Data Processing Agreement - Zeldoc AI Platform
This DPA forms an integral part of the Terms of Service and governs all processing Zeldoc performs on the Customer's behalf in delivering the Platform (ZControl, ZCore, ZDev, ZRouter etc.). The subprocessor list is available at zeldoc.ai/subprocessors. Enterprise customers may request a signature-ready version via [email protected].
1.Roles
Zeldoc is the processor, and the Customer is the controller, cf. GDPR Art. 28.
2.Nature of processing
All operations under GDPR Art. 4(2), as follows:
- (a) Transient processing during AI inference: Prompts, files and context are transmitted to the selected model and processed during the inference itself. Zeldoc's AI infrastructure (ZCore/ZDev) does not store content; request/response storage is disabled.
- (b) Storage at Zeldoc: Account/administration data, operational, security and technical data and backups, cf. §6.2 and §7.1.
- (c) Application layer (not covered): Storage of e.g. chats and history takes place in the application layer chosen by the Customer (e.g. OpenWebUI, development clients or partner apps), cf. §6.3. For inference on model providers, reference is made to each provider's data processing and retention policies, as stated on the subprocessor list.
3.Purpose
To deliver, operate, secure and support the Platform.
4.Duration
For the term of the Customer's use of the Platform and until deletion per §7.
5.Categories of data subjects
The Customer's users (employees); the Customer's end customers and other natural persons contained in Customer content. For customers who use only API keys, pseudonymised key/team IDs are processed instead of named account data.
6.Categories of personal data
6.1 Processed transiently - not stored by Zeldoc
Prompts, files, context and outputs are processed during the AI inference itself; request/response storage is disabled. Content is not retained by Zeldoc's AI infrastructure (ZCore/ZDev).
6.2 Stored by Zeldoc - complete inventory
- Account/administration data: name, email, role and login metadata (deleted 30 days after termination)
- Pseudonymised key/team IDs for API-key customers (cannot be linked to account data in ZControl)
- Operational and usage metadata per AI call: timestamp, model, token count, cost, pseudonymised key/team ID, status - retained 30 days (operation, billing, security)
- Security logging of access and administrative events - retained 90 days
- Technical data: internal IP addresses in connection with AI calls, session data
- Backups of the Platform's system and configuration - retained 90 days (no backups of the Customer's content)
6.3 Not covered by the DPA (application layer)
Chat history, notes, knowledge bases, memories and similar content data are stored in the application layer operated and hosted by the Customer or a partner authorised by the Customer (e.g. OpenWebUI, development clients or partner apps). Zeldoc neither hosts nor has access to this layer, cf. §2.
7.Storage and deletion
7.1 Storage
Account and administration data (name, email) are stored for the subscription term and deleted 30 days after termination. Content is not stored by Zeldoc's AI infrastructure; request/response storage is disabled. Operational and usage metadata per AI call is retained for 30 days. Security logging of access and administrative events is retained for 90 days. Backups of the Platform's system and configuration are retained for 90 days; backups are not taken of the Customer's data (content).
7.2 Return or deletion upon termination (art. 28(3)(g))
Upon termination, the Customer chooses whether Customer data and associated tenant data (including the §6.2 categories) shall be (i) returned in a common, machine-readable format (export via ZControl/API) or (ii) deleted. Return/deletion no later than 30 days after termination; statutory retention (the Danish Bookkeeping Act) excepted. Written confirmation upon request.
8.Subprocessors
Zeldoc maintains a general written authorisation for subprocessors, cf. Art. 28(2). The current named list is published at zeldoc.ai/subprocessors stating name, purpose, data categories, location (EU/non-EU), transfer mechanism and retention status. Customers are notified of new subprocessors at least 30 days in advance and may object on reasonable grounds; in case of disagreement, the Customer has the right to terminate the affected part of the subscription. Each subprocessor is bound in writing to no less protective terms, and Zeldoc remains liable, cf. Art. 28(2) and (4). Categories: hosting, routing of external model inference (OpenRouter) and operational/network services. AI model providers - including EU-hosted ones - appear on the subprocessor list as independent recipients and are contractually bound to no less protective terms; Zeldoc remains liable, cf. art. 28(2) and (4).
9.Authorised users
The Customer's tenant is accessed by the Customer's authorised users, including the Customer's advisors and implementation partners, for whom the Customer has secured DPA/confidentiality obligations. Zeldoc processes only on the Customer's instructions.
10.Transfers outside the EU/EEA
Baseline: EU/EEA models and infrastructure only. Frontier add-on: inference may be processed outside the EU; in that case the transfer is governed by the European Commission's Standard Contractual Clauses (2021/914) and a Transfer Impact Assessment (TIA). Providers are identified on the subprocessor list with their transfer mechanism. External model inference is delivered via OpenRouter (subprocessor, USA, SCC 2021/914 + TIA). Zero Data Retention cannot be guaranteed via OpenRouter; the selected model provider's own retention policy applies, cf. the subprocessor list.
11.Security (Art. 32)
Encryption in transit (TLS), role-based access control, least privilege, two-factor authentication for administrators, security logging of access and administrative events (retained for 90 days) and vulnerability management.
No persistent content storage (compensating measure): Inference on ZCore/ZDev runs exclusively in memory (memory-only processing); request/response storage is disabled, and content is not retained by the AI infrastructure, cf. §6.1. Encryption at rest for transient content is therefore not relevant; the process is accessed solely by the inference process, and data is deleted at process completion.
GPU colocation (team.blue): Data is secured through the data centre's physical security (access control, surveillance), Zeldoc's network controls (firewall, VPN/overlay network) and memory-only processing without persistent content storage on the colocation equipment.
Encryption at rest (not applied): Encryption at rest on storage media at the hosting provider (Hetzner) that may contain §6.2 data (account/administration data, logs, backups) is not available by default from the provider ("There is no default data-at-rest encryption of objects", Hetzner) and is therefore not applied; nor at application level. Compensating measures are maintained: the data centre's physical security (access control, surveillance), network controls (firewall, VPN/overlay network), data minimisation (only §6.2 data is stored; no customer content), security logging for 90 days and sensitive data minimisation in logs.
12.Confidentiality
Zeldoc's personnel and subcontractors are bound by confidentiality obligations.
13.Assistance (art. 28(3)(e)-(f))
Zeldoc assists the Customer with: (a) responding to data subject requests, cf. art. 28(3)(e); (b) the security of processing and measures under art. 32 as well as consultation with the supervisory authority under art. 36, cf. art. 28(3)(f); (c) information for the Customer's record of processing under art. 30(2) - via the Platform's features and documentation.
14.Data breach (Art. 33)
Notification without undue delay, at the latest 48 hours, covering the nature, scope, likely consequences and remedial measures.
15.Audit
Zeldoc annually provides documentation/self-declaration and an annual audit report on compliance with the data locality and security terms, cf. Terms §12.1. Upon reasoned suspicion, the Customer may, with 30 days' written notice, have an independent third party review relevant systems and procedures under confidentiality and without disruption of operations, cf. Terms §12.2 and art. 28(3)(h).
16.Termination
Deletion per §7; written confirmation upon request.
17.Liability
Per the liability clause of the Terms of Service.
18.On-Premise addendum
When installed on customer-owned hardware, Zeldoc is not the processor of content on the customer's installation unless processing access is granted. Remote support takes place only upon written instruction and with least privilege. Zeldoc's own infrastructure (licensing, support portal) is governed by this DPA.
19.Amendments
30 days' notice; material disadvantage gives right to terminate.
Contact