Data Processing Addendum
Product: ZevoBot — AI Chatbot SaaS platform
Processor:Akula Palkish (sole proprietor) (“ZevoBot”, “Processor”)
Controller: the Customer that has accepted the Terms of Service (“Customer”, “Controller”)
Effective date: the date the Customer accepts the Terms of Service or signs this DPA.
This DPA governs ZevoBot's processing of personal data on the Customer's behalf (end-user chatbot data). It forms part of the Terms of Service. Provide a countersignable version to EU/UK/India customers on request. Have counsel review the SCC and cross-border sections.
1. Roles and scope
1.1 For personal data that Customers' End-Users provide through the Chatbots (“Customer Personal Data”), the Customer is the Controller (or a processor acting for its own customer) and ZevoBot is the Processor.
1.2 ZevoBot processes Customer Personal Data only to provide the Service and on the Customer's documented instructions (including as configured in the dashboard and as set out in the Terms). ZevoBot will inform the Customer if an instruction infringes applicable data-protection law.
1.3 This DPA incorporates the requirements of GDPR Article 28, the UK-GDPR, and India's DPDP Act, 2023 (ZevoBot acting as a Data Processor).
2. Subject matter, duration, nature, and purpose
- Subject matter: provision of the ZevoBot AI chatbot platform.
- Duration: the term of the Customer's subscription plus the retention/deletion periods in §9.
- Nature & purpose: hosting, storing, indexing (vector embeddings), retrieving, transmitting, and generating AI responses from Customer Personal Data; sending messages, notifications, and bookings as configured.
- Types of personal data: identifiers and contact details (name, email, phone), conversation/message content, lead and booking details, WhatsApp opt-in status, and any data End-Users choose to submit in free-text.
- Categories of data subjects: the Customer's website visitors, WhatsApp contacts, leads, and booking customers.
- Special categories: not intended; the Customer must not submit special-category data without a lawful basis and safeguards.
3. Customer obligations
The Customer warrants that it has a lawful basis and any required consent/notice to collect End-User data and to have ZevoBot process it, that its instructions are lawful, and that it has provided End-Users with an appropriate privacy notice. The Customer is responsible for the content of its Chatbots and training data.
4. ZevoBot obligations as Processor
ZevoBot will:
- Process Customer Personal Data only per §1.2 and applicable law.
- Ensure persons authorised to process are bound by confidentiality.
- Implement the technical and organisational security measures in Annex B.
- Respect the conditions in §6 for engaging subprocessors.
- Assist the Customer, taking into account the nature of processing, with data-subject requests (Annex A tooling), security, breach notification, DPIAs, and prior consultation.
- At the Customer's choice, delete or return Customer Personal Data at the end of the Service (§9).
- Make available information necessary to demonstrate compliance and allow audits (§8).
5. Data-subject requests
ZevoBot provides self-service tooling that helps the Customer meet requests:
- Per-account data export (JSON) and account/chatbot deletion with cascading removal of conversations, messages, leads, documents, and associated assets.
- Per-End-User export and erasure: the Customer can export or erase a single End-User's records (matched by phone number, email, or chat session) across conversations, messages, leads, bookings, WhatsApp opt-ins, handoff records, broadcast recipients, and attached media, scoped to the Customer's chatbot. Each erasure is recorded in an audit log.
If ZevoBot receives a request directly from a data subject, it will (unless legally required to act) refer them to the Customer and assist the Customer in responding.
6. Subprocessors
6.1 The Customer provides general authorisation for ZevoBot to engage the subprocessors listed in Annex A to deliver the Service.
6.2 ZevoBot imposes data-protection obligations on each subprocessor no less protective than this DPA and remains liable for their performance.
6.3 ZevoBot will give the Customer reasonable notice of any intended addition or replacement of a subprocessor (e.g., via email or an updated subprocessor page), giving the Customer the opportunity to object on reasonable data-protection grounds.
7. International transfers
Where ZevoBot transfers Customer Personal Data outside the EEA/UK/India to a country without an adequacy decision, it relies on appropriate safeguards, including the EU Standard Contractual Clauses (2021/914) and the UK International Data Transfer Addendum, which are incorporated by reference, and applies DPDP-consistent contractual safeguards for India-origin data. The relevant module/clauses apply according to the parties' roles.
8. Audits
ZevoBot will make available information reasonably necessary to demonstrate compliance with this DPA and allow for audits, including inspections, conducted by the Customer or an independent auditor on reasonable prior notice, no more than once per year (or after a personal-data breach), subject to confidentiality and not unreasonably disrupting operations. Where available, ZevoBot may satisfy audit requests by providing existing reports/certifications of itself or its subprocessors.
9. Retention, return, and deletion
On termination or expiry, and at the Customer's choice, ZevoBot will delete or return Customer Personal Data within a reasonable period, and delete existing copies except where retention is required by law. Cascading deletion removes chatbots, documents, embeddings, conversations, leads, and stored assets. Backups are purged on their normal rotation cycle.
During the subscription, ZevoBot also enforces default time-based retention via a daily automated purge: conversations/messages and handoff records are deleted 12 months after last activity; leads, bookings, and broadcast delivery records after 24 months; inactive WhatsApp opt-ins after 24 months (opt-out records are retained as a suppression list). Attached media is deleted with the records.
10. Personal-data breaches
ZevoBot will notify the Customer without undue delay after becoming aware of a personal-data breach affecting Customer Personal Data, with information reasonably available to help the Customer meet its own notification obligations (which for GDPR is generally within 72 hours to the authority).
11. Liability
Each party's liability under this DPA is subject to the limitation-of-liability provisions of the Terms of Service.
12. Order of precedence
If there is a conflict between this DPA and the Terms of Service regarding the processing of Customer Personal Data, this DPA prevails.
Annex A — Subprocessor list
Current as of 7 July 2026. Verify each provider's processing location and the transfer mechanism, and keep this list published and up to date.
| Subprocessor | Function in ZevoBot | Data processed | Typical region |
|---|---|---|---|
| Vercel | Application hosting / edge | All request data in transit | USA / global edge |
| Neon | PostgreSQL database (incl. pgvector embeddings) | All stored personal data + embeddings | USA / EU [confirm your region] |
| Clerk | Authentication & user management (Customers) | Customer account identity, auth cookies | USA |
| Razorpay | Payments & subscriptions | Customer billing identifiers | India |
| OpenAI | LLM / embeddings (RAG answers) | Chatbot messages + retrieved content chunks at query time | USA |
| Google (Generative AI / Gemini) | LLM / embeddings | Chatbot messages + content chunks at query time | USA / global |
| Google (Calendar API, OAuth) | Booking calendar sync (opt-in per chatbot) | Booking details, connected calendar tokens | USA / global |
| Meta / WhatsApp Business Platform | WhatsApp messaging (opt-in) | Phone numbers, message content, opt-in status | USA / global |
| Shopify | E-commerce integration (opt-in) | Store + order/product data, connection token | USA / global |
| WooCommerce / WordPress (Customer's own store) | E-commerce integration (opt-in) | Store data via consumer key/secret | Customer-hosted |
| Cloudinary | Media/file storage for training documents & chat media | Uploaded documents/media | USA / global |
| Uploadthing | File upload handling | Uploaded files | USA |
| Brevo (and SMTP/email provider) | Transactional & notification email | Recipient email + notification content | EU / global [confirm] |
| Redis provider (e.g., Upstash) [confirm] | Caching, rate-limiting, queues/DLQ, session state | Transient identifiers & state | [confirm region] |
Remove any provider you do not actually use, and add any you do. Confirm each region and whether SCCs/DPAs are in place with each.
Annex B — Technical and organisational security measures
ZevoBot maintains measures appropriate to the risk, including:
- Encryption in transit: TLS for all client/server and API traffic.
- Encryption at rest for secrets: third-party OAuth tokens (Google, WhatsApp) and connector credentials (Shopify, WooCommerce) are encrypted with AES-256-GCM.
- Credential hygiene: generated API keys are stored hashed; the encryption key is required in production (fail-closed).
- Webhook integrity: inbound webhooks are verified by signature/HMAC (Razorpay, WhatsApp/Meta, Shopify, WooCommerce, Clerk).
- Tenant isolation: data is scoped per Customer/chatbot with foreign-key cascades and access controls.
- Access control: authentication via Clerk; least-privilege access to production.
- Deletion tooling: per-account export and cascading deletion endpoints, plus per-End-User export/erasure endpoints (phone/email/session matched).
- Automated retention: a daily purge job enforces the retention windows in §9 (aged conversations, messages, leads, bookings, WhatsApp records, and their media).
- Sensitive-operation controls: data export, account deletion, and End-User erasure are rate-limited and recorded in an audit log.
- Encryption verification: an automated check verifies no stored token/credential remains in plaintext.
- Logging & observability: operational logs and admin observability for incident detection.
- Platform compliance webhooks: Shopify mandatory GDPR webhooks (
customers-data-request,customers-redact,shop-redact) are implemented. - Cookie consent: non-essential analytics on the ZevoBot site loads only after visitor consent.