Skip to content
iNTELIGENCIA VIVA
  • Home
  • Product
  • Pricing
  • Downloads
  • Developers
  • Resources
  • About
  • Legal
  • Contact
  • Sign in
Sign in
EN
  • Español
  • Português
  • Français
  • Deutsch
  • Italiano
  • 日本語
  • العربية
Start free

← Back to Legal

Data Processing Agreement (DPA)

Draft — pending external legal review. This document sets out the product requirements and decisions that the final text must reflect; it has not been reviewed by a lawyer. It does not constitute legal advice and is not a publishable final version.

Last updated: [EFFECTIVE DATE]

1. Purpose

This Data Processing Agreement ("DPA") supplements the Terms of Service entered into between ZARZA CORP, S.A. ("the Processor", "we", "us") and the Workspace that subscribes to a paid plan of iNTELIGENCIA VIVA ("the Controller", "the Customer"). It applies only to paid plans (Pro, Business, Enterprise), under which we process personal data of the Customer's Contacts on its behalf. It does not apply to the free Directory or the free WordPress Plugin, which never send data to our infrastructure.

If this DPA conflicts with the Terms of Service regarding the processing of personal data, this DPA prevails.

2. Definitions

  • Personal Data: any information relating to an identified or identifiable natural person that the Customer or its Contacts enter into the Service.
  • Controller: the Customer, with respect to the Personal Data of its Contacts and its own Agents.
  • Processor: us, with respect to that same Personal Data, which we process solely to provide the contracted Service.
  • Data Subject: the natural person to whom the Personal Data relates — typically a Contact, and in some cases a Customer Agent.
  • Sub-processor: a third party we engage to process Personal Data on our behalf, under Section 6.
  • Security Incident: any security breach leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, Personal Data.

3. Duration

This DPA takes effect on the date the Customer accepts the Terms of Service and remains in effect for as long as the Customer maintains a Workspace on a paid plan, and during the subsequent retention period described in Section 10.

4. Nature, purpose, duration, and categories of processing

Nature and purpose. We process Personal Data to provide the customer-conversation platform: receiving and routing messages, generating AI responses, handing off to human Agents, running semantic search over the Customer's knowledge sources, aggregate analytics, and billing for usage.

Duration. For as long as the paid plan agreement lasts, plus the retention period configured by the Customer under Section 10.

Categories of Data Subjects. The Customer's Contacts (its end customers) and, where relevant, the Customer's Agents.

Categories of Personal Data. Contact identifiers depending on the originating channel (phone number, username, email address), name, the content of exchanged messages, conversation metadata (channel, timestamp, department, AI-generated summary, tags), and any additional data the Data Subject voluntarily includes in their messages.

5. Processor obligations

As Processor, we commit to:

  1. Process Personal Data only on the Customer's documented instructions, as expressed through its configuration of the Service and these Terms, unless required otherwise by law — in which case, where the law permits, we will inform the Customer of that legal requirement before processing.
  2. Ensure that persons authorized to process the Personal Data are bound by a confidentiality commitment.
  3. Implement the technical and organizational measures described in Section 8, aligned with our product documentation's security requirements: encryption in transit and at rest, revocable-scope API keys, HMAC-signed outbound webhooks, and per-Workspace data isolation across every storage layer.
  4. Not transfer Personal Data to a Sub-processor without complying with Section 6.
  5. Assist the Customer as set out in Section 7.
  6. Notify the Customer without undue delay of a Security Incident affecting its Personal Data, under Section 9.
  7. At the Customer's choice, delete or return the Personal Data at the end of the relationship, under Section 10.
  8. Make available to the Customer information reasonably necessary to demonstrate compliance with this DPA, under Section 11.

6. Sub-processors

The Customer generally authorizes the use of Sub-processors to provide the Service. As of this document's date, current Sub-processors are:

Sub-processorFunction
Cloudflare, Inc.Compute infrastructure, database (D1), file storage (R2), and vector storage for semantic search (Vectorize), Durable Objects for real-time conversations.
Payment service provider(s) selected by Zarza Corp, S.A.Payment processing. Zarza Corp, S.A. may add or change payment service providers without amending this table.
Transactional email delivery provider (configurable; Resend by default)Sending the Service's transactional emails.
Frontier AI model providers (per the model router's configuration)Generating AI responses when the router routes a request outside Workers AI.

We will keep an up-to-date list of Sub-processors published or available on request. We will notify the Customer with reasonable advance notice before adding a new Sub-processor that processes Personal Data, so the Customer may object on reasonable data-protection grounds; if the objection is not resolved, the Customer may terminate the affected paid plan without additional penalty on that specific ground.

We remain responsible for our Sub-processors' compliance with data-protection obligations to the same extent we are ourselves responsible under this DPA.

7. Assistance to the Controller

We will reasonably assist the Customer to: (i) respond to Data Subjects exercising their rights of access, rectification, erasure, portability, or objection; (ii) carry out data protection impact assessments where the processing requires it; and (iii) consult in advance with the competent supervisory authority when an assessment indicates a high risk. When a Data Subject contacts us directly regarding data we process on the Customer's behalf, we will refer them to the Customer and notify the Customer of the request without undue delay.

8. Security measures

We apply, at a minimum: encryption in transit across all Service surfaces (site, API, WebSocket) and at rest in our databases and file/vector storage; access control based on API keys with configurable permission scope and individual revocation; cryptographic signing (HMAC) of every outbound webhook delivery; logical isolation of each Workspace's data at the query level across every storage layer, so that no Workspace can access another's data; and real (not merely logical) deletion processes once the configured retention period elapses.

9. Security Incident notification

We will notify the Customer without undue delay after confirming a Security Incident affecting Personal Data we process on its behalf, providing reasonably available information about its nature, the categories and approximate number of Data Subjects and records affected, the measures taken or proposed to mitigate it, and a point of contact for further information. This notification does not constitute an admission of liability and is intended solely to allow the Customer to meet its own legal notification obligations.

10. Deletion or return of data

The Customer configures, within the limits offered by the Service, the retention period for its Workspace's conversation data. Once that period elapses, or the contractual relationship ends after any applicable grace period, we will delete Personal Data for real — not through simple soft deletion — from our production systems and corresponding backups according to their own lifecycle, unless the law requires us to retain specific copies, in which case those copies remain subject to this DPA's same confidentiality and security obligations until their deletion. At the Customer's request made before deletion, we will facilitate export of the Personal Data through the public API's mechanisms.

11. Audits

On reasonable request and with adequate confidentiality, we will provide the Customer with information necessary to demonstrate compliance with this DPA, including summaries of third-party audits or security certifications where they exist. A broader audit right, including on-site inspections or inspection by a designated third party, may be agreed specifically for Enterprise plans.

12. Liability

Each party's liability under this DPA is governed by the limit and exclusions set out in the Terms of Service's limitation-of-liability section, except to the extent applicable law makes such limitation unenforceable.

13. Term and amendments to this DPA

We may update this DPA to reflect regulatory or Service changes, notifying the Customer with reasonable advance notice. Changes that materially reduce the safeguards described here will require the Customer's express consent where the law so requires.

14. Contact

Questions regarding this DPA, including requests about Sub-processors or incident notification: legal@inteligenciaviva.com.

iNTELIGENCIA VIVA

The conversation inbox for your business: human agents and AI agents, together.

Product

  • Product
  • Pricing
  • Downloads
  • Developers

Company

  • About
  • Resources
  • Contact

Legal

  • Terms of Service
  • Privacy Policy
  • Data Processing Agreement (DPA)
  • Acceptable Use Policy
  • Developer API Terms
  • Legal Notice for the Free Plugin and Directory

iNTELIGENCIA VIVA is a product built by iNTELIGENCIA VIVA, the agency — a trusted backer, not the star of the show.

The free Directory and the WordPress Plugin are open core, released under the Apache License 2.0.

© 2026 ZARZA CORP, S.A. — All rights reserved.