INSTALLED -
Z7 Solutions LLC · Legal
Version 1.2 · Last updated June 14, 2026
Governs Z7's processing of personal data on Client's behalf. Incorporated into the SOW Terms.
← All legal documentsPlain-English summary (not legally binding)
How Z7 handles personal data we process for you: we act on your documented instructions, keep it secure, do not train AI on it, use vetted subprocessors, and notify you promptly after we confirm a breach. This summary is for convenience and is not part of the contract.
This Data Processing Addendum (the "DPA") forms part of the Statement of Work Terms of Business and any Statement of Work between Z7 Solutions LLC and the Client, and applies whenever Z7 processes personal data on Client's behalf in providing the Services. Where this DPA conflicts with the body of the Terms with respect to personal data, this DPA controls.
1.1 "Applicable Data Protection Laws" means the data protection and privacy laws that apply to the processing, including the EU General Data Protection Regulation (GDPR), the UK GDPR and Data Protection Act 2018, the Swiss Federal Act on Data Protection, and US state privacy laws including the California Consumer Privacy Act as amended by the California Privacy Rights Act (CCPA).
1.2 "Personal Data," "Processing," "Controller," "Processor," "Data Subject," and "Personal Data Breach" have the meanings given in Applicable Data Protection Laws. For US laws, "Business," "Service Provider," and "Sell" and "Share" have their statutory meanings.
1.3 "Client Personal Data" means Personal Data that Z7 processes on Client's behalf under the Services.
1.4 "Subprocessor" means a third party engaged by Z7 to process Client Personal Data.
1.5 "Standard Contractual Clauses" means the EU Standard Contractual Clauses approved under Commission Implementing Decision (EU) 2021/914, with the UK International Data Transfer Addendum and the Swiss adaptations as applicable.
2.1 As between the parties, Client is the Controller (or Business), and Z7 is the Processor (or Service Provider), of Client Personal Data. Where Client is itself a processor acting for a third-party controller, Z7 acts as a subprocessor and Client's instructions reflect that controller's instructions.
2.2 Each party will comply with its obligations under Applicable Data Protection Laws.
The subject matter, duration, nature, and purpose of the processing, the types of Personal Data, and the categories of Data Subjects are described in the applicable Statement of Work and in Annex 1. Processing continues for the term of the Services and as needed for return or deletion under Section 11.
4.1 Z7 will process Client Personal Data only on Client's documented instructions, including the Statement of Work and this DPA, unless required by law, in which case Z7 will notify Client where legally permitted.
4.2 Z7 will ensure persons authorized to process Client Personal Data are bound by confidentiality.
4.3 With respect to Personal Data subject to the CCPA, Z7 acts as a Service Provider and processes Client Personal Data solely for the limited and specified business purpose of performing the Services as set out in the SOW and this DPA. Z7 will not: (a) sell or share Client Personal Data; (b) retain, use, or disclose it for any purpose other than the specified business purpose, including for a commercial purpose other than the Services; (c) retain, use, or disclose it outside the direct business relationship between the parties; or (d) combine it with personal data Z7 receives from another source or collects from its own interaction with the consumer, except as the CCPA permits to perform a business purpose. Z7 certifies that it understands and will comply with these restrictions. Client may take reasonable steps to ensure Z7 uses Client Personal Data consistent with Client's CCPA obligations and to stop and remediate unauthorized use. Z7 will impose these restrictions on any Subprocessor by written contract.
4.4 Z7 will notify Client if Z7 determines it can no longer meet its obligations under Applicable Data Protection Laws.
4.5 Z7 will inform Client without undue delay if, in Z7's opinion, an instruction from Client infringes Applicable Data Protection Laws, and may suspend performance of the affected instruction, without liability, until Client confirms or withdraws it.
4A.1 Z7 will not use Client Personal Data to train, fine-tune, or improve any artificial-intelligence or machine-learning model, except (a) a model used solely to provide the Services to Client and not exposed to other clients, or (b) data Z7 has de-identified or anonymized so it is no longer reasonably capable of being associated with a data subject, which Z7 will not attempt to re-identify. De-identification is to a standard consistent with the CCPA, and anonymization for EEA and UK data is to the GDPR Recital 26 standard.
4A.2 Z7 will not submit Client Personal Data to a third-party AI or large-language-model provider unless that provider is engaged as a Subprocessor under Section 6 and is contractually prohibited from training on, retaining beyond the processing purpose, or further disclosing Client Personal Data. Prompts, inputs, and outputs containing Client Personal Data are Client Personal Data under this DPA.
4A.3 Z7 will not carry out solely automated decision-making producing legal or similarly significant effects on a data subject using Client Personal Data, and will assist Client with the human-review and information rights such processing requires.
Z7 will implement and maintain appropriate technical and organizational measures designed to protect Client Personal Data against a Personal Data Breach, taking into account the state of the art, the costs of implementation, and the nature, scope, context, and purposes of processing. Z7's measures are aligned to recognized frameworks including NIST SP 800-171 and ISO/IEC 27001 and are summarized in Annex 2.
6.1 Client provides general written authorization for Z7 to engage Subprocessors. Z7 maintains a current list of Subprocessors (Annex 3) and will give Client at least 30 days prior written notice, by email or a subscribable change feed, before authorizing a new Subprocessor to process Client Personal Data. Client may object on reasonable, documented data-protection grounds within that period. If the parties cannot resolve the objection, Client may, as its sole remedy, suspend or terminate the affected portion of the Services without early-termination fee and without liability for the terminated portion.
6.2 Z7 will engage each Subprocessor under a written contract imposing data-protection obligations no less protective than those in this DPA, including the relevant Standard Contractual Clauses where the Subprocessor is outside an adequate country. Z7 remains fully liable to Client for the acts and omissions of its Subprocessors to the same extent as if performed by Z7.
7.1 Taking into account the nature of the processing, Z7 will assist Client by appropriate technical and organizational measures, insofar as possible, in responding to Data Subject requests to exercise rights under Applicable Data Protection Laws.
7.2 Z7 will assist Client in ensuring compliance with security, breach-notification, data-protection-impact-assessment, and prior-consultation obligations, taking into account the information available to Z7.
Z7 will notify Client without undue delay after Z7 confirms a Personal Data Breach affecting Client Personal Data, and will use commercially reasonable efforts to provide initial notice within 72 hours of confirmation, providing the information reasonably available about the breach, its likely consequences, and the measures taken or proposed. The notification period runs from Z7's confirmation of a breach, and a reasonable delay required to investigate and confirm a breach is not a breach of this Section. The breach-related cost-allocation provisions of the Statement of Work Terms of Business apply.
9.1 Where Z7 processes Client Personal Data originating in the EEA, the UK, or Switzerland and transfers it to, or accesses it from, a country without an adequacy decision, the EU Standard Contractual Clauses (Commission Implementing Decision (EU) 2021/914) are incorporated into this DPA and apply as Module Two (Controller to Processor) where Client is a controller, and Module Three (Processor to Processor) where Client acts as a processor for a third-party controller.
9.2 For the purposes of the Clauses: Client is the data exporter and Z7 the data importer; the docking clause (Clause 7) applies; in Clause 9, Option 2 (general written authorization) applies with the notice period in Section 6.1; the Clause 11 optional independent-dispute-resolution body does not apply; the governing law (Clause 17) and forum (Clause 18) are those of the Member State of the data exporter, or the Republic of Ireland where the exporter is not EEA-established. Annex I and Annex II of the Clauses are populated by Annex 1 and Annex 2 of this DPA, and the competent supervisory authority is that of the exporter, or the Irish Data Protection Commission.
9.3 For UK transfers, the UK International Data Transfer Addendum (version B1.0) is incorporated with the EU Clauses as its underlying clauses, populated by this DPA's Annexes. For Swiss transfers, the Clauses apply with the adaptations of the Swiss Federal Data Protection and Information Commissioner, including that the FDPIC is the competent authority, references to the GDPR are read as the Swiss FADP, and data of legal entities is protected until the FADP no longer requires it.
9.4 Where Z7 engages a Subprocessor outside an adequate country, Z7 will put the relevant Clauses, or the UK or Swiss equivalent, in place with that Subprocessor. To the extent legally permitted, Z7 will notify Client of any binding government request for Client Personal Data, will challenge requests it considers unlawful, and will provide the transparency information described in Clause 15 of the Clauses.
Z7 will make available information reasonably necessary to demonstrate compliance with this DPA and will allow for and contribute to audits, including through written security questionnaires or Z7's then-current third-party audit reports, on reasonable advance notice and at Client's expense, consistent with the audit provisions of the Statement of Work Terms of Business and the legally mandated access of a regulator.
On termination of the Services, Z7 will, at Client's choice, return or delete Client Personal Data, and delete existing copies, except where retention is required by law or by routine backup, in which case the data remains protected under this DPA until purged within the normal backup rotation not to exceed 90 days. On request, Z7 will provide written certification of deletion.
Where the Services involve Protected Health Information under HIPAA, the parties will execute a Business Associate Agreement, which governs that data and controls over this DPA to the extent of any conflict.
This DPA is subject to the limitation of liability in the Statement of Work Terms of Business. This DPA controls over the body of the Terms with respect to the processing of Personal Data. The Standard Contractual Clauses control over this DPA with respect to transfers they govern.
Subject matter, duration, nature and purpose of processing, types of Personal Data, and categories of Data Subjects are as set out in the applicable Statement of Work. Absent a more specific description, the nature and purpose is the delivery of the contracted information-technology, cloud, security, and advisory Services, the Personal Data is business-contact and account data of Client's personnel and any end-user data within systems Z7 supports, and the Data Subjects are Client's personnel and authorized users.
Access control and least privilege; multi-factor authentication for administrative access; encryption in transit and, where applicable, at rest; logging and monitoring; vulnerability and patch management; personnel confidentiality and screening; secure development and change management; incident response; and Subprocessor oversight, aligned to NIST SP 800-171 and ISO/IEC 27001.
The current list of Subprocessors is available to Client on request and is updated under Section 6.
Z7 Solutions LLC · 7380 W Sand Lake Rd, Suite 500-110, Orlando, FL 32819 · (844) 974-8669 · z7solutions.com