Ziplinezipline
Platform
Pipelines Declare a pipeline in one file Connectors 30 sources and sinks Observability Metrics, logs, and lag per table Assistant Ask Pip about your pipelines
Evaluate
Security SOC 2 Type II and HIPAA Roadmap What we are building next Compare Zipline against the rest
Try the CLI A real simulator, in your browser Run commands against a sandbox. Nothing touches a runtime. Open the playground
Move data
Database replication Keep a second database current Warehouse loading Land changes in the warehouse Lakehouse & Iceberg Append to object storage
Power applications
Event-driven services Publish changes as events Search index sync Keep an index in step Cache invalidation Expire on write, not on a timer AI agent context Give agents current data
Build
CLI Drive the control plane TUI cockpit Six screens in a terminal Playground A simulated CLI to poke at Reference Every command and flag
Reference
API HTTP control plane SDKs Build your own connector Handbook How the runtime fits together Config Every configuration key
Follow
Changelog What shipped, and when Customers Teams streaming with Zipline
PricingDocs
Sign in Start free
Product PipelinesConnectorsObservabilityAssistantSecurityRoadmapCompare Open the playground
Use cases Database replicationWarehouse loadingLakehouse & IcebergEvent-driven servicesSearch index syncCache invalidationAI agent context
Developers CLITUI cockpitPlaygroundReferenceAPISDKsHandbookConfigChangelogCustomers
PricingDocs Sign in Start free

Data Processing Addendum

Last updated: April 24, 2026 · Forms part of your subscription agreement
Draft - under legal review This Addendum is a working draft. The signed, executable version is available on request from legal@zipline.run. For binding terms applicable to your account, contact us before relying on this text.
Need a signed copy? Most customers can self-execute the DPA in-product. For larger deals, a counter-signed PDF is available on request.
Request signed DPA

This Data Processing Addendum ("DPA") is entered into between Zipline, Inc. ("Zipline") and the customer identified in the order form ("Customer") and forms part of the agreement governing Customer's use of the Zipline service (the "Agreement"). It applies to the extent Zipline processes Personal Data on Customer's behalf in connection with the service.

Contents

  1. Definitions
  2. Roles and scope
  3. Subject and purpose of processing
  4. Customer instructions
  5. Personnel and confidentiality
  6. Security measures
  7. Sub-processors
  8. Data subject rights
  9. Personal data breach
  10. International transfers
  11. Audits
  12. Return and deletion
  13. Liability
  14. Term and termination
  15. Order of precedence

1. Definitions

Capitalized terms not defined here have the meanings given in the Agreement or in applicable Data Protection Laws.

  • "Data Protection Laws" means all laws applicable to the processing of Personal Data, including the GDPR, UK GDPR, the Swiss FADP, and the CCPA/CPRA.
  • "Personal Data", "Controller", "Processor", "Data Subject", "Process/Processing", and "Personal Data Breach" have the meanings given in Article 4 of the GDPR (or equivalent provisions of other Data Protection Laws).
  • "Customer Personal Data" means Personal Data Processed by Zipline on behalf of Customer in connection with the service.
  • "SCCs" means the Standard Contractual Clauses approved by the European Commission Decision 2021/914.

2. Roles and scope

For Customer Personal Data, Customer is the Controller and Zipline is the Processor. Where Customer is itself a Processor (acting on behalf of a third-party Controller), Zipline acts as a Sub-processor and the parties' obligations under this DPA apply accordingly.

3. Subject and purpose of processing

Subject matterProvision of the Zipline service.
DurationThe term of the Agreement plus any retention period required by law.
Nature and purposeHosting, transmission, replication, transformation, and observability of Customer Personal Data flowing through Customer-configured pipelines.
Categories of Data SubjectsAs determined by Customer; typically Customer's end users, employees, contractors, and other persons whose data Customer routes through the service.
Categories of Personal DataAs determined by Customer; may include identifiers, contact information, technical identifiers, content, and other categories Customer chooses to route.

4. Customer instructions

Zipline will Process Customer Personal Data only on Customer's documented instructions, including the Agreement, Customer's configuration of the service, and any further written instructions, except where Processing is required by law (in which case Zipline will, to the extent permitted, inform Customer in advance).

5. Personnel and confidentiality

Zipline ensures that personnel authorized to Process Customer Personal Data are bound by confidentiality obligations and have received appropriate training.

6. Security measures

Zipline implements and maintains appropriate technical and organizational measures designed to protect Customer Personal Data against unauthorized or unlawful Processing and against accidental loss, destruction, damage, alteration, or disclosure. These measures are described at /security and include, at minimum, encryption in transit and at rest, least-privilege access, audit logging, vulnerability management, secure SDLC, and annual independent SOC 2 Type II auditing.

7. Sub-processors

Customer authorizes Zipline to engage Sub-processors to assist with Processing. The current list of Sub-processors is published at /security. Zipline will give Customer at least 30 days' prior notice before engaging a new Sub-processor and will give Customer a reasonable opportunity to object on legitimate data-protection grounds. Zipline imposes data-protection obligations on its Sub-processors that are no less protective than those in this DPA and remains liable for its Sub-processors' acts and omissions.

8. Data subject rights

Taking into account the nature of the Processing, Zipline will assist Customer by appropriate technical and organizational measures, insofar as possible, in the fulfilment of Customer's obligations to respond to requests from Data Subjects exercising their rights under Data Protection Laws. If Zipline receives a request directly from a Data Subject, it will, without undue delay, redirect the Data Subject to Customer.

9. Personal data breach

Zipline will notify Customer without undue delay, and in any event within 72 hours, after becoming aware of a Personal Data Breach affecting Customer Personal Data. Notice will include the information required under Article 33(3) of the GDPR to the extent then known, and Zipline will provide updates as more information becomes available.

10. International transfers

Where the Processing of Customer Personal Data involves a transfer from the EEA, UK, or Switzerland to a country not subject to an adequacy decision, the parties agree that the SCCs are incorporated into this DPA by reference. Module Two (Controller to Processor) applies where Customer is a Controller; Module Three (Processor to Processor) applies where Customer is a Processor. Customer's authorized Sub-processors and the relevant transfer mechanisms are described at /security. EU data residency for the service plane is available on Enterprise plans.

11. Audits

Zipline will make available to Customer all information necessary to demonstrate compliance with this DPA. On Customer's reasonable request and not more than once per year (except following a Personal Data Breach), Zipline will respond to a written security questionnaire and provide a summary of its most recent SOC 2 Type II report under NDA. Customer may conduct an on-site audit only with Zipline's prior written consent and at Customer's expense.

12. Return and deletion

On termination or expiry of the Agreement, Customer may export Customer Personal Data using the service's standard export tools. Within 30 days after termination, Zipline will delete Customer Personal Data from active systems, except to the extent retention is required by law. Backup copies are deleted on Zipline's standard rotation cycle.

13. Liability

Each party's liability arising out of or related to this DPA, whether in contract, tort, or under any other theory of liability, is subject to the limitations and exclusions set out in the Agreement.

14. Term and termination

This DPA is effective for as long as Zipline Processes Customer Personal Data. Termination of this DPA does not affect either party's obligations under Data Protection Laws.

15. Order of precedence

In the event of a conflict between the Agreement and this DPA with respect to the Processing of Personal Data, this DPA controls. In the event of a conflict between this DPA and the SCCs, the SCCs control.

For questions about this DPA, contact legal@zipline.run or privacy@zipline.run.

Ziplinezipline

Real-time data streaming for teams who can't afford to lose a message.

Product
Connectors Pipelines Observability Security Roadmap
Use cases
Database replication Warehouse loading Lakehouse & Iceberg Event-driven services Search index sync Cache invalidation AI agent context
Developers
Docs CLI reference API reference SDK reference Changelog Compare
Company
About Customers Careers Partners Press Contact
Compliance
SOC 2 Type II HIPAA FedRAMP DPA Trust center
© 2026 Zipline, Inc. · Privacy · Terms · DPA status.zipline.run · ● all systems operational