Legal
Data Processing Summary (DPA)
A plain-language summary of how Zivvy processes Customer Data. Request a signed DPA when your procurement process needs one.
Last updated: 2026-07-24
This page summarizes how Zivvy processes personal data contained in Customer Data on behalf of customer organizations. It is not a substitute for a negotiated Data Processing Addendum (DPA). If you need a signed DPA for GDPR, similar laws, or vendor review, email support@zivvy.xyz.
Related: Privacy Policy, Security, Terms of Service.
1. Roles
- Customer (controller): your organization decides why and how Customer Data is processed in Zivvy (CRM records, invoices, employees, inventory, etc.).
- Zivvy (processor / service provider): we process Customer Data only to provide, secure, support, and improve the service under your instructions (including configuration you set in-product).
2. Nature and purpose of processing
Processing includes hosting, storage, retrieval, transmission, backup, logging, and support access as needed to operate multi-module ERP workflows (sales, stock, finance, HR, manufacturing, and related modules enabled on your plan).
3. Categories of data and data subjects
Categories depend on what you enter into Zivvy. Typical examples: contact and customer records; order and invoice data; inventory movements; employee/HR fields if you use those modules; user account identifiers for your teammates. Data subjects may include your employees, customers, suppliers, and other business contacts.
You should not upload special-category data unless your plan, configuration, and legal basis allow it and you have assessed the risk.
4. Region and location of processing
Cloud workspaces are region-pinned. At signup you choose India, EU, or US; Customer Data for that workspace is hosted in the selected region and is not moved across regions without your explicit action. Limited operational metadata (authentication, billing identifiers via Polar, transactional email) may involve subprocessors outside the primary region under contract.
5. Subprocessors
We use infrastructure and service providers under written agreements. Material categories include: regional hosting, email delivery, monitoring, and Polar for subscription billing (Polar primarily processes account/billing data, not your full ERP Customer Data store). A current list is available on request from support@zivvy.xyz.
6. Security measures
We apply administrative, technical, and organizational measures appropriate to the risk — including encryption in transit, access controls, tenant isolation, and operational monitoring. See Security for a product-oriented overview. We do not claim certifications on this page that we have not completed.
7. Assistance with rights and incidents
We will reasonably assist with data subject requests that relate to Customer Data we process, typically by enabling admin tools or supporting your investigation. Suspected personal-data breaches affecting Customer Data will be communicated to your organization without undue delay once we become aware, with information reasonably available at the time.
8. Return and deletion
During an active subscription you may export data using product tools or by requesting help from support. After termination or written request, we will delete or return Customer Data within a commercially reasonable period, except for backups retained for a limited time and records we must keep by law or for billing disputes.
9. Self-hosted Business deployments
If you self-host on the Business plan, you typically control the hosting environment. In that case, Zivvy’s processor obligations for cloud hosting may not apply to infrastructure you operate; license and support terms still apply. Clarify roles in your order or DPA.
10. Request a signed DPA
Email support@zivvy.xyz with your company name, primary contact, chosen data region, and any required template. We will work with reasonable, industry-standard DPA language.