This Data Processing Agreement (“DPA”) governs how PKG AB, a Swedish company (Reg. No. SE559008922201), hereafter referred to as the “Service Provider,” “we,” “us,” or “our,”, processes personal data on behalf of Customers in connection with providing the Zensli service.
This DPA is intended to establish the responsibilities of the parties where the Service Provider processes personal data under the Customer’s instructions. The Customer determines how Zensli is configured and used for the Customer’s websites, applications, systems, users, and business purposes.
1 Introduction
This DPA forms part of the agreement between the Customer and the Service Provider for use of the Zensli service.
The purpose of this DPA is to define the respective responsibilities of the parties where the Service Provider processes personal data on behalf of the Customer.
This DPA applies only to processing performed by the Service Provider on behalf of the Customer. Processing for which PKG AB independently determines the purposes and means, such as Customer account administration, billing, security, support, and certain service operations, is governed by the Zensli Privacy Policy and applicable law.
2 Definitions
- Customer
- The organisation that has entered into an agreement to use the Zensli Service and that determines how the Service is configured and used for its websites, applications, systems, and business purposes.
- Service Provider
- PKG AB, the provider of the Zensli Service and, where applicable, the Data Processor, service provider, contractor, or equivalent entity processing personal data on behalf of the Customer.
- Service
- The Zensli service, including functionality for website and application analytics, visitor identification, interaction tracking, segmentation, profiling, security analysis, reporting, integrations, automation, and activation of Customer-controlled data.
- Customer Data
- Personal data, event data, identifiers, configuration data, submitted information, and other information processed through the Service on behalf of the Customer.
- Data Protection Legislation
- The General Data Protection Regulation (GDPR), Regulation (EU) 2016/679, applicable national data-protection and electronic communications laws, and other privacy or consumer privacy laws applicable to the processing covered by this DPA.
- Data Protection Terms
- Terms such as Data Controller, Data Processor, Data Subject, Personal Data, Processing, Business, Service Provider, Contractor, Consumer, Sale, Sharing, and Appropriate Technical and Organisational Measures shall, where applicable, be interpreted according to the relevant Data Protection Legislation.
- Documented Instructions
- Instructions provided by the Customer through this DPA, the applicable agreement, written communications, API requests, integrations, administrative settings, retention settings, tracking configuration, or other configuration of the Service.
3 Roles of the Parties
With respect to Customer Data processed through the Service, the Customer normally acts as Data Controller, business, or equivalent responsible entity under applicable law. The Service Provider normally acts as Data Processor, service provider, contractor, or equivalent entity processing data on the Customer’s behalf.
The Customer determines the purposes for which Customer Data is processed and determines how available Zensli functionality is configured and used.
This includes decisions regarding which tracking and analytics functions are enabled, whether visitors are identified, whether browser or device signals are used, what information is collected from forms, how profiles and analytical results are used, which external systems receive data, and how long Customer Data is retained.
The Service Provider does not determine the Customer’s legal basis for processing and does not determine whether a particular Customer configuration requires consent, notice, opt-out, recognition of privacy preference signals, or other measures under applicable law.
Where PKG AB independently processes information for purposes such as account administration, billing, service security, fraud prevention, support, or legal compliance, PKG AB may act as Data Controller or an equivalent responsible entity for that separate processing.
4 Nature and Purpose of Processing
The Service Provider processes Customer Data for the purpose of providing the Zensli Service in accordance with the Customer’s configuration and documented instructions.
Depending on the Customer’s configuration, processing may include collecting, receiving, recording, structuring, storing, organising, analysing, pseudonymising, identifying, matching, aggregating, scoring, segmenting, transmitting, retrieving, displaying, exporting, deleting, and otherwise processing Customer Data as necessary to provide the Service.
Processing may support functionality including:
- Website and application traffic analytics.
- Page-view, event, click, download, form, media, and interaction tracking.
- Visitor and user identification where configured by the Customer.
- Association of multiple identifiers or interactions with a Customer-controlled visitor or user profile.
- Segmentation and behavioural analysis.
- Engagement scoring, churn-risk analysis, classifications, and other analytical indicators.
- Bot, abuse, security, or suspicious-activity detection.
- Data export and transmission to CRM, marketing automation, analytics, databases, or other systems selected and configured by the Customer.
- Customer-defined alerts, monitoring, reporting, workflows, and automation.
The Service Provider shall not use Customer Data to create independent advertising profiles, sell Customer Data, or build a cross-Customer identity graph for its own independent purposes.
Customer Data may be aggregated or de-identified where reasonably necessary to provide, secure, maintain, or improve the Service, provided such use is consistent with applicable law and does not identify a Customer’s individual end users.
5 Categories of Personal Data Processed
The categories of Customer Data processed depend on the Customer’s configuration of the Service. Such data may include:
- IP address and related network information.
- Geographic information derived from network data, such as city, region, country, approximate location, ASN, or network organisation.
- Browser, device type, operating system, user agent, language, platform, and similar technical information.
- Screen dimensions and other browser or device characteristics.
- Cookies, local-storage identifiers, pseudonymous visitor identifiers, browser signals, device signals, fingerprints, or similar identifiers where enabled or used by the Customer.
- Date, time, session, and visit information.
- Pages and screens visited, including URLs, paths, titles, and navigation activity.
- Referrer information.
- Marketing, campaign, and URL parameters.
- Clicks, downloads, external links, media interactions, forms, and other events.
- Internal search terms or search interactions.
- Custom dimensions, variables, events, parameters, metadata, and Customer-defined content.
- User IDs, external IDs, Customer IDs, or other identifiers configured by the Customer.
- Email addresses, phone numbers, names, and other contact or identifying information submitted by individuals or supplied through Customer-controlled systems.
- E-commerce or transaction-related information where configured, such as order identifiers, dates, product interactions, or abandoned-cart activity.
- Profiles, segments, classifications, scores, engagement indicators, churn-risk indicators, and similar derived information.
- Information received from or transmitted to Customer-selected CRM, marketing automation, analytics, database, or other connected systems.
The data subjects affected are primarily visitors, users, prospects, customers, contacts, or other individuals interacting with the Customer’s websites, applications, communications, or connected systems.
The Service Provider does not independently determine the sensitivity, lawfulness, relevance, or necessity of Customer Data submitted or collected through Customer-configured functionality. The Customer is responsible for determining which categories of information may lawfully be processed for its purposes.
Passwords, authentication secrets, full payment card details, bank account credentials, security codes, or other information that the Service is not designed to process must not be intentionally submitted to Zensli.
The Customer must not intentionally configure the Service to collect special-category, highly sensitive, protected health, biometric, government-issued identification, precise geolocation, or similar sensitive personal data unless such processing has been expressly agreed with PKG AB and appropriate safeguards and legal requirements have been established.
Where the Service provides configuration mechanisms for identifying or excluding particular form fields or data types, the Customer is responsible for configuring those mechanisms appropriately.
6 Obligations of the Service Provider
- Processing Instructions: The Service Provider shall process Customer Data only on documented instructions from the Customer, including instructions expressed through the Customer’s configuration and use of the Service, unless processing is required by applicable law.
- Purpose Limitation: The Service Provider shall not process Customer Data for unrelated independent purposes or combine Customer Data with personal data received from unrelated Customers for independent advertising or identity-building purposes.
- Confidentiality: The Service Provider shall protect the confidentiality of Customer Data and ensure that personnel authorised to process Customer Data are subject to appropriate confidentiality obligations.
- Security: The Service Provider shall implement appropriate technical and organisational measures designed to protect Customer Data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure, or access.
- Compliance with Instructions: Where required by applicable Data Protection Legislation, the Service Provider shall inform the Customer if, in its reasonable opinion, a documented instruction infringes applicable Data Protection Legislation.
- Data Subject Requests: Where a data subject submits a request concerning Customer Data directly to the Service Provider, the Service Provider shall, where appropriate, direct or forward the request to the Customer and shall provide reasonable assistance in accordance with applicable law and this DPA.
- Subprocessors: The Service Provider shall ensure that subprocessors processing Customer Data are subject to appropriate contractual data-protection obligations.
- Personal Data Breaches: The Service Provider shall notify the Customer without undue delay after becoming aware of a personal data breach affecting Customer Data and shall provide information reasonably available to assist the Customer in meeting applicable notification obligations.
- Assistance: Taking into account the nature of the processing and information available to the Service Provider, the Service Provider shall provide reasonable assistance to the Customer concerning applicable data-subject rights, data-protection impact assessments, security obligations, breach notification, and consultations with supervisory authorities where required.
- Deletion and Return: Upon termination of the Service, the Service Provider shall delete or return Customer Data in accordance with this DPA, the applicable agreement, Customer instructions, and legal retention requirements.
- Audit Information: The Service Provider shall make available information reasonably necessary to demonstrate compliance with applicable processor obligations and shall cooperate with reasonable audit or assessment requests subject to appropriate confidentiality, security, scope, and cost arrangements.
7 Customer Obligations
The Customer is responsible for the lawfulness of its collection and use of Customer Data and for determining whether and how the available Zensli functionality is appropriate for its purposes and jurisdictions.
- Legal Basis: The Customer is responsible for establishing and documenting a valid legal basis for processing Customer Data where required by applicable law.
- Consent: Where consent is required for the Customer’s use of tracking, browser or device storage, fingerprinting, analytics, identification, marketing, profiling, or other functionality, the Customer is responsible for obtaining and managing valid consent before enabling the relevant processing.
- Notices: The Customer is responsible for providing clear, accurate, and sufficiently detailed privacy and tracking notices to affected individuals.
- Opt-Out and Privacy Choices: The Customer is responsible for providing and honouring applicable opt-out mechanisms, withdrawal of consent, privacy preference signals, Global Privacy Control signals, or other legally required privacy choices.
- Regulatory Compliance: The Customer shall comply with applicable privacy, data-protection, electronic communications, consumer-protection, and marketing laws in each jurisdiction relevant to its use of the Service.
- Configuration: The Customer is responsible for configuring tracking, identification, form processing, integrations, profiling, retention, and other Zensli functionality consistently with the Customer’s chosen privacy approach and legal requirements.
- Data Minimisation: The Customer shall take reasonable steps to limit Customer Data to information relevant and necessary for the Customer’s documented purposes.
-
Form Data and Exclusions:
The Customer is responsible for determining which forms and form
fields may be processed through the Service. The Customer shall use
the exclusion mechanisms provided by Zensli, including
data-zensli-ignore, or other appropriate technical measures, to exclude individual form fields or entire forms containing sensitive, confidential, unnecessary, prohibited, or otherwise inappropriate information from collection by the Service. - Sensitive Data: The Customer shall not intentionally submit prohibited or unsupported sensitive information and is responsible for ensuring that any permitted sensitive information is processed lawfully and with appropriate safeguards.
- Integrations and Recipients: Where the Customer configures the Service to send Customer Data to another system, platform, CRM, marketing tool, database, endpoint, or recipient, the Customer is responsible for selecting that recipient and ensuring the transfer and subsequent use are lawful.
- Sale and Sharing: The Customer is responsible for determining whether its use or disclosure of Customer Data constitutes a sale, sharing, targeted advertising, cross-context behavioural advertising, or another regulated disclosure under applicable law and for implementing any required notices and opt-out mechanisms.
- Profiling and Automated Decisions: The Customer is responsible for determining whether use of Zensli profiles, scores, classifications, segments, churn-risk indicators, or automation constitutes profiling or automated decision-making regulated by applicable law.
- Retention: The Customer is responsible for selecting retention periods appropriate to its purposes, legal basis, and applicable requirements.
- Data Subject Rights: The Customer is responsible for receiving, evaluating, authenticating, and responding to requests from individuals concerning Customer Data, except to the extent applicable law provides otherwise.
- Data Accuracy: The Customer acknowledges that analytics and identification technologies may not always identify individuals or activity with complete accuracy. Shared devices, browser restrictions, inaccurate input, changing identifiers, network conditions, and other technical factors may result in incomplete or incorrect attribution.
- Verification and Use: The Customer is responsible for evaluating Customer Data and analytical results before relying on them for material actions concerning individuals.
The availability of a feature, setting, integration, identifier, tracking method, or analytical capability in Zensli does not constitute a determination by PKG AB that the Customer may use that functionality without consent, notice, opt-out, contractual restrictions, or another legal requirement.
8 Customer Privacy Controls and Configuration
Zensli is a configurable service. The Customer may use available settings and implementation choices to adapt the Service to the Customer’s privacy requirements.
Depending on the functionality available under the Customer’s subscription and implementation, configuration may include choices relating to:
- Whether tracking is enabled.
- When tracking begins.
- Consent-dependent or consent-independent operation where technically supported.
- Browser, device, fingerprint, cookie, or local storage functionality.
- Visitor and user identification.
- Collection and handling of form information.
-
Exclusion of individual form fields or entire forms from collection,
including through
data-zensli-ignore. - Data categories captured through custom events.
- Retention periods.
- Integrations and data destinations.
- Profiles, segments, scoring, classifications, and automation.
- Recognition and handling of privacy or opt-out signals where supported.
The Customer is responsible for reviewing available controls and selecting settings appropriate to the Customer’s intended processing.
The Service Provider may provide documentation, configuration options, APIs, or other technical tools intended to assist the Customer. Such functionality does not constitute legal advice and does not replace the Customer’s responsibility to assess applicable requirements.
9 Subprocessors
The Service Provider may engage subprocessors where reasonably necessary to provide, maintain, support, or secure the Service.
The Service Provider shall ensure that subprocessors processing Customer Data are subject to appropriate confidentiality, security, and data-protection obligations consistent with the Service Provider’s obligations under this DPA.
The Service Provider remains responsible for the performance of its subprocessors to the extent required by applicable Data Protection Legislation.
Where required by applicable law or the applicable agreement, the Customer will be informed of material changes concerning subprocessors and provided an opportunity to raise reasonable data-protection objections.
10 International Data Transfers
Where the Service Provider or a subprocessor transfers Customer Data to a country requiring a recognised transfer mechanism under applicable Data Protection Legislation, the Service Provider shall implement an appropriate mechanism where required.
Such mechanisms may include an adequacy decision, Standard Contractual Clauses, another approved transfer mechanism, or another lawful basis for the transfer.
Appropriate supplementary safeguards may be implemented where reasonably required based on the destination, recipient, data, processing, and identified risks.
Where the Customer configures Zensli to transmit Customer Data to a third-party service, endpoint, CRM, marketing platform, database, or other recipient selected by the Customer, that transmission constitutes a Customer-directed instruction.
The Customer is responsible for assessing the lawfulness of Customer-selected destinations and for establishing any required contractual or international-transfer mechanism relating to those recipients.
11 Data Subject and Consumer Requests
The Customer is normally responsible for responding to requests by individuals exercising privacy or data-protection rights in relation to Customer Data.
Depending on applicable law, such requests may concern access, information, correction, deletion, restriction, portability, objection, withdrawal of consent, opt-out, or other applicable privacy rights.
Taking into account the nature of the processing, the Service Provider shall provide reasonable technical and organisational assistance to enable the Customer to respond to valid requests where Customer Data can be reasonably identified within the Service.
If the Service Provider receives a request directly from an individual relating to Customer Data, the Service Provider may direct the individual to the relevant Customer or forward the request to the Customer, unless applicable law requires another response.
12 Personal Data Breaches and Security Incidents
The Service Provider shall maintain reasonable procedures for identifying, investigating, mitigating, and documenting security incidents affecting the Service.
Where the Service Provider becomes aware of a personal data breach affecting Customer Data, the Service Provider shall notify the Customer without undue delay in accordance with applicable Data Protection Legislation.
The notification shall include information reasonably available to the Service Provider concerning the nature of the incident, affected data, potential consequences, mitigation measures, and other information reasonably required to assist the Customer in meeting applicable legal obligations.
Notification of an incident does not constitute an admission of fault or liability by the Service Provider.
13 Technical and Organisational Measures
The Service Provider implements technical and organisational measures designed to provide a level of security appropriate to the nature of the Service, Customer Data, processing activities, and associated risks.
Access Control
Access to Customer Data and production environments is restricted according to authorisation, responsibility, and operational need.
Encryption
HTTPS or equivalent transport protection is used for supported data transmissions, with appropriate encryption controls applied to stored data where implemented.
Monitoring
Relevant system and application activities are logged and monitored to support security, incident detection, troubleshooting, investigation, and auditing.
Availability
Backup, redundancy, recovery, and operational measures are used as appropriate to support availability and resilience of the Service.
Additional technical and organisational measures are described in Appendix 1.
14 Responsibility and Liability
Each party is responsible for its own obligations under this DPA and applicable Data Protection Legislation.
The Customer remains responsible for determining the purposes and lawfulness of Customer-controlled processing, selecting appropriate privacy settings, issuing lawful instructions, and determining how Customer Data and analytical outputs are used.
The Service Provider is responsible for performing its processor obligations under this DPA and for processing Customer Data in accordance with documented Customer instructions, subject to applicable law.
The Service Provider does not warrant that a particular Customer configuration, use case, legal basis, consent mechanism, privacy notice, or Customer-selected integration complies with every law or jurisdiction.
Liability, indemnification, exclusions, and limitations shall otherwise be governed by the applicable agreement between the parties and mandatory provisions of applicable law.
15 Duration, Retention, and Termination
This DPA becomes effective when incorporated into or accepted as part of the Customer’s agreement for the Zensli Service and continues for as long as the Service Provider processes Customer Data on behalf of the Customer.
During the term of the Service, Customer Data is retained according to the Customer’s configuration, documented instructions, applicable agreement, and technical capabilities of the Service.
The Customer is responsible for selecting retention settings appropriate to its purposes and legal obligations.
Upon termination, the Service Provider shall delete or return Customer Data in accordance with the Customer’s documented instructions and the applicable agreement. Unless otherwise agreed, Customer Data will normally be deleted or anonymised within 30 days following termination, except where continued retention is required by applicable law or reasonably necessary for backup expiration, dispute resolution, security, or enforcement of legal rights.
Data remaining temporarily in backups shall remain protected under this DPA and shall not be restored for ordinary business use except where reasonably necessary for disaster recovery, security, legal compliance, or similar purposes.
A1 Appendix 1 – Technical and Organisational Measures
The following describes categories of measures used by the Service Provider to protect Customer Data. Specific implementations may change over time as technologies, risks, and the Service evolve, provided that the overall level of protection is not materially reduced.
Access Control
- Authentication mechanisms for administrative and Customer access.
- Authorisation controls limiting access according to account, role, responsibility, and operational need.
- Restricted access to production environments and Customer Data.
- Processes for managing, reviewing, and revoking access where appropriate.
- Confidentiality obligations for personnel with authorised access.
Customer Data Separation
- Logical controls designed to associate Customer Data with the appropriate Customer account or server context.
- Access controls intended to prevent unauthorised access to another Customer’s data.
- Customer-controlled identifiers, configuration, credentials, and integration settings are scoped according to the relevant Customer context where applicable.
- Customer Data is not intentionally combined across unrelated Customers to create an independent cross-Customer identity graph.
Transmission and Storage Protection
- HTTPS or equivalent encrypted transport for supported communications.
- Appropriate encryption controls for stored data where implemented.
- Protection of credentials, secrets, and authentication information using appropriate technical mechanisms.
Logging and Monitoring
- Logging of relevant system and application activity.
- Monitoring intended to support detection of suspicious activity, misuse, attacks, errors, and operational problems.
- Security and operational logs may be retained separately where reasonably necessary for security, auditing, abuse prevention, or legal purposes.
Incident Detection and Response
- Processes for identifying and investigating relevant security incidents.
- Procedures for containment, mitigation, remediation, and documentation where appropriate.
- Customer notification procedures for personal data breaches where required.
Availability and Recovery
- Backup and recovery mechanisms appropriate to the Service.
- Redundancy and fault-tolerance measures where appropriate.
- Operational procedures supporting restoration of service after relevant incidents.
Data Minimisation and Retention
- Configurable functionality may allow Customers to control certain categories of processing and retention.
- Customer Data is retained according to applicable Customer instructions, agreements, and system settings.
- Data may be deleted, anonymised, aggregated, or allowed to expire according to applicable retention processes.
Personnel and Operational Security
- Personnel authorised to access relevant systems are subject to confidentiality obligations.
- Appropriate security and privacy awareness is maintained for personnel based on their role and responsibilities.
- Access to systems and Customer Data is limited to legitimate operational purposes.
16 Privacy Policy, Interpretation, and Acceptance
For additional information about how PKG AB processes personal data in connection with the Zensli Service, please refer to the Zensli Privacy Policy .
This DPA and the Privacy Policy address different processing roles. This DPA primarily governs processing performed by PKG AB on behalf of the Customer. The Privacy Policy also describes processing for which PKG AB independently determines the purposes and means.
If this DPA conflicts with another provision of the applicable Customer agreement concerning the processing of Customer Data, this DPA shall prevail to the extent of that conflict unless the parties have expressly agreed otherwise in writing.
Nothing in this DPA limits obligations or rights that cannot lawfully be limited under applicable Data Protection Legislation.
Zensli provides configurable technology. The Customer determines which available functionality is appropriate for its organisation and how the Service is configured in light of the Customer’s purposes, users, legal basis, jurisdictions, privacy notices, consent requirements, opt-out obligations, retention requirements, and other applicable rules.