Skip to main content

Policy

Data Processing Addendum

For customers processing personal data through ZeroWidth services.

Effective: June 2026 · Processor: ZeroWidth, LLC (Illinois, USA)

This Data Processing Addendum ("DPA") supplements the agreement between ZeroWidth, LLC ("ZeroWidth", "we", "Processor") and the customer ("Customer", "Controller") where Customer processes personal data through ZeroWidth services that is subject to the EU General Data Protection Regulation (GDPR), the UK GDPR, the California Consumer Privacy Act (CCPA / CPRA), or comparable data-protection laws.

The DPA forms part of the Terms of Service and any signed master agreement; in case of conflict it controls on data-protection matters.

Roles

  • Customer is the Controller of the personal data it submits to ZeroWidth ("Customer Personal Data").
  • ZeroWidth is the Processor acting only on Customer's documented instructions.
  • For its own corporate functions (billing, account administration, security operations), ZeroWidth is an independent Controller — covered separately by the Privacy Policy.

Subject matter and scope

  • Subject matter: processing of Customer Personal Data necessary to provide the ZeroWidth services.
  • Duration: for as long as ZeroWidth holds Customer Personal Data, which is bounded by the Terms (and the deletion schedule in the Privacy Policy).
  • Nature and purpose: to deliver, support, secure, and improve the services; to operate AI features at Customer's direction.
  • Categories of data subjects: Customer's end users, employees, contractors, and any individuals whose data Customer chooses to upload.
  • Categories of personal data: as determined by Customer — typically identifiers (name, email, role), workspace content (text, files, conversation transcripts), and any data Customer submits to AI providers via the services.

Processor obligations

ZeroWidth will:

  1. Process Customer Personal Data only on documented instructions from Customer, including with regard to transfers to a third country, unless required by law to do otherwise (in which case we'll inform Customer first unless prohibited).
  2. Ensure confidentiality: personnel authorized to process Customer Personal Data are under a duty of confidentiality.
  3. Apply security measures appropriate to the risk — see Security below.
  4. Engage subprocessors only under the conditions in Subprocessors below.
  5. Assist Customer in responding to data subject requests (access, rectification, erasure, restriction, portability, objection) to the extent possible given the nature of the processing.
  6. Assist with compliance with Articles 32-36 GDPR (security, breach notification, DPIA, prior consultation) taking into account the information available to ZeroWidth.
  7. Delete or return Customer Personal Data at the end of the services, subject to the deletion schedule in the Privacy Policy.
  8. Make available the information necessary to demonstrate compliance and contribute to audits — on reasonable notice, and at a reasonable frequency unless a supervisory authority requires otherwise.

Security

ZeroWidth implements technical and organizational measures including:

  • Encryption of Customer Personal Data in transit and at rest, with additional encryption for sensitive secrets such as integration tokens.
  • Tenant isolation enforced at the database level so workspaces only see their own data.
  • Access control for personnel via single sign-on and per-system allow-lists. Production access is logged.
  • Audit logging of changes to Customer Personal Data.
  • Vulnerability management through dependency monitoring and routine patching.
  • Backup and recovery of primary storage with documented restore procedures.
  • Incident response plan covering detection, containment, remediation, and notification.

Subprocessors

Customer authorizes ZeroWidth to engage subprocessors as listed on the Subprocessors page. ZeroWidth will:

  • Impose contractual obligations on each subprocessor no less protective than this DPA.
  • Notify Customer of new or replaced subprocessors with reasonable advance written notice before they begin processing.
  • Allow Customer to object on reasonable grounds; if the parties can't resolve the objection, Customer may terminate the affected services.
  • Remain liable for the acts and omissions of subprocessors as if they were its own.

International transfer

Where Customer Personal Data is transferred from the EEA, UK, or Switzerland to the United States or another third country, the parties incorporate the EU Standard Contractual Clauses (Commission Implementing Decision 2021/914) and, where applicable, the UK International Data Transfer Addendum, into this DPA. Module Two (Controller-to-Processor) governs where Customer is Controller. The clauses prevail in case of conflict.

Breach notification

ZeroWidth will notify Customer without undue delay, and in any event within 72 hours of becoming aware of a personal data breach affecting Customer Personal Data. The notification will include the information required by GDPR Article 33(3) to the extent known, with updates as more facts emerge.

Data subject requests

If a data subject contacts ZeroWidth directly about Customer Personal Data, we'll redirect them to Customer and assist Customer with the response. ZeroWidth doesn't respond on Customer's behalf.

Return and deletion

On termination of the services, ZeroWidth will, at Customer's choice, delete or return Customer Personal Data and delete existing copies, unless storage is required by law. The deletion schedule in the Privacy Policy applies by default; Customer can request earlier deletion in writing.

CCPA / CPRA addendum

To the extent ZeroWidth processes personal information of California residents on Customer's behalf, ZeroWidth acts as a "service provider" under the CCPA/CPRA. ZeroWidth will not:

  • Sell or share Customer Personal Data.
  • Retain, use, or disclose Customer Personal Data outside the direct business relationship.
  • Combine Customer Personal Data with personal information from other sources except as permitted for service providers.

Term and changes

This DPA remains in effect for as long as ZeroWidth processes Customer Personal Data. We may update it to reflect changes in law or operational reality, with reasonable advance notice for material changes.

Contact

For DPA matters: contact@zerowidth.ai (subject line "DPA").

ZeroWidth, LLC