ZyeneLegalData Processing Agreement

Data Processing Agreement

How Zyene processes customer operational data, and which subprocessors we use.

This Data Processing Agreement (“DPA”) describes how Zyene processes personal and operational data when a customer uses our website or engages us to design, build, or run a production workflow. It is intended for IT and legal review. It sits alongside our Privacy Policy and Terms & Conditions.

1. Roles

For the zyene.com website, Zyene is the controller of contact, hiring, and analytics information you submit to us. For a client engagement, the customer is the controller of the operational data in that workflow. Zyene is a processor of that data, acting on the customer’s documented instructions.

2. What we process in an engagement

A typical workflow reads work that already exists in the customer’s operation: emails, purchase orders, RFQs, bid packets, invoices, drawings, and records in the ERP, CRM, or field software the customer already runs. That data can include names, email addresses, phone numbers, customer and vendor records, order lines, and the documents attached to them.

We process that data to extract, validate, and prepare the next action, and to keep an audit of what the system did. We do not use customer operational data to train public models.

3. Customer instructions

The statement of work, this DPA, and any written security requirements the customer provides are the instructions. We will not process engagement data for our own marketing, sell it, or share it with a third party except as a subprocessor listed here or as required by law.

4. Subprocessors

We use the following providers to operate the website and, where an engagement requires it, to run a workflow. The statement of work names the model provider when one is in use.

  • Vercel — hosts and deploys zyene.com.
  • Cloudflare — DNS and SSL for zyene.com. Cloudflare Turnstile also protects our forms from automated abuse.
  • Zoho — stores contact-form and talent-pool submissions from this website.
  • Model providers — language and document models used inside a client workflow, chosen for that engagement. The customer’s statement of work names the provider when it is in use.

Website forms may also use Web3Forms (email routing), Abstract API (email validation), and Cal.com (scheduling), as described in the Privacy Policy. Stripe is used when an engagement or product subscription is billed.

We will update this page when a subprocessor is added or removed. Material changes to how engagement data is processed are agreed in writing before they apply to an existing customer.

5. Security

Transmission to zyene.com uses HTTPS. Access to customer data is limited to people working on that engagement. Critical writes to a customer’s ERP or CRM can require an employee of the customer to approve. We log important actions so they can be reviewed. Deployment (our cloud, the customer’s cloud, or a more private setup) is scoped per project. See Security.

6. Location, retention, and deletion

Zyene operates from the United States. Subprocessors may process data in the United States or other regions where they operate. Retention for a client engagement follows the statement of work. When the engagement ends, we delete or return the customer’s operational data according to those terms, except where we must keep a record for law or dispute.

7. Customer rights and our help

If a person whose data is in a customer workflow exercises a privacy right, the customer is responsible for the response. We will assist with information we hold, within a reasonable time, so the customer can reply.

8. Agreement

By signing a Zyene statement of work that incorporates this DPA, or by otherwise agreeing in writing, the customer and Zyene agree to these terms for that engagement. Questions: legal@zyene.com. Privacy requests: privacy@zyene.com.

Last updated: October 2, 2026.