ZenFlowPro

Data Processing Agreement

Last Updated: 25 February 2026 Effective: 1 April 2026 Version 2.0

This Data Processing Agreement ("DPA") is entered into between the entity agreeing to these terms ("Customer" or "Controller") and ZenFlowPro Ltd (company number SC879068), a company registered in Scotland with its registered office at 5 South Charlotte Street, Edinburgh, EH2 4AN ("ZenFlowPro" or "Processor").

This DPA forms part of, and supplements, the ZenFlowPro Terms of Service (the "Agreement") and applies to all Personal Data that ZenFlowPro processes on behalf of the Customer in connection with the provision of AI chatbot services.

In the event of any conflict between this DPA and the Agreement, this DPA shall prevail with respect to the processing of Personal Data.

1. Definitions

In this DPA, the following terms shall have the meanings set out below. Capitalised terms not defined herein shall have the meanings given to them in the Agreement.

2. Scope and Purpose

2.1 This DPA supplements the ZenFlowPro Terms of Service and applies to all Personal Data processed by ZenFlowPro on behalf of the Customer in the course of providing the services described therein.

2.2 The purpose of the processing is the provision of AI chatbot services as described in the Agreement, including but not limited to:

2.3 The duration of the processing shall be for the term of the Agreement, unless otherwise agreed in writing by the parties.

2.4 This DPA is intended to ensure compliance with Article 28 of the UK GDPR and Article 28 of the EU GDPR, as applicable to the processing activities described herein.

3. Roles of the Parties

3.1 The Customer acts as the Data Controller. The Customer determines the purposes and means of processing Personal Data and is responsible for:

3.2 ZenFlowPro acts as the Data Processor. ZenFlowPro processes Personal Data solely on behalf of, and in accordance with the documented instructions of, the Controller. ZenFlowPro shall not process Personal Data for any purpose other than as set out in this DPA or as otherwise instructed by the Controller in writing.

3.3 If ZenFlowPro believes that an instruction from the Controller infringes applicable data protection legislation, ZenFlowPro shall promptly inform the Controller and shall be entitled to suspend the relevant processing until the Controller confirms or modifies the instruction.

4. Types of Personal Data Processed

The following categories of Personal Data may be processed by ZenFlowPro in the course of providing the services, depending on the modules and features enabled by the Customer:

Category Examples Condition
Contact Data Names, email addresses, job titles of staff members Always (core service)
Conversation Content Chat messages, questions, AI-generated responses, conversation history Always (core service)
Authentication Data Email verification codes, session tokens, OAuth tokens Always (core service)
Microsoft 365 Data Calendar events, email metadata and content, file names and metadata, SharePoint list items If M365 module enabled
Audio Recordings Meeting recordings, voice messages, transcription outputs If Meeting Transcription module enabled
Usage Metadata Timestamps, IP addresses, browser/device information, feature usage statistics Always (core service)
Note: ZenFlowPro does not intentionally collect or process special categories of personal data (e.g., data revealing racial or ethnic origin, health data, biometric data). If such data is incidentally included in conversation content by users, the Customer is responsible for ensuring an appropriate legal basis exists for such processing.

5. Categories of Data Subjects

The Personal Data processed under this DPA may relate to the following categories of Data Subjects:

6. Aggregated and De-Identified Data

6.1 Definition

"De-Identified Data" means information derived from Customer Data and/or usage data that has been aggregated and modified so that it: (i) does not include any personally identifiable information of any natural person; and (ii) does not identify, and cannot reasonably be used to identify, the Customer or any other entity.

6.2 Permitted Use

The Controller acknowledges and agrees that ZenFlowPro may create De-Identified Data from Customer Data and usage data, and may use such De-Identified Data for any lawful purpose, including without limitation:

6.3 Ownership

ZenFlowPro retains all ownership rights in and to De-Identified Data. For the avoidance of doubt, De-Identified Data does not constitute Personal Data within the meaning of the UK GDPR or the EU GDPR (in accordance with Recital 26), and the data protection obligations set out in this DPA do not apply to De-Identified Data.

6.4 Technical Safeguards

ZenFlowPro shall apply appropriate technical measures to ensure that De-Identified Data cannot reasonably be used to identify any individual, including:

6.5 Opt-Out

The Controller may opt out of having its data included in De-Identified Data by providing written notice to ZenFlowPro at privacy@zfp.cz. Upon receipt of such notice, ZenFlowPro shall exclude the Controller's data from future aggregation within 30 days. Previously created De-Identified Data that is already aggregated and from which the Controller's data cannot be separated shall not be affected.

7. Processor Obligations

ZenFlowPro, as the Data Processor, undertakes the following obligations:

7.1 Processing on Instructions

ZenFlowPro shall process Personal Data only on documented instructions from the Controller, including with regard to transfers of Personal Data to a third country or an international organisation, unless required to do so by applicable law. In such a case, ZenFlowPro shall inform the Controller of that legal requirement before processing, unless the law prohibits such information on important grounds of public interest.

7.2 Confidentiality

ZenFlowPro shall ensure that all persons authorised to process Personal Data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality. This obligation shall survive the termination of this DPA and the Agreement.

7.3 Security Measures

ZenFlowPro shall implement and maintain appropriate technical and organisational measures to ensure a level of security appropriate to the risk, as further detailed in Section 10 of this DPA. These measures shall be regularly reviewed and updated as necessary to address evolving threats and vulnerabilities.

7.4 Assistance with Data Subject Rights

ZenFlowPro shall assist the Controller, by appropriate technical and organisational measures (insofar as this is possible), in fulfilling the Controller's obligation to respond to requests from Data Subjects exercising their rights under applicable data protection law, including the right of access, rectification, erasure, data portability, restriction of processing, and the right to object.

7.5 Assistance with Compliance Obligations

ZenFlowPro shall assist the Controller in ensuring compliance with the obligations pursuant to Articles 32 to 36 of the UK GDPR / EU GDPR, taking into account the nature of processing and the information available to ZenFlowPro. This includes assistance with:

7.6 Deletion and Return of Data

At the choice of the Controller, ZenFlowPro shall delete or return all Personal Data to the Controller after the end of the provision of services, and shall delete existing copies, unless applicable law requires storage of the Personal Data. Deletion shall be completed within 30 days of the effective date of termination. The Controller may request a data export prior to deletion.

7.7 Demonstration of Compliance

ZenFlowPro shall make available to the Controller all information necessary to demonstrate compliance with the obligations laid down in this DPA and in Article 28 of the UK GDPR / EU GDPR.

7.8 Audit and Inspection

ZenFlowPro shall allow for and contribute to audits, including inspections, conducted by the Controller or another auditor mandated by the Controller, subject to the provisions of Section 14.

8. Sub-processors

8.1 Authorisation

The Controller hereby provides general written authorisation for ZenFlowPro to engage the Sub-processors listed in the table below. ZenFlowPro shall ensure that each Sub-processor is bound by data protection obligations no less protective than those set out in this DPA.

8.2 Current List of Approved Sub-processors

Sub-processor Purpose Location Data Processed
Anthropic (Claude API) AI response generation USA Conversation content
OpenAI (Whisper API) Audio transcription USA Audio recordings
Microsoft Azure Cloud hosting & storage Canada / UK All service data
Stripe Payment processing USA / EU Billing data only
Fakturoid Invoice generation Czech Republic Billing data (CZ clients)
ElevenLabs Text-to-speech USA Text content (if TTS enabled)

8.3 Notification of Changes

ZenFlowPro shall notify the Controller in writing at least 30 days before engaging any new Sub-processor or replacing an existing Sub-processor. Such notification shall include the identity of the proposed Sub-processor, the nature of the processing to be performed, and the location of processing. Customers may subscribe to sub-processor change notifications by emailing privacy@zfp.cz with the subject line "Sub-processor notifications".

8.4 Right to Object

The Controller may object to the appointment of a new Sub-processor by notifying ZenFlowPro in writing within 14 days of receiving the notification described in Section 8.3. The objection must be based on reasonable grounds relating to data protection. If the Controller objects, ZenFlowPro shall use commercially reasonable efforts to make available to the Controller a change in the services or recommend a commercially reasonable change to the Customer's configuration or use of the services to avoid processing of Personal Data by the objected-to Sub-processor.

If ZenFlowPro is unable to accommodate the Controller's objection within a reasonable period (not exceeding 30 days), either party may terminate the affected portion of the services by providing written notice to the other party.

8.5 Sub-processor Obligations

ZenFlowPro shall enter into a written agreement with each Sub-processor imposing data protection obligations substantially equivalent to those set out in this DPA. ZenFlowPro shall remain fully liable to the Controller for the performance of each Sub-processor's obligations.

9. International Data Transfers

9.1 Transfer Mechanisms

ZenFlowPro transfers Personal Data to countries outside the United Kingdom as part of the provision of services. The specific transfer mechanisms for each transfer route are as follows:

9.1.1 UK to Canada (Microsoft Azure Hosting)

Canada benefits from a UK adequacy decision under the Personal Information Protection and Electronic Documents Act (PIPEDA) for private-sector commercial activities. Transfers of Personal Data from the UK to Canada for the purposes of cloud hosting are therefore permitted without additional safeguards.

9.1.2 UK to United States (AI Providers, Payments)

For transfers to Sub-processors in the United States, ZenFlowPro relies on the following mechanisms, in order of preference:

9.1.3 EU to UK

For Controllers based in the European Union, transfers from the EU to the UK are covered by the renewed EU adequacy decision adopted by the European Commission on 19 December 2025, valid until 27 December 2031. No additional safeguards are required for EU-to-UK transfers.

9.1.4 Onward Transfers (UK/EU to US/Canada)

Where Personal Data originating from EU-based Controllers is transferred onward to the United States or Canada via ZenFlowPro's UK infrastructure, ZenFlowPro ensures that the onward transfer is covered by the applicable mechanisms described above (UK-US Data Bridge, IDTA, or UK Addendum to EU SCCs for US transfers; UK adequacy for Canada).

9.2 Transfer Risk Assessments

ZenFlowPro has conducted and shall maintain Transfer Risk Assessments (TRAs) for each Sub-processor located in a country without an adequacy decision. These assessments evaluate the legal framework of the recipient country, including government access to data, and the effectiveness of the supplementary measures in place. TRAs are reviewed at least annually or when material changes occur in the legal framework of the recipient country.

9.3 Supplementary Measures

In addition to the contractual safeguards described above, ZenFlowPro implements the following supplementary measures for international transfers:

10. Security Measures

ZenFlowPro implements and maintains the following technical and organisational security measures, which constitute Annex II for the purposes of the Standard Contractual Clauses:

10.1 Encryption at Rest

All stored Personal Data is encrypted at rest using AES-256 encryption with Azure-managed encryption keys. Database backups and file storage are similarly encrypted.

10.2 Encryption in Transit

All data transmitted between the Customer, ZenFlowPro's services, and Sub-processors is protected using Transport Layer Security (TLS) version 1.2 or higher. Older, less secure protocols are disabled.

10.3 Access Control

Role-based access control (RBAC) is enforced across all systems. Administrative access to production systems is restricted to authorised personnel only. Secrets and credentials are stored in Azure Key Vault and are never stored in application code or environment files. Multi-factor authentication is required for all administrative access.

10.4 Logging and Monitoring

All access to Personal Data is logged with timestamps and user identification. Audit trails are maintained and monitored for suspicious activity. Logs are retained for a minimum of 90 days and are protected against tampering.

10.5 Business Continuity

Services are hosted on Microsoft Azure with availability zone redundancy. Regular backups are performed and tested. Disaster recovery procedures are documented and periodically tested to ensure service continuity.

10.6 Personnel Security

All ZenFlowPro personnel with access to Personal Data are bound by written confidentiality agreements. Personnel receive training on data protection obligations and security best practices. Access is granted on a need-to-know basis and is promptly revoked upon termination of employment or engagement.

10.7 Incident Response

ZenFlowPro maintains documented incident response procedures that include identification, containment, eradication, recovery, and post-incident review. These procedures are tested and updated at least annually. Breach notification obligations are set out in Section 11.

10.8 Secure Development

ZenFlowPro follows secure development practices, including code review, dependency scanning, and regular security assessments. Application updates and patches are deployed through a controlled CI/CD pipeline with appropriate testing stages.

11. Data Breach Notification

11.1 Notification Obligation

ZenFlowPro shall notify the Controller without undue delay, and in any event no later than 72 hours after becoming aware of a personal data breach affecting the Controller's Personal Data. Where it is not possible to provide all information at the time of initial notification, information may be provided in phases without further undue delay.

11.2 Content of Notification

The breach notification shall include, to the extent reasonably ascertainable:

  1. A description of the nature of the personal data breach, including the categories and approximate number of Data Subjects concerned and the categories and approximate number of Personal Data records concerned;
  2. The name and contact details of ZenFlowPro's point of contact for further information;
  3. A description of the likely consequences of the personal data breach;
  4. A description of the measures taken or proposed to be taken to address the breach, including measures to mitigate its possible adverse effects.

11.3 Cooperation

ZenFlowPro shall cooperate with the Controller and take such reasonable steps as are directed by the Controller to assist in the investigation, mitigation, and remediation of the breach. ZenFlowPro shall further assist the Controller in:

11.4 Limitation

ZenFlowPro's obligation to report or respond to a personal data breach under this Section is not and will not be construed as an acknowledgement by ZenFlowPro of any fault or liability with respect to the breach.

12. Data Subject Requests

12.1 Forwarding Requests

If ZenFlowPro receives a request directly from a Data Subject to exercise any of their rights under applicable data protection law, ZenFlowPro shall promptly forward the request to the Controller and shall not respond to the request directly unless authorised by the Controller to do so.

12.2 Assistance

ZenFlowPro shall assist the Controller in responding to Data Subject requests within the timeframes required by applicable law (typically one month, extendable by a further two months for complex requests). Such assistance shall include providing the Controller with the technical capability to:

12.3 Technical Measures

ZenFlowPro provides the following technical measures to support the fulfilment of Data Subject requests:

13. Data Protection Impact Assessment

13.1 ZenFlowPro's DPIA

ZenFlowPro has conducted a Data Protection Impact Assessment (DPIA) in respect of its AI chatbot processing activities, as required by Article 35 of the UK GDPR and EU GDPR where processing is likely to result in a high risk to the rights and freedoms of natural persons. The DPIA covers the core processing activities described in Section 2 of this DPA, including AI-powered conversation processing, audio transcription, and Microsoft 365 integration.

13.2 Access to DPIA

The Controller may request a summary of the relevant portions of ZenFlowPro's DPIA by writing to privacy@zfp.cz. ZenFlowPro will provide such summary within 30 days of a reasonable request, subject to redaction of commercially sensitive information.

13.3 Assistance with Controller's DPIA

Where the Controller is required to conduct its own DPIA in relation to its use of the services, ZenFlowPro shall provide reasonable assistance to the Controller, including:

14. Audit Rights

14.1 Right to Audit

The Controller (or a qualified third-party auditor appointed by the Controller) may audit ZenFlowPro's compliance with this DPA upon providing at least 30 days' prior written notice. Audits shall be conducted during normal business hours and shall not unreasonably interfere with ZenFlowPro's business operations.

14.2 Alternative Assurance

In lieu of an on-site audit, ZenFlowPro may, at its discretion, provide the Controller with:

The Controller shall consider such alternative assurance in good faith before exercising its right to an on-site audit.

14.3 Costs

The Controller shall bear all costs associated with an audit, including the costs of the auditor and any reasonable expenses incurred by ZenFlowPro in facilitating the audit. However, if the audit reveals a material breach of this DPA by ZenFlowPro, ZenFlowPro shall bear the reasonable costs of the audit.

14.4 Confidentiality

Any information obtained or generated during an audit shall be treated as confidential information of ZenFlowPro and shall only be used for the purpose of verifying compliance with this DPA. The Controller shall ensure that any third-party auditor is bound by appropriate confidentiality obligations.

15. EU AI Act Compliance

15.1 Classification

The ZenFlowPro AI chatbot is classified as a limited risk AI system under the EU AI Act (Regulation 2024/1689), being an AI system intended to interact directly with natural persons. It is not classified as a high-risk AI system under Annex III of the EU AI Act, unless the Controller deploys it in a domain listed in Annex III (such as healthcare, legal services, employment, or education).

15.2 Transparency Obligations

In compliance with Article 50 of the EU AI Act (effective 2 August 2026), ZenFlowPro ensures that:

15.3 AI Literacy

In compliance with Article 4 of the EU AI Act (effective since 2 February 2025), ZenFlowPro ensures that its staff members involved in the operation and oversight of AI systems have a sufficient level of AI literacy, taking into account their technical knowledge, experience, education, and the context in which the AI systems are used.

15.4 Controller's Obligations

Where the Controller deploys the ZenFlowPro chatbot in a domain that may be classified as high-risk under Annex III of the EU AI Act (including but not limited to healthcare, legal services, employment decisions, creditworthiness assessments, or education), the Controller is solely responsible for:

ZenFlowPro will provide reasonable technical assistance to support the Controller's compliance efforts upon written request.

15.5 UK AI Governance

ZenFlowPro is committed to the UK's five cross-sector AI governance principles: safety and security, transparency and explainability, fairness, accountability and governance, and contestability and redress. ZenFlowPro will monitor and comply with any future UK AI legislation as it is enacted.

16. Term and Termination

16.1 Duration

This DPA shall become effective on the date the Customer accepts the Agreement (or, where applicable, the date this DPA is separately executed by both parties) and shall remain in effect for the duration of the Agreement. This DPA shall automatically terminate upon termination or expiry of the Agreement.

16.2 Post-Termination Data Handling

Upon termination or expiry of the Agreement:

  1. The Controller may request a complete export of all Personal Data held by ZenFlowPro in a structured, commonly used, and machine-readable format. Such request must be made within 30 days of the effective date of termination.
  2. Following the expiry of the 30-day period (or upon completion of the data export, whichever is later), ZenFlowPro shall securely delete all Personal Data in its possession, including all copies held by Sub-processors, within 30 days.
  3. ZenFlowPro shall provide written confirmation of deletion upon the Controller's request.

16.3 Exceptions to Deletion

ZenFlowPro may retain Personal Data beyond the periods specified above to the extent required by applicable law (for example, billing and transaction records required for tax or accounting purposes). Such retained data shall continue to be protected in accordance with this DPA and shall be processed only for the purpose of complying with the applicable legal obligation.

16.4 Survival

Sections 7.2 (Confidentiality), 11 (Data Breach Notification), 14 (Audit Rights), and 17 (Liability) shall survive the termination of this DPA.

17. Liability

17.1 Limitation

The liability of each party under or in connection with this DPA shall be subject to the exclusions and limitations of liability set out in the Agreement (Terms of Service).

17.2 Indemnification

Each party shall indemnify the other party against all costs, claims, damages, or expenses incurred by the other party or for which the other party may become liable due to any failure by the first party or its employees or agents to comply with any of its obligations under this DPA or applicable data protection law.

18. Governing Law

18.1 Applicable Law

This DPA shall be governed by and construed in accordance with the laws of Scotland.

18.2 Jurisdiction

The Scottish courts shall have exclusive jurisdiction to settle any dispute arising out of or in connection with this DPA, including any dispute regarding its existence, validity, or termination.

18.3 Regulatory Compliance

Nothing in this DPA shall be construed to limit or exclude either party's obligations under the UK GDPR, the EU GDPR, the Data Protection Act 2018, or any other applicable data protection legislation. Where this DPA conflicts with mandatory data protection law, the mandatory provisions of such law shall prevail.

— End of Data Processing Agreement —

If you have questions about this DPA, please contact us at privacy@zfp.cz.