This Data Processing Addendum ("DPA") is part of the Terms of Service between Zeloxa Labs LLC ("Zeloxa") and the customer that accepts them ("Customer"). It applies when Zeloxa processes Personal Data on Customer's behalf while providing the Services, mainly the personal data of visitors to websites Customer hosts on Zeloxa Host and data Customer stores in Zeloxa Cloud. It applies automatically; no signature is needed. If Customer needs a countersigned copy, email legal@zeloxalabs.com.
1. Definitions
"Data Protection Laws" means all laws that apply to the processing of Personal Data under the Terms, including the EU General Data Protection Regulation 2016/679 ("GDPR"), the UK GDPR and Data Protection Act 2018, the Swiss Federal Act on Data Protection, and U.S. state privacy laws such as the California Consumer Privacy Act as amended ("CCPA"). "Personal Data", "controller", "processor", "data subject", "processing" and "supervisory authority" have the meanings given in the GDPR; "business", "service provider", "sell" and "share" have the meanings given in the CCPA. "Customer Personal Data" means Personal Data that Zeloxa processes for Customer under the Terms. "Security Incident" means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, Customer Personal Data.
2. Roles and instructions
- Customer is the controller (or a processor acting for its own controller) and Zeloxa is a processor (and, under the CCPA, a service provider) of Customer Personal Data.
- Zeloxa processes Customer Personal Data only on Customer's documented instructions. The Terms, this DPA, and Customer's configuration and use of the Services (including which forms, integrations and notifications it turns on) are Customer's complete instructions. Zeloxa will tell Customer if it believes an instruction breaks Data Protection Laws, and is not required to follow it.
- Customer is responsible for having a lawful basis for the processing, for giving data subjects the notices and obtaining the consents the law requires, and for the accuracy of Customer Personal Data and the lawfulness of its instructions.
3. Details of the processing
| Subject matter and purpose | Providing the Services: hosting and delivering Customer's websites, receiving and storing form submissions and sending the notifications and integrations Customer chooses, producing cookie-free visitor analytics, and storing data Customer puts in Zeloxa Cloud |
| Duration | The term of the Terms, plus the deletion periods in section 10 |
| Nature of processing | Collection, storage, transmission, retrieval, aggregation and deletion |
| Data subjects | Visitors to Customer's websites; people who submit Customer's forms; Customer's end users in Zeloxa Cloud |
| Categories of data | Whatever visitors enter into Customer's forms (typically name, email address, phone number and message); salted hashes of IP addresses; browser user-agent and referring page; pseudonymous, daily-rotating visitor identifiers and the country, device and pages viewed; data Customer stores in Zeloxa Cloud |
| Special categories | None are intended. Customer will not use the Services to collect special categories of data or government ID, payment card or health information unless Zeloxa agrees in writing |
4. Zeloxa's obligations
Zeloxa will:
- process Customer Personal Data only as described in section 2, and not for its own purposes;
- not sell or share Customer Personal Data, not retain, use or disclose it outside the direct business relationship with Customer or for any purpose other than providing the Services, and not combine it with Personal Data it receives from others except as the CCPA permits. Zeloxa certifies that it understands and will comply with these restrictions;
- ensure that people authorized to process Customer Personal Data are bound by confidentiality obligations;
- implement the security measures in section 6;
- assist Customer, taking into account the nature of the processing, in responding to data subjects' requests and in meeting its obligations on security, breach notification, data protection impact assessments and prior consultation. The Services let Customer view, export and delete form submissions itself;
- notify Customer if it can no longer meet its obligations under the CCPA.
5. Sub-processors
- Customer authorizes Zeloxa to use the sub-processors listed in section 5 of the Privacy Policy (currently Cloudflare, Supabase, Stripe and, where Customer connects it, GitHub).
- Zeloxa has written agreements with each sub-processor that impose data protection obligations no less protective than this DPA, and remains responsible for their performance.
- Zeloxa will notify Customer by email at least 30 days before adding or replacing a sub-processor that processes Customer Personal Data. Customer may object on reasonable data-protection grounds within that period; the parties will discuss it in good faith, and if they cannot resolve it Customer may terminate the affected Services and receive a refund of prepaid fees for the period after termination.
- Integrations and third-party tags Customer turns on (such as Zapier, Make, Slack, Google Analytics or Meta Pixel) are not Zeloxa's sub-processors; they receive data at Customer's direction under Customer's own agreements with them.
6. Security
Zeloxa maintains appropriate technical and organizational measures, including:
- encryption of data in transit (HTTPS/TLS) and at rest by its hosting and database providers;
- storing IP addresses of form submitters and website visitors only as salted, one-way hashes;
- hashing API tokens and passwords, and encrypting stored environment variables;
- role-based access within customer organizations, and an audit log of account activity;
- access to production systems restricted to personnel who need it, protected by strong authentication;
- rate limiting, spam filtering and abuse monitoring;
- vulnerability management, including keeping software dependencies patched.
Zeloxa may update these measures as long as the overall level of protection is not reduced.
7. Security Incidents
Zeloxa will notify Customer without undue delay, and where feasible within 72 hours, after becoming aware of a Security Incident affecting Customer Personal Data. The notice will describe, as far as then known, the nature of the incident, the categories and approximate number of data subjects and records concerned, the likely consequences, and the measures taken or proposed. Zeloxa will take reasonable steps to contain and remedy the incident and will provide information Customer reasonably needs to meet its own notification obligations. Notifying Customer is not an admission of fault.
8. International transfers
Zeloxa and its sub-processors process data in the United States, Canada and other countries. To the extent Customer Personal Data subject to the GDPR, UK GDPR or Swiss law is transferred to a country without an adequacy decision, the parties agree that the Standard Contractual Clauses adopted by the European Commission in Decision 2021/914 are incorporated by reference, with Module Two (controller to processor) or Module Three (processor to processor) as applicable, Clause 7 (docking clause) included, Option 2 (general authorization) in Clause 9 with the notice period in section 5 of this DPA, the optional language in Clause 11 omitted, Irish law in Clause 17 and the courts of Ireland in Clause 18; Annex I is completed by section 3 of this DPA and Annex II by section 6. For UK transfers, the UK International Data Transfer Addendum is incorporated; for Swiss transfers, references to the GDPR are read as references to the Swiss law and the Swiss Federal Data Protection and Information Commissioner is the competent authority.
9. Audits
Zeloxa will make available information reasonably necessary to demonstrate compliance with this DPA, by answering Customer's reasonable written security and privacy questionnaires once per year, and by providing its sub-processors' available audit reports or certifications on request. If that is not enough to meet a requirement of Data Protection Laws or a supervisory authority, Customer may conduct an audit at its own cost, with at least 30 days' notice, during business hours, no more than once a year, under confidentiality obligations, and without access to other customers' data.
10. Return and deletion
During the term, Customer can export and delete Customer Personal Data using the Services. Form submissions are deleted automatically after 12 months and visitor analytics after 90 days. After the Terms end, Zeloxa deletes remaining Customer Personal Data within 30 days, and from backups when they expire (within a further 30 days), unless the law requires it to keep some of it, in which case it will keep that data confidential and process it only for that purpose.
11. Liability and precedence
Each party's liability under this DPA is subject to the limitations in the Terms, to the extent permitted by Data Protection Laws. If this DPA conflicts with the Terms, this DPA controls for the processing of Customer Personal Data; if the Standard Contractual Clauses conflict with this DPA, the Standard Contractual Clauses control.
12. Contact
Privacy questions and requests about this DPA: privacy@zeloxalabs.com. Zeloxa Labs LLC, Orange County, California, United States.

