Data Processing Terms
Last updated 11 July 2026
These Data Processing Terms form part of the Zorren Terms of Service. They apply where Zorren processes Contact Data on behalf of a Customer. Zorren is operated by Ben Collins, ABN 67 688 063 018, trading as Zorren, from New South Wales, Australia. For legal or data protection questions, contact legal@zorren.app.
1. Relationship with other terms
These Data Processing Terms apply in addition to the Terms of Service and Privacy Policy.
If there is a conflict:
- these Data Processing Terms apply to the processing of Contact Data;
- the Terms of Service apply to commercial, billing, account, liability, suspension, and general service matters;
- the Privacy Policy explains how Zorren handles personal information, including information for which Zorren acts as controller or equivalent responsible party.
Capitalised terms not defined in these Data Processing Terms have the meaning given in the Terms of Service.
2. Parties and roles
For Contact Data:
- the Customer is the controller or equivalent responsible party;
- Zorren is the processor, service provider, or equivalent processing party acting on the Customer's behalf.
The Customer decides why Contact Data is collected, who is added to the Customer's list, what broadcasts are sent, and whether the Customer has a lawful basis, permission, or consent to contact each person.
Zorren processes Contact Data on the Customer's behalf to provide, secure, support, and operate the Zorren service.
Zorren is separately responsible for its own account, billing, authentication, abuse prevention, legal, security, and platform operations data as described in the Privacy Policy.
3. Definitions
In these Data Processing Terms:
Contact means a person whose information is collected, stored, imported, manually added, emailed, unsubscribed, suppressed, or otherwise processed through Zorren on behalf of a Customer.
Contact Data means personal information or personal data relating to Contacts that is processed through Zorren on behalf of a Customer.
Customer Data means data, content, and information submitted to or processed through Zorren by or for a Customer, including Contact Data.
Data Protection Laws means privacy, data protection, electronic communications, spam, and direct marketing laws that apply to the relevant processing, including where applicable the Australian Privacy Act, Australian Spam Act, UK GDPR, UK Data Protection Act, UK PECR, Canadian PIPEDA, Canadian Anti-Spam Legislation, and the New Zealand Privacy Act.
Security Incidentmeans a confirmed breach of security affecting Contact Data within Zorren's systems or those of Zorren's subprocessors acting under Zorren's direction.
Services means the Zorren lead capture and email broadcast service.
Subprocessor means a third-party provider engaged by Zorren to process Contact Data or provide infrastructure needed for the Services.
4. Scope of processing
Zorren processes Contact Data only as needed to provide, secure, support, maintain, and improve the Services, and as otherwise permitted by these Data Processing Terms.
Processing may include:
- capturing submitted Contact information through Zorren-hosted capture pages;
- receiving mapped form fields from Customer websites through the Zorren snippet;
- storing Contact records;
- managing Contact statuses;
- processing manual Contact additions;
- processing Contact imports where the Customer's plan allows it;
- sending Customer broadcasts;
- inserting unsubscribe links and postal address footers into broadcasts;
- processing unsubscribes and resubscribe actions;
- processing bounces, complaints, delivery events, and open events;
- maintaining suppression records;
- providing reporting, exports, and account functionality where available;
- providing support and debugging;
- detecting abuse, spam risk, technical issues, and security issues;
- complying with legal, regulatory, provider, and infrastructure requirements.
Zorren does not use Contact Data to independently market to Contacts.
Zorren does not sell Contact lists.
5. Customer instructions
The Customer instructs Zorren to process Contact Data as needed to provide the Services.
These instructions include processing Contact Data to:
- collect and store Contacts;
- process hosted capture page submissions;
- process Customer website snippet submissions;
- process manual Contact additions and imports;
- send broadcasts chosen by the Customer;
- add required unsubscribe and footer information;
- process unsubscribes, bounces, complaints, delivery events, and open events;
- maintain suppression records;
- provide reporting, export, support, security, and compliance functionality;
- use subprocessors as described in these Data Processing Terms;
- retain and delete data according to these Data Processing Terms, the Privacy Policy, and the Terms of Service.
Zorren may refuse, suspend, or delay an instruction if Zorren reasonably believes the instruction is unlawful, technically impossible, outside the Services, inconsistent with these Data Processing Terms, or creates legal, security, deliverability, provider, recipient, or platform reputation risk.
6. Customer obligations
The Customer is responsible for its Contact Data and use of the Services.
The Customer must:
- comply with Data Protection Laws;
- have a lawful basis, permission, consent, or valid relationship for each Contact;
- keep evidence of how and when Contacts were collected where required;
- ensure manual Contact additions and imports are lawful;
- ensure Customer website forms, privacy notices, consent wording, and field mappings are lawful and accurate;
- ensure hosted capture page custom fields are lawful and appropriate;
- avoid collecting sensitive personal information unless legally permitted and necessary;
- respond to Contact rights requests where the Customer is legally responsible;
- keep business, sender, reply-to, billing, country, and postal address information accurate;
- comply with the Terms of Service and Acceptable Use Policy;
- not use purchased, rented, scraped, harvested, or third-party lists;
- not use Zorren for cold outreach or prohibited sending.
Zorren is not responsible for verifying whether each Contact was lawfully collected or may lawfully be emailed by the Customer.
7. Zorren processor obligations
Zorren will:
- process Contact Data only on Customer instructions, unless required by law;
- process Contact Data only to provide, secure, support, operate, and maintain the Services;
- not sell Contact lists;
- not independently market to Contacts;
- use reasonable technical and organisational measures designed to protect Contact Data;
- restrict access to Contact Data to persons and providers who need access for the Services;
- require authorised persons with access to Contact Data to handle it confidentially;
- reasonably assist the Customer with Contact rights requests where required and practical;
- reasonably assist the Customer with security, incident, and compliance obligations relating to Zorren's processing;
- delete or retain Contact Data according to these Data Processing Terms and the Privacy Policy.
8. Confidentiality
Zorren will restrict access to Contact Data to persons authorised by Zorren who need access to provide, secure, support, maintain, or operate the Services, or to comply with legal, provider, security, or abuse-prevention requirements.
Zorren will ensure those persons are subject to confidentiality obligations or equivalent duties.
9. Security measures
Zorren will use reasonable technical and organisational measures designed to protect Contact Data from misuse, interference, loss, unauthorised access, unauthorised modification, and unauthorised disclosure.
Current measures include:
- HTTPS/TLS for data in transit;
- provider-managed encryption at rest where supported by Zorren's infrastructure providers;
- Clerk authentication;
- account-level access controls;
- signed unsubscribe tokens;
- Stripe-hosted payment processing;
- Stripe and Clerk webhook signature verification;
- AWS SNS signature and topic verification for email events;
- email delivery event validation using message ID correlation;
- customer-controlled open tracking with account and broadcast-level controls;
- honeypot, timing, and rate-limit controls on public capture endpoints;
- automated retention enforcement for time-limited raw data;
- limited access to production data;
- use of infrastructure providers with their own operational security controls.
Zorren may update its security measures as the Services, providers, risks, and available controls change.
Zorren does not claim to provide dedicated security staff, 24/7 monitoring, SOC 2 certification, ISO 27001 certification, penetration testing, or formal enterprise audit programmes unless stated separately in writing.
10. Subprocessors
The Customer gives Zorren general authorisation to use subprocessors to provide the Services.
Zorren's current subprocessors and service providers are listed in Schedule 3.
Zorren may add or replace subprocessors from time to time. Where practical, Zorren will give at least 14 days' notice before adding a material new subprocessor that will process Contact Data.
The Customer may object to a new subprocessor on reasonable data protection grounds by contacting legal@zorren.app during the notice period.
If Zorren cannot reasonably resolve the objection, the Customer may stop using the affected feature or cancel the Services.
Where a subprocessor processes Contact Data on Zorren's behalf and fails to fulfil its data protection obligations, Zorren remains responsible to the Customer for the performance of that subprocessor's data protection obligations to the extent required by applicable Data Protection Laws.
11. International processing and transfers
Zorren is operated from Australia.
Contact Data may be stored or processed in Australia, the United States, and other countries where Zorren or its subprocessors operate.
The Customer authorises Zorren and its subprocessors to process Contact Data in those locations as needed to provide the Services.
Where Data Protection Laws require transfer safeguards for Contact Data, Zorren will use reasonable and legally appropriate safeguards for the relevant transfer.
The Customer is responsible for ensuring that its use of Zorren complies with any international transfer obligations that apply to the Customer as controller or equivalent responsible party.
12. Assistance with Contact rights requests
The Customer is responsible for responding to Contact rights requests where the Customer is the controller or equivalent responsible party.
Zorren will provide reasonable assistance where required and practical, including assistance relating to:
- access;
- correction;
- deletion;
- unsubscribe or withdrawal requests;
- objection or restriction requests where applicable;
- export where available;
- suppression status where relevant.
If a Contact sends a request directly to Zorren, Zorren may refer the request to the relevant Customer.
If the Customer is unresponsive within a reasonable period, or the Customer account no longer exists, Zorren may handle the request directly where legally appropriate.
Zorren may verify identity before acting on a request.
13. Assistance with compliance
Zorren will provide reasonable information to help the Customer assess Zorren's processing of Contact Data, where required by applicable Data Protection Laws.
This may include:
- these Data Processing Terms;
- the Privacy Policy;
- the subprocessor list;
- a summary of security measures;
- retention information;
- information about a relevant Security Incident;
- written responses to reasonable data protection questions.
Zorren is not required to provide information that would compromise security, confidentiality, other customers, trade secrets, provider confidentiality, or platform integrity.
14. Security incidents
Zorren's security incident notification obligation applies only to incidents affecting Contact Data within Zorren's systems or those of Zorren's subprocessors acting under Zorren's direction.
Zorren is not responsible for notifying incidents caused by or occurring within a Customer's own website, systems, credentials, devices, or third-party tools outside Zorren's control.
If Zorren becomes aware of a confirmed Security Incident affecting Contact Data, Zorren will notify the affected Customer without undue delay.
Where legally required and applicable, Zorren aims to notify the affected Customer within 72 hours of becoming aware of the confirmed Security Incident.
A notice may include, where known and relevant:
- the nature of the Security Incident;
- the categories of Contact Data affected;
- the likely consequences;
- measures taken or proposed to address the Security Incident;
- recommended steps for the Customer.
The Customer is responsible for deciding whether it must notify Contacts, regulators, or other parties, unless Data Protection Laws require Zorren to notify directly.
If a Customer's own website, form, credentials, devices, staff, contractors, or non-Zorren tools are compromised, the Customer is responsible for investigating, notifying, and responding to that incident.
15. Deletion and return
During the account term, the Customer may access, export, or delete certain Contact Data through the Services where the Customer's plan and available features allow it.
Before cancelling or deleting an account, the Customer should export any Contact Data it needs where export is available.
After account deletion or termination, Zorren will delete or retain Contact Data according to the Privacy Policy and the retention periods below:
- Contact records: generally deleted or de-identified within 30 days after a verified account-deletion request is completed;
- raw snippet submission payloads: retained for up to 30 days;
- Contact event logs: retained for the life of the account, then generally deleted or de-identified within 30 days after a verified account-deletion request is completed;
- raw email delivery event logs: retained for up to 90 days;
- suppression records: retained for up to 2 years after account deletion;
- billing and tax records: retained for up to 7 years where required;
- minimal account deletion tombstones: may be retained indefinitely.
Zorren may retain limited Contact Data or related records where required or reasonably needed for legal, tax, accounting, security, abuse prevention, suppression, dispute, provider, or compliance purposes.
16. Audit and information rights
On reasonable written request, Zorren will provide information reasonably necessary to demonstrate compliance with these Data Processing Terms.
Zorren may satisfy this obligation by providing:
- these Data Processing Terms;
- the Privacy Policy;
- the subprocessor list;
- a security summary;
- retention information;
- written responses to reasonable questions;
- other relevant documentation Zorren makes generally available.
Zorren is not required to allow on-site audits, physical inspections, source code access, infrastructure access, provider account access, or access to information that would compromise security, confidentiality, other customers, trade secrets, provider confidentiality, or platform integrity, unless legally required or separately agreed in writing.
Requests must be reasonable, proportionate, and not excessive.
17. Legal requests and compelled disclosure
If Zorren receives a legal, regulatory, court, law enforcement, provider, or government request for Contact Data, Zorren will review the request before responding.
Where legally permitted and practical, Zorren will notify the affected Customer.
Zorren may disclose Contact Data where Zorren reasonably believes disclosure is legally required, necessary to comply with provider requirements, necessary to protect Zorren, Customers, Contacts, or others, or necessary to prevent abuse, fraud, spam, or security harm.
Zorren will aim to disclose only the information reasonably required in the circumstances.
18. Sensitive data restriction
Zorren is not designed for sensitive personal information.
The Customer must not submit sensitive personal information to Zorren unless:
- the Customer is legally permitted to do so;
- the collection and processing is necessary for the Customer's lawful purpose;
- the Customer has provided any required notices and obtained any required consent;
- the Customer accepts full responsibility for that data and its legal compliance.
Sensitive personal information may include health information, government identifiers, financial account information, children's information, criminal record information, biometric information, or other information treated as sensitive under applicable law.
Zorren may delete, restrict, or require removal of sensitive personal information if Zorren reasonably believes it creates legal, security, platform, or recipient risk.
19. Changes to these Data Processing Terms
Zorren may update these Data Processing Terms as the Services, providers, security measures, legal requirements, or business operations change.
If Zorren makes material changes, it will take reasonable steps to notify Customers, such as by email, dashboard notice, or updating the date at the top of these Data Processing Terms.
Continued use of Zorren after changes take effect means the Customer accepts the updated Data Processing Terms, unless applicable law requires a different process.
20. Liability
All liability arising under or relating to these Data Processing Terms is subject to the liability limits, exclusions, and indemnities in the Terms of Service.
These Data Processing Terms do not increase Zorren's liability beyond the limits set out in the Terms of Service, except to the extent that applicable law does not allow that limitation.
21. Contact
For legal or data protection questions, contact legal@zorren.app.
Schedule 1 — Processing details
| Item | Details |
|---|---|
| Subject matter | Zorren's provision of lead capture, contact management, email broadcast, unsubscribe, suppression, and related service functionality. |
| Duration | The Customer account term, plus the retention periods stated in the Privacy Policy and these Data Processing Terms. |
| Nature of processing | Collection, receipt, storage, organisation, retrieval, use, transmission, email sending, suppression, logging, analysis, deletion, and retention. |
| Purpose of processing | To provide, secure, support, maintain, and operate the Zorren Services for the Customer. |
| Categories of data subjects | Contacts, enquirers, subscribers, recipients, customers of the Customer, prospective customers of the Customer, and people who submit forms connected to the Customer. |
| Categories of personal data | Name, email address, source, status, consent records, timestamps, hosted capture page custom fields, broadcast recipient records, unsubscribe records, bounce records, complaint records, delivery records, open records, suppression records, and related event history. |
| Sensitive data | Not intended. Customers must not submit sensitive personal information unless legally permitted and responsible for doing so. |
| Frequency | Continuous while the Customer uses the Services. |
| Customer instructions | As set out in these Data Processing Terms, the Terms of Service, product settings, broadcasts, imports, form mappings, and support requests. |
Schedule 2 — Security measures
Zorren's current security measures include:
- HTTPS/TLS for data in transit;
- provider-managed encryption at rest where supported by infrastructure providers;
- Clerk authentication;
- account-level access controls;
- signed unsubscribe tokens;
- Stripe-hosted payment processing;
- Stripe and Clerk webhook signature verification;
- AWS SNS signature and topic verification for email events;
- email delivery event validation using message ID correlation;
- honeypot, timing, and rate-limit controls on public capture endpoints;
- limited access to production data;
- use of established infrastructure providers;
- abuse, bounce, complaint, unsubscribe, and suppression handling;
- retention limits for raw payloads and email event logs;
- manual security incident assessment and response.
Zorren may update these measures over time as the Services, providers, and risks change.
Schedule 3 — Subprocessors and service providers
| Provider | Purpose | Data processed |
|---|---|---|
| Convex | Backend, database, serverless functions, and file storage | Account data, Contact Data, broadcasts, suppression records, email event records, settings, and uploaded logos |
| AWS SES | Email delivery | Recipient email addresses, sender details, reply-to details, subject lines, and broadcast message content |
| AWS SNS | Email delivery event notifications | Delivery, bounce, complaint, open, and related email event metadata |
| Clerk | Authentication | Customer login identity and authentication data. Clerk does not normally process Contact Data |
| Stripe | Billing and payment processing | Customer billing data and Stripe identifiers. Stripe does not process payment card numbers through Zorren and does not normally process Contact Data |
| Vercel | Hosting and deployment | Website, application, routing, technical, and service operation data |
These Data Processing Terms were last reviewed 11 July 2026. For questions contact legal@zorren.app.