Data Processing Agreement
Controller–processor terms for Captain Relay business customers.
1. Scope
This DPA forms part of the agreement between a business customer (“Controller”) and ZEBRABYTE LIMITED (“Processor”) where ZEBRABYTE LIMITED processes personal data on the customer's documented instructions in providing Captain Relay. If the customer itself acts as processor for another controller, ZEBRABYTE LIMITED may act as sub-processor to the extent applicable.
2. Subject matter and duration
The subject matter is the provision, operation, security and support of Captain Relay. Processing continues for the service term plus the limited period required for deletion, backup expiry, security, legal obligations and dispute handling.
3. Nature and purpose
Processing may include collection, transmission, storage, retrieval, organisation, remote execution-related processing, OAuth/connected-account management, managed app tool execution and event routing, access control, logging, support, security monitoring, deletion and return of data as required to provide Captain Relay under the customer's documented instructions.
4. Categories of data and data subjects
Data may include account identifiers, device metadata, remote action inputs and outputs, screen content where explicitly invoked, managed-app connected-account identifiers, authorised app inputs/results/events, files or application content accessed by an authorised tool, policy and approval records, audit data and support information. Data subjects may include customer users and other people whose information is present in customer-controlled systems.
5. Processor obligations
ZEBRABYTE LIMITED will:
- process personal data only on documented instructions unless applicable law requires otherwise;
- ensure authorised personnel are subject to appropriate confidentiality obligations;
- implement appropriate technical and organisational security measures;
- assist the Controller with data-subject rights requests where required and reasonably possible;
- assist with security, personal-data breach and DPIA obligations where required;
- notify the Controller of a personal-data breach affecting Customer Personal Data without undue delay in accordance with the applicable agreement and law;
- maintain records required by applicable data-protection law;
- at the end of the service, delete or return Customer Personal Data as required by the agreement, subject to lawful retention;
- make reasonable compliance information available and support audits as required by law and the applicable agreement.
6. Security measures
Measures may include authenticated access, account/device ownership controls, server-enforced execution policies, human approvals, revocation, tenant-scoped data access, security logging, secure development practices, vulnerability management, encryption where appropriate and risk-based retention.
7. Subprocessors
The Controller provides general authorisation for the subprocessors listed at Subprocessors. ZEBRABYTE LIMITED will impose appropriate data-protection obligations on subprocessors and will handle material subprocessor changes in accordance with the applicable customer agreement. Managed Apps may use managed integration infrastructure to maintain connection state and route authorised tool calls or events; customer-selected destination applications remain subject to the customer's separate relationship with those providers.
8. International transfers
ZEBRABYTE LIMITED will use an appropriate lawful transfer mechanism for restricted international transfers where required and will implement supplementary safeguards where appropriate.
9. Controller obligations
The Controller is responsible for ensuring that its instructions are lawful, it has authority over enrolled systems and data, it provides required privacy information to data subjects, and it configures Captain Relay access and policies appropriately.
10. Audit and information
On reasonable request, ZEBRABYTE LIMITED will provide information necessary to demonstrate compliance with applicable processor obligations. Audits should first rely on available documentation, technical evidence and reports and must be conducted in a way that protects the security and confidentiality of other customers and the service.
11. Conflict
If this DPA conflicts with the main agreement on processing of Customer Personal Data, this DPA prevails for that subject unless a signed agreement expressly states otherwise.
12. Contact
Privacy and legal enquiries: legal@zebrabyte.co.uk.