Data Processing Agreement
Last Updated: July 27, 2026
This Data Processing Agreement (“DPA”) forms part of the Customer Agreement between Zyphra Technologies, Inc (“Zyphra”) and Customer. In the event of a conflict between this DPA and the Agreement, this DPA will control to the extent of such conflict.
Definitions
Capitalized terms used but not defined in this DPA will have the meanings given to them in the Agreement. In this DPA:
1.1
"Business," "Controller," "Customer Personal Data Breach," "Processing," and "Supervisory Authority" shall have the meanings defined in Data Protection Law.
1.2
"Customer Personal Data" means Customer Data that constitutes Customer Personal Data Processed by Zyphra has a Processor on behalf of Customer or Third-Party Controller pursuant to the Agreement.
1.3
"Data Protection Law" means privacy and data protection laws applicable to Zyphra's Processing of Customer Personal Data, including, as applicable, the General Data Protection Regulation (EU) 2016/679 ("GDPR") and the e-Privacy Directive 2002/58/EC (as amended by Directive 2009/136/EC), their national implementations in the European Economic Area ("EEA"), the United Kingdom ("UK") General Data Protection Regulation, the UK Data Protection Act 2018, the Swiss Federal Act on Data Protection, and the California Consumer Privacy Act, as amended by the California Privacy Rights Act ("CCPA").
1.4
"Data Subject" means a "data subject" or "consumer" as those terms are defined in Data Protection Law.
1.5
"Data Subject Rights" means Data Subjects' rights under Data Protection Law.
1.6
"Customer Personal Data" means "Customer Personal Data," "personal information," or any equivalent term under applicable Data Protection Law.
1.7
"Processor" means "Processor" or "Service Provider" as those terms are defined in Data Protection Law.
1.8
"Sale" has the meaning defined in the CCPA.
1.9
"Services" has the meaning defined in the Agreement.
1.10
"Share" has the meaning defined in the CCPA.
1.11
"Subprocessor" means a Processor engaged by Zyphra to Process Customer Personal Data.
1.12
"SCCs" means the clauses annexed to the EU Commission Implementing Decision 2021/914 of June 4, 2021 on standard contractual clauses for the transfer of Customer Personal Data to third countries pursuant to Regulation (EU) 2016/679 of the European Parliament and of the Council as amended or replaced from time to time.
1.13
"Third-Party Controller" means a Controller for which Customer is a Processor.
1.14
"UK Addendum" means the addendum to the SCCs issued by the UK Information Commissioner under Section 119A(1) of the UK Data Protection Act 2018 (version B1.0, in force March 21, 2022).
Scope
2.1
The subject matter, nature and purpose of the Processing, the types of Customer Personal Data, and categories of Data Subjects are set out in Exhibit A.
2.2
Customer is a Controller and appoints Zyphra as a Processor on behalf of Customer. Customer is responsible for compliance with the requirements of Data Protection Law applicable to Businesses or Controllers.
2.3
If Customer is a Processor on behalf of a Third-Party Controller, then Customer (a) is the single point of contact for Zyphra, (b) must obtain all necessary authorizations from such Third-Party Controller, and (c) will issue all instructions and exercise all rights on behalf of such other Third-Party Controller.
2.4
Customer acknowledges that Zyphra may Process Customer Personal Data relating to the operation, support, or use of the Services for its own business purposes, such as billing, account management, data analysis, benchmarking, technical support, product development, and compliance with law. Zyphra is the Controller for such Processing.
2.5
Zyphra and Customer shall comply with the obligations of, and provide the level of privacy protection required by, Data Protection Law.
3. Instructions
3.1
Zyphra will Process Customer Personal Data to provide the Services and in accordance with Customer's documented instructions.
3.2
Customer's instructions are documented in this DPA, the Agreement, and any applicable Order Form.
3.3
Customer may reasonably issue additional instructions as necessary to comply with Data Protection Law. Zyphra may charge a reasonable fee to comply with any such additional instructions.
3.4
Zyphra is prohibited from (a) Selling or Sharing Customer Personal Data, (b) retaining, using, or disclosing Customer Personal Data for any purpose other than Customer's instructions, (c) retaining, using, or disclosing Customer Personal Data outside of the direct business relationship between Customer and Zyphra, and (d) combining Customer Personal Data with Customer Personal Data obtained from, or on behalf of, sources other than Customer, except as permitted under applicable Data Protection Law.
3.5
Unless prohibited by applicable law, Zyphra will inform Customer if Zyphra is subject to a legal obligation that requires Zyphra to Process Customer Personal Data in contravention of Customer's documented instructions.
4. Personnel
4.1
Zyphra will take steps to ensure that all personnel authorized by Zyphra to Process Customer Personal Data are subject to a contractual or statutory obligation of confidentiality.
5. Security and Customer Personal Data Breaches
5.1
Zyphra will implement appropriate technical and organizational measures to ensure a level of security appropriate to the risk of its Processing of Customer Personal Data.
5.2
Customer acknowledges that Zyphra's security measures are appropriate in relation to the risks associated with Customer's intended Processing and will notify Zyphra prior to any intended Processing for which Zyphra's security measures may not be appropriate.
5.3
Zyphra will notify Customer without undue delay after becoming aware of a Customer Personal Data Breach involving Customer Personal Data and will take reasonable steps designed to investigate and mitigate such Customer Personal Data Breach.
6. Subprocessing
6.1
Customer hereby authorizes Zyphra to engage Subprocessors. Zyphra's Subprocessors as of the Effective Date consists of: the Subprocessors identified at zyphra.com/legal/subprocessors.
6.2
Zyphra will enter into a written agreement with Subprocessors that complies with Data Protection Law.
6.3
Zyphra will notify Customer prior to any intended change to Subprocessors. Customer may object to the addition of a Subprocessor based on reasonable grounds relating to a potential or actual violation of Data Protection Law by providing written notice detailing the grounds of such objection within thirty (30) days following Zyphra's notification of the intended change. Customer and Zyphra will work together in good faith to address any such objection.
7. Assistance
7.1
Taking into account the nature of the Processing, and the information available to Zyphra, Zyphra will provide commercially reasonable assistance to Customer to fulfill Customer's obligations under Data Protection Law.
7.2
Zyphra may charge a reasonable fee for assistance under this Section 7.
7.3
Upon receiving notice from Zyphra that it is unable to comply with Data Protection Law or this DPA, Customer may direct Zyphra to take reasonable and appropriate steps to stop and remediate unauthorized Processing of Customer Personal Data.
8. Audit
8.1
Upon reasonable advice notice, Zyphra shall make available to Customer information reasonably designed to demonstrate Zyphra's compliance with the obligations of this DPA and allow for and contribute to audits, including inspections, to the extent mandated by a Supervisory Authority. The foregoing shall only extend to those documents and facilities relevant and material to Zyphra's Processing of Customer Personal Data and shall be conducted during normal business hours, in a manner that causes minimal disruption, and in accordance with mutually agreed upon scope and terms.
8.2
As between Customer and Zyphra, Customer will bear all the costs related to any audit.
9. International Data Transfers
9.1
Customer hereby authorizes Zyphra to perform International Data Transfers to any country deemed to have an adequate level of data protection by the European Commission or the applicable competent regulatory authority, on the basis of adequate safeguards in accordance with Data Protection Law or pursuant to the SCCs and the UK Addendum referred to in Section 9.2 and Section 9.3.
9.2
Zyphra and Customer conclude Module 2 (controller-to-processor) of the SCCs and, to the extent Customer is a Processor on behalf of a Third-Party Controller, Module 3 (Processor-to-Subprocessor) of the SCCs, which are hereby incorporated and completed as follows: the "data exporter" is Customer; the "data importer" is Zyphra; the optional docking clause in Clause 7 is implemented; Option 2 of Clause 9(a) is implemented and the time period therein is specified in Section 6.3 above; the optional redress clause in Clause 11(a) is struck; Option 1 in Clause 17 is implemented and the governing law is the law of Ireland the courts in Clause 18(b) are the Courts of Dublin, Ireland. Annex A and Annex AI to Module 2 and 3 of the SCCs are Exhibit A and the Subprocessors list respectively. For International Data Transfers from Switzerland, Data Subjects who have their habitual residence in Switzerland may bring claims under the SCCs before the courts of Switzerland.
9.3
Zyphra and Customer conclude the UK Addendum, which is hereby incorporated and applies to International Data Transfers outside the UK. Part 1 of the UK Addendum is completed as follows: (a) in Table 1, the "Exporter" is Customer and the "Importer" is Zyphra, their details are set forth in this DPA, and the Agreement; (b) in Table 2, the first option is selected and the "Approved EU SCCs" are the SCCs referred to in Section 9.2 of this DPA; (c) in Table 3, Annexes 1 (A and B) and II to the "Approved EU SCCs" are Exhibit A and the Subprocessors list respectively; and (d) in Table 4, both the "Importer" and the "Exporter" can terminate the UK Addendum.
10. Notifications
10.1
Customer will send all notifications, requests and instructions under this DPA to Zyphra via email to privacy@zyphra.com.
10.2
Zyphra will send all notifications under this DPA to Customer's supplied contact.
11. Liability
11.1
Zyphra's and its affiliates' liability shall be subject to the limitations of liability set forth in the Agreement.
12. General
12.1
This DPA is terminated upon the termination of the Agreement. Zyphra will return or destroy Customer Personal Data upon termination of the Agreement. Notwithstanding the foregoing, Zyphra may retain copies of Customer Personal Data if required by applicable law or in Zyphra's standard backups provided that such Customer Personal Data remains subject to the confidentiality restrictions of the Agreement and the protections of this DPA.
12.2
This DPA is governed by the laws of Ireland. Any disputes relating to this DPA will be subject to the exclusive jurisdiction of the courts of Dublin, Ireland.
Exhibit A — Definitions
List of Parties
Data exporter:
Name: Customer
Activities relevant to the data transferred under these Clauses: Customer receives the Services as described in the Agreement and Customer provides Customer Personal Data to Zyphra in that context.
Role (controller/processor): Controller
Data importer:
Name: Zyphra
Activities relevant to the data transferred under these Clauses: Zyphra provides the Services to Customer as described in the Agreement and Processes Customer Personal Data on behalf of Customer in that context.
Role (controller/processor): Processor on behalf of Customer
B. Categories of Data Subjects Whose Customer Personal Data Is Transferred
Determined by Customer in accordance with the Agreement.
C. Categories of Customer Personal Data Transferred
Determined by Customer in accordance with the Agreement.
D. Sensitive Data Transferred (If Applicable)
Sensitive data transferred (if applicable) and applied restrictions or safeguards that fully take into consideration the nature of the data and the risks involved, such as for instance strict purpose limitation, access restrictions (including access only for staff having followed specialized training), keeping a record of access to the data, restrictions for onward transfers or additional security measures: None
E. Frequency of the Transfer
The frequency of the International Data Transfer (e.g. whether the Customer Personal Data is transferred on a one-off or continuous basis): On a continuous basis.
F. Nature of the Processing
To provide the Services to Customer pursuant to the Agreement and as may be further agreed upon between Customer and Zyphra.
G. Purpose(s) of the International Data Transfer and Further Processing
To provide the Services to Customer pursuant to the Agreement and as may be further agreed upon between Customer and Zyphra.
H. Duration of Processing
The period for which the Customer Personal Data will be retained, or, if that is not possible, the criteria used to determine that period: Customer Personal Data will be retained for as long as necessary taking into account the purpose of the Processing, and in compliance with applicable laws, including laws on the statute of limitations and Data Protection Law.
I. Sub-Processor Transfers
For International Data Transfer to (Sub)Processors, also specify subject matter, nature and duration of the Processing: For the subject matter and nature of the Processing, reference is made to the Agreement and this DPA. The Processing will take place for the duration of the Agreement.
J. Competent Supervisory Authority
The competent authority for the Processing of Customer Personal Data relating to Data Subjects located in the EEA is the Supervisory Authority of Ireland.
The competent authority for the Processing of Customer Personal Data relating to Data Subjects located in the UK is the UK Information Commissioner.
The competent authority for the Processing of Customer Personal Data relating to Data Subjects located in Switzerland is the Swiss Federal Data Protection and Information Commissioner.
K. Technical and Organizational Measures
Zyphra will implement security safeguards designed to protect the security, confidentiality and integrity of Customer Personal Data.