These Terms govern the relationship between Dedilayer Ltd. and legal entities and sole traders using the ZynTrail platform. The service is not offered to consumers within the meaning of the Bulgarian Consumer Protection Act.
This is a translation provided for convenience. The Bulgarian text is authentic and prevails in the event of any discrepancy.
Provider
| Legal name | Dedilayer Ltd. |
|---|---|
| Registered seat and address of management | Sofia, Bulgaria |
| hello@zyntrail.com · data protection: privacy@zyntrail.com | |
| Data protection supervisory authority | Commission for Personal Data Protection, www.cpdp.bg |
Published pursuant to Art. 4 of the Electronic Commerce Act (Закон за електронната търговия).
Definitions
Service — the ZynTrail platform at https://app.zyntrail.com, together with all features included in the subscription.
Customer — the legal entity or sole trader that has concluded a contract on these Terms.
User — a natural person holding an account in the Service, created by the Customer.
Customer Data — all data the Customer enters into the Service or which arrives in it through connected channels, including data about its own customers and counterparties, messages, files and call recordings.
Annex 1 — the Data Processing Agreement, which forms an integral part of these Terms.
Formation of the contract
3.1 How it is concluded
The Service offers no self-service registration. An account is created by the Provider following a request from the Customer. The contract is concluded when an authorised representative of the Customer accepts these Terms and Annex 1 electronically and the Provider activates the account.
Electronic acceptance is valid under Art. 293(4) of the Commerce Act (Търговски закон) — the written form is deemed observed where the statement is recorded technically in a manner permitting its reproduction. It also takes effect under Art. 25(1) of Regulation (EU) No 910/2014, under which an electronic signature shall not be denied legal effect solely because it is in electronic form.
Customers who prefer it may sign the contract with a qualified electronic signature.
3.2 What is recorded on acceptance
On acceptance the Provider records and retains unaltered: the Customer's name and EIK (Bulgarian company ID); the name, job title and account of the accepting individual; the version numbers and SHA-256 checksum of the exact text of the Terms and Annex 1 accepted; the date and time in UTC; the IP address; and the method of acceptance.
The record is kept for the term of the contract and three years after termination. Every superseded version remains available at a permanent address.
3.3 Binding effect and order of precedence
Under Art. 298 of the Commerce Act, general terms established by a merchant bind the other party only if they were delivered to it at the time of conclusion. The Provider therefore delivers the full text of the Terms and Annex 1 as an attachment to the activation email, not merely as a link.
Under the same provision, individually negotiated terms prevail over general terms. The order of precedence is:
- an individually signed order form or agreement;
- Annex 1 (Data Processing Agreement);
- these Terms of Service.
3.4 The Customer confirms it is not a consumer
On acceptance the Customer declares that it is contracting in the course of its trade or profession and is not acting as a consumer within the meaning of the Consumer Protection Act. The Provider collects the EIK at account creation precisely so that this is verifiable.
3.5 Language
The contract is concluded in Bulgarian. The published English and Russian texts are translations for convenience. In the event of discrepancy, the Bulgarian text prevails.
Scope of the Service
The features included in each subscription plan are described in the Service and on the website. The Provider may add features. Removal or material restriction of a feature from the current plan is notified at least 60 days in advance and entitles the Customer to terminate without penalty as of the date of the change.
External channels — email, Messenger, Instagram, WhatsApp, Telegram (alerts for the team) and Twilio — are connected using the Customer's own accounts. Phone numbers and the ZynTrail Voice phone system are provided by the Provider. The Customer declares that it holds the necessary rights to them and complies with the respective providers' terms. Termination or restriction of access by such a provider is not a breach by ZynTrail.
Trial, prices, payment
5.1 Trial
A 30-day free trial is provided on account creation. It creates no payment obligation and may be ended at any time.
5.2 Prices
Prices are stated in euro in the published price list. These Terms refer to the price list rather than reproducing it, so that a price change does not require the contract to be reissued.
Prices are exclusive of VAT. For customers VAT-registered in another Member State, the place of supply is where the recipient is established and the reverse charge applies, with the invoice bearing the corresponding annotation. The Customer must provide a valid VAT number and notify any change immediately. Where the number is invalid or withdrawn, the Provider charges Bulgarian VAT and the Customer owes the difference.
5.3 Payment
Payment is made by card through Stripe or by bank transfer against an issued invoice. The Provider does not receive or store payment card data. The subscription renews automatically for a further term equal to the preceding one unless terminated.
5.4 Price changes
The price is fixed for the current subscription term. Changes take effect from the next term and are notified at least 30 days before the renewal date. The Customer may decline by terminating before renewal. Continued use after the start of the new term constitutes acceptance.
The Provider does not reserve a right to change the price unilaterally within a current term.
5.5 Late payment
On late payment the Provider is entitled to statutory interest under Art. 294 of the Commerce Act, and to compensation for recovery costs under the rules on late payment in commercial transactions.
5.6 Refunds
No statutory right of withdrawal applies between merchants. Amounts paid are not refunded pro rata on termination before the end of the term. Termination takes effect at the end of the paid period.
On expiry: read-only, not deletion
On expiry of the subscription a 7-day grace period applies, during which the Service operates unchanged.
After the grace period the account enters read-only mode: the Customer and Users retain access to all data and may view and export it, but cannot create or modify records. No data is deleted.
The purpose of retaining data in this mode is to give the Customer the export window under section 8, not to serve as leverage for payment.
The precise scope of the restriction — what happens to incoming messages, calls and external notifications in this mode — is described in the Service, in the subscription section.
Availability
The Provider prefers to state verifiable numbers rather than a percentage it cannot guarantee.
7.1 What the Provider owes
The Provider exercises the care of a prudent merchant under Art. 302 of the Commerce Act and performs in good faith under Art. 63 of the Obligations and Contracts Act. These duties cannot be excluded by contract and are not excluded by these Terms.
7.2 What the Provider does not guarantee
The Provider does not guarantee any particular availability percentage. The Service runs from a single server configuration without real-time redundancy. A 99.9% commitment on such infrastructure would be a promise that cannot be kept, and a breached commitment is worse than an absent one.
7.3 What the Provider guarantees instead — measured figures
| Measure | Value | Source |
|---|---|---|
| Maximum data loss on failure (RPO) | up to 6 hours | Backup every 6 hours |
| Restoring the database from a backup | 6 seconds (measured) | Drill of 1 September 2026 |
| Full recovery of the service onto a new host | not measured | — |
These are targets, not guarantees, and they derive from an actually performed drill rather than from an estimate.
The distinction between the second and third rows is deliberate. Six seconds is the time taken to bring the data back from a backup. It does not include detecting the failure, provisioning a new host, or repointing addresses. The Provider states what was measured as measured and what was not as not measured, rather than merging the two into a single more flattering figure.
The drill is repeated and the results documented.
7.4 Planned maintenance
Planned maintenance is announced at least 48 hours in advance. Emergency security updates are applied immediately and without prior notice.
7.5 Dependencies
The Provider is not liable for unavailability caused by: Meta (Messenger, Instagram, WhatsApp), Google, Stripe, Telegram, the AI providers, the telephony platform, or the hosting provider. These are named individually because a substantial part of the functionality depends directly on them, and a general reference to "third parties" would conceal the actual allocation of risk.
7.6 Force majeure
Art. 306 of the Commerce Act applies. The affected party notifies the other in writing within a reasonable time. If the impediment persists long enough that the other party no longer has an interest in performance, either party may terminate.
Termination, data export, deletion
8.1 Termination
The Customer may terminate at any time through the Service or the Stripe portal. Termination takes effect at the end of the paid period.
The Provider may terminate on 60 days' notice, and without notice for a material breach not remedied within 14 days of written demand.
8.2 Suspension
The Provider may suspend access immediately in the event of an active security threat, use of the Service for unlawful activity, or sending unsolicited bulk messages that endanger the Provider's accounts with channel providers. The Customer is notified as soon as practicable.
8.3 Data export
After termination the Customer has 30 days in which to export its data.
What can be exported, exhaustively:
| Category | Format |
|---|---|
| Customers and counterparties | CSV |
| Contacts | CSV |
| Tickets | CSV |
| Messages per ticket | CSV / text |
| Attachments | Individual download through the Service |
What cannot be exported automatically, and why:
- Call recordings — not exported through the interface. For calls made through ZynTrail's own telephony platform, recordings are held on the Provider's infrastructure and are supplied on written request within the period stated in the final paragraph of this section. Where a direct integration with an external provider is used, recordings are held by that provider and the Customer downloads them from its account there.
- Shift, leave and attendance data — there is currently no single-operation export.
- A full copy of the database in one file — not offered through the interface.
For each of the categories listed above that is not exported automatically and is held by the Provider, the Provider supplies the data in a machine-readable format on written request, within 14 days and free of charge.
The enumeration is exhaustive by design — a requirement of Art. 25 of Regulation (EU) 2023/2854. A general sentence saying "you may export your data" does not satisfy it.
8.4 Switching providers
Under Regulation (EU) 2023/2854 (Data Act):
- the notice period for initiating a switch is no more than 2 months;
- the transitional period for transfer and retrieval is at least 30 days, extended at the Customer's request;
- the Provider imposes no contractual, commercial, technical or organisational obstacles to switching;
- the Provider levies no switching or export charge.
8.5 Deletion
After the period in 8.3 expires, Customer Data is deleted from live systems within 14 days, unless the Customer has requested earlier deletion or return.
The choice between deletion and return belongs to the Customer, under Art. 28(3)(g) GDPR.
Backups are overwritten on a rolling cycle — up to 7 days for the on-server copy and up to 30 days for the offsite copy. An erased record may persist in a backup for at most 30 days after erasure from the live system. During that period the copies are not read, except in an actual disaster recovery event.
Accounting and tax documents subject to a statutory retention period are not deleted. Those documents are the Provider's data in its capacity as controller, not Customer Data.
Customer obligations and warranties
The Customer declares and undertakes:
- to have a lawful basis for the data it enters into the Service, and to have informed its own data subjects;
- to have informed its own employees about the processing of their data in the Service, including call recording and working-time records;
- not to enter special categories of data under Art. 9 GDPR, or criminal conviction data, without prior written agreement with the Provider;
- not to use the Service for unsolicited bulk messaging;
- to keep credentials confidential and to revoke the rights of departing employees;
- to comply with the terms of the connected channel providers.
Call recording
Where the Customer uses the telephony functionality, calls are recorded.
The Customer is the controller of the recordings. It decides whether to record, for what purpose and for how long, and it owes the notification. The Provider supplies the technical capability.
The Customer undertakes: to ensure notification before the recording begins; to inform both the external participant and its own employee; not to rely on employee consent as a basis, insofar as it is not valid in an employment relationship; and to set a retention period.
Where the recording is stored depends on the call path. For calls through ZynTrail's own telephony platform, the recording is held on the Provider's infrastructure, the Provider acting in that capacity as a processor on the Customer's instructions. Where a direct integration with an external telephony provider is used, the recording is held by that provider and ZynTrail keeps only a reference. In both cases ZynTrail stores the call metadata.
The distinction determines to whom a request to delete or to access a recording must be addressed, and is therefore stated rather than generalised.
Artificial intelligence
- The model provider is determined by the subscription plan, is not chosen by the Customer, and is named in section 6 of the Privacy Policy.
- Processing is carried out on the Customer's instructions; the Customer remains controller of the content.
- Customer Data is not used to train models — neither by the Provider nor by the model provider.
- The Customer may disable AI features entirely.
- Where an AI feature communicates directly with a natural person, the Service informs that person that they are interacting with an automated system, in accordance with Art. 50 of Regulation (EU) 2024/1689. The Customer may not disable or misrepresent this notification.
- Special categories of data under Art. 9 GDPR are not to be routed to the AI features (see also Annex 1, section 1).
Intellectual property
The platform, source code, interface and documentation are and remain the Provider's property. The Customer receives a non-exclusive, non-transferable right of use for the term of the contract.
Customer Data remains the Customer's. The Provider acquires no rights in it and does not use it for its own purposes — see section 6 of Annex 1.
If the Customer provides suggestions for improvement, the Provider may use them without obligation to pay. This does not extend to Customer Data.
Confidentiality
Each party keeps confidential the other's information to which it gains access and does not disclose it to third parties except to staff and subcontractors bound by the same duty. The obligation applies for the term of the contract and 3 years after termination, and for trade secrets until they lose that character.
Liability
14.1 What cannot be limited
The limitations in this section do not apply in cases of intent or gross negligence, pursuant to Art. 94 of the Obligations and Contracts Act, which renders void any prior agreement excluding such liability. Nor do they apply where the law otherwise does not permit limitation.
14.2 Scope of damages
Damages cover loss that was foreseeable at the time the contract was concluded, under Art. 82 of the Obligations and Contracts Act. No compensation is due for lost profits, for indirect loss or for unforeseeable loss.
14.3 Cap
The Provider's total liability under the contract for all events in any twelve consecutive months shall not exceed the amount paid by the Customer for that same period.
Exception: for breach of the confidentiality obligation and for a personal data breach for which the Provider is responsible, the cap is three times the annual subscription fee.
14.4 GDPR liability
The limitations in this section govern the contractual relationship between the Provider and the Customer. They do not and cannot affect a data subject's right to seek compensation directly from the Provider or the Customer under Art. 82 GDPR, including their joint and several liability and the right of recourse between them. A clause purporting to limit liability towards a data subject would be void in that part and is therefore not included.
14.5 Contractual penalties
An agreed penalty is not subject to reduction for being excessive, under Art. 309 of the Commerce Act. This rule operates in favour of both parties.
Amendments
Amendments are notified at least 30 days in advance and take effect from the next subscription term. Continued use after the start of the new term constitutes acceptance. A Customer that does not accept an amendment may terminate before renewal without penalty.
Only amendments required by law or by a change in a sub-processor's terms take immediate effect. In such a case the Provider states the reason expressly.
Annex 1 is amended under a different procedure — see section 11 of that Annex. The reason is that it reflects the Customer's instructions as controller and cannot be changed unilaterally.
Every version carries a number, a date and a description of the changes. Superseded versions remain available at permanent addresses.
Assignment
The Customer may not assign its rights without the Provider's written consent. The Provider may assign the contract on a corporate reorganisation or sale of the business, notifying the Customer and giving it a right to terminate within 30 days.
Governing law and jurisdiction
Bulgarian law applies, pursuant to Art. 3 of Regulation (EC) No 593/2008.
Disputes shall be resolved by the competent court in Sofia, Bulgaria, pursuant to Art. 117(2) of the Civil Procedure Code and Art. 25 of Regulation (EU) No 1215/2012. Under Art. 25(2) of that Regulation, any communication by electronic means which provides a durable record of the agreement is equivalent to writing — which is what makes this clause binding where the Terms were accepted electronically.
If any clause is held invalid, the remainder continues in effect and the invalid clause is replaced by a permissible clause of the closest effect.
ANNEX 1 — Data Processing Agreement
Concluded pursuant to Art. 28 of Regulation (EU) 2016/679, between the Customer as controller and Dedilayer Ltd. as processor. This Annex forms an integral part of the Terms of Service and is accepted together with them. On request, the Provider supplies an identical text as a standalone document for signature, including by qualified electronic signature.
1. Subject matter — Annex I under Art. 28(3)
| Subject matter | Provision of a customer service platform, comprising multi-channel intake and handling of enquiries, telephony, counterparty management and working-time records |
|---|---|
| Duration | For the term of the contract, plus the export window under section 8.3 of the Terms |
| Nature and purpose | Storage, structuring, display, search, transmission over channels, automated assistance, archiving — all exclusively on the controller's instructions |
| Categories of data subjects | The controller's customers and counterparties; persons who contact the controller through any channel; the controller's employees |
| Categories of data | Names, company names, EIK, VAT number, responsible person, addresses, telephone numbers, email, preferred language; free-text message content from email, Messenger, Instagram, WhatsApp and web form; attachments; call data — direction, status, duration, operator, contact — and references to recordings; internal correspondence between the controller's staff; shifts, leave, shift swaps, attendance and activity of staff |
| Special categories | Not expected. The controller undertakes not to route such data into the platform without prior written agreement |
2. Instructions
The processor processes personal data only on documented instructions from the controller, including as regards transfers to third countries, unless required to do otherwise by Union or Member State law; in that case the processor informs the controller before processing, unless that law prohibits such information.
Instructions comprise: the Terms of Service; this Annex; the settings the controller configures in the platform itself — including choice of channels, switching AI features on or off, retention periods and user permissions; and written requests submitted through support.
The processor shall immediately inform the controller if, in its opinion, an instruction infringes the GDPR or other data protection provisions.
3. Confidentiality
Persons authorised to process personal data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality.
4. Security — Annex II
The processor implements the measures required by Art. 32 GDPR, described in Annex II to this Agreement (section 12 below).
The processor may update the measures in Annex II provided that the level of security is not reduced. Without this stipulation, every security improvement would constitute a contract amendment.
5. Sub-processors
The controller gives general prior authorisation for the sub-processors listed in Annex III — the named list of sub-processors, with country, purpose and transfer mechanism. The processor provides it to the controller when the contract is concluded and on request at privacy@zyntrail.com.
Where the processor intends to add or replace a sub-processor, it notifies the controller at least 30 days in advance. The controller may object in writing within 14 days. Where a well-founded objection cannot be resolved, either party may terminate without penalty.
The processor imposes the same data protection obligations on each sub-processor and remains fully liable to the controller for its performance.
6. The processor does not use the data for its own purposes
The processor does not use personal data processed on the controller's behalf for its own purposes — not for product improvement, not for model training, and not for aggregate analytics that are not fully anonymous within the meaning of Recital 26 GDPR.
This clause is express because Art. 28(10) GDPR converts a processor that determines purposes into a controller for that processing, with all the resulting duties and none of the available lawful bases.
7. Assistance with data subject rights
The processor assists the controller in responding to requests under Chapter III GDPR through: the search, export, rectification and deletion functions in the platform; and, where necessary, extraction on written request.
Assistance deadline: 7 days from written request. The period is chosen so that the controller can meet its own one-month deadline under Art. 12(3).
If a data subject request arrives directly with the processor, it does not respond on the merits but forwards it to the controller within 5 business days.
8. Assistance under Arts. 32 – 36
The processor assists the controller with: ensuring security; notifying breaches; communicating breaches to data subjects; data protection impact assessments; and prior consultation with a supervisory authority.
For the purposes of an impact assessment, the processor supplies a pack containing a system description, data flows, applied measures, the sub-processor list and the available retention options.
9. Personal data breaches
The processor notifies the controller without undue delay and no later than 24 hours after becoming aware of a breach affecting its data.
The notification states: the nature of the breach; the categories and approximate number of data subjects and records concerned; the likely consequences; the measures taken and proposed; and contact details.
The 24-hour period is chosen so that the controller retains the remainder of its 72-hour period under Art. 33(1).
10. Deletion or return
On termination the controller chooses whether the data is deleted or returned. Absent a choice by the end of the period in section 8.3 of the Terms, the data is deleted.
The processor also deletes existing copies, except where Union or Member State law requires storage. For backups, the cycle in section 8.5 of the Terms applies.
11. Audit
The processor makes available to the controller all information necessary to demonstrate compliance with Art. 28, and allows for and contributes to audits.
First tier: on written request the processor supplies, within 20 days, a completed security questionnaire, a summary of restore drill results, and written answers to specific questions.
Second tier: if the controller reasonably considers the above insufficient, it may conduct an on-site or remote inspection — at its own cost, no more than once every 12 months (save at the request of a supervisory authority or following a breach), on 30 days' notice, during business hours, by an auditor who is not a competitor of the processor and is bound by confidentiality.
The scope of any inspection excludes other tenants' data and systems whose inspection would compromise their security. This is not a convenience for the processor: granting access to a multi-tenant environment would itself breach its Art. 32 obligations towards the other controllers.
12. Annex II — Technical and organisational measures
- Transmission: HTTPS only, with automatically renewed certificates.
- Storage: the controller's credentials for external channels are stored encrypted.
- Access control: authentication by session cookies of limited duration; separation by role and by department; revocation of rights takes effect from the next request.
- Tenant separation: verified regularly, including by automated tests.
- Files: delivered only via a signed temporary URL; the directory is not publicly served.
- Traceability: administrative actions on accounts are written to an audit log.
- Backups: every 6 hours; retained up to 7 days on the server and up to 30 days in an offsite copy; restore drill performed and documented.
- Infrastructure: server access by cryptographic key only; firewall enabled; automatic security updates.
- Offsite copy: encrypted with symmetric AES-256 before it leaves the server, with a passphrase the storage provider does not hold; only ciphertext is stored there. Every file is read back before upload, and the export fails with an error on a missing passphrase rather than falling back to an unencrypted path.
13. Amendment of this Annex
This Annex is not amended under the procedure for amending the Terms of Service, because it reflects the controller's instructions.
Material amendments require the controller's express acceptance. Changes to the sub-processor list follow the procedure in section 5. Amendments required by law take effect after written notification stating the reason.
Version 1.0 · Effective 24 September 2026 · The Bulgarian text is authentic.