Data Processing Addendum
Last updated August 19, 2026. This standard DPA is incorporated into the Terms of Service for every business and vendor account; a countersigned copy is available on request at hello@zennvue.com.
1. Parties and roles
This Data Processing Addendum ("DPA") is between Trunnion AI LLC, a Duskbridge company ("Zennvue"), and the business or vendor customer that accepts the Terms of Service ("Customer"). For Customer Personal Data, Customer is the business or controller and Zennvue is Customer's service provider (as defined by the California Consumer Privacy Act as amended, "CCPA/CPRA") or processor (as defined by other applicable privacy laws, including where applicable the EU and UK GDPR).
2. Customer Personal Data and purpose
"Customer Personal Data" means personal information that Customer stores in its Zennvue workspace about its own clients and contacts, including names, contact details, messages, proposals, contracts, invoices, files, guest and attendee records, and event details. Zennvue processes Customer Personal Data only to provide, secure, and support the Services under the Terms, for the duration of the Customer's account, and per Customer's documented instructions given through the Services' features and settings.
3. Service-provider restrictions (CCPA/CPRA)
Zennvue will not: sell or share Customer Personal Data; retain, use, or disclose it for any purpose other than the business purposes specified in this DPA, or outside the direct business relationship with Customer; or combine it with personal information received from another source, except as the CCPA/CPRA permits for a service provider. Zennvue certifies that it understands these restrictions and will comply with them, will notify Customer if it determines it can no longer meet its obligations, and grants Customer the right, on reasonable notice, to take reasonable steps to stop and remediate unauthorized use of Customer Personal Data.
4. Processor obligations
- Confidentiality. Personnel authorized to process Customer Personal Data are bound by confidentiality obligations.
- Security. Zennvue implements appropriate technical and organizational measures, including encryption in transit (TLS 1.2 or higher) and at rest (AES-256 via the managed database and storage layers), per-tenant isolation, and role-based access control, as described at Security.
- Assistance. Zennvue provides reasonable assistance with data-subject and consumer rights requests relating to Customer Personal Data, with security, breach-notification, and assessment obligations, taking into account the nature of the processing.
- No training use. Zennvue does not use Customer Personal Data to train or fine-tune AI models across customers, as stated in the Privacy Policy.
- Breach notice. Zennvue notifies Customer without undue delay after confirming a breach of security affecting Customer Personal Data, with the information reasonably available to support Customer's own notification obligations.
- Audit. On reasonable request, no more than annually absent a confirmed incident, Zennvue makes available the information reasonably necessary to demonstrate compliance with this DPA, which may be satisfied through its current security documentation and completed assessment questionnaires.
5. Subprocessors
Customer authorizes the subprocessors listed at Subprocessors, which states each provider's function and processing location. Zennvue gives at least 30 days notice of a new subprocessor that will process Customer Personal Data by updating that page and, for accounts subscribed to notices, by email. Customer may object on reasonable data-protection grounds within the notice period; if the objection cannot be resolved, Customer may terminate the affected subscription and receive a pro-rata refund of prepaid fees for the unused period. Zennvue flows down data-protection obligations no less protective than this DPA to each subprocessor and remains responsible for their performance.
6. Deletion and return
Customer can export Customer Personal Data from the workspace at any time. On termination or on Customer's verified request, Zennvue deletes Customer Personal Data, subject to legal holds and the retention obligations described in the Privacy Policy; deleted content ages out of backups on the backup system's limited rolling window, and deletion is complete when that window lapses.
7. Order of precedence and term
This DPA forms part of the Terms of Service. If this DPA conflicts with the Terms on the processing of Customer Personal Data, this DPA controls. It remains in effect for as long as Zennvue processes Customer Personal Data.
Contact
Trunnion AI LLC, a Duskbridge company, 8100 Wyoming Blvd NE, Ste M4-301, Albuquerque, NM 87113. Email hello@zennvue.com.