Data Processing Addendum

Effective
21 September 2026
Last updated
21 September 2026
Version
1.0

This page sets out the structure and the factual processing details of the Data Processing Addendum ("DPA") that ZeroCredit AI offers to customers who submit personal data to the platform. It supplements our Terms of Service.

Status. The clause text below is a working framework, not an executed contract, and the commercial and liability terms are still to be settled with counsel. If you need a signed DPA, email support@zerocreditai.com and we will execute one with you. Where a negotiated DPA or enterprise agreement is signed, it prevails over this page.

1. Parties and roles

ItemDetail
Processor[LEGAL PLACEHOLDER – TO BE COMPLETED]
Processor registered office[LEGAL PLACEHOLDER – TO BE COMPLETED]
Controller / Data FiduciaryThe customer named in the applicable order form or account record
Contact for this addendumsupport@zerocreditai.com
Effective from[LEGAL PLACEHOLDER – TO BE COMPLETED]

For personal data that a customer submits through the platform — including data contained in API requests — the customer determines the purposes and means of processing and ZeroCredit AI processes it on the customer's instructions. For our own account, billing, security and website data we act in our own right. Where you use your own provider credentials, that provider processes the request under your own agreement with them, not as our subprocessor.

2. Details of processing

ItemDetail
Subject matterProvision of the ZeroCredit AI gateway, routing, analytics, optimization and administration features
Nature of processingReceiving, validating, routing, transmitting, measuring, caching where enabled, logging, storing and deleting data as required to operate the service
PurposeTo provide, secure, operate, troubleshoot and support the service; to measure usage and cost; and to comply with legal obligations
DurationFor the term of the customer's subscription or agreement, plus the period needed for deletion and for legally required records
Categories of personal dataAccount and contact identifiers; authentication and API credential metadata; billing and transaction data; usage, cost and telemetry records; support correspondence; and any personal data the customer chooses to include in request or response content
Special / sensitive categoriesNot requested and not required by the service. If a customer chooses to submit such data in request content, it is the customer's responsibility to have a lawful basis and appropriate safeguards.
Categories of data subjectsThe customer's administrators and team members, and the customer's own end users whose data the customer includes in requests
Retention[RETENTION PERIOD TO BE CONFIRMED]

3. Customer instructions

We process customer personal data only to provide the service in accordance with the Terms, the customer's configuration in the product, and any documented instructions the parties agree in writing. We will tell the customer if, in our view, an instruction would breach applicable data protection law.

4. Confidentiality and personnel

Access to customer personal data is limited to personnel who need it to operate or support the service, who are bound by confidentiality obligations. We do not read request content routinely, and we do not use it to train models.

5. Security measures

We implement the technical and organisational measures described on our Security Overview page, which forms the description of measures for this addendum. We may update those measures provided the overall level of protection is not reduced.

6. Subprocessors

The customer authorises the subprocessors listed on our Subprocessors page. We impose data protection obligations on each subprocessor that are materially equivalent to those in this addendum, and we remain responsible for their performance. Advance-notice and objection rights for new subprocessors are set out in the executed agreement: [LEGAL PLACEHOLDER – TO BE COMPLETED].

7. International transfers

Customer personal data may be processed outside India, including where our infrastructure or a selected AI provider operates in another country. We do not represent that data stays within any single country. Transfers are made subject to the safeguards required by the law applicable to the transfer, and the specific transfer mechanism recorded in the executed agreement: [LEGAL PLACEHOLDER – TO BE COMPLETED].

8. Data subject and data principal requests

Where we receive a request from an individual relating to customer personal data, we will refer it to the customer rather than answering it ourselves, unless legally required to respond. We will give the customer reasonable assistance, using the product's own access, export and deletion features where they are sufficient.

9. Security incident cooperation

We will notify the customer without undue delay after becoming aware of a personal data breach affecting customer personal data, provide the information reasonably available to us, and cooperate with the customer's own notification obligations. Notification is not an admission of fault.

10. Deletion and return of data

On termination, or on the customer's written request, we will delete customer personal data, except where we must retain it to comply with law. Backups are deleted on their ordinary rotation cycle rather than individually edited, so data may persist in backups for a short period after deletion from live systems. We will provide export of the customer's data through the product's export features.

11. Audits and information rights

We will respond to reasonable information requests needed to demonstrate compliance with this addendum. On-site audit rights, frequency and cost allocation are as recorded in the executed agreement: [LEGAL PLACEHOLDER – TO BE COMPLETED]. We hold no third-party audit report or certification today and will not offer one in place of answering questions directly.

12. Government and law enforcement requests

If we receive a legally binding demand for customer personal data, we will attempt to redirect the requester to the customer, and we will notify the customer unless legally prohibited. We will disclose only what the demand actually requires.

13. Liability

Liability arising under this addendum is subject to the limitations and exclusions of the master agreement between the parties, to the maximum extent permitted by applicable law. The specific allocation is as recorded in the executed agreement: [LEGAL PLACEHOLDER – TO BE COMPLETED].

14. Precedence

A negotiated and executed DPA or enterprise agreement prevails over this page. In the absence of one, this page describes the processing we actually perform, read together with our Privacy Notice.

This page is a drafting and transparency aid, not legal advice. Contract terms should be reviewed and executed with qualified legal counsel.