Data processing agreement
The terms on which we process personal data on your behalf, as your processor, under the GDPR and the Swiss FADP.
DRAFT · NOT LEGAL ADVICE
This document records how Zuger intends to operate and is published so you can read it before you sign up. It is a working draft pending review by counsel in each of our three jurisdictions, and it is not legal advice to you. The executed version you receive at signup is the one that governs. Last updated 13 September 2026.
Roles
This agreement is with Zuger Technologies OÜ, Tallinn, Estonia. You are the controller of personal data contained in the content you connect — your customers, employees, candidates and counterparties. We are your processor. Where we determine our own purposes (your account, our billing, platform security) we are a controller, and the privacy policy applies instead.
Scope and duration
We process personal data only to provide the platform, for as long as your account exists, and then for the deletion period set out below. The subject matter is the operation of autonomous agents inside tools you connect; the duration is the term of your subscription.
Categories
Data subjects — your employees, contractors, candidates, customers, suppliers and their staff. Data — identifiers and contact details, employment and payroll data, financial and transaction records, contract contents, correspondence, and whatever else sits in the tools you connect.
Our obligations
We process only on your documented instructions, which include your mandates and thresholds. We keep processing confidential and bind everyone with access. We apply the technical and organisational measures described on the security page. We assist you with data-subject requests, impact assessments and regulator questions.
Subprocessors
Model providers are Anthropic and OpenAI, each with an EU residency option you select per company; bank feeds arrive read-only through the aggregators named on the subprocessors page. You give general authorisation for the subprocessors listed on the subprocessors page. We give 30 days notice before adding one, and you may object; if we cannot resolve your objection you may terminate the affected service without penalty. Every subprocessor is bound by terms no weaker than these.
International transfers
Transfers outside the EEA rely on an adequacy decision or on the EU Standard Contractual Clauses, together with a transfer impact assessment we will share on request.
Security
Encryption in transit and at rest, per-tenant key separation, scoped per-connection tokens reachable only by the agents whose mandate names them, least-privilege access with named approval, append-only audit logging, and annual third-party penetration testing.
Breach notification
We notify you without undue delay and in any event within 72 hours of becoming aware of a personal data breach affecting your data, with what happened, what data was involved, what we have done and what we recommend you do.
Audit
Once a year, or after a breach affecting you, you may audit our compliance — by questionnaire, by reviewing our reports and test results, or on site with reasonable notice and confidentiality undertakings.
Deletion and return
On termination we return or delete personal data at your choice. Deletion completes within 30 days, including from backups on their normal rotation, except where Estonian or EU law requires retention — notably the seven-year accounting record — in which case what is retained stays protected by these terms.
Questions about this?
Write to privacy@zuger.ai for anything on this page. A person answers, not a portal.