Zetta

Data Processing Agreement

The contract required by Section 25 of Law 25,326 between each customer company, controller of the personal data it loads into Zetta, and the Provider, which processes it as processor; instructions, security, sub-processors, international transfers, incidents, assistance and what happens to the data at the end.

Last updated2026-10-05Current versionVersion2026-10-05SHA-25639798b1cec27

01Parties, purpose and term

1.1. This Data Processing Agreement (the "Agreement") is entered into between the customer company identified in the Organization that accepts it (the "Controller" or the "Customer") and Agustín Demarco, with address at Rosario, Provincia de Santa Fe, República Argentina, provider of the Zetta service (the "Processor" or "Zetta").

1.2. The Agreement governs the processing of personal data that the Processor carries out on behalf of and on the instructions of the Controller in order to provide the service described in the Terms and Conditions of Service (the "Service"), and complies with the requirements of Section 25 of Law 25,326 on the Protection of Personal Data (Ley 25.326) and Section 25 of Decree 1558/2001 (Decreto 1558/2001) and, where applicable, Article 28 of Regulation (EU) 2016/679 ("GDPR").

1.3. The Agreement forms part of the Terms and Conditions, is accepted on behalf of the Controller by a User with the owner role of the Organization and remains in force for as long as the Processor processes personal data on behalf of the Controller, including the post-termination period of the Service provided for in Section 11.

1.4. In the event of a conflict between this Agreement and the Terms and Conditions, the Agreement prevails on all matters relating to personal data.

02Definitions

The terms "personal data", "sensitive data", "data subject", "controller", "processor", "processing", "disclosure", "international transfer" and "database" have the meaning assigned to them by Section 2 of Law 25,326 and, where relevant, Article 4 of the GDPR. "Sub-processor" means any third party engaged by the Processor that processes personal data of the Controller. "Security incident" means any breach of security that causes the destruction, loss, alteration, unauthorized disclosure of or access to personal data processed by the Processor. "Customer Data" has the meaning given in the Terms and Conditions.

03Roles of the parties

3.1. The Controller determines the purpose and means of the processing of the personal data it loads into its Organization: that of its customers, suppliers, employees, contacts and buyers of its online store. It is the owner of those databases and is responsible for their lawfulness.

3.2. The Processor processes that data exclusively to provide the Service, in accordance with the Controller's documented instructions, and does not decide on its purpose.

3.3. Zetta acts as controller, and not as processor, with respect to Users' access account data, the Customer's contact and billing data, technical and security logs and the record of acceptance of documents. That processing is governed by the Privacy Policy, not by this Agreement.

04Details of the processing

Annex I describes the nature, purpose, duration, categories of data and data subjects and the processing operations covered. The Controller may expand or restrict those details through the configuration of the modules, permissions and integrations of its Organization, which constitute instructions within the meaning of Section 5.

05Instructions of the Controller

5.1. The Processor processes personal data only in accordance with the Controller's documented instructions. The following constitute instructions: (a) the Terms and Conditions and this Agreement; (b) the configuration of the Organization, its modules, its integrations with third parties (ARCA, Mercado Pago, Mercado Libre, the assistant provider) and each User's permissions; (c) the operations that the Controller's authorized Users perform on the Platform; (d) any additional instructions that the Controller communicates in writing, to the extent they are reasonable and compatible with the Service.

5.2. If the Processor considers that an instruction infringes Law 25,326, the GDPR or other applicable law, it will inform the Controller without delay and may refrain from carrying it out until the Controller confirms or modifies it.

5.3. The Processor does not apply or use the personal data for any purpose other than that set out in this Agreement, does not disclose it to third parties even for its safekeeping (Section 25, subsection 1 of Law 25,326), does not combine it with that of other customers and does not use it to train artificial intelligence models or for its own statistical purposes that would allow a person to be identified.

06Obligations of the Processor

6.1. Confidentiality. The Processor guarantees that the persons authorized to process the personal data are bound by the duty of confidentiality of Section 10 of Law 25,326, which continues even after the relationship has ended, and that they access Customer Data only to resolve a support request or an incident. Platform staff access an Organization's data only through an impersonation session that starts in read-only mode, expires after 60 minutes and requires a written reason; only a super administrator can raise it to write mode, and the opening, the raising and each write operation are recorded in the platform audit log.

6.2. Security. The Processor adopts and maintains the technical and organizational measures necessary to guarantee the security and confidentiality of personal data, prevent its adulteration, loss, unauthorized consultation or processing and detect information leaks (Section 9 of Law 25,326), aligned with the measures recommended by Resolution 47/2018 of the Agencia de Acceso a la Información Pública (AAIP) and, where relevant, with Article 32 of the GDPR. The measures in force are described in Annex II and in the Privacy Policy, and the Processor may improve them without reducing the level of protection.

6.3. Assistance with the exercise of rights. The Processor assists the Controller, through the Platform's functions (consultation, export, rectification and deletion of records) and, when necessary, through direct assistance, so that the Controller can handle data subjects' requests for access, rectification, updating, deletion, objection and portability within the legal deadlines. If a data subject addresses a request to the Processor regarding the Controller's data, the Processor will forward it to the Controller within 2 business days, without responding to it itself except to inform the data subject to whom it was forwarded.

6.4. Assistance with compliance. The Processor makes available to the Controller the information reasonably necessary for the Controller to comply with its obligations regarding security, incident notification, impact assessment and prior consultation with the supervisory authority, taking into account the nature of the processing and the information available to it.

6.5. Security incidents. The Processor notifies the Controller of any security incident affecting its personal data within 72 hours of its confirmation, to the email of the Users with the owner and administrator roles of the Organization, indicating: the nature of the incident; the categories and approximate number of data subjects and records affected; the likely consequences; the measures adopted or proposed to contain and mitigate it; and a contact point. If it is not possible to provide all the information at once, it is delivered in stages. The Processor documents each incident, cooperates with the Controller in the notifications the Controller must make to the supervisory authority and to data subjects, and does not inform the Controller's data subjects itself unless the Controller instructs it to do so or the law requires it.

6.6. Records and demonstration of compliance. The Processor keeps a record of the categories of processing carried out on behalf of the Controller and makes available to it the information necessary to demonstrate compliance with this Agreement.

6.7. Audit. The Controller may, once per calendar year and with 30 calendar days' prior written notice, request from the Processor a written report on the security measures and compliance with this Agreement, and ask reasonable questions. If well-founded doubts arise from the report, or a supervisory authority so requires, the Controller may carry out, or commission an independent auditor bound by confidentiality to carry out, an audit during business hours, without affecting the operation or the confidentiality of other customers, at its own cost unless it detects substantial breaches.

6.8. Return and deletion. Upon termination of the Service, the Processor proceeds in accordance with Section 11.

6.9. Registration. The Processor registers its own databases in the National Registry of Databases (Registro Nacional de Bases de Datos) and keeps the registration up to date. Registration of the Controller's databases is the Controller's obligation.

07Sub-processors

7.1. The Controller grants the Processor a general authorization to engage sub-processors that provide infrastructure, storage, email delivery, security and processing services necessary for the Service. The current sub-processors, with the function they perform, the country where they process the data and the mechanism covering the transfer, are listed in the List of Sub-processors, which forms part of this Agreement.

7.2. The Processor enters into a written contract with each sub-processor that imposes data protection obligations substantially equivalent to those of this Agreement, in particular regarding instructions, confidentiality, security, international transfers and incidents. The Processor is liable to the Controller for compliance with the obligations of its sub-processors as if they were its own.

7.3. Prior notice and objection. The Processor informs the Controller of the addition or replacement of a sub-processor at least 30 calendar days in advance, by email to the Users with the owner and administrator roles and by updating the List of Sub-processors. The Controller may object on reasonable grounds related to data protection within that period. If the parties do not find a satisfactory solution, the Controller may terminate the Service without penalty, with the full export window, before the new sub-processor begins to process its data. The sub-processors that the Controller itself chooses and configures (Mercado Pago, Mercado Libre, banks, the assistant provider when the Controller activates it) are authorized by that same configuration.

08International transfers

8.1. The Controller acknowledges and authorizes that, in order to provide the Service, the Processor and its sub-processors process personal data outside the Argentine Republic, in the countries identified in the List of Sub-processors, mainly the United States of America.

8.2. Each transfer to a country that does not offer an adequate level of protection is covered by contractual clauses that incorporate the obligations of the model contract for the provision of processing services approved by Disposición 60-E/2016 (Annex II) and of the clauses approved by Resolution 198/2023 of the AAIP, entered into between the Processor and each sub-processor, and, where the sub-processor offers them, by the European Union Standard Contractual Clauses or by certification under the EU-US Data Privacy Framework. The Processor files with the AAIP any contracts that deviate from the model within 30 days of their execution (Section 2 of Disposición 60-E/2016) and provides the Controller, upon request, with a copy of the applicable clauses.

8.3. Database backups are stored encrypted with a key whose private counterpart is not held by any sub-processor; file copies are stored in a separate backup bucket.

8.4. If the Controller is established in the European Union or the United Kingdom, the parties incorporate by reference the Standard Contractual Clauses approved by Commission Implementing Decision (EU) 2021/914 (Module 2, controller to processor) or the UK International Data Transfer Agreement, as applicable, for any onward transfer that is not covered by an adequacy decision, and the Processor provides them signed upon request.

09Obligations of the Controller

The Controller undertakes to: (a) have a sufficient legal basis to process the personal data it loads into the Organization and to entrust its processing to the Processor; (b) inform data subjects, in accordance with Section 6 of Law 25,326, that their data is processed through a cloud software provider and, where applicable, that it is transferred abroad; (c) register its databases in the National Registry of Databases where required; (d) give lawful instructions and configure its Users' permissions in accordance with the principle of least privilege; (e) not load sensitive data that is not necessary for the purpose of the processing and, when it does load it (for example, in payroll), have the legal basis required by Section 7 of Law 25,326; (f) handle data subjects' requests within the legal deadlines; (g) notify the Processor, without delay, of any unauthorized use of credentials of which it becomes aware; (h) export its data before termination of the Service.

10Employee data, sensitive data and the artificial intelligence assistant

10.1. The data of the Controller's employees that is processed in the people and payroll modules (including CUIL (employee tax identification number), CBU (bank account number), remuneration, family dependents, health insurance, union membership, leaves and garnishments) is the Controller's data, as their employer and controller. The Processor protects it with the same measures as the rest and expressly excludes it from the data that may be sent to the artificial intelligence assistant.

10.2. If the Controller activates the assistant, it authorizes the Processor to send to the model provider identified in the List of Sub-processors the fragments of operational data strictly necessary to answer each query, limited to the permissions of the User making the query. Costs, margins, CUIL, CBU, credentials and passwords are never sent. The model provider does not use that data to train its models and retains it for the limited period stated in the List of Sub-processors. The Controller may deactivate the assistant at any time, with immediate effect.

11Termination of the Service: return and deletion

11.1. Once the Service has terminated for any reason, the Processor keeps the complete export of the Customer Data available, in open formats, for 30 calendar days. Upon written request from the Controller made before expiration, that period is extended up to a total maximum of 2 years from termination, which is the limit that Section 25, subsection 2 of Law 25,326 allows for retention by the processor.

11.2. Once the period has expired, the Processor permanently deletes the Organization's database schema and its files within the following 30 days, the database backups that contained them expire according to their retention cycle, of 35 days at most, and the backup copy of its files is deleted within that same period. Upon the Controller's request, the Processor issues a written certificate of deletion.

11.3. The Processor retains only what a legal obligation requires it to retain as a controller: its invoices to the Customer and the record of acceptance of the contractual documents, for the periods stated in the Privacy Policy. Those records do not contain personal data of the Controller's data subjects.

12Liability

12.1. Each party is liable for the damages it causes through breach of the obligations that this Agreement and the law impose on it. The Processor is liable for the acts of its sub-processors.

12.2. Toward data subjects and the supervisory authority, each party is liable to the extent of its role. If a party pays compensation or a penalty for an act attributable to the other, it may seek recourse against it.

12.3. The limit of liability in the Terms and Conditions does not apply to damages arising from the breach of the confidentiality or personal data protection obligations of this Agreement, in accordance with Section 23.4 of the Terms.

13General provisions

13.1. This Agreement is governed by the laws of the Argentine Republic and, to the extent applicable to the Controller, by the GDPR. Disputes are resolved in accordance with the jurisdiction clause of the Terms and Conditions.

13.2. Amendments to this Agreement follow the amendment procedure of the Terms and Conditions: notice 30 calendar days in advance, new acceptance by a User with the owner role and the right to cancel the Service without penalty.

13.3. If a clause is found to be invalid, the remaining clauses remain in force and the clause is completed with the valid provision closest to its purpose.

14Annex I. Details of the processing

ElementDescription
Nature and purposeHosting, storage, organization, consultation, modification, backup, export, transmission to the integrations that the Controller enables and deletion of data, for the sole purpose of providing the contracted management system
DurationFor as long as the Service is in force and during the subsequent period under Section 11
Categories of data subjectsCustomers and their contacts; suppliers and their contacts; employees, former employees and their dependents; buyers and users of the online store portal; third parties mentioned in invoices, documents and notes; the Controller's Users
Categories of dataIdentification (name, ID document, CUIT/CUIL), contact (address, email, phone), commercial and billing data, accounts receivable and declared payment methods (no card data), employment and payroll data, order and delivery data, attached documents, audit logs of the operations performed on that data
Sensitive dataOnly that which the Controller loads in payroll or in attached documents (health insurance, union membership, health-related leaves). No other categories of sensitive data are processed
Special operationsTransmission of invoices to ARCA with the Controller's certificate; creation of preferences and receipt of payment notifications from Mercado Pago with the Controller's token; sending of transactional emails to the data subjects indicated by the Controller; queries to the artificial intelligence assistant, if the Controller activates it

15Annex II. Security measures

The technical and organizational measures in force are those described in Section 9 of the Privacy Policy, which are incorporated into this Agreement, and comprise in summary: isolation of each Organization in its own database schema; encryption of traffic, passwords, secrets and backups; limited sessions with rotating tokens and anti-CSRF protection; two-step verification, passkeys and lockout against brute force; role- and permission-based access control with default-deny for writes; automatic audit log of each creation, modification and deletion; encrypted daily database backups with a weekly restoration test, and a daily copy of the files to a separate backup bucket; observability on own infrastructure; restricted administrative access with personal keys; code review, automated security tests and mechanical verification of the architecture; incident response procedure.

16Annex III. Sub-processors

The current List of Sub-processors forms part of this Agreement.

Contact

Write to us and we answer through the same channel.

Personal data and data subject rights

privacidad@zetta.ar

General enquiries

hola@zetta.ar

This document is published in Spanish. If you are reading a translation, the Spanish version is the only binding one.