LEGAL

DPA & Subprocessors

Last updated: September 2026

Overview

This page describes how zn ("usezn") processes personal data on behalf of customers, and lists the subprocessors we engage. It supplements our Privacy Policy and our Security Policy. Enterprise customers can execute a Data Processing Agreement (DPA) with us on request — contact legal@usezn.com.

Roles

Customer (controller): you decide what input you send to the API and remain responsible for your own users and applications.

zn (processor): we analyze input and produce evidence records only to deliver the service described in our Terms and Privacy Policy.

Polar (independent controller): as Merchant of Record, Polar processes payment and tax data under its own privacy terms. zn does not receive full payment card data.

Data We Process on Your Behalf

  • API input: evaluated in volatile memory and not stored on paid plans. The free Contributor plan only shares PII-scrubbed, non-reversible telemetry with explicit opt-in.
  • Evidence records: SHA-256 hash of the analyzed input plus verdict, confidence, rule, latency, and timestamp. Retained for up to 90 days and exportable as CSV or JSONL.
  • Account and usage data: email address, optional company name, API key metadata, call counts, and latency metrics.
  • Billing data: managed by Polar as Merchant of Record.

Subprocessors

SubprocessorPurposeData categories
Amazon Web Services (AWS)Cloud hosting, object storage, and managed database servicesAccount data, usage metadata, and SHA-256 evidence records
Auth0Authentication and identity managementAccount email and login identifiers
PolarPayments, invoicing, tax handling, and Merchant of RecordBilling details processed by Polar under its own privacy terms
Amazon SESTransactional email deliveryEmail address and message metadata

International Transfers

Where personal data originating in the EEA or the UK is transferred to a subprocessor outside those regions, we rely on the subprocessor's Standard Contractual Clauses and/or an applicable adequacy mechanism such as the EU-US Data Privacy Framework where the subprocessor is certified. Subprocessor agreements include confidentiality, security, and data protection obligations.

Security Measures

Technical and organizational measures include TLS 1.3 in transit, AES-256 encryption at rest with AWS KMS-managed keys, least-privilege access controls, and a SHA-256 hash-chained evidence ledger. We run on AWS, whose data centers hold SOC 2 Type II and ISO 27001 certifications. zn itself is not yet SOC 2 or ISO certified; the compliance roadmap is published on our Security Policy page.

Changes to Subprocessors

We keep this page current. If you have executed a DPA with us and we add a subprocessor that processes personal data, we will notify you by email so you can object as described in the agreement.

Data Subject Requests

We assist customers in responding to data subject requests relating to the data we process on their behalf. Send requests to privacy@usezn.com.

Contact

For DPA execution, subprocessor questions, or legal inquiries, contact legal@usezn.com. We are based in Europe and reply in English or Spanish.