This Data Processing Agreement ("DPA") is entered into between the entity agreeing to these terms ("Customer" or "Controller") and ZenFlowPro Ltd (company number SC879068), a company registered in Scotland with its registered office at 5 South Charlotte Street, Edinburgh, EH2 4AN ("ZenFlowPro" or "Processor").
This DPA forms part of, and supplements, the ZenFlowPro Terms of Service (the "Agreement") and applies to all Personal Data that ZenFlowPro processes on behalf of the Customer in connection with the provision of AI chatbot services.
In the event of any conflict between this DPA and the Agreement, this DPA shall prevail with respect to the processing of Personal Data.
1. Definitions
In this DPA, the following terms shall have the meanings set out below. Capitalised terms not defined herein shall have the meanings given to them in the Agreement.
- "Controller" means the natural or legal person, public authority, agency, or other body which, alone or jointly with others, determines the purposes and means of the processing of Personal Data. In the context of this DPA, the Controller is the Customer.
- "Processor" means the natural or legal person, public authority, agency, or other body which processes Personal Data on behalf of the Controller. In the context of this DPA, the Processor is ZenFlowPro Ltd.
- "Data Subject" means an identified or identifiable natural person to whom the Personal Data relates.
- "Personal Data" means any information relating to an identified or identifiable natural person, as defined under the UK GDPR and/or the EU GDPR, as applicable.
- "Processing" means any operation or set of operations performed on Personal Data, whether or not by automated means, including collection, recording, organisation, structuring, storage, adaptation, alteration, retrieval, consultation, use, disclosure by transmission, dissemination, alignment, combination, restriction, erasure, or destruction.
- "Sub-processor" means any third-party processor engaged by ZenFlowPro to process Personal Data on behalf of the Controller in connection with the services provided under the Agreement.
- "Supervisory Authority" means an independent public authority responsible for monitoring the application of data protection legislation, including (but not limited to) the UK Information Commissioner's Office (ICO) and EU member state data protection authorities.
- "UK GDPR" means the United Kingdom General Data Protection Regulation, being the retained EU law version of the GDPR as incorporated into UK law by the European Union (Withdrawal) Act 2018 and the Data Protection Act 2018.
- "EU GDPR" means Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data.
- "SCCs" means the Standard Contractual Clauses approved by the European Commission for the transfer of personal data to third countries, as adopted by Commission Implementing Decision (EU) 2021/914.
- "UK IDTA" means the International Data Transfer Agreement or UK Addendum to the EU SCCs, as approved by the UK Information Commissioner under Section 119A of the Data Protection Act 2018.
2. Scope and Purpose
2.1 This DPA supplements the ZenFlowPro Terms of Service and applies to all Personal Data processed by ZenFlowPro on behalf of the Customer in the course of providing the services described therein.
2.2 The purpose of the processing is the provision of AI chatbot services as described in the Agreement, including but not limited to:
- Operating and maintaining the AI chatbot assistant(s) configured for the Customer;
- Processing and responding to chat messages submitted by the Customer's authorised users;
- Integrating with the Customer's Microsoft 365 environment (where the M365 module is enabled), including calendar, email, and document services;
- Transcribing audio recordings of meetings (where the Meeting Transcription module is enabled);
- Generating analytics and usage reports for the Customer;
- Providing technical support and service maintenance.
2.3 The duration of the processing shall be for the term of the Agreement, unless otherwise agreed in writing by the parties.
2.4 This DPA is intended to ensure compliance with Article 28 of the UK GDPR and Article 28 of the EU GDPR, as applicable to the processing activities described herein.
3. Roles of the Parties
3.1 The Customer acts as the Data Controller. The Customer determines the purposes and means of processing Personal Data and is responsible for:
- Ensuring a lawful basis exists for the processing of Personal Data;
- Providing any required notices to, and obtaining any required consents from, Data Subjects;
- Ensuring that the Personal Data provided to ZenFlowPro is accurate and up to date;
- Complying with all applicable data protection laws in relation to its use of the services.
3.2 ZenFlowPro acts as the Data Processor. ZenFlowPro processes Personal Data solely on behalf of, and in accordance with the documented instructions of, the Controller. ZenFlowPro shall not process Personal Data for any purpose other than as set out in this DPA or as otherwise instructed by the Controller in writing.
3.3 If ZenFlowPro believes that an instruction from the Controller infringes applicable data protection legislation, ZenFlowPro shall promptly inform the Controller and shall be entitled to suspend the relevant processing until the Controller confirms or modifies the instruction.
4. Types of Personal Data Processed
The following categories of Personal Data may be processed by ZenFlowPro in the course of providing the services, depending on the modules and features enabled by the Customer:
| Category | Examples | Condition |
|---|---|---|
| Contact Data | Names, email addresses, job titles of staff members | Always (core service) |
| Conversation Content | Chat messages, questions, AI-generated responses, conversation history | Always (core service) |
| Authentication Data | Email verification codes, session tokens, OAuth tokens | Always (core service) |
| Microsoft 365 Data | Calendar events, email metadata and content, file names and metadata, SharePoint list items | If M365 module enabled |
| Audio Recordings | Meeting recordings, voice messages, transcription outputs | If Meeting Transcription module enabled |
| Usage Metadata | Timestamps, IP addresses, browser/device information, feature usage statistics | Always (core service) |
5. Categories of Data Subjects
The Personal Data processed under this DPA may relate to the following categories of Data Subjects:
- Customer's employees and staff members — individuals who are authorised by the Customer to access and use the ZenFlowPro services, including administrators and end users;
- Customer's website visitors (end users) — individuals who interact with the Customer's AI chatbot widget embedded on the Customer's website or application;
- Third parties mentioned in conversations — individuals whose Personal Data may be referenced within chat messages, calendar events, emails, or other content processed through the services (e.g., clients, partners, or contacts of the Customer).
6. Aggregated and De-Identified Data
6.1 Definition
"De-Identified Data" means information derived from Customer Data and/or usage data that has been aggregated and modified so that it: (i) does not include any personally identifiable information of any natural person; and (ii) does not identify, and cannot reasonably be used to identify, the Customer or any other entity.
6.2 Permitted Use
The Controller acknowledges and agrees that ZenFlowPro may create De-Identified Data from Customer Data and usage data, and may use such De-Identified Data for any lawful purpose, including without limitation:
- Improving, optimising, and developing the services and AI models;
- Generating aggregated analytics, benchmarks, and trend reports;
- Conducting research into customer service patterns and industry best practices;
- Publishing anonymised industry insights and benchmark reports;
- Training and fine-tuning AI models (using only anonymised, aggregated data, never individual personal data).
6.3 Ownership
ZenFlowPro retains all ownership rights in and to De-Identified Data. For the avoidance of doubt, De-Identified Data does not constitute Personal Data within the meaning of the UK GDPR or the EU GDPR (in accordance with Recital 26), and the data protection obligations set out in this DPA do not apply to De-Identified Data.
6.4 Technical Safeguards
ZenFlowPro shall apply appropriate technical measures to ensure that De-Identified Data cannot reasonably be used to identify any individual, including:
- Removal of all personal identifiers (names, email addresses, IP addresses, and other PII) prior to aggregation;
- Application of minimum group sizes to prevent identification through small datasets;
- Prohibition on any attempt to re-identify individuals from De-Identified Data.
6.5 Opt-Out
The Controller may opt out of having its data included in De-Identified Data by providing written notice to ZenFlowPro at privacy@zfp.cz. Upon receipt of such notice, ZenFlowPro shall exclude the Controller's data from future aggregation within 30 days. Previously created De-Identified Data that is already aggregated and from which the Controller's data cannot be separated shall not be affected.
7. Processor Obligations
ZenFlowPro, as the Data Processor, undertakes the following obligations:
7.1 Processing on Instructions
ZenFlowPro shall process Personal Data only on documented instructions from the Controller, including with regard to transfers of Personal Data to a third country or an international organisation, unless required to do so by applicable law. In such a case, ZenFlowPro shall inform the Controller of that legal requirement before processing, unless the law prohibits such information on important grounds of public interest.
7.2 Confidentiality
ZenFlowPro shall ensure that all persons authorised to process Personal Data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality. This obligation shall survive the termination of this DPA and the Agreement.
7.3 Security Measures
ZenFlowPro shall implement and maintain appropriate technical and organisational measures to ensure a level of security appropriate to the risk, as further detailed in Section 10 of this DPA. These measures shall be regularly reviewed and updated as necessary to address evolving threats and vulnerabilities.
7.4 Assistance with Data Subject Rights
ZenFlowPro shall assist the Controller, by appropriate technical and organisational measures (insofar as this is possible), in fulfilling the Controller's obligation to respond to requests from Data Subjects exercising their rights under applicable data protection law, including the right of access, rectification, erasure, data portability, restriction of processing, and the right to object.
7.5 Assistance with Compliance Obligations
ZenFlowPro shall assist the Controller in ensuring compliance with the obligations pursuant to Articles 32 to 36 of the UK GDPR / EU GDPR, taking into account the nature of processing and the information available to ZenFlowPro. This includes assistance with:
- Security of processing;
- Notification of personal data breaches to the Supervisory Authority;
- Communication of personal data breaches to Data Subjects;
- Data protection impact assessments (DPIAs) where required;
- Prior consultation with the Supervisory Authority.
7.6 Deletion and Return of Data
At the choice of the Controller, ZenFlowPro shall delete or return all Personal Data to the Controller after the end of the provision of services, and shall delete existing copies, unless applicable law requires storage of the Personal Data. Deletion shall be completed within 30 days of the effective date of termination. The Controller may request a data export prior to deletion.
7.7 Demonstration of Compliance
ZenFlowPro shall make available to the Controller all information necessary to demonstrate compliance with the obligations laid down in this DPA and in Article 28 of the UK GDPR / EU GDPR.
7.8 Audit and Inspection
ZenFlowPro shall allow for and contribute to audits, including inspections, conducted by the Controller or another auditor mandated by the Controller, subject to the provisions of Section 14.
8. Sub-processors
8.1 Authorisation
The Controller hereby provides general written authorisation for ZenFlowPro to engage the Sub-processors listed in the table below. ZenFlowPro shall ensure that each Sub-processor is bound by data protection obligations no less protective than those set out in this DPA.
8.2 Current List of Approved Sub-processors
| Sub-processor | Purpose | Location | Data Processed |
|---|---|---|---|
| Anthropic (Claude API) | AI response generation | USA | Conversation content |
| OpenAI (Whisper API) | Audio transcription | USA | Audio recordings |
| Microsoft Azure | Cloud hosting & storage | Canada / UK | All service data |
| Stripe | Payment processing | USA / EU | Billing data only |
| Fakturoid | Invoice generation | Czech Republic | Billing data (CZ clients) |
| ElevenLabs | Text-to-speech | USA | Text content (if TTS enabled) |
8.3 Notification of Changes
ZenFlowPro shall notify the Controller in writing at least 30 days before engaging any new Sub-processor or replacing an existing Sub-processor. Such notification shall include the identity of the proposed Sub-processor, the nature of the processing to be performed, and the location of processing. Customers may subscribe to sub-processor change notifications by emailing privacy@zfp.cz with the subject line "Sub-processor notifications".
8.4 Right to Object
The Controller may object to the appointment of a new Sub-processor by notifying ZenFlowPro in writing within 14 days of receiving the notification described in Section 8.3. The objection must be based on reasonable grounds relating to data protection. If the Controller objects, ZenFlowPro shall use commercially reasonable efforts to make available to the Controller a change in the services or recommend a commercially reasonable change to the Customer's configuration or use of the services to avoid processing of Personal Data by the objected-to Sub-processor.
If ZenFlowPro is unable to accommodate the Controller's objection within a reasonable period (not exceeding 30 days), either party may terminate the affected portion of the services by providing written notice to the other party.
8.5 Sub-processor Obligations
ZenFlowPro shall enter into a written agreement with each Sub-processor imposing data protection obligations substantially equivalent to those set out in this DPA. ZenFlowPro shall remain fully liable to the Controller for the performance of each Sub-processor's obligations.
9. International Data Transfers
9.1 Transfer Mechanisms
ZenFlowPro transfers Personal Data to countries outside the United Kingdom as part of the provision of services. The specific transfer mechanisms for each transfer route are as follows:
9.1.1 UK to Canada (Microsoft Azure Hosting)
Canada benefits from a UK adequacy decision under the Personal Information Protection and Electronic Documents Act (PIPEDA) for private-sector commercial activities. Transfers of Personal Data from the UK to Canada for the purposes of cloud hosting are therefore permitted without additional safeguards.
9.1.2 UK to United States (AI Providers, Payments)
For transfers to Sub-processors in the United States, ZenFlowPro relies on the following mechanisms, in order of preference:
- UK-US Data Bridge — the UK extension of the EU-US Data Privacy Framework (DPF). Where a Sub-processor is certified under the DPF and has self-certified for the UK Extension, this serves as the primary transfer mechanism.
- UK International Data Transfer Agreement (IDTA) or the UK Addendum to the EU Standard Contractual Clauses (SCCs), as approved by the UK Information Commissioner under Section 119A of the Data Protection Act 2018 — used as a fallback or supplementary mechanism.
9.1.3 EU to UK
For Controllers based in the European Union, transfers from the EU to the UK are covered by the renewed EU adequacy decision adopted by the European Commission on 19 December 2025, valid until 27 December 2031. No additional safeguards are required for EU-to-UK transfers.
9.1.4 Onward Transfers (UK/EU to US/Canada)
Where Personal Data originating from EU-based Controllers is transferred onward to the United States or Canada via ZenFlowPro's UK infrastructure, ZenFlowPro ensures that the onward transfer is covered by the applicable mechanisms described above (UK-US Data Bridge, IDTA, or UK Addendum to EU SCCs for US transfers; UK adequacy for Canada).
9.2 Transfer Risk Assessments
ZenFlowPro has conducted and shall maintain Transfer Risk Assessments (TRAs) for each Sub-processor located in a country without an adequacy decision. These assessments evaluate the legal framework of the recipient country, including government access to data, and the effectiveness of the supplementary measures in place. TRAs are reviewed at least annually or when material changes occur in the legal framework of the recipient country.
9.3 Supplementary Measures
In addition to the contractual safeguards described above, ZenFlowPro implements the following supplementary measures for international transfers:
- Encryption: All Personal Data is encrypted both in transit (TLS 1.2+) and at rest (AES-256) before and during transfer;
- Access controls: Strict role-based access controls ensure that only authorised personnel can access Personal Data;
- Data minimisation: Only the minimum Personal Data necessary for the specific processing purpose is transferred to each Sub-processor;
- Contractual restrictions: Sub-processors are contractually prohibited from accessing Personal Data for any purpose other than providing the contracted service;
- Transparency reporting: ZenFlowPro monitors Sub-processors' transparency reports regarding government data access requests.
10. Security Measures
ZenFlowPro implements and maintains the following technical and organisational security measures, which constitute Annex II for the purposes of the Standard Contractual Clauses:
10.1 Encryption at Rest
All stored Personal Data is encrypted at rest using AES-256 encryption with Azure-managed encryption keys. Database backups and file storage are similarly encrypted.
10.2 Encryption in Transit
All data transmitted between the Customer, ZenFlowPro's services, and Sub-processors is protected using Transport Layer Security (TLS) version 1.2 or higher. Older, less secure protocols are disabled.
10.3 Access Control
Role-based access control (RBAC) is enforced across all systems. Administrative access to production systems is restricted to authorised personnel only. Secrets and credentials are stored in Azure Key Vault and are never stored in application code or environment files. Multi-factor authentication is required for all administrative access.
10.4 Logging and Monitoring
All access to Personal Data is logged with timestamps and user identification. Audit trails are maintained and monitored for suspicious activity. Logs are retained for a minimum of 90 days and are protected against tampering.
10.5 Business Continuity
Services are hosted on Microsoft Azure with availability zone redundancy. Regular backups are performed and tested. Disaster recovery procedures are documented and periodically tested to ensure service continuity.
10.6 Personnel Security
All ZenFlowPro personnel with access to Personal Data are bound by written confidentiality agreements. Personnel receive training on data protection obligations and security best practices. Access is granted on a need-to-know basis and is promptly revoked upon termination of employment or engagement.
10.7 Incident Response
ZenFlowPro maintains documented incident response procedures that include identification, containment, eradication, recovery, and post-incident review. These procedures are tested and updated at least annually. Breach notification obligations are set out in Section 11.
10.8 Secure Development
ZenFlowPro follows secure development practices, including code review, dependency scanning, and regular security assessments. Application updates and patches are deployed through a controlled CI/CD pipeline with appropriate testing stages.
11. Data Breach Notification
11.1 Notification Obligation
ZenFlowPro shall notify the Controller without undue delay, and in any event no later than 72 hours after becoming aware of a personal data breach affecting the Controller's Personal Data. Where it is not possible to provide all information at the time of initial notification, information may be provided in phases without further undue delay.
11.2 Content of Notification
The breach notification shall include, to the extent reasonably ascertainable:
- A description of the nature of the personal data breach, including the categories and approximate number of Data Subjects concerned and the categories and approximate number of Personal Data records concerned;
- The name and contact details of ZenFlowPro's point of contact for further information;
- A description of the likely consequences of the personal data breach;
- A description of the measures taken or proposed to be taken to address the breach, including measures to mitigate its possible adverse effects.
11.3 Cooperation
ZenFlowPro shall cooperate with the Controller and take such reasonable steps as are directed by the Controller to assist in the investigation, mitigation, and remediation of the breach. ZenFlowPro shall further assist the Controller in:
- Fulfilling the Controller's obligation to notify the relevant Supervisory Authority (within 72 hours of the Controller becoming aware of the breach, per Article 33 of the UK GDPR / EU GDPR);
- Communicating the breach to affected Data Subjects where required under Article 34 of the UK GDPR / EU GDPR;
- Documenting the breach and the response measures taken.
11.4 Limitation
ZenFlowPro's obligation to report or respond to a personal data breach under this Section is not and will not be construed as an acknowledgement by ZenFlowPro of any fault or liability with respect to the breach.
12. Data Subject Requests
12.1 Forwarding Requests
If ZenFlowPro receives a request directly from a Data Subject to exercise any of their rights under applicable data protection law, ZenFlowPro shall promptly forward the request to the Controller and shall not respond to the request directly unless authorised by the Controller to do so.
12.2 Assistance
ZenFlowPro shall assist the Controller in responding to Data Subject requests within the timeframes required by applicable law (typically one month, extendable by a further two months for complex requests). Such assistance shall include providing the Controller with the technical capability to:
- Access and retrieve Personal Data held within the services;
- Rectify inaccurate Personal Data;
- Erase Personal Data (right to be forgotten);
- Export Personal Data in a structured, commonly used, and machine-readable format (data portability);
- Restrict the processing of Personal Data.
12.3 Technical Measures
ZenFlowPro provides the following technical measures to support the fulfilment of Data Subject requests:
- Data Export API — enables the Controller to export all Personal Data associated with a specific Data Subject in JSON format;
- Data Deletion API — enables the Controller to request the permanent deletion of all Personal Data associated with a specific Data Subject;
- Admin Dashboard — provides the Controller with self-service tools for viewing, exporting, and managing user data.
13. Data Protection Impact Assessment
13.1 ZenFlowPro's DPIA
ZenFlowPro has conducted a Data Protection Impact Assessment (DPIA) in respect of its AI chatbot processing activities, as required by Article 35 of the UK GDPR and EU GDPR where processing is likely to result in a high risk to the rights and freedoms of natural persons. The DPIA covers the core processing activities described in Section 2 of this DPA, including AI-powered conversation processing, audio transcription, and Microsoft 365 integration.
13.2 Access to DPIA
The Controller may request a summary of the relevant portions of ZenFlowPro's DPIA by writing to privacy@zfp.cz. ZenFlowPro will provide such summary within 30 days of a reasonable request, subject to redaction of commercially sensitive information.
13.3 Assistance with Controller's DPIA
Where the Controller is required to conduct its own DPIA in relation to its use of the services, ZenFlowPro shall provide reasonable assistance to the Controller, including:
- Providing information about the nature, scope, context, and purposes of processing;
- Providing details of the technical and organisational security measures in place;
- Assisting with the assessment of necessity and proportionality;
- Assisting with the identification and assessment of risks to the rights and freedoms of Data Subjects.
14. Audit Rights
14.1 Right to Audit
The Controller (or a qualified third-party auditor appointed by the Controller) may audit ZenFlowPro's compliance with this DPA upon providing at least 30 days' prior written notice. Audits shall be conducted during normal business hours and shall not unreasonably interfere with ZenFlowPro's business operations.
14.2 Alternative Assurance
In lieu of an on-site audit, ZenFlowPro may, at its discretion, provide the Controller with:
- A summary of the results of an independent third-party audit or certification (such as SOC 2 Type II or ISO 27001), where available;
- Responses to a reasonable written information security questionnaire;
- Relevant documentation demonstrating compliance with the obligations set out in this DPA.
The Controller shall consider such alternative assurance in good faith before exercising its right to an on-site audit.
14.3 Costs
The Controller shall bear all costs associated with an audit, including the costs of the auditor and any reasonable expenses incurred by ZenFlowPro in facilitating the audit. However, if the audit reveals a material breach of this DPA by ZenFlowPro, ZenFlowPro shall bear the reasonable costs of the audit.
14.4 Confidentiality
Any information obtained or generated during an audit shall be treated as confidential information of ZenFlowPro and shall only be used for the purpose of verifying compliance with this DPA. The Controller shall ensure that any third-party auditor is bound by appropriate confidentiality obligations.
15. EU AI Act Compliance
15.1 Classification
The ZenFlowPro AI chatbot is classified as a limited risk AI system under the EU AI Act (Regulation 2024/1689), being an AI system intended to interact directly with natural persons. It is not classified as a high-risk AI system under Annex III of the EU AI Act, unless the Controller deploys it in a domain listed in Annex III (such as healthcare, legal services, employment, or education).
15.2 Transparency Obligations
In compliance with Article 50 of the EU AI Act (effective 2 August 2026), ZenFlowPro ensures that:
- All individuals interacting with the chatbot are clearly informed that they are communicating with an AI system;
- The chatbot widget displays an "AI-powered" indicator;
- AI-generated content is labelled in a machine-readable format in accordance with applicable transparency requirements as they come into effect.
15.3 AI Literacy
In compliance with Article 4 of the EU AI Act (effective since 2 February 2025), ZenFlowPro ensures that its staff members involved in the operation and oversight of AI systems have a sufficient level of AI literacy, taking into account their technical knowledge, experience, education, and the context in which the AI systems are used.
15.4 Controller's Obligations
Where the Controller deploys the ZenFlowPro chatbot in a domain that may be classified as high-risk under Annex III of the EU AI Act (including but not limited to healthcare, legal services, employment decisions, creditworthiness assessments, or education), the Controller is solely responsible for:
- Conducting the appropriate conformity assessment;
- Implementing human oversight measures;
- Maintaining appropriate records and documentation;
- Complying with all applicable high-risk AI system obligations.
ZenFlowPro will provide reasonable technical assistance to support the Controller's compliance efforts upon written request.
15.5 UK AI Governance
ZenFlowPro is committed to the UK's five cross-sector AI governance principles: safety and security, transparency and explainability, fairness, accountability and governance, and contestability and redress. ZenFlowPro will monitor and comply with any future UK AI legislation as it is enacted.
16. Term and Termination
16.1 Duration
This DPA shall become effective on the date the Customer accepts the Agreement (or, where applicable, the date this DPA is separately executed by both parties) and shall remain in effect for the duration of the Agreement. This DPA shall automatically terminate upon termination or expiry of the Agreement.
16.2 Post-Termination Data Handling
Upon termination or expiry of the Agreement:
- The Controller may request a complete export of all Personal Data held by ZenFlowPro in a structured, commonly used, and machine-readable format. Such request must be made within 30 days of the effective date of termination.
- Following the expiry of the 30-day period (or upon completion of the data export, whichever is later), ZenFlowPro shall securely delete all Personal Data in its possession, including all copies held by Sub-processors, within 30 days.
- ZenFlowPro shall provide written confirmation of deletion upon the Controller's request.
16.3 Exceptions to Deletion
ZenFlowPro may retain Personal Data beyond the periods specified above to the extent required by applicable law (for example, billing and transaction records required for tax or accounting purposes). Such retained data shall continue to be protected in accordance with this DPA and shall be processed only for the purpose of complying with the applicable legal obligation.
16.4 Survival
Sections 7.2 (Confidentiality), 11 (Data Breach Notification), 14 (Audit Rights), and 17 (Liability) shall survive the termination of this DPA.
17. Liability
17.1 Limitation
The liability of each party under or in connection with this DPA shall be subject to the exclusions and limitations of liability set out in the Agreement (Terms of Service).
17.2 Indemnification
Each party shall indemnify the other party against all costs, claims, damages, or expenses incurred by the other party or for which the other party may become liable due to any failure by the first party or its employees or agents to comply with any of its obligations under this DPA or applicable data protection law.
18. Governing Law
18.1 Applicable Law
This DPA shall be governed by and construed in accordance with the laws of Scotland.
18.2 Jurisdiction
The Scottish courts shall have exclusive jurisdiction to settle any dispute arising out of or in connection with this DPA, including any dispute regarding its existence, validity, or termination.
18.3 Regulatory Compliance
Nothing in this DPA shall be construed to limit or exclude either party's obligations under the UK GDPR, the EU GDPR, the Data Protection Act 2018, or any other applicable data protection legislation. Where this DPA conflicts with mandatory data protection law, the mandatory provisions of such law shall prevail.
— End of Data Processing Agreement —
If you have questions about this DPA, please contact us at privacy@zfp.cz.