← All legal documents

Data Processing Addendum

The processor terms that apply when we handle personal data on your behalf. Incorporated into the Terms of Service, so no signature is required.

Effective 6 September 2026 · For Customers who are controllers of personal data processed in Reckon

This addendum forms part of the Terms of Service between you ("Controller") and Zu Technologies Pvt Ltd ("Processor") and applies whenever we process personal data on your behalf. If your organisation requires a signed copy or your own paper, write to [email protected].

Terms such as personal data, processing, controller, processor, data subject and supervisory authority carry the meanings given in the GDPR, and the equivalent meanings under the UK GDPR, India's DPDP Act and applicable US state privacy laws.

1. Roles

You are the controller of the personal data you bring into Reckon, the data inside your connected ad accounts, including comment authors, and the details of the users you invite. We are your processor for it, and act only on your documented instructions. Your use of the product, and this addendum, are those instructions.

We are an independent controller for a narrow set of data described in the Privacy Policy: account administration, billing, security, and aggregated statistics that identify no one.

2. Details of processing

Subject matter and duration
Providing Reckon, for as long as your workspace is open, plus the deletion periods in section 8.
Nature and purpose
Collecting, storing, organising, analysing and displaying advertising data; generating recommendations and summaries, including with AI models; sending briefs you configure.
Categories of data subject
Your personnel who use the workspace; members of the public who commented on posts behind your ads.
Categories of personal data
Names, email addresses, roles and usage data for users; public display names, comment text and engagement data for commenters; any personal data your ad copy or creative happens to contain.
Special category data
None requested and none required. Do not put it into Reckon.

3. Our obligations

  • Process only on your documented instructions, including for transfers, unless the law requires otherwise, in which case we tell you first, unless that law forbids it.
  • Tell you if, in our opinion, an instruction infringes data protection law.
  • Ensure everyone authorised to process is bound by confidentiality.
  • Implement the technical and organisational measures in section 6.
  • Assist you with data subject requests, impact assessments and consultations with regulators, taking into account the nature of the processing and the information available to us.
  • Make available the information needed to demonstrate compliance, and allow audits as set out in section 9.

4. Your obligations

  • Have a lawful basis for the data you bring into Reckon, including the ad accounts you connect and the comments they surface.
  • Give the notices and hold the consents your own privacy law requires.
  • Keep workspace membership current, and remove people who should no longer see the data.
  • Do not use Reckon for purposes we have not described, and do not introduce special category data.

5. Sub-processors

You give general authorisation for us to engage the sub-processors listed on the sub-processor page. We impose data-protection obligations on each of them no less protective than these, remain liable for their performance, and give 30 days' notice before a new one starts, with a right to object as described there.

6. Security

We maintain measures appropriate to the risk, including encryption in transit and at rest, separate encryption of platform OAuth tokens, per-workspace access scoping enforced server-side, least-privilege staff access, secret management, monitoring and alerting, and regular review. The current measures are described on the Security page and form part of this addendum.

7. Personal data breach

We notify you without undue delay and in any event within 72 hours of becoming aware of a personal data breach affecting your data, with what we know about its nature, the categories and approximate numbers affected, the likely consequences, and the measures taken. We assist you with your own notification duties. We do not notify a supervisory authority or your data subjects on your behalf unless you ask us to.

8. Return and deletion

On termination, or on your request at any time, we delete or return your personal data at your choice. Deletion completes within 30 days from live systems and within 90 days from backups, except where the law requires us to keep a copy, which stays subject to this addendum for as long as we hold it. Export your data before you close the workspace; we do not guarantee retrieval afterwards. The steps are on the deletion page.

9. Audit

On reasonable written notice, no more than once a year unless a regulator or a breach requires otherwise, we will answer a security questionnaire and provide the documentation we hold about our controls. Where that is genuinely insufficient for your compliance obligations, we will discuss an on-site or third-party audit at your cost, scoped so it does not compromise other customers' confidentiality. Requests go to [email protected].

10. International transfers

Where we or a sub-processor process personal data outside the UK or EEA without an adequacy decision, the European Commission's Standard Contractual Clauses (Module Two, controller to processor; Module Three where we onward-transfer to a sub-processor) are incorporated into this addendum by reference, with the UK International Data Transfer Addendum where the UK GDPR applies. You are the data exporter; we are the data importer. Where an optional clause requires a choice, the parties select the option consistent with the terms of this addendum, and the governing law and forum are those in section 15 of the Terms.

11. Liability and precedence

Liability under this addendum is subject to the limitations in the Terms of Service. Where this addendum conflicts with the Terms on the processing of personal data, this addendum prevails; where it conflicts with the Standard Contractual Clauses, the Clauses prevail.