ZagaPrime AI Hub

Legal · ZagaPrime AI Hub

Data Processing Addendum

Effective August 31, 2026 · ZagaPrime LLC, New Jersey, United States

For businesses that hire ZagaPrime to build and run automations: how we handle your customers' and employees' personal data as your processor — instructions, sub-processors, security, breach notice within 72 hours, and deletion when we're done.

1. Scope and roles

This Data Processing Addendum ("DPA") applies when ZagaPrime LLC ("ZagaPrime", the "Processor") processes personal data on behalf of a client (the "Controller") while delivering done-for-you automation, website, branding, or consulting services under a signed Master Service Agreement and Statement of Work ("Agreement"). It forms part of the Agreement. If there is a conflict, this DPA controls for data-protection matters.

The Controller decides why and how personal data is processed; ZagaPrime processes it only to deliver the services described in the SOW and on the Controller's documented instructions. ZagaPrime is not a Business Associate under HIPAA and will not process protected health information unless a separate Business Associate Agreement is signed first.

2. Details of processing

ItemDescription
Subject matterBuilding, testing, operating, and supporting the automations, integrations, websites, and AI agents described in the SOW
DurationThe term of the Agreement plus 30 days for return or deletion
Nature and purposeCollection from the Controller's systems, transformation, transfer between systems, storage in the Controller's or ZagaPrime-managed tools, generation of AI outputs, monitoring and error handling
Types of personal dataContact details, business information, communications content, appointment and transaction data, form submissions, CRM records, and any other data the Controller routes through the automations
Data subjectsThe Controller's customers, leads, employees, contractors, and business contacts
Special categoriesNone, unless expressly agreed in writing in the SOW with appropriate safeguards

3. ZagaPrime's obligations

  • Process personal data only on the Controller's documented instructions (the SOW and written change requests), unless required by law — in which case we tell the Controller first where legally allowed.
  • Ensure everyone with access is bound by confidentiality and trained on secure handling.
  • Apply appropriate technical and organizational measures (Section 5).
  • Assist the Controller with data-subject requests, security incidents, and privacy assessments, to the extent reasonably possible and at the Controller's cost where the assistance is substantial.
  • Delete or return all personal data at the end of the services (Section 7).
  • Make available the information reasonably necessary to demonstrate compliance and allow audits (Section 8).
  • Notify the Controller if an instruction, in our opinion, violates applicable data-protection law.

4. Sub-processors

The Controller authorizes ZagaPrime to use the following categories of sub-processors, and the specific providers named in the SOW. We will give at least 14 days' notice of new sub-processors by email; the Controller may object on reasonable data-protection grounds, in which case we will work in good faith on an alternative.

CategoryTypical providersLocation
Automation and workflow platformsn8n, Make, ZapierUnited States / EU
Hosting, databases, storageVercel, Supabase, Cloudflare, Base44, Amazon Web ServicesUnited States
AI model providersOpenAI, Anthropic, Google AIUnited States
CommunicationGoogle Workspace, Twilio or similar SMS providers, email delivery providers, ZoomUnited States
CRM and business tools chosen by the ControllerHubSpot, GoHighLevel, QuickBooks, Calendly, and others in the SOWUnited States
Payments (where the automation touches payments)StripeUnited States

Sub-processors are bound by written terms that impose data-protection obligations no less protective than this DPA. ZagaPrime remains responsible for their performance.

5. Security measures

  • Credentials stored in a password manager or the platform's secret store — never in email, chat, or documents; least-privilege access; removal of access within 24 hours of an engagement ending.
  • Encryption in transit (TLS) and at rest using the providers' encryption; multi-factor authentication on ZagaPrime accounts.
  • Separate environments and test data for development; production data only when necessary for the SOW.
  • Error notifications and monitoring on every automation; logs limited to what is needed for support and retained for a defined period.
  • Documented incident-response plan; backups and rollback plans for automations before go-live.
  • Contractors bound by written agreements with confidentiality, IP assignment, and data-handling terms.

6. Personal data breaches

ZagaPrime will notify the Controller without undue delay, and in any case within 72 hours, after becoming aware of a personal data breach affecting the Controller's data, with the information reasonably available (nature of the breach, categories and approximate numbers affected, likely consequences, and measures taken), and will cooperate with the Controller's investigation and notifications to regulators or individuals.

7. Return and deletion

At the end of the services, or on the Controller's written request, ZagaPrime will return the personal data in a commonly used format and then delete it from its systems within 30 days, including from backups within the providers' standard cycles, unless retention is required by law. Where deliverables live in the Controller's own accounts, the Controller keeps them and ZagaPrime's access is revoked.

8. Audits

Once per year, or after a breach, the Controller may request written evidence of ZagaPrime's compliance with this DPA (policies, sub-processor list, security summary). Where that is insufficient, the Controller may conduct or commission an audit on 30 days' written notice, during business hours, at the Controller's cost, subject to confidentiality and without disrupting other clients.

9. International transfers

Data is processed primarily in the United States. Where data originates from the EEA, UK, or Switzerland, ZagaPrime relies on standard contractual clauses (and the UK Addendum) with its sub-processors and will enter into them with the Controller on request.

10. U.S. state privacy laws

For purposes of the CCPA/CPRA, the New Jersey Data Privacy Act, and similar U.S. state laws, ZagaPrime acts as a "service provider" or "processor": we do not sell or share the Controller's personal data, do not retain, use, or disclose it outside the direct business relationship or for any purpose other than the services, and do not combine it with personal data from other sources except as permitted by law. We certify that we understand these restrictions.

11. Liability and term

Each party's liability under this DPA is subject to the limitations in the Agreement. This DPA lasts as long as ZagaPrime processes personal data for the Controller. Related documents: Privacy Policy · Terms of Service. Requests to execute this DPA, or a Business Associate Agreement for healthcare clients: kzee@zagaprime.com.

Questions about this policy? Email kzee@zagaprime.com.