Acceptable online — counter-signed copy available on request

Data Processing Agreement

Last Updated: August 5, 2026

This Data Processing Agreement ("DPA") describes how ZEA International processes personal data on behalf of customers of ZEA AssetOps. It supplements our Terms of Service and Privacy Policy. Workspace owners can accept these terms at the bottom of this page; a counter-signed execution copy is available from sales@zeainternational.com.

1. Parties & Roles

For personal data entered into your workspace, the customer is the data controller: you decide what data is collected and why. ZEA International is the data processor: we process that data only to provide ZEA AssetOps, on your documented instructions, and never for our own purposes. People with workspace access act under the customer's authority.

2. Scope & Nature of Processing

Processing covers hosting, storage, transmission, display, backup, and deletion of workspace data; sending notifications you configure (email, SMS, push); and generating reports and evidence packs you request. Processing lasts for the duration of your subscription plus the deletion window described in section 8.

3. Categories of Data

Workspace data typically includes:

  • User accounts: names, work email addresses, phone numbers, roles, and authentication records of the people you invite to your workspace.
  • Asset & operations records: assets, locations, tickets, work orders, inspections, maintenance, waste, and custody data you enter while operating the platform.
  • Supplier contacts: supplier company details, contact persons, questionnaire responses, and ESG assessment records.
  • Sensor telemetry: readings, alerts, and device metadata from sensors you connect to your workspace.
  • IP addresses: the network address a session signs in from, recorded for each active session to enforce concurrent-session limits and support fraud investigation. Retained for 30 days after a session's last activity, then deleted.
  • Device & browser information: the user agent string reported by the browser or app for each session, recorded alongside a device fingerprint to detect unfamiliar sign-ins. Retained on the same 30-day schedule as IP addresses.

4. Subprocessors

We use a small set of vetted subprocessors to run the service. Each is bound by data protection terms at least as protective as this DPA. We will notify customers before adding or replacing a subprocessor, with an opportunity to object.

SubprocessorPurposeLocation
RailwayApplication hosting and managed PostgreSQL databaseRegion selected at deployment
Cloudflare R2Object storage for uploads, attachments, and evidence filesBucket location set per deployment
UpstashRedis cache and QStash background job deliveryRegion selected at provisioning
ResendTransactional email deliveryUSA
HubtelSMS delivery and payment processingGhana
SentryError and performance monitoringUSA or EU, per account instance
ipapi.coIP-to-country lookup for sign-in and visit analyticsUSA

5. Security Measures

  • All traffic is encrypted in transit with TLS.
  • Account credentials are hashed with bcrypt; sessions are server-side and revocable.
  • Role-based access control (RBAC) scopes every record to your workspace and the member's role.
  • An append-only audit log records state changes, approvals, and access-relevant events.
  • Exported evidence packs are signed with Ed25519 so tampering is detectable.

6. Breach Notification

If we become aware of a personal data breach affecting your workspace, we will notify you without undue delay and within 72 hours, describing the nature of the breach, the data affected, the likely consequences, and the measures taken or proposed to contain and remediate it.

7. Data Subject Rights

Taking into account the nature of processing, we assist you in responding to data subject requests — access, rectification, erasure, restriction, and portability. Most records can be exported or deleted directly in the product; where they cannot, we act on your written instruction.

8. Retention & Deletion

Workspace data is retained while your subscription is active. On termination, you may export your data; we then delete personal data from production systems within 30 days and from encrypted backups within 90 days, unless retention is required by law.

9. Data Residency

We want to be precise here, because residency is often overstated.

  • Application and database. ZEA AssetOps runs on Railway, with its primary PostgreSQL database managed by the same provider. The hosting region is chosen when the environment is deployed. The application does not pin a region, and we do not currently make a standing commitment that a given workspace is hosted in a specific country or region.
  • File storage. Uploads, attachments, and evidence packs are stored in Cloudflare R2. R2 is addressed with the region value auto, which is a protocol placeholder rather than a location: the bucket's physical location is set on the storage account when the bucket is created, not by the application.
  • Supporting services. Cache and background jobs (Upstash), email (Resend), and error monitoring (Sentry) each process data in the region of the account they are provisioned under. SMS and payments are processed by Hubtel in Ghana.
  • Backups. Database backups are written to object storage and inherit that bucket's location.

If your organization requires data residency in a named region — for example EU-only processing — contact sales@zeainternational.com before signing. That is deliverable by provisioning your environment in the required region and recording it as a contractual commitment in the execution copy of this DPA. It is not something this page can promise on its own, and we would rather tell you that than imply a guarantee we have not made.

10. International Transfers

Subprocessors may process data outside your country (see the table above). Where data is transferred internationally, we rely on appropriate safeguards such as standard contractual clauses and equivalent contractual commitments from each subprocessor.

11. Audit Rights

On reasonable written notice, we will make available the information necessary to demonstrate compliance with this DPA — including summaries of security measures, subprocessor terms, and audit log evidence — and will allow audits required by applicable law, subject to confidentiality and at most once per year unless a breach has occurred.

Need a counter-signed copy?

Accepting above records agreement to these terms for your workspace. If your procurement process needs a counter-signed document, or edits reviewed by counsel, contact sales@zeainternational.com and we will send the execution copy.