DRAFT — LEGAL REVIEW REQUIRED
Data Processing Addendum
Last updated: September 14, 2026. This draft describes how Zambo processes data when a customer uses Zambo services. It is not legal advice or an executed agreement.
1. Scope and roles
The customer is the controller or business that decides what information to send to Zambo. Zambo is a processor only where it handles that information to provide the requested service. For a no-account free request, Zambo may act as the service provider for the request and operational security data; there is no assumption that a controller-processor relationship exists for every public request.
2. Data processed
Zambo processes the job text, structured inputs, URLs, repository references, wallet addresses, transaction hashes, and other content the user chooses to submit. Requests may be routed to live tools or model providers needed to return the requested result. Receipts are keyed by a UUID and contain execution metadata such as timestamps, status, tool names, and a hash. Do not send passwords, private keys, seed phrases, card numbers, or confidential information that should not be processed.
3. Purposes and instructions
Processing is limited to executing requested tools, returning results and receipts, verifying requested payments or transactions, preventing abuse, securing the service, troubleshooting, and maintaining service records. Zambo does not sell submitted personal information. Zambo does not use a free request as a promise of human review or as independent verification of the requested facts.
4. Sub-processors
Zambo may use infrastructure, hosting, database, payment, blockchain-RPC, email, and AI/model providers to provide the requested feature. The current provider list and applicable notices should be confirmed with Zambo before signing a customer-specific agreement; this draft does not claim that a fixed sub-processor list is complete.
5. Retention and deletion
Operational logs, rate-limit records, payment records, and receipts may be retained for the period reasonably needed to provide the service, prevent abuse, resolve disputes, meet legal obligations, and maintain auditability. A customer may request deletion of customer-controlled personal data by contacting Zambo; deletion may be limited where retention is required for legal, security, payment, or fraud-prevention reasons. Public blockchain records cannot be deleted by Zambo.
6. Security and incidents
Zambo applies the safeguards described on the security page. Zambo will provide legally required notice of a confirmed personal-data incident through the contact channel available for the customer, subject to applicable law and security constraints.
7. Contact
For a DPA request or deletion request, contact brennanzambo@zambo.dev. This draft requires legal review before it is incorporated into a customer contract.