Compliance & Data Protection

Data Processing Addendum (DPA)

DRAFTPending legal & deployment review•Intended for GDPR (Article 28) & UK GDPR alignment•Version: 1.1•ZTICOM Tech Ltd

This is a draft addendum pending legal and deployment review — it does not create binding commitments. See the Trust Center for data handling details.

1. Scope and Applicability

This draft Data Processing Addendum ("DPA") is a proposed text that would supplement a WorkAgent OS agreement only once separately executed between ZTICOM Tech Ltd ("Processor") and the Customer ("Controller"). Until execution, it creates no obligations and governs nothing.

2. Processor Obligations (GDPR Article 28)

Under the proposed terms, ZTICOM Tech Ltd would commit to:

  • Process Personal Data only on documented instructions from the Controller, including with regard to transfers of Personal Data to a third country or international organization.
  • Ensure that persons authorized to process Personal Data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality.
  • Implement technical and organizational measures appropriate to the risk — targets include encryption at rest and in transit, Row-Level Security (RLS) isolation, and tamper-evident audit logging (design targets pending deployment verification).
  • Respect the conditions referred to in paragraphs 2 and 4 of GDPR Article 28 for engaging another processor (Sub-processor).
  • Assist the Controller by appropriate technical and organizational measures in responding to requests for exercising data subject rights.

3. Technical & Organizational Measures (TOMs)

Access Control & RLS

Design target: database-level Row-Level Security bound to authenticated session tenant_id, with ABAC policy enforcement out-of-band before tool execution.

Cryptographic Integrity

Design target: canonical SHA-256 action hashing for human approvals; append-only, hash-chained audit ledgers.

Secret Isolation

Design target: third-party OAuth tokens and secrets isolated inside dedicated vaults; no raw credentials in model prompts.

Model Data Handling

Target: stateless inference with training-exclusion terms per provider contract. No specific ZDR agreement is asserted as executed.

4. Sub-processors

Controller would grant general authorization to Processor to engage Sub-processors under an executed agreement. A directory of proposed providers is published at /subprocessors. Advance notification periods for Sub-processor changes will be defined in the executed agreement.

5. Security Incident Notification

Breach notification timing commitments will be defined in the executed agreement; a formal incident response process is planned (see the Trust Center).

6. Inquiries & Executed DPA Requests

ZTICOM Tech Ltd — Data Protection Office