Home/DPA & sub-processors
Data Processing Addendum — summary and sub-processor notice
When we test your product we process data on your behalf. This page summarises the Data Processing Addendum (DPA) we sign with every customer, the technical and organisational measures behind it, and how we handle sub-processors. The signed DPA — with the EU Standard Contractual Clauses and the UK Addendum attached — is the binding document; ask for it at any stage of evaluation.
1. Roles and scope
For personal data contained in the systems, environments and evidence we handle during an engagement, you are the controller (or a processor acting for your own customers) and Smartintent AI Solutions Private Limited, trading as Zenius QA, is the processor. The DPA forms part of the Master Services Agreement or platform terms and applies to all such processing, wherever it takes place. For our own business contacts, we are a controller under the Privacy Policy.
2. Details of processing
| Subject matter | Quality-assurance services: automated and exploratory testing, load and performance rehearsal, triage, reporting and release verdicts |
|---|---|
| Duration | The term of the engagement, plus the return-and-deletion period in section 9 |
| Nature and purpose | Accessing repositories and test environments, executing tests, capturing evidence of failures (video, traces, HAR files, logs), classifying failures, reporting results |
| Types of personal data | Typically none by design. Incidentally: names and identifiers of your staff appearing in code, commits and environments; synthetic or pseudonymised test-user data; personal data that may appear in screen recordings or network captures of test environments |
| Categories of data subjects | Your employees and contractors; test users; where you authorise production testing, potentially your end customers |
| Special categories | Not intended; if your product handles special-category data, we agree specific measures in the Statement of Work |
3. Our obligations as processor
- Process personal data only on your documented instructions (the agreement, the SOW and written instructions from your named contacts), unless law requires otherwise, in which case we tell you first where permitted.
- Ensure everyone with access is bound by confidentiality and trained in data protection.
- Implement the measures in section 4 and help you meet your own security, breach-notification, impact-assessment and consultation obligations.
- Assist with data-subject requests that relate to the data we process for you, within five business days of your request.
- Engage sub-processors only as set out in section 6, under written terms no less protective than the DPA, and remain responsible for them.
- Delete or return personal data at the end of the engagement (section 9).
- Make available the information needed to demonstrate compliance and allow audits (section 8).
- Inform you if we believe an instruction infringes data-protection law.
4. Technical and organisational measures
| Domain | Measures |
|---|---|
| Access control | Named accounts only; least privilege scoped to the engagement; multi-factor authentication; access through the customer's identity provider where available; quarterly reviews; revocation within 24 hours of a role change |
| Environments | Staging by default; production only with written authorisation on read-only or synthetic paths; test payment methods; no copies of production personal data into test systems |
| Encryption | TLS 1.2+ in transit; encryption at rest for hosted evidence and reports; secrets held in the customer's vault or CI secret store, never in tickets or documents |
| Evidence handling | Videos, traces, HAR files and logs treated as confidential; stored in the region agreed in the SOW or in the customer's own storage; access logged; retained 90 days by default; deleted on request |
| Secure development | Peer review, dependency and secrets scanning, OWASP ASVS Level 2 target for the platform, CIS-hardened hosts, patching targets of 7 days (critical) / 30 days (high) |
| Organisation | Written confidentiality obligations; onboarding and annual security training; background verification where lawful; documented incident-response and continuity procedures; control mapping to ISO/IEC 27001:2022 and SOC 2 criteria |
| Data minimisation | Synthetic and pseudonymised test data; evidence captured only for failures; personal data redacted from reports where feasible |
5. International transfers
Processing takes place in India (registered office and engineering), the United States (US office) and in the regions of the cloud providers agreed in the SOW. For data subject to the GDPR, UK GDPR or Swiss law, the DPA incorporates the EU Standard Contractual Clauses (Decision (EU) 2021/914, Module 2 controller-to-processor, and Module 3 where you are a processor), the UK International Data Transfer Addendum, and the Swiss amendments, together with the supplementary measures in section 4. Transfer impact assessment documentation is available on request.
6. Sub-processors
We use a small number of sub-processors to host the platform and store evidence, run communications and manage the business. The complete, current list — with each provider's role and processing location — is attached to the DPA and provided to every customer at signature. We give 30 days' written notice before adding or replacing a sub-processor that will process your data; you may object on reasonable data-protection grounds, and if we cannot resolve the objection you may terminate the affected services without penalty. Any affiliate that assists with delivery is bound by the same obligations.
| Category | Purpose | Location |
|---|---|---|
| Cloud infrastructure | Hosting the platform, running tests where not run in the customer's CI, storing evidence and reports | Region agreed in the SOW (US, EU or India) |
| Source-control and CI providers | Access to repositories and pipelines chosen by the customer | Per the customer's own provider |
| Communication and productivity tools | Email, chat channels, document collaboration, video calls | US / EU |
| Business systems | E-signature, invoicing, support ticketing | US / EU / India |
To receive sub-processor change notices, ask your engagement lead to add your address to the notification list, or email rahul@zenius.ai.
7. Breach notification
We notify you without undue delay and within 48 hours of confirming a personal-data breach affecting data we process for you, with the information you need for your own notifications (nature of the breach, categories and approximate numbers of data subjects and records, likely consequences, measures taken), followed by a written post-incident report. This sits inside the GDPR's 72-hour controller deadline and India's DPDP requirement to inform affected individuals without delay.
8. Audits
You may audit our compliance with the DPA once a year (more often after a breach or where a regulator requires it) on 30 days' notice, during business hours, under confidentiality, either directly or through an independent auditor. We first provide our control mapping, completed questionnaires and available third-party reports; on-site or remote audits address what those cannot. Each party bears its own costs.
9. Return and deletion
At the end of an engagement, and at any time on your written request, we return your data in open formats (tests and configuration in your repositories; evidence and reports in files) and delete our copies within 30 days, providing a deletion confirmation on request. We retain only what law requires us to keep, under continued confidentiality.
10. Contact
Data Protection Officer: Rahul — rahul@zenius.ai · Smartintent AI Solutions Private Limited, T-18, Plot No. 9B & 9C, Cross River Mall, Shahdara, Delhi 110032, India · US office: 221 Camille St, Leander, TX 78641, USA.