List of Sub-processors and Recipients
Who processes data on behalf of Zetta, for what purpose, in which country, under what contractual safeguard, and how to be informed 30 days in advance when the list changes. It also includes the third parties that receive data without being sub-processors.
01What this list is
1.1. This list forms part of the Privacy Policy and of the Data Processing Agreement. It identifies each provider that processes personal data on behalf of Zetta (sub-processor), the function it performs, the country in which it processes the data and the safeguard covering the transfer when that country does not offer an adequate level of protection according to the Agencia de Acceso a la Información Pública (AAIP, the Argentine Access to Public Information Agency).
1.2. Zetta only uses sub-processors with which it enters into a written data processing agreement that imposes obligations regarding instructions, confidentiality, security, transfers and incidents that are substantially equivalent to those Zetta assumes with each customer company. Zetta is liable for its sub-processors as for its own acts.
1.3. The "Safeguard" column indicates the mechanism covering the international transfer: the provider's data processing agreement, which incorporates the obligations of the model contracts of Disposición 60-E/2016 and of Resolution 198/2023 of the AAIP, and, where the provider offers them, the European Union Standard Contractual Clauses (SCCs) or its certification under the EU-US Data Privacy Framework (DPF).
02Infrastructure and operations sub-processors
They process data of all customer companies, because they support the service.
| Provider | Function | Data it reaches | Country | Safeguard |
|---|---|---|---|---|
| DigitalOcean, LLC | Hosting of the virtual server managed by Zetta where the API and each company's PostgreSQL database run | All Platform data; secrets encrypted at field level | United States | DigitalOcean data processing agreement with EU SCCs; model contract Disp. 60-E/2016 |
| Cloudflare, Inc. | Content delivery network, traffic protection (WAF, DNS) and object storage (R2): product photos and logos in a public bucket; documents, invoice PDFs, attachments and exports in a private bucket with no direct access; encrypted database backups and a copy of the files in separate backup buckets | Platform traffic and stored files | Global network, headquartered in the United States | Cloudflare data processing agreement with EU SCCs and DPF certification; model contract Disp. 60-E/2016 |
| Vercel Inc. | Hosting of the corporate website https://zetta.ar and of the application frontend https://app.zetta.ar, including cookie-less visit measurement on the corporate website | Traffic to the websites, corporate website forms, data that the application displays on screen | United States (corporate website) and Brazil, São Paulo region (web application functions) | Vercel data processing agreement with EU SCCs and DPF certification; model contract Disp. 60-E/2016 |
| Resend, Inc. | Sending of transactional email: invitations, email verification, access recovery, sign-in links, security and service notices, invoices and notifications that each company sends to its customers | Recipient's email address, subject and content of the message, delivery status | United States | Resend data processing agreement with EU SCCs and DPF certification; model contract Disp. 60-E/2016 |
03Sub-processors that intervene only if the company activates a feature
| Provider | Function | Data it reaches | Country | Safeguard |
|---|---|---|---|---|
| Anthropic, PBC | Provider of the assistant's language model, only for companies that activate it | The fragments of operational data strictly necessary to answer each query, limited to the permissions of the User making the query. Costs, margins, CUIL (employee tax identification number), CBU (bank account number), credentials and passwords are never sent. The provider does not train its models on this data and retains it for a maximum of 30 days for abuse monitoring | United States | Anthropic data processing agreement with EU SCCs; model contract Disp. 60-E/2016 |
If Zetta configures a different or additional model provider, it will add it to this list with the prior notice described in Section 6 before it processes any company's data.
04Own infrastructure
The Platform's technical logs (application, web server and security logs) and application errors are processed on infrastructure managed directly by Zetta in the Argentine Republic, to which the logs travel through an encrypted tunnel. No external error-tracking or analytics services are involved with those logs.
05Third parties that receive data without being sub-processors
These third parties receive personal data because the customer company or the User decides so, and process it under their own policies and responsibility. They are not subject to Zetta's instructions.
| Third party | When it receives data | What it receives | Country |
|---|---|---|---|
| Agencia de Recaudación y Control Aduanero (ARCA) | When the company issues an electronic invoice with its own certificate | The invoice data that tax regulations require to be transmitted | Argentina |
| Mercado Pago (MercadoLibre S.R.L.) | When the company collects payments from its customers with its own account, and when it pays its Zetta subscription | The payment transaction data; card data is entered only in the Mercado Pago environment | Argentina |
| Mercado Libre and other integrations that the company connects | When the company connects an integration from Configuration → Integrations | The data that the integration synchronizes (listings, orders, stock, bank movements) | Depends on the chosen provider |
| Google LLC and Microsoft Corporation | When the User chooses to sign in with their Google or Microsoft account | The provider reports to Zetta the name, email and an account identifier; Zetta sends nothing to the provider beyond the authentication request | United States |
| Apple Inc. | When the User installs the mobile applications from the App Store | What Apple collects as an application distributor, under its own policy | United States |
| Google Ireland Limited (Google Analytics 4) | Only on the corporate website and only if the visitor accepts measurement cookies | Browsing data from the corporate website | Ireland and United States |
| Judicial and administrative authorities | Upon a legally valid request | What the request covers | Argentina |
06How a change is notified
6.1. Zetta announces the addition or replacement of a sub-processor at least 30 calendar days in advance, by email to the Users with owner and administrator roles of each company and by updating this list, whose version date appears in the header. During that period the company may object on reasonable grounds related to data protection and, if there is no satisfactory solution, cancel the service without penalty, in accordance with the Data Processing Agreement.
6.2. The removal of a sub-processor and changes that do not involve a new provider or a new country (for example, a change of the provider's corporate name) are reflected in this list without prior notice.
6.3. Previous versions of this list are retained and provided upon request to privacidad@zetta.ar.
Contact
Write to us and we answer through the same channel.
Personal data and data subject rights
privacidad@zetta.arGeneral enquiries
hola@zetta.arThis document is published in Spanish. If you are reading a translation, the Spanish version is the only binding one.