[ Legal · DPA ]
Last updated: June 1, 2026
This DPA forms part of the agreement between Zanzo Streaming (“Processor”) and the Organiser (“Controller”) and sets out how we process personal data on the Organiser’s behalf under Article 28 GDPR. It applies whenever we process personal data of the Organiser’s viewers/customers.
01
Roles
For personal data about an Organiser’s viewers and customers, the Organiser is the Controller and Zanzo is the Processor. Zanzo only processes that data on the Organiser’s documented instructions, which include the configuration choices made in the product.
02
Subject matter, duration, nature & purpose
Subject matter: provision of the streaming platform. Duration: for as long as the Organiser uses the Service (plus any limited wind-down). Nature & purpose: hosting, transcoding and streaming content; authenticating viewers; processing purchases; and producing analytics and billing for the Organiser.
03
Categories of data & data subjects
04
Processor obligations
05
Sub-processors
The Controller authorises Zanzo to engage the sub-processors below to deliver the Service. We impose data-protection terms on each that are no less protective than this DPA, and remain responsible for their performance. We’ll give notice of intended changes so the Controller can object.
06
Security
We maintain measures appropriate to the risk, including encryption in transit, access controls and least-privilege, signed/expiring URLs for protected media, host-scoped session cookies, and EU-hosted infrastructure. Measures may evolve as the Service improves, without materially reducing protection.
07
Data subject requests & breaches
We will, taking into account the nature of processing, assist the Controller in responding to requests to exercise data-subject rights. We will notify the Controller without undue delay after becoming aware of a personal-data breach affecting the Controller’s data, with the information reasonably available to us.
08
International transfers
We aim to keep processing within the EU/EEA. Where a sub-processor transfers data outside the EEA, the transfer relies on an adequacy decision or the EU Standard Contractual Clauses.
09
Return & deletion
On termination, we will, at the Controller’s choice, delete or return the personal data we process on their behalf, and delete existing copies, unless retention is required by law (e.g. accounting records).
10
Contact
To countersign this DPA or raise a data-protection question, contact privacy@conferencestreaming.eu. See also our Privacy Policy.