Sub-processor Policy

Effective 2026-08-31 · Version 1.0

1. Purpose

This Sub-processor Policy (the "Policy") explains how ZynReach, owned and operated by Zyntra Digital ("ZynReach," the "Company," "we," or "us"), selects, evaluates, manages, and monitors third parties that may process personal data on behalf of ZynReach or on behalf of its customers.

This Policy has been prepared to provide an appropriate level of transparency to ZynReach's customers, particularly those using ZynReach's services under a Data Processing Agreement (DPA) or any other commercial or service agreement governing the processing of personal data.

This Policy forms part of ZynReach's privacy, security, and compliance framework and should be read together with:

In the event of a conflict between this Policy and any written and signed agreement between ZynReach and the customer, the provisions of the signed agreement shall govern to the extent permitted by law.

  • Privacy Policy.
  • Data Processing Agreement (DPA).
  • Security & Trust Policy.
  • Terms of Service / Master Services Agreement.
  • Any other privacy or data security agreements or addenda applicable to the relevant customer.

2. Definitions

For the purposes of this Policy, the following terms shall have the meanings set out below:

"Customer Data" means the data provided by the customer to ZynReach, or entered, uploaded, stored, or processed by the customer or its users through the Services.

"Personal Data" means any data considered personal data or personal information under applicable law.

"Processing" means any operation or set of operations performed on personal data, including collection, storage, use, access, transfer, disclosure, alteration, or deletion.

"Processor" means the entity that processes personal data on behalf of a Controller or on behalf of another entity legally authorized to do so.

"Sub-processor" means any third party engaged by ZynReach to process personal data on behalf of ZynReach or its customers, where such processing relates to the Services provided to the customer.

"Controller" means the entity that determines the purposes and means of processing personal data, in accordance with applicable law.

"Applicable Data Protection Law" means all data protection and privacy laws and regulations applicable to the relevant processing, depending on the nature of the data, the location of the parties and individuals, and the place of processing.

3. Scope

This Policy applies to Sub-processors engaged by ZynReach in providing its services, where such third party has access to personal data processed on behalf of the customer.

The mere use by ZynReach of an external vendor or service provider does not necessarily mean that vendor is a Sub-processor.

The scope of this Policy includes, as applicable, service providers offering services such as:

  • Hosting and cloud infrastructure.
  • Data storage.
  • Databases.
  • Email and messaging services.
  • Technical support services.
  • Monitoring and logging services.
  • Cybersecurity.
  • Backup and disaster recovery.
  • Analytics services.
  • Communications services.
  • Artificial intelligence or machine learning services.
  • Payment processing services, where the processing of personal data is part of the service.
  • Other technical or operational services necessary for the provision of the Services.

4. Basic Principle

ZynReach undertakes not to engage a Sub-processor to process personal data except where necessary or appropriate to provide the Services, operate the infrastructure, maintain its security, or improve its reliability, and in a manner consistent with applicable contractual and legal obligations.

ZynReach retains responsibility for the acts of Sub-processors to the extent required by applicable laws and relevant agreements.

5. Selection of Sub-processors

ZynReach follows appropriate procedures before engaging a new Sub-processor where the nature of the service requires the processing of personal data on behalf of the customer.

The evaluation process may include, depending on the level of risk and the nature of the service:

ZynReach is not obligated to apply the same level of scrutiny to all Sub-processors; the level of due diligence may be proportionate to the nature of the service, the volume and type of data, and the associated risks.

  • Determining the nature of the service and the purpose of the processing.
  • Identifying the types of data that may be accessed.
  • Identifying the categories of affected data subjects.
  • Assessing security and privacy risks.
  • Reviewing available technical and organizational controls.
  • Reviewing the service provider's privacy and security policies.
  • Assessing the data storage location and processing locations.
  • Assessing international data transfer mechanisms where necessary.
  • Reviewing contractual obligations relating to confidentiality and data protection.
  • Assessing security incident management procedures.
  • Assessing data deletion and retention procedures.
  • Assessing relevant security accreditations or certifications, where available.
  • Conducting an additional risk assessment where the nature of the processing is highly sensitive or high-risk.

6. Contractual Requirements

ZynReach seeks to impose appropriate contractual obligations on Sub-processors that process personal data on its behalf.

These obligations may include, depending on the nature of the relationship:

A Sub-processor may not use Customer Data for its own purposes except where contractually authorized, required by law, or within an independent and lawful scope that does not constitute processing on behalf of ZynReach.

  • Confidentiality obligations.
  • Processing data in accordance with authorized instructions.
  • Implementing appropriate security measures.
  • Restricting access to data.
  • Reporting security incidents.
  • Cooperating in responding to data subject requests.
  • Cooperating on data protection obligations.
  • Assisting with incident investigations.
  • Complying with restrictions on international transfers.
  • Returning or deleting data upon termination of the service, in accordance with the contract and applicable law.
  • Not using data for unauthorized independent purposes.

7. List of Sub-processors

ZynReach may publish or make available a list of the Sub-processors used in providing the Services through its website, Trust Center, or any other appropriate electronic means.

The list of Sub-processors may include, depending on the nature of the service, the following categories and information:

Note: This list does not, in itself, constitute a commitment to use any specific provider throughout the term of the contractual relationship, and ZynReach may change or replace Sub-processors in accordance with the provisions of this Policy and applicable agreements.

  • Infrastructure / Hosting — Nature of processing: Storage & Processing; Sub-processor name: as identified in the current Sub-processor list; Processing/hosting location: as applicable to the service.
  • Communications — Nature of processing: Email / Messaging; Sub-processor name: as identified in the current Sub-processor list; Processing/hosting location: as applicable to the service.
  • Security — Nature of processing: Security Monitoring; Sub-processor name: as identified in the current Sub-processor list; Processing/hosting location: as applicable to the service.
  • Support — Nature of processing: Customer Support; Sub-processor name: as identified in the current Sub-processor list; Processing/hosting location: as applicable to the service.

8. Adding or Replacing Sub-processors

ZynReach may add or replace a Sub-processor where necessary or appropriate for operational, technical, security, or commercial reasons, including:

Where required under a DPA or applicable law, ZynReach will notify the customer prior to engaging a new Sub-processor, in accordance with the mechanism and timeframe specified in the applicable agreement.

  • Improving the level of security.
  • Improving performance or reliability.
  • Providing more efficient infrastructure.
  • Developing the Services.
  • Replacing an existing vendor.
  • Business continuity.
  • Legal or regulatory requirements.
  • Reducing risk.
  • Introducing new functionality or services.

9. Notification of Changes

Customers may be notified of changes relating to Sub-processors through one or more of the following means:

The agreement entered into with the customer may specify a different notification mechanism, in which case the contractually agreed mechanism shall apply.

  • Updating the published Sub-processor list.
  • Sending an email notification.
  • In-platform notification.
  • Notification via the customer portal.
  • Updating the Trust Center.
  • Any other means permitted by the applicable agreement.

10. Right to Object

Where a DPA or applicable law grants the customer the right to object to the appointment of a new Sub-processor, the customer may submit a written objection within the period specified in the DPA or relevant agreement.

The objection must be based on reasonable grounds directly related to data protection, privacy, or security.

The customer's mere lack of preference for the service provider, or the existence of an alternative provider in the market, does not in itself constitute sufficient grounds for objection unless the agreement or applicable laws provide otherwise.

11. Handling Customer Objections

Upon receipt of a valid objection, ZynReach may, at its reasonable discretion and consistent with applicable agreements and law:

ZynReach does not guarantee that every objection will result in the removal or replacement of a Sub-processor.

  • Work with the customer to address the concerns raised.
  • Provide additional information about the Sub-processor.
  • Implement appropriate additional measures, where practicable.
  • Propose a suitable alternative, if available.
  • Reassess the Sub-processor.
  • Take other appropriate action to reduce risk.

12. If the Objection Cannot Be Resolved

If a customer's objection materially prevents ZynReach from providing an essential part of the Services, and no reasonable resolution is reached within the period specified in the applicable agreement, either party may take the actions set out in the agreement, which may include, as applicable, termination of the affected part of the Services.

This Policy shall not be construed as granting the customer a right of immediate termination or any additional right not expressly set out in the contract or applicable law.

13. Security and Data Protection

ZynReach expects Sub-processors to implement appropriate technical and organizational measures to protect the data processed on its behalf.

These measures may include, depending on the nature of the service:

The level of controls required is determined based on risk and the nature of the service.

  • Access control.
  • Principle of least privilege.
  • Multi-factor authentication where applicable.
  • Encryption in transit.
  • Encryption at rest where appropriate.
  • Logging and monitoring.
  • Vulnerability management.
  • Patch and update management.
  • Backup.
  • Disaster recovery.
  • Incident management.
  • Infrastructure protection.
  • Personnel and user controls.
  • Access de-provisioning procedures.

14. Confidentiality

ZynReach undertakes to take appropriate steps to ensure that authorized personnel of Sub-processors who have access to personal data are bound by appropriate confidentiality obligations.

Personal data may not be made available to a Sub-processor's employees or contractors except to the extent necessary to perform the authorized services.

15. Security Incidents

Where a security incident at a Sub-processor affects personal data processed on behalf of ZynReach or its customers, ZynReach seeks to obtain appropriate information from the Sub-processor and take reasonable measures to address the incident.

The response may include:

An incident at a Sub-processor does not mean that all customer data has been compromised; the impact assessment depends on the nature of the incident and the data and systems affected.

  • Investigating the nature of the incident.
  • Assessing the scope of impact.
  • Taking containment measures.
  • Addressing the root cause.
  • Implementing corrective measures.
  • Documenting the actions taken.
  • Providing notifications required by law or contract.

16. Data Subject Requests

Where the customer is the Controller and ZynReach is the Processor, ZynReach does not typically handle data subject requests as the Controller of the customer's data.

As specified in the DPA, ZynReach may provide reasonable assistance to the customer in handling data subject requests.

ZynReach may rely on Sub-processors to carry out certain technical procedures necessary for this assistance.

17. International Data Transfers

Data may be processed or made accessible from locations outside the country in which the customer or data subjects are located.

Where international data transfers are subject to data protection laws, ZynReach seeks to apply an appropriate lawful transfer mechanism as applicable, such as:

ZynReach may rely on Sub-processors that themselves use infrastructure or providers located in multiple countries.

  • An adequacy decision issued by a competent authority.
  • Standard Contractual Clauses (SCCs).
  • Other permitted contractual or organizational measures.
  • Any other lawful mechanism available under applicable law.

19. Cloud Infrastructure Services

ZynReach may use cloud infrastructure and hosting service providers to operate the Services.

These services may rely on multiple components, including:

This may result in more than one party being involved in providing the technical infrastructure for the Service.

  • Compute.
  • Storage.
  • Database.
  • Networking.
  • Backup.
  • Monitoring.
  • Security.
  • Content Delivery.
  • Disaster Recovery.

20. AI Providers

If ZynReach uses artificial intelligence services or machine learning models from third parties, the service provider may be considered a Sub-processor where personal data is shared with it on behalf of the customer.

In such cases, ZynReach seeks to apply appropriate controls relating to:

It should not be assumed that all AI service providers have the same data processing policies; the relevant service is therefore assessed according to its nature and risks.

  • The scope of data transmitted.
  • The purpose of the processing.
  • Use of data for training.
  • Data retention.
  • Access to data.
  • Security.
  • Confidentiality.
  • International transfer.
  • Legal requirements.

21. Payment Services

ZynReach may use external payment service providers to carry out payment and billing operations.

The payment provider may process certain personal or financial data independently, acting as an entity independent of ZynReach in certain cases.

Where the payment provider is the entity that determines the purposes and means of certain processing under law, it may not be considered a Sub-processor with respect to that specific processing.

22. Support Service Providers

ZynReach may use external service providers or systems to manage:

Access to data is restricted in accordance with operational need and applicable controls.

  • Support tickets.
  • Customer communications.
  • Email.
  • Request management.
  • Service issue resolution.

23. Independent Processing by Service Provider

A third party is not considered a Sub-processor merely because it receives or processes certain information relating to the customer.

Where the third party:

the Sub-processor provisions of this Policy may not apply to that processing.

  • Independently determines the purposes and means of processing; or
  • Acts as an independent Controller; or
  • Is legally obligated to process independently;

24. No Sale of Customer Data

ZynReach does not grant Sub-processors the right to sell Customer Data or use it for independent advertising purposes or unauthorized commercial purposes, except as may be expressly permitted under the contract or applicable law.

Technical processing necessary to provide, operate, or secure the Service is not considered a "sale" of data merely because an external service provider is used.

25. Use of Data for Analytics Purposes

ZynReach or Sub-processors may use certain data for legitimate operational and analytical purposes, such as:

This processing must occur within the limits permitted under the agreement and applicable law.

  • Performance monitoring.
  • Error detection.
  • Improving stability.
  • Preventing fraud and abuse.
  • Security.
  • Capacity planning.

26. Data Retention and Deletion

Upon the cessation of the need for personal data or the termination of the relationship with the customer, data is managed in accordance with applicable retention and deletion policies, consistent with the DPA, the contract, and applicable law.

Certain copies may persist in backup systems for a limited period due to the nature of backup and disaster recovery systems, while remaining subject to protective controls and not being returned to operational use except where necessary.

27. Monitoring and Reassessment

ZynReach may reassess Sub-processors from time to time, particularly when:

This does not mean that ZynReach is obligated to conduct a full periodic audit of every Sub-processor in all cases.

  • The nature of the service changes.
  • The risks of processing change.
  • A security incident occurs.
  • Legal requirements change.
  • A material change occurs at the service provider.
  • A new type of data is introduced.
  • The processing location changes.

28. Audit and Verification

ZynReach may use various means to verify the level of security and compliance of Sub-processors, including:

ZynReach may rely on independent reports or certifications rather than conducting a direct audit in all cases.

  • Security questionnaires.
  • Document review.
  • Review of certifications and accreditations.
  • Independent audit reports.
  • Risk assessments.
  • Contractual reviews.
  • Available technical evidence.

29. ZynReach's Responsibility

Subject to the limitations and exceptions set out in the applicable DPA and commercial agreements, ZynReach remains responsible to the customer for the performance of its data processing obligations carried out by Sub-processors, to the extent required by law and contract.

ZynReach bears no independent responsibility for any processing carried out by a third party acting as an independent Controller outside the scope of ZynReach's instructions or the relevant contractual relationship.

30. No Additional Rights Granted

This Policy does not grant the customer or any third party any additional rights beyond those set out in:

Nor shall any provision of this Policy be construed as a guarantee or undertaking that ZynReach will use a specific Sub-processor for the duration of the service, unless a written contract provides otherwise.

  • The DPA.
  • The Master Agreement.
  • The Terms of Service.
  • Applicable law.

31. Amendments to This Policy

ZynReach may amend this Policy from time to time to reflect:

The updated version is published through appropriate channels.

Where a law or DPA requires specific notice, the notice requirements set out in the relevant document or law shall be observed.

  • Changes in the Services.
  • Changes in Sub-processors.
  • Legal and regulatory developments.
  • Technical changes.
  • Operational improvements.
  • Security and privacy requirements.

32. Relationship with the Data Processing Agreement

This Policy is to be read together with the Data Processing Agreement entered into between ZynReach and the customer.

In the event of a discrepancy between the provisions of this Policy and the provisions of the DPA regarding the use of Sub-processors, the provisions of the DPA shall govern.

In particular, the publication of this Policy shall not be construed as an implied amendment of the DPA or a waiver of any right or contractual defense available to ZynReach.

33. Governing Law and Jurisdiction

This Policy is governed by the law applicable to the contractual relationship between ZynReach and the customer, and this Policy does not, in itself, create independent jurisdiction unless the relevant contract or mandatory law provides otherwise.

34. Contact

For inquiries relating to Sub-processors, data protection, or privacy, ZynReach may be contacted through the official communication channels published on the Company's website.

Correspondence should preferably include:

  • Customer name.
  • Organization name.
  • The email address associated with the account.
  • The name of the relevant service.
  • The name of the Sub-processor in question.
  • The nature of the objection or request.
  • Any additional information that would help assess the matter.

35. Acknowledgement

By using or continuing to use ZynReach's services, the customer acknowledges that it has reviewed this Policy to the extent permitted by the agreement and applicable law, and that this Policy forms part of ZynReach's privacy and data processing management framework.

This does not affect any rights or obligations established under a written agreement or applicable law.

36. Document Record

The following record sets out the details of this document:

  • Document name: Sub-processor Policy.
  • Company: Zyntra Digital.
  • Platform: ZynReach.
  • Website: zynreach.com.
  • Version: 1.0.
  • Effective date: August 31, 2026.
  • Classification: Public / Legal / Compliance.
  • Review: Periodically or upon a material change.
  • Related documents: Privacy Policy / DPA / Security & Trust Policy / Terms of Service.

For privacy-related requests, contact us at privacy@zynreach.com.