Last updated: June 3, 2026
This Data Processing Agreement (“DPA”) forms part of, and is governed by, the Zentriq Terms of Service. It applies whenever Zentriq Software processes personal data on behalf of a customer (the “Customer”) in connection with the Services, and sets out the obligations of the parties under Article 28 of the EU General Data Protection Regulation (GDPR) and the Swiss Federal Act on Data Protection (nFADP).
For personal data processed through the Services, the Customer acts as the data controller and Zentriq acts as the data processor. Where Zentriq engages subprocessors (Section 6), they act as subprocessors of the Customer's personal data.
Personal data processed through the Services is hosted in the European Union (Frankfurt, Germany). Where a subprocessor processes personal data outside the EU or Switzerland, such transfers rely on the European Commission's Standard Contractual Clauses (SCCs) together with the Swiss addendum issued by the Swiss Federal Data Protection and Information Commissioner (FDPIC), and on appropriate supplementary safeguards.
The Customer authorizes Zentriq to engage the subprocessors listed below. Each subprocessor is bound by a data processing agreement imposing protection obligations no less protective than those in this DPA.
| Subprocessor | Purpose | Used by | Region |
|---|---|---|---|
| Microsoft (Entra ID) | Sign-in & identity | Agent & PunchOut | EU / global (per Microsoft tenant) |
| Microsoft (Dynamics 365 Business Central) | ERP data source via delegated OAuth (never relocated) | Agent & PunchOut | Your BC tenant region |
| Anthropic (Claude) | AI inference, zero retention | Agent & PunchOut | EU (Frankfurt, via AWS Bedrock) |
| Stripe | Payments & subscriptions | Agent & PunchOut | EU / US |
| Vercel | Application hosting | Agent & PunchOut | EU (Frankfurt + Paris) |
| Vercel Blob | Document / file storage (Document Capture) | Agent | EU |
| Neon | PostgreSQL database (accounts, billing, conversation history) | Agent & PunchOut | EU (Frankfurt) |
| Resend | Transactional email | Agent & PunchOut | EU / US |
| Sentry | Error & performance monitoring | Agent & PunchOut | EU (Frankfurt) |
| FirstPromoter | Affiliate / referral tracking (marketing website only) | Website visitors | EU / US |
Where a region is shown as “EU / US”, the precise location depends on the provider's infrastructure; please refer to the relevant provider's own DPA for details. FirstPromoter operates only on our public marketing website to attribute referrals; it is not a subprocessor of Customer personal data processed through the authenticated Services.
We give the Customer prior notice of any intended addition or replacement of a subprocessor and a reasonable opportunity to object on legitimate grounds. To subscribe to subprocessor-change notifications, email privacy@zentriqsoftware.com.
On reasonable request, Zentriq will make available the security documentation needed to demonstrate compliance with this DPA. A SOC 2 Type II readiness assessment is in progress; Zentriq is not yet SOC 2 or ISO 27001 certified and does not claim such certifications.
Upon termination of the Services, and at the Customer's choice, Zentriq will delete or return all Customer personal data and delete existing copies, unless retention is required by applicable law (for example, Stripe billing records retained for statutory accounting periods). Customers may also delete their data, or close their account, at any time from the dashboard.
To countersign this DPA for your organization, email privacy@zentriqsoftware.com. We will return a signed copy.
For data-protection inquiries, contact us at privacy@zentriqsoftware.com.