Skip to content
ZeroACE

Data Processing Agreement

Last updated: September 28, 2026

This Data Processing Agreement (“DPA”) forms part of the Terms of Service between the Customer (the “Controller”) and Zero Core Studio LLC (“ZeroACE”, the “Processor”) and applies where ZeroACE processes personal data of the Customer’s End Customers on the Customer’s behalf.

It reflects the requirements of Article 28 of the GDPR and equivalent obligations under the KVKK and other applicable data-protection laws.

1. Roles and scope

The Customer is the controller and ZeroACE is the processor of the personal data processed to provide the Service. Each party will comply with its obligations under applicable data-protection law. Where the Customer is itself a processor for a third party, ZeroACE acts as a sub-processor.

2. Details of processing

  • Subject matter and duration — processing to provide the Service for the duration of the subscription and any wind-down period.
  • Nature and purpose — hosting, routing, and processing conversations and orders; generating AI responses; reading from and writing to the Controller’s store platform (for example Shopify or WooCommerce); and triggering fulfillment actions through Connected Providers on the Controller’s instructions.
  • Types of personal data — contact details, conversation content, order and transaction metadata, and other data the Controller configures.
  • Categories of data subjects — the Controller’s End Customers and other individuals whose data the Controller submits.

3. Processing on instructions

ZeroACE will process personal data only on the Controller’s documented instructions, including as set out in the Terms and the configuration of the Service, unless required to do otherwise by law (in which case it will inform the Controller where permitted). ZeroACE will not use Customer Data to train foundation models and configures its AI sub-processors accordingly.

ZeroACE will not use personal data processed on the Controller’s behalf for any purpose of its own. In particular it will not sell, rent, license, or otherwise disclose that data to third parties for their own purposes, and will not use it to create or enrich user or advertising profiles. Disclosure to sub-processors engaged to provide the Service, and to authorities where legally required, is not a purpose of ZeroACE’s own and is addressed separately below.

4. Confidentiality

ZeroACE ensures that persons authorized to process the personal data are bound by confidentiality obligations.

5. Security measures

ZeroACE implements appropriate technical and organizational measures to protect personal data, including encryption of provider credentials in a key vault with a separate key per business, tenant-scoped access controls, least-privilege and timing-safe authentication, and checkpointed processing designed to prevent duplicate side effects. A summary is available on our Security page.

Access to End Customer personal data is recorded in a tamper-evident, append-only log, kept separately for each business and cryptographically chained so that a later insertion, edit or deletion is detectable. The log records which category of personal data was accessed, by which internal actor reference, for what purpose and with what outcome. It does not record the personal data itself.

6. Sub-processors

The Controller authorizes ZeroACE to engage sub-processors to provide the Service, including cloud hosting, large-language-model providers, email delivery, and telephony. The current list is published at Sub-processors. ZeroACE imposes data-protection obligations on its sub-processors substantially similar to those in this DPA and remains responsible for their performance. ZeroACE will give notice of intended changes to sub-processors and allow the Controller a reasonable opportunity to object on reasonable data-protection grounds.

7. Assistance with data-subject requests

Taking into account the nature of the processing, ZeroACE will assist the Controller with appropriate technical and organizational measures to respond to requests from data subjects to exercise their rights, and will forward any such request it receives directly to the Controller.

For erasure, the Service lets the Controller erase an individual End Customer's personal data from the console. ZeroACE carries the erasure out across the Service once any order of that End Customer still in progress is complete and its legal documents are issued, and keeps the order records the Controller must retain by law without the personal data. Where the Controller's WhatsApp account is connected, the End Customer is also removed from its contact book; if the connection refuses this, ZeroACE tells the Controller at once, and the erasure completes when it is reconnected.

A few working copies are not reached by an individual erasure and are deleted on a fixed schedule: raw messages and delivery updates received from providers (30 days); saved provider answers, such as invoice and label links, kept so that a retried request is never carried out twice (at least 97 days); conversations that cannot be tied to the End Customer (90 days, or 180 with a call recording); contact details held while a delivery problem is resolved (3 days); and system logs (up to 90 days). Backups are kept for up to 35 days.

8. Personal data breaches

ZeroACE will notify the Controller without undue delay after becoming aware of a personal data breach affecting the Controller’s data, and will provide information reasonably available to help the Controller meet its notification obligations.

9. International transfers

Where processing involves transferring personal data across borders, ZeroACE relies on appropriate safeguards such as the Standard Contractual Clauses (with the UK Addendum where relevant) and the transfer mechanisms permitted under the KVKK, together with supplementary measures where needed.

10. Return and deletion

On termination of the Service, ZeroACE will, at the Controller’s choice, delete or return the personal data it processes on the Controller’s behalf and delete existing copies, unless retention is required by law. The Controller may export its data for 30 days after termination. Copies in backups are overwritten within 35 days.

The access log described under Security measures is an exception: it is retained beyond termination and is neither deleted nor altered, because it holds no personal data values and exists to demonstrate compliance. Deletion and redaction of the underlying records proceed as described above, and once those records are redacted the internal identifiers the log refers to no longer resolve to an identifiable person.

11. Audits and information

ZeroACE will make available information reasonably necessary to demonstrate compliance with this DPA and will allow for and contribute to audits, including inspections, conducted by the Controller or an auditor it mandates, subject to reasonable confidentiality and scheduling arrangements.

12. Liability and precedence

Each party’s liability under this DPA is subject to the limitations of liability in the Terms of Service. In the event of a conflict between this DPA and the Terms regarding the processing of personal data, this DPA prevails.