Data Processing Agreement (DPA)
Last updated: June 2026 · Annex to the Terms of Service · Art. 28 GDPR
This Data Processing Agreement (“DPA”) specifies the data protection obligations of the contracting parties with respect to the processing of personal data that the Processor carries out on behalf of the Controller in connection with the use of zalu.ai. It becomes a binding part of the contract upon conclusion of the main agreement (Terms of Service).
The Controller (principal) is the customer. The Processor (contractor) is Silas Gehring, zalu.ai, Unterer Sägerweg 104, 75305 Neuenbürg, Germany, info@zalu.ai.
§ 1 Subject Matter and Duration
(1) The subject matter of this DPA is the processing of personal data by the Processor on behalf of the Controller for the purpose of providing the services described in the Terms of Service (operation of the AI assistant).
(2) The term of this DPA corresponds to the term of the main agreement. Termination of the main agreement also constitutes termination of this DPA.
§ 2 Nature, Scope, and Purpose; Types of Data; Data Subjects
(1) Nature & purpose: Storage and processing of content that the Controller's end users enter via the assistant, in order to generate answers based on the content provided by the Controller and to capture form submissions.
(2) Types of data: chat and query content, form data (e.g. name, email, message), a pseudonymous visitor identifier, technical connection data (e.g. timestamp, language).
(3) Categories of data subjects: visitors and end users of the Controller's website(s).
§ 3 The Controller's Right to Issue Instructions
(1) The Processor processes personal data only on documented instructions from the Controller, unless the Processor is required to process the data by law.
(2) Instructions are generally issued through the use and configuration of the software; supplementary individual instructions are issued in text form.
(3) If the Processor considers an instruction to be unlawful, it shall inform the Controller without undue delay and may suspend execution of the instruction until it is confirmed.
§ 4 Obligations of the Processor
(1) Confidentiality: Persons authorized to process the data are bound to confidentiality.
(2) Security: The technical and organizational measures pursuant to Art. 32 GDPR as set out in Annex 2 are implemented.
(3) Support: The Processor supports the Controller with data subject rights (§ 7), breach notification obligations (§ 9), and, where applicable, data protection impact assessments.
(4) Return/deletion after the end of the contract in accordance with § 10.
§ 5 Technical and Organizational Measures
The Processor implements the technical and organizational measures described in Annex 2 (Art. 32 GDPR) and continuously adapts them to the state of the art.
§ 6 Sub-Processors
(1) The Controller approves the use of the sub-processors listed in Annex 1.
(2) The Processor informs the Controller in good time of any intended changes (addition or replacement of sub-processors); the Controller may object to such changes on important data protection grounds.
(3) The Processor imposes data protection obligations on sub-processors that are equivalent to those set out in this DPA.
(4) For transfers to third countries, appropriate safeguards (EU Standard Contractual Clauses, Art. 46 GDPR) are agreed.
§ 7 Support with Data Subject Rights
The Processor supports the Controller with appropriate technical and organizational measures in fulfilling requests from data subjects (access, rectification, erasure, data portability, etc.). If a data subject contacts the Processor directly, the Processor forwards the request to the Controller without undue delay.
§ 8 Evidence and Audits
The Processor makes available to the Controller all information necessary to demonstrate compliance with the obligations set out in this DPA and allows for audits (including by auditors appointed by the Controller) with reasonable advance notice and without disproportionate disruption to operations.
§ 9 Notification of Personal Data Breaches
The Processor notifies the Controller of any personal data breach without undue delay after becoming aware of it and supports the Controller in fulfilling its notification and communication obligations (Art. 33, 34 GDPR).
§ 10 Deletion and Return
After the end of the processing, the Processor deletes the personal data or, at the Controller's choice, returns it, unless a statutory retention obligation applies. The Controller can also export and delete data at any time using the functions of the software.
§ 11 Liability
The liability provisions of the Terms of Service apply. In relation to data subjects, Art. 82 GDPR applies.
§ 12 Final Provisions
In the event of any conflict between this DPA and the Terms of Service, the provisions of this DPA prevail with respect to data protection. The law of the Federal Republic of Germany applies. Should any provision be invalid, the remainder of the agreement remains in effect.
Annex 1 — Sub-Processors
The Controller approves the use of the following sub-processors:
- STRATO AG, Otto-Ostrowski-Straße 7, 10249 Berlin, Germany — hosting/web servers (server location: Germany).
- Supabase, Inc. — database and backend infrastructure (server region: EU – Frankfurt, Germany).
- Google Ireland Limited (Google Gemini), Gordon House, Barrow Street, Dublin 4, Ireland; where applicable Google LLC, USA — AI-powered answer generation. Any third-country transfers are based on EU Standard Contractual Clauses.
Annex 2 — Technical and Organizational Measures (Art. 32 GDPR)
Confidentiality
- Physical access control: operation in certified data centers of the infrastructure providers (access restricted to authorized personnel).
- System access control: individual logins, authentication, no shared accounts.
- Data access control: role-based permissions; strict tenant separation via row level security (each customer sees only their own data).
- Separation control: logical separation of customer data in the database.
Integrity
- Transfer control: transport encryption (TLS/HTTPS) for all connections.
- Input control: logging of security-relevant events.
Availability and Resilience
- Regular, automated backups by the database provider.
- Recoverability after incidents; availability monitoring.
- Encryption of stored data at the infrastructure provider.
Pseudonymization & Review
- Visitors are processed only via pseudonymous identifiers.
- Procedures for regularly testing, assessing, and adapting the measures.
