Legal

Data Processing Addendum

Hectile is operated by Zealsync Private Limited. This Addendum forms part of the Terms of Service between Zealsync Private Limited (“Zealsync”) and an Organization (“Customer”) and applies whenever Zealsync processes personal data on the Customer’s behalf in providing Hectile.

Effective date
26 September 2026
Last updated
9 October 2026
Operated by
Zealsync Private Limited

1.Parties, scope and applicability

This Addendum applies to Customer Personal Data: personal data contained in the content an Organization enters into or generates with Hectile — customer records, Invoices, Estimates, payment records, recipient addresses and sending records — which Zealsync processes on the Customer’s behalf to provide the service.

It does not apply to personal data Zealsync processes for its own purposes as described in the Privacy Policy (for example, account holders’ sign-in details, subscription billing records and support communications), for which Zealsync is the controller.

This Addendum applies automatically to every Organization by acceptance of the Terms of Service. Organizations that require a countersigned copy, or that act as a processor for their own clients and need corresponding terms, can request them through Contact Legal.

2.Definitions

Applicable Data Protection Law
The data-protection and privacy laws that apply to the processing of Customer Personal Data under this Addendum, including the Information Technology Act, 2000 and rules made under it and the Digital Personal Data Protection Act, 2023 as and when in force, and any other law that applies to the Customer’s processing.
Controller, Processor, Data Subject, Personal Data, Processing, Personal Data Breach
Have the meanings given in Applicable Data Protection Law; equivalent terms in other laws (such as Data Fiduciary and Data Processor) are read accordingly.
Subprocessor
A third party engaged by Zealsync that processes Customer Personal Data on Zealsync’s behalf in order to provide the service.
Service
The Hectile application and related services described in the Terms of Service.

3.Subject matter, duration, nature and purpose of processing

The details of the processing are set out in Annex A (section 12). In summary: Zealsync hosts, stores, displays, transmits and, on the Customer’s instruction, emails and renders as PDF the business documents the Customer creates, for the duration of the Customer’s account (including any read-only period) and until deletion in accordance with section 8.

4.Documented instructions

Zealsync processes Customer Personal Data only on the Customer’s documented instructions, unless required to do otherwise by law, in which case Zealsync will inform the Customer before processing unless the law prohibits it. The Customer’s instructions are: this Addendum, the Terms of Service, and the Customer’s use of the features of the Service (for example, finalizing a document, sending it to a recipient, creating or revoking a document link, or recording a payment).

Zealsync will inform the Customer if, in its opinion, an instruction infringes Applicable Data Protection Law. The Customer is responsible for the lawfulness of the Customer Personal Data it provides, for the accuracy of recipients’ details and for its own notices to the people whose data it processes.

Zealsync does not use Customer Personal Data for its own purposes beyond what the Privacy Policy describes for service operation, security and legal compliance, and does not train any model of its own on it. Where the Customer uses AI features, the AI providers and the terms governing their handling of request content are those published on the Subprocessors page at the time of use.

5.Confidentiality and security

Zealsync ensures that persons authorized to process Customer Personal Data are bound by confidentiality obligations, and implements the technical and organizational measures described in Annex B (section 13), which it may update from time to time provided the overall level of protection is not reduced.

6.Subprocessing

The Customer authorizes Zealsync to engage the Subprocessors listed on the Subprocessors page (Annex C, section 14) and any replacement or additional Subprocessor notified under this section. Zealsync imposes data-protection obligations on each Subprocessor that are no less protective than those in this Addendum, and remains responsible to the Customer for the Subprocessor’s performance.

Zealsync will update the Subprocessors page and notify Organization Admins by email or in the application at least 30 days before a new or replacement Subprocessor begins processing Customer Personal Data. The Customer may object on reasonable data-protection grounds within that period through Contact Legal; if the objection cannot be resolved, the Customer may cancel the affected Organization’s subscription and receive a pro-rata refund of prepaid fees for the remainder of the current period. This pro-rata refund applies only to an unresolved Subprocessor objection; ordinary cancellation follows the Refund & Cancellation Policy, which does not otherwise provide prorated refunds.

Providers that process personal data independently for their own purposes — for example, the subscription-billing provider acting as merchant of record — are identified on the Subprocessors page with that role and are not Subprocessors of Customer Personal Data.

7.Assistance with rights requests and incidents

Taking into account the nature of the processing, Zealsync will assist the Customer, by appropriate technical and organizational measures and insofar as possible, in responding to requests from Data Subjects to exercise their rights. Many requests can be fulfilled by the Customer directly in the Service (for example, correcting a customer record or revoking a document link). Where a Data Subject contacts Zealsync directly about Customer Personal Data, Zealsync will refer them to the Customer and will not respond substantively unless instructed or required by law.

Zealsync will notify the Customer’s Admins without undue delay, and in any event within 72 hours, after becoming aware of a Personal Data Breach affecting Customer Personal Data, and will provide the information reasonably available to help the Customer meet its own notification obligations. Zealsync will assist the Customer with data-protection impact assessments and consultations with supervisory authorities where required and related to the Service. Assistance that goes beyond the Service’s standard features may be charged at Zealsync’s reasonable cost, agreed in advance.

8.Return and deletion of Customer Personal Data

During the term, the Customer can download issued documents as PDFs and view its records through the Service, including during read-only access. When a subscription ends, the Organization’s Customer Personal Data is retained in read-only access and is not deleted automatically (Terms of Service, section 11). Removal of a member or closure of an individual account does not delete the Organization’s data.

The Customer’s Admin may at any time — during the term, during read-only access or after termination, with no deadline — request through Contact Legal that Zealsync delete the Organization and its Customer Personal Data. After verifying the request, Zealsync deletes the data from the live service and confirms deletion to the requesting Admin in writing; copies in routine backups are removed as those backups expire in the ordinary rotation cycle. Zealsync may retain Customer Personal Data to the extent required by law, in which case it remains protected by this Addendum and is processed only for that purpose.

9.Audit and information obligations

Zealsync makes available to the Customer the information reasonably necessary to demonstrate compliance with this Addendum: the Security & Trust page, this Addendum’s annexes, and written responses to reasonable security questionnaires no more than once in any 12-month period, or more often following a Personal Data Breach or where required by a supervisory authority. Where Applicable Data Protection Law grants the Customer an audit right that these measures do not satisfy, the Customer may, on 30 days’ written notice and subject to reasonable confidentiality and scheduling terms, conduct or mandate an audit limited to the processing of its Customer Personal Data, at the Customer’s cost.

10.International transfers

Zealsync is established in India. Its Subprocessors operate infrastructure in more than one country, so Customer Personal Data may be processed outside India and outside the Customer’s country. Zealsync ensures that each transfer to a Subprocessor is governed by data-protection terms between Zealsync and that Subprocessor that are no less protective than this Addendum, including any transfer terms that Applicable Data Protection Law requires. Where Applicable Data Protection Law requires the Customer and Zealsync to enter into additional transfer terms for the Customer’s own transfers to Zealsync, the parties will agree them on request through Contact Legal.

11.Order of precedence, term and execution

This Addendum is accepted together with the Terms of Service and needs no separate signature; a countersigned copy is available on request. In the event of conflict, this Addendum prevails over the Terms of Service with respect to the processing of Customer Personal Data; otherwise the Terms of Service apply. This Addendum remains in force for as long as Zealsync processes Customer Personal Data for the Customer. Nothing in it limits liability protections that Applicable Data Protection Law makes mandatory, and the liability provisions of the Terms of Service apply to it.

12.Annex A — Details of processing

ItemDescription
Subject matterProvision of the Hectile Service to the Customer: creation, storage, finalization, sending and tracking of Invoices and Estimates — including the scheduled creation and sending of recurring invoices and payment reminders that the Customer sets up — and recording of payments received.
DurationThe term of the Customer’s account, including read-only periods, until deletion under section 8.
NatureHosting, storage, display, structuring, scheduled processing of recurring invoices and payment reminders configured by the Customer, transmission (email and document links), PDF rendering, and — where the Customer uses AI features — transmission of request text and the limited details described on the Subprocessors page, through the AI request router to the AI model provider, to generate a proposed Draft or a suggested line description, note or terms text.
PurposeEnabling the Customer to issue and manage business documents and to communicate them to its customers.
Categories of Data SubjectsThe Customer’s customers and their staff or billing contacts; the Customer’s own Admins and Members insofar as their names appear in documents and activity records; recipients of documents.
Categories of Personal DataNames, business and postal addresses, email addresses, tax identifiers, document content (line items, amounts, notes, payment instructions), payment records entered by the Customer, document-link access events and email-delivery events.
Special categoriesNone intended. The Customer must not enter special-category or similarly sensitive data into document fields.
FrequencyContinuous, as the Customer uses the Service.

13.Annex B — Technical and organizational measures

This Annex sets out the technical and organizational measures Zealsync is bound to implement and maintain for Customer Personal Data. It states contractual obligations; it is not a certification, an audit report or a description of a particular configuration.

AreaMeasure
Tenant isolationZealsync will keep each Organization as a separate tenant: every server request must validate the active Organization and the member’s role before reading or writing data, and database-level access policies must enforce the same boundary.
Access controlZealsync will authenticate members through the Service’s sign-in system, enforce Organization roles (Admin and Member) on the server, and restrict access to its internal administration tooling to separately authorized, named staff, with privileged actions recorded in an audit log.
Transport securityZealsync will use HTTPS/TLS for traffic between browsers and the Service and between the Service and its Subprocessors.
StorageZealsync will store Customer Personal Data only with the database and storage Subprocessor listed in Annex C and will rely on the encryption at rest and infrastructure security that provider commits to in its terms.
Document integrityZealsync will keep issued documents as immutable snapshots; corrections are made by cancellation with a stated reason and re-issue, and payment records are voided with a reason, never deleted.
Document linksZealsync will generate public document links with unguessable tokens, allow an Admin to revoke and regenerate a link, and show an unavailable state for a revoked link.
LoggingZealsync will configure operational logging to exclude document content, tax identifiers, raw link tokens, AI request text and credentials, and will retain logs only for the period needed to secure and troubleshoot the Service.
SecretsZealsync will hold provider credentials server-side in protected configuration, never expose them to the browser, and rotate them when a compromise is suspected or when a person with access to them no longer requires it.
Backups and recoveryZealsync will maintain database backups through the database Subprocessor and the ability to restore the database from them; backup copies expire in the ordinary rotation cycle.
Incident responseZealsync will triage and contain security incidents and notify affected Customers as set out in section 7.
PersonnelZealsync will bind staff with access to Customer Personal Data to confidentiality obligations and limit access to those who need it to operate and support the Service.

14.Annex C — Subprocessors

The current Subprocessors, their roles and the categories of Customer Personal Data they process are listed on the Subprocessors page, which forms Annex C to this Addendum and is updated as described in section 6.

Need a countersigned copy for your Organization, or have questions?

Use the Legal reason on the contact form and say which document and section your question relates to. We reply from Zealsync Private Limited, the operator of Hectile.

Zealsync Private Limited · 11/131, Elanthoor, Pathanamthitta – 689643, Kerala, India