Scoped services

This document specifically applies to the following Zoho Office Integrator services

Zoho Writer (online word processor)

Zoho Sheet (online spreadsheet application)

Zoho Show (online presentation tool)

Zoho PDFEditor (PDF editing tool)

Data processing roles

Zoho as a service provider

When customers (typically businesses or developers) use Zoho Office Integrator within their applications, they become the data controllers, and Zoho acts as a data processor. This means we process end-user content strictly under the instruction of our customers who are integrating Zoho's editors into their platforms.

Responsibilities of data controllers

It is the responsibility of the data controller (i.e., the web application owner who integrated Zoho Office Integrator) to:

Collect valid consent from their end users, if required.

Clearly communicate the usage of Zoho Office Integrator.

Ensure appropriate disclosures are made in their own privacy policy or data processing agreements.

Our API documentation provides clear guidelines on how data is transferred, stored, and processed through our secure infrastructure. The data controller has full control over what content is loaded, stored, and retained using the API calls.

Data localization

All your documents are securely stored (temporarily during the editing process) within Zoho's infrastructure, which includes data centers within Europe. For our users in the European region, data of accounts created with zoho.eu resides only in our EU data centers.

Right to rectification

You can access and change your account settings anytime to update and complete your account information. Also contact us at support@eu.zohoofficeapi.com to access, correct or amend information we have about you.

Right to erasure

The data controller who has integrated Zoho Office Integrator retains complete control over the data they upload, modify, and delete within our ecosystem.

In Office Integrator, user data remains on Zoho's servers only as long as the document session is valid (6 hours by default). However, we also provide an option to customize the session expiration time for up to a maximum of 10 days. If you prefer to remove the data before the default session ends, you can use our Delete APIs to erase any content that has been created, uploaded, or edited.Once the session expires, we run a scheduler and remove all user data from Zoho's servers automatically

Data encryption

Your data is encrypted in transit and at rest. The server always stores encryption keys and user data in an encrypted format. Office Integrator is secured with TLS 1.2 and 256-bit AES encryption. In case of a data breach or leak, end-to-end encryption helps keep information anonymous.

Learn more about Zoho's GDPR readiness.

Disclaimer: The information presented herein should not be taken as legal advice. We recommend that you seek legal advise on what you need to do to comply with the requirements of GDPR.