ZipLoom
Home
PricingSign inGet Your Live URL
Draft — not legally reviewed. Do not rely on before launch.
Legal

Data Processing Addendum

How ZipLoom processes personal data on your behalf as your data processor.

1. Roles

For personal data contained in Customer Content, the Customer is the data controller and ZipLoom is the data processor. ZipLoom processes personal data only on the Customer's documented instructions, including as set out in the Terms of Service and this Addendum.

2. Scope and purpose of processing

ZipLoom processes personal data solely to provide the service: scanning, deploying, and monitoring the Customer's applications, and providing support. The categories of data and data subjects are those the Customer chooses to route through the service.

3. Sub-processors

ZipLoom uses vetted sub-processors to deliver the service (including Cloudflare, Supabase, Stripe, and SendPulse — see the Trust Center). ZipLoom will inform the Customer of intended changes to sub-processors and give the Customer the opportunity to object.

4. Security measures

ZipLoom maintains technical and organizational measures appropriate to the risk, including encryption of secrets at rest (AES-256), role-based access control, audit logging, and network protections. Full detail is in the Trust Center.

5. Data-subject requests

ZipLoom will assist the Customer, taking into account the nature of the processing, in responding to requests from data subjects exercising their rights under applicable law.

6. Personal-data breach

ZipLoom will notify the Customer without undue delay after becoming aware of a personal-data breach affecting the Customer's data, and will provide information reasonably necessary for the Customer to meet its own notification obligations.

7. Return and deletion

On termination, ZipLoom will delete or return the Customer's personal data in accordance with the Terms, save where retention is required by law.

8. International transfers

Where personal data is transferred across borders, ZipLoom relies on an appropriate transfer mechanism as required by applicable law.

Draft — to finalize before launch
  • REQUIRED: full legal review by counsel before this is published or linked — the text above is a structural placeholder, not legal advice
  • Insert the correct legal entity name, address, and governing-law jurisdiction
  • Attach the SCC / transfer-mechanism specifics and any UK/EU addenda
  • Confirm the sub-processor list and the notice/objection mechanism
  • Confirm breach-notification timeframe wording and retention periods
  • Decide the signature / acceptance mechanism (click-accept vs signed) and how customers request a countersigned copy
  • This page is set to noindex until finalized