Legal
Data Processing Addendum
This addendum sets out how Zirozen Software Corporation LLP processes personal data on behalf of customers who use the Trinetri Autonomous Platform, and the commitments we make to protect it under data protection laws worldwide.
Contents17 sections + 3 annexes
1.How this addendum applies
This Data Processing Addendum “DPA” forms part of the agreement between Zirozen Software Corporation LLP , a limited liability partnership registered in India with its registered office at L801, Safal Parisar-1, South Bopal, Ahmedabad 380058, Gujarat, India “Zirozen”, “we”, “us”, and the customer that has entered into that agreement for the use of the Trinetri Autonomous Platform.
This DPA applies whenever Zirozen processes Customer Personal Data in providing the Services. It takes effect when the Agreement takes effect, including by acceptance of our online terms, without a separate signature. Where a customer buys through a partner, reseller or managed service provider, this DPA applies between Zirozen and that customer to the extent Zirozen processes the customer’s personal data, and the partner remains responsible for its own processing.
2.Definitions
Terms not defined here have the meaning given in the Agreement or in Data Protection Laws.
- Customer Personal Data means personal data processed by Zirozen on behalf of the Customer in providing the Services, as described in Annex I.
- Data Protection Laws means all laws on privacy and personal data that apply to the processing, including India’s Digital Personal Data Protection Act, 2023 and its Rules (“DPDP Act”), the EU General Data Protection Regulation 2016/679 (“GDPR”), the UK GDPR and Data Protection Act 2018, the Swiss Federal Act on Data Protection, the California Consumer Privacy Act as amended by the CPRA (“CCPA”) and other US state privacy laws, Brazil’s LGPD, Canada’s PIPEDA, Singapore’s PDPA, Australia’s Privacy Act 1988, the UAE and Saudi Arabian PDPLs, South Africa’s POPIA and Japan’s APPI.
- Controller includes a “data fiduciary” under the DPDP Act and a “business” under the CCPA. Processor includes a “data processor” under the DPDP Act and a “service provider” under the CCPA.
- Data Subject includes a “data principal” under the DPDP Act and a “consumer” under the CCPA.
- Personal Data Breach means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, Customer Personal Data.
- Services means the Trinetri platform, including EndpointOps, CloudOps, MobileOps, GAS AI, the Trinetri agents and apps, and related support, as described in the Agreement.
- Sub-processor means any third party engaged by Zirozen to process Customer Personal Data.
- SCCs means the standard contractual clauses approved by the European Commission in Implementing Decision (EU) 2021/914.
- UK Addendum means the International Data Transfer Addendum to the SCCs issued by the UK Information Commissioner.
3.Roles and scope
For Customer Personal Data, the Customer is the controller (or a processor acting for its own controllers, such as a managed service provider acting for its clients) and Zirozen is the processor (or sub-processor). Each party will comply with the Data Protection Laws that apply to it.
The Customer is responsible for the lawfulness of the personal data it provides or causes to be collected through the Services, including giving any notices and obtaining any consents required from its employees, contractors and device users, for example before enabling device location tracking or managing personally owned devices.
Zirozen acts as an independent controller for account, billing, usage and security data it needs to run its business, as described in the Trinetri Privacy Policy. That processing is outside the scope of this DPA.
4.Customer instructions
Zirozen will process Customer Personal Data only on the Customer’s documented instructions, which are: the Agreement and this DPA; the Customer’s configuration and use of the Services, including the modules, policies, automations and integrations it enables; and any further reasonable written instructions consistent with the Agreement.
Zirozen will not process Customer Personal Data for any other purpose unless required by law, in which case it will inform the Customer beforehand unless the law prohibits it. Zirozen will tell the Customer promptly if it believes an instruction infringes Data Protection Laws.
Zirozen will not sell Customer Personal Data, use it for advertising or profiling, or use it (including prompts and outputs of GAS AI) to train or improve artificial intelligence models for anyone other than the Customer. Zirozen may create aggregated, de-identified data that cannot reasonably identify any person or the Customer, and use it to operate and improve the Services.
5.Confidentiality of personnel
Zirozen will ensure that everyone authorised to process Customer Personal Data is bound by confidentiality obligations, receives appropriate privacy and security training, and has access only to the extent needed to perform their role.
6.Security
Zirozen will implement and maintain appropriate technical and organisational measures to protect Customer Personal Data, taking into account the state of the art, the costs of implementation, and the nature, scope, context and purposes of processing, as well as the risks to individuals. These measures include those in Annex II, and meet the reasonable security safeguards required by Section 8(5) of the DPDP Act.
Zirozen may update these measures over time, provided the overall level of protection is not reduced. The Customer is responsible for its own secure use of the Services, including protecting administrator credentials, enabling multi-factor authentication and configuring access controls.
7.Sub-processors
The Customer gives general authorisation for Zirozen to engage Sub-processors. The current list is in Annex III.
- Zirozen will impose on each Sub-processor data protection obligations no less protective than those in this DPA, and remains fully liable to the Customer for each Sub-processor’s performance.
- Zirozen will notify the Customer of any new Sub-processor at least 30 days before it starts processing Customer Personal Data, by updating Annex III and emailing customers who subscribe to updates at info@trinetriops.com.
- The Customer may object on reasonable data protection grounds within that notice period. The parties will discuss the objection in good faith. If no reasonable solution is found, the Customer may terminate the affected Services and receive a pro-rata refund of prepaid fees for the remaining term.
- In an emergency affecting the security or availability of the Services, Zirozen may replace a Sub-processor with shorter notice and will inform the Customer as soon as possible.
8.Data subject requests
The Services give the Customer tools to access, correct, export and delete Customer Personal Data. If Zirozen receives a request from a Data Subject relating to Customer Personal Data, it will direct the person to the Customer (where it can identify them) and will not respond directly except as the Customer instructs or the law requires. Taking into account the nature of the processing, Zirozen will provide reasonable assistance to help the Customer respond to Data Subject requests and grievances within the time limits set by Data Protection Laws.
9.Personal data breaches
Zirozen will notify the Customer without undue delay, and in any event within 48 hours, after becoming aware of a Personal Data Breach. The notice will include, as far as then known:
- the nature of the breach, including the categories and approximate number of Data Subjects and records concerned;
- the likely consequences;
- the measures taken or proposed to address the breach and reduce its effects;
- a contact point for further information.
Zirozen will provide further information as it becomes available, take reasonable steps to contain and remedy the breach, and give reasonable assistance to help the Customer meet its own notification obligations, including to the Data Protection Board of India, EU and UK supervisory authorities, and affected individuals. Zirozen will also report cyber security incidents to CERT-In where Indian law requires it. Notifying a breach is not an admission of fault.
10.Impact assessments and consultations
Zirozen will give the Customer reasonable information and assistance to carry out data protection impact assessments and prior consultations with regulators, where required by Data Protection Laws and relating to the Customer’s use of the Services. Zirozen may charge reasonable fees for assistance beyond providing its standard documentation.
11.Audits and certifications
Zirozen maintains ISO/IEC 27001:2022 certification for the Services. On written request, and subject to confidentiality, Zirozen will provide the Customer with its current certificate, a summary of recent third-party penetration test results, and completed security questionnaires reasonably required by the Customer.
If that information is not sufficient to demonstrate compliance with this DPA, or a regulator requires it, the Customer (or an independent auditor bound by confidentiality and not a competitor of Zirozen) may carry out an audit, no more than once every 12 months unless following a Personal Data Breach or regulatory demand. The Customer must give at least 30 days’ notice, agree the scope in advance, conduct the audit during business hours without disrupting operations or compromising other customers’ data, and bear its own costs.
12.International transfers
Zirozen is based in India and processes Customer Personal Data in the hosting regions described in Annex I. Zirozen may transfer Customer Personal Data to other countries, including India, only in compliance with Data Protection Laws.
Transfers from the EEA
Where Customer Personal Data is transferred from the EEA to a country without an adequacy decision, the SCCs are incorporated into this DPA as follows: Module Two (controller to processor) applies where the Customer is a controller, and Module Three (processor to processor) applies where the Customer is a processor. For the SCCs:
- in Clause 7, the optional docking clause applies;
- in Clause 9, Option 2 (general written authorisation) applies, with the notice period in the Sub-processors section;
- in Clause 11, the optional language does not apply;
- in Clauses 17 and 18, the law and courts of Ireland apply;
- Annexes I, II and III of the SCCs are completed with the information in the Annexes to this DPA.
Transfers from the UK
For transfers from the UK, the SCCs as incorporated above apply as amended by the UK Addendum. Table 1 is completed with the party details in Annex I, Table 2 with the modules and options above, Table 3 with the Annexes to this DPA, and in Table 4 either party may end the UK Addendum as allowed by its Section 19.
Transfers from Switzerland
For transfers from Switzerland, the SCCs apply with references to the GDPR read as references to the Swiss FADP, the Swiss Federal Data Protection and Information Commissioner as the competent supervisory authority, and “Member State” read to include Switzerland so that Swiss data subjects can enforce their rights there.
Other countries
Where other Data Protection Laws require a transfer mechanism (for example Brazil’s LGPD, Saudi Arabia’s PDPL or South Africa’s POPIA), the parties agree that the terms of this DPA, including the SCCs where accepted by the relevant authority, apply as that mechanism. Zirozen will comply with any restrictions on transfers notified by the Government of India under the DPDP Act.
If there is a conflict between this DPA and the SCCs or UK Addendum, the SCCs or UK Addendum prevail.
13.Return and deletion of data
During the subscription term, the Customer can export Customer Personal Data using the Services. After the Agreement ends, the Customer has 30 days to export its data. Zirozen will then delete Customer Personal Data from active systems within 30 days, and from backups within X days as they expire in the normal cycle, unless the law requires it to keep some data. Any retained data remains protected by this DPA and is processed only as required by law. On request, Zirozen will confirm deletion in writing.
For on-premises deployments, the Customer holds Customer Personal Data in its own environment and is responsible for its deletion. Zirozen will delete any Customer Personal Data it received for support within the same periods.
14.Regional terms
The following terms apply in addition to the rest of this DPA where the relevant law applies.
IndiaDPDP Act, 2023
The Customer is the data fiduciary and engages Zirozen as a data processor under a valid contract, as required by Section 8(2) of the DPDP Act. Zirozen will process personal data only to provide the Services, maintain reasonable security safeguards, assist the Customer in handling data principal requests and grievances, delete personal data when the Customer withdraws it or the purpose is fulfilled as instructed, and notify the Customer of any personal data breach so the Customer can inform the Data Protection Board and affected data principals. Where the Customer processes data of children or persons with disabilities, the Customer is responsible for obtaining verifiable consent from the parent or lawful guardian.
United StatesCCPA and other state privacy laws
Zirozen acts as a service provider or processor. Zirozen will not: sell or share Customer Personal Data (as those terms are defined in the CCPA); retain, use or disclose it for any purpose other than the business purposes set out in the Agreement, or outside the direct business relationship between the parties; or combine it with personal information received from others, except as the CCPA permits. Zirozen will comply with its obligations under the CCPA, provide the same level of privacy protection the CCPA requires, and notify the Customer if it can no longer meet these obligations. The Customer may take reasonable steps to stop and remediate unauthorised use. Zirozen certifies that it understands and will comply with these restrictions.
16.Liability
Each party’s liability under or in connection with this DPA is subject to the limitations and exclusions of liability in the Agreement, except where Data Protection Laws or the SCCs do not allow such limitation, including liability owed directly to Data Subjects under the SCCs.
17.Term, precedence and general terms
- Term. This DPA lasts for as long as Zirozen processes Customer Personal Data, including after the Agreement ends until deletion is complete.
- Precedence. If there is a conflict, the following order applies: the SCCs and UK Addendum; then this DPA; then the Agreement.
- Changes. Zirozen may update this DPA to reflect changes in law or the Services, provided the changes do not reduce the protection of Customer Personal Data. Zirozen will post updates on this page and notify customers of material changes.
- Governing law. Except as required by the SCCs or Data Protection Laws, this DPA is governed by the law and jurisdiction set out in the Agreement.
- Severability. If any part of this DPA is found invalid, the rest remains in effect.
Annex I: Details of processing
A. Parties
| Data exporter | Data importer | |
|---|---|---|
| Name | The Customer named in the Agreement | Zirozen Software Corporation LLP |
| Address | As stated in the Agreement | L801, Safal Parisar-1, South Bopal, Ahmedabad 380058, Gujarat, India |
| Contact | As stated in the Agreement or the Customer’s account | Gaurang Kanpariya, CEO, info@trinetriops.com |
| Activities | Use of the Services | Provision of the Services |
B. Description of processing and transfer
| Categories of data subjects | The Customer’s employees, contractors, administrators and other users of devices, cloud accounts and applications managed through the Services; the Customer’s end clients where the Customer is a managed service provider. |
|---|---|
| Categories of personal data | Names, usernames, business email addresses and user IDs; device identifiers (hostname, serial number, UDID or enrolment ID, IMEI/MEID for corporate-owned devices, MAC and IP addresses); hardware and software inventory; OS, patch, vulnerability and compliance status; performance and experience metrics; file and registry integrity events on customer-configured paths; peripheral and USB events; device location where enabled by the Customer; cloud identity and access metadata; audit logs of administrator and automation actions; GAS AI prompts and outputs; content of support tickets. |
| Sensitive data | None intended. The Services are not designed to process special categories of personal data, and the Customer should not configure them to do so. Precise location, where enabled, is protected by the measures in Annex II and access controls set by the Customer. |
| Frequency | Continuous, for the duration of the Agreement. |
| Nature of processing | Collection, storage, organisation, analysis, retrieval, use (including automated remediation actions directed by the Customer), transmission to integrations enabled by the Customer, and deletion. |
| Purpose | Providing IT and security operations services: asset management, monitoring, vulnerability and patch management, compliance assessment, device control, mobile device management, cloud posture and cost management, AI-assisted analysis and remediation, and support. |
| Duration and retention | For the term of the Agreement and as described in Return and deletion of data. |
| Hosting locations | India (Mumbai), EU (Frankfurt), US (Virginia), Singapore; remote support access from India. |
| Transfers to Sub-processors | As listed in Annex III, for the same subject matter, nature and duration as above. |
C. Competent supervisory authority
For transfers under the SCCs, the supervisory authority of the EU Member State in which the Customer is established or, if the Customer is not established in the EU, where its EU representative is located. For the UK, the Information Commissioner’s Office. For Switzerland, the Federal Data Protection and Information Commissioner.
Annex II: Technical and organisational security measures
| Area | Measures |
|---|---|
| Governance | Information security management system certified to ISO/IEC 27001:2022; documented security and privacy policies reviewed at least annually; named person responsible for security. |
| Encryption | TLS 1.2 or higher for data in transit; AES-256 encryption at rest; managed encryption keys with restricted access and rotation. |
| Agent and device communication | Mutually authenticated, encrypted channels between agents and the platform; code-signed agent releases; tamper protection. |
| Tenant isolation | Logical separation of each customer’s data in the multi-tenant platform, enforced in the application and data layers. |
| Access control | Role-based access for customer administrators; SSO, SCIM and multi-factor authentication; least-privilege, approval-based and logged access for Zirozen staff; access reviews at least quarterly; prompt removal on role change or exit. |
| Logging and monitoring | Centralised security logging and alerting; audit trails of administrator and automation actions; logs retained as required by law, including CERT-In directions. |
| Vulnerability management | Regular vulnerability scanning and patching of Zirozen systems; annual independent penetration testing; responsible disclosure process. |
| Secure development | Secure coding standards, peer code review, dependency and static analysis, and separation of development, test and production environments. Production data is not used for testing. |
| Availability and resilience | Regular encrypted backups; redundancy across availability zones; tested business continuity and disaster recovery plans. |
| Personnel | Background checks where lawful; confidentiality agreements; security and privacy training at onboarding and annually. |
| Physical security | Hosting in data centres operated by providers with ISO 27001 and SOC 2 certifications; controlled access to Zirozen offices. |
| Data minimisation | Customer-configurable collection settings; BYOD support through Android work profile and Apple User Enrollment so personal data stays outside management scope. |
| Incident response | Documented incident response plan, tested at least annually, with customer and regulator notification procedures. |
| Sub-processor management | Security and privacy due diligence before engagement and periodically after; written data protection terms. |
Annex III: Sub-processors
Zirozen uses the following Sub-processors to provide the Services.
| Sub-processor | Purpose | Location |
|---|---|---|
| Cloud hosting provider | Hosting and storage of the Trinetri cloud | Region |
Apple (APNs), Google (Firebase Cloud Messaging and Android Management API) and Microsoft (Graph and Azure APIs) receive limited device or account data only because the Customer enables device management or integrations that require them. Integrations the Customer chooses to connect, such as ServiceNow or Jira, act on the Customer’s behalf under the Customer’s own agreements with those providers and are not Zirozen Sub-processors.