Data Processing Agreement

Controller–processor terms for Captain Relay business customers.

Operated by ZEBRABYTE LIMITED · Registered in England and Wales · Company 15194067 · ICO registration ZB748706 · Registered office: Suite 7165a, 60 Tottenham Court Road, Fitzrovia, London, United Kingdom, W1T 2EW · Last updated: 23 September 2026

1. Scope

This DPA forms part of the agreement between a business customer (“Controller”) and ZEBRABYTE LIMITED (“Processor”) where ZEBRABYTE LIMITED processes personal data on the customer's documented instructions in providing Captain Relay. If the customer itself acts as processor for another controller, ZEBRABYTE LIMITED may act as sub-processor to the extent applicable.

2. Subject matter and duration

The subject matter is the provision, operation, security and support of Captain Relay. Processing continues for the service term plus the limited period required for deletion, backup expiry, security, legal obligations and dispute handling.

3. Nature and purpose

Processing may include collection, transmission, storage, retrieval, organisation, remote execution-related processing, OAuth/connected-account management, managed app tool execution and event routing, access control, logging, support, security monitoring, deletion and return of data as required to provide Captain Relay under the customer's documented instructions.

4. Categories of data and data subjects

Data may include account identifiers, device metadata, remote action inputs and outputs, screen content where explicitly invoked, managed-app connected-account identifiers, authorised app inputs/results/events, files or application content accessed by an authorised tool, policy and approval records, audit data and support information. Data subjects may include customer users and other people whose information is present in customer-controlled systems.

5. Processor obligations

ZEBRABYTE LIMITED will:

6. Security measures

Measures may include authenticated access, account/device ownership controls, server-enforced execution policies, human approvals, revocation, tenant-scoped data access, security logging, secure development practices, vulnerability management, encryption where appropriate and risk-based retention.

7. Subprocessors

The Controller provides general authorisation for the subprocessors listed at Subprocessors. ZEBRABYTE LIMITED will impose appropriate data-protection obligations on subprocessors and will handle material subprocessor changes in accordance with the applicable customer agreement. Managed Apps may use managed integration infrastructure to maintain connection state and route authorised tool calls or events; customer-selected destination applications remain subject to the customer's separate relationship with those providers.

8. International transfers

ZEBRABYTE LIMITED will use an appropriate lawful transfer mechanism for restricted international transfers where required and will implement supplementary safeguards where appropriate.

9. Controller obligations

The Controller is responsible for ensuring that its instructions are lawful, it has authority over enrolled systems and data, it provides required privacy information to data subjects, and it configures Captain Relay access and policies appropriately.

10. Audit and information

On reasonable request, ZEBRABYTE LIMITED will provide information necessary to demonstrate compliance with applicable processor obligations. Audits should first rely on available documentation, technical evidence and reports and must be conducted in a way that protects the security and confidentiality of other customers and the service.

11. Conflict

If this DPA conflicts with the main agreement on processing of Customer Personal Data, this DPA prevails for that subject unless a signed agreement expressly states otherwise.

12. Contact

Privacy and legal enquiries: legal@zebrabyte.co.uk.