Skip to main content

Zayloft Data Processing Terms

These Data Processing Terms govern Zayloft’s processing of Personal Data on behalf of a Customer when Zayloft acts as a processor, service provider, contractor or equivalent data-processing role under applicable privacy law.

They are designed to support enterprise use of Zayloft communications, verification, identity, email, voice, developer and AI/NLP services while keeping the Customer in control of its processing instructions and data responsibilities.

Translations are provided for convenience. If a translated version conflicts with the English version, the English version controls to the extent permitted by applicable law.

Relationship and processing instructions.

1. Scope and incorporation

These Data Processing Terms form part of the agreement between Customer and the contracting Zayloft entity where Zayloft processes Personal Data on Customer’s behalf in connection with the Services.

If the parties have signed a separate data processing agreement that expressly replaces these Terms for the same processing, the signed agreement controls. Capitalized terms not defined here have the meanings given in the applicable Terms of Service or Order Form.

2. Roles of the parties

Customer acts as controller, business or equivalent decision-making party for Customer Personal Data, except where Customer itself acts as a processor for another controller. Zayloft acts as processor, service provider, contractor or equivalent role when processing Customer Personal Data on Customer’s documented instructions.

Each party remains independently responsible for Personal Data it processes for its own purposes as a controller or business, including account administration, billing, security, legal compliance and its own business operations where applicable.

3. Customer instructions

Zayloft will process Customer Personal Data only on documented instructions from Customer, including instructions contained in the Agreement, configured product settings, API requests, support requests and other lawful written directions consistent with the Services.

If Zayloft is required by applicable law to process Customer Personal Data outside Customer’s instructions, Zayloft will inform Customer before the processing unless the law prohibits that notice.

Zayloft will notify Customer if, in Zayloft’s reasonable view, an instruction infringes applicable data-protection law. Zayloft may suspend the affected processing while the parties address the instruction.

4. Processing details

The subject matter, duration, nature, purpose, categories of Personal Data and categories of Data Subjects are described in Annex 1 below and may be further specified in an Order Form or service configuration.

Customer determines which Customer Personal Data is submitted to the Services and is responsible for ensuring that its instructions are lawful, sufficiently specific and appropriate for the relevant data.

Processor obligations.

5. Confidentiality and personnel

Zayloft will ensure that personnel authorized to process Customer Personal Data are subject to appropriate confidentiality obligations and receive access only as reasonably necessary for their responsibilities.

Access will be managed using role, project, environment and operational controls appropriate to the Service and the sensitivity of the data.

6. Security measures

Taking into account the state of the art, implementation costs, the nature, scope, context and purposes of processing, and risks to individuals, Zayloft will maintain appropriate technical and organizational measures designed to protect Customer Personal Data.

The measures include the controls described in Annex 2 as applicable to the relevant Services. Zayloft may update security measures where the update does not materially reduce the overall protection of Customer Personal Data.

7. Personal Data Breaches

Zayloft will notify Customer without undue delay after becoming aware of a Personal Data Breach affecting Customer Personal Data processed by Zayloft as processor.

The notice will include information reasonably available to Zayloft that Customer needs to assess the incident and meet applicable notification obligations, such as the nature of the incident, affected data or systems, likely consequences and measures taken or proposed.

Notification of an incident does not constitute an admission of fault or liability. Customer remains responsible for determining whether notifications to authorities or Data Subjects are legally required unless applicable law assigns that obligation directly to Zayloft.

8. Data Subject requests

Taking into account the nature of the processing, Zayloft will provide reasonable assistance to Customer through appropriate technical and organizational measures for responding to requests to exercise Data Subject rights.

If Zayloft receives a request directly concerning Customer Personal Data for which Customer is controller, Zayloft may direct the requester to Customer and will not independently respond on the merits unless authorized by Customer or required by law.

9. DPIAs, consultations and compliance assistance

Taking into account the nature of processing and information available to Zayloft, Zayloft will provide reasonable assistance with Customer obligations relating to security, Personal Data Breaches, data-protection impact assessments and prior consultation with supervisory authorities where the assistance relates to the Services.

Assistance that requires substantial bespoke work may be subject to mutually agreed fees unless the need for assistance results from Zayloft’s breach of the Agreement or applicable law.

10. Records, information and audits

Zayloft will make available information reasonably necessary to demonstrate compliance with processor obligations applicable to the Services, subject to confidentiality, security and legal restrictions.

Where required by applicable law, Customer may request an audit or inspection relating to Zayloft’s processing of Customer Personal Data. The parties will first use available independent reports, certifications, questionnaires or documentation where they reasonably satisfy the request.

Any on-site audit must be proportionate, coordinated in advance, avoid unreasonable disruption, protect other customers’ confidentiality and systems, and comply with reasonable security requirements.

Subprocessors and data lifecycle.

11. Subprocessors

Customer provides general authorization for Zayloft to use subprocessors to provide the Services. Zayloft will impose written data-protection obligations on subprocessors that are appropriate to the processing and materially consistent with the protections required of Zayloft under these Terms.

Zayloft remains responsible for the performance of its subprocessors to the extent required by applicable law and the Agreement.

Where applicable law requires notice of new subprocessors and an opportunity to object, Zayloft will provide the applicable notice mechanism. An objection must be based on reasonable data-protection grounds. The parties will work in good faith on a commercially reasonable resolution.

12. Subprocessor information

The categories of subprocessors used by Zayloft can include cloud hosting and infrastructure, communications networks and channel providers, security and monitoring services, support and operational tooling, payment or billing infrastructure, and AI or data-processing infrastructure where enabled by the Customer.

A current service-specific subprocessor list should be made available through the applicable account, trust, legal or support channel when required. Zayloft will not invent or publish providers that are not actually used.

13. Return and deletion

At the end of the applicable Services, Zayloft will, at Customer’s choice and subject to product functionality, delete or return Customer Personal Data and delete remaining copies unless applicable law requires retention.

Deletion can be subject to reasonable backup, disaster-recovery, security-log and technical deletion cycles. Data retained solely because deletion is not yet technically completed or because law requires retention will remain protected and will not be used for unrelated purposes.

Customer is responsible for exporting information it needs before account closure or expiration of an applicable export period.

Transfers and regional privacy requirements.

14. Cross-border transfers

Zayloft and its subprocessors may process Customer Personal Data in countries other than the country where Customer or a Data Subject is located when permitted by the Agreement and applicable law.

Where a restricted transfer requires a legal transfer mechanism, the parties will use a valid mechanism applicable to the transfer, such as an adequacy decision, approved standard contractual clauses, binding corporate rules, an approved certification mechanism where available, or another mechanism recognized by applicable law.

Where the EU Standard Contractual Clauses, the UK IDTA or UK Addendum, Swiss transfer clauses or another prescribed instrument must be completed with party-specific selections, the parties will execute or incorporate the appropriate module and annex information for the relevant transfer rather than inventing a jurisdiction or selection that does not match the actual contracting relationship.

15. EEA, United Kingdom and Switzerland

For processing subject to the GDPR or UK GDPR, Zayloft will comply with processor obligations applicable to it, including documented instructions, confidentiality, security, subprocessor controls, assistance with rights and compliance obligations, return or deletion, and information needed to demonstrate compliance.

For a transfer subject to Chapter V of the GDPR or the corresponding UK transfer rules, the applicable transfer mechanism and supplementary safeguards will be identified according to the actual transfer, locations and roles of the parties.

Where Swiss data-protection law applies, references to GDPR concepts will be interpreted to include equivalent Swiss requirements to the extent necessary for the relevant processing.

16. California and other U.S. state privacy laws

Where Zayloft processes Personal Information as a service provider, contractor or processor under an applicable U.S. state privacy law, Zayloft will process that Personal Information only for the limited and specified purposes permitted by the Agreement and applicable law.

Zayloft will not sell Customer Personal Information or retain, use or disclose it outside the direct business relationship or for purposes prohibited to a service provider, contractor or processor by applicable law. Zayloft will not combine Customer Personal Information with other Personal Information where such combination is prohibited, except as legally permitted.

Zayloft will provide required assistance with verified consumer requests and will notify Customer if it determines it can no longer meet an applicable service-provider, contractor or processor obligation.

17. Brazil

Where Brazil’s LGPD applies and Customer acts as controlador while Zayloft acts as operador, Zayloft will process Personal Data according to Customer’s lawful instructions and the obligations applicable to operadores.

The parties will maintain appropriate security and governance measures and cooperate as reasonably necessary regarding Data Subject rights, security incidents and legally required records or assessments.

Cross-border transfers involving Personal Data subject to the LGPD will use a transfer mechanism permitted by Brazilian law and applicable ANPD regulation when required.

Service-specific processing and customer duties.

18. Communications and verification services

Communications services may require Personal Data to pass through telecommunications networks, carriers, mailbox providers, voice infrastructure, messaging channels and destination-specific delivery participants in order to provide the requested Service.

Customer instructs Zayloft to make those disclosures and transmissions as necessary for delivery, receipt, verification, routing, troubleshooting and related Service operation, subject to the Agreement and applicable law.

Customer remains responsible for the lawfulness of its recipient lists, sender identities, communications content, consent records, opt-out handling and destination-specific instructions.

19. AI and NLP processing

If Customer enables AI or NLP functionality, Customer instructs Zayloft to process the prompts, documents, retrieved content, embeddings, outputs and related metadata necessary to provide the configured functionality.

Zayloft will apply the applicable service settings and contractual restrictions to that processing. Customer should not submit sensitive or regulated data to AI functionality unless it is necessary, authorized and appropriate for the configured service.

If an external model or infrastructure provider is used as a subprocessor, the subprocessor and transfer provisions of these Terms apply to that processing.

20. Customer obligations

Customer is responsible for providing legally required notices, identifying an appropriate legal basis, responding to Data Subjects where Customer is controller, and ensuring that Customer’s instructions do not violate applicable law.

Customer will use reasonable security measures for its own systems, credentials, endpoints, devices, users and integrations and will notify Zayloft promptly of compromised credentials or Customer-side security incidents that could affect the Services.

Customer will not instruct Zayloft to process data that Customer is prohibited from collecting, using or disclosing.

21. Government and third-party requests

If Zayloft receives a legally binding request from a government authority for Customer Personal Data, Zayloft will, where legally permitted, notify Customer and may challenge or narrow the request where Zayloft reasonably determines there is a lawful basis to do so.

Zayloft will disclose only the information it reasonably determines is legally required and will apply available safeguards appropriate to the request and applicable law.

Agreement mechanics and annexes.

22. Liability and order of precedence

Liability arising from these Terms is subject to the exclusions, limitations and remedies in the Agreement unless applicable data-protection law prohibits those limitations.

For data-processing matters, a signed Data Processing Agreement or transfer instrument expressly executed by the parties controls over conflicting general terms. The applicable Order Form can supplement processing details without reducing mandatory protections.

23. Term and survival

These Terms apply for as long as Zayloft processes Customer Personal Data on Customer’s behalf. Obligations that by their nature continue after processing ends, including confidentiality, deletion restrictions and legally required protections, survive for the applicable period.

24. Privacy contact

Privacy and data-processing questions may be sent to support@zayloft.com with “Data Processing” or “Privacy request” in the subject line.

If Customer requires execution of a transfer instrument, security review or service-specific processing schedule, Customer should identify the relevant account, services, contracting entity and processing locations so that the correct documents can be completed.

Processing schedules

Annex 1 — Processing description

Subject matter

Provision, operation, support, security and administration of the Zayloft Services selected by Customer.

Duration

For the term of the applicable Services and any limited period necessary for deletion, return, security, legal retention or dispute obligations.

Nature of processing

Collection, receipt, organization, storage, retrieval, consultation, transmission, routing, transformation, analysis, restriction, security monitoring, support and deletion as required by the configured Services.

Purposes

Providing communications, verification, identity, developer, email, voice, AI/NLP and related functions requested by Customer; securing and troubleshooting those Services; and complying with lawful processor obligations.

Data Subjects

Customer users and personnel; Customer’s customers, contacts and recipients; website or application users; callers and message recipients; and other individuals whose Personal Data Customer submits.

Personal Data categories

Contact identifiers, phone numbers, email addresses, names, account or customer identifiers, communication content, message or call metadata, delivery and event data, device or network information, verification data, support information, and AI/NLP inputs and outputs where enabled.

Sensitive data

Not required by default. Customer may submit sensitive or regulated data only where the selected Service is appropriate for that data and Customer has the required legal basis, instructions and safeguards.

Frequency

Continuous, recurring or event-driven according to Customer’s use of the Services.

Annex 2 — Technical and organizational measures

Identity and access

Role-based access, least privilege, strong authentication where appropriate, controlled administrative access, account and service-credential separation, and timely access revocation.

Tenant and environment controls

Logical separation of customer resources and appropriate separation of development, testing and production environments.

Transport and credentials

Secure transport for supported interfaces, protected storage of secrets, credential rotation and signed or authenticated event mechanisms where applicable.

Logging and monitoring

Operational, authentication, security and administrative logging designed to support investigation while avoiding unnecessary exposure of secrets.

Application security

Input validation, safe error handling, rate and abuse controls, secure development practices, dependency management and security testing appropriate to the Service.

Data lifecycle

Data minimization, access restrictions, retention and deletion controls, backup management and protection of data exports.

Incident response

Processes for detection, containment, investigation, remediation, evidence preservation and Customer notification where required.

Resilience

Reasonable availability, backup, recovery and continuity controls appropriate to the relevant Service and risk.

Annex 3 — Subprocessor framework

Authorization

Customer grants general authorization subject to the notice and objection rights required by applicable law and the Agreement.

Categories

Infrastructure and hosting; communications and channel delivery; monitoring and security; customer-support and operations tooling; billing infrastructure; and AI/data infrastructure where enabled.

Flow-down terms

Subprocessors must be bound by written obligations appropriate to the processing and materially protective of Customer Personal Data.

Current list

The actual service-specific subprocessor list should be provided through Zayloft’s account, trust, legal or support channel rather than inferred from this public document.

Contact privacy support

support@zayloft.com