This Data Processing Addendum ("DPA") is entered into between Zipline, Inc. ("Zipline") and the customer identified in the order form ("Customer") and forms part of the agreement governing Customer's use of the Zipline service (the "Agreement"). It applies to the extent Zipline processes Personal Data on Customer's behalf in connection with the service.
Capitalized terms not defined here have the meanings given in the Agreement or in applicable Data Protection Laws.
For Customer Personal Data, Customer is the Controller and Zipline is the Processor. Where Customer is itself a Processor (acting on behalf of a third-party Controller), Zipline acts as a Sub-processor and the parties' obligations under this DPA apply accordingly.
| Subject matter | Provision of the Zipline service. |
|---|---|
| Duration | The term of the Agreement plus any retention period required by law. |
| Nature and purpose | Hosting, transmission, replication, transformation, and observability of Customer Personal Data flowing through Customer-configured pipelines. |
| Categories of Data Subjects | As determined by Customer; typically Customer's end users, employees, contractors, and other persons whose data Customer routes through the service. |
| Categories of Personal Data | As determined by Customer; may include identifiers, contact information, technical identifiers, content, and other categories Customer chooses to route. |
Zipline will Process Customer Personal Data only on Customer's documented instructions, including the Agreement, Customer's configuration of the service, and any further written instructions, except where Processing is required by law (in which case Zipline will, to the extent permitted, inform Customer in advance).
Zipline ensures that personnel authorized to Process Customer Personal Data are bound by confidentiality obligations and have received appropriate training.
Zipline implements and maintains appropriate technical and organizational measures designed to protect Customer Personal Data against unauthorized or unlawful Processing and against accidental loss, destruction, damage, alteration, or disclosure. These measures are described at /security and include, at minimum, encryption in transit and at rest, least-privilege access, audit logging, vulnerability management, secure SDLC, and annual independent SOC 2 Type II auditing.
Customer authorizes Zipline to engage Sub-processors to assist with Processing. The current list of Sub-processors is published at /security. Zipline will give Customer at least 30 days' prior notice before engaging a new Sub-processor and will give Customer a reasonable opportunity to object on legitimate data-protection grounds. Zipline imposes data-protection obligations on its Sub-processors that are no less protective than those in this DPA and remains liable for its Sub-processors' acts and omissions.
Taking into account the nature of the Processing, Zipline will assist Customer by appropriate technical and organizational measures, insofar as possible, in the fulfilment of Customer's obligations to respond to requests from Data Subjects exercising their rights under Data Protection Laws. If Zipline receives a request directly from a Data Subject, it will, without undue delay, redirect the Data Subject to Customer.
Zipline will notify Customer without undue delay, and in any event within 72 hours, after becoming aware of a Personal Data Breach affecting Customer Personal Data. Notice will include the information required under Article 33(3) of the GDPR to the extent then known, and Zipline will provide updates as more information becomes available.
Where the Processing of Customer Personal Data involves a transfer from the EEA, UK, or Switzerland to a country not subject to an adequacy decision, the parties agree that the SCCs are incorporated into this DPA by reference. Module Two (Controller to Processor) applies where Customer is a Controller; Module Three (Processor to Processor) applies where Customer is a Processor. Customer's authorized Sub-processors and the relevant transfer mechanisms are described at /security. EU data residency for the service plane is available on Enterprise plans.
Zipline will make available to Customer all information necessary to demonstrate compliance with this DPA. On Customer's reasonable request and not more than once per year (except following a Personal Data Breach), Zipline will respond to a written security questionnaire and provide a summary of its most recent SOC 2 Type II report under NDA. Customer may conduct an on-site audit only with Zipline's prior written consent and at Customer's expense.
On termination or expiry of the Agreement, Customer may export Customer Personal Data using the service's standard export tools. Within 30 days after termination, Zipline will delete Customer Personal Data from active systems, except to the extent retention is required by law. Backup copies are deleted on Zipline's standard rotation cycle.
Each party's liability arising out of or related to this DPA, whether in contract, tort, or under any other theory of liability, is subject to the limitations and exclusions set out in the Agreement.
This DPA is effective for as long as Zipline Processes Customer Personal Data. Termination of this DPA does not affect either party's obligations under Data Protection Laws.
In the event of a conflict between the Agreement and this DPA with respect to the Processing of Personal Data, this DPA controls. In the event of a conflict between this DPA and the SCCs, the SCCs control.
For questions about this DPA, contact legal@zipline.run or privacy@zipline.run.