Data Processing Addendum
Last updated: July 2026
This Data Processing Addendum ("DPA") forms part of the Terms of Service between [COMPANY LEGAL NAME] ("Processor", "we") and the Client ("Controller") wherever the Client's use of the Services involves the processing of personal data subject to the GDPR, UK GDPR, or substantially similar data protection law. Capitalized terms not defined here have the meaning given in the Terms of Service or in Article 4 GDPR.
1. Roles of the Parties
The Client is the Controller of Client Data. We are the Processor, and will process personal data within Client Data only on the Client's documented instructions, as set out in the Terms of Service, this DPA, and the Client's configuration of the Services — except where we are required to do otherwise by law, in which case we will inform the Client unless that law prohibits it.
2. Confidentiality
We ensure that personnel authorized to process personal data are bound by confidentiality obligations, whether contractual or statutory.
3. Security Measures
We implement technical and organizational measures appropriate to the risk, including:
- Password hashing — passwords are never stored in plain text;
- Encryption at rest (AES-256-GCM) for connected email account credentials and OAuth tokens;
- One-way hashing of API keys;
- Encryption in transit (HTTPS/TLS) for all traffic between the Client's browser and our servers;
- Workspace-level access control, so personal data in one Client's Workspace is never accessible from another Client's Workspace;
- Role-based permissions within a Workspace, configurable by the Client.
4. Sub-processors
The Client authorizes us to engage the sub-processors listed on our Sub-processor page, which we keep up to date. We impose data protection obligations on each sub-processor no less protective than this DPA. If we add a new sub-processor, we will update that page; Clients with a paid Subscription may object on reasonable data-protection grounds by contacting [email protected]within 14 days, in which case we will work together in good faith to find a resolution, which may include ceasing to use that sub-processor for the Client's data or, if no resolution is reached, allowing the Client to terminate the affected Services.
5. International Transfers
Where personal data is transferred outside the EEA/UK to a sub-processor, we rely on the European Commission's Standard Contractual Clauses (or the equivalent UK mechanism), incorporated by reference into this DPA, together with any supplementary measures reasonably necessary.
6. Assistance with Data Subject Requests
Taking into account the nature of the processing, we will reasonably assist the Client in responding to requests from data subjects exercising their rights under applicable data protection law, and in the Client's own data protection impact assessments and consultations with supervisory authorities, where relevant to our processing.
7. Personal Data Breach Notification
We will notify the Client without undue delay after becoming aware of a personal data breach affecting the Client's Client Data, and provide information reasonably available to us to help the Client meet its own notification obligations.
8. Audit Rights
On reasonable written request, no more than once per year (except following a confirmed breach), we will provide the Client with information reasonably necessary to demonstrate compliance with this DPA, which may take the form of relevant certifications, summaries of audit reports, or a call to address specific questions, in lieu of an on-site audit.
9. Return or Deletion of Data
On termination of the Services, we will make Client Data available for export as described in the Terms of Service, and will delete or anonymize remaining Client Data within a reasonable period thereafter, except to the extent retention is required by law.
10. Liability & Term
This DPA remains in effect for as long as we process personal data on the Client's behalf under the Terms of Service. Liability under this DPA is subject to the limitation of liability provisions in the Terms of Service.
Annex A — Description of Processing
| Subject matter | Provision of the ZowaLab Services to the Client |
| Duration | For the term of the Client's Subscription, plus any post-termination export/retention period |
| Nature and purpose | Hosting, storage, transmission, and display of Client Data as needed to operate the Services the Client configures and uses |
| Categories of data subjects | The Client's Authorized Users, and the Client's own contacts, leads, and customers recorded in the Services |
| Categories of personal data | Names, contact details, correspondence, documents, and other business records the Client chooses to store in the Services |
| Special category data | Not intended to be processed; the Client should not submit special category data unless a specific feature is designed for it |
Contact
Questions about this DPA? Contact [email protected].