Legal

OverviewTerms of ServiceAcceptable Use PolicyAI TermsPrivacy PolicyRefund PolicyData Processing AddendumSub-processorsService Level AgreementCookies StatementData Act Addendum
Trust Center

Bourbon Science Inc.

Data Processing Addendum

Effective date: January 1, 2025 ยท Last updated: September 27, 2026

1. Scope and Roles

This Data Processing Addendum ("DPA") forms part of the Zoko Terms of Service between Bourbon Science Inc., trading as Zoko, and the customer ("you"). It applies where Zoko processes personal data on your behalf in providing the Services, and where that processing is subject to Data Protection Law.

"Data Protection Law" means all laws applicable to the processing of personal data under this DPA, including the EU General Data Protection Regulation (Regulation 2016/679), the UK GDPR and Data Protection Act 2018, the Swiss Federal Act on Data Protection, the Brazilian LGPD, and the California Consumer Privacy Act as amended. Terms such as controller, processor, personal data, processing, data subject, and personal data breach have the meaning given in the EU GDPR.

YOU ARE THE CONTROLLER OF THE PERSONAL DATA OF YOUR END USERS AND YOUR PERSONNEL. ZOKO IS YOUR PROCESSOR IN RESPECT OF THAT DATA. WHERE ZOKO PROCESSES PERSONAL DATA FOR ITS OWN PURPOSES, SUCH AS ACCOUNT ADMINISTRATION, BILLING, SECURITY, AND PRODUCT IMPROVEMENT, ZOKO IS A CONTROLLER AND ITS PRIVACY POLICY APPLIES.

Where you act as a processor for another organisation, for example where you are an Agency acting for a Business Owner, Zoko acts as sub-processor and you confirm you have the authority of that organisation to enter into this DPA.

2. Details of Processing

ItemDetail
Subject matterProvision of the Zoko WhatsApp commerce and messaging platform
DurationThe term of the Terms of Service, plus the retention and deletion periods described in Section 9
Nature and purposeHosting, storage, transmission, retrieval, organisation, analysis, and deletion of personal data in order to deliver messaging, automation, commerce, support, and AI features at your instruction
Categories of data subjectYour end users and customers; your personnel and team members; your agency personnel
Categories of personal dataName, phone number, email address, messaging identifiers and profile data, message content and attachments, conversation metadata, order, cart and catalogue data, tags and segments, consent and opt-out records, and any other data you choose to submit
Special category dataNot permitted. You must not submit special category or sensitive personal data to the Services, and Zoko does not undertake to handle it.

3. Zoko's Obligations

Zoko will:

  • process personal data only on your documented instructions, which comprise the Terms of Service, this DPA, your configuration of the Services, and any support request you raise under Section 2.1 of the Terms of Service, unless required otherwise by law, in which case we will inform you in advance unless the law prohibits it;
  • ensure that personnel authorised to process personal data are bound by confidentiality obligations;
  • implement the technical and organisational measures described in Section 4;
  • assist you, taking into account the nature of the processing and the information available to us, with data subject requests, data protection impact assessments, prior consultation, and breach notification;
  • inform you if, in our opinion, an instruction infringes Data Protection Law;
  • make available the information reasonably necessary to demonstrate compliance with this DPA.

Where Zoko creates de-identified data from Customer Content and uses it to improve the Services and its own models, as described in the Zoko AI Terms, that data is no longer personal data and Zoko acts as a controller in respect of it. Nothing in this DPA prevents that use, and the opt-out in those AI Terms applies.

You are responsible for the lawfulness of the personal data you submit and of your instructions, for having a valid legal basis and any required consent, for providing notices to data subjects, and for the accuracy and quality of your data. Sections 5 and 8 of the Terms of Service set out those obligations in full.

4. Security Measures

Zoko is ISO 27001 v2022 compliant and maintains an information security management system that includes:

  • encryption of personal data in transit and at rest;
  • role-based access control on a least-privilege basis, with multi-factor authentication for administrative access;
  • logging, monitoring, and alerting on access to production systems;
  • network segregation, vulnerability management, and patching;
  • secure development practices and change management;
  • backup and disaster recovery arrangements;
  • personnel screening, confidentiality undertakings, and security training;
  • a documented incident response process.

Current detail is published in our Trust Center at https://zoko.trust.site/. We may update these measures provided the level of protection is not reduced.

5. Sub-processors

You give Zoko general written authorisation to engage sub-processors. Our current sub-processors are listed in the Sub-processor List, which forms part of this DPA.

Zoko imposes on each sub-processor data protection obligations no less protective than those in this DPA, and remains responsible for their performance. We will give at least thirty (30) days' notice before adding or replacing a sub-processor, by updating the list and, where you have subscribed to notifications, by email. You may object on reasonable data protection grounds within that period, in which case we will work with you in good faith to find an alternative; if none is available you may terminate the affected Services and receive a refund of prepaid fees for the unused period.

Platforms you choose to connect, including Meta and Shopify, are not Zoko sub-processors. They are separate controllers or your own processors, and Section 13 of the Terms of Service governs them.

6. International Transfers

Where this DPA involves a restricted transfer of personal data from the European Economic Area, the United Kingdom, or Switzerland, the parties agree that:

  • the European Commission's Standard Contractual Clauses (Decision 2021/914), Module Two (controller to processor) or Module Three (processor to processor) as applicable, are incorporated into this DPA and completed with you as data exporter and Zoko as data importer, with the optional docking clause applying. For the purposes of Clause 17 and Clause 18 of those Clauses only, the governing law and forum are those of Ireland;
  • the UK International Data Transfer Addendum (version B1.0) is incorporated and applies to transfers subject to the UK GDPR;
  • for Swiss transfers, references to the GDPR are read as references to the Swiss FADP and the competent authority is the Swiss Federal Data Protection and Information Commissioner.

Annex I of the Standard Contractual Clauses is populated by Sections 1, 2, and 5 of this DPA, and Annex II by Section 4.

FOR THE AVOIDANCE OF DOUBT, THIS IS NOT AN EXCEPTION TO THE GOVERNING LAW OF THE AGREEMENT. THE AGREEMENT, THIS DPA, AND EVERY DISPUTE BETWEEN THE PARTIES ARE GOVERNED BY THE LAWS OF THE STATE OF DELAWARE, USA, AND ARE SUBJECT TO SECTIONS 23 AND 24 OF THE TERMS OF SERVICE. THE STANDARD CONTRACTUAL CLAUSES CANNOT LAWFULLY BE GOVERNED BY DELAWARE LAW: CLAUSE 17 REQUIRES THE LAW OF AN EU MEMBER STATE THAT ALLOWS THIRD-PARTY BENEFICIARY RIGHTS. THE CHOICE OF IRELAND IS CONFINED TO THE CLAUSES THEMSELVES AND TO CLAIMS BROUGHT UNDER THEM BY AN EU DATA SUBJECT, AND HAS NO EFFECT ON ANY OTHER PART OF THE AGREEMENT.

7. Data Subject Requests

The Services give you tools to access, correct, export, and delete personal data in your Account. You are responsible for responding to data subject requests using them.

If a data subject contacts Zoko directly with a request concerning data we process on your behalf, we will not respond substantively. We will tell them to contact you and, where we can identify you, notify you of the request promptly. Where you cannot fulfil a request using the self-service tools, we will provide reasonable assistance at your cost.

8. Personal Data Breach

Zoko maintains security incident management policies and procedures covering how we handle personal data breaches and other security incidents. On discovery of a personal data breach affecting personal data we process on your behalf, we will promptly investigate it and, to the extent permitted by applicable law, will notify you without undue delay. Notification will be given by email to the Primary Contact on your Account, or by another method agreed with you.

Our notification will describe, so far as the information is available to us at the time and taking into account the stage of our investigation, the nature of the breach, the categories and approximate volume of personal data and data subjects affected, the likely consequences, and the measures taken or proposed to address it. Where we cannot provide all of that information at once, we will provide it in phases as the investigation progresses.

We will provide reasonable assistance with your own notification obligations to regulators and data subjects. Notification is not, and will not be construed as, an admission of fault or liability. You are responsible for deciding whether and how to notify regulators and data subjects, and for breaches arising in your own systems, as set out in Section 2.2 of the Terms of Service.

9. Deletion and Return

On termination, and at your choice, Zoko will delete or return the personal data it processes on your behalf. The export window and assistance described in Section 12 of the Terms of Service apply, and customers in the European Union have the additional rights in the Data Act Addendum. After that period we delete personal data in the ordinary course of operations, except where we are required by law to retain it, in which case we continue to protect it under this DPA.

10. Audit

Zoko will make available the information reasonably necessary to demonstrate compliance with this DPA, ordinarily through our Trust Center documentation, security questionnaire responses, and any third-party certification or report we hold.

Where that is not sufficient to satisfy an audit obligation under Data Protection Law, you may request an audit no more than once in any twelve-month period, on at least thirty (30) days' written notice, during business hours, subject to confidentiality, conducted so as not to disrupt our operations, and at your cost. A regulator with authority over you may audit on the same basis. Additional audits may be carried out following a confirmed personal data breach affecting your data.

11. Liability and Order of Precedence

Each party's liability under this DPA is subject to the limitations and exclusions in Section 21 of the Terms of Service, except to the extent Data Protection Law does not permit that limitation.

This DPA prevails over the Terms of Service to the extent of any conflict about the processing of personal data. The Standard Contractual Clauses prevail over this DPA to the extent of any conflict. In all other respects the Terms of Service prevail.