This DPA forms part of the Service Agreement between Nekuda Ltd. ("Processor", operating Zing) and the subscribing professional/organisation ("Controller") and governs the processing of personal data on behalf of the Controller's end-users ("Data Subjects").
| Category | Examples |
|---|---|
| Identifiers | Client name, phone, age |
| Health-adjacent | Diagnosis text, treatment goals, completion history |
| Caregiver contacts | Parent/spouse name and phone |
| Communications | WhatsApp messages, voice notes, photos, videos |
The following sub-processors are engaged with the Controller's authorisation:
| Sub-processor | Purpose | Region |
|---|---|---|
| Twilio | WhatsApp message delivery | US/EU |
| OpenAI | Voice transcription (Whisper) | US |
| Stripe | Subscription billing (Controller-side only) | US |
| Google (optional) | Calendar event mirroring | US |
| Railway | Hosting + database | US |
| Cloudflare | DNS + CDN | Global |
Changes to this list will be notified at least 30 days in advance by email and in-app banner. The Controller may object in writing; on unresolved objection, the Controller may terminate.
The Processor maintains technical and organisational measures including:
The Processor will, on the Controller's request, assist with responding to data subject rights within statutory deadlines. The in-product features that already serve these rights:
GET /api/me/export — full JSON export of the Controller's data (incl. their clients).DELETE /api/me — soft-delete that blocks further access immediately.PATCH/DELETE endpoints for granular correction/erasure.In the event of a personal data breach, the Processor will notify the Controller without undue delay and in any case within 72 hours of becoming aware, providing:
Data may be transferred to the United States via the listed sub-processors. Transfers rely on each sub-processor's contractual safeguards (Standard Contractual Clauses where applicable).
On termination of the Service Agreement, the Processor will:
The Controller (or an independent auditor) may, on 30 days' written notice and no more than once per 12 months, audit the Processor's compliance with this DPA — typically by reviewing security documentation rather than on-site inspection. Costs borne by the Controller unless a material breach is found.
Israeli law. Disputes — Tel Aviv courts.
To execute: print, sign, return to privacy@zing.co.il or counter-sign electronically.