauthorized access to, personal data.
4. Relationship Between the Agreements
This DPA forms part of the commercial agreement entered into between the Parties.
The principal commercial agreement is referred to as the Master Services Agreement — MSA, or the Terms of Service / Subscription Agreement, depending on what is signed with the Customer.
In the event of a direct conflict between this DPA and the principal agreement with respect to the processing of personal data, this DPA shall prevail solely to the extent necessary to address the subject matter of data protection.
This DPA does not amend:
unless the commercial agreement expressly provides otherwise.
- Pricing.
- The scope of Services.
- The SLA.
- Limitation of liability.
- Intellectual property.
- Payment terms.
5. Roles of the Parties
5.1 Customer — Controller: The Customer is Controller with respect to personal data that it uploads to ZynReach, creates within the platform, collects from its customers, collects from its employees, imports from its own systems, or directs ZynReach to process.
5.2 ZynReach — Processor: ZynReach acts solely as Processor when it processes Customer Data on the Customer's behalf, based on the Customer's instructions, and for the purpose of providing the Services.
6. Customer Obligations
The Customer represents and warrants, to the extent permitted by law, that it:
- Has a lawful basis for processing the data.
- Has the right to collect the data.
- Has the right to input the data into ZynReach.
- Has provided the required notices to data subjects.
- Has obtained the required consents, where necessary.
- Will not use ZynReach in a manner that violates the law.
- Will not upload unnecessary data.
- Will not upload highly sensitive data without a lawful basis and appropriate controls.
- Bears responsibility for the accuracy of the data it provides.
- Bears responsibility for the instructions it issues to ZynReach.
7. Customer's Responsibility for Processing Instructions
ZynReach processes personal data in accordance with:
ZynReach shall not be liable for the Customer's violation of law resulting from the nature of the data it entered, the purpose for which it uses the data, the manner in which it obtained the data, or the instructions it issued.
- The Agreement.
- This DPA.
- The Customer's documented instructions.
- The platform functions selected by the Customer.
- Applicable law.
8. Customer Instructions
The following are deemed approved processing instructions:
Additional instructions may be provided in writing.
- Creating accounts.
- Storing data.
- Retrieving data.
- Searching within data.
- Organizing data.
- Running reports.
- Exporting data.
- Performing system operations.
- Running integrations.
- Operating the features selected by the Customer.
9. Unlawful Instructions
If ZynReach reasonably believes that a Customer instruction:
ZynReach may suspend implementation of the affected instructions until the matter is clarified, unless prohibited by law. Such suspension shall not constitute a breach of the Agreement where it is necessary to avoid unlawful processing.
- Violates applicable law.
- Exposes ZynReach to unlawful legal liability.
- Conflicts with this DPA.
10. Limits on Use of Data
ZynReach may not use Customer Data for purposes independent of providing the Services, except in cases where:
- The Customer consents to it.
- It is required by law.
- It is necessary for security and the prevention of fraud and misuse.
- The data has been anonymized or aggregated such that it no longer allows identification of the data subject.
- ZynReach is Controller under its own Privacy Policy.
11. Aggregated and Anonymized Data
ZynReach may create:
from Service usage data, provided that such data, once appropriately de-identified, does not allow identification of the Customer or the data subject. This data may be used for purposes such as product improvement, analytics, security, performance measurement, planning, and service development. This paragraph does not grant ZynReach the right to use the Customer's raw personal data for independent purposes.
- Aggregated Data.
- Statistical Data.
- Usage Metrics.
- De-identified Data.
- Anonymized Data.
12. Categories of Personal Data
The data processed may include the following categories:
- Identity data: name, username, internal identifier.
- Contact data: email address, phone number, address.
- Business data: company, job title, department, position.
- Customer data: CRM Records, Leads, Contacts, Accounts.
- Transactional data: depending on the Customer's use of the Service.
- Support data: support messages, assistance requests, issue records.
- Usage data: Login Events, Audit Logs, System Events.
- Document data: any personal data contained within a document uploaded by the Customer.
13. Categories of Data Subjects
Categories of data subjects may include:
- The Customer's employees.
- Customers.
- Prospective customers.
- Suppliers.
- Partners.
- Business contacts.
- The Customer's users.
- Visitors to websites operated by the Customer.
- Any individual whose data is contained within Customer Content.
14. Sensitive Data
The Customer is not permitted to use ZynReach to process:
unless it is necessary for the Service, it is permitted under the Agreement, the Customer has an appropriate lawful basis, the required controls have been implemented, or it has been agreed upon, where required.
- Health data.
- Biometric data.
- Children's data.
- Sensitive financial data.
- Data relating to sexual life.
- Data relating to beliefs or origin.
- Any special category of data.
15. Children's Data
The Customer may not use ZynReach to process children's data as a core part of the Service without:
ZynReach may decline certain types of processing that it considers to involve unacceptable risk.
- Appropriate legal consent.
- An appropriate lawful basis.
- The required controls.
16. Duration of Processing
ZynReach continues processing Customer Data for the duration of the Customer's subscription to the Services, and until:
subject to legally required retention periods, backups, and security records.
- The Agreement ends.
- The data is deleted in accordance with this DPA.
- The Customer's instructions are carried out.
17. Confidentiality
ZynReach undertakes to ensure that individuals authorized to access the data:
Customer Data may not be used outside the scope of the authorizations granted.
- Are bound by confidentiality.
- Are subject to appropriate contractual or legal obligations.
- Are granted access under the principle of Least Privilege.
18. Information Security
ZynReach implements technical and organizational measures appropriate to the risk, which may include:
Security measures evolve over time in line with the evolution of risks and technologies.
- Encryption in Transit.
- Encryption at Rest.
- Access Controls.
- RBAC.
- MFA.
- Least Privilege.
- Audit Logging.
- Monitoring.
- Vulnerability Management.
- Backup.
- Disaster Recovery.
- Incident Response.
- Security Testing.
19. No Guarantee of Absolute Security
The Parties acknowledge that no technical environment can be guaranteed to be absolutely secure. No reference to:
shall constitute a guarantee that a security breach will not occur. ZynReach undertakes to take appropriate measures, not to guarantee the absence of risk.
- Encryption.
- MFA.
- SOC.
- ISO.
- Monitoring.
20. Access Control
ZynReach applies the principle of Need-to-Know / Least Privilege, and access by employees or contractors to Customer Data is limited to what is necessary to perform their duties.
21. ZynReach Personnel
ZynReach takes appropriate measures to ensure that employees who can access Customer Data:
- Are trained.
- Are bound by confidentiality.
- Are granted the minimum level of privileges necessary.
- Are subject to access termination procedures once the need for access has ended.
22. Sub-processors
The Customer authorizes ZynReach to use Sub-processors to provide the Service. Their categories may include:
ZynReach is contractually responsible for the obligations of Sub-processors to the extent set out in law and the Agreement.
- Cloud Infrastructure.
- Database Services.
- Email Delivery.
- Customer Support.
- Monitoring.
- Analytics.
- Security.
- AI Infrastructure.
- Payment Services.
23. Notice of Sub-processors
ZynReach may add or replace Sub-processors as operational or technical need requires. ZynReach seeks to provide appropriate information about Sub-processors through the mechanism adopted in the Trust Center or the Agreement. Where the Customer has a legal right to object to a new Sub-processor, such objection shall be handled in accordance with law and the Agreement.
24. Customer Objection to Sub-processor
Where law or the Agreement grants the Customer a right to object, the objection must be:
The right to object may not be used as a means of disrupting the Service without legitimate cause.
- In writing.
- Based on grounds relating to data protection.
- Submitted within the specified period.
25. Data Subject Requests
When the Customer receives a request from a data subject relating to data held within ZynReach, the Customer shall handle it in its capacity as Controller. ZynReach shall assist the Customer, to a reasonable and appropriate extent, with:
in accordance with the capabilities of the platform.
- Access.
- Correction.
- Deletion.
- Restriction.
- Export.
- Search.
- Identification of data.
26. Requests Received Directly by ZynReach
If ZynReach receives a direct request from a Data Subject concerning Customer Data, then, where permitted by law, it shall:
unless ZynReach is required by law to respond directly.
- Not respond to the request on the Customer's behalf independently.
- Refer the request to the Customer.
- Provide appropriate assistance.
27. Assistance with Compliance
ZynReach shall provide, within reasonable limits, the assistance necessary for the Customer to fulfill its obligations relating to:
Additional assistance requiring substantial resources shall be subject to agreed fees, unless prohibited by law.
- Security of processing.
- Data Subject Requests.
- Data Breach.
- DPIA.
- Regulatory Requests.
28. Data Protection Impact Assessment
If the Customer is required to conduct a Data Protection Impact Assessment (DPIA), it may request appropriate information from ZynReach regarding:
ZynReach does not guarantee that the information provided is, by itself, sufficient to complete the Customer's DPIA.
- The nature of the processing.
- Security controls.
- Sub-processors.
- Processing locations.
- Protection mechanisms.
29. Regulatory Advice
ZynReach does not provide:
The Customer remains responsible for determining the legal requirements applicable to its activities.
- Legal advice.
- Regulatory advice.
- A legal opinion on the Customer's compliance.
30. Notification of Data Breach
Upon becoming aware of a personal data breach affecting Customer Data, ZynReach shall, in accordance with law and the Agreement, notify the Customer without undue delay. The notification shall include, to the extent available:
- The nature of the incident.
- The date of discovery.
- The data affected.
- The actions taken.
- Remedial measures.
- Contact information for the response point of contact.
31. Non-Reporting of Immaterial Alerts
Not every:
is considered a personal data breach. ZynReach determines whether an event constitutes a Personal Data Breach based on the facts, the risks, and applicable law.
- Failed Login.
- Malware Alert.
- Vulnerability.
- Service Interruption.
- Security Event.
32. Customer Obligations Following an Incident
In the event of an incident relating to its account, the Customer shall:
- Cooperate with ZynReach.
- Provide the necessary information.
- Not obstruct response procedures.
- Take appropriate action toward its users.
- Change login credentials where necessary.
33. Government Requests
If ZynReach receives a lawful request for Customer Data, it may disclose data to the extent required by law. Where permitted by law, ZynReach seeks to:
ZynReach does not guarantee that it will be able to notify the Customer in every case, particularly where the law prohibits notification.
- Notify the Customer.
- Determine the scope of the request.
- Limit the data disclosed.
34. Government Transparency
Where permitted by law, ZynReach may publish or update general information regarding:
There is no obligation to publish any information where the law prohibits it.
- Government requests.
- Disclosure requests.
- Legal proceedings.
35. International Transfers
Data may be processed outside the Customer's country or the country of data subjects. Where data is subject to the GDPR or a similar regime, ZynReach uses an appropriate lawful transfer mechanism. Potential mechanisms include:
The European Commission recognizes that the transfer of personal data outside the EEA requires appropriate safeguards, and that SCCs constitute one of the approved mechanisms for this purpose.
- Adequacy Decision.
- Standard Contractual Clauses.
- Appropriate Safeguards.
- Derogation, where permitted by law.
36. Standard Contractual Clauses
Where SCCs are required for the transfer of personal data from the EEA to a third country, the Parties agree to use the EU Standard Contractual Clauses in effect at the time of transfer, according to the module or modules appropriate to the nature of the relationship. The European Commission provides the official texts of the SCCs relating to international transfers, as well as the SCCs governing the relationship between Controller and Processor. This paragraph shall not be construed as incorporating the full text of the SCCs into this DPA; rather, they shall be executed or appended as a separate annex where needed.
37. Transfer Impact Assessment
Where legally required, ZynReach shall reasonably cooperate with the Customer with respect to assessing the risks of international transfer. The Customer remains responsible for assessing whether the transfer relating to its activities meets its own legal requirements.
38. Data Storage Location
Data storage and processing locations are set out in Annex B — Data Processing Details. Processing locations may be changed for operational or security reasons, subject to legal and contractual requirements.
39. Audit Rights
The Customer may request reasonable information to demonstrate ZynReach's compliance with its data protection obligations. Such information may include:
subject to considerations of confidentiality, security, and protection of intellectual property.
- Security Documentation.
- Certifications.
- Audit Reports.
- Policies.
- Penetration Test Summaries.
- Subprocessor Information.
40. Limits on Audits
No audit may:
- Disrupt the Service.
- Expose ZynReach's systems to risk.
- Disclose another customer's data.
- Disclose trade secrets.
- Disclose encryption keys.
- Disclose credentials.
- Disclose sensitive security information that could increase risk.
41. Third-Party Audits
ZynReach may satisfy audit requirements by providing:
instead of allowing each customer to conduct a direct technical audit, whenever this is sufficient under law.
- SOC Reports.
- ISO Certificates.
- Independent Audit Reports.
- Security Assessments.
42. On-Site Audit
If a direct audit is legally required and cannot be satisfied by alternative means, the following shall apply:
The Customer shall bear the reasonable costs arising from its own audit, unless the law or the Agreement provides otherwise.
- The date shall be agreed in advance.
- The scope shall be defined.
- The duration of the audit shall be defined.
- Security shall be observed.
- Confidentiality shall be observed.
- Access to other customers' data shall not be permitted.
43. Record Retention
ZynReach may retain processing records, security records, or audit records for the period necessary for:
- Compliance.
- Security.
- Fraud prevention.
- Dispute resolution.
- Defense of legal rights.
44. Return of Data
Upon termination of the Service, the Customer may request the export of its data in accordance with the capabilities of the platform. The following shall be determined:
in accordance with the Service and the Agreement.
- The format.
- The export period.
- The scope.
45. Deletion of Data
After the Agreement ends, ZynReach shall delete or render Customer Data unidentifiable in accordance with its applicable deletion cycle, unless:
- The Customer requests that it be retained.
- The law requires that it be retained.
- It exists within backups subject to an independent retention cycle.
46. Backups
Some data may remain within:
after deletion from production systems. This data is removed in accordance with the applicable technical retention cycle.
- Backups.
- Disaster Recovery Systems.
- Archives.
47. Early Deletion Request
The Customer may request deletion of data before the end of the contractual retention period. Responding to this request may be subject to:
- Legal restrictions.
- Contractual obligations.
- Additional fees if the deletion process requires extensive manual processing.
48. Ownership
Data that the Customer uploads to ZynReach remains owned by the Customer or the party holding the rights to it. This Agreement does not transfer ownership of the data to ZynReach.
49. ZynReach's Intellectual Property
This DPA does not grant the Customer any right to:
These rights remain owned by their respective owners.
- Source Code.
- Architecture.
- Algorithms.
- Software.
- Databases.
- Security Systems.
- Trade Secrets.
- Documentation.
50. Data Arising from Service Operation
Customer Data and Customer Content remain owned by the Customer. However:
may be used by ZynReach in accordance with this DPA, the Agreement, and the Privacy Policy.
- System Metrics.
- Aggregated Statistics.
- De-identified Information.
- Platform Telemetry.
51. Artificial Intelligence
When the Customer uses AI features, the data necessary to operate the feature may be processed. The Customer must:
- Use the feature in accordance with the documentation.
- Not input data it does not have the right to use.
- Not use AI to make unlawful decisions.
- Apply Human Oversight where necessary.
52. AI Sub-processors
Certain AI features may rely on third-party infrastructure or AI service providers. Where this is:
it shall be handled in accordance with the provisions of this DPA.
- Part of the Service.
- Authorized.
- Disclosed within the Subprocessor Framework.
53. No Training of General Models with Customer Data
Unless expressly agreed otherwise, this DPA does not grant ZynReach a general license to use Customer Content to train general-purpose AI models independent of the Service. Data may be used for the purposes of operating the requested features, security, and improving the Service in accordance with the Agreement and applicable law.
54. Third-Party Integrations
When the Customer connects ZynReach to a third-party service:
ZynReach is not responsible for the third party's processing once the data has passed to it outside of ZynReach's control.
- The Customer is responsible for its choice of service.
- The Customer consents to sharing the data required for the integration.
- The third party is subject to its own terms and privacy policy.
55. APIs
When using the API, the Customer is responsible for:
ZynReach may suspend an API Key if usage is found to pose a security risk.
- Protecting API Keys.
- Managing access.
- Defining privileges.
- Monitoring usage.
- Preventing the sharing of keys.
56. Customer's Security Obligations
The Customer must:
ZynReach shall not be liable for a breach resulting directly from the Customer's negligence in protecting its login credentials.
- Use MFA where available.
- Protect accounts.
- Not share passwords.
- Manage users.
- Remove inactive users.
- Review privileges.
- Protect devices used to access the Service.
57. Customer's Responsibility for Users
Users to whom the Customer grants access to ZynReach are deemed to be users authorized by the Customer. The Customer bears responsibility for:
- Their actions.
- Their privileges.
- The data they enter.
- Their use of the platform.
58. Cooperation
The Parties shall cooperate in good faith on:
- Investigations.
- Regulatory authority requests.
- Data subject requests.
- Security incidents.
- Audits.
- Risk assessments.
59. Fees
The Service's basic fees do not necessarily include:
Reasonable fees may be charged in accordance with the Agreement or a work order.
- Legal consultations.
- A dedicated DPIA.
- A special on-site audit.
- Extensive manual data extraction.
- Dedicated deletion services.
- A special legal response.
60. Indemnification
Each Party is responsible for damages arising from its material breach of its obligations under law and the commercial agreement. This DPA does not create an independent indemnification regime that exceeds the limits of liability set out in the principal agreement, unless mandatory law provides otherwise.
61. Limitation of Liability
Unless mandatory law provides otherwise, ZynReach's liability arising from this DPA is subject to the Limitation of Liability set out in the principal commercial agreement. The mere characterization of data as:
does not cancel or exceed the agreed limit of liability. This is a very important protection point for the company; a DPA should not contain an unlimited liability commitment covering all customer data while the MSA has a defined limitation of liability.
- Personal Data.
- Confidential Data.
- Sensitive Data.
62. Force Majeure
ZynReach shall not be liable for delay or failure to perform resulting from events beyond its reasonable control, such as:
while taking reasonable measures to mitigate the effects of the event.
- Natural disasters.
- Wars.
- Large-scale attacks.
- Infrastructure outages.
- Decisions of governmental authorities.
- Disruption of the public internet.
63. Term of the Agreement
This DPA takes effect upon:
and continues for as long as ZynReach processes Customer Data.
- Signature by the Parties; or
- Acceptance by the Customer as part of the subscription; or
- Commencement of use of the Service, where the Terms of Service so provide.
64. Termination
This DPA terminates upon:
Provisions that by their nature survive termination shall remain in effect.
- Termination of the MSA.
- Termination of the subscription.
- Cessation of all data processing operations.
65. Surviving Provisions
The following remain in effect after termination of the Agreement, in accordance with their nature:
- Confidentiality.
- Deletion of data.
- Records.
- Liability.
- Audit.
- Legal obligations.
66. No Assignment
The Customer may not assign this DPA or its rights under it without regard to the terms of the principal agreement. ZynReach may transfer the Agreement to an affiliate or legal successor in the event of:
with continued protection of the data in accordance with law.
- Restructuring.
- Merger.
- Acquisition.
- Sale of the business.
67. Severability
If any provision of this DPA is found to be:
this shall not affect the remaining provisions. The unenforceable provision shall be replaced with a lawful provision that achieves the closest commercial and legal purpose.
- Invalid.
- Unlawful.
- Unenforceable.
68. No Waiver of Rights
ZynReach's failure to exercise any right under this Agreement shall not be deemed a waiver of that right.
69. Governing Law
This DPA is governed by the law specified in the principal commercial agreement. In the absence of such specification, it shall be governed by the competent law agreed upon between the Parties. The final governing law and jurisdiction shall be specified in the executed version according to the legal entity contracting with the Customer.
70. Compliance with Local Laws
Each Party shall comply with the laws applicable to it. For operations subject to Egyptian law, obligations must be assessed in accordance with Egyptian legislation governing the protection of personal data, including Personal Data Protection Law No. 151 of 2020, depending on the scope of application and the role of each Party. This DPA does not mean that a single law applies to all customers or all processing operations.
71. GDPR
Where the GDPR applies to the processing of data, this DPA is intended to govern the relationship between Controller and Processor in a manner consistent with the relevant requirements. This includes, as applicable:
- Article 28.
- Article 29.
- Article 32.
- Article 33.
- Article 34.
- Chapter V.
- Data Subject Rights.
72. Processor Obligations
ZynReach undertakes, to the extent applicable law requires, to:
- Process data in accordance with instructions.
- Ensure confidentiality.
- Implement appropriate security measures.
- Assist the Controller.
- Manage Sub-processors.
- Assist with incidents.
- Delete or return data.
- Make appropriate compliance information available.
73. Controller Obligations
The Customer undertakes, to the extent applicable law requires, to:
- Determine the lawful basis.
- Provide notices.
- Respect the rights of data subjects.
- Provide lawful instructions.
- Determine the purposes of processing.
- Ensure the lawfulness of the data.
- Not direct ZynReach to engage in unlawful processing.
74. Priority of Mandatory Law
If a data protection law imposes an obligation that the Parties cannot contractually exclude, the mandatory law shall apply to the extent required. No provision of this DPA shall be deemed a waiver of a right that cannot lawfully be waived.
75. Amendments
ZynReach may update this DPA where an amendment is necessary due to:
The Customer shall be notified where notice is required by law or the Agreement.
- A change in law.
- A regulatory change.
- A change to the Service.
- A change in Sub-processors.
- A change in technical architecture.
- New security requirements.
76. Material Amendments
If a material amendment materially reduces the level of data protection, it shall be handled in accordance with the rights and procedures set out in the principal agreement and applicable law.
77. Notices
Privacy-related notices shall be directed to privacy@zynreach.com. Legal notices shall be directed to legal@zynreach.com. Security notices shall be directed to security@zynreach.com.
- Privacy — privacy@zynreach.com
- Legal — legal@zynreach.com
- Security — security@zynreach.com
78. Entire Agreement
This DPA, together with:
constitutes the contractual and regulatory framework relating to the processing of data.
- The MSA.
- Terms of Service.
- Privacy Policy.
- Security & Trust Policy.
- Subprocessor List.
79. Electronic Signature
The Parties may execute this DPA electronically, and electronic signatures shall be valid and enforceable to the extent permitted by applicable law.
80. Annex A — Data Processing Details
A.1 Subject Matter of Processing: Provision of ZynReach's SaaS services and management of the data uploaded or created by the Customer within the platform.
A.2 Duration of Processing: The subscription period and any subsequent period necessary for deletion or legal compliance.
A.3 Nature of Processing: Collection, Storage, Organization, Retrieval, Consultation, Use, Transmission, Modification, Deletion.
A.4 Purposes of processing include:
- Operating the Service.
- Customer support.
- User management.
- Execution of Customer operations.
- Security.
- Backup.
- Business continuity.
- Integrations.
- Features requested by the Customer.
81. Annex B — Categories of Personal Data
The following categories illustrate examples of the personal data that may be processed:
- Identity — name, user ID
- Contact — email, phone
- Professional — job title, company
- CRM — Leads, Contacts, Accounts
- Transactional — transaction data
- Support — support tickets and messages
- Usage — Login / Audit Events
- Documents — data contained within documents
- Technical — IP, Device, Browser
- Other — any data entered by the Customer within the scope of the Service
82. Annex C — Categories of Data Subjects
Categories of data subjects may include:
- Employees.
- Customers.
- Prospects.
- Suppliers.
- Business Contacts.
- Partners.
- Authorized Users.
- Website Visitors.
- Other individuals represented in Customer Data.
83. Annex D — Security Measures
ZynReach seeks to implement a set of controls, proportionate to the nature of the Service and its risks, including:
- Access Control — RBAC, Least Privilege, MFA, Access Reviews
- Encryption — Encryption in Transit, Encryption at Rest, Secure Key Management
- Monitoring — Security Monitoring, Logging, Audit Trails, Alerting
- Infrastructure — Segmentation, Secure Configuration, Vulnerability Management, Patch Management
- Resilience — Backups, Disaster Recovery, Business Continuity
- Incident Response — Detection, Containment, Investigation, Remediation, Notification
- Personnel — Confidentiality, Security Awareness, Access Revocation
84. Annex E — Sub-processor Framework
ZynReach may use the categories of Sub-processors necessary to provide the Service, such as:
ZynReach publishes or otherwise makes available the current list in accordance with the mechanism adopted in its Trust Center.
- Cloud Infrastructure — Hosting
- Database — Data Storage
- Email — Notifications
- Analytics — Product Analytics
- Support — Customer Support
- Security — Security Services
- AI Infrastructure — AI Features
- Payment — Billing
85. Annex F — Data Breach Procedure
Upon discovery of a Personal Data Breach, ZynReach follows the sequence:
ZynReach maintains appropriate incident records in accordance with its security and compliance policies.
- Detection.
- Triage.
- Containment.
- Investigation.
- Risk Assessment.
- Remediation.
- Notification.
- Post-Incident Review.
86. Annex G — Data Subject Request Procedure
Handling of data subject requests follows the sequence:
ZynReach is not obligated to disclose data belonging to another customer or another data subject.
- Request Received.
- Identity Verification.
- Scope Assessment.
- Customer Notification.
- Data Search.
- Response Support.
- Completion.
- Record Keeping.
87. Annex H — Data Return & Deletion
Upon termination of the Service, the return and deletion of data follows the sequence:
subject to legal obligations, security requirements, backups, and legal disputes.
- Customer Export.
- Retention Period.
- Production Deletion.
- Backup Expiration.
- Final Disposal.
88. Annex I — International Transfer
Where an international transfer is required, ZynReach follows the sequence:
The transfer mechanism may include EU SCCs / Adequacy / Other Legally Permitted Mechanism, depending on applicable law. The European Commission officially publishes SCC templates governing the relationship between Controllers and Processors, as well as SCCs governing transfers to countries outside the EEA.
- Transfer Assessment.
- Applicable Mechanism.
- Safeguards.
- Documentation.
- Monitoring.
89. Annex J — AI Processing
When the Customer uses AI features:
- The Customer remains responsible for the lawfulness of the data it inputs.
- The data necessary to perform the requested function is processed.
- The platform's access privileges apply wherever available.
- This DPA does not grant a general license to use Customer Data to train independent general-purpose models.
- AI Sub-processors are subject to the provisions governing Sub-processors.
- The Customer bears responsibility for reviewing outputs before using them in high-impact decisions.
90. Annex K — Enterprise Security & Compliance Evidence
Enterprise customers may, in accordance with ZynReach's terms, request appropriate security or compliance documentation, such as:
This does not automatically include Source Code, Encryption Keys, Internal Credentials, Detailed Network Architecture, Customer Data, Vulnerability Details, or information that could expose ZynReach to risk. Requests for security documentation are subject to the separate Security & Compliance Documentation Request Policy.
- Security Overview.
- Privacy Documentation.
- DPA.
- Subprocessor List.
- Security Questionnaire.
- Compliance Reports.
- Independent Audit Reports.
- Certificates.
- Penetration Testing Summary.
91. Annex L — Order of Precedence
In the event of a conflict, the order of precedence is as follows:
This applies solely with respect to the specific subject matter of data processing and data protection.
- Mandatory Applicable Law.
- Data Protection Addendum / SCCs where applicable.
- This DPA.
- MSA / Subscription Agreement.
- Terms of Service.
- Other Product Documentation.
92. Execution & Signatures
The Parties may execute this Agreement by signature or acceptance in accordance with the mechanism described in Section 79 (Electronic Signature). The signed instance of the Agreement includes the following fields for each Party:
- For ZynReach / Zyntra Digital — Legal Entity Name
- For ZynReach / Zyntra Digital — Authorized Representative
- For ZynReach / Zyntra Digital — Title
- For ZynReach / Zyntra Digital — Signature
- For ZynReach / Zyntra Digital — Date
- For the Customer — Legal Entity Name
- For the Customer — Authorized Representative
- For the Customer — Title
- For the Customer — Signature
- For the Customer — Date
For privacy-related requests, contact us at privacy@zynreach.com.