Data Processing Addendum

Version 1.0.0|Effective: 2026-07-19|Last updated: 2026-07-19

Introduction

This Data Processing Addendum ("DPA") forms part of the Zcope Terms of Service (the "Agreement") between 2morrow.ai, LLC, a Colorado limited liability company doing business as Zcope ("Processor" or "Zcope"), and the Creator or Publisher utilizing the Zcope platform ("Controller" or "Publisher").

This DPA applies exclusively to the extent Zcope processes Personal Data on behalf of the Publisher that is subject to the General Data Protection Regulation (GDPR) or similar applicable data protection laws.

1. Definitions

For the purposes of this DPA:

  • "Data Protection Laws" means all applicable worldwide legislation relating to data protection and privacy, including the EU General Data Protection Regulation 2016/679 ("GDPR"), the UK General Data Protection Regulation, the Swiss Federal Act on Data Protection ("FADP"), and the California Consumer Privacy Act ("CCPA").
  • "Personal Data" means any information relating to an identified or identifiable natural person processed by Zcope on behalf of the Publisher under the Agreement.
  • "Sub-processor" means any third-party data processor engaged by Zcope to assist in fulfilling its obligations with respect to providing the Services.
  • The terms "Controller," "Processor," "Data Subject," "Processing," and "Personal Data Breach" shall have the meanings given to them in the GDPR.

2. Roles and Scope of Processing

2.1. Roles of the Parties. The Parties acknowledge and agree that with regard to the Processing of Personal Data under this DPA, the Publisher is the Data Controller, and Zcope is the Data Processor.

(Note: As defined in the Zcope Privacy Policy, Zcope acts as an independent Data Controller for cross-brand /me Consumer Accounts; this DPA does not apply to Zcope's processing of /me account data).

2.2. Publisher's Instructions. Zcope will process Personal Data only in accordance with Publisher's documented lawful instructions, which are embodied in the Agreement, this DPA, and Publisher's configuration and use of the Zcope Platform.

2.3. Compliance with Laws. Publisher warrants that it has all necessary rights, consents, and legal bases to provide the Personal Data to Zcope for the Processing described in this DPA.

3. Sub-processing

3.1. General Authorization. Publisher grants Zcope general authorization to engage Sub-processors to process Personal Data on Publisher's behalf.

3.2. Current Sub-processors. Zcope currently utilizes the following Sub-processors:

  • Amazon Web Services (AWS) / Supabase: Cloud infrastructure and database hosting (USA).
  • Stripe: Payment processing infrastructure (USA).
  • Resend: Email delivery infrastructure (USA).
  • Google (Gemini): AI processing for content generation and safety screening (USA).

3.3. Sub-processor Obligations. Zcope shall enter into a written agreement with each Sub-processor imposing data protection terms that require the Sub-processor to protect Personal Data to the standard required by Data Protection Laws. Zcope remains liable for the acts and omissions of its Sub-processors to the same extent Zcope would be liable if performing the services directly.

4. Security Measures

Zcope shall implement and maintain appropriate technical and organizational security measures to protect Personal Data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure, or access. These measures include encryption in transit (TLS), encryption at rest, role-based access controls, and regular security reviews, consistent with Article 32 of the GDPR.

5. Personal Data Breach Notification

Upon becoming aware of a Personal Data Breach affecting Publisher's Personal Data, Zcope shall notify the Publisher without undue delay. Zcope will provide Publisher with sufficient information to allow Publisher to meet any obligations to report or inform Data Subjects or Data Protection Authorities of the breach under Data Protection Laws.

6. Data Subject Rights

Zcope shall, to the extent legally permitted, promptly notify Publisher if Zcope receives a request from a Data Subject to exercise their rights (e.g., access, rectification, erasure, portability) relating to Publisher's Personal Data. Zcope will not respond to such requests directly unless authorized by Publisher, but will provide commercially reasonable assistance to Publisher via the Platform's technical features to enable Publisher to fulfill its obligations to respond to such requests.

7. Return or Deletion of Data

Upon termination of the Agreement, or upon Publisher's explicit request, Zcope shall delete or return all Personal Data to Publisher, except where applicable law or valid compliance/anti-spam requirements mandate retention (e.g., suppression logs for CAN-SPAM compliance).

  • Routine Deletions: Creator-initiated subscriber deletions are subject to a 90-day soft-delete grace period before permanent erasure.
  • Data Subject Erasure Requests: Erasure requests initiated pursuant to Data Subject Rights (e.g., GDPR Art. 17) bypass the soft-delete grace period and are purged without undue delay and within 30 days.

8. International Data Transfers

To the extent the processing of Personal Data involves a transfer of data outside of the European Economic Area (EEA), the UK, or Switzerland to a jurisdiction that has not been recognized as providing an adequate level of data protection (such as the United States), the Parties agree that such transfers shall be governed by the Standard Contractual Clauses (SCCs) approved by the European Commission, which are hereby incorporated by reference, with Publisher acting as the "data exporter" and Zcope acting as the "data importer."

9. Limitation of Liability

Each party's and all of its affiliates' liability, taken together in the aggregate, arising out of or related to this DPA — whether in contract, tort, or under any other theory of liability — is strictly subject to the limitations and exclusions of liability set forth in the Agreement (including Section 16, Limitation of Liability, of the Zcope Terms of Service). Nothing in this DPA enlarges either party's aggregate liability beyond that set forth in the Agreement, and any reference in this DPA to a party's liability means that party's aggregate liability under the Agreement and this DPA together.

Annex 1: Details of Processing

Subject Matter and Duration: The subject matter of the processing is the provision of the Zcope SaaS Platform to the Publisher. The duration of the processing is the term of the Agreement between Zcope and the Publisher.

Nature and Purpose of Processing: Zcope provides a platform for creators to host content, manage audiences, send email newsletters, and sell digital products. Personal Data is processed to facilitate these services, including email delivery, AI-assisted content screening and generation, and audience management.

Categories of Data Subjects: Publisher's audience members, newsletter subscribers, assessment/scorecard respondents, community members, and buyers of Publisher's digital products.

Types of Personal Data: Email addresses, names, IP addresses, engagement metrics (e.g., email opens, form submissions), assessment/quiz responses, purchase records, and any user-generated content submitted to Publisher's community or forms.

This document is provided for informational purposes and does not constitute legal advice. Consult a qualified attorney for advice specific to your situation.