Back to Zing

Data Processing Agreement

Template version: 2026-05-15

This DPA forms part of the Service Agreement between Nekuda Ltd. ("Processor", operating Zing) and the subscribing professional/organisation ("Controller") and governs the processing of personal data on behalf of the Controller's end-users ("Data Subjects").

1. Roles

2. Categories of data

CategoryExamples
IdentifiersClient name, phone, age
Health-adjacentDiagnosis text, treatment goals, completion history
Caregiver contactsParent/spouse name and phone
CommunicationsWhatsApp messages, voice notes, photos, videos

3. Sub-processors

The following sub-processors are engaged with the Controller's authorisation:

Sub-processorPurposeRegion
TwilioWhatsApp message deliveryUS/EU
OpenAIVoice transcription (Whisper)US
StripeSubscription billing (Controller-side only)US
Google (optional)Calendar event mirroringUS
RailwayHosting + databaseUS
CloudflareDNS + CDNGlobal

Changes to this list will be notified at least 30 days in advance by email and in-app banner. The Controller may object in writing; on unresolved objection, the Controller may terminate.

4. Security measures

The Processor maintains technical and organisational measures including:

5. Data subject rights

The Processor will, on the Controller's request, assist with responding to data subject rights within statutory deadlines. The in-product features that already serve these rights:

6. Personal data breach

In the event of a personal data breach, the Processor will notify the Controller without undue delay and in any case within 72 hours of becoming aware, providing:

7. International transfers

Data may be transferred to the United States via the listed sub-processors. Transfers rely on each sub-processor's contractual safeguards (Standard Contractual Clauses where applicable).

8. Return / deletion at end of service

On termination of the Service Agreement, the Processor will:

  1. Disable further access to the Controller's account immediately.
  2. Retain the data in cold storage for 90 days to allow recovery requests.
  3. Delete all Controller data thereafter, except records required for legal/tax obligations (e.g. invoices retained for 7 years per Israeli tax law).

9. Audit

The Controller (or an independent auditor) may, on 30 days' written notice and no more than once per 12 months, audit the Processor's compliance with this DPA — typically by reviewing security documentation rather than on-site inspection. Costs borne by the Controller unless a material breach is found.

10. Governing law

Israeli law. Disputes — Tel Aviv courts.


To execute: print, sign, return to privacy@zing.co.il or counter-sign electronically.