Start free

Data Processing Addendum

Your customers' data is yours. We process it only to run your site, and here is exactly how.

Plain-English baseline. This is a clear, good-faith starting draft — not legal advice. Have your counsel review and adapt it before relying on it for your jurisdiction.
Version 2.1 · Effective 2026-10-04

1. Scope and roles

This Data Processing Addendum ("DPA") forms part of the Terms of Service between you (the account holder, the "controller") and Arad Soft Ltd. (xigzag, the "processor"). It applies whenever we process personal data on your behalf about your site's customers, members, visitors or staff ("Customer Personal Data") under the GDPR, the UK GDPR, the Swiss FADP, PIPEDA and Quebec Law 25, or the CCPA/CPRA. It applies automatically; nothing needs signing. A countersigned copy is available from privacy@xigzag.com. If this DPA conflicts with the Terms, this DPA prevails for Customer Personal Data.

2. Documented instructions (Art. 28(3)(a))

We process Customer Personal Data only on your documented instructions: the Terms, this DPA and your settings and actions in the Studio, including transfers to third countries, unless EU or member-state law requires otherwise (in which case we tell you first unless the law forbids it). We immediately inform you if, in our opinion, an instruction infringes data-protection law. We don't sell Customer Personal Data, use it to advertise, or train shared AI models on it.

3. Details of the processing (Annex I)

  • Subject matter and purpose: hosting your site and providing its features: orders, bookings, memberships, forms, messages, emails you configure, analytics you enable, backups and security.
  • Data subjects: your site's visitors, customers, members, applicants, staff and contacts.
  • Categories: contact details, order, booking and payment references (never full card numbers), messages and form answers, account credentials (stored hashed), technical data such as IP address. Special-category data only if you choose to collect it (e.g. a clinic intake form); you must have a lawful condition for it, and the Health Data Addendum then applies.
  • Frequency and duration: continuous, for as long as you use the service, then deletion under section 10.

4. Confidentiality (Art. 28(3)(b))

Everyone at xigzag authorised to process Customer Personal Data is bound by a contractual or statutory duty of confidentiality and accesses it only where needed to support you or keep the service safe.

5. Security (Art. 28(3)(c), Art. 32) — Annex II

  • Isolation: each site's data in its own separate database.
  • Encryption: TLS 1.2+ with HSTS in transit; sealed (AES-256-GCM) storage of secrets and API keys; encrypted offsite backups.
  • Access control: hashed passwords, optional two-factor sign-in, least-privilege staff roles, short-lived and logged support sessions, session revocation on password change.
  • Resilience: daily verified backups, a tested restore procedure, health and readiness monitoring, error alerting.
  • Testing: automated security gates on every release, periodic review of these measures.

See Security & Trust.

6. Sub-processors (Art. 28(2) and (4))

You give us general authorisation to engage the Sub-processors listed below. We impose on each, by written contract, data-protection obligations offering the same level of protection as this DPA, and we remain liable to you for their performance. We will give at least 30 days' notice of a new or replaced Sub-processor by email and on this page; you may object on reasonable data-protection grounds within that period, and if we cannot reasonably accommodate the objection you may terminate the affected service with a pro-rata refund.

  • [HOSTING PROVIDER]: Servers that host the platform and every site. Data: All service data. Location: [HOSTING COUNTRY]. Transfer safeguard: Adequacy or SCCs where outside the EEA. DPA / SCCs: [HOSTING PROVIDER DPA URL].
  • [OFFSITE BACKUP STORAGE PROVIDER]: Encrypted offsite backups (the provider cannot read them). Data: Encrypted copies of all service data. Location: [BACKUP REGION]. Transfer safeguard: SCCs where outside the EEA. DPA / SCCs: [BACKUP PROVIDER DPA URL].
  • Stripe, Inc. / Stripe Payments Europe, Ltd.: Platform subscription billing; card payments on storefronts that connect Stripe. Data: Name, email, billing address, payment details (held by Stripe, not us). Location: Ireland / USA. Transfer safeguard: EU-US Data Privacy Framework; SCCs. DPA / SCCs: https://stripe.com/legal/dpa.
  • NameSilo, LLC: Domain registration and renewal (registrant details are required by ICANN). Data: Registrant name, address, email, phone. Location: USA. Transfer safeguard: SCCs; ICANN registration-data rules. DPA / SCCs: [NAMESILO REGISTRATION AGREEMENT / DPA URL].
  • Cloudflare, Inc.: Bot protection on forms (Turnstile) and DNS for connected domains. Data: IP address, browser signals; DNS records. Location: Global network / USA. Transfer safeguard: EU-US Data Privacy Framework; SCCs. DPA / SCCs: https://www.cloudflare.com/cloudflare-customer-dpa/.
  • Google LLC / Google Ireland Ltd.: Optional Google sign-in, Calendar and Maps features. Data: Profile/email for sign-in; calendar events when connected. Location: Ireland / USA. Transfer safeguard: EU-US Data Privacy Framework; SCCs. DPA / SCCs: https://business.safety.google/processorterms/.
  • Telegram FZ-LLC: Operational alerts to our on-call staff. Data: No personal data: the alert type, route, internal ids and a link to our console (personal data is stripped before sending). Location: UAE / global. Transfer safeguard: Not a transfer of personal data. DPA / SCCs: Not needed: no personal data is sent (https://telegram.org/privacy).
  • [ERROR MONITORING PROVIDER, OR "self-hosted"]: Error monitoring (ERROR_WEBHOOK_URL). Data: Error reports: route, message, stack trace, request id. Location: [REGION]. Transfer safeguard: SCCs where outside the EEA. DPA / SCCs: [ERROR MONITORING DPA URL].

Used only when a feature is enabled:

The current list, with each provider's region, purpose and DPA, is also at /legal/subprocessors, where you can sign up for the 30-day change notice.

Providers you connect with your own account (payment, shipping, marketplaces, accounting and other business tools) are not our Sub-processors: they act under your own contract with them, and we transmit to them only what your site needs. For transparency:

  • Payment providers the owner connects: Taking payment on the owner's storefront: PayPal, Adyen, Checkout.com, Mollie, Razorpay, Paystack, Flutterwave, Mercado Pago, Midtrans, Xendit, Omise, Iyzico, Paymob, PayTabs, Tap, Thawani, Khalti, SSLCommerz, PayHere, Wompi, Toss Payments, YooKassa, CloudPayments, Tinkoff. Data: Shopper name, email, billing details, order amount. Location: Per provider. Transfer safeguard: Under the owner's contract with the provider. DPA / SCCs: Each provider's own terms (your contract with them).
  • Shipping carriers and label services the owner connects: Rates, labels and tracking: EasyPost, Shippo, ShipEngine, DHL, Aramex, CDEK, Envia, Melhor Envio, Shiprocket, Biteship. Data: Recipient name, address, phone, parcel details. Location: Per provider. Transfer safeguard: Under the owner's contract with the provider. DPA / SCCs: Each provider's own terms (your contract with them).
  • Sales channels and marketplaces the owner connects: Listing products and importing orders: Amazon, eBay, Etsy, Walmart, Mercado Libre, TikTok Shop, Meta (Facebook/Instagram shops and Conversions API), LinkedIn. Data: Product data; order and buyer details; hashed customer identifiers for conversion reporting when the owner enables it. Location: Per provider. Transfer safeguard: Under the owner's contract with the provider. DPA / SCCs: Each provider's own terms (your contract with them).
  • Business tools the owner connects: Accounting, tax, CRM, email marketing and travel booking: Xero, FreshBooks, TaxJar, HubSpot, ConvertKit (Kit), Duffel. Data: Invoices, customer contact details, order totals, booking details. Location: Per provider. Transfer safeguard: Under the owner's contract with the provider. DPA / SCCs: Each provider's own terms (your contract with them).

7. Assistance (Art. 28(3)(e) and (f))

Taking into account the nature of the processing, we help you respond to data-subject requests: the Studio lets you export, correct and delete a customer's data, and your shoppers can request their own export or erasure from your site (confirmed by email). We forward any request we receive directly to you without answering it ourselves. We also assist you with security (Art. 32), breach notification (Art. 33-34), data-protection impact assessments and prior consultation (Art. 35-36).

8. Personal data breaches

We notify you without undue delay, and in any case within 72 hours, after becoming aware of a personal data breach affecting Customer Personal Data, with what we know at that time: the nature of the breach, the categories and approximate numbers concerned, the likely consequences and the measures taken or proposed. We update you as we learn more. We also record every breach of security safeguards in our breach register (kept at least 24 months, PIPEDA s. 10.3 / Law 25 confidentiality-incident register) and help you notify the Office of the Privacy Commissioner of Canada, the CAI and individuals where there is a real risk of significant harm.

9. International transfers

Where Customer Personal Data is transferred outside the EEA, the UK or Switzerland to a country without an adequacy decision, the European Commission's Standard Contractual Clauses (Decision 2021/914) apply and are incorporated by reference: Module Two (controller to processor) between you and us, and Module Three (processor to processor) between us and our Sub-processors, with clause 7 (docking) included, clause 9(a) option 2 (general authorisation, 30 days' notice), clause 11 optional language excluded, and clauses 17 and 18 governed by the law and courts of Ireland (our own law is Canadian, not that of an EU member state). Transfers from the EU/EEA to us in Canada are covered by the Commission's adequacy decision for Canada (2002/2/EC), so the SCCs apply to onward transfers to Sub-processors in countries without adequacy. For UK transfers the UK International Data Transfer Addendum applies; for Swiss transfers the FADP replaces the GDPR references. Annex I is section 3, Annex II is section 5, Annex III is section 6.

10. Return and deletion (Art. 28(3)(g))

You can export your sites and data at any time. When you delete a site or your account, we delete Customer Personal Data from live systems after a short recovery grace period (30 days), and from encrypted backups as they age out of retention (at most 30 days later), unless EU or member-state law requires us to keep it.

11. Audits (Art. 28(3)(h))

We make available all information necessary to demonstrate compliance with Art. 28, including our security documentation and answers to your questionnaire. Where that is not sufficient, or a regulator requires it, we allow an audit or inspection by you or an independent auditor bound by confidentiality, once a year with 30 days' notice, during business hours and at your cost.

12. CCPA / CPRA service-provider terms

For personal information of California residents we act as your service provider. We do not sell or share it, do not retain, use or disclose it outside our direct business relationship with you or for any purpose other than providing the service, and do not combine it with personal information from other sources except as the CCPA permits. We comply with the CCPA, give the same level of protection it requires, notify you if we can no longer meet our obligations, and let you take reasonable steps to stop and remediate unauthorised use.

Who we are

xigzag is operated by Arad Soft Ltd., a company established in Ontario, Canada. Privacy officer (the person in charge of the protection of personal information): Privacy Officer, support@xigzag.com, privacy@xigzag.com; requests can also be made at /privacy/request. EU representative: [EU REPRESENTATIVE (Art. 27) OR "not required"]. UK representative: [UK REPRESENTATIVE OR "not required"]. General contact: hello@xigzag.com.

Change log

  • 2.1 (2026-10-04): Added PIPEDA and Law 25, Ireland as the SCC clause 17/18 law and forum, the Canada adequacy decision, the breach register, a DPA link for each sub-processor, /legal/subprocessors and the Health Data Addendum.
  • 2.0 (2026-10-04): Restructured around GDPR Art. 28(3) (a)–(h): instructions, confidentiality, Art. 32 security, sub-processor authorisation with 30 days' notice and objection, assistance, deletion, audits; added the sub-processor list, SCC modules, the UK addendum and CCPA service-provider terms.
  • 1.0 (2026-06-01): First published version.

For a material change we give at least 30 days' notice by email and in the Studio before it takes effect, except where a change is required by law or to address abuse or security.

Questions?

We're happy to talk it through.

Email hello@xigzag.com →