Data Processing Addendum
Version 1.3 · Last updated: 20 September 2026
The standard form addendum we offer where Zencra Labs processes personal data on behalf of a business customer.
1. About this addendum
This is the standard form of Data Processing Addendum offered by ZENCRA LABS PRIVATE LIMITED. It sets out the terms on which we would process personal data on behalf of a business customer. It is published here so that an organisation can review it before deciding whether to enter into it with us.
Publishing this page does not by itself put an addendum in place. We do not currently operate a signature, click-through, or acceptance step for it, and we do not represent that an addendum is in force with any particular customer. If your organisation needs an addendum for its use of the platform, contact legal@zencralabs.com and we will arrange it.
This page describes the terms we offer. It is not a statement that any certification, audit, or regulatory approval has been obtained.
2. Definitions
We use the terms of the Digital Personal Data Protection Act, 2023 where they apply, and equivalent terms under other applicable data protection law where they apply.
- Customer means the organisation that has entered into our Terms of Service for business use.
- Customer Personal Data means personal data contained in content that the Customer or its members upload to, or generate through, the platform.
- Data Principal means the individual to whom personal data relates. Data Subject has the equivalent meaning under other applicable law.
- Data Fiduciary means the party that determines the purpose and means of processing. Controller has the equivalent meaning under other applicable law.
- Data Processor means a party that processes personal data on behalf of a Data Fiduciary. Processor has the equivalent meaning under other applicable law.
- Service Provider means a third party we engage to process Customer Personal Data in connection with the platform. Sub-processor has the equivalent meaning under other applicable law.
3. Roles of the parties
For the Customer's own account data, such as the account holder's contact details, authentication data, billing records, and usage and security logs, Zencra Labs is the Data Fiduciary and our Privacy Policy at /privacy applies. This addendum does not change that.
For Customer Personal Data, meaning personal data that the Customer or its members choose to put into the platform as content, including a person's image, likeness, voice, or other personal details contained in an upload, a prompt, or a reference, the Customer is the Data Fiduciary and Zencra Labs acts as a Data Processor on the Customer's behalf. Where an addendum on these terms has been entered into, it governs that processing.
Where a member of a Customer's workspace also holds a personal account with us, our relationship with that person in their personal capacity is governed by our Privacy Policy and not by this addendum.
4. Subject matter, duration, and instructions
Subject matter and purpose: providing the Zencra Labs platform and its AI creative features to the Customer under our Terms of Service. Duration: for as long as the Customer uses the platform, and afterwards as described in section 10. Categories of Data Principal and categories of personal data: those the Customer chooses to submit.
We will process Customer Personal Data only to provide and support the platform, to secure it and prevent abuse, to comply with law, and otherwise on the Customer's documented instructions. The Customer's use of the platform, including the settings and features it enables, constitutes its documented instructions.
If we believe an instruction would breach applicable data protection law, we will tell the Customer and may decline to act on it.
5. Customer obligations
The Customer is responsible for having a lawful basis for the Customer Personal Data it submits, for giving any notice and obtaining any consent that applies, and for the accuracy of its instructions.
The Customer must not submit personal data of a kind that requires protection beyond what the platform provides, and must not submit a person's image, likeness, or voice without the rights and permissions required by our User Generated Content Policy at /ugc-policy and our AI Content Policy at /ai-content-policy.
The Customer is responsible for managing its workspace, its members, and their access, as set out in our Business and Enterprise Terms at /business-terms.
6. Confidentiality and personnel
We limit access to Customer Personal Data to personnel who need it to perform our obligations, and those personnel are bound by a duty of confidentiality.
7. Security
We use reasonable technical and organisational measures appropriate to the risk, including access controls, encryption in transit, and rate limiting, as described at /security and in our Privacy Policy.
No system is completely secure, and we do not warrant that the platform cannot be compromised. We do not hold a security certification or third-party audit attestation, and we make no such claim in this addendum. Security measures may change over time, and we may update them provided the level of protection is not materially reduced.
8. Service providers
The Customer gives a general authorisation for us to engage the Service Providers we use to operate the platform. Our current list of these providers, with the role each performs, is published at /subprocessors.
We will keep that page up to date and will update it before a new Service Provider begins processing Customer Personal Data, or as soon as reasonably practicable afterwards where an urgent change is needed. The Customer may object to a new Service Provider on reasonable data protection grounds by contacting us; where we cannot accommodate an objection, the Customer may stop using the affected feature or end its subscription in accordance with our Refund and Cancellation Policy at /refund-policy.
We remain responsible to the Customer for the performance of the Service Providers we engage. We rely on the data protection terms each Service Provider offers and we seek terms covering its processing; we do not represent that a written agreement is in place with every Service Provider or that any such arrangement takes a particular form, and we will tell the Customer the position for a specific provider on request.
9. International processing
We are based in India and may process and store Customer Personal Data in India and in other countries where we or our Service Providers operate, including where AI providers are located outside India. Where required, we apply appropriate safeguards for such transfers.
We do not offer a data residency option and we do not commit to processing or storing Customer Personal Data in any particular country.
10. Assistance, rights, deletion, and return
Taking into account the nature of the processing, we will provide reasonable assistance to the Customer in responding to a request from a Data Principal, and in meeting the Customer's obligations relating to security, breach notification, and any assessment that applies to it. Where a Data Principal contacts us directly about Customer Personal Data, we will refer them to the Customer unless the law requires otherwise.
The Customer can access, correct, and remove Customer Personal Data using the controls in the platform for as long as its account is active. On termination, the Customer may delete its content through the platform and may request deletion as described at /data-deletion.
After deletion, residual copies may remain in backups until they are purged on a rolling schedule, and we retain what applicable law requires us to retain, including billing and tax records, and anything covered by a legal hold. We do not represent that every copy is removed immediately or that deletion extends to material a Service Provider holds under its own terms.
11. Personal data breach
We will notify the Customer without undue delay after becoming aware of a personal data breach affecting Customer Personal Data, and we will provide the information reasonably available to us so the Customer can meet its own obligations. We will act in accordance with applicable law, including notifying the relevant authority and affected individuals where required.
Our notification of a breach is not an admission of fault or liability.
12. Information and audit
On reasonable written request, and not more often than once a year unless a regulator or a breach requires otherwise, we will make available the information reasonably necessary to demonstrate our compliance with this addendum. We do not currently hold a third-party audit report or certification to provide.
Any audit must be at the Customer's cost, must be agreed with us in advance, must respect the confidentiality and security of other customers, and must not disrupt the platform. We may satisfy an audit request by providing written responses and available documentation.
13. Liability, precedence, and changes
The limitations and exclusions of liability in our Terms of Service apply to this addendum and to any claim arising from it. Nothing in this addendum excludes or limits liability where applicable law does not permit such exclusion or limitation.
Where an addendum on these terms has been entered into and it conflicts with our Terms of Service or Business and Enterprise Terms on the processing of Customer Personal Data, the addendum applies on that subject. Where it conflicts with a written agreement we have signed with the Customer, the signed agreement applies.
This addendum is governed by the laws of India, and the courts at Mumbai, Maharashtra, India have jurisdiction over disputes relating to it. We may change the standard form published on this page, and the form shown here is the one we currently offer as at the date shown above. Changing this page does not alter an addendum already entered into.
14. Contact
To request an addendum on these terms for your organisation, to raise a data protection question about business use, or to object to a Service Provider, contact legal@zencralabs.com. For questions about how we handle personal data generally, contact privacy@zencralabs.com.
Contact
This document is effective from the Last updated date shown above and may be updated from time to time. When we make changes we will revise that date and, where appropriate, notify you through the platform or by email. Continued use of Zencra Labs after an update means you accept the revised version.