Data Processing Agreement
Version 2.1Last update:
This Data Processing Agreement ("DPA" or "Addendum"), including the Standard Contractual Clauses (as defined below) attached hereto (collectively, the "DPA"), is made and entered into as of the effective date (the "Effective Date") of the applicable customer's ("Customer") acceptance of the Terms of Service between Zenovay ("Company" or "Zenovay") and Customer to which this DPA is attached and incorporated (the "Agreement"). All capitalized terms not otherwise defined in this DPA will have the meaning given to them in the Agreement.
This Addendum shall become legally binding upon Customer entering into the Agreement or upon execution of this Addendum.
1. Definitions
For the purposes of this DPA, the following terms have the meanings set out below:
- "Affiliate" means (i) an entity of which a party directly or indirectly owns fifty percent (50%) or more of the stock or other equity interest, (ii) an entity that owns at least fifty percent (50%) or more of the stock or other equity interest of a party, or (iii) an entity which is under common control with a party by having at least fifty percent (50%) or more of the stock or other equity interest of such entity and a party owned by the same person, but such entity shall only be deemed to be an Affiliate so long as such ownership exists.
- "Data Subject" means an identified or identifiable natural person whose Personal Information is protected under applicable Data Protection Laws, and includes a "consumer" as defined in the CCPA and equivalent terms under other applicable Data Protection Laws.
- "Customer Data" means any content, data, information or other materials (including Personal Information) that Customer, End Users, or Customer's Affiliates submit to, or which are collected by, the Services for processing by Zenovay in connection with the Services.
- "EEA" means the European Economic Area.
- "Data Protection Laws" means all privacy and data protection laws and regulations applicable to the Processing of Personal Information under the Agreement, including, where and to the extent applicable: Regulation (EU) 2016/679 (GDPR) and its national implementing laws; the UK GDPR and the Data Protection Act 2018; Directive 2002/58/EC (ePrivacy) as implemented nationally; the Swiss Federal Act on Data Protection of 25 September 2020 (revFADP/revDSG, in force since 1 September 2023) and its Ordinance; and applicable United States state privacy laws including the California Consumer Privacy Act as amended (CCPA). References in this DPA to a provision of one of these laws are to be read, in respect of a Data Subject protected by another of them, as references to the functionally equivalent provision of that other law.
- "Personal Information" or "Personal Data" means information that identifies, relates to, describes, is reasonably capable of being associated with, or could reasonably be linked, directly or indirectly, with a particular Data Subject. Personal Information includes information that is considered "personal data", "personally identifiable information", or similar terms as defined by applicable Data Protection Laws.
- "Processing" means any operation or set of operations which is performed on Personal Information, whether or not by automated means, such as collection, recording, organization, structuring, storage, adaptation, retrieval, consultation, use, disclosure, dissemination, restriction, erasure, or destruction.
- "Standard Contractual Clauses" or "SCCs" means the standard contractual clauses for the transfer of personal data to processors established in third countries approved by the European Commission Decision 2021/914 of 4 June 2021.
- "Sub-processor" means any third-party processor engaged by Zenovay or its Affiliates to process Personal Information on behalf of Customer under the Agreement.
2. Relationship of the Parties; Processing of Data
2.1 Roles and Scope of Processing
The parties acknowledge and agree that with regard to the processing of Personal Information, Customer is the data controller (or "business" under the CCPA) and Zenovay is the data processor (or "service provider" under the CCPA). Customer shall, in its use of the Services, process Personal Information in accordance with the requirements of applicable Data Protection Laws. Customer's instructions for the processing of Personal Information shall comply with applicable Data Protection Laws. Customer is solely responsible for the accuracy, quality, and legality of Personal Information and the means by which Customer acquired Personal Information.
2.2 Customer's Processing Instructions
By entering into this DPA, Customer instructs Zenovay to process Personal Information only in accordance with applicable law: (a) to provide the Services and related technical support; (b) as further specified via Customer's use of the Services (including through the dashboard, API, or other interfaces); (c) as documented in the Agreement, including this DPA; and (d) as further documented in any other written instructions given by Customer and acknowledged by Zenovay as constituting instructions for purposes of this DPA.
2.3 Zenovay's Compliance with Instructions
Zenovay shall process Personal Information only in accordance with Customer's documented instructions, unless processing is required by applicable laws to which Zenovay is subject, in which case Zenovay shall inform Customer of that legal requirement before processing unless such law prohibits such information on important grounds of public interest.
2.4 Details of Processing
The subject matter, nature, purpose, duration, and types of Personal Information and categories of Data Subjects processed under this DPA are described in Exhibit A (Details of Processing) attached hereto.
3. Confidentiality
Zenovay shall ensure that any persons authorized to process Personal Information on its behalf are subject to a duty of confidentiality, whether by contract or statutory obligation.
4. Security
4.1 Security Measures
Taking into account the state of the art, the costs of implementation, and the nature, scope, context, and purposes of processing as well as the risk of varying likelihood and severity for the rights and freedoms of natural persons, Zenovay shall implement and maintain appropriate technical and organizational measures to protect Personal Information from Security Incidents (as defined below) and to preserve the security and confidentiality of Personal Information, as described in Exhibit B (Security Measures) attached hereto.
4.2 Security Incident Notification
"Security Incident" means a breach of security leading to the accidental or unlawful destruction, loss, alteration, or unauthorised disclosure of, or access to, Personal Information Processed by Zenovay under this DPA. It does not include unsuccessful attempts or activity that does not compromise the security of Personal Information, such as pings, port scans, failed log-in attempts, denial-of-service attacks, or packet sniffing on network infrastructure. Zenovay shall notify Customer without undue delay, and in any event within seventy-two (72) hours, after becoming aware of a Security Incident. Zenovay is a processor and does not notify supervisory authorities or Data Subjects on Customer's behalf; Customer, as controller, remains responsible for any such notification and for determining whether one is required. Zenovay's notification is not, and shall not be construed as, an acknowledgement of fault or liability. Such notification shall, to the extent the information is then available to Zenovay:
- Describe the nature of the Security Incident, including the categories and approximate number of Data Subjects and Personal Information records concerned
- Communicate the contact details for Zenovay's designated privacy contact ([email protected]) from whom further information can be obtained
- Describe the likely consequences of the Security Incident
- Describe the measures taken or proposed to be taken to address the Security Incident and to mitigate its possible adverse effects
5. Sub-processors
5.1 Authorized Sub-processors
Customer acknowledges and agrees that Zenovay may engage Sub-processors to process Personal Information on Customer's behalf. The current list of Sub-processors is available at zenovay.com/legal/subprocessors.
5.2 Sub-processor Obligations
Zenovay shall:
- Enter into a written agreement with each Sub-processor imposing data protection obligations substantially similar to those imposed on Zenovay under this DPA
- Remain fully liable to Customer for the performance of each Sub-processor's obligations
- Select Sub-processors that offer sufficient guarantees to implement appropriate technical and organisational measures, taking into account the nature of the Processing entrusted to them, and maintain the published Sub-processor register accordingly
5.3 Changes to Sub-processors
Zenovay shall provide Customer with at least 30 days' prior written notice of the addition of any new Sub-processor. Customer may object to Zenovay's use of a new Sub-processor by notifying Zenovay in writing within 10 days of receipt of Zenovay's notice, provided such objection is based on reasonable grounds relating to data protection. If Customer reasonably objects to a new Sub-processor and Zenovay cannot provide a commercially reasonable alternative, Customer may terminate the affected Services by providing written notice to Zenovay.
6. Data Subject Rights
Zenovay shall, to the extent legally permitted and within the scope of its role as processor, promptly notify Customer if Zenovay receives a request from a Data Subject for access to, correction, amendment, or deletion of that person's Personal Information. Zenovay shall, taking into account the nature of the processing, assist Customer by appropriate technical and organizational measures, insofar as this is possible, for the fulfillment of Customer's obligations to respond to requests for exercising Data Subject rights under Data Protection Laws, including the right to access, rectify, erase, restrict processing, data portability, and object to processing.
7. Return and Deletion of Data
7.1 Data Retention Periods
Personal Information is retained according to Customer's subscription plan:
- Free Plan: 1 year (365 days)
- Pro Plan: 2 years (730 days)
- Scale Plan: 4 years (1,460 days)
- Enterprise Plan: Custom retention period as agreed in the applicable Order Form
7.2 Retention Expiry: Hide, Grace Period, Deletion
When Personal Information passes the retention period applicable to Customer's plan, it goes through three stages before it is deleted:
- Phase 1 - Soft Hide: Personal Information older than the retention period is marked as hidden and excluded from Customer's analytics queries. The data remains in Zenovay's systems but is not accessible through the Services.
- Phase 2 - Grace Period: Customer is notified via email that data has been hidden. A 30-day grace period begins, during which Customer may upgrade to a higher plan to recover the hidden data.
- Phase 3 - Permanent Deletion: After the 30-day grace period expires, hidden Personal Information is permanently deleted using secure deletion methods.
7.3 Data Recovery
If Customer upgrades to a plan with a longer retention period during the grace period, Zenovay will automatically recover (unhide) Personal Information that falls within the new retention period. Data that was permanently deleted cannot be recovered.
7.4 Deletion Upon Termination
Upon termination or expiration of the Agreement, Customer may, within thirty (30) days, elect in writing that Zenovay (a) make Personal Information available for export through the Services, or (b) delete it. Absent such an election, Zenovay will delete Personal Information from its active production systems within ninety (90) days of the end of that thirty-day period. Deletion from routine encrypted backups occurs on the ordinary expiry of the applicable backup cycle rather than on demand; until it expires, backed-up Personal Information is not accessed and is protected by the measures in Exhibit B. This Section does not apply to the extent Zenovay is required by applicable law to retain Personal Information, or retains it in aggregated or de-identified form that is no longer attributable to a Data Subject, or retains records of billing, tax, audit-log and abuse-prevention data as permitted or required by law, in which case Zenovay shall isolate and protect it from any further Processing except as required by that law. Deleting Customer's account through the Services deletes the associated Personal Information immediately and permanently; Customer is responsible for exporting anything it wishes to keep before doing so.
8. Audit Rights
Zenovay shall make available to Customer, upon reasonable request and subject to confidentiality obligations, all information necessary to demonstrate compliance with this DPA and allow for and contribute to audits, including inspections, conducted by Customer or an auditor mandated by Customer. Customer may exercise its audit rights under this Section by:
- Reviewing security certifications maintained by Zenovay's infrastructure providers (Cloudflare: SOC 2 Type II, ISO 27001, ISO 27018; Supabase: SOC 2 Type II), provided upon reasonable request. Zenovay itself is not currently SOC 2 certified; we will update this disclosure if and when an audit is completed.
- Sending Zenovay a questionnaire concerning Zenovay's data protection practices (limited to once per year unless required by Data Protection Laws)
- In exceptional circumstances, conducting an on-site or remote audit of Zenovay's data protection practices, subject to reasonable notice, confidentiality obligations, and reimbursement of Zenovay's reasonable costs
9. International Transfers
9.1 Data Transfers
Zenovay is established in Switzerland. The European Commission has recognised Switzerland as providing an adequate level of protection (Decision 2000/518/EC, as maintained), and the United Kingdom has carried that finding over, so a transfer of Personal Information from the EEA or the UK to Zenovay in Switzerland does not itself require an additional transfer tool. Where Zenovay onward-transfers Personal Information to a Sub-processor in a country that has not been recognised as adequate by the European Commission, the UK authorities or the Swiss Federal Council, that transfer is made under one of the following:
- EU-US Data Privacy Framework (DPF) / Swiss-US DPF: For transfers to a Sub-processor in the United States that is actively certified under the relevant Data Privacy Framework programme for the categories of data concerned, reliance on Commission Implementing Decision (EU) 2023/1795 of 10 July 2023, the UK Extension in force since 12 October 2023, and the Swiss recognition effective 15 September 2024. Zenovay does not represent that any particular Sub-processor is so certified; the mechanism relied on for each is stated on the Sub-processors page.
- Standard Contractual Clauses (SCCs): As detailed in Section 9.2 below.
- Supplementary Measures: Transfer Impact Assessments, encryption in transit and at rest, access controls, and other measures recommended by the EDPB and EDOEB in light of the Schrems II ruling.
9.2 Standard Contractual Clauses
Transfers of Customer Personal Information from the EEA or the UK to Zenovay in Switzerland are made in reliance on the adequacy decisions referred to in Section 9.1. If an adequacy decision covering Switzerland is repealed, suspended, annulled or otherwise ceases to provide a valid basis for such transfers, the parties shall be deemed, with effect from that date and without further action, to have entered into the Standard Contractual Clauses, Module Two (controller to processor), with Customer as data exporter and Zenovay as data importer. Where Zenovay onward-transfers Personal Information to a Sub-processor outside Switzerland and outside any adequate country and the Sub-processor is not covered by Section 9.1(a), Zenovay concludes the Standard Contractual Clauses, Module Three (processor to processor), with that Sub-processor, as data exporter, together with the UK International Data Transfer Addendum where UK data is involved and the amendments recognised by the Swiss Federal Data Protection and Information Commissioner where Swiss data is involved. For the purposes of any Standard Contractual Clauses concluded under this Section:
- Under Module Two, Customer is the "data exporter" and Zenovay is the "data importer"; under Module Three, Zenovay is the "data exporter" and the relevant Sub-processor is the "data importer"
- The parties agree to the optional clauses in Clause 7, Clause 11, and Clause 9(a)
- The Member State governing law shall be the law of the Member State in which Customer is established or, if Customer is not established in a Member State, the law of Ireland
- The competent supervisory authority shall be the supervisory authority of the Member State in which Customer is established; for Swiss Customers, the EDOEB (Federal Data Protection and Information Commissioner); for Customers not established in a Member State or Switzerland, the Irish Data Protection Commission
- For transfers subject to Swiss law, the amendments recognised by the Swiss Federal Data Protection and Information Commissioner apply: references to the GDPR are read as references to the revFADP, the competent supervisory authority is the FDPIC, and references to the EU or the EEA are read as references to Switzerland. For transfers subject to UK law, the UK International Data Transfer Addendum applies and takes precedence to the extent of any conflict
- The description of the transfer is set out in Exhibit A (Details of Processing)
- The technical and organizational measures are set out in Exhibit B (Security Measures)
10. Limitation of Liability
Each party's liability arising out of or in connection with this DPA is subject to the exclusions and limitations of liability set out in the Agreement, and the cap in the Agreement is a single aggregate cap across the Agreement and this DPA taken together rather than a separate cap for each. Nothing in this DPA or in the Agreement limits either party's liability towards a Data Subject under Article 82 GDPR or any equivalent statutory provision, or affects the rights a Data Subject has directly against a controller or processor under applicable Data Protection Laws; the limitation operates between the parties only. Where Standard Contractual Clauses are concluded under Section 9.2, nothing in this Section limits the liability of either party under those Clauses towards a Data Subject.
11. General Provisions
11.1 Order of Precedence
In the event of any conflict or inconsistency between this DPA and the Agreement, the provisions of this DPA shall prevail to the extent of such conflict or inconsistency.
11.2 Modification
Zenovay may update this DPA from time to time to reflect changes in Data Protection Laws, regulatory guidance, or industry best practices. Material changes will be notified to Customer at least 30 days before they take effect.
11.3 Severability
If any provision of this DPA is held to be invalid or unenforceable, the remaining provisions shall remain in full force and effect.
11.4 Force Majeure
Neither party shall be liable for any failure or delay in performing its obligations under this DPA (other than payment obligations) to the extent caused by an event of force majeure as defined in the Agreement. Without limiting the generality of the foregoing, Zenovay shall be excused from its processor obligations under this DPA to the extent that performance is prevented, hindered, or delayed by an outage, failure, security incident, regulatory order, or contractual termination affecting any subprocessor listed in the Subprocessors page, including without limitation Cloudflare, Supabase, Stripe, Resend, OpenAI (via Cloudflare AI Gateway), Anthropic, LemonSqueezy, Polar, IPwho.is, Mapbox, and Sentry. Zenovay will use commercially reasonable good-faith efforts to notify Customer of any material force majeure event affecting Personal Information processing and to mitigate its impact, without thereby creating any service-level commitment.
For the avoidance of doubt, the force majeure clause does not relieve Zenovay of its obligation as processor to notify Customer of a Security Incident without undue delay after becoming aware of it, which Article 33(2) GDPR and Article 24(3) of the Swiss Federal Act on Data Protection impose without a fixed deadline and which Section 4.2 of this DPA supplements with a seventy-two hour outer limit. Zenovay shall fulfil that notification obligation regardless of the force majeure event, using whatever communication channels remain available, including out-of-band channels such as SMS, telephone, or a notice posted on the Zenovay status page where the primary email channel is unavailable.
If a force majeure event prevents Zenovay from performing its material processor obligations for more than thirty (30) consecutive calendar days, Customer may terminate this DPA on written notice. Termination of this DPA shall not, of itself, terminate the Agreement, which remains governed by its own force majeure and termination provisions.
11.5 Governing Law and Jurisdiction
This DPA shall be governed by and construed in accordance with the governing law and jurisdiction provisions in the Agreement, except where the Standard Contractual Clauses specify otherwise.
Exhibit A: Details of Processing
List of Parties
Data exporter: Customer (as defined in the Agreement)
Data importer: Zenovay, Wanderstrasse 19, 4054 Basel, Switzerland
Description of Transfer
Subject matter: The subject matter of the data processing is the provision of website analytics services.
Nature and purpose of processing: Zenovay will process Personal Information to provide website and application analytics services, including:
- Collecting and analyzing website visitor data
- Generating analytics reports and insights
- Providing dashboard and data visualization services
- Storing and maintaining analytics data
- Automated visitor value scoring: a score from 0 to 100 derived from behavioural signals, approximate geography and device data, calculated on Customer's instruction and displayed to Customer. Zenovay takes no automated action on the basis of the score
- AI-assisted analytics features, routed through Cloudflare AI Gateway to OpenAI when used by Customer. Depending on the request, the data sent to the model can include individual analytics records and identifiers that Customer has supplied through the identify feature
- Providing customer support and account management
Duration of processing: for the term of the Agreement plus the data retention period applicable to Customer's subscription plan (1 year for Free, 2 years for Pro, 4 years for Scale, or as agreed for Enterprise). Personal Information that passes the retention period is subject to the hide, grace-period and deletion process described in Section 7.2, and Personal Information remaining at the end of the Agreement is dealt with under Section 7.4.
Categories of Personal Information: The categories of Personal Information transferred may include:
- Network Data: IP addresses. The address is used in plain form to resolve approximate location, apply rate limits and detect abuse, and is then converted into a daily-salted SHA-256 hash; the hash, not the address, is written to the analytics database. Approximate geolocation (country, region, city)
- Device Data: User agent strings, device type, browser, operating system, screen resolution
- Browsing Data: Page URLs visited, page titles, referrer URLs, timestamps, time spent on pages
- Behavioral Data: Scroll depth, click counts, form interactions (excluding sensitive fields), engagement metrics
- Campaign Data: UTM parameters, advertising platform click identifiers (e.g., Google, Facebook, TikTok)
- Conversion Data: Custom events, goal completions, and associated values as configured by Customer
- Session Data: Session identifiers, duration, pages per session, returning visitor status
Optional Data (when features enabled by Customer):
- Session Replay: DOM snapshots, mouse movements, clicks and scroll behaviour. Input fields are masked and password and payment-card fields are blocked by default; text rendered by the page is captured as displayed unless Customer enables text masking, so Customer is responsible for not rendering Personal Information it does not wish to have recorded
- Heatmaps: Aggregated click and scroll position data
- User Identification: Name, email, phone, company, and custom identifiers when provided by Customer's implementation
- B2B Enrichment: Company name, domain, industry, size, and other business attributes derived from third-party enrichment services
Customer is responsible for determining what Personal Information is collected and ensuring compliance with applicable privacy laws.
Categories of Data Subjects: Data Subjects whose Personal Information is processed include:
- Visitors to Customer's websites and applications
- Users of Customer's online services
- Customers of Customer's products or services
- Employees or representatives of Customer (for account management purposes)
Sensitive data: Zenovay does not intend to process sensitive personal data (e.g., health information, biometric data, financial account details). Customer is prohibited from transmitting sensitive personal data to Zenovay without prior written agreement and appropriate safeguards.
Frequency of transfer: The frequency of transferring the personal data is continuous, until the agreement comes to an end.
Exhibit B: Security Measures
This Exhibit describes the technical and organisational measures in place as at the Last Updated date of this DPA. Zenovay operates a small, highly automated infrastructure and relies on its infrastructure providers for a substantial part of these measures; where a measure is operated by a provider rather than implemented by Zenovay directly, that is stated. Zenovay may change individual measures over time, including in response to changes in technology or in the threat landscape, provided the overall level of security is not materially reduced. The measures are those Zenovay considers appropriate to the risk within the meaning of Article 32 GDPR and equivalent provisions of other Data Protection Laws. They are not a warranty that Personal Information will not be affected by a Security Incident.
1. Physical and Environmental Security (operated by infrastructure providers)
- Compute, caching, object storage and network security are provided by Cloudflare, Inc. on its global edge network. Cloudflare maintains SOC 2 Type II, ISO 27001 and ISO 27018 certifications; these are Cloudflare's certifications, not Zenovay's
- The primary database, its backups and file storage are provided by Supabase, Inc., hosted on certified cloud infrastructure in the European Union (eu-central-1, Frankfurt). Supabase's certifications are Supabase's own, not Zenovay's
- Zenovay operates no data centre, server room, or other facility of its own, and holds no Personal Information on Zenovay-controlled physical media in the ordinary course of providing the Services. All physical and environmental controls for the systems that hold Personal Information are the responsibility of the providers named above
- Facility access control, monitoring and environmental protection are performed by those providers and are described in their own published certifications and audit reports, which Zenovay makes available to Customer on request in place of an on-site inspection
2. System Access Controls
- Administrative access to Zenovay's internal operations console sits behind a zero-trust access perimeter that is re-verified at the origin, an authenticated session, and an authorisation check against an explicit administrator list held in the environment configuration rather than in the database, so that a database compromise cannot grant administrative access. A hardware-backed passkey challenge is deployed as a further factor
- Role-based access control. Within Customer's workspace, access is limited by role (owner, administrator, editor, viewer). On Zenovay's side, administrative capabilities are scoped by a per-section read/write permission matrix, with role and member management reserved to the operator and never grantable through that matrix
- Individual named accounts for administrative access; shared or generic administrative logins are not used
- Multi-factor authentication, by time-based one-time password or passkey, is available to Customer's users. Customer is responsible for enabling it for its own Authorized Users and for revoking their access when they are no longer engaged
- Administrative and privileged actions are written to append-only audit logs with no update or delete policy. Audit writes are deliberately non-blocking, so that a logging failure cannot block the underlying action; the logs are therefore an accountability record and are not warranted to be a complete record of every event
3. Data Access Controls
- All connections to the Services are served over HTTPS, with TLS terminated at the Cloudflare edge; traffic between Zenovay's compute and the database is encrypted in transit
- Personal Information at rest is encrypted by the providers that store it (Supabase for the primary database and its backups, Cloudflare for object storage). Encryption at rest and the associated key management are provider-operated controls; Zenovay does not operate a separate encryption or key-management layer over stored Personal Information
- Access to Personal Information restricted to authorized personnel only
- Customer Data is logically segregated per website and per team. Row Level Security is enabled on every table in the production database, and each application query path additionally enforces a tenant predicate; on the API path, which authenticates with a service role, that application-layer check is the primary control and Row Level Security is defence in depth
4. Transmission Controls
- Encryption of data transmission using TLS/SSL protocols
- Secure APIs with authentication and authorization controls
- Rate limiting, IP reputation scoring and abuse heuristics applied at the edge and in the application tier
5. Input Controls
- Audit logging of data creation, modification, and deletion
- Version control and change management procedures
- Automated daily backups of the primary database, taken by the database provider. Point-in-time recovery is not currently enabled, so the recovery point objective is up to twenty-four (24) hours
6. Availability Controls
- Cloudflare's global edge network, with provider-operated failover between edge locations
- Managed database service with provider-operated infrastructure maintenance and daily automated backups
- The primary database runs in a single European Union region. Backups are held by the database provider under that provider's own arrangements; Zenovay does not operate a separate geographically distributed backup estate
- A documented disaster-recovery and business-continuity runbook, whose recovery objectives are internal targets rather than commitments to Customer
- System monitoring and incident response procedures
- Note: No specific uptime SLA is provided unless separately agreed in an Enterprise contract
7. Organizational Measures
- Access to Personal Information is limited to the operator and to personnel expressly authorised by the operator, and is granted only where it is necessary to provide, secure or support the Services
- Every person authorised to process Personal Information on Zenovay's behalf is bound by a duty of confidentiality, whether by contract or by statute, as set out in Section 3
- Incident response and breach notification procedures
- Automated security scanning of every Zenovay service on a weekly schedule, covering dependency vulnerabilities, static analysis and secret scanning, with dynamic application scanning additionally configured for the web-facing services, together with weekly review of the database provider's security advisories. Zenovay has not commissioned an independent penetration test or third-party security audit and does not represent that it has
- Sub-processors are engaged on written data processing terms that impose data protection obligations substantially similar to those in this DPA, and are recorded in a register that Zenovay maintains and publishes at zenovay.com/legal/subprocessors
Contact Information
For questions about this DPA or data processing practices, please contact:
Email: [email protected]
Support: [email protected]
Address: Zenovay, Wanderstrasse 19, 4054 Basel, Switzerland