Data Processing Agreement
Effective date: June 28, 2026 · Version 1.0
Self-service: no back-and-forth required
This Data Processing Agreement ("DPA") is automatically incorporated into and effective as part of your acceptance of iZop AI's Terms of Service. If you use iZop AI, both parties have already agreed to these terms.
For your own records or to satisfy a client requirement: click Download / Print PDF, fill in your company details in the signature block at the bottom, sign it, and keep a copy. You do not need to send it back to us. No countersignature from Xethra LLC is required because the DPA is already binding through your Terms of Service acceptance.
If a specific client or regulator requires a wet-ink or separately countersigned copy, email support@izop.ai and we will arrange it.
DATA PROCESSING AGREEMENT
iZop AI (Xethra LLC) — Version 1.0 — Effective June 28, 2026
Article 1. Parties and definitions
Processor: Xethra LLC, a Montana limited liability company, 1001 S Main St Ste 600, Kalispell, MT 59901, USA, operating the iZop AI service (“we,” “us,” “Processor”).
Controller: The customer entity that has accepted the iZop AI Terms of Service (“you,” “Controller”). Where you are a marketing agency or social media manager using iZop AI on behalf of your clients (“Brands”), you are the Controller for those Brands' data.
Terms not defined here have the meanings given in Regulation (EU) 2016/679 (“GDPR”) or applicable data protection law.
Article 2. Subject matter, nature, and purpose
The Processor provides a social media management platform (scheduling, publishing, unified inbox, analytics, AI-assisted content tools) and processes personal data on behalf of the Controller for the sole purpose of delivering those services as described in the Terms of Service and the iZop AI Privacy Policy.
Processing activities include: storing and publishing social media content; retrieving and displaying analytics and inbox data from connected platforms; generating AI-assisted captions and reply drafts using the minimal content you provide; and operating background sync jobs on your behalf.
Article 3. Categories of personal data and data subjects
Personal data processed: Social media profile information (names, handles, profile images); post captions and media; comments left on your posts (including commenter names and profile images); direct messages and conversation threads (including sender names, profile images, and message text); follower and engagement analytics.
Special categories: The Processor does not intentionally process special categories of personal data under GDPR Article 9. The Controller is responsible for ensuring that content it publishes or retrieves through the Service does not contain such data unless an appropriate legal basis exists.
Data subjects: The Controller's social media followers, audience members, and anyone who sends a message to or comments on the Controller's connected social accounts.
Article 4. Duration
This DPA applies for as long as the Processor processes personal data on behalf of the Controller (i.e. for as long as the Controller has an active iZop AI account with connected social accounts). Obligations that by nature survive termination (data deletion, confidentiality, breach notification) continue after the Controller's account is closed or the service relationship ends.
Article 5. Controller's obligations
The Controller warrants and agrees that it:
- Has a lawful basis under applicable law to process the personal data it shares with the Processor.
- Has provided (or will provide) appropriate privacy notices to data subjects whose data is processed through the Service.
- Is authorized by each Brand whose social accounts it connects to iZop AI (where applicable).
- Will promptly notify the Processor of any instructions that in the Controller's view would require the Processor to violate applicable law.
- Will supervise the Processor's activities as required by applicable law, including conducting audits where needed.
Article 6. Processor's obligations
6.1 Processing on instructions only
The Processor will process personal data only on the Controller's documented instructions (as established through use of the Service and these terms), unless required otherwise by applicable law. In that case, the Processor will inform the Controller of that legal requirement before processing unless prohibited by law.
6.2 Confidentiality
The Processor ensures that persons authorized to process personal data are bound by appropriate confidentiality obligations and receive adequate training in data protection.
6.3 Security (GDPR Article 32)
The Processor implements technical and organizational measures appropriate to the risk, including those described on the Security page. These include: TLS 1.2+ encryption in transit; AES-256 encryption at rest; encrypted OAuth token storage; short-lived authenticated sessions; payment processing via PCI DSS Level 1 provider; private object storage with signed URLs; connection pooling and rate limiting; environment variable isolation for secrets.
6.4 Sub-processors
By accepting the Terms of Service and this DPA, the Controller grants general authorization for the Processor to engage sub-processors. The current sub-processors are listed in Annex III. The Processor will notify the Controller of any new or changed sub-processor with at least 14 days' notice by posting an updated Annex III at this URL. The Controller may object within 14 days; if no resolution is reached the Controller may terminate the service.
6.5 Data subject rights
The Processor will assist the Controller in responding to requests from data subjects exercising their rights (access, rectification, erasure, restriction, portability, objection) to the extent technically feasible given the nature of the processing. Data subjects wishing to exercise rights related to data the Processor holds on behalf of the Controller should contact the Controller in the first instance.
6.6 Data breach notification
The Processor will notify the Controller without undue delay, and in any case within 72 hours of becoming aware, of a personal data breach affecting the Controller's data. Notification will include at minimum: nature of the breach; categories and approximate number of affected data subjects and records; likely consequences; measures taken or proposed. The Controller remains responsible for notifying supervisory authorities and affected data subjects as required by law.
6.7 Data protection impact assessments
The Processor will provide reasonable assistance to the Controller in conducting data protection impact assessments (DPIAs) and in prior consultations with supervisory authorities, where required, taking into account the nature of processing and the information available to the Processor.
6.8 Audit rights
The Processor will make available to the Controller all information reasonably necessary to demonstrate compliance with this DPA. The Processor will permit and cooperate with audits or inspections conducted by the Controller or its authorized auditor, subject to reasonable advance notice (at least 30 days), agreement on scope, confidentiality obligations, and the Controller bearing any third-party audit costs. The Processor may object to an auditor with a reasonable conflict of interest.
6.9 Return and deletion
Upon termination of the service relationship or on the Controller's request, the Processor will delete or return personal data as requested, and delete existing copies unless applicable law requires continued storage. The Processor may retain anonymized or aggregated data that does not identify the Controller or any data subject.
Article 7. International transfers
Where the Processor transfers personal data from the European Economic Area, United Kingdom, or Switzerland to countries not subject to an adequacy decision, the Processor relies on the European Commission's Standard Contractual Clauses (SCCs) (Commission Implementing Decision (EU) 2021/914 for Controller-to-Processor transfers, Modules 2 and 3) or equivalent approved transfer mechanisms. The SCCs are hereby incorporated by reference and form part of this DPA.
Current hosting regions: application infrastructure (Vercel) in the United States; database (Supabase on AWS) in the Asia-Pacific region (Seoul, South Korea). South Korea is subject to an EU adequacy decision. AI processing (OpenAI) in the United States under an API Data Processing Addendum.
Article 8. Governing law
This DPA is governed by the law of the State of Montana, USA, without regard to its conflict of law principles, except to the extent that GDPR or applicable EU/UK/Swiss data protection law mandates otherwise. For EEA and UK data subjects, the relevant supervisory authority shall have jurisdiction over GDPR-specific disputes.
Annex I. Technical and organizational security measures
- Encryption in transit: TLS 1.2 or higher for all data between client and server.
- Encryption at rest: AES-256 on Supabase-managed PostgreSQL (AWS).
- OAuth token storage: access tokens encrypted in the database; minimum required permissions requested per platform.
- Authentication: Supabase Auth with email OTP and Google OAuth; no plaintext passwords; short-lived rotating JWTs.
- Payment data: processed by Stripe (PCI DSS Level 1); no card numbers stored by the Processor.
- Media storage: Cloudflare R2 (private); files served only via short-lived signed URLs.
- Infrastructure: serverless edge deployment (Vercel); connection pooling; rate limiting; environment variable isolation for all secrets.
- Access control: no direct production database access in normal operations; principle of least privilege.
- Vulnerability disclosure: security@izop.ai with 48-hour response target; responsible disclosure policy.
Annex II. Sub-processor list
Last updated: June 29, 2026. The current list is also published at izop.ai/legal/subprocessors.
| Sub-processor | Purpose | Location |
|---|---|---|
| Vercel Inc. | Application hosting and serverless infrastructure | USA |
| Supabase Inc. (AWS ap-northeast-2) | Database hosting and authentication | South Korea |
| Cloudflare Inc. (R2) | Media file storage | USA / Global CDN |
| Stripe Inc. | Payment processing and billing | USA |
| Resend Inc. | Transactional email delivery | USA |
| OpenAI, L.L.C. | AI-assisted content generation (optional features only) | USA |
| Google LLC (Analytics) | Aggregated usage analytics (with consent) | USA |
Signatures
This DPA is effective upon the Controller's acceptance of the iZop AI Terms of Service. For record-keeping, both parties may complete the fields below. Print or save as PDF, fill in the Controller section, sign, and keep for your records.
Processor (iZop AI)
Company
Xethra LLC
Address
1001 S Main St Ste 600
Kalispell, MT 59901, USA
Authorized by
Guy Kogen, Founder
Date
June 28, 2026
Signature
Accepted via Terms of Service publication
Controller (Your company)
