ZENTRE – Data Processing Agreement (DPA)

English convenience translation. Only the German version (“AVV/DPA”) is legally binding; the English translation is provided for information purposes only. In case of discrepancies, the German version prevails.

Last updated: 15 Jul 2026

Key points at a glance *(non-binding orientation — the contract text prevails):* Your data is processed exclusively in the EU (hosting: Scaleway, Paris) · AI requests are routed via the EU gateway Cortecs, with zero data retention where available · Your content is not used to train AI models · Chats are deleted after 90 days (exportable beforehand) · New subprocessors are announced 14 days in advance and you may object · We notify you of personal data breaches within 48 hours · For professional secrecy holders, Section 20 (Section 203 mode) additionally applies.

Who is who: the “Controller” under this DPA is you — the Customer within the meaning of the GTC. The “Processor” is EZTO.

1. Preamble, parties, order of precedence

2. Roles and delineation (Processor vs. Controller)

3. Definitions

4. Subject matter, nature, purpose, duration

5. Instructions and instruction management

6. Obligations of the Controller

7. Confidentiality

8. Security of processing (Art. 32 GDPR)

9. Hosting and data location (default)

10. Assistance with data subject rights

11. Assistance with compliance (Art. 28 (3) (f) GDPR)

EZTO appropriately assists the Controller with Art. 32–34, 35, 36 GDPR — primarily through the documentation provided in the Trust Center (TOM, data flow document, subprocessor list). Individual assistance beyond this (e.g., completing customer-specific DPIA templates, workshops) is reasonably remunerated in accordance with the main agreement, to the extent permissible.

12. Subprocessors

13. AI providers / AI routing

14. Third-country transfers

15. Deletion and return

16. Personal data breaches

17. Authority requests / disclosure

18. Evidence and audits

19. Documentation

EZTO maintains – to the extent required – a record of processing activities as a processor (Art. 30 (2) GDPR) and provides the Controller upon request with appropriate information/extracts therefrom, to the extent necessary to fulfil the accountability obligation and provided no legitimate confidentiality interests or third-party trade secrets conflict.

20. Involvement in professional secrecy (Section 203 StGB; professional law requirements)

21. Final provisions

Annexes to the DPA

Annex 1 — Description of the processing (Art. 28 (3) GDPR)

Subject matter of the processing: provision and operation of the AI orchestration and governance platform “Zentre” (chat assistant, agents, RAG/knowledge tool) as SaaS.

Nature of the processing: automated collection, recording, storage, display, structuring, transmission (to the AI gateway/AI providers and – where activated – to the search provider), restriction, and deletion.

Purpose: provision of the contractually agreed services, user/access management, support/error analysis, security/abuse prevention/incident handling.

Categories of personal data:

Categories of data subjects: users of the Controller (employees); where applicable, third parties named in content/search data (e.g., clients, patients, customers, business partners of the Controller) – depending on the Controller’s inputs.

Special categories (Art. 9 GDPR): only where the Controller inputs such data; this is the responsibility of and on the instruction of the Controller (cf. Section 6).

Duration: for the term of the main agreement; chat/workspace content data 90 days; thereafter deletion/return pursuant to Section 15 and Annex 4.

Place of processing: EU/EEA – hosting Scaleway (France, Paris fr-par); content delivery via Bunny CDN (BunnyWay d.o.o., Slovenia, EU – delivery restricted to EU/EEA locations); AI routing via Cortecs (EU); web search via Linkup (EU). Third-country transfers only pursuant to Section 14.

Annex 2 — Technical and organizational measures (Art. 32 GDPR)

EZTO operates an ISO/IEC 27001-aligned information security management system (ISMS) and is currently undergoing ISO/IEC 27001 certification. The standard evidence package (TOM documentation, security whitepaper, management summary of current penetration tests, standard security questionnaire completed by EZTO) is available for retrieval in the Trust Center. Full penetration-test reports and the completion of customer-specific questionnaires and templates take place only by separate agreement (Enterprise/order form), under confidentiality, and against reasonable remuneration.

1. Confidentiality

2. Integrity

3. Availability and resilience

4. Procedures for regular review, assessment, and evaluation

5. Key management: provider-managed keys; “Bring Your Own Key” (BYOK) is not currently offered.

Annex 3 — Subprocessors

This Annex reflects the status at the time of contract conclusion (the “last updated” date of this DPA); changes are made exclusively in accordance with the procedure under Section 12. The current version is published in the Trust Center (zentre.ai/trust-center); previous versions are available in the Trust Center with their date. The following are engaged in particular:

| Provider | Purpose | Location/Country | Transfers |

|—|—|—|—|

| Scaleway (Scaleway SAS) | Hosting/infrastructure | EU (France, Paris fr-par) | n/a (EU) |

| Bunny (BunnyWay d.o.o.) | CDN/content delivery (EU delivery) | EU (Slovenia) | n/a (EU, EU delivery regions) |

| Cortecs (Cortecs GmbH) | AI gateway/routing (EU routing, ZDR) | EU (Austria) | generally none; SCC where necessary |

| Linkup (Linkup Technologies SAS) | Web search (where activated; ZDR) | EU (France) | n/a (EU) |

| Infomaniak (Infomaniak Network SA) | Transactional emails | Switzerland/EU | adequacy decision (CH) |

| Stripe (Stripe Payments Europe Ltd., Ireland) | Billing/payment (partly controller context, cf. Section 2) | EU (Ireland); transfer to Stripe, Inc. (USA) as its sub-processor possible | EU-US DPF / SCC |

| Friendly Captcha (Friendly Captcha GmbH) | Bot/abuse protection (signup and login pages; cookieless, hashed IP) | EU (Germany) | n/a (EU) |

| Usercentrics (Usercentrics GmbH) | Consent management (website; controller context, informational only) | EU (Germany) | n/a (EU) |

| Plausible (Plausible Insights OÜ) | Analytics (website; controller context, informational only) | EU | n/a (EU) |

The AI model providers are integrated via the Cortecs gateway as its subprocessors (decisive: Cortecs subprocessor list). Changes are announced at least 14 days in advance (Section 12).

Annex 4 — Retention and deletion