Data Processing Addendum

The finest print around.

Data Processing Addendum (DPA)

Version 1.3 · Last Updated: September 3, 2026

1. Purpose and Scope

This Data Processing Addendum (“Addendum”) forms part of the principal services agreement (“Principal Agreement”) between Controller and Processor and sets out the obligations of the parties with respect to the processing of personal data as required by Article 28 GDPR and related legislation.

All capitalised terms not defined herein have the meaning given in the Principal Agreement or in the GDPR.

2. Subject Matter, Duration, Nature, and Purpose

  1. Subject Matter: Processing of personal data to enable survey creation, display, response collection, analytics, and related customer-experience functions provided by Zigpoll.
  2. Duration: For the term of the Principal Agreement and until deletion or return of data pursuant to § 13.
  3. Nature and Purpose: Collection, storage, analysis, export, and reporting of survey responses and associated metadata (including contact details, online identifiers, transaction references, timestamps, and engagement metrics) for purposes of feedback, marketing analysis, and customer-experience optimisation.
  4. Categories of Data Subjects: End-users, customers, and website visitors of Controller.
  5. Categories of Personal Data: Order-related metadata, usage data, device or browser identifiers, and survey responses.
  6. Special Categories of Data: None intentionally processed.

3. Processing on Documented Instructions

  1. Processor shall process personal data only on documented instructions from Controller.
  2. Persons authorised to issue and receive such instructions are identified in Schedule B.
  3. Oral instructions must be confirmed in writing (email suffices) within 24 hours and archived by both parties.
  4. Processor shall immediately inform Controller if, in its opinion, an instruction infringes applicable data-protection law.
  5. Processor shall notify Controller without undue delay if it becomes subject to any legal obligation that would require it to process personal data outside of or contrary to Controller's documented instructions, unless the law in question prohibits such notification on important grounds of public interest (Art. 28(3)(a) GDPR).

4. Artificial Intelligence and Model Training

  1. Processor uses the artificial-intelligence sub-processor identified in Schedule A to provide the AI-assisted features of the Services, including generating analytical summaries, themes, and insights from survey data on Controller's behalf, answering Controller's natural-language questions about Controller's own survey data, assisting Controller in drafting surveys, and detecting abusive or fraudulent content. Personal data is disclosed to that sub-processor for no other purpose.
  2. Processor does not use Controller personal data, including survey responses, to train, fine-tune, or otherwise develop any artificial-intelligence or machine-learning model, whether its own or a third party's.
  3. Personal data disclosed to the artificial-intelligence sub-processor is not used by that sub-processor to train or improve its models. Processor transmits such data with server-side storage disabled, and the sub-processor retains it only transiently for abuse monitoring in accordance with its published API data-usage policy.
  4. Participant metadata is supplied entirely at Controller's discretion. Processor does not create, populate, or require participant metadata and collects none of it automatically; such metadata exists only where Controller has chosen to send it, through the embed snippet, the API, or the MCP integration. Controller determines whether to supply any metadata at all and which fields it contains, and may omit it entirely without loss of core Service functionality.
  5. Controller acknowledges that any personal data it elects to place in participant metadata — for example names, email addresses, or customer and order identifiers — forms part of the survey data that AI-assisted analysis features may process, and may accordingly be transmitted to the artificial-intelligence sub-processor when Controller uses those features. Controller remains responsible for establishing a lawful basis for supplying such metadata and for observing the principle of data minimisation when doing so.
  6. Separately from Controller-supplied metadata, Processor collects certain technical data automatically in the ordinary course of delivering the Services, namely IP address, the approximate location derived from it (country, region, city), and device or browser metadata.
  7. The point at which each category is disclosed to the artificial-intelligence sub-processor differs, and Controller controls it:
    • Processor's automated generation of survey insights transmits survey responses and aggregate survey statistics only. It does not transmit participant metadata, IP address, derived location, or device or browser metadata.
    • Participant metadata, IP address, derived location, and device or browser metadata are transmitted only where Controller itself invokes an AI-assisted analysis feature and the request Controller submits requires that data in order to be answered. Processor does not transmit these categories on any automatic, background, or bulk basis.
  8. Controller acknowledges that free-text survey responses may contain personal data volunteered by the data subject, and remains responsible for the design and wording of its survey questions.
  9. Outputs generated by the artificial-intelligence sub-processor are returned to Processor, stored within Processor's own infrastructure, and made available only to Controller. They are not disclosed to any other customer.
  10. Processor shall not add or replace the artificial-intelligence sub-processor, nor materially expand the categories of personal data disclosed to it, except in accordance with Section 7 (Sub-Processing).

5. Confidentiality

Processor shall ensure that all authorised personnel have committed themselves to confidentiality or are under an appropriate statutory obligation of secrecy. Written records of such undertakings shall be retained and made available to Controller upon request.

6. Technical and Organisational Measures (TOMs)

Processor shall implement the technical and organisational measures described in Schedule C, ensuring a level of security appropriate to the risk as required by Article 32 GDPR. Processor shall provide evidence of implementation upon reasonable request or audit.

7. Sub-Processing

  • Controller grants Processor a general authorisation to engage sub-processors for the performance of the Services.
  • The current list of sub-processors is attached in Schedule A.
  • Processor shall notify Controller in writing at least 30 days before adding or replacing any sub-processor. Controller may object on reasonable data-protection grounds within 14 days.
  • Processor shall ensure each sub-processor is bound by equivalent obligations and safeguards.

8. Data Subject Rights

Processor shall assist Controller, by appropriate technical and organisational measures, in fulfilling its obligations to respond to data-subject requests under Chapter III GDPR (access, rectification, erasure, restriction, portability, objection).

9. Assistance Obligations (Art. 28(3)(f) GDPR)

Taking into account the nature of the processing and the information available to Processor, Processor shall assist Controller in ensuring compliance with the following obligations:

  • Security of processing (Article 32 GDPR);
  • Notification of personal data breaches to the supervisory authority (Article 33 GDPR);
  • Communication of personal data breaches to data subjects (Article 34 GDPR);
  • Data protection impact assessments (Article 35 GDPR), including by providing information necessary for Controller to conduct and, where required, update such assessments; and
  • Prior consultation with the supervisory authority (Article 36 GDPR).

Processor shall respond to reasonable assistance requests without undue delay and may charge a reasonable fee for assistance that is manifestly excessive or unfounded.

10. International Data Transfers

  • Personal data processed under this Addendum may be transferred to, stored, or processed in the United States and other countries where Processor's sub-processors operate.
  • For transfers of personal data from the European Economic Area (EEA), United Kingdom, or Switzerland to countries that have not received an adequacy decision from the European Commission, Processor shall ensure that appropriate safeguards are in place in accordance with Article 46 GDPR, including:
    • The European Commission's Standard Contractual Clauses (SCCs) as adopted under Implementing Decision (EU) 2021/914, which are hereby incorporated into this Addendum; and/or
    • Certification of the data importer under an approved framework such as the EU-US Data Privacy Framework, where applicable; and
    • For transfers subject to the UK GDPR, the SCCs as read with the UK Addendum incorporated in § 10.5; and for transfers subject to the Swiss FADP, the SCCs with the adaptations in § 10.6.

10.1 Module Selection

The following SCC modules apply:

  • Module Two (Controller to Processor): Applies to transfers of personal data from Controller (as data exporter) to Processor (as data importer) for the provision of the Services described in § 2 of this Addendum.
  • Module Three (Processor to Processor): Applies to onward transfers of personal data from Processor (as data exporter) to the sub-processors listed in Schedule A (as data importers) for the purposes described therein.

10.2 Optional Clause Selections

The parties agree to the following selections for the optional and variable clauses of the SCCs:

Clause Selection
Clause 7 – Docking Clause Included. Additional parties may accede to the SCCs as data exporter or data importer with the agreement of the existing parties.
Clause 9(a) – Sub-processor Authorisation Option 2: General written authorisation. Processor has Controller's general authorisation to engage sub-processors. Processor shall notify Controller at least 30 days in advance of any intended changes to the list of sub-processors, giving Controller the opportunity to object per § 6 of this Addendum.
Clause 11(a) – Independent Dispute Resolution Body The optional language permitting data subjects to lodge a complaint with an independent dispute resolution body is not adopted.
Clause 13(a) – Competent Supervisory Authority The competent supervisory authority is the Irish Data Protection Commission (DPC). Where the data exporter is established in another EU/EEA Member State, the supervisory authority of that Member State shall serve as the competent authority for that data exporter.
Clause 17 – Governing Law Option 1. The SCCs shall be governed by the laws of Ireland.
Clause 18(b) – Forum and Jurisdiction Disputes arising under the SCCs shall be resolved before the courts of Ireland.

10.3 SCC Annexes

The required annexes to the SCCs are completed as follows:

  • Annex I (Description of the Transfer): Schedule D of this Addendum.
  • Annex II (Technical and Organisational Measures): Schedule C of this Addendum.
  • Annex III (List of Sub-Processors): Schedule A of this Addendum.

10.4 Supplementary Measures

  • The applicable transfer mechanism for each sub-processor is identified in Schedule A. Where SCCs apply, Processor shall ensure that a Transfer Impact Assessment (TIA) has been conducted and that supplementary measures are implemented where necessary to ensure an essentially equivalent level of protection.
  • Processor shall promptly inform Controller of any changes in legislation or circumstances that materially affect the lawfulness or adequacy of the transfer safeguards relied upon.
  • Upon request, Processor shall make available copies of the executed SCCs and relevant TIA documentation.

10.5 Transfers subject to the UK GDPR

For transfers of personal data that are subject to the UK GDPR, the parties agree that the International Data Transfer Addendum to the EU Commission Standard Contractual Clauses issued by the Information Commissioner under section 119A of the Data Protection Act 2018 (version B1.0, in force 21 March 2022) (the "UK Addendum") is incorporated into and forms part of this Addendum, and the SCCs shall be read and interpreted in accordance with the UK Addendum in respect of those transfers. The UK Addendum is completed as follows:

UK Addendum table Completion
Table 1 – Parties As set out in Schedule D, Part A: the Exporter is Controller and the Importer is Processor. The start date is the Effective Date of this Addendum.
Table 2 – Selected SCCs, Modules and Selected Clauses The Approved EU SCCs as incorporated by this § 10 (Implementing Decision (EU) 2021/914, in the version current at the date of this Addendum), Module Two, and Module Three for onward transfers to sub-processors, with the clause selections made in § 10.2.
Table 3 – Appendix Information Annex 1A (List of Parties) and Annex 1B (Description of Transfer): Schedule D. Annex II (Technical and Organisational Measures): Schedule C. Annex III (List of Sub-processors): Schedule A.
Table 4 – Ending this Addendum when the Approved Addendum changes Importer (Processor) may end the UK Addendum as set out in Section 19 of the UK Addendum.

In accordance with Part 2 (Mandatory Clauses) of the UK Addendum, for transfers subject to the UK GDPR: references in the SCCs to the GDPR and to EU or Member State law are read as references to the UK GDPR and UK law; the competent supervisory authority is the Information Commissioner's Office (ICO); the SCCs are governed by the laws of England and Wales; disputes are resolved before the courts of England and Wales, and a data subject may also bring proceedings before the courts of any country in the United Kingdom. Where the SCCs and the UK Addendum conflict in respect of such a transfer, the UK Addendum prevails.

10.6 Transfers subject to the Swiss FADP

For transfers of personal data that are subject to the Swiss Federal Act on Data Protection of 25 September 2020 (FADP), the SCCs apply with the following adaptations, as recognised by the Federal Data Protection and Information Commissioner (FDPIC):

  1. references to the GDPR are read as references to the FADP, and references to Article 46(2)(c) GDPR as references to Article 16(2)(d) FADP, insofar as the transfer is subject to the FADP;
  2. references to the "EU", "Union", "Member State" and "Member State law" are read as including Switzerland and Swiss law;
  3. insofar as the transfer is subject to the FADP, the competent supervisory authority under Clause 13 and Schedule D, Part C is the FDPIC; insofar as it is also subject to the GDPR, the authority identified in § 10.2 remains competent in parallel;
  4. Clause 18(c) is read so that data subjects may also bring legal proceedings against Controller and/or Processor before the courts of Switzerland; and
  5. the governing law and forum selected in § 10.2 otherwise remain unchanged.

11. Personal Data Breach Notification

In the event of a personal data breach, Processor shall without undue delay and, where feasible, not later than 48 hours after becoming aware, notify Controller.

The notice shall include:

  • contact details of a data-protection contact point;
  • description of the nature of the breach (categories and approximate number of data subjects and records concerned);
  • likely consequences; and
  • measures taken or proposed to remedy or mitigate the breach.

If all information cannot be provided simultaneously, the Processor shall supply it incrementally without undue delay.

12. Audit and Compliance

  • Processor shall make available to Controller all information necessary to demonstrate compliance with Article 28 GDPR and shall allow for and contribute to audits, including on-site inspections, by Controller or a qualified independent auditor mandated by Controller.
  • Controller may conduct one routine audit per calendar year with at least 30 days’ prior written notice. Additional audits may be conducted following a substantiated data-protection incident or a reasonable suspicion of non-compliance, with notice reduced to a reasonable minimum under the circumstances.
  • Audits may be performed remotely or on-site at Controller’s discretion. Processor shall provide reasonable co-operation, access to relevant systems, and personnel, and any documentation necessary for the audit. Processor operates without dedicated office premises. Where physical inspection is requested, it shall be conducted at Processor’s infrastructure sub-processor facilities (subject to that sub-processor’s audit policies) or, where physical inspection is not applicable, through supervised remote access sessions providing equivalent visibility into systems, configurations, and documentation.
  • Where Processor engages an independent third-party auditor to produce a compliance report (e.g., SOC 2 Type II), Processor may offer such report to satisfy Controller’s audit right, provided Controller retains the right to conduct its own audit if the report does not adequately address its concerns.

13. Return and Deletion of Data

Upon termination or expiry of the Services, Processor deactivates Controller’s account immediately: personal data is no longer served, delivered, exported or processed. At Controller’s choice, Processor then returns and/or deletes all personal data as follows:

  • On Controller’s written instruction (including an instruction given before or at termination), personal data is deleted from production systems within 30 days of the instruction.
  • Absent an instruction, personal data is retained in deactivated form for a grace period of 90 days, so that an accidental termination or lapsed subscription can be reversed and any outstanding billing, dispute or legal matter resolved, and is then permanently deleted from production systems, in any event within 12 months of termination.

Encrypted backups are immutable and are not edited; copies of deleted personal data expire on Processor’s backup rotation schedule (point-in-time recovery window of 7 days; snapshots retained for up to 12 months). Backups are used only for disaster recovery, are never restored to reintroduce deleted data, and if a backup containing deleted data is restored, the deletion log is replayed before the restored data is returned to service.

Processor retains personal data beyond these periods only where Union, Member State or United Kingdom law requires retention (for example billing and tax records), in which case the data is de-identified where possible and placed beyond ordinary use until the retention period ends. On request, Processor confirms in writing what was deleted, what is retained, on what legal basis and until when. The procedure is set out in Processor’s Data Management Policy (Data Deletion Procedure), available on request.

14. Liability and Governing Law

This Addendum is governed by the laws of the State of New York, USA, except to the extent mandatory provisions of EU data-protection law prevail. The Standard Contractual Clauses incorporated under § 9 are governed exclusively by the laws of Ireland, as specified in Clause 17 of the SCCs. Liability provisions of the Principal Agreement apply equally to this Addendum.

15. Notices

All notices and communications under this Addendum must be in writing (email suffices) and addressed to the contacts listed in Schedule B.


Schedules

Schedule A – Approved Sub-Processors (SCC Annex III)

Sub-Processor Purpose Location Safeguard Mechanism
Amazon Web Services (AWS) Hosting & Storage US SCCs + EU-US DPF
MongoDB Atlas Database Services US SCCs
Redis Inc. (Redis Cloud) Database Services US SCCs
Cloudflare Inc. CDN & Security EU / US SCCs + EU-US DPF
Mailgun Technologies, Inc. (Sinch) Transactional & Survey Email Delivery US SCCs
Twilio Inc. SMS Survey Delivery US SCCs
DigitalOcean, LLC Hosting (Background Workers) US SCCs
Stripe, Inc. Billing & Payment Processing US SCCs
Sentry Inc. Error Monitoring EU / US SCCs + EU-US DPF
Google LLC (Analytics) Analytics / Reporting EU / US SCCs + EU-US DPF
OpenAI AI Infrastructure US SCCs

Schedule B – Authorised Representatives & Instruction Contacts

Party Name / Role Email Function
Processor Jason Zigelbaum – CEO (Zigpoll) [email protected] Receives instructions
Alternate Support Lead (Zigpoll) [email protected] Backup contact

Schedule C – Technical and Organisational Measures (SCC Annex II)

The following measures are implemented in accordance with Article 32 GDPR to ensure a level of security appropriate to the risk of the processing.

C.1 Access Control – Authentication & Authorisation

Measure Detail
Multi-factor authentication (MFA) Required for all employees accessing production systems, administrative consoles, and source-code repositories.
Role-based access control (RBAC) Access to personal data is granted on a need-to-know basis. Roles are defined per function (engineering, support, management) with least-privilege principles enforced.
Periodic access reviews Access rights are reviewed quarterly. Accounts of departing employees are revoked within 24 hours of separation.
Production/non-production segregation Development and staging environments are logically separated from production. Production data is not used in development or testing.

C.2 Encryption

Measure Detail
Encryption in transit All data transmitted between clients, servers, and sub-processors is encrypted using TLS 1.2 or higher (TLS 1.3 preferred). HSTS is enforced on all public endpoints.
Encryption at rest All databases and storage volumes are encrypted with AES-256 using provider-managed keys (AWS KMS, MongoDB Atlas encryption).
Key management Encryption keys are managed through AWS Key Management Service (KMS) with automatic annual rotation. Access to key management is restricted to authorised personnel.

C.3 Network Security

Measure Detail
Firewall & network segmentation Cloud infrastructure uses security groups and network ACLs to restrict traffic. Only required ports and protocols are permitted.
DDoS protection Cloudflare is deployed in front of all public-facing services, providing WAF, rate-limiting, and DDoS mitigation.
Intrusion detection AWS GuardDuty and Cloudflare security analytics are enabled for continuous monitoring of suspicious activity.

C.4 Data Minimisation & Pseudonymisation

Measure Detail
Data minimisation Only personal data strictly necessary for the provision of survey and analytics services is collected. No special category data (Article 9 GDPR) is intentionally processed.
Pseudonymisation Where feasible, survey responses are stored with pseudonymous identifiers. Direct identifiers are separated from response data in storage.
Retention limits Personal data is retained only for the duration of the service agreement. Upon termination, the account is deactivated immediately and personal data is permanently deleted after a 90-day grace period and in any event within 12 months, or within 30 days of Controller’s instruction, per § 13.

C.5 Integrity & Availability

Measure Detail
Automated backups Databases are backed up continuously with point-in-time recovery (7-day window) and encrypted snapshots retained on a rotation schedule (hourly 2 days, daily 7 days, weekly 4 weeks, monthly 12 months). Deleted personal data therefore persists in backups for at most 12 months, and backups are never restored to reintroduce deleted data (§ 13).
Restore testing Backup restoration is tested periodically to verify recoverability and data integrity.
Redundancy Application services run across multiple availability zones to ensure high availability and fault tolerance.
Uptime monitoring Continuous uptime and performance monitoring with automated alerting for service degradation or outages.

C.6 Vulnerability Management

Measure Detail
Patch management Security patches for operating systems, frameworks, and dependencies are applied on a monthly cycle. Critical vulnerabilities are patched within 72 hours of disclosure.
Dependency scanning Automated dependency vulnerability scanning is integrated into the CI/CD pipeline. Builds with known critical vulnerabilities are blocked.
Penetration testing An independent penetration test of the application and public APIs is scheduled for Q4 2026 and at least annually thereafter, and after major changes; findings are remediated on a risk-prioritised basis. Continuous automated dependency scanning operates in the interim.

C.7 Logging & Monitoring

Measure Detail
Audit logging Access to personal data, administrative actions, and authentication events are logged. Logs are retained for a minimum of 90 days.
Error & exception monitoring Application errors are tracked via Sentry with real-time alerting for anomalies affecting data processing.
Log integrity Logs are stored in append-only storage and are not modifiable by application-level processes.

C.8 Physical Security

Measure Detail
Data centre security All infrastructure is hosted on Amazon Web Services (AWS). AWS data centres maintain SOC 2 Type II, ISO 27001, and other certifications covering physical access controls, surveillance, and environmental safeguards.
Endpoint security Employee devices with access to production systems use full-disk encryption and are protected with up-to-date endpoint security software.

C.9 Incident Response

Measure Detail
Incident response plan A documented incident response playbook is maintained covering identification, containment, eradication, recovery, and post-incident review.
Breach notification Controller is notified without undue delay and, where feasible, within 48 hours of Processor becoming aware of a personal data breach, per § 11 of this Addendum.
Designated security contact A designated security officer is responsible for coordinating incident response and communication.

C.10 Employee Measures

Measure Detail
Confidentiality obligations All employees and contractors with access to personal data are bound by written confidentiality agreements per § 4 of this Addendum.
Security training Employees receive data-protection and security-awareness training upon onboarding and annually thereafter.

Schedule D – SCC Annex I (Description of the Transfer)

A. List of Parties

Data Exporter Data Importer
Name The entity identified as "Controller" in the Principal Agreement Argonautic Labs LLC (dba Zigpoll)
Address As specified in the Principal Agreement New York, NY, United States
Contact Person As specified in the Principal Agreement Jason Zigelbaum, CEO — [email protected]
Activities Use of the Zigpoll platform for survey creation, distribution, and analysis of responses from end users Provision of SaaS survey, feedback collection, analytics, and customer-experience optimisation services
Role Controller Processor

B. Description of the Transfer

Element Detail
Categories of Data Subjects End users, customers, and website visitors of the Data Exporter (Controller).
Categories of Personal Data Order-related metadata, usage data, device or browser identifiers, email addresses, survey responses, engagement metrics, timestamps, and online identifiers. No special categories of data (Article 9 GDPR) are intentionally transferred.
Sensitive Data None intentionally transferred. Should Controller configure surveys that collect sensitive data, Controller is responsible for ensuring a lawful basis under Article 9 GDPR.
Frequency of Transfer Continuous, for the duration of the Principal Agreement.
Nature and Purpose of Processing Collection, storage, analysis, export, and reporting of survey responses and associated metadata for the purposes of feedback, marketing analysis, and customer-experience optimisation as described in § 2 of this Addendum.
Retention Period For the duration of the Principal Agreement. Upon termination, the account is deactivated immediately and personal data is deleted or returned per § 13: within 30 days of Controller’s instruction, otherwise after a 90-day grace period and in any event within 12 months, with backup copies expiring within a further 12 months; unless retention is required by applicable law.
Sub-Processors As listed in Schedule A (which also constitutes SCC Annex III).

C. Competent Supervisory Authority

The competent supervisory authority is the Irish Data Protection Commission (An Coimisiún um Chosaint Sonraí), in accordance with Clause 13(a) of the SCCs. Where the Data Exporter is established in another EU/EEA Member State, the supervisory authority of that Member State shall serve as the competent authority for that Data Exporter. For transfers subject to the UK GDPR, the competent supervisory authority is the Information Commissioner's Office (§ 10.5); for transfers subject to the Swiss FADP, the Federal Data Protection and Information Commissioner (§ 10.6).

Start collecting feedback in 5 minutes.

Try our no-code surveys that visitors actually answer.

Questions or Feedback?

We are always ready to hear from you.