Zerva

Data Processing Addendum

1.1 · Effective August 21, 2026

This Data Processing Addendum ("DPA") is part of the Zerva Master Service Agreement ("MSA") between Divinify LLC, a Georgia limited liability company ("Divinify," "we," "us"), and the customer that accepted the MSA ("Customer," "you"). It applies whenever we process personal information on your behalf through the Zerva platform.

If this DPA conflicts with the MSA or the Terms of Service on a data-protection matter, this DPA controls. On all other matters, the MSA controls. Capitalized terms not defined here have the meaning given in the MSA.

1. Roles

1.1 You are the controller; we are the processor. For Applicant Data and all other personal information in your account, you decide what is collected, why, how long it is kept, and what happens to it. We process it only to provide the Service, on your instructions. Under U.S. state privacy laws, you are the "controller" or "business" and we are the "processor" or "service provider."

1.2 Your responsibilities as controller. You are responsible for: the lawfulness of the data you collect and submit; providing applicants any required privacy notices; obtaining consents (including for messaging, recording, and AI analysis); responding to applicants' rights requests; and complying with employment, anti-discrimination, automated-employment-decision, telemarketing, and recording laws that apply to you.

1.3 Our instructions. Your instructions to us are the MSA, this DPA, and your configuration and use of the Service. We will not process personal information for any other purpose. If we believe an instruction violates applicable law, we will tell you and may pause that processing.

1.4 Independent controller data. We act as a controller — not a processor — for your own business account information (contact details, billing, support history, and usage data about your account). That processing is described in our Privacy Policy, not this DPA.

2. What We Process

2.1 Subject matter and duration. We process personal information to provide the Zerva applicant tracking platform, for as long as your subscription is active plus the post-termination period in Section 8.

2.2 Categories of individuals. Job applicants and candidates; your employees, recruiters, and other authorized Users; and other individuals whose information you choose to submit.

2.3 Categories of personal information. Depending on your configuration: name; email address; phone number; mailing address or general location; résumé and its contents; work and education history; application form responses; interview scheduling data; one-way video interview submissions; live interview recordings and transcripts; AI-generated scores, rankings, and summaries; SMS, MMS, and call records and content; consent and opt-out records; and hiring pipeline status, notes, and dispositions.

2.4 Sensitive information. The Service is not designed for, and you should not submit, government identification numbers, financial account numbers, health information, or biometric identifiers. If your configuration or use causes such information to be submitted, you remain solely responsible for the additional legal requirements that attach to it.

2.5 Nature and purpose of processing. Collection, recording, organization, storage, retrieval, transmission, transcription, AI analysis, display, export, and deletion — in each case to provide the Service.

2.6 Geographic scope. This DPA covers personal information about individuals located in the United States. You have agreed under MSA Section 4(e) not to submit personal information about individuals located outside the United States. See Section 10.

3. Our Obligations

We will:

  • (a) process personal information only on your documented instructions (Section 1.3);
  • (b) not sell personal information and not share it for cross-context behavioral advertising, as those terms are defined under applicable state privacy law;
  • (c) not use personal information for our own purposes, including our own marketing;
  • (d) not use Customer Data or Applicant Data to train artificial-intelligence models, and require our AI subprocessors to be contractually prohibited from training their models on it;
  • (e) not combine personal information from your account with information from other sources, except as permitted by law for a service provider;
  • (f) ensure personnel with access are bound by confidentiality obligations;
  • (g) limit access to personnel who need it to perform their role;
  • (h) maintain the security measures in Section 5;
  • (i) assist you as described in Sections 6 and 7; and
  • (j) notify you if we determine we can no longer meet our obligations under applicable privacy law.

4. Subprocessors

4.1 Authorization. You authorize us to engage subprocessors to help provide the Service. We remain responsible for their performance of the obligations in this DPA.

4.2 Requirements. Before engaging a subprocessor, we conduct reasonable diligence and put in place a written contract imposing data protection obligations no less protective than those in this DPA.

4.3 Current subprocessors.

| Subprocessor | Purpose | Data involved | |---|---|---| | Supabase | Database and file storage | All Customer Data stored in the platform | | Vercel | Application hosting | Data in transit through the application | | Cloudflare (R2) | Storage of one-way applicant video submissions | Video submissions and related metadata | | Telnyx | SMS, MMS, and voice communications | Phone numbers, message content, call records | | Twilio | SMS, MMS, and voice communications (legacy accounts during provider transition) | Phone numbers, message content, call records | | Anthropic | AI analysis, scoring, and summaries | Résumé text, transcripts, and application content submitted for analysis | | Recall.ai | Live interview recording and transcription | Meeting audio/video and transcripts | | Resend | Transactional email | Email addresses and message content | | Stripe | Payment processing | Your billing information (not Applicant Data) | | Railway (n8n) | Workflow automation | Data passing through automated workflows |

The current list is maintained at zerva.us/legal.

4.4 Changes and objection. We may add or replace subprocessors. We will give you at least 30 days' notice before a new subprocessor begins processing, by email or in-Service notice, and by updating the list at zerva.us/legal. If you have a reasonable, good-faith data-protection objection, tell us at info@zerva.us within those 30 days and we will work with you in good faith to address it. If we cannot, you may cancel your subscription without further charge, effective before the new subprocessor begins processing — this is your exclusive remedy for an objection.

We may engage a replacement subprocessor immediately, with notice as soon as reasonably practicable, where necessary to maintain the Service or address a security or availability emergency.

5. Security

5.1 Measures. We maintain technical and organizational measures appropriate to the risk, including:

  • Encryption in transit (TLS) and encryption at rest for stored data
  • Row-level security in our database, so each customer's data is logically isolated and inaccessible to other customers
  • Private storage buckets for interview media, with access only through short-lived, authorized links — media is not publicly accessible by URL
  • Access controls and authentication limiting personnel and User access to what their role requires
  • Audit logging of significant actions within the platform
  • Subprocessor diligence and contractual data protection obligations
  • Backups with defined rotation, and restoration procedures

5.2 Changes. We may update our security measures as technology and threats evolve, provided we do not materially reduce overall protection.

5.3 Your responsibilities. You are responsible for the security of your own environment: credentials, User account management, permission settings, devices, and how you configure the Service. Do not share logins between people.

6. Security Incidents

6.1 Notification. If we become aware of a personal data breach — a confirmed unauthorized access to, disclosure of, or loss of personal information we process for you — we will notify you without undue delay and in any case within 72 hours of becoming aware.

6.2 Contents. Our notice will describe, to the extent known: the nature of the incident, the categories and approximate volume of information affected, the likely consequences, the measures taken or proposed, and a contact point for further information. Where we cannot provide all details at once, we will provide them in phases as our investigation progresses.

6.3 Cooperation. We will take reasonable steps to contain and remediate the incident and will reasonably assist you with your own notification obligations to applicants and regulators.

6.4 Your obligations. You are responsible for determining whether the incident requires notification to applicants or regulators and for making those notifications, since you are the controller and hold the relationship with the individuals. Our notice to you is not an admission of fault or liability.

6.5 Your own incidents. Tell us promptly at info@zerva.us if you become aware of a compromise of your account credentials or any unauthorized access to your account.

7. Rights Requests and Assistance

7.1 Requests come to you. Applicants exercise their rights with you, not with us. You are responsible for verifying, evaluating, and responding to those requests.

7.2 If they contact us. If an applicant contacts us directly about their information, we will not respond substantively. We will direct them to the hiring office and, where the law requires or you instruct us, forward the request to you.

7.3 Our assistance. Taking into account the nature of the processing, we will provide reasonable assistance — through the Service's built-in access, export, correction, and deletion functions — to help you respond to requests for access, correction, deletion, and portability. Where the Service's tools are not sufficient, we will provide reasonable additional assistance; we may charge for assistance that is unreasonable in scope or frequency, on notice to you before doing so.

7.4 Deletion capability. The Service provides functions for you to delete applicant records and associated media, including video submissions and interview recordings. You are responsible for using them to meet your own deletion obligations, including any statutory deadlines such as those under state AI video interview laws.

7.5 Regulatory cooperation and assessments. We will provide reasonably available information to help you complete data protection assessments, respond to regulator inquiries, and demonstrate compliance, at your reasonable request and expense.

7.6 AI Feature descriptions. We maintain a plain-language description of what each AI Feature evaluates and how it produces its output at zerva.us/legal (MSA Section 7.2). You may use it to prepare applicant notices required by automated-employment-decision laws; the accuracy and sufficiency of any notice you give remain your responsibility.

8. Deletion and Return

8.1 During the subscription. You may export or delete data at any time using the Service's tools.

8.2 On termination. For 30 days after termination, you may export your Customer Data using the Service's export tools or request a reasonable export from us in a standard format.

8.3 Deletion. After that 30-day window, we will delete Customer Data from active systems within a further 30 days, and it will age out of backups on our normal backup rotation. We may retain information where required by law, and any retained information remains subject to this DPA.

8.4 Certification. On written request made within the 30-day export window, we will confirm deletion in writing once completed.

8.5 Phone numbers. Phone numbers port out with you as described in MSA Section 10.3.

9. Audit

9.1 Information. On your reasonable written request, no more than once in any 12-month period, we will provide information reasonably necessary to demonstrate our compliance with this DPA — including a written description of our security measures and, where available, security assessments or reports for our subprocessors.

9.2 On-site audits. Given the size of our organization and the shared, multi-tenant nature of the platform, we do not offer customer-conducted on-site audits or penetration testing of the production environment. Where a law that applies to you requires an audit right we cannot satisfy through Section 9.1, contact us and we will work with you in good faith on a reasonable alternative.

10. International Transfers

Zerva is offered for use in the United States and all processing occurs in the United States. We do not knowingly process personal information originating in the European Union or United Kingdom, and this DPA does not include GDPR-specific terms or transfer mechanisms. You have agreed under MSA Section 4(e) not to use the Service to process information about individuals located outside the United States; if you do so in breach of that Section, you are solely responsible for any resulting obligations under non-U.S. law.

11. Liability and General

11.1 Liability. Each party's liability under this DPA is subject to the limitations and exclusions in MSA Section 17, including the 12-month cap.

11.2 Term. This DPA takes effect when you accept the MSA and continues until we have deleted the personal information we process for you under Section 8.

11.3 Changes. We may update this DPA on at least 30 days' notice, consistent with MSA Section 19. Material changes get a new version number and effective date. We will not make changes that materially reduce the protections in this DPA.

11.4 Contact. Data protection questions and notices: info@zerva.us.