Data Processing Agreement (DPA)
1. Purpose and scope
This Data Processing Agreement (“DPA”) supplements the terms applicable to Zyllio Studio (the “Terms”). It applies where Zyllio processes personal data on the Customer's behalf in providing the Platform.
In that case, the Customer is the controller and Zyllio is the processor within the meaning of Regulation (EU) 2016/679 (“GDPR”). This DPA does not apply to processing for which Zyllio acts in its own name, including account, billing, commercial relationship and support management, as described in Zyllio's Privacy Policy.
2. Instructions, purpose and term
Zyllio processes personal data only on the Customer's documented instructions, including for transfers to a third country, unless EU or French law requires otherwise. Zyllio will inform the Customer before such processing unless prohibited by law.
The Customer's initial instructions are those necessary to host, store, display, technically process, back up and make available the projects and applications configured in Zyllio Studio. Additional instructions may be sent to contact@zyllio.com, provided they are lawful, feasible and compatible with the Terms.
Processing begins when the account is opened or the Platform is made available, whichever occurs first, and continues until data is returned or deleted under section 9, unless a legal retention obligation applies.
3. Description of processing
| Item | Description |
|---|---|
| Subject matter | Provision of Zyllio Studio and related services. |
| Nature | Hosting, storage, organisation, consultation, technical transmission, backup, maintenance and deletion under the Customer's instructions. |
| Purpose | Enable the Customer to create, configure, operate and administer its projects and applications. |
| Data subjects | Users, customers, prospects, employees, partners and any other individuals whose data the Customer includes in its projects. |
| Data categories | Account or contact data, content, text, media, business data, technical identifiers, settings, logs and other data imported or generated by the Customer. |
The Customer must not use the Platform to process special categories of data under Article 9 GDPR, criminal-offence data or other data subject to enhanced requirements without Zyllio's prior written agreement and appropriate safeguards.
4. Customer obligations
The Customer warrants that it has a valid legal basis for processing entrusted to Zyllio and provides data subjects with the required information. It remains responsible for the lawfulness of its instructions and content, application configuration and handling of data-subject requests. It must promptly report unlawful instructions and protect account credentials.
5. Confidentiality and security
Zyllio ensures that authorised personnel are subject to an appropriate duty of confidentiality. Zyllio implements appropriate technical and organisational measures, including TLS encryption in transit, access controls, backups, logging and security reviews.
6. Sub-processors
The Customer authorises Zyllio to use the sub-processors necessary to provide the Platform, identified in the up-to-date list of sub-processors. Zyllio imposes data-protection obligations at least equivalent to those in this DPA.
Zyllio will notify the Customer at least 30 days before adding or replacing a sub-processor. The Customer may object on legitimate data-protection grounds during that period by writing to contact@zyllio.com. The parties will seek a reasonable solution; failing that, the Customer may terminate the affected service before the change takes effect, subject to the Terms.
7. Transfers outside the EEA
Data hosted in Zyllio Studio is stored in France with OVHcloud. Zyllio does not transfer that data outside the European Economic Area.
8. Assistance, data-subject rights and data breaches
Taking account of the nature of processing, Zyllio assists the Customer, where possible and through appropriate measures, in responding to data-subject requests. If Zyllio receives such a request directly, it forwards it to the Customer and does not respond on the merits unless instructed or legally required.
Zyllio provides reasonably necessary information to help the Customer meet its obligations regarding security, data-protection impact assessments, prior consultation and personal-data breach notifications. In the event of a breach affecting Customer data, Zyllio notifies the Customer without undue delay after becoming aware of it and provides available information. Zyllio does not notify data subjects or a supervisory authority on the Customer's behalf unless instructed or legally required.
9. End of service
When the service ends, Zyllio deletes or anonymises personal data processed for the Customer and existing copies no later than one month after account closure, unless retention is required by law or the Customer gives a documented contrary instruction. On reasonable request, Zyllio confirms completion of deletion.
10. Information, audits and compliance
Zyllio makes available information reasonably necessary to demonstrate compliance with its Article 28 GDPR obligations. The Customer may request relevant compliance information at contact@zyllio.com.
Where that information does not reasonably enable verification, the Customer may request an audit no more than once every twelve months with at least 30 days' written notice, during business hours and without unduly disrupting Zyllio or compromising the security or confidentiality of other customers. The Customer bears the audit cost and uses an independent auditor bound by confidentiality.
11. Priority and contact
In the event of conflict between this DPA and the Terms, this DPA prevails for processing of personal data on the Customer's behalf. For questions or documented instructions, contact contact@zyllio.com.
Zyllio
SASU — SIREN 994 131 274
24 rue des Fleurs
91470 Limours, France
