Data Processing Agreement
Effective 30 September 2026.
This agreement forms part of the Terms of Service between the Customer (the controller) and DigiAutomate, a trading name of ZEN AI GOVERNANCE UK LTD (company number 16827795) (the processor). It applies whenever we process personal data in Customer Content on the Customer's behalf. It takes effect when the Customer accepts the Terms and lasts as long as we process Customer personal data.
1. The processing
- Subject matter and purpose: hosting and processing Customer Content to provide WMS Serton: storing project documents, proposing discovery facts, answering questions from project documents, and generating deliverables.
- Nature: storage, retrieval, AI analysis, display, export and deletion.
- Personal data: names, job titles, business contact details and other personal data that appears in the documents and notes the Customer uploads.
- Data subjects: the Customer's users, and people named in the Customer's project material (for example staff of the Customer's clients and suppliers).
- Special category data: not intended. The Customer should not upload it.
2. Our obligations
We will:
- process the personal data only on the Customer's documented instructions, which are these terms and the Customer's use of the Service, unless the law requires otherwise (and then we will tell the Customer first if the law allows);
- make sure that everyone authorised to process it is bound by confidentiality;
- keep appropriate technical and organisational security measures, including encryption in transit and at rest, per-project access control checked on every request, and keeping one client's material out of shared libraries and other projects;
- use only the sub-processors listed in Annex 1 below (the same list is in the Privacy Policy), bind each one to data protection terms no weaker than these, and give the Customer at least 30 days' notice of a new sub-processor, during which the Customer may object and, if we cannot resolve the objection, end the subscription;
- not use a public AI service to process Customer Content, and not use Customer Content to train AI models;
- help the Customer respond to requests from data subjects exercising their rights;
- help the Customer meet its duties on security, breach notification, data protection impact assessments and consultation with the regulator, taking into account the information available to us;
- tell the Customer without undue delay, and in any case within 48 hours, after becoming aware of a personal data breach affecting Customer Content, with the information we have;
- at the end of the Service, at the Customer's choice, return the personal data (by export) and delete it within 30 days, unless the law requires us to keep it;
- make available the information needed to show we meet these obligations, and allow and contribute to reasonable audits, on at least 30 days' notice, at most once a year unless a breach has occurred.
3. International transfers
Customer Content is stored in the United States (Google: Firestore database in the US multi-region, uploaded files and application servers in us-central1, Iowa; account sign-in by Firebase Authentication, which runs only in the US). Evaluator session records are stored in Ireland (Supabase, eu-west-1). AI processing takes place in the United Kingdom on our own workstation. See Annex 1. We transfer personal data outside the UK and the EEA only under an appropriate safeguard:
- UK personal data: the UK International Data Transfer Agreement (IDTA), or the International Data Transfer Addendum to the EU Standard Contractual Clauses, in each case as incorporated in the sub-processor's data processing terms; or the UK Extension to the EU–US Data Privacy Framework where the recipient is certified under it;
- EEA personal data: the EU Standard Contractual Clauses (Commission Decision 2021/914, module 3, processor to processor, where we are the Customer's processor), or the EU–US Data Privacy Framework where the recipient is certified under it.
We carry out and keep a transfer risk assessment for these transfers and will give the Customer a copy of the relevant safeguard on request. Where the Customer is the exporter, the Customer authorises these transfers and these safeguards by accepting this agreement. If a safeguard stops being valid, we will tell the Customer and move to another valid safeguard or stop the transfer.
4. The Customer's obligations
The Customer is responsible for having a lawful basis for the personal data it uploads, for telling the people concerned where required, and for the access it gives its own users.
5. Liability and precedence
Liability under this agreement is subject to the limits in the Terms of Service. If this agreement and the Terms conflict on the processing of personal data, this agreement prevails.
6. Contact
Data protection questions and breach reports: info@digiautomate.com.
Annex 1. Sub-processors and processing locations
Checked against our live configuration on 30 September 2026.
| Provider | Role | Data | Location |
|---|---|---|---|
| Google LLC (Firebase and Google Cloud) | Sub-processor | Firestore database: account records, projects, discovery facts, playbook reviews, questions and answers, generated documents | United States (nam5 US multi-region; fixed when the project was created) |
| Google LLC (Firebase and Google Cloud) | Sub-processor | Cloud Storage: uploaded documents. App Hosting: the application servers that handle every request | United States (us-central1, Iowa) |
| Google LLC (Firebase Authentication) | Sub-processor | Account sign-in: email address, password (stored hashed), sign-in IP address and browser details | United States (Firebase Authentication runs only in US data centres) |
| Supabase Inc. | Sub-processor | Evaluator database (Postgres): session records and evaluation workspace records | Ireland, EU (AWS eu-west-1) |
| DigiAutomate (our own infrastructure) | Processor (not a third party) | AI processing: document text and questions are read by a private model to propose facts, answer questions and draft documents. Nothing is sent to a third-party AI provider | United Kingdom (a private workstation we operate) |
| Stripe | Sub-processor, only if you pay by card | Card payments and subscription status. We never see or store card numbers | Not active yet. If card payment is switched on: Stripe data centres, including the United States, under Stripe’s data processing terms |