LEGAL
Data Processing Addendum
Last updated 3 September 2026. Processor terms for supplier-controlled personal data handled through Zntrix Commerce.
1. Parties and incorporation
This Data Processing Addendum ("DPA") forms part of the Zntrix Terms of Service between the business or professional customer using Zntrix Commerce ("Customer") and Elijah Espela, an individual based in the Philippines operating the Zntrix brand ("Zntrix"). It applies when Zntrix processes Customer Personal Data on behalf of the Customer in connection with the service.
This DPA is automatically incorporated into the Terms when the Customer uses Zntrix to process personal data for which the Customer determines the business purpose and means of processing. Capitalized terms not defined here have the meanings given in the Terms or applicable data-protection law.
2. Roles of the parties
For Customer Personal Data, the Customer generally acts as the personal information controller, controller, or equivalent responsible party, and Zntrix acts as the personal information processor, processor, or equivalent service provider. Each party will comply with the obligations applicable to its role under the Philippine Data Privacy Act of 2012 and other data-protection law that applies to the processing.
The Customer is responsible for the lawfulness of its collection and use of Customer Personal Data, including providing required notices, establishing a lawful basis, responding to individuals, defining appropriate retention, and ensuring that its instructions to Zntrix are lawful.
Zntrix may separately act as a controller for account, security, service-administration, support, fraud-prevention, billing-administration, and legal-compliance data it processes for its own legitimate purposes, as described in the Privacy Policy. Paddle may also act independently as merchant of record for subscription transaction data.
3. Processing details
Subject matter: hosting and operating the Customer’s Zntrix workspace, supplier administration, dealer portal, catalogs, pricing, customer-specific access, quotes, orders, inventory workflows, support, security, media, imports, and related functionality selected or used by the Customer.
Duration: for the period in which Zntrix provides the service and for the retention and backup periods described in the Terms, Privacy Policy, and this DPA, unless applicable law requires a different period.
Nature and purpose: collecting, recording, organizing, storing, retrieving, consulting, displaying to authorized users, transmitting, securing, backing up, deleting, and otherwise processing Customer Personal Data as necessary to provide the service and follow the Customer’s documented instructions.
Data subjects may include the Customer’s owners, staff, sales agents, dealers, customers, prospective dealers, contacts, authorized representatives, and other individuals whose information the Customer lawfully places in the service.
Categories of data may include names, business contact details, account identifiers, roles, company information, dealer/customer profiles, pricing assignments, quotations, orders, transaction or payment-status metadata, payment-proof files, support information, communications, IP or security metadata, uploaded files, and other workspace information submitted by or for the Customer.
4. Customer instructions
Zntrix will process Customer Personal Data only on documented instructions from the Customer unless applicable law requires otherwise. The Terms, this DPA, the Customer’s configuration and use of the service, authorized feature selections, API or integration settings, and documented support requests constitute the Customer’s instructions.
If Zntrix reasonably believes an instruction violates applicable data-protection law, we may notify the Customer and suspend the affected processing until the parties clarify or modify the instruction. We are not required to perform an instruction that would make Zntrix violate applicable law or materially compromise the security of the service or another tenant.
5. Confidentiality and personnel
Zntrix will limit access to Customer Personal Data to people and service providers who need access to provide, secure, support, or maintain the service. Persons acting under Zntrix’s authority who can access Customer Personal Data will be subject to appropriate confidentiality obligations or duties.
Zntrix will not authorize its personnel to process Customer Personal Data for unrelated purposes and will take reasonable steps to ensure that authorized persons understand their privacy and security responsibilities.
6. Security measures
Zntrix will maintain reasonable and appropriate administrative, technical, and organizational safeguards designed to protect Customer Personal Data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure, or unauthorized access, taking into account the nature of the service, available technology, implementation cost, and processing risks.
Current safeguards may include tenant-scoped access controls, authentication and session protections, role-based authorization, encrypted transport, restricted database and object-storage access, secrets management, logging, rate limiting, backup controls, software dependency review, and procedures for addressing security vulnerabilities and incidents. Zntrix may modify safeguards as technology and risks change, provided the overall protection of Customer Personal Data is not materially reduced without a valid reason.
The Customer is responsible for securing its own devices, credentials, user accounts, integrations, exports, and internal access practices and for configuring workspace permissions appropriately.
7. Subprocessors
The Customer gives Zntrix general authorization to engage subprocessors reasonably necessary to provide the service. Current infrastructure or service providers that may process Customer Personal Data on Zntrix’s behalf include Vercel for application hosting and deployment, Supabase/PostgreSQL infrastructure for database services, Cloudflare R2 for object and media storage, and Resend for transactional or support email.
Paddle processes Zntrix subscription transactions as merchant of record and may act as an independent controller for payment, tax, fraud, and compliance information rather than solely as a Zntrix subprocessor. GreenCloud may be introduced as a hosting or VPS provider if Zntrix deploys that infrastructure in the future.
Zntrix will require subprocessors handling Customer Personal Data on our behalf to protect that data under obligations appropriate to the services they provide. Where applicable law requires notice or an opportunity to object to a material new subprocessor, Zntrix will provide reasonable information or notice through the service, an account contact, the Privacy Policy, or another appropriate channel. A Customer objection must be based on reasonable data-protection grounds; the parties will work in good faith toward a commercially reasonable solution.
8. International transfers
The Customer acknowledges that Zntrix and its providers may process Customer Personal Data in the Philippines, the United States, and other countries in which relevant infrastructure providers or subprocessors operate. The Customer authorizes those transfers as necessary to provide the service, subject to applicable law.
Where a transfer requires a specific legal mechanism or contractual safeguard, the parties will cooperate in good faith to use an available lawful mechanism reasonably appropriate to the processing. The Customer remains responsible for transfer requirements created by its own locations, instructions, users, or data sources.
9. Data-subject requests
Taking into account the nature of the processing, Zntrix will provide reasonable assistance to the Customer, through service functionality or support, with requests from individuals exercising applicable privacy rights concerning Customer Personal Data.
If Zntrix receives a request that clearly relates to Customer Personal Data controlled by the Customer, we may direct the requester to the Customer and, where appropriate, notify the Customer. Zntrix will not independently determine the merits of a request concerning Customer-controlled data unless required by law. The Customer remains responsible for responding within legally required deadlines.
10. Security incidents and regulatory assistance
If Zntrix becomes aware of a confirmed security incident involving Customer Personal Data for which applicable law requires processor notification, Zntrix will notify the affected Customer without undue delay after obtaining information sufficient to identify the affected Customer and incident. The notice will include information reasonably available to Zntrix that the Customer may need to assess its own notification obligations.
Zntrix will take reasonable steps to contain, investigate, mitigate, and remediate incidents within its control. The Customer is responsible for determining whether it must notify regulators, data subjects, business partners, or other parties, including compliance with any applicable statutory deadline.
Taking into account the nature of processing and information available to Zntrix, we will provide reasonable assistance with legally required privacy impact assessments, regulator consultations, or compliance inquiries relating specifically to Zntrix’s processing of Customer Personal Data. Additional work outside normal service support may be subject to reasonable fees where permitted by law and agreed in advance.
11. Return, retention, and deletion
While a workspace is active, the Customer may use the export functionality that Zntrix makes available under the applicable plan and service features. Zntrix does not provide a general contractual right to access or export the workspace after paid access or an authorized trial has ended.
When a trial expires or paid access effectively ends, Zntrix currently retains active workspace data for 60 calendar days for potential eligible reactivation. During this retention period the dealer portal is paused and general workspace use or export is not guaranteed. If the workspace is not reactivated before the period ends, Zntrix may permanently delete or anonymize active Customer Personal Data and other tenant data.
Encrypted backup copies may remain until normal backup rotation completes. Zntrix may retain limited information for longer where required or reasonably necessary for legal compliance, payment or tax records, fraud or abuse prevention, security, dispute resolution, or establishment, exercise, or defense of legal claims. These retained records remain protected under applicable confidentiality and security obligations.
12. Information and audits
Zntrix will make available information reasonably necessary to demonstrate compliance with the processor obligations in this DPA, taking into account the size and maturity of the service, confidentiality obligations, security risks, and information already available through policies, documentation, questionnaires, or provider reports.
If applicable law gives the Customer an audit right that cannot be satisfied through available documentation, the Customer may request a reasonable audit relating specifically to Customer Personal Data. Unless a regulator or confirmed incident reasonably requires otherwise, audits must be coordinated in advance, occur no more than once in a 12-month period, avoid unnecessary disruption, protect other tenants and Zntrix confidential information, and be performed by the Customer or a mutually acceptable independent auditor subject to confidentiality. The Customer bears its audit costs, and Zntrix may charge reasonable costs for substantial assistance where permitted by law and disclosed in advance.
13. Customer responsibilities
The Customer will use the service only for lawful processing, provide legally sufficient instructions, limit uploaded personal data to what is appropriate for its business purposes, keep information reasonably accurate, assign access on a need-to-know basis, and maintain any notices, consents, contracts, registrations, records, or assessments required for the Customer’s own processing.
The Customer will not instruct Zntrix to collect or process personal data in violation of applicable law or use the service as the sole repository for information that the Customer is legally required to preserve independently.
14. Liability and conflict
The liability limitations, exclusions, dispute provisions, and governing law in the Terms apply to this DPA to the fullest extent permitted by applicable law. Nothing in this DPA limits a responsibility that applicable data-protection law does not permit the parties to limit.
If this DPA conflicts with the Terms specifically regarding Zntrix’s processing of Customer Personal Data on behalf of the Customer, this DPA controls for that conflict. A separately signed data-processing agreement or Enterprise agreement may replace or supplement this DPA where it expressly says so.
15. Changes and contact
Zntrix may update this DPA when the service, subprocessors, law, or security practices change. Material changes will be communicated where appropriate or required, and no update will retroactively authorize processing that was unlawful when performed.
Questions about this DPA, subprocessors, or processing of Customer Personal Data may be sent to support@zntrix.com.
Related: Terms of Service · Privacy Policy · Refund Policy · Contact
