ZENTRE – Data Processing Agreement (DPA)
English convenience translation. Only the German version (“AVV/DPA”) is legally binding; the English translation is provided for information purposes only. In case of discrepancies, the German version prevails.
Last updated: 4 Sep 2026
Key points at a glance (non-binding orientation — the contract text prevails): Your data is processed exclusively in the EU (hosting: Scaleway, Paris) · AI requests are routed via the EU gateway Cortecs, with zero data retention · Your content is not used to train AI models · You select the model class — “EU-hosted” or “EU-sovereign”; in both classes exclusively EU endpoints, zero data retention, and exclusion of training (Section 13) · Chats are deleted after 90 days (exportable beforehand) · New subprocessors are announced 14 days in advance and you may object · We notify you of personal data breaches within 48 hours · For professional secrecy holders, Section 20 (Section 203 mode) additionally applies.
Who is who: the “Controller” under this DPA is you — the Customer within the meaning of the GTC. The “Processor” is EZTO.
1. Preamble, parties, order of precedence
- This Data Processing Agreement (“DPA”) governs the processing of personal data by EZTO TECHNOLOGIES GmbH, Mainz (“Processor”) on behalf of the Customer (“Controller”) in connection with the “Zentre” service.
- This DPA forms part of the main agreement (Terms/order form). In case of conflict, the provisions of this DPA prevail for data protection matters. Otherwise, the main agreement applies.
- GDPR terms apply accordingly.
2. Roles and delineation (Processor vs. Controller)
- Processor scope: This DPA applies to processing in which EZTO processes Customer data as a processor on behalf of the Controller, in particular: provision and operation of Zentre (workspace/chat, user management, access control); inference/orchestration/routing to AI providers per configuration; support and error analysis where Customer data is processed for this purpose; security/abuse prevention/incident handling.
- Controller scope: Where EZTO processes personal data as its own controller (e.g., marketing/website, contract initiation/conclusion, billing/payment processing, company-related compliance, and product improvement based on aggregated, non-personal usage statistics — content data is not used for this), this DPA does not apply; the privacy notices and any separate agreements apply instead.
- No BYOK: Zentre does not currently support “Bring Your Own Key” (BYOK). The selection/activation of AI providers takes place via Zentre configurations.
- Roles under the AI Act: The data protection roles (controller/processor) and the roles under Regulation (EU) 2024/1689 as amended by Regulation (EU) 2026/1744 (the “AI Act”: provider/deployer) are independent of one another and do not correspond: the Customer is the controller and at the same time the deployer within the meaning of the AI Act; EZTO is the processor and at the same time the provider of the AI system made available in the Service. The allocation of duties under the AI Act is governed by Section 8 of the Terms.
3. Definitions
- “Customer data”: all personal data that the Controller or its users input, upload, generate, or otherwise provide in Zentre (including content data and metadata).
- “Content data”: workspace/chat content, prompts, uploads, documents, and outputs (where stored/displayed in Zentre).
- “Metadata”: usage, billing, security, and technical telemetry data (e.g., timestamps, request IDs, configuration parameters, token/volume metrics, error messages), where personal.
- “AI provider”: a third-party provider to which Zentre forwards workloads for inference/generation.
- “Subprocessor”: a sub-processor within the meaning of Art. 28 (2) GDPR.
- “Plan”: the seat-based license named in the order form/main agreement (one plan, per user); in addition, Enterprise and Private Cloud options exist by separate agreement.
4. Subject matter, nature, purpose, duration
- The subject matter is the processing of Customer data to provide, securely operate, maintain, and support Zentre.
- Duration: the term of the main agreement; thereafter deletion/return in accordance with Section 15.
- Details on nature/purpose/data categories/data subjects: Annex 1.
5. Instructions and instruction management
- Processing takes place exclusively on the documented instruction of the Controller (Art. 28 (3) (a) GDPR).
- Documented instructions include: (i) the main agreement/DPA, (ii) product and account configurations (provider selection, allow/deny, routing, regions, retention, logging), (iii) individual instructions by an administrator of the Controller in text form to legal@zentre.ai; EZTO may refer instructions from individual users to the administrators.
- The instruction requirement also applies to transfers of personal data to a third country or an international organisation, unless EZTO is required to process by Union or Member State law to which it is subject; in that case, EZTO informs the Controller of that legal requirement before processing, unless that law prohibits such information on important grounds of public interest (Art. 28 (3) (a) GDPR).
- If EZTO is of the opinion that an instruction infringes the GDPR or other Union or Member State data protection provisions, EZTO informs the Controller without undue delay (Art. 28 (3), second subparagraph, GDPR); manifestly unlawful instructions are not carried out.
- Additional, non-agreed effort may be remunerated in accordance with the main agreement, to the extent permissible.
6. Obligations of the Controller
- Responsible for legal bases/transparency obligations, the content of the Customer data, the configuration (provider/region/retention/logging), and the assessment of the suitability/permissibility of outputs for its own purposes.
- Data minimization: The Controller ensures that only necessary personal data is processed. Special categories (Art. 9 GDPR) only where legally safeguarded and necessary for the use case.
- Religious (church) institutions (optional): Where the Controller is subject to ecclesiastical data protection law (the Catholic KDG or the Protestant DSG-EKD), its provisions apply additionally or with priority. The Parties shall ensure processing accordingly, in particular as regards reporting channels and the competence of the respective ecclesiastical data protection supervisory authority; references to the GDPR apply mutatis mutandis to the KDG/DSG-EKD.
7. Confidentiality
- EZTO ensures that persons authorized to process are bound to confidentiality (Art. 28 (3) (b) GDPR).
- Need-to-know, role-based access, appropriate logging.
- For professional secrecy holders, Section 20 applies in addition.
8. Security of processing (Art. 32 GDPR)
- Appropriate TOMs pursuant to Annex 2 (including transport encryption TLS 1.2 or higher, encryption of data/artifacts at rest with AES-256 (at minimum), RBAC/least privilege, tenant separation, secure SDLC, monitoring/incident response). EZTO operates an ISO/IEC 27001-aligned ISMS; certification is underway; EZTO publishes the current status in the Trust Center.
- TOMs may be further developed, provided the overall level of security is not reduced.
9. Hosting and data location (default)
- Standard hosting path: EU hosting with Scaleway (Scaleway SAS, France), region Paris (fr-par), to the extent technically provided for in the respective service/plan. Productive processing of Customer data takes place within the EU/EEA.
- Differing Enterprise options may be agreed via order form.
10. Assistance with data subject rights
- EZTO assists the Controller – to the extent possible and taking into account the nature of the processing – with data subject rights (Art. 28 (3) (e) GDPR), in particular through provided functions (export/deletion) and appropriate cooperation.
- Direct data subject requests to EZTO are – where permissible – forwarded to the Controller; no independent response without instruction.
11. Assistance with compliance (Art. 28 (3) (f) GDPR)
EZTO appropriately assists the Controller with Art. 32–34, 35, 36 GDPR — primarily through the documentation provided in the Trust Center (TOM, data flow document, subprocessor list). Individual assistance beyond this (e.g., completing customer-specific DPIA templates, workshops) is reasonably remunerated in accordance with the main agreement, to the extent permissible.
12. Subprocessors
- General authorization (Art. 28 (2) GDPR).
- Current list: Annex 3 and the subprocessor list published in the Trust Center (zentre.ai/trust-center).
- Changes (engagement or replacement of subprocessors) are announced at least fourteen (14) days before they take effect in text form to the administrator e-mail address stored in the account and are additionally published via the subprocessor list in the Trust Center; the notice period begins upon dispatch of the e-mail. The Controller keeps the address up to date. Compelling security reasons may require a faster change, in which case the Controller is informed without undue delay. The Controller may object to the change in text form to legal@zentre.ai within the notice period (Art. 28(2) GDPR).
- In the event of legitimate objections: a reasonable alternative or a right of termination for the affected part of the service.
- Flow-down: EZTO binds subprocessors at least equivalently (Art. 28 (4) GDPR).
- EZTO remains responsible for compliance with subprocessor obligations within the framework of the GDPR, to the extent legally mandatory.
13. AI providers / AI routing
- Zentre acts as an infrastructure, orchestration, and governance layer. Depending on the configuration, content data is forwarded to AI providers for inference/generation.
- AI gateway Cortecs: Routing to AI providers takes place by default via the EU-based AI gateway Cortecs (Cortecs GmbH, Vienna), which processes data within the EU (zero data retention) and integrates the AI providers as its own subprocessors; the current subprocessor list of Cortecs is decisive in this respect (Annex 3 / Trust Center).
- Model classes: The integrated endpoints are assigned to two classes. Both classes cumulatively require: inference exclusively via endpoints in the EU/EEA, zero data retention, no use of content data for training or fine-tuning, and a prior contractual undertaking from every link in the chain (gateway, operator of the endpoint, any further contributing persons). The classes differ in who operates the endpoint:
- “EU-hosted” (default): the endpoint is operated in the EU/EEA; the operator or its ultimate parent may additionally be subject to the law of a third country. This class also includes models at the respective current performance frontier (“frontier models”), to the extent their providers make available EU endpoints with zero data retention. A disclosure request by a third-country authority addressed to the operator is not entirely excluded in law; EZTO counters this through zero data retention, the exclusion of training, and the procedure under Section 17.
- “EU-sovereign”: the endpoint is operated by an undertaking that is subject exclusively to the law of an EU/EEA state and has no ultimate parent in a third country. This also includes open models that this operator runs itself in the EU; in that case the model developer receives no access to inference data. The origin of the model is irrelevant for the assignment; only the operator is decisive.
- Selection and switching of the model class: The Controller selects the model class per tenant in the product. The selection constitutes a documented instruction; it is logged with timestamp, selecting person and selected class and is retrievable by the Controller. A switch is possible at any time; it takes effect for requests from the time of the switch and is logged in the same way. For Section 203 mode, Section 20 applies in addition.
- No model names in the contract text: This DPA does not name individual models or model versions. Which endpoints are enabled per class and who operates them follows from the subprocessor list (Annex 3 / Trust Center) and, for Section 203 mode, additionally from Annex 2 of the confidentiality agreement.
- Image generation: Image generation is available in the Service. The same model classes, the same purpose limitation, and the same exclusion of training apply to image generation as to the remaining inference. Generated image files are marked machine-readably as AI-generated in accordance with the paragraph on provenance metadata. Inputs that the Controller provides for image generation (e.g., uploaded photographs) are content data; their processing takes place on the Controller’s instruction, and the Controller remains responsible for their permissibility — in particular in the case of depictions of identifiable persons and of data under Art. 9 GDPR.
- Web search (Linkup): Where the web search function is activated, search queries are transmitted to the search provider Linkup (Linkup Technologies SAS, France); activation constitutes a documented instruction. Linkup is integrated with the zero-data-retention option activated; no permanent storage of the queries by Linkup or EZTO takes place. For the processing of protected secrets (Section 203 StGB), Section 20 applies: in Section 203 mode, web search is deactivated.
- Storage/retention in Zentre (chat/workspace): chat/workspace content data is retained for 90 days by default; differing configurations (e.g., Enterprise/Private Cloud) constitute a documented instruction. After expiry of the retention, the content data is deleted or – where technically provided for – irreversibly removed.
- Clarification: additional permanent content “logging” does not take place by default, except in the following exceptional cases.
- Exceptions (logging/support/security): content data may be temporarily processed/stored to the extent necessary for activated debug/logging options, support cases on documented instruction, or security-relevant events – in each case in accordance with the retention configuration and the principle of necessity.
- No training: EZTO does not use content data to train its own or generic models. Use for training purposes is also contractually excluded vis-à-vis the integrated AI providers (a precondition for activation under this Section).
- Provider-dependent processing: processing by AI providers is provider-dependent; the selection/activation of an AI provider constitutes a documented instruction.
- Professional secrecy: For the processing of protected secrets within the meaning of Section 203 StGB, the model selection is restricted to the endpoints authorized for Section 203 mode within the model class selected by the Controller; the class must be expressly selected upon activation of Section 203 mode (Section 20).
- Contractual integration as a precondition for activation: A model endpoint is activated only if (i) its operator is contractually integrated as a subprocessor — directly or via the gateway, (ii) zero data retention and the exclusion of training and fine-tuning with content data are contractually committed, and (iii) for Section 203 mode, an undertaking of confidentiality in text form in accordance with EZTO’s template is additionally in place (Section 20). If any of these preconditions is absent, the endpoint is not activated; if it ceases to apply later, the endpoint is blocked. There is no reservation in favour of what the respective provider offers or enables.
- Scope of guarantees: Beyond the integration set out above and the passing-on of the terms and declarations committed by the operator, EZTO owes no guarantees for the conduct of the operators. Responsibility for an operator’s deviations from its own commitments exists only within the framework of mandatory statutory provisions and otherwise in accordance with the liability provisions of the main agreement.
- Knowledge of provider deviations: If EZTO becomes aware of a material deviation by an AI provider from its commitments, EZTO takes appropriate measures (e.g., informing the Controller, recommending/implementing deactivation or routing blocking), to the extent technically possible and economically reasonable.
- Provenance metadata (Art. 50(2) AI Act): To fulfil the marking obligation under Art. 50(2) AI Act, files generated in the Service embed machine-readable provenance indications (“provenance metadata”); this covers generated image files as well as generated documents, structured outputs, and text outputs. This metadata forms part of the generated file and generally remains in it when the Controller exports the file or transmits it to third parties; format-related loss caused by downstream processing in third-party systems lies outside EZTO’s sphere of influence. The scope of the embedded fields is documented in the Trust Center; EZTO limits the fields to what Art. 50(2) AI Act requires. Art. 50(2) AI Act applies to the Service only from 2 December 2026 pursuant to Art. 111(4) AI Act; the marking is nevertheless already active in the Service today, and EZTO implements it voluntarily ahead of the statutory application date. The allocation of roles and duties under the AI Act is otherwise governed by Section 8 of the Terms.
14. Third-country transfers
- No third-country transfers take place in the product data flow: hosting, routing and inference take place in the EU/EEA, and both model classes require endpoints in the EU/EEA (Section 13). Transfers outside the EU/EEA are limited to the ancillary services identified in Annex 3 (payment processing, transactional email) and take place in compliance with Art. 44 et seq. GDPR (adequacy decision, SCC).
- Upon request, EZTO provides the Controller with appropriate information on transfer mechanisms and – where available – supplementary measures.
- Group of companies: EZTO belongs to a group of companies; the ultimate parent is established outside the EU. The shareholding exists solely at shareholder level; details and group chart: data flow document in the Trust Center, section 4. No processing of content data takes place above EZTO; no company of the group outside the EU/EEA acts as processor or subprocessor or is otherwise involved in providing the service for the Controller, and none is granted access to content data or key material (Annex 2, sections 1 and 5; data flow document in the Trust Center). No transfer of Customer data to companies of the group takes place. Should a service region outside the EU be operated in future, the regions will be kept separate; there is no mutual access, and the region assigned to the Controller remains unchanged until the Controller selects a different region.
15. Deletion and return
- During the contract term, deletion takes place according to the configured retention (cf. Section 13 and Annex 4).
- After contract termination: at the Controller’s choice, (i) return (export in commonly used machine-readable formats, where available) or (ii) deletion.
- Production systems: the export is generally provided within fourteen (14) days, at the latest within 30 days of receipt of the request. Deletion takes place after expiry of the 30-day retrieval period (Annex 4), but no earlier than after complete provision of an export requested within that period; where agreed exit assistance is used (e.g., Section 8(4) of the DORA Addendum), no earlier than after its completion.
- Backups: data may be contained in backups until the expiry of technical deletion/overwrite cycles; backups are not used productively. Backup cycles are typically up to 90 days. Where data is restored from backups, previously deleted data is deleted again without undue delay.
16. Personal data breaches
- EZTO informs the Controller without undue delay, at the latest within 48 hours of becoming aware, of breaches of the protection of personal data.
- The notification contains – where available – the nature of the incident, the categories of data affected, the approximate number, the likely consequences, the remedial measures taken/planned, and a point of contact; updates follow as soon as new information is available.
17. Authority requests / disclosure
- To the extent legally permissible, EZTO informs the Controller without undue delay of legally binding requests from authorities to disclose Customer data.
- Disclosures are – where possible – limited to the necessary minimum; EZTO cooperates in appropriate protective measures.
18. Evidence and audits
- EZTO makes available to the Controller all information necessary to demonstrate compliance with the obligations laid down in Art. 28 GDPR (Art. 28 (3) (h) GDPR), e.g., TOM overviews, policies, audit and certification reports, and allows for and contributes to reviews — including inspections — conducted by the Controller or an auditor mandated by the Controller (bound to confidentiality and not a direct competitor of EZTO).
- Audits are permitted after prior notice (at least 60 days) and under appropriate conditions; “remote-first” on the basis of the standard evidence package (Annex 2). On-site inspections are permitted after prior notice during normal business hours where remote audit and evidence are insufficient in the individual case or a competent supervisory authority orders them; they are conducted under confidentiality and without disproportionate disruption of operations; more extensive on-site rights may be agreed in the Enterprise order form.
- Frequency: a maximum of 1 audit per contract year, unless there is a security incident or legitimate cause.
- No (automated) vulnerability/penetration tests against EZTO systems without prior consent in text form.
- Audits are subject to strict confidentiality; no disclosure of operating/trade secrets beyond the necessary extent.
- Costs: the Controller bears its audit costs; reasonable effort by EZTO may be charged in accordance with the main agreement, to the extent permissible.
19. Documentation
EZTO maintains a record of processing activities as a processor (Art. 30 (2) GDPR) and provides the Controller upon request with appropriate information/extracts therefrom, to the extent necessary to fulfil the accountability obligation and provided no legitimate confidentiality interests or third-party trade secrets conflict.
20. Involvement in professional secrecy (Section 203 StGB; professional law requirements)
- Scope: To the extent the Controller is subject to a criminally sanctioned confidentiality obligation under Section 203 StGB (Austria: professional confidentiality duties such as Section 80 WTBG 2017 or Section 9 RAO and — in particular for health professions — Section 121 öStGB; Switzerland: Article 321 of the Swiss Criminal Code) and uses Zentre to process protected secrets, EZTO acts as an “other contributing person” within the meaning of Section 203 (3) StGB. In addition, the relevant professional-law requirements apply, in particular Section 43e of the German Federal Lawyers’ Act (BRAO) in conjunction with Section 2 of the Professional Code for Lawyers (BORA), Section 62a of the German Tax Advisory Act (StBerG), Sections 43(1), 50 and 50a of the German Public Accountants Act (WPO) (public auditors and sworn auditors), Sections 18, 26 and 26a of the German Federal Notaries Act (BNotO), Section 39a in conjunction with Section 39c of the German Patent Attorneys Act (PAO), and Section 80 of the Austrian WTBG 2017 (Austrian tax advisors and auditors); in the case of statutory audits, Section 323 of the German Commercial Code (HGB) applies in addition.
- Confidentiality & instruction: EZTO and the persons authorized to process are bound to confidentiality in text form and instructed about the criminal consequences (Section 203 (4) StGB); the obligation continues after contract termination.
- Requirements of the service-provider provisions: The requirements applicable to the contract with a service provider (Section 43e(3) BRAO, Section 62a(3) StBerG, Section 50a(3) WPO, Section 26a(3) BNotO, Section 39c(3) PAO) are reflected in the confidentiality agreement under Section 203 StGB: text form, undertaking together with instruction about the criminal consequences, limitation of access to what is necessary for the performance of the contract, and the express stipulation that EZTO may involve further persons and must bind them to confidentiality in text form.
- Obligations remaining with the professional: The careful selection and monitoring of the service provider, and the termination of the cooperation where compliance is no longer ensured (Section 43e(2) BRAO, Section 62a(2) StBerG, Section 50a(2) WPO, Section 26a(2) BNotO), are incumbent on the Controller; EZTO provides the information required for this purpose via the Trust Center. Where the use of the Service directly serves an individual mandate, granting access to third-party secrets requires the client’s consent (Section 43e(5) BRAO, Section 62a(5) StBerG, Section 50a(5) WPO; for notaries correspondingly Section 26a(4) BNotO — consent of the party concerned for services directly serving an individual notarial transaction); obtaining this consent is incumbent on the Controller.
- Flow-down: EZTO binds subprocessors and operators of model endpoints that may access protected secrets, before their deployment, to equivalent confidentiality in text form. If a further contributing person cannot be bound equivalently, it is not used for the processing of protected secrets.
- Section 203 mode: The processing of protected secrets is permitted only in a suitable configuration: hosting and productive processing in the EU/EEA, EU routing, zero data retention, exclusion of training, deactivated web search, a separate tenant in accordance with this Section, and exclusively endpoints that are enabled for Section 203 mode within the selected model class (Annex 2 of the confidentiality agreement).
- Model classes in Section 203 mode: The two model classes under Section 13 apply, with their common basis (EU endpoints, zero data retention, no training or fine-tuning, undertaking from every link in the chain). In Section 203 mode, both classes are additionally subject to the requirement that every link in the chain is also bound to confidentiality under the flow-down provision of this Section and that access from third countries to the content of the Section 203 tenant stored in Zentre and to the control plane is technically prevented. In the “EU-sovereign” class, no operator in the chain is subject to the law of a third country; in the “EU-hosted” class, the operator of an endpoint or its ultimate parent may additionally be subject to the law of a third country, so that a disclosure request by a third-country authority is not entirely excluded in law.
- Selection of the model class (Controller’s right of choice): The Controller selects the model class for the Section 203 tenant. The selection must be made expressly upon activation of Section 203 mode; without such selection, Section 203 mode is not activated. It constitutes a documented instruction and is logged with timestamp, selecting person and selected class; the record is retrievable by the Controller and may be presented in professional-law audits. A switch between the classes is possible at any time, takes effect for requests from the time of the switch, and is logged in the same way. For contracts concluded before this version took effect, the existing configuration (class “EU-sovereign”) continues to apply until the Controller actively selects a different class.
- EZTO’s duty to inform: In the selection dialogue, EZTO points out in clear language the difference between the classes and the residual risk of a third-country disclosure request that remains in the “EU-hosted” class. The professional-law assessment of which class is required for the specific activity is incumbent on the Controller; EZTO does not provide legal advice in this respect.
- Web search in Section 203 mode: Web search is deactivated in Section 203 mode in both model classes.
- Tenant separation (separate tenant): Protected secrets are processed in a dedicated, logically isolated tenant separated from normal operation, with its own, isolated knowledge base/index. A physically separated environment (private cloud/on-premises) may be agreed separately as an Enterprise option. There is no shared knowledge base and no cross-tenant data transfer/cross-tenant search; a tenant switch is a pure identity/navigation switch (e.g., via SSO) without content transfer. The assignment of data to the Section 203 tenant is the responsibility of the Controller (in case of doubt, the Section 203 tenant); secrecy-free/internal matters may be processed in the normal tenant.
- Statutory audit (Section 323 HGB): Where the Controller performs statutory audits, the confidentiality obligation under Section 323(1) sentence 1 HGB applies in addition to Section 203 StGB and the professional-law requirements. Trade and business secrets to which EZTO gains access in this context are not exploited; in particular, no use for training or fine-tuning takes place (cf. Section 323(1) sentence 2 HGB and Section 13). The responsibility and liability of the auditor under Section 323 HGB is neither excluded nor limited by this DPA (Section 323(4) HGB).
- Foreign element: In the case of services performed abroad, granting access to third-party secrets requires protection comparable to that available domestically (Section 43e(4) BRAO, Section 62a(4) StBerG, Section 50a(4) WPO). In Section 203 mode, hosting, routing, and inference take place exclusively in the EU/EEA; access to the content of the Section 203 tenant stored in Zentre and to the control plane from third countries does not take place and is prevented by technical access controls. For inference: exclusively endpoints in the EU/EEA with zero data retention; in the “EU-hosted” class, protection vis-à-vis the operator of the endpoint rests on its contractual undertaking (flow-down under this Section), not on technical control by EZTO.
- Supplementary agreement: The processing of protected secrets requires the conclusion of a separate confidentiality agreement under Section 203 StGB, which may also be concluded electronically; EZTO provides this agreement. In case of conflict, its provisions prevail for Section 203 matters.
- Model changes in Section 203 mode: For the removal or replacement of the endpoints authorized in Section 203 mode, the 30-day period pursuant to Section 7(4) of the confidentiality agreement applies, notwithstanding Section 12. The addition of further endpoints of operators already integrated and announced, within the model class selected by the Controller is permitted without separate announcement; endpoints of new operators are announced pursuant to Section 12 (at least 14 days), provided they meet the requirements of this Section; an endpoint is not moved to the respective other model class without a selection by the Controller.
21. Final provisions
- Governing law and place of jurisdiction are governed by the main agreement (German law; place of jurisdiction Mainz, to the extent permissible).
- Should any provision of this DPA be or become invalid, the validity of the remaining provisions remains unaffected; the invalid provision is replaced by a valid one that comes closest to its purpose and meets the requirements of the GDPR.
- Amendments and supplements require at least text form.
Annexes to the DPA
Annex 1 — Description of the processing (Art. 28 (3) GDPR)
Subject matter of the processing: provision and operation of the AI orchestration and governance platform “Zentre” (chat assistant, agents, RAG/knowledge tool, image generation) as SaaS.
Nature of the processing: automated collection, recording, storage, display, structuring, transmission (to the AI gateway/AI providers and – where activated – to the search provider), restriction, and deletion.
Purpose: provision of the contractually agreed services, user/access management, support/error analysis, security/abuse prevention/incident handling.
Categories of personal data:
- account/organization data (name, business email, organization, roles/permissions);
- usage, billing, security, and technical metadata (timestamps, request IDs, configuration, token/volume metrics, error messages, IP where necessary);
- content data (prompts, uploads, documents, images and other outputs; including uploaded and AI-generated image files);
- web search queries (only where web search is activated).
Categories of data subjects: users of the Controller (employees); where applicable, third parties named in content/search data (e.g., clients, patients, customers, business partners of the Controller) – depending on the Controller’s inputs.
Special categories (Art. 9 GDPR): only where the Controller inputs such data; this is the responsibility of and on the instruction of the Controller (cf. Section 6).
Duration: for the term of the main agreement; chat/workspace content data 90 days; thereafter deletion/return pursuant to Section 15 and Annex 4.
Place of processing: EU/EEA – hosting Scaleway (France, Paris fr-par); content delivery via Bunny CDN (BunnyWay d.o.o., Slovenia, EU – delivery restricted to EU/EEA locations); AI routing via Cortecs (EU); web search via Linkup (EU). Third-country transfers only pursuant to Section 14.
Annex 2 — Technical and organizational measures (Art. 32 GDPR)
EZTO operates an ISO/IEC 27001-aligned information security management system (ISMS) and is currently undergoing ISO/IEC 27001 certification. The standard evidence package (TOM documentation, security whitepaper, management summary of current penetration tests, standard security questionnaire completed by EZTO) is available for retrieval in the Trust Center. Full penetration-test reports and the completion of customer-specific questionnaires and templates take place only by separate agreement (Enterprise/order form), under confidentiality, and against reasonable remuneration.
1. Confidentiality
- Physical access control: hosting in certified EU data centers (Scaleway); physical security by the infrastructure provider.
- System access control: authentication with multi-factor authentication (MFA) for administrative access; role-based assignment of rights (RBAC) according to the least-privilege principle.
- Data access control: need-to-know, role-based access, access logging; restriction of administrative access.
- Separation control: tenant-separated processing (logical tenant separation).
- No group-wide administrative rights: no group-wide super-admin, no shared emergency access (“break-glass”); administrative and emergency access exclusively for bound EZTO employees, logged and reviewed regularly.
- Separation from the group of companies: the control plane is operated exclusively by EZTO; no shared identity or directory service and no shared administration tooling with other companies of the group; group companies outside the EU/EEA do not participate in providing the service of the EU region and receive no access to content data (Section 14).
- Pseudonymization/minimization: to the extent possible for the purpose.
2. Integrity
- Transfer control: transport encryption (TLS 1.2 or higher) for data in transit.
- Encryption of data/artifacts at rest with AES-256 (at minimum).
- Input control: logging of relevant actions.
3. Availability and resilience
- Data backup (backups) with defined deletion/overwrite cycles (up to 90 days);
- monitoring, incident response process; business continuity/emergency plan.
4. Procedures for regular review, assessment, and evaluation
- ISMS pursuant to ISO/IEC 27001 (undergoing certification); regular penetration tests; vulnerability management; secure software development lifecycle (secure SDLC).
- Order/subprocessor control: careful selection, contractual binding at least equivalently (Art. 28 (4) GDPR), flow-down.
5. Key management: provider-managed keys; “Bring Your Own Key” (BYOK) is not currently offered. Key generation, storage and management take place exclusively in the EU/EEA; no keys, credentials or data are placed in escrow with any company of the group, and no access to key material from outside the EU/EEA is configured.
Annex 3 — Subprocessors
This Annex reflects the status at the time of contract conclusion (the “last updated” date of this DPA); changes are made exclusively in accordance with the procedure under Section 12. The current version is published in the Trust Center (zentre.ai/trust-center); previous versions are available in the Trust Center with their date. The following are engaged in particular:
| Provider | Purpose | Location/Country | Transfers |
|---|---|---|---|
| Scaleway (Scaleway SAS) | Hosting/infrastructure | EU (France, Paris fr-par) | n/a (EU) |
| Bunny (BunnyWay d.o.o.) | CDN/content delivery (EU delivery) | EU (Slovenia) | n/a (EU, EU delivery regions) |
| Cortecs (Cortecs GmbH) | AI gateway/routing (EU routing, ZDR) | EU (Austria) | none (EU endpoints in both model classes, Section 13) |
| Linkup (Linkup Technologies SAS) | Web search (where activated; ZDR) | EU (France) | n/a (EU) |
| Infomaniak (Infomaniak Network SA) | Transactional emails | Switzerland/EU | adequacy decision (CH) |
| Stripe (Stripe Payments Europe Ltd., Ireland) | Billing/payment (predominantly controller context under Section 2; processing on behalf only for product-related usage and billing data) | EU (Ireland); transfer to Stripe, Inc. (USA) as its sub-processor possible | EU-US DPF / SCC |
| Friendly Captcha (Friendly Captcha GmbH) | Bot/abuse protection (signup and login pages; cookieless, hashed IP) | EU (Germany) | n/a (EU) |
| Usercentrics (Usercentrics GmbH) | Consent management (website; controller context, informational only) | EU (Germany) | n/a (EU) |
| Plausible (Plausible Insights OÜ) | Analytics (website; controller context, informational only) | EU | n/a (EU) |
The operators of the model endpoints are integrated via the Cortecs gateway as its subprocessors (decisive: Cortecs subprocessor list). The subprocessor list in the Trust Center identifies, for each endpoint, the model class (“EU-hosted” or “EU-sovereign”) and the operator; this also applies to endpoints for image generation. Changes are announced at least 14 days in advance (Section 12); for Section 203 mode, Section 20 applies.
Annex 4 — Retention and deletion
- Chat/workspace content data: 90 days by default (uniform); differing per the Controller’s product-side retention configuration or by separate agreement (e.g., Enterprise/Private Cloud) — in each case a documented instruction (Sections 5, 13). After expiry, deletion or irreversible removal.
- Backups: technical deletion/overwrite cycles typically up to 90 days; no productive use.
- Metadata/security logs: only as long as necessary (security, abuse prevention, incident analysis); potentially longer in the event of legal claims/statutory obligations.
- Web search queries: no permanent storage by EZTO.
- After contract termination: export in a commonly used, machine-readable format; requests are possible for at least 30 days. Deletion after expiry of the retrieval period — no earlier than day 31 and not before complete provision of an export requested in time — pursuant to Section 15.