Data Processing Agreement

Parties: Nordrose Technologies OÜ, registry code 16358057, Erika tn 14, 10416 Tallinn, Estonia ("Zeronode", processor) and the customer of the Zeronode service ("Customer", controller).

This agreement takes effect when the Customer creates a Zeronode account or adds the Zeronode widget to its website, and remains in force for as long as the service is used.

1. Scope

Zeronode provides an AI sales assistant for the Customer’s website: a widget on the website, a dashboard and conversation analytics. In doing so, Zeronode processes personal data of the Customer’s website visitors on the Customer’s behalf. The Customer is the controller and Zeronode the processor within the meaning of Article 28 of the General Data Protection Regulation (GDPR).

2. Zeronode’s obligations

  1. Zeronode processes visitor data only under this agreement and the settings the Customer makes in the dashboard. If Zeronode considers an instruction unlawful, it informs the Customer.
  2. Only Zeronode staff who need access to provide the service have it, and they are bound by confidentiality.
  3. Zeronode applies the security measures described in the annex.
  4. The Customer gives general authorisation to use the sub-processors listed below. Zeronode notifies the Customer of a new sub-processor by email at least 30 days in advance. If the Customer raises a reasoned objection and no solution is found, the Customer may terminate. Zeronode is liable for its sub-processors as for itself.
  5. Visitors can delete their own conversations from the widget. Where a conversation is identifiable, for example by an email address given in it, Zeronode assists the Customer in deleting it.
  6. Zeronode notifies the Customer of a personal data breach without undue delay and no later than 48 hours after becoming aware of it.
  7. Zeronode reasonably assists the Customer with its obligations on security, breaches and impact assessments.
  8. Zeronode deletes the Customer’s visitor data within 30 days after the service ends, except where law requires retention. On request, Zeronode exports conversations and leads before deletion.
  9. Zeronode answers the Customer’s reasonable written questions about the processing. If that is not sufficient, the Customer or an independent auditor it appoints may audit Zeronode’s compliance with this agreement at the Customer’s expense, with at least 30 days’ notice and no more than once a year.

3. Customer’s obligations

  1. The Customer ensures it has a legal basis for processing visitor data and informs visitors about the AI assistant in its privacy notice.
  2. The Customer does not use the service to deliberately collect special categories of personal data.
  3. The Customer is responsible for access by its dashboard users.

4. Data location and transfers

Zeronode stores data in the European Union. The model providers listed below, whose servers may be in the USA, process conversation content and photos. Transfers rely on the EU-US Data Privacy Framework and the European Commission’s Standard Contractual Clauses included in the providers’ data processing terms.

5. Governing law

This agreement is governed by Estonian law. Disputes are resolved by Harju County Court.

Description of processing

Retention

Sub-processors

Security measures

  • All traffic between the visitor’s browser, the Customer’s website and Zeronode is encrypted (TLS).
  • Data is stored in the European Union in an AWS data centre. Photos are kept in a private, encrypted store and deleted automatically after 7 days.
  • The widget only works on domains the Customer allows.
  • Access to production data is limited to Zeronode staff who need it to provide the service.
  • Conversations and usage events are deleted automatically per the retention table.
  • Visitor IP addresses and user agents are not stored.