Data Processing Agreement
Version 1.0 · 2026-10-08
Parties: Nordrose Technologies OÜ, registry code 16358057, Erika tn 14, 10416 Tallinn, Estonia ("Zeronode", processor) and the customer of the Zeronode service ("Customer", controller).
This agreement takes effect when the Customer creates a Zeronode account or adds the Zeronode widget to its website, and remains in force for as long as the service is used.
1. Scope
Zeronode provides an AI sales assistant for the Customer’s website: a widget on the website, a dashboard and conversation analytics. In doing so, Zeronode processes personal data of the Customer’s website visitors on the Customer’s behalf. The Customer is the controller and Zeronode the processor within the meaning of Article 28 of the General Data Protection Regulation (GDPR).
2. Zeronode’s obligations
- Zeronode processes visitor data only under this agreement and the settings the Customer makes in the dashboard. If Zeronode considers an instruction unlawful, it informs the Customer.
- Only Zeronode staff who need access to provide the service have it, and they are bound by confidentiality.
- Zeronode applies the security measures described in the annex.
- The Customer gives general authorisation to use the sub-processors listed below. Zeronode notifies the Customer of a new sub-processor by email at least 30 days in advance. If the Customer raises a reasoned objection and no solution is found, the Customer may terminate. Zeronode is liable for its sub-processors as for itself.
- Visitors can delete their own conversations from the widget. Where a conversation is identifiable, for example by an email address given in it, Zeronode assists the Customer in deleting it.
- Zeronode notifies the Customer of a personal data breach without undue delay and no later than 48 hours after becoming aware of it.
- Zeronode reasonably assists the Customer with its obligations on security, breaches and impact assessments.
- Zeronode deletes the Customer’s visitor data within 30 days after the service ends, except where law requires retention. On request, Zeronode exports conversations and leads before deletion.
- Zeronode answers the Customer’s reasonable written questions about the processing. If that is not sufficient, the Customer or an independent auditor it appoints may audit Zeronode’s compliance with this agreement at the Customer’s expense, with at least 30 days’ notice and no more than once a year.
3. Customer’s obligations
- The Customer ensures it has a legal basis for processing visitor data and informs visitors about the AI assistant in its privacy notice.
- The Customer does not use the service to deliberately collect special categories of personal data.
- The Customer is responsible for access by its dashboard users.
4. Data location and transfers
Zeronode stores data in the European Union. The model providers listed below, whose servers may be in the USA, process conversation content and photos. Transfers rely on the EU-US Data Privacy Framework and the European Commission’s Standard Contractual Clauses included in the providers’ data processing terms.
5. Governing law
This agreement is governed by Estonian law. Disputes are resolved by Harju County Court.
Description of processing
| Data subjects | Visitors to the Customer’s website. Customer staff who use the dashboard. |
|---|---|
| Purpose | Conversation with the visitor, product recommendations, prefilling the Customer’s web forms on the visitor’s confirmation, passing leads to the Customer, conversation analytics. |
| Categories of data | Conversation content. Contact details if the visitor gives them. Browsing context within the same visit: pages viewed, time on page, products viewed, searches, cart state. Uploaded photos. Browser language. |
| Not collected | No cookies are set. No persistent visitor identifier is created. Visitors are not tracked across websites or visits. IP address and user agent are not stored. |
Retention
| Data | Retention |
|---|---|
| Conversation content | 30 days after the last message |
| Raw conversation state kept to resume a conversation | 7 days after the last message |
| Search texts and conversation summary | 30 days |
| Widget usage events without free text (opens, clicks, add-to-cart) | 90 days |
| Conversation statistics without free text (duration, outcome, products shown) | 13 months |
| Photos uploaded by visitors | 7 days |
| Leads including contact details | until the Customer deletes them or the agreement ends |
Sub-processors
| Sub-processor | Purpose | Location | Transfer basis | Retention at provider |
|---|---|---|---|---|
| Amazon Web Services EMEA SARL | servers, database, photo storage, widget files | Stockholm, Sweden | no transfer outside the EU | per the retention table |
| OpenAI | conversation model | USA | EU-US Data Privacy Framework, Standard Contractual Clauses | up to 30 days for abuse monitoring; not used for training |
| photo search, room visualisation, email notifications to the Customer | USA and other Google locations | EU-US Data Privacy Framework, Standard Contractual Clauses | limited period for abuse monitoring; not used for training |
Security measures
- All traffic between the visitor’s browser, the Customer’s website and Zeronode is encrypted (TLS).
- Data is stored in the European Union in an AWS data centre. Photos are kept in a private, encrypted store and deleted automatically after 7 days.
- The widget only works on domains the Customer allows.
- Access to production data is limited to Zeronode staff who need it to provide the service.
- Conversations and usage events are deleted automatically per the retention table.
- Visitor IP addresses and user agents are not stored.