Data Processing Addendum
- Effective
- 21 September 2026
- Last updated
- 21 September 2026
- Version
- 1.0
This page sets out the structure and the factual processing details of the Data Processing Addendum ("DPA") that ZeroCredit AI offers to customers who submit personal data to the platform. It supplements our Terms of Service.
Status. The clause text below is a working framework, not an executed contract, and the commercial and liability terms are still to be settled with counsel. If you need a signed DPA, email support@zerocreditai.com and we will execute one with you. Where a negotiated DPA or enterprise agreement is signed, it prevails over this page.
1. Parties and roles
| Item | Detail |
|---|---|
| Processor | [LEGAL PLACEHOLDER – TO BE COMPLETED] |
| Processor registered office | [LEGAL PLACEHOLDER – TO BE COMPLETED] |
| Controller / Data Fiduciary | The customer named in the applicable order form or account record |
| Contact for this addendum | support@zerocreditai.com |
| Effective from | [LEGAL PLACEHOLDER – TO BE COMPLETED] |
For personal data that a customer submits through the platform — including data contained in API requests — the customer determines the purposes and means of processing and ZeroCredit AI processes it on the customer's instructions. For our own account, billing, security and website data we act in our own right. Where you use your own provider credentials, that provider processes the request under your own agreement with them, not as our subprocessor.
2. Details of processing
| Item | Detail |
|---|---|
| Subject matter | Provision of the ZeroCredit AI gateway, routing, analytics, optimization and administration features |
| Nature of processing | Receiving, validating, routing, transmitting, measuring, caching where enabled, logging, storing and deleting data as required to operate the service |
| Purpose | To provide, secure, operate, troubleshoot and support the service; to measure usage and cost; and to comply with legal obligations |
| Duration | For the term of the customer's subscription or agreement, plus the period needed for deletion and for legally required records |
| Categories of personal data | Account and contact identifiers; authentication and API credential metadata; billing and transaction data; usage, cost and telemetry records; support correspondence; and any personal data the customer chooses to include in request or response content |
| Special / sensitive categories | Not requested and not required by the service. If a customer chooses to submit such data in request content, it is the customer's responsibility to have a lawful basis and appropriate safeguards. |
| Categories of data subjects | The customer's administrators and team members, and the customer's own end users whose data the customer includes in requests |
| Retention | [RETENTION PERIOD TO BE CONFIRMED] |
3. Customer instructions
We process customer personal data only to provide the service in accordance with the Terms, the customer's configuration in the product, and any documented instructions the parties agree in writing. We will tell the customer if, in our view, an instruction would breach applicable data protection law.
4. Confidentiality and personnel
Access to customer personal data is limited to personnel who need it to operate or support the service, who are bound by confidentiality obligations. We do not read request content routinely, and we do not use it to train models.
5. Security measures
We implement the technical and organisational measures described on our Security Overview page, which forms the description of measures for this addendum. We may update those measures provided the overall level of protection is not reduced.
6. Subprocessors
The customer authorises the subprocessors listed on our Subprocessors page. We impose data protection obligations on each subprocessor that are materially equivalent to those in this addendum, and we remain responsible for their performance. Advance-notice and objection rights for new subprocessors are set out in the executed agreement: [LEGAL PLACEHOLDER – TO BE COMPLETED].
7. International transfers
Customer personal data may be processed outside India, including where our infrastructure or a selected AI provider operates in another country. We do not represent that data stays within any single country. Transfers are made subject to the safeguards required by the law applicable to the transfer, and the specific transfer mechanism recorded in the executed agreement: [LEGAL PLACEHOLDER – TO BE COMPLETED].
8. Data subject and data principal requests
Where we receive a request from an individual relating to customer personal data, we will refer it to the customer rather than answering it ourselves, unless legally required to respond. We will give the customer reasonable assistance, using the product's own access, export and deletion features where they are sufficient.
9. Security incident cooperation
We will notify the customer without undue delay after becoming aware of a personal data breach affecting customer personal data, provide the information reasonably available to us, and cooperate with the customer's own notification obligations. Notification is not an admission of fault.
10. Deletion and return of data
On termination, or on the customer's written request, we will delete customer personal data, except where we must retain it to comply with law. Backups are deleted on their ordinary rotation cycle rather than individually edited, so data may persist in backups for a short period after deletion from live systems. We will provide export of the customer's data through the product's export features.
11. Audits and information rights
We will respond to reasonable information requests needed to demonstrate compliance with this addendum. On-site audit rights, frequency and cost allocation are as recorded in the executed agreement: [LEGAL PLACEHOLDER – TO BE COMPLETED]. We hold no third-party audit report or certification today and will not offer one in place of answering questions directly.
12. Government and law enforcement requests
If we receive a legally binding demand for customer personal data, we will attempt to redirect the requester to the customer, and we will notify the customer unless legally prohibited. We will disclose only what the demand actually requires.
13. Liability
Liability arising under this addendum is subject to the limitations and exclusions of the master agreement between the parties, to the maximum extent permitted by applicable law. The specific allocation is as recorded in the executed agreement: [LEGAL PLACEHOLDER – TO BE COMPLETED].
14. Precedence
A negotiated and executed DPA or enterprise agreement prevails over this page. In the absence of one, this page describes the processing we actually perform, read together with our Privacy Notice.