v1.0Last updated: June 1, 2026

Data Processing Agreement

DPA — Article 28 GDPR

This agreement applies to professional users (businesses, freelancers, agencies) who process personal data of third parties via Zymera.ai and require a DPA compliant with Article 28 of the GDPR. Individual users are covered by the standard Privacy Policy.

1. Parties

This Agreement is entered into between:

Data Controller

You (the professional user of Zymera.ai),
representing the entity whose clients' or employees' data is processed via the Platform.

Data Processor

Zymera SAS
France
contact@zymera.ai

2. Subject Matter and Nature of Processing

2.1 Subject Matter

Zymera acts as a data processor when you use the Platform to process personal data belonging to third parties (e.g. generating the image or voice of a client, uploading a file containing faces of third parties).

2.2 Nature of Processing

  • Temporary collection and storage of uploaded files
  • Processing via third-party AI models (inference)
  • Generation and delivery of the result
  • Logging of operations for security and billing purposes

2.3 Categories of Data

  • Images containing faces (potentially biometric data)
  • Audio files (voice)
  • Video files
  • Descriptive texts that may contain personal data

2.4 Data Subjects

Any identifiable natural person present in the content you upload.

3. Zymera's Obligations as Data Processor

Zymera undertakes to:

  • Process only on instruction: Process personal data exclusively in accordance with your documented instructions (use of the Platform) and immediately inform you if an instruction infringes the GDPR.
  • Confidentiality: Ensure that persons authorised to process the data are subject to a confidentiality obligation.
  • Security: Implement the technical and organisational measures referred to in Article 32 of the GDPR (encryption, access control, logging).
  • Sub-processing: Only engage further sub-processors with your general authorisation (list of sub-processors available in our Privacy Policy) and by imposing equivalent obligations on them.
  • Assistance: Assist you in responding to requests from data subjects exercising their rights, as far as possible given the nature of the processing.
  • Breach notification: Notify you of any data breach within 72 hours of becoming aware of it.
  • Deletion or return: At the end of the service, delete all personal data or return it to you on request, unless required by law to retain it.
  • Audit: Make available all information necessary to demonstrate compliance with the obligations set out in this article.

4. Controller's Obligations

As data controller, you undertake to:

  • Have a valid legal basis for processing third-party personal data;
  • Inform data subjects of the use of Zymera.ai;
  • Obtain necessary consents, particularly for biometric data (faces, voices);
  • Not upload data of minors;
  • Comply with Zymera's Acceptable Use Policy.

5. International Transfers

Some of our sub-processors are established outside the European Union (in particular in the United States). These transfers are governed by:

  • Standard Contractual Clauses (SCCs) issued by the European Commission
  • Appropriate certifications (e.g. Data Privacy Framework for certified US entities)
  • Specific safeguards negotiated with each sub-processor

The full list of sub-processors and applicable safeguards is available on request at contact@zymera.ai.

6. Term and Termination

This DPA applies throughout the duration of your use of the Platform. Upon termination of your account, Zymera will delete your data within 90 days, unless required by law to retain it or you expressly request its return.

7. Contact and Signed DPA Request

If your organisation requires a DPA in the form of a signed contractual agreement (particularly for enterprise accounts), please contact us:

Email: contact@zymera.ai

Subject: Signed DPA Request — [Your organisation name]