Skip to content

Legal

Data Processing Agreement

Effective date: 9 August 2026 Last updated: 9 August 2026

This Data Processing Agreement (the “DPA”) applies whenever Zappush (“we”, “our”, “us”) handles personal information on behalf of a customer (“you”, “your”) while providing the Zappush platform. It forms part of, and is incorporated by reference into, our Terms and Conditions. By accepting those Terms, or by using the platform, you accept this DPA. You do not need to sign anything separately.

This DPA covers information about your shoppers, customers, leads, and other individuals whose data you send us. It does not cover your own account information, which is covered by our Privacy Policy.

It also covers agreed implementation work to the extent we process Your Data on your behalf. The applicable Statement of Work sets out that service's scope.

If you need a countersigned copy for your records, or a negotiated version, write to [email protected] and we will sort it out.

1. Definitions

  • “Your Data” means personal information about your shoppers, customers, leads, or other individuals that you send to us, or that you authorise us to collect through the platform.
  • “Process” means anything we do with Your Data, including collecting, receiving, storing, organising, using, transmitting, and deleting it.
  • “Sub-processor” means a third party we engage to process Your Data on our behalf.
  • “Security Incident” means a breach of security leading to accidental or unlawful destruction, loss, alteration, unauthorised access to, or disclosure of, Your Data processed by us or our sub-processors.
  • “Data Protection Law” means the privacy and data protection law that applies to the processing, including the EU General Data Protection Regulation (“GDPR”), the UK GDPR and the UK Data Protection Act 2018, where applicable.
  • “Transfer Safeguard” means an adequacy decision, the EU Standard Contractual Clauses (“SCCs”), the UK Addendum or International Data Transfer Agreement, or another mechanism recognised under Data Protection Law for moving personal information across borders.
  • Terms used here and not defined have the meaning given to them in the Terms and Conditions or applicable Data Protection Law.

2. Roles and ownership

You decide what Your Data is collected, why it is collected, and where it is sent. You own it. Nothing in this DPA or in the Terms transfers ownership of Your Data to us, and we acquire no rights in it beyond those needed to provide the platform to you.

You act as the controller and we act as your processor. If you process data for another controller, you act as a processor and we act as your sub-processor. In that case, you confirm that you have authority to appoint us and give us instructions.

We process Your Data only to provide the platform to you and only on your instructions. Your instructions are given through the way you configure the platform, through this DPA and the Terms, and through any written request you send us. This includes instructions about international transfers. Annex C describes the processing covered by this DPA.

3. What we will do

We will:

  • Process Your Data only to provide, maintain, secure, and support the platform for you, and as otherwise instructed by you or required by law. If a law requires us to process Your Data in some other way, we will tell you before we do, unless that law forbids us from telling you. Any such processing remains subject to Data Protection Law and any applicable Transfer Safeguard.
  • Never sell Your Data, never share it with anyone for their own marketing, and never use it for any purpose of our own.
  • Keep Your Data confidential, and limit access to the personnel who need it to do their jobs, each of whom is under a duty of confidentiality that survives the end of their engagement with us.
  • Apply the security measures set out in Annex A, and not materially weaken them for as long as we hold Your Data.
  • Keep Your Data logically separated from every other customer's data.
  • Tell you without undue delay if we become aware of a Security Incident affecting Your Data, and give you the information you reasonably need in order to respond.
  • Help you respond to requests from individuals about their information, and to reasonable questions from a regulator or a platform partner.
  • Help you meet your security, breach-notification, data protection impact assessment and prior-consultation obligations, taking account of the processing and the information available to us.
  • Tell you immediately if, in our opinion, an instruction infringes Data Protection Law. We may pause the affected processing until the issue is resolved.
  • Delete Your Data as set out in clause 9 and in our Data Retention Policy.

Where our help with individual requests, regulator questions, impact assessments or transfer assessments goes beyond the self-service features of the platform, we may charge for it at our then-current rates.

Each party is responsible for its own compliance with Data Protection Law.

4. What you will do

You will:

  • Make sure you have the right to send us Your Data, and that you have given whatever notice and obtained whatever consent applies to the people it is about, wherever you operate.
  • Give the platform accurate instructions, including which events are captured, which destinations receive them, and which of your team have access.
  • Not send us information we do not need. The platform is not intended for government identifiers, payment card numbers, passwords, health records, or similarly sensitive categories of information, including event fields, URLs or purchase details that reveal them, unless we have expressly agreed to that processing in writing.
  • Keep your account credentials secure, and remove access for people who no longer need it.
  • Act as the point of contact for your own shoppers. They are your customers, not ours.

We will follow the consent and withdrawal signals supplied through the agreed integration and configuration. If we become aware of sensitive information we have not agreed to process, we will tell you and work with you to restrict and remove it. Neither your instructions nor this clause removes obligations the law places on us.

5. Sub-processors

You authorise us to engage the sub-processors listed in Annex B. Each one is engaged under written terms that are no less protective of Your Data than this DPA, and we remain responsible to you for what they do.

We may add or replace a sub-processor. When we do, we will update Annex B and give you at least 30 days' notice, by email or in the dashboard, before that sub-processor begins processing Your Data. If within that period you object on reasonable grounds relating to the protection of Your Data, we will work with you in good faith to find an alternative.

If no reasonable alternative is available, you may terminate the affected part of the service and we will refund any prepaid fees covering the unused remainder of the term.

We will provide relevant information and copies of sub-processor terms where required by Data Protection Law, with permitted redactions to protect unrelated confidential information.

6. Where we process Your Data

The standard platform runs on Google Cloud Platform infrastructure in the United States. Our team accesses it from India. Sub-processors process Your Data in the locations named alongside them in Annex B.

If we agree a dedicated hosting region, such as the EU, your order or hosting schedule will identify the regions and the customer data, processing, databases, logs and backups covered. That schedule takes priority over the standard hosting description in this DPA and our Security page. It will also identify any external-provider processing that remains outside that region.

Our team may still access a dedicated deployment from India for support, maintenance and security. Data sent to connected advertising platforms is also subject to those recipients' arrangements. A dedicated hosting region does not eliminate all international transfers.

You instruct us to process Your Data in the agreed locations, subject to the transfer safeguards in clause 13.

7. Security incidents

If we become aware of a Security Incident, we will notify you without undue delay. The notice will describe what we know, which of Your Data is affected as far as we can tell, and what we are doing about it. We will keep you updated as the picture becomes clearer, and we will not withhold information you need in order to meet your own obligations.

Where available, this includes the categories and approximate numbers of affected people and records, likely consequences, measures taken or proposed, and a contact for further information. We may provide details in stages without delaying the initial notice.

We will take reasonable steps to contain the incident and reduce its effects. Notifying you is not an admission of fault or liability on our part.

8. Requests from individuals

Where an individual contacts us directly about information we hold on your behalf, we will not deal with the substance of it ourselves unless authorised by you or required by law. We will tell them to contact you, and we will let you know without undue delay.

If you ask us to help find, correct, export, restrict or delete a specific individual's information, we will do it. Clause 3 applies to any charge for that assistance. Where your e-commerce platform sends us a deletion request on a shopper's behalf, we treat that as your instruction and act on it.

9. Deletion, export, and return

While your account is active, we keep Your Data so the platform works, subject to your instructions and Data Protection Law.

You may ask us at any time to export or delete any part of Your Data, whether that is one individual, a date range, a connected store, or all of it. Write to [email protected] from an address on your account. There is no charge, and deletion is permanent.

When your account closes, you may choose return of Your Data followed by deletion of our copies, or deletion without return. Unless you instruct otherwise, we keep Your Data for up to 120 days so you can reactivate or take an export, and then delete it from the live systems. If you want it gone sooner, ask us and we will do it.

Encrypted backups expire on the separate rolling 30-day cycle described in our Data Retention Policy. Pending expiry, deleted data in backups remains protected and is not used for normal processing. Deletion instructions are reapplied if a backup is restored. We will pass relevant instructions to our sub-processors and confirm completion where required.

Any longer retention must be permitted by Data Protection Law and any applicable Transfer Safeguard, and limited to the required purpose and period.

10. Information and audit

On reasonable written request, we will give you the information needed to demonstrate our compliance with this DPA and our applicable processor obligations. We will allow and contribute to audits, including inspections, by you or a qualified independent auditor you appoint.

Audits will normally take place no more than once in any twelve-month period. Additional audits are allowed where required by Data Protection Law, a Transfer Safeguard, a competent authority, a Security Incident or reasonable indications of non-compliance.

Please give at least six weeks' written notice and a proposed scope. We will agree arrangements that protect security and confidentiality and avoid unnecessary disruption. Shorter notice will apply where the circumstances or law require it. Relevant reports and other evidence can be used where they adequately address the review, without removing legally required audit rights.

Audits do not give unrestricted access to our systems, source code or another customer's data. Any necessary inspection will be subject to appropriate safeguards that do not prevent effective verification. Auditors must keep the information they receive confidential.

11. Liability and precedence

Each party's liability under this DPA is subject to the limitations and exclusions set out in the Terms and Conditions, to the extent permitted by law.

If this DPA and the Terms, Privacy Policy or Data Retention Policy conflict on how Your Data is processed on your behalf, this DPA prevails. If this DPA conflicts with a separate written agreement signed by both of us, that agreement prevails for the engagement it covers, subject to the following paragraph.

An applicable Transfer Safeguard prevails over conflicting terms in this DPA, the Terms or any separate agreement. Nothing in these agreements limits rights or obligations that Data Protection Law does not allow us to limit.

12. Term

This DPA applies for as long as we hold Your Data. The clauses on confidentiality, deletion, and liability survive its termination. An applicable Transfer Safeguard continues for as long as it requires.

We will give at least 30 days' notice of changes that materially affect your rights or obligations, in line with the Terms. Changes cannot reduce the protections required by Data Protection Law or an applicable Transfer Safeguard.

13. International transfers

Your Data may be processed outside the country where it was collected, in the locations described in clause 6 and Annex B. Where a transfer needs a Transfer Safeguard, we put the appropriate one in place with you before the transfer begins and record it in your order or processing record.

Where the EU Standard Contractual Clauses apply, Module Two applies when you are a controller and Module Three when you are a processor, you are the data exporter and we are the data importer, Annex B provides the sub-processor authorisation with 30 days' notice, Annex A provides the security measures, and Annex C provides the processing details. Governing law, courts and the competent supervisory authority under the SCCs are recorded in your processing record. The SCCs prevail over any conflicting term in this DPA, the Terms or a separate agreement.

We will give you the information you reasonably need to assess a transfer and cooperate on any additional safeguards. We will comply with the requirements of the applicable Transfer Safeguard for government requests, including notifying you where permitted. If we can no longer comply with a Transfer Safeguard, we will tell you promptly and take the steps it requires, including suspension and, where necessary, return or deletion of the affected data. Unless your order says otherwise, Zappush does not claim certification under the EU–US Data Privacy Framework.

Annex A: Security measures

Taking into account the state of the art, the costs of implementation, and the nature, scope, context and purposes of the processing, as well as the risks to individuals, we maintain technical and organisational measures appropriate to the risk, including the applicable requirements of GDPR Article 32. Our Security page describes our current measures in more detail and forms part of this annex. These include:

  • Encryption of Your Data in transit over public networks and at rest on the underlying storage.
  • Logical separation of each customer's data from every other customer's.
  • Access controls that grant access to Your Data on a need-to-know and least-privilege basis, using individual credentials, with access reviewed as roles change and removed promptly when no longer needed.
  • Credential and key management using managed secret and key services rather than storage in code or configuration.
  • Logging and monitoring of access to and activity on production systems, retained for a limited period for security investigation.
  • Change management procedures so that changes to production systems are reviewed, tested and approved before they ship.
  • Vulnerability management, including patching and monitoring for known threats and malicious code.
  • Incident management procedures to detect, investigate, contain and notify Security Incidents.
  • Encrypted backups and recovery procedures to maintain availability and restore the service after a failure.
  • Personnel measures, including confidentiality obligations and security awareness for staff with access to Your Data.
  • Secure disposal of systems and media so that Your Data cannot be recovered after deletion.

We may update these measures from time to time, provided that the overall level of protection for Your Data is not reduced. Hashing does not by itself make personal data anonymous.

Annex B: Sub-processors

The third parties who process Your Data on our behalf, what each of them does, and where each of them does it. The providers used depend on the features and integrations you enable.

  • Google Cloud Platform: hosting, databases, storage, encryption keys, logs and backups for the platform. Processed in: United States, or the regions specified in an agreed EU-hosting schedule for the covered services.
  • Cloudflare: content delivery, script caching and DNS in front of our services. Browser requests may include IP addresses and request metadata. Processed in: United States and global edge network.
  • IPLocate: resolving an IP address to an approximate location. It receives the IP address without accompanying shopper names, email addresses or order information. Processed in: Australia, with servers in Europe, the United States, Singapore and Australia.

Sub-processor list last updated: 9 August 2026

A provider is a sub-processor under this DPA only to the extent it processes Your Data on our behalf. Activities involving only our own website visitors, account holders or billing are covered by the relevant privacy terms. We will identify the applicable provider legal entities, processing details and transfer safeguards for your service on request.

Advertising platforms that you choose to connect, such as Meta, receive data on your instruction as independent recipients. Their handling of that data is governed by your agreement with them, subject to the transfer requirements in clause 13.

Annex C: Processing and transfer details

Parties

Customer / data exporter: the legal entity and registered address identified in your order or account records. Your role is controller or processor, as described in clause 2. Your relevant activity is operating the connected stores or services, or processing their data for the identified controller.

Zappush / data importer: the Zappush entity named in your order or account records or, if none is named, Zappush LLP at the address in the Contact section. Our role is processor or sub-processor. Our relevant activity is providing and supporting the Zappush platform on your instructions.

Registration numbers, privacy contacts and any data protection officer or representative are recorded in the order or processing record, together with the date this DPA was accepted.

Processing

ItemDetails
Subject matter and purposeProviding the selected Zappush customer data platform, tracking, attribution, reporting, segmentation and customer-directed activation services, including their maintenance, security and support.
IndividualsVisitors, shoppers, customers, leads and other individuals whose data you lawfully supply for the agreed service.
DataNames and contact details; customer and online identifiers; IP addresses; browser, device and approximate location information; consent signals; website and product interactions; cart, checkout, order and refund details; attribution, profile and segment information; and other agreed customer attributes needed for the selected service.
Sensitive dataNot intended for the standard service, including event fields that reveal health or other special-category information, unless expressly agreed in writing. Clause 4 applies.
OperationsCollection, receipt, storage, organisation, matching, analysis, hashing, reporting, customer-directed transmission, support, export, correction and deletion.
FrequencyContinuous or recurring event processing, with periodic synchronisation, uploads and support access as needed.
Duration and retentionFor the service term and the limited return, deletion and lawful retention periods in clause 9. Operational logs are kept for up to 30 days under the Data Retention Policy. Agreed shorter periods and overriding legal requirements apply.
LocationsGoogle Cloud Platform infrastructure in the United States for the standard infrastructure; India for staff access; any agreed dedicated hosting regions; and the applicable external-provider locations in Annex B.
Sub-processor scopeThe specific functions listed in Annex B, for the service duration and any permitted return or deletion period.

The order or processing record identifies any material differences for your deployment, including enabled providers, retention settings and EU-hosted components.

Supervisory authority

The competent supervisory authority for any applicable Transfer Safeguard is recorded in your processing record.

Contact

Questions about this DPA, or a request for a countersigned or negotiated copy:

Zappush LLP Desk No. WSA43, First Floor, B128, B Block, Sector 2, Noida Uttar Pradesh 201301, India Email: [email protected]