Data Processing Addendum
This Data Processing Addendum ("DPA") forms part of and is incorporated into the Terms of Service ("Agreement") between the customer using the Services ("Customer") and Zeetaminds Technologies Private Limited ("Zeetaminds").
The purpose of this DPA is to ensure that the Processing of Personal Data by Zeetaminds on behalf of Customer in connection with the Services is conducted in accordance with Applicable Data Protection Law and protects the rights of individuals whose Personal Data is Processed under the Agreement.
1. Definitions
"Services" means the Zeetaminds digital-signage content management software and related services provided under the Agreement.
"Customer Data" means data submitted to, stored in, or transmitted through the Services by or on behalf of Customer, including Personal Data ("Customer Personal Data").
"Applicable Data Protection Law" means the EU General Data Protection Regulation ("EU GDPR"), the UK General Data Protection Regulation ("UK GDPR"), the California Consumer Privacy Act, as amended ("CCPA"), other applicable U.S. state privacy laws, and India's Digital Personal Data Protection Act, 2023, to the extent its provisions are in force and applicable to the relevant Processing ("DPDP Act"), in each case to the extent applicable.
"Subprocessor" means a third party engaged by Zeetaminds to Process Customer Personal Data on Zeetaminds' behalf, excluding Zeetaminds' personnel.
"Controller," "Processor," "Data Subject," "Personal Data," and "Personal Data Breach" have the meanings given to them under the Applicable Data Protection Law governing the relevant Processing. Where the CCPA applies, "Business," "Service Provider," "Contractor," "Consumer," "Sell," and "Share" have the meanings given under the CCPA. Where the DPDP Act applies, "Data Fiduciary," "Data Processor," and "Data Principal" have the meanings given under the DPDP Act, and are treated as equivalent to "Controller," "Processor," and "Data Subject" respectively for purposes of this DPA. "Special Categories of Personal Data" has the meaning given under the EU/UK GDPR, where applicable.
2. Roles, Scope, and Processing Instructions
2.1 For Customer Personal Data Processed by Zeetaminds directly on behalf of Customer, Customer is the Controller (or equivalent) and Zeetaminds is the Processor (or equivalent). If Customer is a white-label or reseller partner that itself Processes Customer Personal Data as a processor or equivalent on behalf of its own end customers, Zeetaminds acts as a Subprocessor to Customer with respect to that Personal Data, and the applicable EU SCC module and equivalent mechanisms are determined accordingly (see Annex 4). Customer remains solely responsible for its own data processing agreement with its end customers; this DPA does not extend to, and does not describe, the terms of that downstream relationship, even though Zeetaminds may Process Personal Data belonging to those end customers as Customer's Subprocessor.
2.2 Zeetaminds will Process Customer Personal Data only on Customer's documented instructions, to: provide, secure, and support the Services; perform Customer-requested operations; prevent, detect, and investigate fraud, abuse, and security incidents; and comply with applicable law. If an instruction appears to violate Applicable Data Protection Law, Zeetaminds will notify Customer.
2.3 Zeetaminds will not sell or share Customer Personal Data, or use it for advertising or independent commercial purposes.
2.4 Zeetaminds may separately Process its own account, billing, and transaction records (via its billing and payment providers) as an independent controller for its own business purposes; this data is outside the scope of this DPA and is governed by the applicable privacy notice.
3. Customer Obligations
3.1 Customer will use the Services in accordance with Applicable Data Protection Law and will not upload, or instruct Zeetaminds to Process, Customer Data for any unlawful purpose.
3.2 Customer is responsible for the accuracy and quality of Customer Data, for having a lawful basis for its collection and Processing, for providing any notices required to its own Data Subjects or Data Principals, and for configuring the Services in a manner consistent with its obligations under Applicable Data Protection Law.
3.3 The Services are not designed or intended to Process Special Categories of Personal Data, biometric data, health data, financial account information, government-issued identification numbers, or other highly sensitive Personal Data, and Customer must not submit such data to the Services.
4. Confidentiality, Personnel, and Security
4.1 Personnel authorized to Process Customer Personal Data are bound by confidentiality obligations, are trained appropriately, and Process such data only on Customer's instructions unless law requires otherwise.
4.2 Zeetaminds will implement and maintain the technical and organizational security measures described in Annex 2, appropriate to the nature, scope, and risk of Processing, and may update them provided the overall level of protection is not materially reduced.
4.3 Zeetaminds will provide Customer with reasonable assistance, taking into account the nature of Processing and the information available to Zeetaminds, with Customer's own obligations under Applicable Data Protection Law relating to security of Processing, data protection impact assessments, and prior consultation with a supervisory authority, where applicable.
5. Data Subject / Data Principal Rights
5.1 Zeetaminds will provide reasonable assistance, taking into account the nature of Processing, to help Customer respond to valid requests or rights applicable under Applicable Data Protection Law, including, as applicable, access, correction, deletion/erasure, portability, objection, restriction, withdrawal of consent, opt-out of sale/sharing, and limitation of use/disclosure of sensitive personal information.
5.2 If Zeetaminds receives such a request directly, it will, where legally permitted, redirect the requester to Customer rather than respond substantively.
5.3 Customer is responsible for verifying requester identity and determining how a request should be fulfilled.
6. Personal Data Breaches
6.1 Zeetaminds will notify Customer without undue delay, and in any event within 72 hours, after becoming aware of a Personal Data Breach affecting Customer Personal Data. Where applicable law requires Customer to notify a supervisory authority within a specified timeframe, including the 72-hour period under the EU or UK GDPR where applicable, Zeetaminds will provide Customer with reasonable cooperation and information to assist Customer in meeting its notification obligations.
6.2 Zeetaminds will take reasonable steps to contain, investigate, and remediate the incident, and will provide reasonable cooperation for Customer's own legal/regulatory obligations.
6.3 Zeetaminds will not itself notify a regulator or Data Subject about a Customer-specific breach unless legally required or instructed by Customer.
7. Subprocessors
7.1 Customer authorizes Zeetaminds to engage the Subprocessors listed in Annex 3, under a written agreement imposing data protection obligations materially equivalent to this DPA.
7.2 Zeetaminds remains responsible for its Subprocessors' performance of their obligations to the extent required by Applicable Data Protection Law.
7.3 Zeetaminds will provide Customer with prior notice, by updating Annex 3 of this DPA, of any intended addition or replacement of a Subprocessor, ordinarily at least 30 days before the change takes effect, except where a shorter period is reasonably necessary to address an urgent operational, security, or legal requirement.
7.4 Customer may object on reasonable data-protection grounds, and the parties will work in good faith to resolve the objection, including Zeetaminds providing an alternative where feasible. If no reasonable alternative is available and the objection is not resolved, Customer may terminate the affected Services on written notice, without prejudice to any other remedy under the Agreement.
8. International Data Transfers
8.1 Where a restricted transfer of Customer Personal Data requires an appropriate safeguard, the parties will rely on the transfer mechanism applicable to the relevant transfer, with particulars set out in Annex 4.
8.2 No specific data-residency commitment is made unless stated in the Agreement or an Order Form.
8.3 Where Zeetaminds engages a Subprocessor outside the EEA or UK to Process Customer Personal Data, Zeetaminds will put in place the applicable Standard Contractual Clauses (Module Three, Processor to Sub-processor) or another valid transfer mechanism with that Subprocessor, and will conduct or support the completion of a transfer risk assessment and implement additional safeguards reasonably necessary to address risks it identifies, where required by Applicable Data Protection Law.
9. Compliance, Deletion, and Audits
9.1 Following termination of the Services, Zeetaminds will return or delete Customer Data, at Customer's choice, within 6 months, except where retention is legally required. If Customer requests deletion, whether during the term or following termination, Zeetaminds will delete the specified Customer Data promptly, where technically and legally feasible. In either case, backup copies are deleted or overwritten within 30 days after the Customer Data itself is deleted, as part of Zeetaminds' normal backup cycle.
9.2 Zeetaminds will make available information reasonably necessary to demonstrate compliance with this DPA and permit an audit, ordinarily no more than once in any 12-month period, unless required by applicable law, a supervisory authority, a material Personal Data Breach, or a reasonable and documented indication of material non-compliance. An audit may be satisfied through existing audit reports/certifications in lieu of an on-site visit, will be conducted on reasonable notice during business hours, and will not extend to other customers' data or unreasonably disrupt the Services. Customer bears its own audit costs; any third-party auditor is subject to confidentiality obligations at least as protective as this DPA's.
9.3 If legally required to disclose Customer Data to a public authority, Zeetaminds will, where permitted, notify Customer first and limit disclosure to what's legally required.
10. Jurisdiction-Specific Terms
10.1 EU/UK GDPR. For purposes of the EU GDPR and UK GDPR, the obligations set out in Clauses 1 through 9 of this DPA apply directly.
10.2 U.S. state privacy laws. For purposes of the CCPA and other applicable U.S. state privacy laws, Zeetaminds Processes Customer Personal Data only to provide, maintain, secure, and support the Services; perform Customer-requested operations; prevent fraud, abuse, and security incidents; and comply with applicable law. Zeetaminds will not Sell or Share Customer Personal Data, or retain, use, or disclose it outside these purposes, except as permitted by applicable law, and will not combine it with personal information received from or collected about an individual from another source except as permitted by that law. Zeetaminds grants Customer the right to take reasonable and appropriate steps to ensure Zeetaminds uses Customer Personal Data consistently with Customer's obligations under the CCPA, and Customer may take reasonable and appropriate steps to stop and remediate any unauthorized use it becomes aware of. Zeetaminds will provide reasonable assistance to Customer in responding to verified consumer requests to know, delete, correct, or opt out of sale/sharing, to the extent applicable. Zeetaminds will notify Customer if it determines it can no longer comply with its obligations under applicable U.S. state privacy laws and will take reasonable steps to stop and remediate the non-compliant use.
10.3 India DPDP Act. Where the DPDP Act applies and to the extent its relevant provisions are in force, Customer is the Data Fiduciary and Zeetaminds the Data Processor, and the obligations set out elsewhere in this DPA apply equally under DPDP terminology.
11. Term, Liability, Precedence, and Changes
11.1 Liability. The Agreement's liability terms apply to this DPA except where Applicable Data Protection Law requires otherwise.
11.2 Term. This DPA takes effect with the Agreement and continues until Zeetaminds no longer Processes Customer Personal Data.
11.3 Precedence. Where this DPA conflicts with the Agreement on data-protection matters, this DPA controls to that extent; mandatory SCC/Addendum terms prevail over any conflicting provision of this DPA.
11.4 Changes. Zeetaminds may update this DPA to reflect legal, regulatory, or technical changes, without materially reducing protection during the then-current term. No such update will modify or override the mandatory terms of the EU SCCs, UK Addendum, or other mandatory transfer mechanism referenced in Annex 4.
12. Notices
Notices under this DPA go to privacy@zeetaminds.com, subject line "Data Protection — [Customer Name]."
Annex 1 — Details of Processing
- Subject matter / duration
- Provision of the Zeetaminds digital-signage CMS and related Services, for the term of the Agreement plus the return/deletion/retention period.
- Nature and purpose
- Collection, storage, organization, transmission to authorized devices, and deletion of Customer Data to provide, support, secure, and operate the Services.
- Categories of Personal Data
- Identity/contact: name and email address (required); phone number (only if voluntarily provided). Account/authentication: account identifiers, authentication data, SSO/OAuth identifiers. Technical: device identifiers, IP addresses, service and security logs. Service data: support records, Customer content submitted through the Services. Location: hardware display/device location (tied to the physical display, not to an identifiable individual).
- Special categories
- The Services are not designed or intended to collect or Process Special Categories of Personal Data; Customer must not submit such data (see Clause 3.3). This describes the intended scope of the Services, not a technical guarantee about arbitrary Customer content.
- Categories of Data Subjects
- Customer's employees, contractors, administrators, and users. Where applicable, this may also include individuals whose Personal Data is Processed through the Services on behalf of Customer's own customers or end customers. The terms governing any downstream relationship are Customer's responsibility, as described in Clause 2.1.
- Processing frequency
- Continuous or event-driven, as required to operate the Services.
- Processing location
- AWS Singapore region.
Annex 2 — Technical and Organizational Security Measures
- Authentication
- Access to the Services is protected by industry-standard authentication controls, including multi-factor authentication (MFA), role-based access control, and strong passwords.
- Network security
- The production environment is hosted within a logically segmented cloud network with firewall rules and security groups restricting inbound and outbound traffic to required ports and services. Administrative access is restricted through network-level access controls.
- Encryption
- Data is encrypted in transit and at rest.
- Vulnerability management
- Regular VAPT (Vulnerability Assessment and Penetration Testing), conducted annually.
- Certification
- SOC 2 Type II.
- Access control
- Least-privilege administration; individual accounts; periodic access reviews are performed.
- Logging and monitoring
- Security, admin, and service logs.
- Incident response
- Documented response and escalation process.
- Backup and recovery
- Backup copies are deleted or overwritten within 30 days per Clause 9.1.
- Personnel security
- Confidentiality obligations and role-appropriate training.
- Physical security
- Production infrastructure is hosted in Amazon Web Services (AWS) data centres. AWS maintains industry-standard physical and environmental controls, including restricted facility access, video surveillance, and environmental safeguards.
- Deletion controls
- Processes for deletion, deprovisioning, and backup expiry consistent with Clause 9.
Annex 3 — Subprocessors
| Entity | Function | Processing location |
|---|---|---|
| Amazon Web Services (AWS) | Cloud hosting and infrastructure | Singapore |
| Google LLC | Optional "Sign in with Google" OAuth login, offered alongside email/password login | Global |
| Google Workspace | Business email and customer/compliance correspondence | Global |
Amazon Web Services (AWS)
Cloud hosting and infrastructure
Processing location: Singapore
Google LLC
Optional "Sign in with Google" OAuth login, offered alongside email/password login
Processing location: Global
Google Workspace
Business email and customer/compliance correspondence
Processing location: Global
Zeetaminds will provide notice of additions or replacements to this list in accordance with Clause 7.
Annex 4 — International Transfer Particulars
Where a transfer of Customer Personal Data from the EEA constitutes a restricted transfer requiring an appropriate safeguard under applicable EU data protection law, the parties will use the EU Standard Contractual Clauses set out in the Annex to Commission Implementing Decision (EU) 2021/914 of 4 June 2021 ("EU SCCs"). Module Two will apply where Customer is a Controller and Zeetaminds is a Processor. Module Three will apply where Customer is a Processor and Zeetaminds is its Subprocessor. These are incorporated into this DPA by reference in the form published by the European Commission, completed with the data exporter (Customer, as identified in the Agreement) and data importer (Zeetaminds Technologies Private Limited, incorporated in India).
For restricted transfers subject to the UK GDPR, the EU SCCs will be used together with the UK International Data Transfer Addendum issued by the UK Information Commissioner's Office ("UK Addendum"), as applicable.
The transfer details, categories of Data Subjects, categories of Personal Data, purposes, frequency, and security measures are described in Annexes 1 and 2. Subprocessors are listed in Annex 3.
For questions about this DPA, please contact privacy@zeetaminds.com.