Effective Date: 1 January 2026
This Data Processing Addendum ("DPA") forms part of the agreement between Zubu.AI, Inc. ("Zubu") and the customer that has accepted the Zubu Terms of Service or signed an Enterprise Agreement or Order Form with Zubu ("Customer"), together the "Agreement". It applies automatically, without signature, whenever Zubu processes Personal Data on Customer's behalf in providing the Services. It applies whether Customer purchased the Services from Zubu or through an authorized Zubu partner.
1. Definitions
1.1 Capitalized terms not defined here have the meanings given in the Agreement. "Customer Data", "Customer Source Data" and "Customer Hold Records" have the meanings given in the Zubu Terms of Service. The Zubu Privacy Policy refers to Customer Data as "Customer Content".
1.2 "Data Protection Laws" means all laws that apply to the processing of Personal Data under the Agreement, including, where applicable, the EU General Data Protection Regulation ("GDPR"), the UK GDPR and Data Protection Act 2018, the Swiss Federal Act on Data Protection, and United States federal and state privacy laws, including the California Consumer Privacy Act as amended ("CCPA").
1.3 "Personal Data" means any information in Customer Data that relates to an identified or identifiable individual, or that is otherwise defined as personal data or personal information under Data Protection Laws.
1.4 "Personal Data Breach" means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, Personal Data that Zubu processes under this DPA.
1.5 "Standard Contractual Clauses" or "SCCs" means the clauses annexed to European Commission Implementing Decision (EU) 2021/914.
1.6 "Sub-processor" means a third party that Zubu engages to process Personal Data on Customer's behalf.
1.7 "Controller", "processor", "data subject", "processing" and "supervisory authority" have the meanings given in the GDPR. "Business", "service provider", "sell" and "share" have the meanings given in the CCPA.
2. Scope and Roles
2.1 Roles. Customer is the controller or business, or a processor acting for its own client, of Personal Data. Zubu is Customer's processor or service provider. Where Customer is itself a processor, for example a law firm or service provider running legal holds for its client, Zubu is a sub-processor and Customer confirms that its instructions are authorized by the relevant controller.
2.2 Zubu as controller. This DPA does not apply to Personal Data that Zubu processes as a controller, such as account, billing, security and marketing contact data. The Privacy Policy describes that processing.
2.3 Details of processing. Annex I describes the subject matter, duration, nature and purpose of the processing, the types of Personal Data and the categories of data subjects.
2.4 Order of precedence. If this DPA conflicts with the rest of the Agreement on the processing of Personal Data, this DPA controls. If this DPA conflicts with the SCCs, the SCCs control.
3. Customer Instructions and Responsibilities
3.1 Documented instructions. Zubu will process Personal Data only on Customer's documented instructions. The Agreement, this DPA, Customer's configuration and use of the Services, and any written instructions Zubu accepts are Customer's complete instructions. Processing needed to provide, maintain, support and secure the Services, and to comply with law, is within those instructions.
3.2 Unlawful instructions. Zubu will tell Customer promptly if, in Zubu's opinion, an instruction infringes Data Protection Laws. Zubu is not required to follow that instruction until the Parties resolve it, and is not required to give legal advice.
3.3 Legal requirement. If law requires Zubu to process Personal Data other than on Customer's instructions, Zubu will tell Customer before processing unless that law prohibits it.
3.4 Customer responsibilities. Customer is responsible for (a) the lawfulness of its instructions and of its legal holds, preservation and collection, including any notice to or consent from custodians and employees and any works-council or employee-monitoring requirement; (b) having authority to connect each source system and to grant the permissions it grants; (c) the accuracy and content of Customer Data; and (d) its own privacy notice to the individuals whose data it processes through the Services.
4. Zubu's Obligations
4.1 Confidentiality. Zubu will ensure that its personnel who process Personal Data are bound by written or statutory duties of confidentiality and have access only as needed to provide the Services.
4.2 In-place processing. The Services operate on Customer Source Data in place, inside Customer's own systems. Zubu does not retain copies of Customer Source Data. During a collection that Customer directs, content passes through Zubu's environment and may be held in temporary files, which are deleted when the collection completes. Customer Hold Records are stored in Zubu's environment.
4.3 Connector credentials. Zubu uses the credentials and tokens Customer authorizes solely to perform the operations Customer has configured, requests only the permission scopes those operations require, stores them encrypted, and deletes them when Customer disconnects the source or the Agreement ends.
4.4 No other use. Zubu will not sell or share Personal Data, will not use it for advertising, and will not use it to train or improve artificial intelligence or machine learning models. Zubu may create aggregated, de-identified operational statistics that identify neither Customer nor any individual, as the Agreement permits.
4.5 Assistance. Taking into account the nature of the processing and the information available to Zubu, Zubu will give Customer reasonable assistance with data protection impact assessments and prior consultation with supervisory authorities that Data Protection Laws require of Customer in connection with the Services.
5. Security
5.1 Measures. Zubu will maintain the technical and organizational measures described in Annex II, which are designed to protect Personal Data against Personal Data Breaches and to provide a level of security appropriate to the risk.
5.2 Changes. Zubu may update its measures as technology and threats change, provided it does not materially reduce the overall level of protection during a Subscription Term.
5.3 Customer's part. Customer is responsible for the security of its own systems, its source-system configuration and permissions, its Authorized Users' credentials, and the destinations it chooses for collected content.
6. Sub-processors
6.1 General authorization. Customer authorizes Zubu to engage Sub-processors, including those listed in Annex III and at https://www.zubu.ai/sp.
6.2 Terms and responsibility. Zubu will bind each Sub-processor by a written agreement with data protection obligations no less protective than this DPA, and remains responsible to Customer for each Sub-processor's performance.
6.3 Changes. Zubu will give Customer at least thirty (30) days' notice before a new Sub-processor begins processing Personal Data, by updating the published list and emailing the administrative contact Customer has designated in the Services. Zubu may engage a replacement on shorter notice where needed to maintain the security or availability of the Services, and will then give notice as soon as practicable.
6.4 Objection. Customer may object on reasonable data protection grounds within fifteen (15) days after notice. The Parties will discuss the objection in good faith. If Zubu cannot offer a commercially reasonable alternative within thirty (30) days, Customer may terminate the affected Services on written notice and receive a refund of fees prepaid for the unused period, through its authorized partner where it purchased through one. That is Customer's sole remedy for an objection.
6.5 Not Sub-processors. Customer's own source systems, storage, review platforms and identity providers, any third-party tool Customer chooses to connect to the Services, and any authorized Zubu partner that Customer engages are not Zubu's Sub-processors.
7. Requests from Individuals and Third Parties
7.1 Data subject requests. If Zubu receives a request from an individual to exercise rights over Personal Data, Zubu will refer the individual to Customer where it can identify Customer, and will not respond to the request itself except to make that referral or as law requires.
7.2 Assistance. The Services give Customer tools to access, correct, export and delete Customer Hold Records. Where Customer cannot fulfil a request with those tools, Zubu will give reasonable assistance, taking into account the nature of the processing. Customer Source Data remains in Customer's own systems, and Customer fulfils requests about it there.
7.3 Government and third-party demands. If Zubu receives a legally binding demand for Personal Data from a court, regulator or law-enforcement body, Zubu will, unless prohibited by law, notify Customer promptly, direct the requester to Customer where it can, and disclose only what the law requires. Zubu will challenge a demand it reasonably believes to be unlawful.
8. Personal Data Breach
8.1 Notice. Zubu will notify Customer without undue delay after confirming a Personal Data Breach, at the security or administrative contact Customer has designated in the Services.
8.2 Content. The notice will describe, to the extent known, the nature of the breach, the categories and approximate numbers of data subjects and records affected, the likely consequences, and the measures Zubu has taken or proposes. Zubu may give information in stages as it becomes available.
8.3 Response. Zubu will take reasonable steps to contain and remedy the breach and will give Customer reasonable assistance in meeting Customer's own notification obligations. Zubu will meet any notification obligation that Data Protection Laws place directly on Zubu.
8.4 No admission. A notice under this Section is not an admission of fault or liability. This Section does not apply to incidents caused by Customer, its Authorized Users or its systems, or to unsuccessful attempts that do not compromise Personal Data.
9. International Transfers
9.1 Hosting location. Zubu hosts the Services on Amazon Web Services and Microsoft Azure infrastructure in the United States, unless the Parties agree a different hosting region in an Order. Customer Source Data stays in the systems and regions Customer has chosen, except while it passes through Zubu's hosting environment during a collection Customer directs.
9.2 Transfer mechanism. Where the processing involves a transfer of Personal Data from the European Economic Area, the United Kingdom or Switzerland to a country not recognized as providing adequate protection, and no other valid mechanism applies, the Standard Contractual Clauses are incorporated into this DPA and apply as set out in Annex IV.
9.3 Onward transfers. Zubu will transfer Personal Data to a Sub-processor in a country without an adequacy decision only under the Standard Contractual Clauses or another mechanism that Data Protection Laws recognize.
9.4 Alternative mechanism. If Zubu adopts another recognized transfer mechanism, such as certification under the EU-U.S. Data Privacy Framework and its UK and Swiss extensions, that mechanism applies in place of the Standard Contractual Clauses for the transfers it covers, for as long as it remains valid.
10. Return and Deletion
10.1 During the term. Customer can export and delete Customer Hold Records using the Services during the Subscription Term.
10.2 After termination. For thirty (30) days after the Agreement ends, Zubu will make Customer Hold Records available for Customer to export. Within sixty (60) days after that period, Zubu will delete Customer Hold Records and connector credentials from its production systems. Backups are overwritten on Zubu's rolling backup cycle, and remain protected under this DPA until then.
10.3 Legal holds. Customer Hold Records are Customer's record of its preservation steps. If Customer tells Zubu in writing before deletion that the records are subject to a continuing preservation obligation, the Parties will agree in good faith an extended retrieval period or continued storage, which may carry a fee.
10.4 Retention required by law. Zubu may keep Personal Data to the extent and for the period that law requires, and will protect it under this DPA and process it only for that purpose.
10.5 Certification. Zubu will confirm deletion in writing on Customer's request.
11. Audits
11.1 Information. On written request, and subject to confidentiality obligations, Zubu will make available the information reasonably needed to show its compliance with this DPA, including a summary of its security program, its responses to a reasonable security questionnaire, and any current independent audit report or certification it holds.
11.2 Audit. If that information is not sufficient to show compliance, or a supervisory authority requires it, Customer may audit Zubu's processing of Personal Data no more than once in any twelve (12) months, on at least thirty (30) days' written notice, during business hours, under a mutually agreed scope, and without unreasonable disruption. A further audit is permitted after a Personal Data Breach affecting Customer.
11.3 Conditions. Customer bears its own audit costs. An auditor must be independent, bound by confidentiality, and not a competitor of Zubu. An audit will not give access to other customers' data, to Zubu's trade secrets beyond what is needed, or to systems in a way that would compromise security. Customer will share the audit report with Zubu and treat it as Zubu's Confidential Information.
11.4 Sub-processors. Audit rights over a Sub-processor are exercised through Zubu, under the terms Zubu has with that Sub-processor.
12. United States Privacy Laws
12.1 Service provider. To the extent the CCPA or a comparable United States state privacy law applies, Zubu is a service provider or processor, and Customer discloses Personal Data to Zubu only for the limited and specified business purpose of providing the Services described in the Agreement.
12.2 Restrictions. Zubu will not (a) sell or share Personal Data; (b) retain, use or disclose Personal Data for any purpose other than providing the Services, including any commercial purpose of its own, except as those laws permit a service provider; (c) retain, use or disclose Personal Data outside the direct business relationship between Zubu and Customer; or (d) combine Personal Data with personal information it receives from another source or collects from its own interactions with an individual, except as those laws permit.
12.3 Compliance. Zubu will comply with the obligations those laws place on service providers and provide the level of privacy protection they require. Zubu will tell Customer if it decides it can no longer meet those obligations.
12.4 Customer's rights. Customer may take the reasonable and appropriate steps described in Section 11 to help ensure that Zubu uses Personal Data consistently with Customer's obligations, and may, on notice, take reasonable and appropriate steps to stop and remedy unauthorized use of Personal Data.
12.5 Certification. Zubu certifies that it understands the restrictions in this Section and will comply with them.
13. Artificial Intelligence
13.1 No training. Zubu will not use Personal Data, or any other Customer Data, to train, retrain, fine-tune or otherwise improve artificial intelligence or machine learning models, whether Zubu's own or a third party's.
13.2 Where AI Features run. AI Features that analyze Customer Source Data run inside Customer's own cloud environment, and Zubu's environment receives only the resulting output, which is stored as Customer Hold Records. AI Features that operate on Customer Hold Records run within Zubu-controlled infrastructure hosted by the Sub-processors in Annex III.
13.3 No third-party model providers. Zubu will not send Personal Data to a third-party large-language-model or AI service provider for processing. If that changes, the provider is a new Sub-processor and Section 6 applies before it processes any Personal Data.
13.4 No solely automated decisions. AI Features produce suggestions and analyses for review by Customer's authorized personnel. Zubu does not use them to make decisions that produce legal or similarly significant effects on individuals.
13.5 Customer-directed integrations. If Customer connects the Services to a third-party AI tool or assistant, that tool processes data under Customer's configuration and the third party's terms. It is not Zubu's Sub-processor, and this Section does not apply to it.
14. Purchases Through Authorized Partners
14.1 Direct application. Where Customer purchased the Services through an authorized Zubu partner, this DPA applies directly between Customer and Zubu.
14.2 Partner's role. The partner is not Zubu's Sub-processor. If the partner accesses Personal Data, for example to provide support or to operate the Services for Customer, it does so under Customer's authorization and under Customer's own agreement with the partner, and Customer is responsible for having data processing terms with the partner that meet Data Protection Laws.
14.3 Information shared with the partner. Zubu may share account, usage and support information about Customer with the partner as the Agreement permits. Zubu will not give the partner access to Customer Data except through credentials Customer has issued to the partner's personnel or on Customer's instruction.
15. Liability
15.1 Each Party's liability arising out of or relating to this DPA, including under the Standard Contractual Clauses as between the Parties, is subject to the exclusions and limits of liability in the Agreement, and those limits apply in aggregate to all claims under the Agreement and this DPA together.
15.2 Nothing in this DPA limits either Party's liability to a data subject or a supervisory authority where Data Protection Laws do not allow that liability to be limited.
16. General
16.1 Term. This DPA takes effect when the Agreement does and continues for as long as Zubu processes Personal Data on Customer's behalf.
16.2 Governing law. This DPA is governed by the law that governs the Agreement and is subject to the same courts, except where the Standard Contractual Clauses provide otherwise.
16.3 Updates. Zubu may update this DPA to reflect changes in Data Protection Laws, the Services or its Sub-processors by posting a revised version. Zubu will not materially reduce the protection of Personal Data during a Subscription Term without Customer's consent, unless law requires the change.
16.4 Signed copy. This DPA binds the Parties without signature. Customer may request a countersigned copy at privacy@zubu.ai.
16.5 Contact. Privacy questions and notices under this DPA: privacy@zubu.ai. Security incidents: security@zubu.ai.
Annex I: Details of Processing
A. Parties
| Data exporter | Data importer | |
|---|---|---|
| Name | Customer, as identified in the Agreement or Order | Zubu.AI, Inc. |
| Address | As stated in the Agreement or Order | 100 Pine Street, Suite 1250, San Francisco, CA 94111, United States |
| Contact | The administrative contact designated in the Services | privacy@zubu.ai |
| Role | Controller, or processor for its own client | Processor, or sub-processor |
| Activities | Use of the Services for legal hold, preservation and collection | Provision of the Services |
B. Description of processing
| Item | Description |
|---|---|
| Subject matter | Provision of Zubu's hosted legal hold, preservation and collection Services under the Agreement |
| Duration | The Subscription Term, plus the retrieval and deletion periods in Section 10 |
| Nature and purpose | Issuing and tracking legal hold notices and questionnaires; identifying custodians and data sources; applying preservation holds and performing collections in place in Customer's systems; delivering collected content to a destination Customer controls; indexing, search, classification and summarization, including by AI Features; audit logging; support and security |
| Categories of data subjects | Customer's Authorized Users; custodians, who are typically Customer's current and former employees, contractors and agents; and other individuals who appear in Customer Source Data, such as correspondents and third parties named in documents and messages |
| Categories of Personal Data in Customer Hold Records | Names, business contact details, employer, job title and department; hold notices, acknowledgments and questionnaire responses; search criteria; metadata, indexes and search results derived from Customer Source Data; output of AI Features; audit logs, including IP address, browser type and timestamps from the custodian portal; connector credentials and tokens |
| Categories of Personal Data in Customer Source Data | Whatever Personal Data is contained in the mailboxes, files, chat messages and other records Customer places in scope, and their metadata. Zubu does not select or control these categories |
| Special categories | Customer Source Data may contain special categories of data or data about criminal convictions, depending on what Customer places in scope. Zubu does not require or intentionally seek such data. The safeguards in Annex II apply to all Personal Data |
| Frequency of transfer | Continuous during the Subscription Term |
| Retention | Customer Source Data: not retained; temporary files created during a collection are deleted when the collection completes. Customer Hold Records: as Customer configures during the Subscription Term, then returned and deleted under Section 10 |
| Sub-processor transfers | As described in Annex III, for the duration of the Agreement |
C. Competent supervisory authority
The supervisory authority of the EEA member state in which Customer is established or, if Customer is not established in the EEA, in which its representative is established or in which the data subjects whose data is transferred are located.
Annex II: Technical and Organizational Measures
Zubu maintains a written information security program aligned with the SOC 2 Trust Services Criteria and ISO/IEC 27001. Its measures include:
Encryption. Data in transit is encrypted using TLS 1.2 or higher, and data at rest using AES-256 or equivalent.
Access control. Role-based access, least-privilege provisioning and multi-factor authentication for access to production systems.
In-place architecture. Customer Source Data stays within Customer's own systems and security perimeter and is not retained in Zubu's. Temporary files created during a collection are deleted when the collection completes.
Tenant separation. Logical separation of each Customer's Customer Hold Records. Access by Zubu personnel is limited to what is necessary to operate the Services and provide support, and is logged.
Credential protection. Connector credentials are stored encrypted in a dedicated secrets-management service, with least-privilege permission scopes and Customer-side revocation.
Monitoring and testing. Security monitoring, centralized audit logging, vulnerability scanning, and periodic penetration testing by independent third parties.
Secure development. Code review and change management.
Personnel. Background checks where permitted by law, confidentiality obligations, and security and privacy training for personnel who handle Personal Data.
Incident response. An incident-response program, tested regularly, with Customer notification under Section 8.
Sub-processors. Written data protection terms with each Sub-processor no less protective than this DPA.
Annex III: Sub-processors
The current list is published at https://www.zubu.ai/sp. At the Effective Date it is:
| Sub-processor | Purpose | Location |
|---|---|---|
| Amazon Web Services, Inc. | Cloud hosting and infrastructure for the Services | United States, unless another region is agreed |
| Microsoft Corporation (Azure) | Cloud hosting and infrastructure for the Services | United States, unless another region is agreed |
Annex IV: Standard Contractual Clauses
Where Section 9.2 applies, the Parties agree the following.
A. EEA transfers
| Item | Election |
|---|---|
| Module | Module Two (controller to processor) where Customer is a controller; Module Three (processor to processor) where Customer is a processor |
| Clause 7 (docking) | Applies |
| Clause 9(a) (sub-processors) | Option 2, general written authorization, with the notice period in Section 6.3 of this DPA |
| Clause 11(a) (redress) | The optional language does not apply |
| Clause 17 (governing law) | Option 1, the law of Ireland |
| Clause 18(b) (forum) | The courts of Ireland |
| Annex I | Annex I of this DPA |
| Annex II | Annex II of this DPA |
| Annex III | Annex III of this DPA |
B. United Kingdom transfers. The International Data Transfer Addendum to the EU Commission Standard Contractual Clauses issued by the UK Information Commissioner (version B1.0) is incorporated. Its Tables 1 to 3 are completed with the information in this DPA and its Annexes. For Table 4, either Party may end the Addendum as its Section 19 provides.
C. Swiss transfers. For transfers subject to the Swiss Federal Act on Data Protection, the Standard Contractual Clauses apply with these changes: references to the GDPR include the Swiss Act; the competent supervisory authority is the Swiss Federal Data Protection and Information Commissioner; "member state" does not exclude data subjects in Switzerland from suing in their place of habitual residence; and the governing law for those transfers is Swiss law.
D. Interpretation. Audits under the Standard Contractual Clauses are carried out as Section 11 describes, sub-processor authorization as Section 6 describes, and deletion certification as Section 10 describes. Nothing in this DPA is intended to modify the Standard Contractual Clauses or reduce the rights they give data subjects.

