DPA
Data processing agreement
This agreement under Article 28 GDPR (Auftragsverarbeitungsvertrag) covers the personal data you put into Zebu. It is part of the Zebu terms. You accept it by using the service.
1. Parties
The customer is the business that holds a Zebu workspace (the controller). The processor is the provider: Alan Woo, Leuschnerdamm 13, 10999 Berlin, Germany (“I” or “Zebu”).
2. Subject matter and duration
I host and run Zebu, a time tracking and invoicing service, for the customer. This agreement lasts as long as I process personal data for the customer’s workspace, and ends when the workspace and its backups are deleted.
3. Nature and purpose
I store, organise, display, calculate, export and delete data, create documents such as invoice PDFs, and send emails the customer asks me to send. I do this only to provide the service.
4. Data and data subjects
Categories of data
- Names, email addresses, roles and settings of team members;
- time entries, notes, timesheets, cost and billing rates;
- client and contact names, addresses, emails, phone numbers and tax ids;
- invoices, estimates, payments, expenses and receipts;
- records of emails opened and invoice links viewed (time, browser details, hashed IP address);
- any other data the customer enters or imports.
The service is not designed for special categories of data (Art. 9 GDPR). The customer should not enter them.
Data subjects
- The customer’s owners, employees and contractors who use the workspace;
- the customer’s clients and their contact persons;
- recipients of invoices, estimates and reminders;
- other people named in the customer’s data.
5. Instructions
I process the data only on the customer’s documented instructions. The terms, this agreement and the customer’s use of the app’s features are those instructions. I process data otherwise only where EU or German law requires it, and then tell the customer first unless the law forbids that. If I think an instruction breaks data protection law, I tell the customer.
6. Confidentiality
Everyone who can access the data is bound to confidentiality. Today that is only me.
7. Security measures
I take the measures required by Article 32 GDPR. They include:
- a separate database and file folder for each workspace;
- encrypted connections (HTTPS with HSTS);
- passwords hashed with bcrypt; API and app tokens stored hashed; passkeys supported;
- email verification, sign-in rate limits, CSRF protection and a strict content security policy;
- role-based access within each workspace;
- a firewall that allows only web traffic and key-only SSH, with fail2ban;
- an operator admin area reachable only over a private network;
- encrypted backups every hour to a separate Hetzner Storage Box, and every night to hardware in Germany that the server cannot reach; daily server images kept for 7 days;
- regular automatic checks that backups can be read back;
- automated security tests and dependency audits on every code change;
- production access limited to me.
I may change these measures, but never to a lower level of protection.
8. Subprocessors
The customer allows me to use the subprocessors in the annex. I bind each one to data protection duties equal to these.
I give at least 30 days’ notice by email before adding or replacing a subprocessor. The customer can object within that time for good reason. If I cannot resolve it, the customer can cancel and receives a prorated refund.
9. Assistance
The app lets the customer find, correct, export and delete data, which answers most requests from data subjects. Where it does not, I help. If a data subject writes to me directly, I pass the request on to the customer.
I also help the customer with security, breach notifications, data protection impact assessments and consultation with authorities (Articles 32 to 36 GDPR), as far as my part of the processing allows.
10. Personal data breaches
I tell the customer without undue delay after I become aware of a breach affecting their data. I say what happened, which data is affected, the likely consequences and what I am doing about it, and add details as I learn them.
11. End of the service
The customer can export all data at any time. When the workspace is deleted, I delete its live data immediately and its backup copies within 90 days, unless the law requires me to keep it.
If Zebu is discontinued, the terms apply: at least 6 months’ notice by email, with export available throughout that period.
12. Audits
I show compliance by documentation: this agreement, my security measures and answers to reasonable written questions. If that is not enough, the customer or an auditor bound to confidentiality may inspect by appointment, with reasonable notice and at the customer’s cost.
13. Transfers outside the EU
I transfer data outside the EU and EEA only as Chapter V GDPR allows, such as under the EU-US Data Privacy Framework or the EU Standard Contractual Clauses.
14. Other terms
Liability follows the terms and Article 82 GDPR. If this agreement and the terms conflict on data protection, this agreement wins. German law applies.
Annex: subprocessors
| Subprocessor | Purpose | Location | Safeguard |
|---|---|---|---|
| Hetzner Online GmbH, Industriestr. 25, 91710 Gunzenhausen, Germany | Server hosting, backup storage | Helsinki, Finland; Storage Box in the EU | EU |
| Sendinblue SAS (Brevo), 106 boulevard Haussmann, 75008 Paris, France | Sending invoices, estimates, reminders and service emails | EU | EU |
Stripe handles only billing for the customer’s own Zebu subscription; the privacy policy covers that, not this agreement. Zebu itself sends no workspace data to any AI provider. AI assistants the customer connects are chosen by the customer and are not my subprocessors; data they read goes to the customer’s own provider under that provider’s terms.
Last updated 23 September 2026