Legal
OverviewTerms of ServiceAcceptable Use PolicyAI TermsPrivacy PolicyRefund PolicyData Processing AddendumSub-processorsService Level AgreementCookies StatementData Act AddendumTrust CenterBourbon Science Inc.
This Data Processing Addendum ("DPA") forms part of the Zoko Terms of Service between Bourbon Science Inc., trading as Zoko, and the customer ("you"). It applies where Zoko processes personal data on your behalf in providing the Services, and where that processing is subject to Data Protection Law.
"Data Protection Law" means all laws applicable to the processing of personal data under this DPA, including the EU General Data Protection Regulation (Regulation 2016/679), the UK GDPR and Data Protection Act 2018, the Swiss Federal Act on Data Protection, the Brazilian LGPD, and the California Consumer Privacy Act as amended. Terms such as controller, processor, personal data, processing, data subject, and personal data breach have the meaning given in the EU GDPR.
YOU ARE THE CONTROLLER OF THE PERSONAL DATA OF YOUR END USERS AND YOUR PERSONNEL. ZOKO IS YOUR PROCESSOR IN RESPECT OF THAT DATA. WHERE ZOKO PROCESSES PERSONAL DATA FOR ITS OWN PURPOSES, SUCH AS ACCOUNT ADMINISTRATION, BILLING, SECURITY, AND PRODUCT IMPROVEMENT, ZOKO IS A CONTROLLER AND ITS PRIVACY POLICY APPLIES.
Where you act as a processor for another organisation, for example where you are an Agency acting for a Business Owner, Zoko acts as sub-processor and you confirm you have the authority of that organisation to enter into this DPA.
| Item | Detail |
|---|---|
| Subject matter | Provision of the Zoko WhatsApp commerce and messaging platform |
| Duration | The term of the Terms of Service, plus the retention and deletion periods described in Section 9 |
| Nature and purpose | Hosting, storage, transmission, retrieval, organisation, analysis, and deletion of personal data in order to deliver messaging, automation, commerce, support, and AI features at your instruction |
| Categories of data subject | Your end users and customers; your personnel and team members; your agency personnel |
| Categories of personal data | Name, phone number, email address, messaging identifiers and profile data, message content and attachments, conversation metadata, order, cart and catalogue data, tags and segments, consent and opt-out records, and any other data you choose to submit |
| Special category data | Not permitted. You must not submit special category or sensitive personal data to the Services, and Zoko does not undertake to handle it. |
Zoko will:
Where Zoko creates de-identified data from Customer Content and uses it to improve the Services and its own models, as described in the Zoko AI Terms, that data is no longer personal data and Zoko acts as a controller in respect of it. Nothing in this DPA prevents that use, and the opt-out in those AI Terms applies.
You are responsible for the lawfulness of the personal data you submit and of your instructions, for having a valid legal basis and any required consent, for providing notices to data subjects, and for the accuracy and quality of your data. Sections 5 and 8 of the Terms of Service set out those obligations in full.
Zoko is ISO 27001 v2022 compliant and maintains an information security management system that includes:
Current detail is published in our Trust Center at https://zoko.trust.site/. We may update these measures provided the level of protection is not reduced.
You give Zoko general written authorisation to engage sub-processors. Our current sub-processors are listed in the Sub-processor List, which forms part of this DPA.
Zoko imposes on each sub-processor data protection obligations no less protective than those in this DPA, and remains responsible for their performance. We will give at least thirty (30) days' notice before adding or replacing a sub-processor, by updating the list and, where you have subscribed to notifications, by email. You may object on reasonable data protection grounds within that period, in which case we will work with you in good faith to find an alternative; if none is available you may terminate the affected Services and receive a refund of prepaid fees for the unused period.
Platforms you choose to connect, including Meta and Shopify, are not Zoko sub-processors. They are separate controllers or your own processors, and Section 13 of the Terms of Service governs them.
Where this DPA involves a restricted transfer of personal data from the European Economic Area, the United Kingdom, or Switzerland, the parties agree that:
Annex I of the Standard Contractual Clauses is populated by Sections 1, 2, and 5 of this DPA, and Annex II by Section 4.
FOR THE AVOIDANCE OF DOUBT, THIS IS NOT AN EXCEPTION TO THE GOVERNING LAW OF THE AGREEMENT. THE AGREEMENT, THIS DPA, AND EVERY DISPUTE BETWEEN THE PARTIES ARE GOVERNED BY THE LAWS OF THE STATE OF DELAWARE, USA, AND ARE SUBJECT TO SECTIONS 23 AND 24 OF THE TERMS OF SERVICE. THE STANDARD CONTRACTUAL CLAUSES CANNOT LAWFULLY BE GOVERNED BY DELAWARE LAW: CLAUSE 17 REQUIRES THE LAW OF AN EU MEMBER STATE THAT ALLOWS THIRD-PARTY BENEFICIARY RIGHTS. THE CHOICE OF IRELAND IS CONFINED TO THE CLAUSES THEMSELVES AND TO CLAIMS BROUGHT UNDER THEM BY AN EU DATA SUBJECT, AND HAS NO EFFECT ON ANY OTHER PART OF THE AGREEMENT.
The Services give you tools to access, correct, export, and delete personal data in your Account. You are responsible for responding to data subject requests using them.
If a data subject contacts Zoko directly with a request concerning data we process on your behalf, we will not respond substantively. We will tell them to contact you and, where we can identify you, notify you of the request promptly. Where you cannot fulfil a request using the self-service tools, we will provide reasonable assistance at your cost.
Zoko maintains security incident management policies and procedures covering how we handle personal data breaches and other security incidents. On discovery of a personal data breach affecting personal data we process on your behalf, we will promptly investigate it and, to the extent permitted by applicable law, will notify you without undue delay. Notification will be given by email to the Primary Contact on your Account, or by another method agreed with you.
Our notification will describe, so far as the information is available to us at the time and taking into account the stage of our investigation, the nature of the breach, the categories and approximate volume of personal data and data subjects affected, the likely consequences, and the measures taken or proposed to address it. Where we cannot provide all of that information at once, we will provide it in phases as the investigation progresses.
We will provide reasonable assistance with your own notification obligations to regulators and data subjects. Notification is not, and will not be construed as, an admission of fault or liability. You are responsible for deciding whether and how to notify regulators and data subjects, and for breaches arising in your own systems, as set out in Section 2.2 of the Terms of Service.
On termination, and at your choice, Zoko will delete or return the personal data it processes on your behalf. The export window and assistance described in Section 12 of the Terms of Service apply, and customers in the European Union have the additional rights in the Data Act Addendum. After that period we delete personal data in the ordinary course of operations, except where we are required by law to retain it, in which case we continue to protect it under this DPA.
Zoko will make available the information reasonably necessary to demonstrate compliance with this DPA, ordinarily through our Trust Center documentation, security questionnaire responses, and any third-party certification or report we hold.
Where that is not sufficient to satisfy an audit obligation under Data Protection Law, you may request an audit no more than once in any twelve-month period, on at least thirty (30) days' written notice, during business hours, subject to confidentiality, conducted so as not to disrupt our operations, and at your cost. A regulator with authority over you may audit on the same basis. Additional audits may be carried out following a confirmed personal data breach affecting your data.
Each party's liability under this DPA is subject to the limitations and exclusions in Section 21 of the Terms of Service, except to the extent Data Protection Law does not permit that limitation.
This DPA prevails over the Terms of Service to the extent of any conflict about the processing of personal data. The Standard Contractual Clauses prevail over this DPA to the extent of any conflict. In all other respects the Terms of Service prevail.