Back to home Data processing addendum How Zobi processes personal data on behalf of merchants under data protection law. Version 2026-06-22 · last updated 22 June 2026 Save a copy of this version Introduction and incorporation Definitions Scope and roles Processing on instructions Controller warranties and indemnity Details of processing (Annex 1) Confidentiality Security measures (Annex 2) Sub-processors International transfers Data subject requests Personal data breach Assistance Return and deletion Audits and information CCPA / CPRA terms Liability General and contact Introduction and incorporation This data processing addendum (the "addendum") forms part of the terms of service available at /terms (the "agreement") between you (the merchant) and Zobi OÜ, a private limited company (osaühing) incorporated in Estonia with registered office at Maakri 23a, Tallinn, Estonia, operating the Zobi service ("Zobi", "we", "us"). The addendum applies wherever Zobi processes personal data on the merchant's behalf in the course of providing the service, including when the service messages the merchant's customers and prospects over iMessage, with SMS and RCS fallback, to recover checkouts and drive repeat purchases. For the purposes of applicable data protection law, the merchant is the controller and Zobi is the processor with respect to the personal data described in Annex 1. The merchant alone determines the purposes and means of the processing; Zobi acts only as a processor on the merchant's documented instructions. Where there is a conflict between the addendum and the rest of the agreement on the subject of data protection, the addendum prevails to the extent of that conflict. The addendum takes effect when the merchant accepts the terms of service or first uses the service, whichever is earlier, and remains in force for as long as Zobi processes personal data on the merchant's behalf. Definitions Terms used in this addendum have the meanings given to them in applicable data protection law. For convenience: Controller means the party that determines the purposes and means of the processing of personal data; here, the merchant. Processor means the party that processes personal data on behalf of the controller; here, Zobi OÜ, operating Zobi. Personal data means any information relating to an identified or identifiable natural person that Zobi processes on the merchant's behalf under the agreement. Processing means any operation performed on personal data, such as collection, storage, use, disclosure, or erasure. Data subject means the identified or identifiable natural person to whom the personal data relates. Sub-processor means any third party engaged by Zobi to process personal data on the merchant's behalf. Applicable data protection law means all data protection and privacy laws that apply to the processing under the agreement, including the EU General Data Protection Regulation (GDPR) and the UK GDPR where relevant. This addendum is intended to be read consistently with GDPR Article 28. Scope and roles Zobi processes personal data only on the merchant's documented instructions, including with regard to international transfers of personal data, unless Zobi is required to process by law to which it is subject. Where Zobi is required to process by law, it will inform the merchant of that legal requirement before processing, unless the law prohibits such information on important grounds of public interest. The merchant's instructions are set out in the agreement, in this addendum, and in the configuration and use of the service. The merchant is responsible for ensuring it has a lawful basis to collect the personal data and to instruct Zobi to process it, and for the accuracy and legality of the personal data and instructions it provides. Processing on instructions Zobi processes personal data only on the merchant's documented instructions, including those given through the configuration and ordinary use of the service. The merchant is responsible for issuing instructions that comply with applicable data protection law. If Zobi considers that an instruction infringes applicable data protection law, it may inform the merchant, though Zobi is not obliged to provide legal advice on the merchant's compliance and is not obliged to follow any instruction it reasonably considers to be unlawful. Zobi may suspend the affected processing, in whole or in part, until the instruction is withdrawn, amended, or confirmed in writing, without liability for any resulting interruption to the service. Any processing that the merchant requests beyond the documented instructions, or that departs from the standard configuration of the service, is carried out at the merchant's sole risk and cost, and only where Zobi agrees in writing to perform it. Zobi may charge for such additional processing on a time-and-materials basis at its then-current rates. Controller warranties and indemnity The merchant warrants and undertakes, on a continuing basis, that: it has, and will maintain throughout the term, a valid lawful basis under applicable data protection law for the collection of the personal data and for instructing Zobi to process it for the purposes of the service, including any consent or other lawful basis required for sending marketing or transactional messages over iMessage, SMS, and RCS; it has provided all notices, obtained all consents, and met all transparency and opt-out/unsubscribe requirements required of it as controller in relation to the data subjects and the processing, including under applicable electronic-communications and telemarketing laws; its instructions, and Zobi's processing of personal data in accordance with those instructions and the standard operation of the service, will not cause Zobi to breach applicable data protection law; and the personal data it provides or makes available is accurate and lawfully obtained, and the merchant is entitled to disclose it to Zobi and its sub-processors for the purposes of the service. The merchant will defend, indemnify, and hold Zobi (and its officers, employees, and sub-processors) harmless from and against all claims, demands, actions, fines, penalties, losses, damages, and reasonable costs and expenses (including legal fees) arising out of or in connection with: (a) the merchant's breach of the warranties above or of its obligations as controller; (b) the absence of a lawful basis, consent, or required notice for the personal data or the instructions; (c) any instruction given by the merchant that is unlawful or that causes Zobi to act in breach of applicable data protection law; or (d) the inaccuracy or unlawful provision of personal data by the merchant. This indemnity is given by the merchant in its capacity as controller, is in addition to any other remedy available to Zobi, and is not subject to and does not count toward the aggregate liability cap referred to in the Liability section below. Details of processing (Annex 1) This Annex 1 describes the processing carried out by Zobi on the merchant's behalf. Subject matter Provision of the service, namely automated and assisted messaging to the merchant's customers and prospects to recover abandoned checkouts and encourage repeat purchases. Duration For the term of the agreement, plus any additional period during which Zobi is required or permitted to retain personal data under this addendum or applicable law. Nature and purpose Receiving and storing order, checkout, and cart data; generating message content (including with the assistance of a third-party AI model provider); sending and receiving messages over iMessage, SMS, and RCS; and the related hosting, logging, support, and analytics necessary to provide and improve the service for the merchant. Types of personal data Names Phone numbers Email addresses Message content exchanged with data subjects over iMessage, SMS, and RCS Order, checkout, and cart data relating to the merchant's customers and prospects Categories of data subjects The merchant's customers The merchant's prospects and leads (including those who abandon a checkout or sign up) Confidentiality Zobi ensures that the personnel authorized to process the personal data are bound by an appropriate duty of confidentiality, whether by contract or by statutory obligation, and that access to personal data is limited to personnel who need it to provide the service. Security measures (Annex 2) Zobi implements and maintains technical and organizational measures designed to protect personal data against unauthorized or unlawful processing and against accidental loss, destruction, or damage, taking into account the state of the art, the costs of implementation, and the nature, scope, context, and purposes of the processing, as required by GDPR Article 32. These measures are commercially reasonable and appropriate rather than absolute, may evolve over time, and do not amount to a guarantee that personal data will be completely secure; no method of transmission or storage is completely secure. Current measures include: Encryption of personal data in transit; Access controls and least-privilege principles restricting access to personal data; Hosting within the EU on DigitalOcean (Amsterdam) and DigitalOcean Spaces; Regular backups of the systems that store personal data; Logging and monitoring of relevant system activity; Vendor management and review of sub-processors that handle personal data. Zobi may update these measures from time to time provided the updates do not materially reduce the overall level of protection for the personal data. The merchant is responsible for the security of its own systems, store, accounts, and credentials, for controlling access to the service on its side, and for assessing whether the measures described here are appropriate for the personal data it chooses to process through the service. Where the merchant requires specific additional security measures, the parties may agree them in writing, at the merchant's cost. Sub-processors The merchant gives Zobi general written authorization to engage sub-processors to process personal data in connection with the service. The current list of sub-processors is published at /subprocessors. Where Zobi intends to add or replace a sub-processor, it will give the merchant notice (for example by updating the list at /subprocessors or by other reasonable means). The merchant may object to a new sub-processor on reasonable data-protection grounds by written notice within ten (10) days of that notice. The parties will work in good faith to resolve the objection; if it cannot be resolved within a reasonable period, the merchant's sole and exclusive remedy is to terminate the part of the service that requires the use of that sub-processor. Absent a timely written objection, the merchant is deemed to have authorized the new or replacement sub-processor. Zobi imposes data-protection terms on each sub-processor that are no less protective than those in this addendum to the extent applicable to the sub-processor's services. Zobi remains responsible to the merchant for a sub-processor's performance of its data-protection obligations only to the extent required by GDPR Article 28(4), and not further. International transfers Where Zobi transfers personal data outside the European Economic Area, it relies on an appropriate transfer mechanism under applicable data protection law, namely the EU Standard Contractual Clauses (Commission Implementing Decision (EU) 2021/914), together with the UK addendum or international data transfer agreement where the transfer is subject to the UK GDPR, or another appropriate safeguard. Details of where personal data is processed are reflected in the sub-processor list at /subprocessors. Data subject requests Taking into account the nature of the processing and the information available to Zobi, Zobi assists the merchant by appropriate technical and organizational measures, insofar as this is possible, in responding to requests from data subjects exercising their rights under applicable data protection law (such as access, rectification, erasure, restriction, portability, and objection). The merchant, as controller, is responsible for assessing and responding to those requests. Zobi may recover its reasonable costs of providing assistance that goes beyond minimal effort. If Zobi receives a request directly from a data subject relating to personal data processed on the merchant's behalf, it will, where lawful to do so, forward the request to the merchant and will not respond to the request itself except on the merchant's instructions or as required by law. Personal data breach Zobi notifies the merchant without undue delay after becoming aware of a personal data breach affecting personal data processed on the merchant's behalf. The notification will include the information then available to and in the possession of Zobi that is reasonably necessary to help the merchant meet its own breach obligations, and Zobi will provide further information as it becomes available. The merchant, as controller, is solely responsible for assessing the breach and for any notification to supervisory authorities and affected data subjects. Zobi provides reasonable assistance to the merchant in connection with the merchant's obligations to investigate and remediate the breach, and may recover its reasonable costs of assistance that goes beyond minimal effort. Zobi's notification is not, and will not be construed as, an acknowledgement of fault or liability. Assistance Taking into account the nature of the processing and the information available to Zobi, Zobi provides reasonable assistance to the merchant with data protection impact assessments and prior consultations with supervisory authorities where the merchant is required to carry these out under applicable data protection law. Zobi may recover its reasonable costs of providing such assistance where it goes beyond minimal effort. Return and deletion On termination or expiry of the agreement, Zobi deletes or returns the personal data processed on the merchant's behalf at the merchant's choice, and deletes existing copies, within thirty (30) to ninety (90) days, unless Zobi is required to retain the personal data by law. Where the merchant does not make a choice within thirty (30) days of termination or expiry, Zobi may delete the personal data in accordance with its standard retention practices. Backups that contain personal data are deleted in the ordinary course of Zobi's backup cycle and are not separately retrieved for individual deletion before then. Audits and information Zobi makes available to the merchant information reasonably necessary to demonstrate compliance with its obligations under this addendum and allows for and contributes to audits, including inspections, conducted by the merchant or an independent auditor mandated by the merchant. Zobi may satisfy an audit request in the first instance by providing existing third-party certifications, audit reports, or responses to a reasonable security questionnaire, and an on-site or hands-on audit may be requested only where those materials are reasonably insufficient. Such audits are subject to reasonable safeguards, including that they: are requested on reasonable prior written notice; are subject to appropriate confidentiality obligations; are conducted during normal business hours; take place no more than once in any twelve-month period, except where required by a competent supervisory authority or following a personal data breach affecting the merchant's personal data; are carried out at the merchant's cost; are conducted in a manner that does not disrupt Zobi's operations or compromise the security or confidentiality of other customers' data. CCPA / CPRA terms To the extent the California Consumer Privacy Act, as amended by the California Privacy Rights Act (together, "CCPA"), applies to personal information processed under the agreement, Zobi acts as a service provider. Zobi does not sell or share (as those terms are defined under the CCPA) personal information, and does not retain, use, or disclose personal information except as necessary to provide the service to the merchant, as otherwise permitted under the agreement, or as permitted by applicable law. Zobi will comply with applicable CCPA obligations that apply to it as a service provider. Liability Each party's liability arising out of or related to this addendum, whether in contract, tort, or otherwise, is subject to the exclusions and limitations of liability set out in the terms of service at /terms. The addendum and the agreement share one single, combined aggregate liability cap: liability under this addendum is subject to, and counts toward, the same aggregate cap set out in the terms of service, namely the lesser of (a) the fees paid by the merchant in the twelve (12) months before the event giving rise to the liability and (b) one hundred euros (€100). This addendum does not create any separate or additional cap and does not increase the cap in the agreement. Nothing in this addendum or the agreement excludes or limits either party's liability to the extent that liability cannot be excluded or limited under the GDPR or under Estonian mandatory law. The merchant's indemnification obligations under the Controller warranties and indemnity section above are not subject to this cap. General and contact This addendum is governed by the laws of Estonia, consistent with the governing law of the agreement. The competent supervisory authority is the Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon). If any provision of this addendum is held to be invalid or unenforceable, the remaining provisions continue in full force. For data protection questions or to exercise rights described here, contact Zobi OÜ at legal@heyzobi.com. You can also review our privacy policy, our sub-processor list, and our messaging terms. This document is provided for general information and does not constitute legal advice. If you have questions about it, contact us at legal@heyzobi.com.