Connor — Data Processing Agreement
Zindex Limited trading as Connor · Version 1.1 · 25 September 2026
This Data Processing Agreement (DPA) forms part of the Agreement between Zindex Limited (Processor) and the Customer named in the Order Form (Controller) under the Connor Terms of Service. It applies when Zindex processes personal data on the Customer's behalf to provide Connor Financial Promotions, including any agreed scheduled promotion monitoring. It does not cover the separate AI Monitoring product or other services unless expressly agreed in a separate scope and processing schedule.
1. Definitions
1.1 Data Protection Law means the UK GDPR, the Data Protection Act 2018 and, where applicable, the EU GDPR, each as amended.
1.2 Customer Personal Data means personal data processed by Zindex on the Customer's behalf in providing the Service.
1.3 Sub-processor means a third party engaged by Zindex to process Customer Personal Data.
1.4 Controller, processor, personal data, processing, data subject and personal data breach have the meanings given in Data Protection Law. Other capitalised terms have the meanings given in the Terms of Service.
2. Roles and scope
2.1 The Customer is the controller and Zindex is the processor of Customer Personal Data. Where the Customer acts as processor for another controller, Zindex is its sub-processor; the Customer must have that controller's authority to appoint Zindex and give the instructions in this DPA.
2.2 The subject matter, nature, purpose and duration of the processing, and the types of personal data and data subjects, are set out in Annex 1 and the completed Order Form Deployment Schedule, which forms part of this DPA. Complete that schedule before processing starts. The Service covers financial promotion reviews, including selected scheduled monitoring of agreed websites and social channels at frequencies up to once daily. The Deployment Schedule records the sources, frequency, material, authorised providers and retention. Employee AI monitoring and endpoint scanning are excluded.
2.3 If this DPA conflicts with the Agreement on personal data, this DPA prevails. Mandatory international transfer terms prevail over this DPA. No variation may reduce protections required by law or those transfer terms.
3. Instructions
3.1 Zindex will process Customer Personal Data only on the Customer's documented instructions, including for international transfers, unless required by applicable law. In that case Zindex will inform the Customer of the legal requirement before processing, unless the law prohibits this on important grounds of public interest. Instructions comprise the Agreement, the completed Deployment Schedule and authorised users' requests within that agreed scope. Use of an unselected feature does not extend the instructions.
3.2 Zindex will tell the Customer promptly if it believes an instruction infringes Data Protection Law.
3.3 Zindex will not use Customer Personal Data to train or fine-tune any AI model that is shared with other customers or offered generally.
3.4 The Customer is responsible for having a lawful basis for the processing and for giving any required notices to data subjects.
3.5 Processing personal data to create anonymous statistics requires documented Customer instructions in the Deployment Schedule, specifying the purpose, permitted fields, aggregation controls and retention. Removing identifiers alone does not establish anonymity. Zindex will not use Customer Personal Data for advertising, shared demonstrations or a shared evaluation corpus.
4. Confidentiality
4.1 Zindex will ensure that everyone authorised to process Customer Personal Data is bound by a duty of confidentiality and accesses it only as needed to provide the Service.
5. Security
5.1 Zindex will implement appropriate technical and organisational measures to protect Customer Personal Data, taking into account the nature of the processing and the risks involved. The measures are described in Annex 2.
5.2 Zindex may update the measures, provided the overall level of protection is not reduced.
6. Sub-processors
6.1 The Customer authorises the Sub-processors identified in the completed Deployment Schedule, by legal entity, service and processing locations. The provider information below supports that record; listing an integration alone does not authorise its use. An alternative AI provider may receive data only if its processing route is authorised.
6.2 Under the Customer's general authorisation for subsequent changes, Zindex will notify its nominated contact directly in writing of an intended addition or replacement, with sufficient information and time to make a reasonable data-protection objection before processing begins. A website update alone is not notice. If the parties cannot resolve the objection, the Customer may terminate the affected Service. Pending resolution, Zindex will use an authorised route or suspend the affected processing.
6.3 Zindex will impose data protection obligations on each Sub-processor that are no less protective than this DPA, and remains liable for their performance.
Provider information
The providers belowsupport Connor's platform and business operations. The signed deployment schedule identifies the selected legal entities, services, processing and access countries, retention and transfer safeguards. Inclusion here does not authorise every integration for every customer.
| Provider | Purpose | Location evidence |
|---|---|---|
| Vercel | Application and website functions | Dublin, Ireland — verified production deployments |
| Vercel | Private file storage | London, United Kingdom — verified connected store |
| Supabase | Database | Ireland — owner-supplied project screenshot; production connection to confirm |
| Clerk | Sign-in and user authentication | Account-specific locations to confirm |
| Anthropic | Selected AI-assisted review | Service and account-specific locations to confirm |
| OpenAI | Selected transcription and AI review | Service and account-specific locations to confirm |
| Resend | Transactional email | Processing and retention locations to confirm |
| Google Workspace | Business and authorised support correspondence | Account-specific storage and access locations to confirm |
| Apify | Selected link retrieval | Processing and access locations to confirm |
A provider's headquarters or default configuration does not establish this deployment's processing locations. Google Workspace supports Zindex's own business correspondence and may process customer material when used for authorised support; its role depends on the purpose.
Any additional retrieval or proxy provider must be identified, assessed and authorised before customer material is sent to it. Both AI providers require selection in the deployment schedule before either can be used as an alternative route.
Upstash and Sentry were not configured in the production deployment inspected during this review. Enabling either requires the applicable supplier review and authorisation.
This information supports the completed Deployment Schedule and does not replace the direct notice required by clause 6.2.
7. International transfers
7.1 Zindex will not transfer Customer Personal Data outside the UK unless the transfer complies with Data Protection Law, using an adequacy decision or regulations, or the International Data Transfer Addendum to the EU Standard Contractual Clauses or another approved mechanism.
7.2 Transfers from the EEA to Zindex in the UK rely on the European Commission's adequacy decision for the UK. If that decision ceases to apply, the parties will put in place the appropriate EU Standard Contractual Clauses.
7.3 The Deployment Schedule must identify storage, backup, remote-access and onward-processing countries and the applicable transfer safeguards, assessments and supplementary measures. Any reliance on adequacy or a data privacy framework is limited to recipients and processing actually covered. If no lawful route is available, the affected transfer must not start or continue.
8. Data subject requests
8.1 Zindex will assist the Customer, by appropriate technical and organisational measures, to respond to requests from data subjects exercising their rights.
8.2 If Zindex receives a request directly, it will forward it to the Customer promptly and will not respond substantively except on the Customer's instructions or as required by law. It may acknowledge receipt and explain the parties' roles.
9. Personal data breaches
9.1 Zindex will notify the Customer without undue delay after becoming aware of a personal data breach affecting Customer Personal Data.
9.2 The notice will describe, as far as then known, the nature of the breach, the categories and approximate number of data subjects and records affected, the likely consequences, the measures taken or proposed, and a contact for further information. Zindex will provide further information as it becomes available without delaying the initial notice for a completed investigation.
9.3 Zindex will take reasonable steps to contain and remedy the breach and will assist the Customer with any notifications it must make.
10. Assistance
10.1 Taking account of the nature of processing and information available to it, Zindex will assist the Customer with its obligations under Articles 32–36, including security, breach notifications, data protection impact assessments and prior consultations with supervisory authorities relating to the Service.
11. Audits
11.1 Zindex will make available to the Customer the information necessary to demonstrate compliance with this DPA and Article 28 of the UK GDPR.
11.2 Zindex will allow and contribute to audits, including inspections, by the Customer or its appointed auditor. Routine audits are limited to one in any 12-month period, on at least 30 days' written notice, during business hours and subject to reasonable confidentiality terms. These limits do not restrict information requests under clause 11.1 or apply to regulator access, legally required audits, urgent investigations, relevant breaches, material changes or reasonable cause concerning compliance. Arrangements and charges must not obstruct legally required access.
12. Deletion and return
12.1 When the Agreement ends, Zindex will, at the Customer's choice, return or delete Customer Personal Data and delete existing copies unless applicable law requires retention. The standard return arrangement provides 30 days of secure export access or an assisted export, followed by deletion within a further 30 days. The Customer may instruct earlier return or deletion. The Deployment Schedule records the formats, deadlines and any specific legal retention requirement.
12.2 The Deployment Schedule records backup and provider-copy expiry periods. Pending deletion, those copies remain protected, beyond ordinary use and accessible only for authorised recovery or legal retention. Any restored data remains subject to deletion instructions.
12.3 Zindex will confirm deletion in writing on request.
13. Liability
13.1 Each party's liability under this DPA is subject to the limitations in the Terms of Service, except where mandatory law or applicable transfer terms prevent limitation. Those limits do not restrict individuals' statutory rights or regulatory powers.
14. Term
14.1 This DPA continues for as long as Zindex processes Customer Personal Data.
Annex 1 — Details of processing
| Item | Details |
|---|---|
| Subject matter | Review of financial promotions submitted by the Customer or retrieved from agreed websites and social channels through selected scheduled monitoring. |
| Nature of processing | Receiving, storing, retrieving submitted links and promotional material from agreed monitored sources, converting files for review, text extraction, audio transcription, AI-assisted analysis, recording comments and decisions, notifications, export and deletion. |
| Purpose | Helping the Customer's reviewers identify potential compliance issues in promotions and keep a record of review decisions. |
| Duration | The term, agreed exit period and any authorised backup or legally required retention, while Customer Personal Data remains held. |
| Data subjects | The Customer's users and contacts; people who appear in or are named in submitted or monitored promotions and necessary source context, such as presenters, endorsers and creators. |
| Personal data | Names, work contact details, user identifiers, images, voices, social media handles, statements in promotions, comments and review decisions. |
| Special category data | None. The Customer must not submit special category data or select monitoring sources intended to collect it unless agreed in writing. Any incidental collection must be restricted and addressed under the Customer’s documented instructions. |
Annex 2 — Security measures
Zindex must maintain these measures for the agreed deployment. The Deployment Schedule records implementation evidence, backup coverage and any additional requirements before customer processing starts; this annex is a contractual baseline, not a certification of completed testing.
- Access control: unique user accounts, role-based access within each customer workspace, and administrator access limited to authorised Zindex personnel.
- Customer separation: each request and file is authorised against the customer and user role.
- Encryption: data is encrypted in transit and at rest by our hosting and database providers.
- File storage: customer files are held in private storage and served only through authenticated requests.
- AI providers: AI providers are used under terms that prohibit training on customer data.
- Backups and recovery: maintain the database and file backup coverage, frequency, retention and recovery arrangements agreed in the Deployment Schedule, and verify restoration before activation.
- Incident response: security incidents are investigated and notified in accordance with section 9.
- Deletion: customer data is deleted in accordance with section 12.