Skip to content
connor
Legal

Connor — Data Processing Agreement

Zindex Limited trading as Connor · Version 1.1 · 25 September 2026

This Data Processing Agreement (DPA) forms part of the Agreement between Zindex Limited (Processor) and the Customer named in the Order Form (Controller) under the Connor Terms of Service. It applies when Zindex processes personal data on the Customer's behalf to provide Connor Financial Promotions, including any agreed scheduled promotion monitoring. It does not cover the separate AI Monitoring product or other services unless expressly agreed in a separate scope and processing schedule.

1. Definitions

1.1 Data Protection Law means the UK GDPR, the Data Protection Act 2018 and, where applicable, the EU GDPR, each as amended.

1.2 Customer Personal Data means personal data processed by Zindex on the Customer's behalf in providing the Service.

1.3 Sub-processor means a third party engaged by Zindex to process Customer Personal Data.

1.4 Controller, processor, personal data, processing, data subject and personal data breach have the meanings given in Data Protection Law. Other capitalised terms have the meanings given in the Terms of Service.

2. Roles and scope

2.1 The Customer is the controller and Zindex is the processor of Customer Personal Data. Where the Customer acts as processor for another controller, Zindex is its sub-processor; the Customer must have that controller's authority to appoint Zindex and give the instructions in this DPA.

2.2 The subject matter, nature, purpose and duration of the processing, and the types of personal data and data subjects, are set out in Annex 1 and the completed Order Form Deployment Schedule, which forms part of this DPA. Complete that schedule before processing starts. The Service covers financial promotion reviews, including selected scheduled monitoring of agreed websites and social channels at frequencies up to once daily. The Deployment Schedule records the sources, frequency, material, authorised providers and retention. Employee AI monitoring and endpoint scanning are excluded.

2.3 If this DPA conflicts with the Agreement on personal data, this DPA prevails. Mandatory international transfer terms prevail over this DPA. No variation may reduce protections required by law or those transfer terms.

3. Instructions

3.1 Zindex will process Customer Personal Data only on the Customer's documented instructions, including for international transfers, unless required by applicable law. In that case Zindex will inform the Customer of the legal requirement before processing, unless the law prohibits this on important grounds of public interest. Instructions comprise the Agreement, the completed Deployment Schedule and authorised users' requests within that agreed scope. Use of an unselected feature does not extend the instructions.

3.2 Zindex will tell the Customer promptly if it believes an instruction infringes Data Protection Law.

3.3 Zindex will not use Customer Personal Data to train or fine-tune any AI model that is shared with other customers or offered generally.

3.4 The Customer is responsible for having a lawful basis for the processing and for giving any required notices to data subjects.

3.5 Processing personal data to create anonymous statistics requires documented Customer instructions in the Deployment Schedule, specifying the purpose, permitted fields, aggregation controls and retention. Removing identifiers alone does not establish anonymity. Zindex will not use Customer Personal Data for advertising, shared demonstrations or a shared evaluation corpus.

4. Confidentiality

4.1 Zindex will ensure that everyone authorised to process Customer Personal Data is bound by a duty of confidentiality and accesses it only as needed to provide the Service.

5. Security

5.1 Zindex will implement appropriate technical and organisational measures to protect Customer Personal Data, taking into account the nature of the processing and the risks involved. The measures are described in Annex 2.

5.2 Zindex may update the measures, provided the overall level of protection is not reduced.

6. Sub-processors

6.1 The Customer authorises the Sub-processors identified in the completed Deployment Schedule, by legal entity, service and processing locations. The provider information below supports that record; listing an integration alone does not authorise its use. An alternative AI provider may receive data only if its processing route is authorised.

6.2 Under the Customer's general authorisation for subsequent changes, Zindex will notify its nominated contact directly in writing of an intended addition or replacement, with sufficient information and time to make a reasonable data-protection objection before processing begins. A website update alone is not notice. If the parties cannot resolve the objection, the Customer may terminate the affected Service. Pending resolution, Zindex will use an authorised route or suspend the affected processing.

6.3 Zindex will impose data protection obligations on each Sub-processor that are no less protective than this DPA, and remains liable for their performance.

Provider information

The providers belowsupport Connor's platform and business operations. The signed deployment schedule identifies the selected legal entities, services, processing and access countries, retention and transfer safeguards. Inclusion here does not authorise every integration for every customer.

ProviderPurposeLocation evidence
VercelApplication and website functionsDublin, Ireland — verified production deployments
VercelPrivate file storageLondon, United Kingdom — verified connected store
SupabaseDatabaseIreland — owner-supplied project screenshot; production connection to confirm
ClerkSign-in and user authenticationAccount-specific locations to confirm
AnthropicSelected AI-assisted reviewService and account-specific locations to confirm
OpenAISelected transcription and AI reviewService and account-specific locations to confirm
ResendTransactional emailProcessing and retention locations to confirm
Google WorkspaceBusiness and authorised support correspondenceAccount-specific storage and access locations to confirm
ApifySelected link retrievalProcessing and access locations to confirm

A provider's headquarters or default configuration does not establish this deployment's processing locations. Google Workspace supports Zindex's own business correspondence and may process customer material when used for authorised support; its role depends on the purpose.

Any additional retrieval or proxy provider must be identified, assessed and authorised before customer material is sent to it. Both AI providers require selection in the deployment schedule before either can be used as an alternative route.

Upstash and Sentry were not configured in the production deployment inspected during this review. Enabling either requires the applicable supplier review and authorisation.

This information supports the completed Deployment Schedule and does not replace the direct notice required by clause 6.2.

7. International transfers

7.1 Zindex will not transfer Customer Personal Data outside the UK unless the transfer complies with Data Protection Law, using an adequacy decision or regulations, or the International Data Transfer Addendum to the EU Standard Contractual Clauses or another approved mechanism.

7.2 Transfers from the EEA to Zindex in the UK rely on the European Commission's adequacy decision for the UK. If that decision ceases to apply, the parties will put in place the appropriate EU Standard Contractual Clauses.

7.3 The Deployment Schedule must identify storage, backup, remote-access and onward-processing countries and the applicable transfer safeguards, assessments and supplementary measures. Any reliance on adequacy or a data privacy framework is limited to recipients and processing actually covered. If no lawful route is available, the affected transfer must not start or continue.

8. Data subject requests

8.1 Zindex will assist the Customer, by appropriate technical and organisational measures, to respond to requests from data subjects exercising their rights.

8.2 If Zindex receives a request directly, it will forward it to the Customer promptly and will not respond substantively except on the Customer's instructions or as required by law. It may acknowledge receipt and explain the parties' roles.

9. Personal data breaches

9.1 Zindex will notify the Customer without undue delay after becoming aware of a personal data breach affecting Customer Personal Data.

9.2 The notice will describe, as far as then known, the nature of the breach, the categories and approximate number of data subjects and records affected, the likely consequences, the measures taken or proposed, and a contact for further information. Zindex will provide further information as it becomes available without delaying the initial notice for a completed investigation.

9.3 Zindex will take reasonable steps to contain and remedy the breach and will assist the Customer with any notifications it must make.

10. Assistance

10.1 Taking account of the nature of processing and information available to it, Zindex will assist the Customer with its obligations under Articles 32–36, including security, breach notifications, data protection impact assessments and prior consultations with supervisory authorities relating to the Service.

11. Audits

11.1 Zindex will make available to the Customer the information necessary to demonstrate compliance with this DPA and Article 28 of the UK GDPR.

11.2 Zindex will allow and contribute to audits, including inspections, by the Customer or its appointed auditor. Routine audits are limited to one in any 12-month period, on at least 30 days' written notice, during business hours and subject to reasonable confidentiality terms. These limits do not restrict information requests under clause 11.1 or apply to regulator access, legally required audits, urgent investigations, relevant breaches, material changes or reasonable cause concerning compliance. Arrangements and charges must not obstruct legally required access.

12. Deletion and return

12.1 When the Agreement ends, Zindex will, at the Customer's choice, return or delete Customer Personal Data and delete existing copies unless applicable law requires retention. The standard return arrangement provides 30 days of secure export access or an assisted export, followed by deletion within a further 30 days. The Customer may instruct earlier return or deletion. The Deployment Schedule records the formats, deadlines and any specific legal retention requirement.

12.2 The Deployment Schedule records backup and provider-copy expiry periods. Pending deletion, those copies remain protected, beyond ordinary use and accessible only for authorised recovery or legal retention. Any restored data remains subject to deletion instructions.

12.3 Zindex will confirm deletion in writing on request.

13. Liability

13.1 Each party's liability under this DPA is subject to the limitations in the Terms of Service, except where mandatory law or applicable transfer terms prevent limitation. Those limits do not restrict individuals' statutory rights or regulatory powers.

14. Term

14.1 This DPA continues for as long as Zindex processes Customer Personal Data.

Annex 1 — Details of processing

ItemDetails
Subject matterReview of financial promotions submitted by the Customer or retrieved from agreed websites and social channels through selected scheduled monitoring.
Nature of processingReceiving, storing, retrieving submitted links and promotional material from agreed monitored sources, converting files for review, text extraction, audio transcription, AI-assisted analysis, recording comments and decisions, notifications, export and deletion.
PurposeHelping the Customer's reviewers identify potential compliance issues in promotions and keep a record of review decisions.
DurationThe term, agreed exit period and any authorised backup or legally required retention, while Customer Personal Data remains held.
Data subjectsThe Customer's users and contacts; people who appear in or are named in submitted or monitored promotions and necessary source context, such as presenters, endorsers and creators.
Personal dataNames, work contact details, user identifiers, images, voices, social media handles, statements in promotions, comments and review decisions.
Special category dataNone. The Customer must not submit special category data or select monitoring sources intended to collect it unless agreed in writing. Any incidental collection must be restricted and addressed under the Customer’s documented instructions.

Annex 2 — Security measures

Zindex must maintain these measures for the agreed deployment. The Deployment Schedule records implementation evidence, backup coverage and any additional requirements before customer processing starts; this annex is a contractual baseline, not a certification of completed testing.

  • Access control: unique user accounts, role-based access within each customer workspace, and administrator access limited to authorised Zindex personnel.
  • Customer separation: each request and file is authorised against the customer and user role.
  • Encryption: data is encrypted in transit and at rest by our hosting and database providers.
  • File storage: customer files are held in private storage and served only through authenticated requests.
  • AI providers: AI providers are used under terms that prohibit training on customer data.
  • Backups and recovery: maintain the database and file backup coverage, frequency, retention and recovery arrangements agreed in the Deployment Schedule, and verify restoration before activation.
  • Incident response: security incidents are investigated and notified in accordance with section 9.
  • Deletion: customer data is deleted in accordance with section 12.