Legal

Data Processing Addendum

Review the data processing terms, roles, subprocessors, and security measures that apply to business and enterprise customers using Zoiko Sema.

1.Overview

This Data Processing Addendum ("DPA") describes the terms that apply when Zoiko Sema processes personal data on behalf of a business or enterprise customer in connection with the Service, supplementing the Terms of Service.

2.Applicability and Roles

This DPA applies where the customer acts as a data controller (or equivalent) and Zoiko Sema acts as a data processor (or equivalent) with respect to personal data processed through the Service.

Final role terminology (controller/processor/business/service provider) to be confirmed by legal counsel based on applicable law.

3.Processing Scope

Zoiko Sema processes personal data only to provide, secure, and support the Service in accordance with the customer's documented instructions and this DPA.

4.Customer Data Categories

Processed data categories may include workspace and account data, communication content, meeting data, AI-generated outputs, support data, usage data, and integration data.

  • Account and workspace configuration data
  • Messages, files, and meeting recordings
  • AI summaries, transcripts, and action items
  • Usage, device, and diagnostic data
  • Support tickets and correspondence
  • Integration and API activity data

5.Processing Purposes and Instructions

Zoiko Sema processes personal data solely to deliver, secure, support, and improve the Service in accordance with the customer's instructions as reflected in the order form and this DPA.

6.Subprocessors

Zoiko Sema engages approved subprocessors to support hosting, security, and operational functions. A current subprocessor list is available on request, and customers will be notified of material changes in accordance with this DPA.

Request the current subprocessor list.View Subprocessors

7.Security Measures

Zoiko Sema maintains technical and organizational security measures described in our Security Policy and available in more detail through the Trust Center.

Review our security program in detail.Read Security Policy

8.International Transfers

Where personal data is transferred internationally, Zoiko Sema relies on appropriate transfer mechanisms as required by applicable law.

Transfer mechanism language (e.g., SCCs) pending confirmation by legal counsel.

9.Data Subject Requests

Zoiko Sema will provide reasonable assistance to customers in responding to verified data subject requests relating to personal data processed through the Service.

Submit or route a data subject request.Submit Privacy Request

10.Return, Deletion, and Retention

Upon termination of the Service or upon customer request, Zoiko Sema will return or delete personal data in accordance with this DPA and applicable retention obligations.

11.Audit and Compliance Review

Zoiko Sema will make available information reasonably necessary to demonstrate compliance with this DPA, subject to confidentiality and security considerations, and may direct requests to existing audit reports where available.

12.DPA Request and Signature Workflow

Business and enterprise customers can request execution of this DPA through our sales or legal team. Requests are reviewed and routed to a signature workflow once commercial context is confirmed.

Request DPA Review — routes to the legal review and e-signature workflow.

13.Changes to This Addendum

We may update this DPA to reflect legal, operational, or security changes. Material changes will be reflected by an updated effective date.

14.Contact Us

Questions about this DPA can be directed to our legal and privacy team using the contact options below.

Ready to execute a DPA for your organization?

Business and enterprise customers can request DPA execution, review subprocessor lists, or discuss data residency and security requirements with our legal and sales teams.

Contact Sales
ZoikoSema Logo