In plain language
A quick orientation. The numbered sections below are the binding text.
- This DPA applies automatically whenever your agents process other people's personal data on Zoft. You are the controller; Zoft is the processor and follows your instructions.
- It covers what the law requires of a processor: instructions, confidentiality, security, sub-processors, help with data-subject requests and impact assessments, breach notification, audits, and deletion at the end.
- Transfers out of the EEA, UK and Switzerland are covered by the EU Standard Contractual Clauses and UK Addendum, incorporated by reference. Indian DPDP and US state-law terms are included too.
- You can accept it by using the Service, or contact sales if your procurement process needs a countersigned copy.
1. Parties, scope and order of precedence
This Data Processing Addendum ("DPA") forms part of the Terms of Service or other agreement (the "Agreement") between Zoft.AI Private Limited ("Zoft" or "Processor") and the customer accepting the Agreement ("Customer" or "Controller"). It applies to the extent Zoft processes Personal Data on behalf of Customer in providing the Service ("Customer Personal Data").
If this DPA conflicts with the Agreement, this DPA prevails for data-protection matters. If the Standard Contractual Clauses incorporated in Section 9 conflict with this DPA, the Clauses prevail. Capitalised terms not defined here have the meaning given in the Agreement.
This DPA does not apply to personal data for which Zoft is the controller — account, billing, and Site data — which is governed by the Privacy Policy.
2. Definitions
- Data Protection Laws
- All laws applying to the processing of Customer Personal Data under this DPA, including the Digital Personal Data Protection Act, 2023 (India) and rules made under it; Regulation (EU) 2016/679 (GDPR); the UK GDPR and Data Protection Act 2018; the Swiss Federal Act on Data Protection; the California Consumer Privacy Act as amended by the CPRA and other US state privacy laws; and any successor legislation.
- Personal Data, Controller, Processor, Data Subject, Processing, Personal Data Breach, Supervisory Authority
- Have the meanings given in the GDPR, and the corresponding meanings under other Data Protection Laws (for example "Data Fiduciary", "Data Processor" and "Data Principal" under the DPDP Act; "Business", "Service Provider" and "Consumer" under the CCPA).
- Standard Contractual Clauses or SCCs
- The clauses annexed to European Commission Implementing Decision (EU) 2021/914, and for UK transfers the International Data Transfer Addendum issued by the UK Information Commissioner under s.119A of the Data Protection Act 2018.
- Sub-processor
- Any third party engaged by Zoft to process Customer Personal Data.
3. Roles and processing instructions
- Customer is the Controller (or a Processor acting on behalf of a third-party controller, in which case Customer warrants that its instructions are authorised by that controller) and Zoft is the Processor.
- Zoft will process Customer Personal Data only on Customer's documented instructions, which consist of: the Agreement; this DPA; Customer's configuration of Agents, workflows, Connected Services and workspace settings; and other written instructions Customer gives through the Service or to privacy@zoft.ai. Zoft will not process Customer Personal Data for its own purposes.
- Zoft will inform Customer without delay if, in its opinion, an instruction infringes Data Protection Laws, and may suspend the affected processing until the instruction is amended. Zoft is not obliged to perform a legal review of Customer's instructions.
- Where Zoft is required by law to process Customer Personal Data other than on Customer's instructions, Zoft will inform Customer of that requirement before processing unless the law prohibits it.
- Customer is responsible for the lawfulness of the Customer Personal Data it provides and the instructions it gives, including obtaining all consents, providing all notices and making all disclosures that Data Protection Laws require of a Controller, and for the accuracy and quality of Customer Personal Data.
4. Details of processing (Annex I)
| Item | Description |
|---|---|
| Subject matter | Provision of the Zoft agentic AI platform: building and running voice, chat, browser and workflow agents on Customer's behalf. |
| Duration | The term of the Agreement plus the export and deletion periods in Section 11. |
| Nature and purpose | Hosting, storage, transmission, transcription, speech synthesis, retrieval, language-model inference, tool execution against Connected Services, browser automation, workflow orchestration, logging and display in the Customer's workspace, as configured by Customer. |
| Categories of Data Subjects | Customer's customers, prospects, patients, tenants, employees, contractors, suppliers and other individuals who interact with Customer's Agents or whose data is held in Customer's Connected Services; Customer's Authorised Users. |
| Categories of Personal Data | Contact details (name, phone, email, address); identifiers on channels (phone number, messaging-channel ID, chat session ID); voice recordings and transcripts; chat transcripts; appointment, order, ticket and account details; free-text content of conversations; browser session content; any other data Customer chooses to process. |
| Special categories | Only if Customer configures Agents to process them, and subject to Terms §6.3. May include health, financial or biometric (voice) data. Customer is responsible for the additional safeguards and legal bases these require. |
| Frequency | Continuous, for as long as Agents are deployed. |
5. Sub-processors
- Customer gives Zoft general written authorisation to engage Sub-processors. The current list, including location, purpose and the Customer action that engages each one, is at /legal/subprocessors.
- Zoft will impose on each Sub-processor, by written contract, data-protection obligations no less protective than those in this DPA, and remains fully liable to Customer for the Sub-processor's performance.
- Zoft will give at least 30 days' notice before a new Sub-processor processes Customer Personal Data, by updating the list and emailing customers who have subscribed to notices at privacy@zoft.ai. Customer may object within that period on reasonable, documented data-protection grounds. The parties will discuss in good faith; if Zoft cannot reasonably accommodate the objection, Customer may terminate the affected part of the Service on written notice and receive a pro-rated refund of prepaid fees.
- Model, speech, telephony and messaging Sub-processors are engaged only when Customer selects that model or connects that channel; Customer may avoid a particular Sub-processor by not selecting it.
6. Security measures (Annex II)
Taking into account the state of the art, the costs of implementation and the nature, scope, context and purposes of processing, Zoft implements and maintains the following technical and organisational measures, and will not materially decrease the overall security of the Service during the term:
| Area | Measures |
|---|---|
| Encryption | TLS 1.2 or higher in transit. AES-256 or equivalent at rest for databases, object storage and backups. Application-layer encryption of Connected Service credentials and API keys with keys stored separately from data. |
| Access control | Per-workspace logical isolation. Role-based access control for Customer's Authorised Users. Least-privilege, named accounts with mandatory multi-factor authentication for Zoft personnel; production access is time-bound, logged and reviewed at least quarterly. |
| Agent controls | Per-tool permissions, human-approval gates, run records of every input, output and tool call, and evaluation suites so Customer can constrain and verify Agent behaviour before and after deployment. |
| Execution isolation | Workflows and browser agents run in isolated execution environments that are torn down after the run. Secrets are injected at run time and never written to logs. |
| Availability and resilience | Redundant infrastructure across availability zones, automated encrypted backups with tested restore procedures, monitoring and on-call alerting. |
| Secure development | Code review for all changes, automated dependency and secret scanning, separation of development, staging and production environments, and periodic penetration testing. |
| Personnel | Confidentiality obligations in employment and contractor agreements, security and privacy training on joining and annually, and background checks where lawful. |
| Incident management | Documented incident-response procedure, 24/7 alerting, and post-incident review. Vulnerability reports to security@zoft.ai acknowledged within two business days. |
| Data minimisation and deletion | Customer-configurable retention for recordings, transcripts and run records; deletion tooling in the Service; certified deletion on termination per Section 11. |
7. Confidentiality and personnel
Zoft will ensure that every person it authorises to process Customer Personal Data is bound by a duty of confidentiality, receives appropriate training, and accesses Customer Personal Data only to the extent needed to provide the Service, to support Customer at Customer's request, to investigate abuse or a security incident, or as required by law. Such access is logged.
8. Assistance to Customer
8.1 Data Subject requests
The Service provides search, export, correction and deletion tools that Customer can use to respond to Data Subject requests directly. If Zoft receives a request from a Data Subject relating to Customer Personal Data, Zoft will not respond substantively except to direct the Data Subject to Customer, and will notify Customer within five business days. Zoft will provide reasonable additional assistance at Customer's request and, where the effort is significant, at Zoft's then-current professional-services rates.
8.2 Impact assessments and consultations
Zoft will provide the information reasonably available to it — including this DPA, the Sub-processor list, security documentation and descriptions of processing — to help Customer carry out data-protection impact assessments and any prior consultation with a Supervisory Authority.
8.3 Personal Data Breach
Zoft will notify Customer without undue delay, and in any event within 48 hours, after confirming a Personal Data Breach affecting Customer Personal Data. The notice will describe the nature of the breach, the categories and approximate number of Data Subjects and records affected, the likely consequences, the measures taken or proposed, and a contact point, and will be updated as more information becomes available. Zoft will cooperate with Customer's investigation and Customer's notifications to Supervisory Authorities and Data Subjects. Zoft's notification of a breach is not an acknowledgement of fault.
9. International transfers (Annex III)
Zoft processes Customer Personal Data in the United States (AWS us-east-1), and Zoft personnel access it from India. Customer authorises these transfers and any onward transfers to Sub-processors in the locations listed on the Sub-processor page, subject to the following safeguards:
- EEA transfers. The SCCs are incorporated by reference and apply with Module Two (controller to processor) where Customer is a controller and Module Three (processor to processor) where Customer is a processor. Clause 7 (docking) is included; Clause 9 option 2 (general authorisation) applies with the notice period in Section 5; Clause 11 optional language is not included; Clause 13 and 17: the law of Ireland; Clause 18: the courts of Ireland. Annexes I, II and III are completed by Sections 4, 6 and the Sub-processor page respectively.
- UK transfers. The UK International Data Transfer Addendum (version B1.0) applies to the SCCs, with the tables completed by reference to this DPA and either party able to end it under section 19.
- Swiss transfers. The SCCs apply as adapted by the FDPIC guidance: references to the GDPR are to the Swiss FADP, the competent authority is the FDPIC, and Swiss law and courts apply to data subjects in Switzerland.
- Indian transfers. Transfers comply with section 16 of the DPDP Act and any restriction notified by the Central Government.
- Supplementary measures. Encryption in transit and at rest, application-layer encryption of credentials, minimisation of Personal Data sent to model providers to what the Agent requires, and the transparency commitments in Section 10.
If a transfer mechanism relied on above is invalidated or Zoft is unable to comply with it, Zoft will promptly inform Customer, and the parties will cooperate in good faith to implement an alternative lawful mechanism.
10. Government and law-enforcement requests
If Zoft receives a legally binding request from a public authority for access to Customer Personal Data, Zoft will: notify Customer promptly unless legally prohibited; review the request for legal validity and challenge it where there are reasonable grounds to do so; disclose only the minimum data required; and document the request. Zoft will not voluntarily provide Customer Personal Data to any public authority, and will publish aggregate statistics of such requests annually if any are received.
11. Return and deletion
During the term Customer may export Customer Personal Data at any time through the Service. Following termination or expiry of the Agreement, Customer has 30 days to export Customer Personal Data. Zoft will then delete Customer Personal Data from production systems within 30 days, and from backups within a further 35 days through normal backup rotation, unless retention is required by law, in which case Zoft will isolate and protect it and delete it when the requirement ends. On written request Zoft will certify deletion.
12. Audits and compliance information
- Zoft will make available to Customer the information necessary to demonstrate compliance with this DPA, including this DPA, the Sub-processor list, security documentation, summaries of penetration tests and any third-party audit reports or certifications Zoft holds from time to time.
- Where those materials are insufficient to meet a requirement of Data Protection Laws, Customer or an independent auditor bound by confidentiality may conduct an audit of Zoft's relevant controls, no more than once in any 12-month period (or more often if required by a Supervisory Authority or following a Personal Data Breach), on at least 30 days' written notice, during business hours, without disrupting Zoft's operations, and subject to Zoft's reasonable security policies. Audits are at Customer's expense unless they reveal a material non-compliance.
- Zoft will remedy any material non-compliance identified within a reasonable time.
13. Jurisdiction-specific terms
13.1 India (DPDP Act, 2023)
Customer is the Data Fiduciary and Zoft the Data Processor. Zoft processes Data Principals' personal data only under a valid contract (this DPA) and Customer's instructions; implements reasonable security safeguards to prevent breach; notifies Customer of a breach so Customer can notify the Data Protection Board and affected Data Principals in the prescribed form and time; erases personal data when Customer's purpose is served or on Customer's instruction unless retention is required by law; and assists Customer with grievance redressal. Where Customer is notified as a Significant Data Fiduciary, Zoft will cooperate with any additional obligations that impose on Customer.
13.2 California and other US states
Zoft is a Service Provider or Processor. Zoft will not: sell or share Customer Personal Data; retain, use or disclose it for any purpose other than the business purposes specified in the Agreement or outside the direct business relationship with Customer; or combine it with personal information it receives from other sources, except as permitted for Service Providers. Zoft will comply with applicable obligations under the CCPA and provide the same level of privacy protection as the law requires of Customer; will notify Customer if it can no longer meet those obligations; and grants Customer the right to take reasonable steps to stop and remediate unauthorised use. Zoft certifies that it understands and will comply with these restrictions.
13.3 EEA, UK and Switzerland
This DPA is intended to satisfy Article 28(3) GDPR and its UK and Swiss equivalents. To the extent the SCCs apply, nothing in this DPA is intended to limit the rights of Data Subjects under the SCCs.
14. Liability and general
- Each party's liability under this DPA is subject to the exclusions and limitations in the Agreement, except to the extent the SCCs or Data Protection Laws require otherwise. Liability to Data Subjects under the SCCs is as set out in the SCCs.
- Zoft may update this DPA to reflect changes in Data Protection Laws or the Service, provided the changes do not materially reduce the protection for Customer Personal Data; material changes follow the notice process in the Agreement.
- This DPA is governed by the law and dispute-resolution provisions of the Agreement, except where the SCCs require otherwise.
- Customers whose procurement requires a signed copy of this DPA, or who need bespoke terms (specific hosting region, custom sub-processor restrictions, sectoral addenda), should contact sales.