Last updated 8 October 2026

Data processing addendum

How cf0, Corp. processes personal data for your firm, under Article 28 of the GDPR and US state privacy laws.

This addendum is part of the terms of service. It applies to your firm without a signature. If your firm needs a signed copy, or the Standard Contractual Clauses signed separately, email luca@cf0.ai.

1. Scope and parties

This Data Processing Addendum (“DPA”) is between cf0, Corp., 131 Continental Dr, Suite 305, Newark, DE 19713, United States (“cf0”, “we”, “us”), and the firm that uses cf0 under the terms of service or under a signed cf0 contract (“your firm”, “you”). It forms part of that agreement (the “Agreement”). For a firm that first accepts the Agreement on or after 8 October 2026, it applies from that acceptance. For a firm that accepted the Agreement earlier, it applies from 7 November 2026.

It covers both ways to work with cf0: Tasks only, and a cf0 contract. It applies for as long as cf0 processes Customer Personal Data, also after the Agreement ends. Words with a capital letter that this DPA does not define have the meaning that the Agreement gives them.

2. Definitions

  • Applicable Data Protection Laws means the privacy and data protection laws that apply to cf0’s processing of Customer Personal Data: as far as they apply, the EU GDPR, the UK GDPR and the UK Data Protection Act 2018, the Swiss Federal Act on Data Protection, and the US State Privacy Laws.
  • Customer Personal Data means personal data that your firm, or anyone acting for it, puts into the Service, connects to it, or causes Zero to collect, and that cf0 processes for your firm to provide the Service. It does not include the account, billing, sales and website data for which cf0 is the controller, as described in the privacy policy.
  • GDPR means the EU General Data Protection Regulation (Regulation (EU) 2016/679) and, where UK law applies, the UK GDPR.
  • Restricted Transfer means a transfer of Customer Personal Data from the EEA, the UK or Switzerland to a recipient in another country, where no adequacy decision of the authority that applies to that transfer covers that recipient. Each transfer to cf0 in the United States is a Restricted Transfer.
  • SCCs means the standard contractual clauses that the European Commission approved in Implementing Decision (EU) 2021/914.
  • Security Incident means a breach of cf0’s security that leads to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, Customer Personal Data. Unsuccessful attempts that do not compromise Customer Personal Data, such as failed sign-ins, pings, port scans or blocked denial-of-service attacks, are not Security Incidents.
  • Subprocessor means a third party that cf0 engages to process Customer Personal Data for the Service.
  • UK Addendum means the International Data Transfer Addendum to the SCCs that the UK Information Commissioner issued under section 119A of the Data Protection Act 2018.
  • US State Privacy Laws means the comprehensive consumer privacy laws of US states, such as the California Consumer Privacy Act, and their regulations, as far as they apply to cf0’s processing.

“Controller”, “processor”, “data subject”, “personal data”, “processing” and “supervisory authority” have the meanings in the GDPR. Under US State Privacy Laws, they include “business”, “service provider”, “contractor” and “personal information” as those laws define them.

3. Roles

For Customer Personal Data, your firm is the controller and cf0 is its processor. Where your firm itself acts for someone else, such as a landlord whose property it manages, your firm is a processor and cf0 is its subprocessor. Under US State Privacy Laws, cf0 is your firm’s service provider or contractor.

cf0 is the controller of the personal data it needs to run its own business: sign-in and account data, billing data, the sales and onboarding details described in the privacy policy, and data from visitors to cf0.ai. This DPA does not cover that data. The privacy policy does.

Annex 1 sets out the subject matter, duration, nature and purpose of the processing, the types of personal data and the categories of data subjects.

4. Your instructions

cf0 processes Customer Personal Data only on your firm’s documented instructions, unless the law that applies to cf0 requires otherwise. In that case cf0 tells your firm before it processes, unless that law forbids it. Your firm’s instructions are:

  • the Agreement and this DPA;
  • the settings your firm chooses in cf0, such as its approval rules, its connected accounts and the channels it turns on;
  • the tasks, answers and approvals that your firm’s staff give Zero, on cf0.ai or from an AI assistant; and
  • other written instructions that agree with the Agreement. An instruction outside the Service needs a written agreement between us first.

If cf0 thinks that an instruction breaks the GDPR or another data protection law, cf0 tells your firm.

5. Our personnel

cf0 gives access to Customer Personal Data only to personnel who need it to provide, support, secure or fix the Service. Each of them is bound by a duty of confidentiality.

6. Security

cf0 keeps the technical and organisational measures in Annex 2 to protect Customer Personal Data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure or access. cf0 can change those measures, but a change never lowers the overall protection of Customer Personal Data.

Your firm is responsible for its side of security: who it lets into its organisation in cf0, the credentials and devices its staff use, the accounts it connects, and its own copies of data it cannot lose. Your firm has looked at the measures in Annex 2 and agrees that they are appropriate for the data it puts into cf0.

7. Security incidents

cf0 tells your firm without undue delay after it becomes aware of a Security Incident. The notice goes to your firm’s admins by email. It says, as far as cf0 then knows, what happened, which categories and about how many data subjects and records it affects, its likely consequences, what cf0 has done and will do about it, and who at cf0 your firm can contact. cf0 adds what it learns later.

cf0 takes reasonable steps to contain the incident and helps your firm meet its own duty to notify a supervisory authority or data subjects. Your firm decides whether to notify them. A notice from cf0 is not an admission of fault or liability.

8. Subprocessors

Your firm gives cf0 general authorisation to engage Subprocessors. Annex 3 lists the Subprocessors that cf0 uses today, what each one does and where it processes data. cf0 may keep using them.

  • cf0 engages each Subprocessor under a written contract with data protection obligations that protect Customer Personal Data at least as well as this DPA, as far as they apply to its service.
  • cf0 stays responsible to your firm for the work of each Subprocessor, as if cf0 did it itself.
  • At least 15 days before a new Subprocessor starts to process Customer Personal Data, cf0 updates Annex 3 and emails your firm’s admins with its name, what it does and where.
  • Your firm can object in writing within those 15 days, on reasonable grounds about the protection of personal data. We then work in good faith to find a solution. If we find none in a reasonable time, your firm can end the Agreement by written notice, and pays only what it owes up to that date.

The AI assistant your firm’s staff use to reach Zero, such as ChatGPT or Claude, and the services your firm connects to cf0, such as its mailbox, calendar or property-management system, are your firm’s own providers. They are not cf0’s Subprocessors. What reaches them is held under your firm’s agreement with them.

9. International transfers

cf0 is a United States company. cf0’s primary database, file storage and Zero’s agent storage are held under European Union jurisdiction, and cf0’s api servers run in Frankfurt, Germany. Some Subprocessors process data outside the EEA, mainly in the United States. Annex 3 says where.

From the EEA

For a Restricted Transfer from the EEA, the SCCs apply and are part of this DPA, with these choices:

  • Modules. Module Two applies where your firm is a controller. Module Three applies where your firm is a processor for someone else.
  • Clause 7. The optional docking clause does not apply.
  • Clause 9. Option 2, general written authorisation, applies. The notice period is the one in section 8 of this DPA.
  • Clause 11. The optional language does not apply.
  • Clauses 17 and 18. Option 1 applies. The SCCs are governed by the law of Ireland, and the courts of Ireland settle disputes under them.
  • Annexes. Annex I of the SCCs takes its details from Annex 1 of this DPA, with your firm as data exporter and cf0 as data importer. The competent supervisory authority is the one of the EU Member State where your firm is established, or, if your firm is not established in the EU, the one that Clause 13 identifies. Annex II takes its details from Annex 2, and Annex III from Annex 3.

From the UK and Switzerland

For a Restricted Transfer from the UK, the SCCs apply as the UK Addendum changes them. The tables of the UK Addendum take their details from this DPA, and the importer may end the UK Addendum as its section 19 allows. For a Restricted Transfer from Switzerland, the SCCs apply with these changes: references to the GDPR mean the Swiss Federal Act on Data Protection, references to the EU and its Member States mean Switzerland, and the supervisory authority is the Swiss Federal Data Protection and Information Commissioner. A data subject in Switzerland can bring proceedings in Switzerland.

Onward transfers

cf0 transfers Customer Personal Data to a Subprocessor outside the EEA, the UK or Switzerland only under a transfer mechanism that Applicable Data Protection Laws accept. If the authorities replace the SCCs or the UK Addendum, cf0 may use the replacement, as long as it does not lower the protection of Customer Personal Data. If the SCCs conflict with this DPA or the Agreement, the SCCs win. If your firm needs a signed copy of the SCCs for a regulator or a data subject, email luca@cf0.ai.

10. Requests and assistance

Your firm answers requests from data subjects, such as a tenant who asks for a copy of their data or for its deletion. cf0 helps your firm, as far as the nature of the processing allows and it is technically possible. Staff can find, correct and remove much of the data in cf0 themselves. For anything else, email luca@cf0.ai.

If a data subject sends a request about Customer Personal Data to cf0, cf0 tells your firm without undue delay, unless the law forbids it, and tells the data subject to contact your firm. cf0 does not answer the request itself unless your firm instructs it to or the law requires it.

cf0 also gives your firm reasonable help, with the information it has, with data protection impact assessments and prior consultations with a supervisory authority under Articles 35 and 36 of the GDPR, as far as they concern cf0’s processing.

11. Your firm’s responsibilities

Your firm is responsible for these things:

  • having a legal basis for each processing it asks of cf0, including for each person it puts on its records and each person Zero contacts for it;
  • giving the people concerned the privacy information that the law requires, such as the notices of Articles 13 and 14 of the GDPR, and getting any consent it needs;
  • the accuracy of the details its staff give, including the name, email address, role and property of a person that staff add on cf0.ai or from an AI assistant, and each email its staff approve;
  • the AI assistant its staff choose, and what they share there.

Unless we agree otherwise in writing, your firm does not put these into cf0 (“Restricted Data”): special categories of personal data under Article 9 of the GDPR, such as health data; data about criminal convictions; government identification numbers, such as passport or social security numbers; payment card data; credentials for bank or other financial accounts; and personal data of children under 16. No feature of cf0 needs them. A tenant or guest may still mention such things in a message. cf0 then processes them only as part of that message.

12. AI models and automated decisions

cf0 does not use Customer Personal Data to train, fine-tune or improve any AI model. Customer Personal Data goes to a model provider in Annex 3 only to produce what the Service needs at that moment.

cf0 does not use Customer Personal Data for decisions based only on automated processing that have legal or similarly significant effects on a data subject. Zero works inside the approval rules that your firm sets, and every email Zero drafts on a task waits until a member of your firm’s staff approves it. If this changes, cf0 tells your firm before it does, with the information about the logic that your firm needs to meet the law.

13. Return and deletion

While the Agreement runs, cf0 keeps and deletes Customer Personal Data as the retention and deletion sections of the privacy policy say.

When the Agreement ends, cf0 stops processing Customer Personal Data, except to return or delete it. For 30 days your firm can ask for a copy in a structured, machine-readable format. After that, or earlier if your firm asks, cf0 deletes Customer Personal Data and confirms in writing what it removed and what it kept. Deleted data can stay for up to 30 days in the recovery history that cf0’s cloud provider keeps of the database and of Zero’s agent storage. When your firm’s Zero email address on agents.cf0.ai is removed, its mailbox and the mail in it are deleted.

cf0 keeps Customer Personal Data after that only where the law requires it, only for as long as it requires, and only for that purpose. cf0 protects it under this DPA until it is deleted.

14. Audits

cf0 makes available to your firm the information it needs to show that cf0 meets this DPA and Article 28 of the GDPR, and answers security questionnaires honestly. cf0 has not completed a SOC 2 audit, an ISO 27001 certification or an independent penetration test. If it gets such a report, it can give the report in place of an audit of the controls that the report covers.

Where that information is not enough, your firm can audit cf0 once a year, and more often if a supervisory authority requires it. Your firm sends an audit plan with its scope, duration and start date at least two weeks before the audit. The audit takes place in business hours, does not unreasonably disrupt cf0, and does not give access to the data of other customers. A third-party auditor must be independent, must not be a competitor of cf0, and must sign a confidentiality agreement. Your firm pays its own costs and the auditor’s fees, and uses the results only to check compliance with this DPA or to meet its regulatory duties.

15. US state privacy laws

Where US State Privacy Laws apply, your firm discloses personal information to cf0 only for the limited and specified purpose of providing the Service. cf0:

  • does not sell or share the personal information;
  • does not keep, use or disclose it for any purpose other than providing the Service, or outside the direct business relationship between cf0 and your firm;
  • does not combine it with personal information that cf0 gets from anyone else, except as those laws allow;
  • gives it the same level of protection that those laws require, and tells your firm if it can no longer meet its duties under them.

Your firm may take reasonable steps to make sure that cf0 uses the personal information as these laws require, and to stop and fix use that they do not allow. The notices of section 8 and the audits of section 14 apply. cf0 confirms that it understands these limits and will comply with them.

16. Liability, precedence and changes

Each party’s liability under this DPA and the SCCs is subject to the limits and exclusions of the Agreement, as far as Applicable Data Protection Laws and the SCCs allow. This does not limit the rights that data subjects have under the SCCs.

If this DPA conflicts with the Agreement on the protection of personal data, this DPA wins. If the SCCs conflict with either, the SCCs win. Everything else in the Agreement stays as it is.

cf0 may change this DPA to keep up with Applicable Data Protection Laws, to add or replace a Subprocessor under section 8, or to replace a transfer mechanism under section 9. A change never lowers the protection of Customer Personal Data or adds to your firm’s duties without its written agreement. Other changes follow the changes clause of the terms. The date at the top of this page shows when this DPA last changed.

cf0 sends notices under this DPA to the email addresses of your firm’s admins in cf0. Your firm sends notices to luca@cf0.ai, which is also cf0’s contact for data protection.

Annex 1. Processing details

The parties

  • Data exporter. Your firm, at the address it gave cf0, through its admins. Activities: managing, letting or renting out property, and using the Service for that. Role: controller, or processor for its own clients.
  • Data importer. cf0, Corp., 131 Continental Dr, Suite 305, Newark, DE 19713, United States. Contact for data protection: luca@cf0.ai. Activities: providing cf0 and its agent Zero. Role: processor, or subprocessor.

The processing

  • Data subjects. Tenants, guests, owners and landlords, and contractors of your firm. Leads, applicants and callers who reach your firm through Zero. Your firm’s staff, as far as they appear in its content. Other people whose data is in the mailboxes, calendars and systems that your firm connects, such as senders, recipients and attendees.
  • Personal data. Names, email addresses and phone numbers. Role, property, tenancy and booking details, and stay dates. The content of emails, WhatsApp messages, chat messages, tasks and replies. On a firm’s phone line, call audio and transcripts. Photos and voice notes that guests send. Calendar busy times and the titles, times, locations and attendee names of events. Work orders, maintenance notes, documents and attachments, and access details such as door codes where your firm’s systems hold them. Records of who added a person, gave a task or approved a message, when, and from where (cf0.ai, ChatGPT or Claude).
  • Special categories. None are intended. Section 11 sets out the Restricted Data that your firm does not put into cf0.
  • Frequency. Continuous, for as long as your firm uses the Service.
  • Nature of the processing. Collection through the channels and accounts your firm turns on, storage, retrieval, organisation, sending and receiving messages, speech-to-text and text-to-speech on calls, processing by AI models to read, classify, summarise and draft, and deletion.
  • Purpose. To provide the Service to your firm: Zero answers, follows up and keeps your firm’s work moving, within your firm’s instructions and approvals.
  • Duration and retention. The term of the Agreement and the period in section 13, with the retention periods in the privacy policy.
  • Transfers to Subprocessors. As Annex 3 lists, for the functions it describes.

Annex 2. Security measures

These are the measures in place today:

  • Location. The primary database, file storage and Zero’s agent storage are held under European Union jurisdiction. cf0’s api servers run in Frankfurt, Germany.
  • Physical security. cf0 has no servers of its own. The data centres, and their physical security, belong to its cloud provider and Subprocessors.
  • Encryption. The primary database is encrypted at rest with a managed encryption key. Traffic to and from the Service travels over TLS. Access credentials for mailboxes and calendars that a firm connects through Google, Microsoft or Calendly are stored encrypted.
  • Authentication. Every request is authenticated against a cryptographically verified sign-in token. The organisation of the user comes from that token, never from anything the browser can set. An AI assistant gets a token that lets it act for one staff member in Zero only, and loses access when that person leaves the firm in cf0.
  • Separation. Every query is scoped to the organisation. Internal services are not reachable from the public internet. They are reachable only through cf0’s own gateway, which is the single place where identity is established. Only isolated code can destroy stored objects.
  • Least data to assistants. Results sent to an AI assistant describe people on your firm’s records by role, property and reference code. Email addresses, phone numbers and access codes are removed.
  • Human approval. Every email that Zero drafts on a task waits until a member of your firm’s staff approves it. Zero’s first message to a person says that it is an AI assistant.
  • Secrets and production access. Secrets are held in a managed secrets store and injected at deploy time. They are not in source control. Production access is limited to the people who need it.
  • Change control. Every change to cf0’s code passes automated type, structure and lint checks before it is committed.
  • Recovery history. cf0’s cloud provider keeps a rolling 30-day history of the primary database and of Zero’s agent storage, so that they can be restored to an earlier point in time.
  • Logging. Request and error logs are kept to secure and fix the Service. A request from an AI assistant is logged as one line with its kind, outcome, assistant and duration, never with its content or token.
  • Incident response. cf0 investigates, contains and reports Security Incidents as section 7 says.

cf0 is a small company. It has no independent security certification, as section 14 says. No system is perfectly secure.

Annex 3. Subprocessors

Your firm authorises cf0 to use these Subprocessors. Each entry says what the Subprocessor does and where it processes Customer Personal Data. Section 8 says how cf0 tells your firm about a change.

For every firm

  • Cloudflare. Hosting, compute, the database, file storage, Zero’s agent storage, queues, logs, the edge network and DNS, and classification with Workers AI. The database, file storage and Zero’s agent storage are under EU jurisdiction, and cf0’s api servers run in Frankfurt, Germany. The edge network is worldwide. Classification, queues and logs are not pinned to a region and may run or be kept outside the EU.
  • Clerk. Sign-in, identity and organisation membership for your firm’s staff. United States.
  • Fireworks AI. Model inference: the AI model that reads, summarises and drafts for Zero. United States.
  • AgentMail. Zero’s mailboxes: the Zero email address on agents.cf0.ai or on your firm’s own domain, and the email Zero sends and receives there. United States.
  • Resend. Email from cf0 to its own team, such as the alert when a firm signs up or asks about a contract. United States.
  • Composio. Brokered connections to some third-party accounts that your firm connects. It holds the access tokens and passes cf0 the content within the scopes your firm grants. United States.
  • Stripe. Payments and invoices for a firm that pays through Stripe, such as on Tasks only, and the business details your firm enters at checkout. United States.

Also for firms on a cf0 contract

These process data only for a firm whose phone line, WhatsApp, voice or inbox features are on.

  • ElevenLabs. Voice: speech-to-text, text-to-speech and calls on your firm’s phone line, and speech-to-text of the voice notes that guests send. Conversations and speech-to-text run in the United States (Iowa), text-to-speech in the Netherlands.
  • Telnyx. Phone numbers and the telephone network leg of calls. Call media on the SIP connections that cf0 manages is anchored in Frankfurt, Germany. Call media on a guest line can be handled at another Telnyx site.
  • Meta (WhatsApp Business Platform). WhatsApp messages to and from your firm’s WhatsApp number. Meta runs this infrastructure, and cf0 does not choose where it processes data.
  • Google Cloud (Pub/Sub). Change notices for the Gmail mailboxes that Zero watches for your firm: the mailbox address and a change number, never the mail. It may process data outside the EU.

Not Subprocessors

The AI assistant your firm’s staff use, such as ChatGPT or Claude, and the accounts your firm connects, such as Google Workspace, Microsoft 365, Calendly, Cal.com, Hostaway or Hosthub, are your firm’s own providers, as section 8 says. The analytics script and the demo booking calendar on cf0’s public website serve cf0’s own business. The privacy policy describes them.