legal

Data ProcessingAgreement.

version 1.0 · effective june 4, 2026

§ 01

Scope, roles, and incorporation

This Data Processing Agreement (“DPA”) forms part of the Terms of Service (or other written agreement) between Sati Technology Inc. (d/b/a Zentrr, “Zentrr”) and the customer entity that accepted them (“Customer”), and applies whenever Zentrr processes Personal Data contained in Customer Content on Customer's behalf.

For that processing, Customer is the controller (or a processor acting on behalf of its own customers) and Zentrr is the processor (or sub-processor). Each party will comply with its own obligations under applicable Data Protection Laws. In the event of a conflict between this DPA and the Terms with respect to the processing of Personal Data, this DPA prevails. Enterprise customers may request a countersigned copy of this DPA (with the Standard Contractual Clauses appended) by contacting privacy@zentrr.com.

§ 02

Definitions

Data Protection Laws” means all laws applicable to the processing of Personal Data under the agreement, including (as applicable) the EU General Data Protection Regulation 2016/679 (“GDPR”), the UK GDPR and Data Protection Act 2018, the Swiss Federal Act on Data Protection (“FADP”), and US state privacy laws including the California Consumer Privacy Act as amended by the CPRA (“CCPA”).

Personal Data” means information relating to an identified or identifiable natural person that is contained in Customer Content and processed by Zentrr on Customer's behalf.

Security Incident” means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to Personal Data processed by Zentrr.

Sub-processor” means a third party engaged by Zentrr to process Personal Data on Customer's behalf.

“Customer Content,” “Output,” and “Specialist” have the meanings given in the Terms. “Controller,” “processor,” “data subject,” and “processing” have the meanings given in the GDPR.

§ 03

Processing instructions and details

Zentrr will process Personal Data only on Customer's documented instructions, including: (a) to provide, secure, and support the Service as described in the Terms; (b) as configured by Customer and its users in the product (Knowledge sources, Connections, Specialist scoping, retention settings); and (c) as further instructed in writing (including support requests). Zentrr will inform Customer if, in its opinion, an instruction infringes Data Protection Laws (and may suspend the affected processing until resolved).

The subject matter, duration, nature and purpose of processing, the types of Personal Data, and the categories of data subjects are set out in Annex A below.

No AI training. Zentrr does not use Customer Content (including Personal Data) to train any AI model. Inference runs on AWS Bedrock; per AWS, prompts and completions are not used to train or improve foundation models. By default, model providers have no access to them.

Optional provider-data-share models. Certain frontier models (currently Claude Fable 5) are offered by AWS Bedrock only under a provider_data_shareretention mode and are disabled by default. Where an authorized user of Customer explicitly enables such a model on a specific agent, Customer instructs Zentrr (as a documented processing instruction, recorded in Customer's audit log) to permit sharing of that agent's prompts and completions with the model provider (Anthropic), retained by the provider for up to thirty (30) days for trust & safety and abuse detection only — never for model training. This applies solely to the opted-in agent. Customer remains responsible for assessing the suitability of such a model for any Special Categories of Personal Data or other regulated data it processes.

§ 04

Confidentiality

Zentrr ensures that personnel authorized to process Personal Data are bound by written confidentiality obligations or an appropriate statutory duty of confidentiality, are granted access on a least-privilege basis, and receive training appropriate to their role.

§ 05

Security measures

Taking into account the state of the art and the nature of the Personal Data processed, Zentrr implements and maintains the technical and organizational measures set out in Annex B(the “Security Measures”), including encryption at rest (AES-256 with AWS KMS) and in transit (TLS 1.3), per-tenant isolation enforced by PostgreSQL row-level security, and audit logging. Zentrr may update the Security Measures from time to time, provided the updates do not materially reduce the overall protection of Personal Data.

A summary of the current security architecture is published at zentrr.com/security.

§ 06

Sub-processors

Customer provides general authorization for Zentrr to engage Sub-processors. The current list — including purpose, location, and category for each — is published at zentrr.com/legal/subprocessors and is incorporated into this DPA.

Zentrr will provide at least thirty (30) days' notice before adding or replacing a Sub-processor that materially handles Customer Content (via email to account admins or in-product notice). Customer may object on reasonable, documented data-protection grounds within that window; if the parties cannot resolve the objection, Customer may terminate the affected portion of the Service and receive a pro-rata refund of prepaid fees for the unused period.

Zentrr imposes data-protection obligations on each Sub-processor that are no less protective than this DPA and remains responsible for each Sub-processor's performance.

Third-party channels and connectors that Customerchooses to connect (Slack, Microsoft 365, Google Workspace, Salesforce, an AMS or EHR, etc.) act on Customer's instructions under Customer's own agreements with those providers; they are not Zentrr Sub-processors.

§ 07

Data subject requests

Taking into account the nature of the processing, Zentrr will assist Customer, by appropriate technical and organizational measures and insofar as reasonably possible, in responding to data subject requests under Data Protection Laws (access, rectification, erasure, restriction, portability, objection). The Service's built-in capabilities — per-organization data scoping, export, and deletion — are the primary means of assistance. If a data subject contacts Zentrr directly about Personal Data processed on Customer's behalf, Zentrr will promptly forward the request to Customer and will not respond substantively except as required by law.

§ 08

Security incidents

Zentrr will notify Customer without undue delay, and in any event within seventy-two (72) hours, after becoming aware of a Security Incident affecting Customer's Personal Data. The notification will describe, to the extent known: the nature of the incident, the categories and approximate volume of Personal Data and data subjects concerned, the measures taken or proposed to address it, and a contact point for further information.

Zentrr will take reasonable steps to contain and remediate the incident and will provide information reasonably required for Customer to meet its own notification obligations. Zentrr's notification of a Security Incident is not an acknowledgment of fault or liability.

§ 09

International transfers

Zentrr processes and stores Customer Content in the United States (primary region AWS us-east-1; dedicated-region deployments available on Enterprise). Where Data Protection Laws of the EEA, the United Kingdom, or Switzerland apply to a transfer of Personal Data to Zentrr in the United States:

(a) the EU Standard Contractual Clauses approved by Commission Implementing Decision (EU) 2021/914 (“SCCs”), Module Two (controller → processor) or Module Three (processor → processor) as applicable, are incorporated into this DPA by reference, with Customer as data exporter and Zentrr as data importer; Annexes I and II of the SCCs are populated by Annex A and Annex B of this DPA; the optional docking clause applies; the governing law and forum are those of Ireland;

(b) for UK transfers, the SCCs apply as amended by the UK International Data Transfer Addendum issued by the ICO; and (c) for Swiss transfers, the SCCs apply with the adaptations required by the FDPIC, with “Member State” read to include Switzerland and data subjects able to enforce their rights in Switzerland.

§ 10

US state privacy laws (CCPA and analogues)

Where the CCPA or another US state privacy law applies, Zentrr acts as Customer's “service provider” or “processor.” Zentrr will not: (a) sell or share Personal Data; (b) retain, use, or disclose Personal Data for any purpose other than performing the Service under the agreement or as permitted by law; (c) retain, use, or disclose Personal Data outside the direct business relationship with Customer; or (d) combine Personal Data with personal information from other sources except as permitted for service providers.

Zentrr certifies that it understands these restrictions and will comply with them, will notify Customer if it can no longer do so, and grants Customer the right to take reasonable steps to stop and remediate unauthorized use of Personal Data. See also Do Not Sell or Share.

§ 11

Audits and reports

Zentrr will make available information reasonably necessary to demonstrate compliance with this DPA, including its security documentation, sub-processor list, compliance posture reports, and — once issued — its SOC 2 Type II report (target Q3 2026). The parties agree these materials satisfy Customer's audit rights in the first instance.

Where Data Protection Laws grant a non-waivable audit right, Customer (or its mandated independent auditor, not a Zentrr competitor) may audit Zentrr's compliance with this DPA no more than once per twelve (12) months, on at least thirty (30) days' written notice, during business hours, subject to reasonable confidentiality and security requirements, at Customer's expense, and without access to other customers' data or to Sub-processor facilities (Sub-processor compliance is demonstrated through their own certifications and reports).

§ 12

Return and deletion

During the term, Customer can export Customer Content through the Service's built-in export capabilities. Upon termination or expiration, Zentrr will, at Customer's choice, return or delete Personal Data: account data is deleted within thirty (30) days of a honored deletion request; chat messages follow the organization's configured retention window (ninety (90) days by default); audit logs follow the retention period of Customer's tier as described in the Privacy Policy.

Residual copies in encrypted backups are purged on the standard backup rotation cycle. Zentrr may retain Personal Data to the extent required by law, subject to the protections of this DPA.

§ 13

Protected health information (BAA)

This DPA does not authorize the processing of protected health information (“PHI”) under HIPAA. If Customer is a covered entity or business associate and intends to submit PHI to the Service, the parties must first execute a Business Associate Agreement (available on Practice tier and above); the BAA governs PHI in the event of any conflict with this DPA.

§ 14

Liability and order of precedence

Each party's liability arising out of or related to this DPA (including the SCCs) is subject to the limitations and exclusions of liability in the Terms, and liability under this DPA and the Terms is aggregated, not cumulative. Nothing in this section limits a data subject's rights under the SCCs or either party's liability where Data Protection Laws do not permit it to be limited.

§ 15

Term

This DPA takes effect when the Terms take effect (or, if later, when Customer first submits Personal Data to the Service) and remains in force as long as Zentrr processes Personal Data on Customer's behalf, surviving termination of the Terms until all Personal Data is returned or deleted under § 12.

§ A

Annex A — Details of processing

Subject matter & duration: processing of Personal Data contained in Customer Content to provide the Zentrr Service, for the term described in § 15.

Nature & purpose: hosting and storage; AI inference to generate Outputs (drafts, summaries, packets, replies) for human review; Knowledge syncing and citation; routing of approvals to the Mailbox; channel delivery as configured by Customer; audit logging; support.

Categories of data subjects:Customer's users and personnel; Customer's clients, patients, policyholders, or other end customers; and other individuals whose Personal Data appears in Customer Content.

Types of Personal Data: identification and contact data; professional and employment data; business, financial, insurance, or other records Customer connects or uploads; message content; usage and approval metadata. Special categories only if and to the extent Customer chooses to submit them (PHI requires a BAA per § 13).

Frequency:continuous, as driven by Customer's use. Retention: per § 12.

§ B

Annex B — Technical and organizational measures

Encryption: AES-256 at rest via AWS KMS across database, object storage, and search; TLS 1.3 in transit.

Tenant isolation: per-organization data partitioning enforced at the database row by PostgreSQL row-level security on every query; per-organization Knowledge stores; dedicated single-tenant AWS deployments available on Enterprise.

Access control: role-based access (Admin, OrgManager, TeamManager, User) backed by AWS Cognito with MFA support; least-privilege IAM; production access restricted to authorized personnel.

Network & infrastructure: private VPC subnets, managed AWS services (HIPAA-eligible), WAF at the edge, region-pinned processing.

Logging & monitoring: CloudTrail on all API calls; application-level tamper-evident audit trail of chats, citations, and approvals; alerting on anomalous activity.

AI-specific measures: inference confined to AWS Bedrock (no third-party AI providers); no training of any model on Customer Content; per-organization guardrails and PII detection configurable by policy; human sign-off required in the Mailbox before Specialist actions with external effect.

Resilience & lifecycle: multi-AZ database, encrypted backups on a standard rotation cycle, documented incident response, vendor (Sub-processor) review, and personnel confidentiality and training per § 04.

Questions

Contact privacy@zentrr.com for DPA questions, a countersigned copy with the SCCs appended, or to notify us of a sub-processor objection.