1. Scope and roles
This Data Processing Addendum ("DPA") applies when ZagaPrime LLC ("ZagaPrime", the "Processor") processes personal data on behalf of a client (the "Controller") while delivering done-for-you automation, website, branding, or consulting services under a signed Master Service Agreement and Statement of Work ("Agreement"). It forms part of the Agreement. If there is a conflict, this DPA controls for data-protection matters.
The Controller decides why and how personal data is processed; ZagaPrime processes it only to deliver the services described in the SOW and on the Controller's documented instructions. ZagaPrime is not a Business Associate under HIPAA and will not process protected health information unless a separate Business Associate Agreement is signed first.
2. Details of processing
| Item | Description |
|---|---|
| Subject matter | Building, testing, operating, and supporting the automations, integrations, websites, and AI agents described in the SOW |
| Duration | The term of the Agreement plus 30 days for return or deletion |
| Nature and purpose | Collection from the Controller's systems, transformation, transfer between systems, storage in the Controller's or ZagaPrime-managed tools, generation of AI outputs, monitoring and error handling |
| Types of personal data | Contact details, business information, communications content, appointment and transaction data, form submissions, CRM records, and any other data the Controller routes through the automations |
| Data subjects | The Controller's customers, leads, employees, contractors, and business contacts |
| Special categories | None, unless expressly agreed in writing in the SOW with appropriate safeguards |
3. ZagaPrime's obligations
- Process personal data only on the Controller's documented instructions (the SOW and written change requests), unless required by law — in which case we tell the Controller first where legally allowed.
- Ensure everyone with access is bound by confidentiality and trained on secure handling.
- Apply appropriate technical and organizational measures (Section 5).
- Assist the Controller with data-subject requests, security incidents, and privacy assessments, to the extent reasonably possible and at the Controller's cost where the assistance is substantial.
- Delete or return all personal data at the end of the services (Section 7).
- Make available the information reasonably necessary to demonstrate compliance and allow audits (Section 8).
- Notify the Controller if an instruction, in our opinion, violates applicable data-protection law.
4. Sub-processors
The Controller authorizes ZagaPrime to use the following categories of sub-processors, and the specific providers named in the SOW. We will give at least 14 days' notice of new sub-processors by email; the Controller may object on reasonable data-protection grounds, in which case we will work in good faith on an alternative.
| Category | Typical providers | Location |
|---|---|---|
| Automation and workflow platforms | n8n, Make, Zapier | United States / EU |
| Hosting, databases, storage | Vercel, Supabase, Cloudflare, Base44, Amazon Web Services | United States |
| AI model providers | OpenAI, Anthropic, Google AI | United States |
| Communication | Google Workspace, Twilio or similar SMS providers, email delivery providers, Zoom | United States |
| CRM and business tools chosen by the Controller | HubSpot, GoHighLevel, QuickBooks, Calendly, and others in the SOW | United States |
| Payments (where the automation touches payments) | Stripe | United States |
Sub-processors are bound by written terms that impose data-protection obligations no less protective than this DPA. ZagaPrime remains responsible for their performance.
5. Security measures
- Credentials stored in a password manager or the platform's secret store — never in email, chat, or documents; least-privilege access; removal of access within 24 hours of an engagement ending.
- Encryption in transit (TLS) and at rest using the providers' encryption; multi-factor authentication on ZagaPrime accounts.
- Separate environments and test data for development; production data only when necessary for the SOW.
- Error notifications and monitoring on every automation; logs limited to what is needed for support and retained for a defined period.
- Documented incident-response plan; backups and rollback plans for automations before go-live.
- Contractors bound by written agreements with confidentiality, IP assignment, and data-handling terms.
6. Personal data breaches
ZagaPrime will notify the Controller without undue delay, and in any case within 72 hours, after becoming aware of a personal data breach affecting the Controller's data, with the information reasonably available (nature of the breach, categories and approximate numbers affected, likely consequences, and measures taken), and will cooperate with the Controller's investigation and notifications to regulators or individuals.
7. Return and deletion
At the end of the services, or on the Controller's written request, ZagaPrime will return the personal data in a commonly used format and then delete it from its systems within 30 days, including from backups within the providers' standard cycles, unless retention is required by law. Where deliverables live in the Controller's own accounts, the Controller keeps them and ZagaPrime's access is revoked.
8. Audits
Once per year, or after a breach, the Controller may request written evidence of ZagaPrime's compliance with this DPA (policies, sub-processor list, security summary). Where that is insufficient, the Controller may conduct or commission an audit on 30 days' written notice, during business hours, at the Controller's cost, subject to confidentiality and without disrupting other clients.
9. International transfers
Data is processed primarily in the United States. Where data originates from the EEA, UK, or Switzerland, ZagaPrime relies on standard contractual clauses (and the UK Addendum) with its sub-processors and will enter into them with the Controller on request.
10. U.S. state privacy laws
For purposes of the CCPA/CPRA, the New Jersey Data Privacy Act, and similar U.S. state laws, ZagaPrime acts as a "service provider" or "processor": we do not sell or share the Controller's personal data, do not retain, use, or disclose it outside the direct business relationship or for any purpose other than the services, and do not combine it with personal data from other sources except as permitted by law. We certify that we understand these restrictions.
11. Liability and term
Each party's liability under this DPA is subject to the limitations in the Agreement. This DPA lasts as long as ZagaPrime processes personal data for the Controller. Related documents: Privacy Policy · Terms of Service. Requests to execute this DPA, or a Business Associate Agreement for healthcare clients: kzee@zagaprime.com.
