This Data Processing Addendum ("DPA") forms part of the agreement between Customer and Software Programming Group LLC governing GenZos.ai. It applies to Provider's Processing of Customer Personal Data on Customer's behalf. Capitalized terms not defined here have the meanings in the agreement or Applicable Data Protection Law.
Definitions
"Applicable Data Protection Law" means privacy, data-protection, and data-security law applicable to the Processing, including as applicable the GDPR, UK GDPR, Swiss Federal Act on Data Protection, U.S. state comprehensive privacy laws, and India's Digital Personal Data Protection Act and rules in force.
"Customer Personal Data" means Personal Data contained in Customer Content that Provider Processes on Customer's behalf to provide the Service, excluding information for which Provider acts independently as controller, business, or data fiduciary.
"Security Incident" means a confirmed breach of security leading to accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to Customer Personal Data Processed by Provider. It excludes unsuccessful attempts and events that do not compromise Customer Personal Data.
"Subprocessor" means a third party engaged by Provider to Process Customer Personal Data on Customer's behalf.
Roles and Instructions
Customer is the Controller, Business, Data Fiduciary, or comparable principal, and Provider is the Processor, Service Provider, Contractor, Data Processor, or comparable recipient, except where law assigns a different role. Customer instructs Provider to Process Customer Personal Data to provide, secure, and support the Service; operate enabled models and integrations; comply with the agreement and Customer's documented use; and follow additional lawful written instructions agreed by the parties.
Customer is responsible for the lawfulness of instructions; notices and lawful bases; data accuracy; data minimization; permissions; retention settings; and determining that the Service, model, integration, and deployment are appropriate. Provider will notify Customer if, in Provider's opinion, an instruction violates Applicable Data Protection Law, unless prohibited from doing so.
Provider Obligations
Provider will:
Process Customer Personal Data only on documented instructions, including for international transfers, unless law requires otherwise;
ensure personnel authorized to Process Customer Personal Data are bound by confidentiality obligations;
implement and maintain appropriate technical and organizational measures designed to protect Customer Personal Data;
assist Customer, taking into account the nature of Processing and information available, with data-subject requests, security obligations, impact assessments, prior consultations, and regulatory inquiries;
notify Customer of a Security Incident without undue delay after confirmation and provide available information reasonably needed for Customer's obligations;
maintain records and information reasonably necessary to demonstrate compliance with this DPA;
delete or return Customer Personal Data at the end of the Services as described below; and
ensure each Subprocessor is bound by data-protection obligations materially protective of Customer Personal Data.
Security
Provider will maintain measures appropriate to risk and the Service configuration. Measures may include security governance, access control, authentication, least privilege, environment separation, encryption in transit and at rest where appropriate, logging, monitoring, vulnerability management, secure development, change control, backup and recovery, incident response, personnel safeguards, vendor review, and tenant or project isolation.
Customer acknowledges that controls differ between provider-managed, customer-managed, private, and third-party environments. Customer is responsible for Customer-controlled credentials, endpoints, repositories, integrations, permissions, secrets, deployment infrastructure, backups, and generated applications.
Security Incidents
Provider's notification will include, as information becomes reasonably available, the nature of the incident; affected data and data subjects; likely consequences; measures taken or proposed; and a contact for follow-up. Provider's notification is not an admission of fault or liability. Customer is responsible for notifications to individuals and authorities unless the parties agree otherwise in writing.
Subprocessors
Customer gives general written authorization for Provider to use Subprocessors. Provider will maintain a current disclosure and provide notice of a new Subprocessor that will materially Process Customer Personal Data. Customer may object on reasonable data-protection grounds within the period stated in the notice. The parties will work in good faith to address the objection. If no commercially reasonable alternative is available, either party may terminate the affected feature or Service, and Provider will refund prepaid unused fees for that affected portion.
Provider remains responsible for a Subprocessor's performance of its obligations to the extent required by Applicable Data Protection Law and the agreement.
Data-Subject Requests
If Provider receives a request relating to Customer Personal Data, Provider may direct the requester to Customer, notify Customer, and provide reasonable assistance through available functionality or support. Customer is responsible for responding. Provider may require reimbursement of reasonable costs for assistance beyond standard functionality where permitted by law and the agreement.
Audits and Information
Upon reasonable written request, Provider will provide information reasonably necessary to demonstrate compliance, which may include completed security questionnaires, policies, summaries, or available independent reports. If that information is insufficient, Customer may conduct one audit per year, and more frequently after a Security Incident or where a regulator requires, subject to reasonable notice, confidentiality, scope, safety, and non-disruption requirements. Customer bears audit costs unless the audit identifies a material Provider breach.
Return and Deletion
During the term, Customer may use available tools to access, export, correct, or delete Customer Personal Data. After termination or expiry, Provider will delete or return Customer Personal Data within the period stated in the agreement or applicable Order Form, unless law requires retention. Data may remain in backups until overwritten under ordinary cycles, protected from active use and deleted according to established procedures. Provider may retain de-identified information that cannot reasonably identify Customer or an individual.
International Transfers
Where Customer Personal Data subject to the GDPR is transferred to a country without an applicable adequacy decision, the parties incorporate the European Commission Standard Contractual Clauses adopted by Decision (EU) 2021/914 ("EU SCCs") as follows:
Module Two applies to Controller-to-Processor transfers and Module Three applies to Processor-to-Processor transfers, as relevant.
Clause 7 docking applies; in Clause 9, Option 2 and a 30-day notice period apply; optional Clause 11 does not apply unless required in an Order Form.
In Clause 17, Option 1 applies and the law of Ireland governs; courts of Ireland are selected under Clause 18.
Annex I is completed by the party and Processing details in this DPA; Annex II is completed by the security measures in this DPA and applicable security documentation; Annex III is the current Subprocessor Disclosure.
If this DPA conflicts with the EU SCCs, the EU SCCs control for the transfer.
For restricted transfers under the UK GDPR, the EU SCCs are modified by and incorporated with the then-current UK International Data Transfer Addendum issued by the Information Commissioner's Office, with the parties and Processing details in this DPA completing the relevant tables. For Swiss transfers, references are adapted to Swiss law and the competent Swiss authority as required.
The parties will cooperate on transfer-risk assessments and supplementary measures reasonably required by law. If a transfer mechanism is invalidated, the parties will use another lawful mechanism where available.
U.S. State Privacy Terms
For Customer Personal Data subject to an applicable U.S. state privacy law, Provider acts as a service provider, contractor, or processor. Provider will not sell or share Customer Personal Data; retain, use, or disclose it outside the direct business relationship or specified purposes except as permitted by law; combine it with personal data from another source except as permitted; or use it for targeted advertising or profiling for significant decisions on Provider's own behalf.
Customer makes Customer Personal Data available only for the limited and specified purposes in the agreement. Provider will provide the same level of privacy protection required by applicable law, notify Customer if it determines it can no longer meet an applicable obligation, and allow reasonable steps to stop and remediate unauthorized use.
India Data-Processing Terms
Where India's Digital Personal Data Protection framework applies, Customer ordinarily determines the purpose and means as Data Fiduciary and Provider Processes as Data Processor on Customer's instructions. Customer is responsible for a valid notice and consent or other lawful use, accuracy where required, grievance handling, and Data Principal rights. Provider will apply reasonable security safeguards, assist with breach and rights obligations, and follow deletion instructions subject to law and contract.
Liability and Order of Precedence
Liability arising from this DPA is subject to the limitations in the agreement, except to the extent Applicable Data Protection Law prohibits a limitation. The EU SCCs or another mandatory transfer instrument controls where required. Otherwise, this DPA controls over conflicting general privacy or security terms for Customer Personal Data.
Processing Details
Subject Matter and Duration
Provision, security, support, and administration of GenZos.ai for the term of the agreement and the deletion or return period.
Nature and Purpose
Hosting, storage, transmission, organization, retrieval, consultation, modification, generation, testing, collaboration, repository synchronization, model routing, export, security, support, analytics, deletion, and other Processing necessary to provide the configured Service.
Data Subjects
Customer personnel, Authorized Users, administrators, stakeholders, contractors, customers, prospects, application users, support contacts, and individuals whose Personal Data Customer places in project requirements, files, images, source code, repositories, databases, tests, or generated applications.
Categories of Personal Data
Identity and contact details; account and authentication data; roles and permissions; business and project records; prompts and instructions; files and images; source code and repository metadata; collaboration and audit records; device, network, log, and security data; support data; and any Personal Data Customer elects to include in Customer Content.
Sensitive Data
The standard Service is not intended to require sensitive or highly regulated data. Any permitted sensitive data depends on Customer's configuration, instructions, contract, and lawful authority and requires safeguards appropriate to risk.
Frequency
Continuous or event-driven according to Customer's use during the term.
Contacts
Provider privacy contact: privacy@genzos.ai
Provider security contact: security@genzos.ai
Provider legal contact: legal@genzos.ai
Provider address: Software Programming Group LLC, 5 Independence Way, Suite 300, Princeton, New Jersey 08540, United States