Fast bereit loszulegen
Wird geladen...

Data Processing Agreement

Kaya Smart LLC d/b/a Zoviz

Version 1.0 | Effective date: 31 August 2026

This Data Processing Agreement (“DPA”) forms part of, and is subject to, the Zoviz Terms of Use, the Zoviz API terms, and any enterprise agreement, order form or other written agreement between Customer and Zoviz that governs Customer’s use of the Services (together, the “Agreement”). It sets out the terms on which Zoviz Processes Personal Data on behalf of Customer and is intended to satisfy the requirements of Article 28(3) of the GDPR and the equivalent provisions of other Data Protection Laws.

This DPA is incorporated into the Agreement automatically and applies to every Customer whose use of the Services involves the Processing of Personal Data that is subject to Data Protection Laws. No signature is required for it to take effect. Customers who need a countersigned copy for their records may request one at [email protected].

1. Definitions

Capitalized terms used in this DPA have the meanings set out below or, where not defined here, in the Agreement.

“Account Data” means Personal Data relating to Customer’s relationship with Zoviz, including the names and contact details of Customer’s authorized users, login credentials, billing and payment information, subscription and usage data, and support communications. Zoviz Processes Account Data as an independent Controller as described in the Zoviz Privacy Policy at https://zoviz.com/de/privacy.

“Affiliate” means an entity that controls, is controlled by, or is under common control with a party.

“Customer” means the person or entity that has entered into the Agreement with Zoviz, together with its Affiliates that use the Services under the Agreement.

“Customer Personal Data” means Personal Data that Customer, its Affiliates or their end users submit to or make available through the Services, including through the Zoviz web and mobile applications, the Zoviz API, the Logo Engine API and the Zoviz MCP server, and that Zoviz Processes on Customer’s behalf. Customer Personal Data does not include Account Data.

“Data Protection Laws” means all laws and regulations that apply to the Processing of Personal Data under the Agreement, including, as applicable, the GDPR, the UK GDPR and the UK Data Protection Act 2018, the Swiss FADP, national laws implementing Directive 2002/58/EC, and U.S. State Privacy Laws, each as amended or replaced from time to time.

“GDPR” means Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 (General Data Protection Regulation). “UK GDPR” means the GDPR as it forms part of the law of the United Kingdom by virtue of section 3 of the European Union (Withdrawal) Act 2018. “Swiss FADP” means the Swiss Federal Act on Data Protection of 25 September 2020 and its implementing ordinances.

“Personal Data Breach” means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, Customer Personal Data transmitted, stored or otherwise Processed by Zoviz or its Subprocessors.

“Restricted Transfer” means a transfer of Personal Data that would be prohibited by the Data Protection Laws of the European Economic Area (“EEA”), the United Kingdom or Switzerland in the absence of a valid transfer mechanism.

“Services” means the Zoviz AI branding platform and related services made available by Zoviz under the Agreement, including Zoviz Branding, Canvas, Studio, Websites, and the Zoviz Developer offerings (the Zoviz API, the Logo Engine API and the MCP server at mcp.zoviz.com), together with associated support.

“Standard Contractual Clauses” or “SCCs” means the standard contractual clauses for the transfer of personal data to third countries annexed to Commission Implementing Decision (EU) 2021/914 of 4 June 2021, as amended or replaced from time to time.

“Subprocessor” means any third party (including any Zoviz Affiliate) engaged by Zoviz to Process Customer Personal Data on Zoviz’s behalf in connection with the Services.

“UK Addendum” means the International Data Transfer Addendum to the EU Commission Standard Contractual Clauses issued by the UK Information Commissioner under section 119A of the Data Protection Act 2018, version B1.0, in force from 21 March 2022, as amended or replaced from time to time.

“U.S. State Privacy Laws” means the laws of U.S. states governing the Processing of Personal Data of consumers that apply to the parties, including the California Consumer Privacy Act as amended by the California Privacy Rights Act (together, the “CCPA”) and comparable laws of other U.S. states.

“Zoviz” means Kaya Smart LLC, a Delaware limited liability company doing business as Zoviz, with its principal address at 228 Park Ave S, PMB 71118, New York, NY 10003, United States, and its successors and permitted assigns.

The terms “Controller”, “Processor”, “Data Subject”, “Personal Data”, “Processing” (and “Process”), “Supervisory Authority” and “special categories of personal data” have the meanings given to them in the GDPR, and the terms “Business”, “Business Purpose”, “Consumer”, “Service Provider”, “Sell” and “Share” have the meanings given to them in the CCPA. Where this DPA uses one of these terms, the equivalent term under other applicable Data Protection Laws applies.

2. Scope, Roles and Precedence

2.1

Application. This DPA applies to the Processing of Customer Personal Data by Zoviz in the course of providing the Services to Customer.

2.2

Roles of the parties. As between the parties, Customer is the Controller of Customer Personal Data and Zoviz is a Processor acting on Customer’s behalf. Where Customer itself acts as a Processor for a third party Controller, Zoviz acts as a Subprocessor, and Customer represents and warrants that (a) its instructions to Zoviz are authorized by the relevant Controller and (b) the Controller has authorized Customer to engage Zoviz and to agree to this DPA, including the Standard Contractual Clauses, on the Controller’s behalf.

2.3

Account Data. Zoviz Processes Account Data as an independent Controller for the purposes described in its Privacy Policy, including creating and administering accounts, billing, providing support, securing and improving the Services, and complying with law. This DPA does not apply to Account Data.

2.4

Customer Affiliates. Customer enters into this DPA on behalf of itself and, to the extent required by Data Protection Laws, on behalf of its Affiliates that use the Services under the Agreement. Any claim by a Customer Affiliate under this DPA shall be brought by Customer on its behalf.

2.5

Order of precedence. In the event of a conflict, the following order of precedence applies: (a) the Standard Contractual Clauses and, where applicable, the UK Addendum; (b) this DPA; (c) the Agreement. Nothing in this DPA reduces the rights of Data Subjects as third party beneficiaries under the Standard Contractual Clauses.

2.6

Details of Processing. The subject matter, duration, nature and purpose of the Processing, the types of Personal Data and the categories of Data Subjects are described in Annex I.

3. Customer Instructions and Responsibilities

3.1

Documented instructions. Customer instructs Zoviz to Process Customer Personal Data (a) in accordance with the Agreement and this DPA; (b) as necessary to provide, maintain, secure and support the Services; (c) as initiated by Customer and its authorized users through their use of the Services, including through API requests, MCP tool calls, uploads and configuration settings; and (d) in accordance with any other reasonable written instructions given by Customer and agreed by Zoviz. The Agreement and this DPA constitute Customer’s complete documented instructions as at the Effective Date.

3.2

Infringing instructions. Zoviz will inform Customer without undue delay if, in its opinion, an instruction infringes Data Protection Laws. Zoviz is not obliged to carry out a legal review of Customer’s instructions and may suspend performance of the instruction concerned until Customer has confirmed or modified it.

3.3

Customer compliance. Customer is responsible for (a) the lawfulness of its collection and Processing of Customer Personal Data and of its instructions to Zoviz; (b) providing all notices and obtaining all consents and authorizations required under Data Protection Laws for Zoviz to Process Customer Personal Data as contemplated by the Agreement; (c) the accuracy, quality and legality of Customer Personal Data; (d) the acts and omissions of its authorized users and of any third party to whom it grants access to the Services or to outputs generated by the Services; and (e) configuring and using the Services in a manner consistent with Data Protection Laws.

3.4

Sensitive data. The Services are not designed to Process special categories of personal data, data relating to criminal convictions or offences, payment card numbers, government identification numbers, precise geolocation data or Personal Data of children under 16, and Customer shall not submit such data to the Services unless Zoviz has expressly agreed in writing. Where Customer uploads photographs or other content depicting identifiable individuals, Customer represents that it has the right to do so and that the Processing requested is lawful.

4. Zoviz Obligations as Processor

4.1

Processing on instructions. Zoviz shall Process Customer Personal Data only on Customer’s documented instructions as described in Section 3.1, including with regard to transfers of Personal Data to a third country or an international organization, unless required to do so by law to which Zoviz is subject. In that case Zoviz shall inform Customer of the legal requirement before Processing, unless that law prohibits such information on important grounds of public interest.

4.2

Confidentiality. Zoviz shall ensure that persons authorized to Process Customer Personal Data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality, receive appropriate training on their responsibilities, and access Customer Personal Data only to the extent necessary to perform the Services.

4.3

Security. Zoviz shall implement and maintain the technical and organizational measures described in Annex II, taking into account the state of the art, the costs of implementation and the nature, scope, context and purposes of Processing, as well as the risk to Data Subjects. Zoviz may update these measures from time to time, provided that no update materially reduces the overall level of protection.

4.4

Data Subject requests. Zoviz shall, taking into account the nature of the Processing, assist Customer by appropriate technical and organizational measures in fulfilling Customer’s obligation to respond to requests from Data Subjects exercising their rights under Data Protection Laws. The Services enable Customer to retrieve, correct, export and delete Customer Personal Data. If Zoviz receives a request directly from a Data Subject relating to Customer Personal Data, Zoviz shall not respond to it except to acknowledge receipt or to direct the Data Subject to Customer, and shall forward the request to Customer without undue delay, unless prohibited by law.

4.5

Assistance with compliance. Zoviz shall provide Customer with reasonable assistance, taking into account the nature of the Processing and the information available to Zoviz, in ensuring compliance with Customer’s obligations relating to security of Processing, notification of Personal Data Breaches, data protection impact assessments and prior consultation with Supervisory Authorities under Articles 32 to 36 of the GDPR and the equivalent provisions of other Data Protection Laws. Where such assistance requires effort beyond that reasonably expected of a Processor providing the Services, Zoviz may charge Customer reasonable fees agreed in advance.

4.6

No use for AI model training. Zoviz shall not use Customer Personal Data to train, retrain or fine tune general purpose artificial intelligence or machine learning models, and shall not permit its Subprocessors to do so, without Customer’s prior written consent. Zoviz engages third party AI model providers only under terms that prohibit the use of Customer inputs and outputs to train or improve those providers’ models. This Section does not prevent Zoviz from Processing Customer Personal Data as input to models in order to generate the outputs requested by Customer, or from using aggregated or deidentified data that does not identify Customer or any Data Subject to operate, secure and improve the Services.

4.7

Records and cooperation. Zoviz shall maintain records of the Processing activities it carries out on behalf of Customer as required by Article 30(2) of the GDPR, and shall cooperate, on request, with Supervisory Authorities in the performance of their tasks.

4.8

Deletion, return and audits. Zoviz’s obligations regarding the deletion and return of Customer Personal Data are set out in Section 8, and its obligations regarding information and audits are set out in Section 7.

5. Subprocessors

5.1

General authorization. Customer provides a general written authorization for Zoviz to engage Subprocessors to Process Customer Personal Data in connection with the Services. The Subprocessors engaged as at the Effective Date are listed in Annex III. Zoviz maintains the current list of Subprocessors in Annex III of the version of this DPA published at https://zoviz.com/de/dpa (the “Subprocessor List”).

5.2

Subprocessor obligations. Zoviz shall (a) carry out appropriate due diligence on each Subprocessor before engaging it; (b) impose on each Subprocessor, by written contract, data protection obligations that are no less protective of Customer Personal Data than those set out in this DPA, to the extent applicable to the services the Subprocessor provides; and (c) remain fully liable to Customer for the performance of each Subprocessor’s obligations.

5.3

Notice of changes. Zoviz shall give Customer at least thirty (30) days’ prior notice of the addition or replacement of any Subprocessor by updating the Subprocessor List and, where Customer has subscribed to notifications by emailing [email protected], by email.

5.4

Right to object. Customer may object to a new Subprocessor on reasonable, documented data protection grounds by notifying Zoviz in writing within thirty (30) days of the notice. The parties shall discuss the objection in good faith. If Zoviz is unable to offer a reasonable alternative within thirty (30) days of receiving the objection, Customer may terminate the affected Services on written notice, and Zoviz shall refund any prepaid fees covering the period after termination for the terminated Services. Termination under this Section is Customer’s sole remedy for an objection to a Subprocessor.

5.5

Emergency replacement. Where a Subprocessor must be replaced urgently for security, continuity or legal reasons, Zoviz may engage a replacement Subprocessor without prior notice and shall notify Customer as soon as reasonably practicable afterwards. Customer’s right to object under Section 5.4 runs from the date of that notice.

6. Personal Data Breach

6.1

Notification. Zoviz shall notify Customer without undue delay, and in any event within forty eight (48) hours, after becoming aware of a Personal Data Breach. Notification shall be sent to the email address associated with Customer’s account or to any other contact designated by Customer in writing.

6.2

Content of notification. To the extent the information is available to Zoviz, the notification shall describe the nature of the Personal Data Breach, including where possible the categories and approximate number of Data Subjects and records concerned, the likely consequences, and the measures taken or proposed to address the breach and mitigate its effects. Where it is not possible to provide all information at the same time, Zoviz may provide it in phases without undue further delay.

6.3

Mitigation and cooperation. Zoviz shall take reasonable steps to contain, investigate and mitigate the effects of the Personal Data Breach, shall keep Customer reasonably informed of material developments, and shall cooperate with Customer’s reasonable requests for information so that Customer can meet its own notification obligations.

6.4

No admission. Notification of, or response to, a Personal Data Breach under this Section shall not be construed as an acknowledgement by Zoviz of any fault or liability. Zoviz shall not notify Supervisory Authorities or Data Subjects of a Personal Data Breach on Customer’s behalf unless instructed by Customer or required by law.

7. Information and Audits

7.1

Information. Zoviz shall make available to Customer all information reasonably necessary to demonstrate compliance with this DPA and with Article 28 of the GDPR. Zoviz shall satisfy this obligation in the first instance by providing (a) this DPA and Annex II; (b) summaries of any third party audit reports, certifications or attestations held by Zoviz; (c) the publicly available compliance documentation of its infrastructure Subprocessors; and (d) written responses to Customer’s reasonable security and privacy questionnaires, no more than once in any twelve (12) month period.

7.2

Audits. Where the information provided under Section 7.1 is not sufficient to demonstrate compliance, or where an audit is required by a Supervisory Authority or by Data Protection Laws, Customer or an independent auditor mandated by Customer (who shall be bound by confidentiality and shall not be a competitor of Zoviz) may audit Zoviz’s compliance with this DPA, subject to the following conditions: (a) audits shall take place no more than once in any twelve (12) month period, unless required by a Supervisory Authority or following a Personal Data Breach; (b) Customer shall give at least thirty (30) days’ written notice; (c) the scope, timing and duration shall be agreed in advance and the audit shall be conducted during normal business hours with minimal disruption to Zoviz’s business; (d) audits shall not extend to the systems or premises of Subprocessors, or to information relating to other customers of Zoviz; and (e) Customer shall bear its own costs and shall reimburse Zoviz for the reasonable time and expenses incurred in supporting the audit, at rates agreed in advance.

7.3

Findings. Customer shall promptly share the audit findings with Zoviz. The parties shall discuss any material findings in good faith, and Zoviz shall address any material nonconformity identified within a reasonable period.

8. Return and Deletion of Customer Personal Data

8.1

During the term. Customer may access, export, correct and delete Customer Personal Data at any time through the Services, including the account dashboard and the API.

8.2

On termination. Upon termination or expiry of the Agreement, Zoviz shall, at Customer’s choice, delete or return to Customer all Customer Personal Data, and delete existing copies, within ninety (90) days, unless and to the extent that applicable law requires storage of the Personal Data. Customer may request the return of Customer Personal Data in a commonly used, machine readable format within thirty (30) days after termination; Zoviz shall not be obliged to retain Customer Personal Data after that period.

8.3

Account deletion. Where Customer deletes its account through the Services, the account and its associated data are deleted permanently after a fourteen (14) day restoration period, as described in the Zoviz Privacy Policy.

8.4

Backups. Customer Personal Data held in backup systems shall be deleted in accordance with Zoviz’s standard backup retention cycle, shall be isolated from further Processing except for restoration purposes, and shall remain subject to the protections of this DPA until deleted.

8.5

Retained data. Where Zoviz is required by law to retain Customer Personal Data, Zoviz shall keep it confidential, protect it in accordance with Annex II and Process it only for the purpose required by that law.

9. International Transfers

9.1

Location of Processing. Customer acknowledges that Zoviz is established in the United States and that Customer Personal Data will be Processed in the United States and in the other locations of the Subprocessors listed in Annex III.

9.2

Transfers from the EEA. To the extent Customer’s use of the Services involves a Restricted Transfer of Customer Personal Data from the EEA to Zoviz, the Standard Contractual Clauses are incorporated into this DPA and apply as follows:

(a)

Module Two (transfer controller to processor) applies where Customer is a Controller, and Module Three (transfer processor to processor) applies where Customer is a Processor;

(b)

Customer is the “data exporter” and Zoviz is the “data importer”;

(c)

in Clause 7, the optional docking clause applies;

(d)

in Clause 9, Option 2 (general written authorization) applies, and the time period for prior notice of Subprocessor changes is thirty (30) days;

(e)

in Clause 11, the optional language does not apply;

(f)

in Clause 13, the competent Supervisory Authority is determined in accordance with Annex I, Part C;

(g)

in Clause 17, Option 1 applies and the Standard Contractual Clauses are governed by the laws of Ireland;

(h)

in Clause 18(b), disputes shall be resolved before the courts of Ireland; and

(i)

Annexes I, II and III of the Standard Contractual Clauses are populated with the information set out in Annexes I, II and III of this DPA.

9.3

Transfers from the United Kingdom. To the extent Customer’s use of the Services involves a Restricted Transfer from the United Kingdom, the Standard Contractual Clauses as completed in Section 9.2 apply as amended by the UK Addendum, which is incorporated into this DPA. Tables 1 to 3 of the UK Addendum are populated with the information in Section 9.2, Annexes I to III and Annex IV, and for Table 4 either party may end the UK Addendum in accordance with its Section 19.

9.4

Transfers from Switzerland. To the extent Customer’s use of the Services involves a Restricted Transfer from Switzerland, the Standard Contractual Clauses as completed in Section 9.2 apply with the following adaptations: references to the GDPR are read as references to the Swiss FADP; the Swiss Federal Data Protection and Information Commissioner is the competent Supervisory Authority; the courts of Switzerland are competent for disputes; the term “Member State” is not interpreted so as to exclude Data Subjects in Switzerland from suing for their rights in their place of habitual residence; and the Standard Contractual Clauses also protect the data of legal entities until the Swiss FADP no longer requires this.

9.5

Alternative mechanisms. If Zoviz adopts an alternative lawful transfer mechanism (including certification under a framework recognized by an adequacy decision of the European Commission, the United Kingdom or Switzerland), Zoviz may apply that mechanism on notice to Customer, and the Standard Contractual Clauses shall cease to apply to the relevant transfers to the extent the alternative mechanism is valid. If the Standard Contractual Clauses or any alternative mechanism cease to be valid, the parties shall cooperate in good faith to implement a replacement mechanism without undue delay.

9.6

Transfer assessments. Zoviz shall provide Customer, on reasonable request, with information reasonably available to it to enable Customer to carry out a transfer impact assessment, and shall notify Customer promptly if it becomes aware of any reason why it can no longer comply with the Standard Contractual Clauses.

9.7

Government access requests. If Zoviz receives a legally binding request from a public authority for access to Customer Personal Data, Zoviz shall (a) review the legality of the request and challenge it where there are reasonable grounds to consider it unlawful; (b) notify Customer of the request unless legally prohibited from doing so, in which case Zoviz shall use reasonable efforts to obtain a waiver of the prohibition; and (c) disclose only the minimum amount of Customer Personal Data necessary to comply.

10. U.S. State Privacy Laws

10.1

Roles. To the extent U.S. State Privacy Laws apply, Customer is a Business (or Controller) and Zoviz is a Service Provider (or Processor) with respect to Customer Personal Data, and this DPA constitutes the written contract between them required by those laws.

10.2

Restrictions. Zoviz shall not (a) Sell or Share Customer Personal Data; (b) retain, use or disclose Customer Personal Data for any purpose other than the Business Purpose of providing the Services under the Agreement, including for any commercial purpose other than that Business Purpose; (c) retain, use or disclose Customer Personal Data outside the direct business relationship between Customer and Zoviz; or (d) combine Customer Personal Data with Personal Data that Zoviz receives from or on behalf of another person, or collects from its own interactions with Consumers, except as permitted by U.S. State Privacy Laws.

10.3

Compliance and cooperation. Zoviz shall (a) comply with the obligations applicable to Service Providers and Processors under U.S. State Privacy Laws and provide the same level of privacy protection as those laws require of Customer; (b) notify Customer if it determines that it can no longer meet its obligations under those laws; (c) grant Customer the right, on reasonable notice, to take reasonable and appropriate steps to ensure that Zoviz uses Customer Personal Data in a manner consistent with Customer’s obligations, and to stop and remediate any unauthorized use; and (d) cooperate with Customer in responding to verifiable Consumer requests, including requests to access, delete, correct or opt out, that Customer forwards to Zoviz.

10.4

Certification. Zoviz certifies that it understands and shall comply with the restrictions set out in this Section 10.

11. Liability

11.1

Each party’s liability, taken together in the aggregate, arising out of or related to this DPA, including the Standard Contractual Clauses and the UK Addendum, whether in contract, tort or under any other theory of liability, is subject to the exclusions and limitations of liability set out in the Agreement. Any reference in the Agreement to the liability of a party means the aggregate liability of that party and all of its Affiliates under the Agreement and this DPA together.

11.2

Nothing in this Section 11 limits any liability that cannot be limited under Data Protection Laws, or the rights of Data Subjects under the Standard Contractual Clauses.

12. General

12.1

Term. This DPA takes effect on the Effective Date or, if later, the date on which Customer accepts the Agreement, and remains in effect for as long as Zoviz Processes Customer Personal Data. The parties agree that this DPA also applies to Processing carried out before the Effective Date.

12.2

Updates. Zoviz may update this DPA from time to time to reflect changes in Data Protection Laws, regulatory guidance, the Services or its Subprocessors, provided that no update materially diminishes the level of protection afforded to Customer Personal Data. Zoviz shall give Customer at least thirty (30) days’ notice of material changes by posting the updated DPA at https://zoviz.com/de/dpa and, where reasonably practicable, by email. Customer’s continued use of the Services after the notice period constitutes acceptance of the updated DPA.

12.3

Governing law. This DPA is governed by the law that governs the Agreement, and disputes shall be resolved as provided in the Agreement, except that the Standard Contractual Clauses and the UK Addendum are governed by the law, and subject to the jurisdiction, specified in Section 9.

12.4

Severability. If any provision of this DPA is held invalid or unenforceable, the remaining provisions remain in full force, and the invalid provision shall be replaced by a valid provision that most closely achieves its intended effect.

12.5

Entire agreement. This DPA, including its Annexes, constitutes the entire agreement between the parties regarding the Processing of Customer Personal Data and supersedes any prior data processing agreement or similar terms between them relating to the Services.

12.6

Notices. Notices to Customer under this DPA may be given to the email address associated with Customer’s account. Notices to Zoviz shall be sent to [email protected], with a copy to Kaya Smart LLC d/b/a Zoviz, 228 Park Ave S, PMB 71118, New York, NY 10003, United States, Attention: Legal.

12.7

Privacy contact. Questions about this DPA, Data Subject requests and Personal Data Breach notifications may be directed to [email protected].

Countersigned copies

This DPA takes effect automatically as part of the Agreement. Customers who require a countersigned copy for their records may request one at [email protected]. Zoviz will provide a signature ready version of this DPA for execution by both parties.

Annex I: Description of the Processing

This Annex I forms part of the DPA and also constitutes Annex I to the Standard Contractual Clauses.

Part A. List of parties

Data exporter Data importer
Name Customer, as identified in the Agreement or in the account details provided to Zoviz. Kaya Smart LLC d/b/a Zoviz
Address As set out in the Agreement or the Customer’s account details. 228 Park Ave S, PMB 71118, New York, NY 10003, United States
Contact The account owner or the contact designated by Customer in writing. [email protected]
Activities relevant to the transfer Use of the Services to create, generate, store, manage and publish logos, brand kits, designs, websites and marketing assets, including through the Zoviz API, the Logo Engine API and the MCP server. Provision of the Services to Customer, including hosting, storage, AI assisted generation of assets, API and MCP request handling, and support.
Role Controller (Module Two) or Processor acting for a third party Controller (Module Three). Processor (Module Two) or Subprocessor (Module Three).

Part B. Description of the Processing

Item Description
Categories of Data Subjects Customer’s authorized users, employees, contractors and agents; Customer’s customers, clients and end users whose Personal Data Customer submits to the Services; and other individuals whose Personal Data is contained in text, images, brand information, website content or other material submitted to the Services.
Categories of Personal Data

Identifiers and contact details: names, business names, email addresses, telephone numbers, postal addresses, job titles and social media handles.

Account and authentication data: user identifiers, API keys, tokens and single sign on identifiers.

Content and inputs: text prompts, business descriptions, slogans and taglines, brand assets, uploaded images and photographs (which may depict individuals), website content, social media content and other material submitted to the Services.

Generated outputs: logos, brand kits, designs, marketing assets, websites and video, to the extent they contain Personal Data.

Technical and usage data: IP addresses, device and browser information, API request logs and metadata, timestamps and error data.

Communications: support requests and correspondence relating to the Services.

Sensitive data None is intended to be Processed. Customer shall not submit special categories of personal data, data relating to criminal convictions or offences, payment card numbers, government identification numbers, precise geolocation data or Personal Data of children under 16 unless expressly agreed in writing (Section 3.4). The Services do not perform facial recognition or biometric identification of individuals.
Frequency of the transfer Continuous, as initiated by Customer and its authorized users through their use of the Services.
Nature of the Processing Collection, recording, storage, hosting, organization, structuring, adaptation and alteration, retrieval, analysis by automated means (including the use of artificial intelligence models to generate and edit assets), transmission, and erasure.
Purpose of the Processing Providing the Services in accordance with the Agreement and Customer’s instructions, including: generating and rendering logos, brand kits, designs, websites and marketing content from Customer inputs; processing API and MCP requests and returning results; storing and delivering assets; providing customer support; maintaining the security, integrity and availability of the Services and preventing abuse; and complying with legal obligations.
Duration and retention For the term of the Agreement and thereafter for the periods described in Section 8 of the DPA. Accounts deleted through the Services are permanently deleted after a fourteen (14) day restoration period.
Transfers to Subprocessors The Subprocessors listed in Annex III Process Customer Personal Data for the purposes, and in the locations, stated there, for the duration of the Services.

Part C. Competent Supervisory Authority

Where Customer is established in an EEA Member State, the Supervisory Authority of that Member State is competent. Where Customer is not established in the EEA but falls within the scope of Article 3(2) of the GDPR and has appointed a representative under Article 27 of the GDPR, the Supervisory Authority of the Member State in which the representative is established is competent. In all other cases, the Supervisory Authority of the Member State in which the Data Subjects whose Personal Data is transferred are predominantly located is competent. For transfers from the United Kingdom, the Information Commissioner is the competent authority. For transfers from Switzerland, the Federal Data Protection and Information Commissioner is the competent authority.

Annex II: Technical and Organizational Measures

This Annex II forms part of the DPA and also constitutes Annex II to the Standard Contractual Clauses. It describes the measures implemented by Zoviz to ensure an appropriate level of security for Customer Personal Data. Zoviz may update these measures in accordance with Section 4.3 of the DPA.

1. Pseudonymization and encryption

(a)

All data in transit between Customer, the Services and Subprocessors is encrypted using TLS 1.2 or higher.

(b)

Customer Personal Data at rest, including databases, object storage and backups, is encrypted using industry standard algorithms (AES 256 or equivalent) with keys managed by the cloud provider.

(c)

API keys, credentials and other secrets are stored using one way hashing or in a managed secrets vault, and are never stored in source code.

(d)

Identifiers in application logs are pseudonymized where feasible. Zoviz does not store payment card numbers; payments are tokenized and processed by its payment Subprocessor.

2. Ongoing confidentiality, integrity, availability and resilience

(a)

The Services are hosted on Microsoft Azure in data centers that hold ISO 27001, SOC 1 and SOC 2 attestations and other recognized certifications.

(b)

Customer Personal Data is logically segregated by account and tenant identifiers, and access is enforced at the application layer.

(c)

Production networks are protected by network segmentation, security groups, firewalls and a web application firewall, with distributed denial of service mitigation at the network edge.

(d)

Infrastructure is deployed redundantly with automated scaling and health monitoring.

3. Ability to restore availability and access after an incident

(a)

Automated backups of production data are taken at regular intervals, encrypted, and stored separately from production systems.

(b)

Recovery procedures are documented and restore tests are performed periodically.

4. Regular testing, assessment and evaluation of effectiveness

(a)

Infrastructure and software dependencies are scanned for vulnerabilities on a continuing basis, and findings are remediated according to severity.

(b)

Code changes are reviewed before deployment, and development, staging and production environments are separated.

(c)

Independent penetration testing is performed periodically.

(d)

Security measures and policies are reviewed at least annually.

5. User identification and authorization

(a)

Every member of personnel uses a unique, individually assigned account; shared credentials are not permitted.

(b)

Access to Customer Personal Data is governed by role based access control on a least privilege basis and is limited to personnel who need it to perform the Services.

(c)

Multifactor authentication is required for access to production systems and cloud management consoles.

(d)

Access rights are reviewed periodically and revoked promptly upon a change of role or departure.

(e)

Customers may enforce single sign on for their own users through Microsoft Entra ID.

6. Protection of data during transmission and storage

(a)

In addition to the encryption measures above, generated assets are delivered through access controlled, time limited links.

(b)

APIs enforce authentication, input validation and rate limiting.

7. Physical security

(a)

Physical security of processing locations is provided by the cloud infrastructure Subprocessors, including controlled access, surveillance and environmental protections. Zoviz personnel have no physical access to servers.

(b)

Devices used by personnel to access production systems are protected by full disk encryption and automatic screen locking.

8. Event logging

(a)

Administrative actions, authentication events and API activity are logged centrally, and logs are protected against unauthorized modification.

(b)

Logs are retained for 90 days and monitored, with alerting on anomalous activity.

9. System configuration and change management

(a)

Infrastructure is defined and deployed through controlled pipelines, and changes are reviewed and approved before reaching production.

(b)

Security patches are applied according to severity, and systems are built from hardened baseline configurations.

10. Internal IT and security governance

(a)

Responsibility for information security is assigned to the Chief Technology Officer.

(b)

Zoviz maintains written information security and incident response policies, reviewed at least annually, with defined roles for responding to security incidents.

(c)

All personnel are bound by confidentiality obligations and receive security awareness training.

(d)

Subprocessors are assessed before onboarding and reviewed periodically, and are bound by written data protection terms.

11. Certification and assurance

(a)

Zoviz relies on the certifications and attestations of its infrastructure Subprocessors and provides summaries of relevant reports to Customers on request.

12. Data minimization, quality and limited retention

(a)

Zoviz Processes only the Customer Personal Data required to provide the Services, and Customer controls what it submits.

(b)

Customer Personal Data is deleted in accordance with Section 8 of the DPA, and deleted accounts are removed automatically after the restoration period.

13. Accountability, portability and erasure

(a)

Zoviz maintains this DPA, its Subprocessor List and records of its Processing activities.

(b)

Customers can export their assets and data and delete Customer Personal Data through the account dashboard and the API, or by contacting [email protected].

Annex III: Subprocessors

This Annex III forms part of the DPA and also constitutes Annex III to the Standard Contractual Clauses. It is the Subprocessor List referred to in Section 5 and is maintained at https://zoviz.com/de/dpa.

Subprocessor Purpose Customer Personal Data Processed Location
Microsoft Corporation (Microsoft Azure) Cloud infrastructure: compute (including GPU compute for AI inference), object storage, databases, backups, networking and identity services (Microsoft Entra ID). All categories of Customer Personal Data. United States.
Cloudflare, Inc. Content delivery network, DNS, TLS termination, distributed denial of service mitigation and web application firewall. Technical data (IP addresses, request metadata) and Customer Personal Data in transit. Global edge network; headquartered in the United States.
Stripe, Inc. Payment processing and subscription billing. Billing and payment data of Customer’s account holders (Account Data). Zoviz does not store full card numbers. United States; Stripe Payments Europe Ltd. (Ireland) for EEA customers.
Third party AI model providers Generation and editing of text, images, video and translations from Customer inputs, under terms that prohibit the use of inputs and outputs to train the providers’ models. The names of the providers currently in use are available to Customers on request at [email protected]. Content and inputs submitted to the Services (prompts, brand information, uploaded images) and the resulting outputs. United States.

Zoviz also uses marketing and analytics tools (including Google Analytics, Google Tag Manager and Meta) on its public website and in relation to Account Data. These providers Process data for which Zoviz is an independent Controller, as described in the Privacy Policy, and are not Subprocessors of Customer Personal Data. Microsoft Azure Marketplace and Partner Center are used for billing of Marketplace transactions and Process Account Data only.

Annex IV: UK Addendum Tables

This Annex IV applies only to Restricted Transfers from the United Kingdom and completes the UK Addendum incorporated by Section 9.3 of the DPA.

Table Content
Table 1: Parties The exporter is Customer and the importer is Zoviz, each as described in Annex I, Part A. Key contacts are as set out in Annex I, Part A.
Table 2: Selected SCCs, Modules and Selected Clauses The Standard Contractual Clauses as incorporated and completed in Section 9.2 of the DPA, including the modules, options and time periods selected there.
Table 3: Appendix Information Annex 1A: Annex I, Part A of the DPA. Annex 1B: Annex I, Part B of the DPA. Annex II: Annex II of the DPA. Annex III: Annex III of the DPA.
Table 4: Ending the Addendum when the Approved Addendum changes Either party (Importer or Exporter) may end the UK Addendum as set out in its Section 19.

© 2026 Kaya Smart LLC d/b/a Zoviz. 228 Park Ave S, PMB 71118, New York, NY 10003, United States. Questions about this DPA: [email protected].

Terms of Use · Privacy Policy · Licensing