ZeroBadge Data Processing Addendum
Version 1.0 · Effective October 6, 2026
This Data Processing Addendum ("DPA") is part of the Master Service Agreement between ZeroBadge ("ZeroBadge") and Customer.
1. Roles
Customer is the "business" and "controller" of personal information about its Workers and Admins that is processed through the Service ("Customer Personal Information"). ZeroBadge is Customer's "service provider" and "processor." Customer determines the purposes of the processing and is responsible for its lawfulness, including all notices and consents.
2. Purpose and scope
2.1 ZeroBadge will process Customer Personal Information only for the limited and specified business purposes of providing, securing, maintaining, supporting, and improving the Service for Customer, as described in the MSA and Privacy Policy, and as Customer otherwise instructs in writing.
2.2 Subject matter and types of data. Worker name, contact details, employer, and role; Badge assignment; Device Data including precise location derived from cellular, WiFi, Bluetooth, and satellite signals, motion data, button presses, battery level, device identifiers, and timestamps; Events; acknowledgment records; and portal usage data. Admin name, contact details, and account activity.
2.3 Duration. For the term of the MSA and the retention periods in Section 7.
3. ZeroBadge's commitments
ZeroBadge will not:
(a) sell or share Customer Personal Information, as those terms are defined in the California Consumer Privacy Act ("CCPA");
(b) retain, use, or disclose Customer Personal Information for any purpose other than the business purposes in Section 2, or outside the direct business relationship between ZeroBadge and Customer, except as the CCPA permits a service provider to do;
(c) combine Customer Personal Information with personal information it receives from other sources, except as the CCPA permits a service provider to do.
ZeroBadge will comply with the obligations that apply to it as a service provider under the CCPA and other applicable privacy laws and will provide the level of privacy protection those laws require. ZeroBadge will notify Customer if it determines it can no longer meet these obligations. Customer may, on reasonable notice, take reasonable and appropriate steps to confirm that ZeroBadge uses Customer Personal Information consistently with Customer's legal obligations, and to stop and remediate any unauthorized use.
4. Sub-processors
Customer authorizes ZeroBadge to use sub-processors, including providers of cloud hosting, databases, authentication, cellular connectivity, device messaging, location services, mapping, payments, email and text messaging, and error monitoring. ZeroBadge will bind each sub-processor to written obligations consistent with this DPA and remains responsible for their performance of those obligations. The current list is in the Privacy Policy and may be updated from time to time.
5. Security
ZeroBadge will maintain reasonable administrative, technical, and physical safeguards designed to protect Customer Personal Information, including encryption in transit, access controls, and restricted internal access to Device Data. No system is perfectly secure, and ZeroBadge does not guarantee that unauthorized access will never occur.
6. Security incidents
If ZeroBadge becomes aware of unauthorized access to Customer Personal Information in its systems, it will notify Customer without unreasonable delay and provide the information reasonably available to it. Customer is responsible for any notices to Workers, regulators, or others that the law requires of Customer. Notice of an incident is not an admission of fault.
7. Retention and deletion
7.1 Device Data. Raw Device Data, including raw location readings, is deleted or irreversibly de-identified within 90 days after collection.
7.2 Events and related records. Events, Badge assignment history, and Worker acknowledgment records are retained for four (4) years from the date they are created and are then deleted or irreversibly de-identified. These periods continue after termination of the MSA unless Customer requests earlier deletion in writing and no law or legal hold requires ZeroBadge to keep the data.
7.3 Backups. Copies in backup systems are overwritten in the ordinary course after the periods above.
7.4 Exceptions. ZeroBadge may retain data longer where required by law, legal process, or a legal hold, or to establish or defend legal claims, and may retain aggregated or de-identified data indefinitely.
7.5 Customer's records. Customer is responsible for exporting and retaining any records it is legally required to keep. ZeroBadge is not Customer's recordkeeper.
8. Individual requests
Customer is responsible for responding to requests from Workers and others to exercise privacy rights. If ZeroBadge receives such a request about Customer Personal Information, it may direct the individual to Customer, and it will give Customer reasonable assistance, at Customer's expense, in responding.
9. Location of processing
Customer Personal Information is processed and stored in the United States. The Service is not offered for use outside the United States.
10. General
The limitation of liability in the MSA applies to this DPA. If this DPA conflicts with the MSA on a data protection matter, this DPA controls. If any provision of this DPA is held unenforceable, the rest remains in effect.
D4 · version 1.0 · sha256 c482f092dce420b1f92c90b3b6a80a7efcb03bbb82974c7b462f6c424012e339