Data protection
Data Processing Schedule
The processing arrangements, safeguards and responsibilities that apply when NewZapp handles personal data on your behalf.
1. Application and interpretation
1.1. This Data Processing Schedule forms part of the Agreement between DestiNet Limited trading as NewZapp Communications (company number 3679291) and the customer identified in the Order Form. Defined terms have the meanings given in the Terms and Conditions.
1.2. This Schedule applies to Customer Personal Data processed by us on your behalf when providing the Services. You are the Controller and we are the Processor. Where you act as a Processor for another Controller, you must be authorised to appoint us as a sub-processor and to give the instructions contemplated by this Schedule.
1.3. Each party will comply with the Data Protection Legislation applicable to it. Your rights and responsibilities include determining the purposes of processing, selecting the data supplied and features used, providing lawful instructions, and obtaining the permissions and providing the privacy information necessary for that processing.
1.4. This Schedule takes precedence over conflicting provisions concerning the processing or protection of Customer Personal Data. Section 15 of the Terms and Conditions continues to govern contractual liability between the parties, including claims under this Schedule, subject to liabilities that cannot lawfully be limited. This Schedule creates no separate indemnity or increased liability cap. Mandatory international-transfer provisions prevail where applicable.
1.5. This Schedule continues for as long as we or our sub-processors retain Customer Personal Data, including backup copies.
2. Processing particulars
| Particular | Agreed scope |
|---|---|
| Subject matter | Processing personal data to provide the NewZapp communications platform and associated support under the Order Form. |
| Duration | The Licence Period and the limited return, retention and deletion periods in section 10 of this Schedule. |
| Purpose | Managing contacts and audiences; creating and distributing communications; measuring engagement where enabled; maintaining delivery and preference records; providing reports, exports, account access and support. |
| Activities | Collection and import; recording, organisation and storage; segmentation; retrieval and display; distribution to intended recipients; recording delivery, bounce, preference and engagement events; reporting and export; support investigation; backup, restoration and deletion. Only activities relevant to the Services purchased and your instructions apply. |
| Data subjects | Your employees, workers, contractors, volunteers, members, subscribers, customers, prospective customers and other intended recipients, together with authorised platform users, as relevant to your use. |
| Contact data | Email addresses and optional information you supply, such as names, roles, departments, locations, identifiers, group membership and communication preferences. |
| Content | Personal data contained in communications, uploaded images and files, and other Content you choose to process through the Services. |
| Delivery and engagement data | Recipient and campaign identifiers, delivery and bounce information, unsubscribe and preference records; where tracking is enabled, opens, clicks, dates and times, and supported viewing-duration indicators. Requests may include IP addresses, user-agent and referrer details where supplied. An IP address may identify a proxy or security service rather than a recipient's device or location. |
| Platform-user data | Names, email addresses, account identifiers, assigned permissions and authentication or access information needed to provide authorised access. Authentication data is processed separately from recipient data as described in Appendix 2. |
| Frequency | Throughout use of the Services, according to your instructions and campaign activity. |
2.1. NewZapp is intended for internal communications and external marketing. You must ensure that personal data submitted to the Services is appropriate for those purposes and that the safeguards described in this Schedule meet the requirements of your intended processing. NewZapp is not designed for use as a patient-record or offender-record management system.
2.2. Disabling Campaign tracking prevents recording of open and click engagement for that campaign. Links may still pass through NewZapp to resolve their destination, but the associated engagement-tracking information is discarded. Delivery and bounce reporting continue. Necessary security processing remains subject to this Schedule and applicable law.
2.3. Your instructions may involve delivery to recipients, exports or integrations outside our hosting environment. Recipient mail systems, devices and systems you independently appoint are not brought within our hosting-location commitment simply because they receive data from NewZapp. Any restricted transfer made by us remains subject to section 9.
3. Instructions and permitted use
3.1. We will process Customer Personal Data only on your documented instructions, including this Agreement, configuration choices and instructions submitted by authorised users, and subsequent instructions agreed in writing. Instructions include those concerning disclosure and international transfers.
3.2. If applicable UK law requires other processing, we will inform you of that requirement before processing unless prohibited by law.
3.3. We will immediately inform you if, in our opinion, an instruction infringes Data Protection Legislation. We may suspend the affected processing while the issue is resolved, limiting that suspension to what is necessary.
3.4. We will not sell Customer Personal Data, use it for our own marketing, or use it to train general-purpose AI models. Processing outside the agreed purposes requires a separate lawful arrangement and, where we act as Processor, your documented instructions.
3.5. This Schedule does not govern separate processing for which we act as an independent Controller, such as administering our customer relationship and invoices or complying with our own legal obligations. Such processing must have its own lawful basis and appropriate privacy information; it does not authorise reuse of your recipient lists or campaign data for unrelated purposes.
4. Confidentiality and security
4.1. We will ensure that people authorised to process Customer Personal Data are subject to binding confidentiality obligations and receive training appropriate to their responsibilities. Access will be limited to what is reasonably required for their authorised duties.
4.2. We will implement and maintain technical and organisational measures appropriate to the processing risks and the requirements of Article 32 of the UK GDPR, including the measures in Appendix 1. These will address confidentiality, integrity, availability and resilience, recovery following incidents, and regular assessment of control effectiveness.
4.3. We may update those measures as technology and risks change, provided the changes do not materially reduce the overall protection of Customer Personal Data during the Licence Period. Material changes to processing locations or sub-processors are subject to sections 8 and 9.
4.4. You are responsible for security within your control, including user permissions, your identity-provider policies, your devices and systems, and downloaded or exported data. This does not reduce our responsibility for the security of our own processing.
5. Personal Data Breaches
5.1. We will notify you without undue delay after becoming aware of a Personal Data Breach affecting Customer Personal Data. This obligation is not limited to support hours or the issue classifications in the SLA. We will not delay an initial notification until an investigation is complete.
5.2. As information becomes available, we will provide the nature of the breach; the categories and approximate numbers of affected individuals and records, where known; likely consequences; the measures taken or proposed to contain and remedy it; and a contact for further information. Information may be supplied in stages without undue further delay.
5.3. We will take reasonable steps to contain, investigate and remedy the breach, preserve relevant evidence, and assist you with your applicable notification obligations. We will cooperate with your reasonably appointed incident advisers, subject to appropriate confidentiality and security arrangements.
5.4. You remain responsible for deciding whether to notify regulators or individuals in your capacity as Controller. We will not make such notifications on your behalf without your instructions unless required by law.
5.5. We will use the data-protection or incident contact you designate in writing, or otherwise the principal customer contact in the Order Form. You must keep those details current. A breach notification is not an admission of liability.
6. Individual rights and regulatory assistance
6.1. Taking account of the nature of the processing, we will provide appropriate technical and organisational assistance to help you respond to individuals exercising their rights under Data Protection Legislation. This includes relevant access, correction, deletion, restriction, objection and portability requests.
6.2. If we receive a request concerning Customer Personal Data directly from an individual, we will refer it to you without undue delay and will not respond substantively except on your instructions or where legally required.
6.3. You should first use the relevant platform facilities where these meet the request. Where further assistance is needed, we will respond without undue delay and in sufficient time to support your applicable legal deadline, taking account of when you notify us and the information reasonably needed to act. We will promptly identify any difficulty affecting that timing.
6.4. Taking account of the processing and information available to us, we will assist you with security obligations, breach notifications, relevant DPIAs and any required prior consultation with the ICO or other competent authority. You remain responsible for your assessment and decisions as Controller.
6.5. Standard documentation, existing platform facilities and assistance needed because of our breach of this Agreement will not attract additional charges. Bespoke assistance requiring material additional work is chargeable at our prevailing professional services daily rate. We will notify you of the applicable rate, estimated time and scope, and obtain your written agreement before undertaking chargeable work. No minimum one-day charge is implied unless expressly agreed. A discussion about charges will not delay assistance that we are legally required to provide within an applicable deadline.
7. Assurance, audits and inspections
7.1. We will make available the information necessary to demonstrate compliance with our Article 28 obligations and allow and contribute to audits and inspections by you or an auditor you appoint.
7.2. Routine assurance should begin with relevant certification, its scope, our applicable control information, this Schedule and available audit or security summaries. Where that evidence is insufficient, you may request a focused audit of the remaining matters relevant to Customer Personal Data.
7.3. For routine audits requested by you, you must normally give us at least 20 working days' written notice. Such audits will normally be conducted during business hours and no more than once in a 12-month period. These arrangements do not restrict additional or more urgent audits reasonably required following a Personal Data Breach, credible evidence of material non-compliance, or a legal or regulatory requirement.
7.4. The notice requirement above applies to customer-requested audits, not to our own internal reviews, certification audits or routine documentation updates. We will review our security documentation at least annually and notify customers of relevant material changes within a reasonable timeframe where appropriate or required. Any specific notification requirements elsewhere in the Agreement continue to apply.
7.5. Audits must have a defined scope, use suitably qualified people bound by confidentiality, and minimise disruption and risks to other customers. We may provide redacted documents, supervised access or equivalent evidence where necessary to protect unrelated customer data, privileged material, commercial confidentiality or security-sensitive information, provided this does not prevent effective verification of our compliance.
7.6. This Schedule does not grant unrestricted access to production systems or authorise active vulnerability scanning, exploitation or penetration testing. Any such testing requires a separately agreed written scope and safe testing arrangements. This does not limit lawful regulatory powers or our obligation to permit an effective audit.
7.7. You will bear your auditor's costs. Substantial additional assistance is chargeable on the basis set out in clause 6.5. Any charges must be reasonable and must not make your audit rights ineffective. We will not charge for assistance necessary to investigate or remedy our material non-compliance.
8. Sub-processors
8.1. You give general written authorisation for us to engage sub-processors to provide the Services, subject to this section. The authorised register at the date of the Agreement is in Appendix 2.
8.2. Before appointing a sub-processor, we will assess whether it provides sufficient data-protection and security guarantees and enter into a written agreement imposing the applicable data-protection obligations required by Article 28, with protection equivalent to this Schedule. We remain responsible to you for its performance of those obligations.
8.3. We will give you at least 30 days' advance written notice of intended additions or replacements of sub-processors that will process Customer Personal Data on our behalf, identifying their function, relevant data and processing locations. You may raise a documented objection on reasonable data-protection grounds during that notice period, before the proposed processing begins.
8.4. We will assess a timely objection in good faith, provide a reasoned response and seek to address any substantiated data-protection concern through appropriate safeguards or another reasonable arrangement. A preference for a different provider, without a substantiated data-protection concern, does not entitle you to dictate our supplier choices. We will not proceed with affected processing where doing so would breach Data Protection Legislation or our obligations under this Agreement. This section does not create a separate right to terminate or receive a refund merely because a sub-processor changes or you object to that change. Rights and remedies otherwise available under this Agreement or applicable law remain unaffected.
8.5. Your independently appointed identity providers, recipient mail providers and customer-selected systems are not our sub-processors merely because you instruct us to exchange data with them. Providers we appoint to process Customer Personal Data on our behalf remain subject to this section.
9. Locations and international transfers
9.1. The core NewZapp platform, including contact data, campaign Content, engagement records, uploaded files and platform backups, is hosted in the United Kingdom. The platform database is hosted in AWS’s London region. Platform-user authentication data is hosted separately through Auth0 in EU data centres in Dublin, Ireland and Frankfurt, Germany. Limited processing through support and campaign-testing providers is described separately in Appendix 2; the UK platform-hosting commitment does not extend to those services.
9.2. NewZapp staff with access to Customer Personal Data are based in the UK, and NewZapp does not give contractors access to that data. Supplier personnel and onward processing are governed by the relevant supplier arrangements and this section. Hosting location does not itself establish where every supplier access occurs. Recipient systems, customer devices and customer-appointed systems may be located elsewhere.
9.3. We will make a restricted international transfer only on your documented instructions and where permitted by Data Protection Legislation, using a valid adequacy basis or appropriate safeguards, required transfer assessments and supplementary measures. We will make relevant information about the transfer basis available to you on request.
9.4. A change that moves hosting outside the UK for core platform data, or outside the EU for authentication data, requires your prior written agreement. Changes within those commitments remain subject to the sub-processor notification and objection procedure where applicable. If an existing transfer basis ceases to be valid, we will establish a lawful alternative or suspend the affected transfer.
10. Return, retention and deletion
10.1. During an active licence, Customer Personal Data is retained to provide the Services, subject to your instructions and available deletion facilities. Engagement history is retained for the customer relationship unless deleted in accordance with your instructions. Expiry or termination ends platform access as set out in section 11 of the Terms and Conditions.
10.2. At the end of the Services, you may choose return or deletion of Customer Personal Data. You should submit a return request before expiry or promptly afterwards, and in any event before the 30-day account-deletion date. We will provide the standard return without charge in a commonly used electronic format using an appropriately secure delivery method. This includes contacts, associated contact fields and recipient engagement records. Support can arrange return after platform access ends; reactivation of the licence is not required. Requests for other Customer Personal Data will be handled in accordance with this Schedule.
10.3. Following expiry or termination, account data is retained only for agreed return arrangements, renewal administration where requested, and necessary protection and deletion activities. Our standard process deletes your account, Content and Customer Personal Data at the end of 30 days from the effective date of expiry or termination. An instruction to delete is implemented through that process; it does not trigger earlier account deletion. If you give no return instruction, deletion is the agreed default instruction.
10.4. Where you request return in time, we will complete it before scheduled deletion. We may, at our discretion, allow a limited extension to the retention period to facilitate return. If an extension is necessary because we cannot complete a timely request before scheduled deletion, we will preserve the relevant data until that return is completed and notify you of the revised deletion date. Retention does not provide platform access or create a renewal. We will delete remaining copies through the agreed deletion process unless applicable UK law requires storage.
10.5. Core platform production data is backed up at least daily and backups are retained for 30 days, in accordance with the SLA. The maximum Recovery Point Objective under the SLA is 24 hours. Residual backup copies expire through those cycles after deletion from live systems. They remain protected and beyond ordinary use, with access limited to necessary recovery, security or legal purposes. Our recovery process includes transaction-log recovery where applicable and review of deletion instructions, so that relevant deletions are preserved or reapplied before restored data is returned to ordinary use. This does not create a zero-data-loss recovery guarantee.
10.6. Account deletion automatically deletes the associated platform-user records from Auth0. Deletion and return obligations also apply to other sub-processors processing Customer Personal Data on our behalf. Residual supplier logs and backups remain subject to the applicable retention arrangements, protection against ordinary use and eventual deletion. Distinct arrangements are recorded in Appendix 2; a continuing supplier subscription does not permit us to retain your Customer Personal Data indefinitely.
10.7. Where UK law requires continued retention, we will retain only the necessary data, restrict its use to that requirement and delete it when the requirement ends. On request, we will confirm completion of deletion, identifying any residual backup or legally required retention still applicable.
10.8. Recipient personal data in support ticket text is redacted or removed once the support issue is resolved and the ticket is closed. Screenshots and attachments containing recipient personal data are deleted at that point. Recipient data supplied through Microsoft 365 for support is deleted from active support records immediately after assistance is completed; support emails are also removed from Deleted Items. Residual recoverable copies and backups remain subject to the relevant supplier retention arrangements. We may retain the remaining support history for our customer relationship, subject to clause 3.5, an appropriate lawful basis and retention review; this does not authorise retention of recipient data for that purpose.
11. Contacts and changes
11.1. Data-protection requests may be sent to support@newzapp.com for referral to the responsible person. Urgent security concerns outside normal support hours should also be sent to urgent@newzapp.com in accordance with the SLA. Your designated privacy and incident contacts are those notified under clause 5.5.
11.2. This Schedule is incorporated into the Agreement and does not require a separate signature. Changes must be made in accordance with the Agreement, except for changes expressly permitted by this Schedule. The processing particulars must be updated by written agreement if the intended processing materially changes.
Appendix 1 — Technical and organisational measures
| Area | Measures and commitments |
|---|---|
| Governance | An information-security management system certified to ISO/IEC 27001:2022 within its certified scope; documented responsibilities, risk assessment and control review. Certification information is available as part of the assurance process. |
| Confidentiality and access | UK-based NewZapp staff, authorised access according to duties, confidentiality obligations and appropriate training. No contractor access to Customer Personal Data. Customer administrators manage invited users and available roles and permissions. |
| Platform sign-in | Invited users only. Microsoft or Okta sign-in where configured. Password sign-in requires an email one-time passcode as MFA; users may choose to trust a device for 30 days. Customer identity-provider policies apply to federated sign-in. |
| Web connections | Platform access, uploads, downloads and recipient tracking requests use encrypted HTTPS/TLS connections. |
| Email transport | STARTTLS is used to negotiate encrypted SMTP transport where supported by the receiving server. Encryption of every delivery connection is not guaranteed; recipient systems may not support TLS. |
| Encryption at rest | Production databases, uploaded files and database and storage backups are encrypted at rest. |
| Hosting | UK hosting for core platform data and backups; EU hosting for authentication. Support and external-campaign testing involve the separate providers and locations in Appendix 2. |
| Backup and recovery | Daily production data backups retained for 30 days, with a maximum Recovery Point Objective of 24 hours under the SLA. Documented recovery procedures and periodic assessment of restoration capability. Service recovery targets remain in the applicable SLA. |
| System protection | Risk-based network access restrictions, vulnerability identification and remediation, security logging and monitoring, and controlled changes to production systems. Detailed configurations and tools are not incorporated into this Schedule. |
| Incident management | Procedures for identifying, assessing, containing and investigating incidents, escalating them to responsible personnel and making the notifications in section 5. |
| Supplier assurance | Assessment of sub-processors, binding data-protection terms, and review of relevant supplier assurance. |
| Deletion | Controlled deletion of account data and expiry of residual backups, including handling of restored backups, as described in section 10. |
Appendix 2 — Sub-processor and location register
The following providers process Customer Personal Data on our behalf for the purposes described below.
| Provider and purpose | Data and hosting | Retention and processing arrangements |
|---|---|---|
| Amazon Web Services EMEA SARL — Core platform infrastructure, database, file storage and backups. | Contact data, campaigns, engagement records and uploaded files. Core hosting in the UK; database in London. | Platform retention and recovery follow section 10. AWS’s DPA includes UK transfer safeguards. AWS publishes service-specific onward processors and overseas support locations. Its customer-initiated support entities process customer content only where the customer agrees to share it for support. |
| Okta, Inc. (Auth0) — Platform-user authentication. | User identifiers, authentication profile and associated authentication/access records; no recipient lists supplied for this purpose. Primary authentication hosting: Dublin and Frankfurt. Auth0’s published onward-processing arrangements include US-based supporting services and global CDN processing; EU hosting is not a promise of EU-only processing. | User records are deleted automatically on account deletion. Tenant logs are retained for five days within Auth0 and are not exported. Residual backups remain protected until deletion through Okta’s normal backup cycle under its Information Security Addendum. |
| HubSpot UK Holdings Limited — Support ticket handling; recipient data only where supplied during support. | Recipient identifiers, screenshots or attachments that customers include in tickets. No customer contact-list hosting. Account hosting: EU, Germany. HubSpot’s DPA permits supporting processing outside the EU, including in the USA, subject to its transfer provisions. | Remove or redact recipient data from ticket text and delete screenshots or attachments containing it when the resolved ticket closes. Remaining support history may be retained separately under clause 3.5. HubSpot publishes a 30-day backup cycle. Files deleted through its Files tool can remain recoverable for 30 days unless permanently deleted sooner. These are distinct retention stages, not a promise that every copy is erased within 30 days of ticket closure. |
| Microsoft Ireland Operations Limited (Microsoft 365) — Support communications and temporary handling of customer-supplied data. | Support emails and files where supplied. Tenant-reported current geography: Exchange Online and Exchange Online Protection — Europe; Teams, OneDrive and SharePoint — United Kingdom. The future UK commitment for Exchange is not its current location. | Delete recipient data from active support records immediately after helping, including removal of support emails from Deleted Items. Purchased directly from Microsoft; default retention settings, with no custom retention policies, legal holds or separate backups, as confirmed by NewZapp. Exchange Online retains permanently deleted items in Recoverable Items for 14 days by default. SharePoint’s default recycle-bin period is 93 days, followed by up to 14 further days of backup retention after actual deletion. Microsoft Ireland Operations Limited is the service-contracting entity under the applicable Microsoft Customer Agreement and incorporated Data Protection Addendum. |
| MAIL TESTER LLC (mail-tester.com) — Paid API spam testing for external-publication campaigns only. Disabled for internal communications. | Generic test message sent to a dedicated testing address, without contact merge data or recipient-specific tracking. Campaign text may nevertheless contain personal data. Hosting country has not been verified. | Published paid-service result availability is 30 days; that does not establish complete log or backup deletion. Supplier assessment exists. A Data Processing Agreement has been requested and the provider’s response is pending. Hosting/access locations, onward processors, transfer basis and complete retention/deletion arrangements also remain to be established. |
Support and testing providers process Customer Personal Data only where the relevant support interaction or feature involves it. Supplier hosting regions do not exclude international support access or onward processing; any such processing remains subject to section 9. Mail Tester is not used for internal-communications campaigns.
Supplier processing and transfer terms
The following sources describe supplier safeguards and onward processing. They do not replace NewZapp’s commitments in sections 8 and 9. Only arrangements relevant to the services used apply; a supplier’s list may also cover optional features that NewZapp does not use.
- AWS: AWS DPA and UK GDPR Addendum; onward processors and support locations. The UK addendum incorporates the relevant UK transfer provisions.
- Auth0 / Okta: Data Processing Addendum, including standard contractual clauses and the UK Addendum; Auth0 onward-processing register; Information Security Addendum for residual backup protection and deletion.
- HubSpot: DPA, including standard contractual clauses, the UK Addendum and applicable Data Privacy Framework provisions; onward-processing register.
- Microsoft: Products and Services DPA. Its international-transfer provisions use standard contractual clauses and the UK international data transfer addendum. Supplier access and onward processing remain subject to that DPA.