Zetta

List of Sub-processors and Recipients

Who processes data on behalf of Zetta, for what purpose, in which country, under what contractual safeguard, and how to be informed 30 days in advance when the list changes. It also includes the third parties that receive data without being sub-processors.

Last updated2026-10-05Current versionVersion2026-10-05SHA-25630f91efa2232

01What this list is

1.1. This list forms part of the Privacy Policy and of the Data Processing Agreement. It identifies each provider that processes personal data on behalf of Zetta (sub-processor), the function it performs, the country in which it processes the data and the safeguard covering the transfer when that country does not offer an adequate level of protection according to the Agencia de Acceso a la Información Pública (AAIP, the Argentine Access to Public Information Agency).

1.2. Zetta only uses sub-processors with which it enters into a written data processing agreement that imposes obligations regarding instructions, confidentiality, security, transfers and incidents that are substantially equivalent to those Zetta assumes with each customer company. Zetta is liable for its sub-processors as for its own acts.

1.3. The "Safeguard" column indicates the mechanism covering the international transfer: the provider's data processing agreement, which incorporates the obligations of the model contracts of Disposición 60-E/2016 and of Resolution 198/2023 of the AAIP, and, where the provider offers them, the European Union Standard Contractual Clauses (SCCs) or its certification under the EU-US Data Privacy Framework (DPF).

02Infrastructure and operations sub-processors

They process data of all customer companies, because they support the service.

ProviderFunctionData it reachesCountrySafeguard
DigitalOcean, LLCHosting of the virtual server managed by Zetta where the API and each company's PostgreSQL database runAll Platform data; secrets encrypted at field levelUnited StatesDigitalOcean data processing agreement with EU SCCs; model contract Disp. 60-E/2016
Cloudflare, Inc.Content delivery network, traffic protection (WAF, DNS) and object storage (R2): product photos and logos in a public bucket; documents, invoice PDFs, attachments and exports in a private bucket with no direct access; encrypted database backups and a copy of the files in separate backup bucketsPlatform traffic and stored filesGlobal network, headquartered in the United StatesCloudflare data processing agreement with EU SCCs and DPF certification; model contract Disp. 60-E/2016
Vercel Inc.Hosting of the corporate website https://zetta.ar and of the application frontend https://app.zetta.ar, including cookie-less visit measurement on the corporate websiteTraffic to the websites, corporate website forms, data that the application displays on screenUnited States (corporate website) and Brazil, São Paulo region (web application functions)Vercel data processing agreement with EU SCCs and DPF certification; model contract Disp. 60-E/2016
Resend, Inc.Sending of transactional email: invitations, email verification, access recovery, sign-in links, security and service notices, invoices and notifications that each company sends to its customersRecipient's email address, subject and content of the message, delivery statusUnited StatesResend data processing agreement with EU SCCs and DPF certification; model contract Disp. 60-E/2016

03Sub-processors that intervene only if the company activates a feature

ProviderFunctionData it reachesCountrySafeguard
Anthropic, PBCProvider of the assistant's language model, only for companies that activate itThe fragments of operational data strictly necessary to answer each query, limited to the permissions of the User making the query. Costs, margins, CUIL (employee tax identification number), CBU (bank account number), credentials and passwords are never sent. The provider does not train its models on this data and retains it for a maximum of 30 days for abuse monitoringUnited StatesAnthropic data processing agreement with EU SCCs; model contract Disp. 60-E/2016

If Zetta configures a different or additional model provider, it will add it to this list with the prior notice described in Section 6 before it processes any company's data.

04Own infrastructure

The Platform's technical logs (application, web server and security logs) and application errors are processed on infrastructure managed directly by Zetta in the Argentine Republic, to which the logs travel through an encrypted tunnel. No external error-tracking or analytics services are involved with those logs.

05Third parties that receive data without being sub-processors

These third parties receive personal data because the customer company or the User decides so, and process it under their own policies and responsibility. They are not subject to Zetta's instructions.

Third partyWhen it receives dataWhat it receivesCountry
Agencia de Recaudación y Control Aduanero (ARCA)When the company issues an electronic invoice with its own certificateThe invoice data that tax regulations require to be transmittedArgentina
Mercado Pago (MercadoLibre S.R.L.)When the company collects payments from its customers with its own account, and when it pays its Zetta subscriptionThe payment transaction data; card data is entered only in the Mercado Pago environmentArgentina
Mercado Libre and other integrations that the company connectsWhen the company connects an integration from Configuration → IntegrationsThe data that the integration synchronizes (listings, orders, stock, bank movements)Depends on the chosen provider
Google LLC and Microsoft CorporationWhen the User chooses to sign in with their Google or Microsoft accountThe provider reports to Zetta the name, email and an account identifier; Zetta sends nothing to the provider beyond the authentication requestUnited States
Apple Inc.When the User installs the mobile applications from the App StoreWhat Apple collects as an application distributor, under its own policyUnited States
Google Ireland Limited (Google Analytics 4)Only on the corporate website and only if the visitor accepts measurement cookiesBrowsing data from the corporate websiteIreland and United States
Judicial and administrative authoritiesUpon a legally valid requestWhat the request coversArgentina

06How a change is notified

6.1. Zetta announces the addition or replacement of a sub-processor at least 30 calendar days in advance, by email to the Users with owner and administrator roles of each company and by updating this list, whose version date appears in the header. During that period the company may object on reasonable grounds related to data protection and, if there is no satisfactory solution, cancel the service without penalty, in accordance with the Data Processing Agreement.

6.2. The removal of a sub-processor and changes that do not involve a new provider or a new country (for example, a change of the provider's corporate name) are reflected in this list without prior notice.

6.3. Previous versions of this list are retained and provided upon request to privacidad@zetta.ar.

Contact

Write to us and we answer through the same channel.

Personal data and data subject rights

privacidad@zetta.ar

General enquiries

hola@zetta.ar

This document is published in Spanish. If you are reading a translation, the Spanish version is the only binding one.