Data Processing Agreement
v1.0.0
This Data Processing Agreement (“DPA”) forms part of the agreement that governs the Customer’s use of Zell’s services (the “Main Agreement”). It applies whenever Zell processes Personal Data on the Customer’s behalf. Terms such as Controller, Processor, Data Subject, Personal Data, Processing and Supervisory Authority have the meanings given to them in the GDPR.
1. Parties and priority
The parties are Zell UG (haftungsbeschränkt), c/o Moritz Beck, Wühlischstraße 55, 10245 Berlin, Germany (“Zell”, “Processor” or “Service Provider”), and the legal entity identified as the customer in the Main Agreement (“Customer”).
This DPA takes effect with the Main Agreement or when it is otherwise accepted by both parties. If its data-protection terms conflict with the Main Agreement, this DPA prevails to the extent of that conflict. The Main Agreement otherwise remains unchanged.
2. Roles and scope
For Customer Personal Data, Customer acts as Controller and Zell acts as Processor. Where Customer processes Personal Data for another Controller, Customer acts as Processor and appoints Zell as its Sub-processor. Each party will comply with the data-protection laws applicable to its role, including Regulation (EU) 2016/679 (“GDPR”) and the German Federal Data Protection Act where applicable.
This DPA covers Customer Personal Data processed to provide Zell’s AI-supported sales coaching and conversation-intelligence services, including call recording or import, transcription, analysis, coaching feedback, voice role plays and avatars, courses and assessments, hiring-assessment features, calendar and meeting integrations, the Zell AI assistant, and related support and security operations, in each case as enabled by Customer.
3. Customer instructions and responsibilities
Zell will process Customer Personal Data only on Customer’s documented instructions, unless Union or Member State law requires otherwise. The Main Agreement, this DPA, Customer’s product configuration and Customer’s authorized use of the services together constitute documented instructions. Additional instructions must be agreed in writing and may be subject to reasonable fees where they require work beyond the services.
If Zell believes an instruction infringes applicable data-protection law, Zell will inform Customer without undue delay and may suspend the affected processing until the parties resolve the issue. If law requires processing beyond Customer’s instructions, Zell will notify Customer before processing unless the law prohibits notice.
Customer is responsible for the lawfulness, fairness and transparency of its processing; for giving required notices and obtaining any required consent; for deciding which meetings, calls, recordings and content are submitted; and for ensuring its instructions and use of the services comply with applicable law. Customer must not intentionally submit Personal Data that is unnecessary for the agreed purposes.
4. Details of processing
The subject matter, nature, purpose and duration of processing, the categories of Data Subjects and the types of Personal Data are described in Annex 1. Zell will process Customer Personal Data for the term of the Main Agreement and for any limited period afterward needed to return or delete it, comply with law, resolve disputes or maintain secure backups.
5. Confidentiality
Zell will ensure that personnel authorized to process Customer Personal Data are bound by confidentiality obligations and receive access only where needed for their duties. These obligations continue after their access ends.
6. Security
Taking into account the state of the art, implementation costs, the nature, scope, context and purposes of processing, and the risk to individuals, Zell will maintain appropriate technical and organizational measures designed to protect Customer Personal Data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure or access. The categories of measures currently used are summarized in Annex 2.
Customer is responsible for securing its own systems and accounts, managing authorized users and permissions, protecting credentials, configuring integrations appropriately, and using available security controls.
7. Personal Data breaches
Zell will notify Customer without undue delay after becoming aware of a Personal Data Breach affecting Customer Personal Data. To the extent reasonably available, Zell will provide information about the nature of the incident, affected data and individuals, likely consequences, and measures taken or proposed. Information may be provided in phases as the investigation progresses.
Zell will take reasonable steps to contain, investigate and remediate the breach. Customer remains responsible for deciding whether notifications to Supervisory Authorities or Data Subjects are required, unless applicable law assigns that obligation to Zell.
8. Data Subject requests
Taking into account the nature of the processing, Zell will provide reasonable assistance through appropriate technical and organizational measures so Customer can respond to requests to exercise Data Subject rights. If Zell receives a request relating to Customer Personal Data directly from a Data Subject, Zell will forward it to Customer without undue delay and will not respond substantively unless Customer authorizes it or law requires it.
9. Compliance assistance
Considering the nature of processing and the information available to Zell, Zell will reasonably assist Customer with security obligations, breach notifications, data-protection impact assessments and prior consultations under Articles 32 to 36 GDPR. Assistance that requires material work beyond the services may be charged at reasonable rates agreed in advance.
10. Sub-processors
Customer gives Zell general authorization to engage Sub-processors where necessary to provide, secure, support or improve the services. Zell will impose written data-protection obligations on each Sub-processor that are no less protective in substance than the obligations applicable to Zell under this DPA, to the extent relevant to the services performed.
Zell maintains its current Sub-processor list at getzell.com/legal/sub-processors. Zell will provide reasonable advance notice of a new Sub-processor where the change may materially affect the processing of Customer Personal Data. Customer may object on reasonable data-protection grounds. The parties will work in good faith toward a commercially reasonable solution; if none is available, Customer may terminate the affected service as provided in the Main Agreement.
Zell remains responsible for each Sub-processor’s performance of its data-protection obligations to the same extent Zell would be responsible if it performed the relevant services itself.
11. International transfers
Zell will not transfer Customer Personal Data to a country outside the European Economic Area unless the transfer complies with Chapter V GDPR. Where required, Zell will rely on an adequacy decision, the European Commission’s Standard Contractual Clauses, or another legally recognized safeguard, and will implement supplementary measures where appropriate.
Where Customer’s use of the services results in a restricted transfer from Customer to Zell that is not otherwise covered by an adequacy decision, the applicable controller-to-processor or processor-to-processor module of the then-current European Commission Standard Contractual Clauses is incorporated by reference. Germany is the governing Member State for the optional clauses, and the competent Supervisory Authority is determined under the GDPR.
12. Return and deletion
At the end of the services involving processing, Zell will, at Customer’s choice and subject to applicable law, return or delete Customer Personal Data and delete existing copies. Customer should export any data it wishes to retain before termination. Zell may retain data where required by law or in backups until those backups are overwritten through ordinary retention cycles, provided retained data remains protected and is not used for other purposes.
Where product functionality permits, Customer may delete calls, recordings, documents, users or other content during the term. Zell will propagate deletion to relevant systems and Sub-processors in accordance with its standard technical processes and the capabilities of those systems.
13. Information and audits
Zell will make available information reasonably necessary to demonstrate compliance with Article 28 GDPR. Zell may satisfy this obligation through security documentation, certifications or audit reports where available, and responses to reasonable questionnaires.
If that information is insufficient, Customer may request an audit by itself or an independent auditor bound by confidentiality. Audits must be proportionate, limited to systems relevant to Customer Personal Data, conducted during normal business hours with reasonable advance notice, and designed to avoid disruption or risk to other customers. Unless required by a Supervisory Authority or following a material incident, audits are limited to once in any twelve-month period. Customer bears its audit costs and may be charged for Zell’s reasonable assistance.
14. AI-enabled processing
To provide AI-enabled features, Zell and its authorized Sub-processors may process recordings, transcripts, prompts, documents, scorecards, feedback, meeting context and generated outputs. Zell will limit that processing to providing the services, following Customer’s documented instructions, maintaining security and reliability, and meeting legal obligations.
Customer Personal Data will not be used to train general-purpose AI models unless Customer expressly authorizes that use in writing. Zell will require AI Sub-processors to process Customer Personal Data under contractual restrictions consistent with this DPA.
Customer is responsible for appropriate human oversight of AI-generated output and for determining whether the services are suitable for its intended use, including any obligations that apply to Customer as a deployer under the EU AI Act.
15. Liability, term and governing law
The liability limitations and exclusions in the Main Agreement apply to this DPA to the extent permitted by law. Nothing in this DPA limits liability that cannot legally be limited.
This DPA remains in effect while Zell processes Customer Personal Data. Amendments must be agreed in writing, except that Zell may update operational details that do not materially reduce the level of protection and may update this DPA as permitted by the Main Agreement. German law applies, and the courts of Berlin have jurisdiction, subject to mandatory data-protection law and the rights of competent Supervisory Authorities.
Annex 1 — Processing details
Subject matter and purposes
Processing needed to provide, operate, secure, maintain and support Zell’s business-to-business AI sales-coaching, conversation-intelligence and related assessment services selected by Customer.
Nature of processing
Collection, recording, organization, structuring and storage of Customer-provided data.
Retrieval, consultation, transmission and display to authorized Customer users.
Recording or import of calls and meetings; transcription and speaker processing.
Automated analysis, classification, scoring and generation of coaching feedback, reports and AI-assisted responses.
Integration with calendars, meeting platforms, customer systems and other services enabled by Customer.
Restriction, export, return, deletion and anonymization where applicable.
Categories of Data Subjects
Customer employees, contractors, administrators and other authorized users.
Participants in calls and meetings, including prospects, customers and partners of Customer.
Candidates and evaluators where Customer enables hiring-assessment features.
Individuals whose information appears in Customer-uploaded documents, playbooks, transcripts or other content.
Types of Personal Data
Identity, account and business-contact information, such as names, work email addresses, roles and organization details.
Calendar and meeting metadata, such as event titles, meeting links, participants and timestamps.
Audio or video recordings, transcripts, speaker labels, notes and communications content.
Sales-coaching data, including scenarios, scorecards, evaluations, feedback, learning progress and generated reports.
Hiring-assessment submissions, candidate contact details and evaluation results where that module is enabled.
Customer-uploaded documents, playbooks, knowledge content, prompts and AI-generated outputs.
Technical and usage data, including IP addresses, device or browser information, authentication records, logs and support communications.
Special categories and sensitive data
The services are not designed for intentional processing of special categories of Personal Data under Article 9 GDPR or data relating to criminal convictions under Article 10 GDPR. Customer must not submit such data unless the parties have agreed appropriate instructions and safeguards in writing. Recordings and free-text content may nevertheless contain sensitive information incidentally; Customer is responsible for minimizing such data and establishing a lawful basis.
Frequency and duration
Processing occurs continuously or as initiated by Customer during the term of the Main Agreement. Retention follows Customer configuration, product functionality, the Main Agreement, this DPA and applicable legal requirements.
Annex 2 — Technical and organizational measures
Zell maintains a risk-based security program. Measures may evolve as technology and the services change, provided the overall level of protection is not materially reduced. Measures include, as appropriate:
Access controls based on business need, authentication safeguards, role and permission management, and periodic access review.
Encryption of data in transit and encryption at rest where supported by the relevant systems and service providers.
Logical tenant separation and controls designed to prevent unauthorized cross-customer access.
Secure software-development practices, change management, code review, dependency management and vulnerability remediation.
Logging, monitoring, alerting and incident-response processes designed to detect and address security events.
Backup, recovery and resilience measures appropriate to the availability needs of the services.
Controlled use of private storage and time-limited or signed access mechanisms for recordings and documents where applicable.
Vendor due diligence and contractual security and data-protection commitments for Sub-processors.
Confidentiality commitments, security awareness and limited access for personnel handling Customer Personal Data.
Processes for deletion, account or tenant offboarding, and removal of imported media from relevant integration providers where supported.
Contact
Questions or notices concerning this DPA may be sent to hey@getzell.com or to Zell UG (haftungsbeschränkt), c/o Moritz Beck, Wühlischstraße 55, 10245 Berlin, Germany.
Now live
Partner program launched
We’re opening a new way for agencies, creators, and operators to grow with us.
Explore the program