Legal · ZebraByte
Acord de Prelucrare a Datelor (DPA)
Terms of data processing applicable when ZebraByte processes personal data on behalf of a customer.
Ultima revizuire: August 17, 2026
This Data Processing Agreement (DPA) complements the agreement between the Customer and ZEBRABYTE LIMITED (“ZebraByte”) and applies when ZebraByte processes Personal Data on behalf of the Customer in connection with the contractualized services. the DPA is designed for the requirements applicable to the processor-contractor relationship, including Article 28 UKGDPR and, where applicable, Article 28 EUGDPR.
Roles of the Parties
To the extent that the Customer sets out the purposes and means of the processing, the Customer is operator (Controller)and ZebraByte is Authorized Person of the Processor (Processor)If the Customer acts himself as a trustee for a third party, ZebraByte may act as a sub-trustee, and the relevant obligations apply accordingly.
For data that ZebraByte processes for its own purposes – for example, the administration of the business account, invoicing, the security of its own service or the fulfillment of legal obligations –ZebraByte may act separately as a controller in accordance with the Privacy Policy.
Documented Instructions
ZebraByte processes Personal Data only on the basis of documented instructions from the Customer, including with regard to international transfers, unless processing is required by law. Configuration and use of the service, orders, contract, support tickets and written instructions constitute documented instructions.
If ZebraByte considers that an instruction violates the applicable data protection law, it will inform the Customer without undue delay and may suspend the execution of the instruction until clarification.
Authorized persons and confidentiality
ZebraByte limits access to Personal Data to persons who need access for the provision, security or support of the Services. Authorized persons are subject to appropriate confidentiality, contractual or legal obligations, and receive access in accordance with the principle of least privilege.
Safety of processing
ZebraByte ins technical and organizational measures appropriate to the risk, taking into account the nature of the service, the state of the art, the costs of implementation and the nature, scope, context and purposes of the processing.
- Identity and access control, MFA and separation of privileges;
- encryption of data in transit and, where permitted by the service, storage;
- logging, monitoring, alerting and incident response processes;
- vulnerability management, patching and hardening;
- logical segregation of clients and limitation of administrative access;
- backup and restoration mechanisms for services that include these functions;
- periodic review of the effectiveness of the relevant controls.
Configurations and responsibilities that remain under the Customer’s control are part of the Shared Responsibility model and must be properly managed by the Customer.
Sub-empowered persons
The Customer grants ZebraByte a general authorization for the use of the authorized sub-persons necessary for the provision of the Services.ZebraByte will impose on them data protection obligations that provide a substantially equivalent level of protection for the subcontractual activities and remains responsible to the Customer for the fulfillment of their obligations in accordance with applicable law.
ZebraByte will provide information about relevant authorized sub-persons and communicate the changes in a way that allows the Customer to raise a justified objection for data protection reasons. If the parties cannot resolve a reasonable objection, they will consider a technical alternative or termination of the affected component, in accordance with the contract.
International transfers
If Personal Data is transferred to a country for which there is no applicable adequacy decision, ZebraByte will use a legal transfer mechanism appropriate to the situation, such as the applicable Standard Contractual Clauses, UK IDTA or UK Addendum, together with additional measures when the assessment of the transfer requires.
7. Drepturile persoanelor vizate
Taking into account the nature of the processing, ZebraByte will assist the Customer with appropriate technical and organizational measures to respond to the requests of the data subjects. If ZebraByte receives a request regarding data processed on behalf of the Customer directly, it will forward it to the Customer without undue delay and will not respond on behalf of the Customer unless authorized or required by law.
Assistance for compliance
ZebraByte will provide reasonable assistance, taking into account the nature of the processing and available information, for the Customer's obligations regarding security, breach notification, DPIA and consultation with supervisory authorities. Support that goes beyond the normal functionality of the service may be subject to reasonable rates agreed in advance, if the request does not result from a breach of the ZBTKEEP obligations1.
Violations of data security
ZebraByte will notify the Customer without undue delay after it becomes aware of a personal data breach affecting data processed on behalf of the Customer. As the information becomes available, the notification will include reasonable details about the nature of the incident, the data affected, the known impact and remedial measures. The notification does not constitute a recognition of guilt or liability.
Return and deletion of data
Upon termination of the Services, at the Customer's choice and to the extent permitted by the functionality of the Service, ZebraByte will return or delete Personal Data processed on behalf of the Customer, except for data that the law requires them to retain. Residual copies from backups are isolated from current use and are overwritten according to the normal retention and backup cycle applicable to the Service.
Evidence, Audit and Inspections
ZebraByte will provide the Customer with the information reasonably necessary to demonstrate compliance with the obligations under this DPA. Normally, the audit is first based on the documentation, reports and proof of compliance available. If these are not sufficient and the law or risk justifies further inspection, the parties will agree on the scope, time and confidentiality measures so that the audit does not compromise the security of other clients.
Details of processing
Obiect: the provision, operation, security and support of the services ordered by the Customer.
The duration: the duration of the contract, plus the limited retention/backup periods required by the service and the law.
Nature and Purpose: hosting, storage, transmission, technical access, support, monitoring, security, backup, administration and other operations necessary for the contracted service.
Categorii de persoane vizate: may include employees, contractors, customers, users, visitors or other persons whose data is entered in the Customer Service.
Categories of Data: The data is set by the Customer and may include identification and contact data, account data, content, files, databases, online identifiers, logs and technical metadata. The Customer will not enter special categories or high-risk data if the service is not configured and authorized for such processing.
Priority and Changes
If there is a conflict between this DPA and the General Terms on Data Processing on behalf of the Client, the DPA prevails. Changes necessary to reflect mandatory requirements of data protection legislation may be implemented with reasonable notice.
Contact for data protection
ZEBRABYTE LIMITED · Company No. 15194067 · ICO registration ZB748706
Suite 7165a, 60 Tottenham Court Road, Fitzrovia, London, W1T 2EW, United Kingdom
Legal / privacy: legal@zebrabyte.co.uk