How to execute a DPA
Contact office@zavyra.com with the legal entity name, address, authorized signatory and intended processing scope. Do not send credentials or production datasets.
Review the public DPA summary for business customers using Zavyra to process buyer, employee or contractor data under documented instructions.
Where a customer uses Zavyra to process buyer, employee or contractor data, the customer normally acts as controller and ProWEB Agency acts as processor under documented instructions.
| Topic | Zavyra commitment | Customer responsibility |
|---|---|---|
| Instructions and purpose | Process customer data only to provide and secure the contracted service. | Use Zavyra lawfully and configure only necessary workflows. |
| Confidentiality and access | Apply role-based access, confidentiality and technical safeguards appropriate to risk. | Authorize only appropriate workspace users and protect credentials. |
| Subprocessors | Maintain a transparent subprocessor list and contractual protections. | Review the list and contact Zavyra about material concerns. |
| Rights and incidents | Provide reasonable assistance with rights requests and qualifying security incidents. | Supply verified request context and meet controller obligations. |
| Return and deletion | Return or delete customer data according to the agreement, law and technical backup cycles. | Export needed records and submit a verified deletion instruction. |
Contact office@zavyra.com with the legal entity name, address, authorized signatory and intended processing scope. Do not send credentials or production datasets.
Where required, transfers rely on an adequacy decision, Standard Contractual Clauses or another GDPR-permitted mechanism.
The signed agreement and applicable order form control where they differ from this public summary.
Explore the workflows described below. Available actions depend on the connected service, account permissions and selected plan.
Define responsibilities for account data and customer-controlled commerce data.
Apply safeguards appropriate to the processing risk.
Use necessary service providers under contractual and transparency controls.
Handle customer instructions according to the agreement, law and technical retention cycles.
Identify the data categories, users, connected providers and business purpose.
Request the contract using the legal entity and authorised signatory details.
Keep workspace configuration and provider access aligned with the documented purpose.
For customer-imported buyer, employee or contractor data, the business customer normally remains controller and ProWEB Agency acts as processor.
Contact office@zavyra.com with the legal entity name, address, authorised signatory and intended processing scope. Do not send credentials or datasets.
No. This is a public summary; the signed DPA and applicable order form control.
Review availability, choose the capabilities you need and keep provider access under your control.