Data Processing Agreement
Last updated: 7 August 2026
This Data Processing Agreement ("DPA") forms part of, and is incorporated into, the Terms of Service between Ascendz Digital Limited, operated by Toni Martin ("Zenitro", "we", "us", "our"), and the Subscriber ("you", "Subscriber") who registers for and uses the Zenitro platform at app.zenitro.co. It governs the processing of personal data carried out by Zenitro on the Subscriber's behalf when the Subscriber uses the Service.
Where this DPA conflicts with the Terms of Service on the subject of personal data processing, this DPA prevails.
1. Parties and Roles
Zenitro is an AI business diagnostics platform that allows businesses to build, publish and share diagnostics, quizzes and assessments, which their own audiences ("respondents") complete to receive a personalised, AI-generated result.
In respect of the personal data of the Subscriber's respondents that flows through the Subscriber's diagnostics, the roles of the parties are:
- The Subscriber is the data controller. The Subscriber determines the purposes and means of processing respondent personal data, is responsible for having a lawful basis to collect it, and is responsible for providing respondents with an appropriate privacy notice.
- Zenitro is the data processor. Zenitro processes respondent personal data only on the Subscriber's documented instructions in order to provide the Service.
This DPA does not apply to personal data for which Zenitro is itself the controller (for example, the Subscriber's own account, login and billing data). That data is governed by the Zenitro Privacy Policy.
2. Subject Matter, Duration, Nature and Purpose
- Subject matter: the processing of respondent personal data collected through the Subscriber's diagnostics on the Zenitro platform.
- Duration: for the term of the Subscriber's subscription, and for the limited period afterwards described in Section 9 (Deletion or Return of Data).
- Nature and purpose: to provide the Service, namely to collect respondent answers, calculate scores and results, generate AI-powered reports, store those results and reports, and make analytics and lead data available to the Subscriber, all on the Subscriber's documented instructions.
The Subscriber's documented instructions are set out in this DPA, the Terms of Service, and the configuration choices and actions the Subscriber takes within the platform (for example, building a diagnostic, choosing an AI model, enabling lead capture, or requesting deletion). If Zenitro is required by law to process respondent personal data other than on the Subscriber's instructions, we will inform the Subscriber of that legal requirement before processing, unless the law prohibits us from doing so.
3. Types of Personal Data and Categories of Data Subjects
Categories of data subjects: the Subscriber's respondents, being the individuals who complete the Subscriber's diagnostics.
Types of personal data:
- Respondent answers to diagnostic questions, including multiple-choice selections, ratings and any free-text responses the respondent enters.
- Scores, results and the AI-generated report calculated from those answers.
- Lead capture details collected by the diagnostic, such as the respondent's name and email address.
- Associated metadata such as timestamps and the campaign or link source of the response.
The Subscriber must not configure its diagnostics to collect special category personal data (as defined by UK GDPR) unless it has ensured an appropriate lawful basis and condition for doing so, and must not use the Service to process personal data of children.
4. Processor Obligations
Zenitro shall:
- Process respondent personal data only on the Subscriber's documented instructions, including with regard to international transfers, unless required to do otherwise by law.
- Ensure that persons authorised to process respondent personal data are bound by an appropriate duty of confidentiality.
- Implement the technical and organisational security measures described in Section 5.
- Respect the conditions in Section 6 for engaging sub-processors.
- Taking into account the nature of the processing, assist the Subscriber by appropriate technical and organisational measures, insofar as possible, in fulfilling the Subscriber's obligation to respond to respondent requests to exercise their rights (Section 7).
- Assist the Subscriber in ensuring compliance with its obligations regarding security, breach notification, data protection impact assessments and prior consultation with a supervisory authority, taking into account the nature of processing and the information available to Zenitro.
- Make available to the Subscriber the information necessary to demonstrate compliance with this DPA, and allow for and contribute to audits as described in Section 10.
- Immediately inform the Subscriber if, in Zenitro's opinion, an instruction infringes UK GDPR or other applicable data protection law.
5. Security Measures
Zenitro implements industry-standard technical and organisational measures to protect respondent personal data, including:
- Encrypted data transmission using TLS/HTTPS.
- Passwords stored only in hashed form via our managed authentication provider.
- Token-based authentication for access to the platform.
- Strict per-account data isolation enforced by database row-level security, so that one Subscriber's data cannot be accessed from another Subscriber's account.
- Encryption at rest of any AI provider API keys the Subscriber supplies, using AES-256-GCM.
- Standard browser security headers, including HTTP Strict Transport Security and an enforced Content Security Policy.
- Role-based access within a Subscriber's account, enforced in the database rather than only in the interface.
- Access to an individual respondent's result via a random, expiring, single-purpose link token rather than a permanent identifier. No such token is issued where the Subscriber has chosen to withhold individual results.
Zenitro conducts regular security reviews. No system is completely secure, and these measures are assessed against the risk of the processing and the state of the art.
6. Sub-processors
The Subscriber provides a general authorisation for Zenitro to engage the sub-processors listed below to process respondent personal data in connection with the Service. Zenitro imposes data protection obligations on each sub-processor that are no less protective than those in this DPA.
- Supabase: database, file storage, authentication and serverless functions (EU region where available).
- Vercel: hosting for the web application.
- Stripe: payment processing.
- Resend: transactional email delivery. Recipient email address, recipient name where provided, and message content are processed to deliver result emails to respondents and notification emails to the Subscriber. Resend retains message metadata for delivery troubleshooting.
- AI providers (Anthropic, OpenAI, Google, xAI): to generate a respondent's report, the relevant diagnostic content and that respondent's answers, including any free-text responses, are sent to an AI provider. This applies both to Zenitro's managed AI models and to any AI provider key the Subscriber supplies. The AI provider used depends on the model the Subscriber selects.
- OpenAI, for knowledge base indexing and retrieval: text from documents the Subscriber uploads to a diagnostic's knowledge base is sent to OpenAI's embeddings API to be indexed, and a summary of a respondent's answers is sent at report generation time so the relevant passages can be identified. This applies irrespective of the AI provider the Subscriber has selected for report generation, because the capability is provider-specific. Its purpose is data minimisation: it is what allows Zenitro to send an AI provider only the passages relevant to a given respondent rather than the Subscriber's entire knowledge base. OpenAI does not use data submitted through its API to train its models.
- Anthropic, for document text extraction: PDF files uploaded to a diagnostic's knowledge base are sent in full to Anthropic to extract their text, irrespective of the AI provider the Subscriber has selected for report generation, because that capability is Anthropic-specific. Zenitro requests the Subscriber's explicit confirmation before each such upload is sent. Word, PowerPoint, Markdown and plain-text uploads are extracted by Zenitro without involving any AI provider.
Zenitro will inform the Subscriber of any intended addition or replacement of a sub-processor, giving the Subscriber the opportunity to object on reasonable data protection grounds. If the Subscriber reasonably objects and the matter cannot be resolved, the Subscriber may terminate the affected part of the Service.
7. Assistance with Data Subject Requests
Taking into account the nature of the processing, Zenitro will assist the Subscriber by appropriate technical and organisational measures, insofar as this is possible, in responding to requests from respondents to exercise their rights under applicable data protection law, including rights of access, rectification, erasure, restriction, portability and objection. Where a respondent contacts Zenitro directly with such a request, Zenitro will, unless legally required to act otherwise, refer the respondent to the relevant Subscriber and will not respond to the request itself except on the Subscriber's instruction.
8. Personal Data Breach Notification
Zenitro will notify the Subscriber without undue delay after becoming aware of a personal data breach affecting respondent personal data processed on the Subscriber's behalf. The notification will describe, to the extent known, the nature of the breach, the categories and approximate number of data subjects and records concerned, the likely consequences, and the measures taken or proposed to address it. Zenitro will provide reasonable assistance to the Subscriber in meeting the Subscriber's own breach notification obligations to supervisory authorities and affected respondents.
9. Deletion or Return of Data
On termination of the Subscriber's subscription, or at the Subscriber's written request, Zenitro will, at the Subscriber's choice, delete or return the respondent personal data processed on the Subscriber's behalf, and delete existing copies, within 30 days, unless a longer retention period is required by applicable law. Deletion is carried out by a scheduled daily job covering both database records and uploaded files, and Zenitro retains a record that the deletion occurred which contains no personal data. The Subscriber may also request deletion of specific respondent data at any time during the term.
10. Audit and Information Rights
Zenitro will make available to the Subscriber the information reasonably necessary to demonstrate compliance with this DPA, and will allow for and contribute to audits, including inspections, conducted by the Subscriber or an auditor mandated by the Subscriber. To respect the confidentiality and security of other Subscribers, audits will normally be satisfied by Zenitro providing relevant documentation and written responses. Any on-site inspection will be limited to once per year (unless a supervisory authority requires otherwise or a breach has occurred), carried out on reasonable prior notice, during business hours, and in a manner that does not disrupt Zenitro's operations.
11. International Data Transfers
Some sub-processors are located outside the United Kingdom and the European Economic Area, in particular the AI providers (Anthropic, OpenAI, Google and xAI), which are based in the United States. When the Subscriber's diagnostics generate reports, the relevant content, including respondent answers, is transferred to and processed in the United States.
Where personal data is transferred outside the UK, Zenitro relies on appropriate safeguards as required by UK GDPR, which may include the UK International Data Transfer Agreement (IDTA) or the UK Addendum to the EU Standard Contractual Clauses (SCCs), together with the data protection terms offered by each sub-processor. The Subscriber may request further information about the specific safeguards applied by contacting clientsupport@ascendz.co.
12. Liability and Governing Law
The liability of each party under or in connection with this DPA is subject to the limitations and exclusions of liability set out in the Terms of Service.
This DPA is governed by the laws of England and Wales, and any disputes arising out of or in connection with it are subject to the exclusive jurisdiction of the courts of England and Wales.
13. Contact
Ascendz Digital Limited / Toni Martin Email: clientsupport@ascendz.co Platform: app.zenitro.co