Back home

Legal · DPA

Data Processing Addendum.

Draft · under legal reviewLast updated · June 2026

This page is a non-binding working draft for legal review. It does not represent a completed compliance assessment, signed data-processing agreement, or certification.

Current scope

SubZero processes account, workspace, subscription, imported CSV, and optional connector data to provide subscription tracking and optimization features. Customers remain responsible for having the authority to submit workspace and member data.

Optional connectors

Connector data is processed only when a user enables a connector marked Live or Beta. The connector setup flow describes requested permissions. Coming-soon connectors do not process customer data.

Service providers

SubZero uses service providers for hosting, database storage, authentication, payment processing, email delivery, analytics, error monitoring, and optional connectors. A verified subprocessor list, processing locations, and transfer terms will be published before this draft becomes binding.

Security measures

Current application controls include HTTPS for public network traffic, authenticated access, scoped connector permissions, server-side authorization checks, code review, and secret separation by environment. The final DPA will contain only controls verified against the production deployment.

Deletion and retention

Account export, deletion, connector revocation, object deletion, and retention enforcement are launch-readiness work. Verified timelines will be added when those controls are production-ready.

Execution

This draft cannot currently be executed. A counsel-reviewed version will describe the parties, processing instructions, subprocessors, transfer terms, security measures, audit process, and signature mechanism.

This working draft is published for transparency. It is not legal advice and is not yet binding.