Data Processing Addendum
The processor commitments that apply when Sagaris handles customer-controlled personal data inside the ROS platform.
Last updated July 5, 2026
How this addendum applies
This Data Processing Addendum (DPA) supplements the Sagaris Terms of Service and applies when Sagaris processes Customer Personal Data on behalf of a customer using the Sagaris ROS platform.
For Customer Personal Data, the customer is the controller or business that determines the purposes and means of processing, and Sagaris acts as processor or service provider. Sagaris processes that data only to provide, secure, support, and improve the service according to the customer's documented instructions.
Subject matter, duration, and purpose
The subject matter is the hosting and operation of Sagaris ROS: CRM records, outbound sequences, email and call activity, SMS and voice workflows, AI-assisted drafts and summaries, integrations, compliance logs, and related operational telemetry.
Processing lasts for the term of the customer's workspace or written agreement, plus any retention period required for security, billing, legal compliance, backup integrity, or documented customer instructions.
- Categories of data subjects may include the customer's users, prospects, leads, contacts, customers, and people who communicate with them.
- Categories of personal data may include names, business contact details, job information, CRM notes, communication content and metadata, call recordings or transcripts when enabled, consent and suppression records, audit events, and integration identifiers.
- Sensitive data should not be uploaded unless the customer has a lawful basis and the feature has been explicitly configured for that use.
Customer instructions and lawful use
The customer instructs Sagaris to process Customer Personal Data as needed to provide the service, comply with the Terms, perform support and security work, and follow written configuration or support instructions from authorized workspace administrators.
Sagaris will promptly inform the customer if an instruction appears to violate applicable data protection law, unless legally prohibited from doing so. The customer remains responsible for the lawfulness of its data sources, outreach, and use of the service.
Personnel and confidentiality
Sagaris restricts access to Customer Personal Data to personnel and contractors who need it to operate, secure, support, or improve the service. Those personnel are bound by confidentiality obligations and receive access appropriate to their role.
Workspace isolation, role-based application authorization, audit logging, and fail-closed authentication controls are part of the platform design and are described further on the Trust & Security page.
Security measures
Sagaris maintains technical and organizational measures designed to protect Customer Personal Data against unauthorized access, loss, misuse, alteration, or disclosure.
- Google Identity Platform authentication with secure session cookies and company-email confirmation codes.
- TLS in transit, GCP-managed encryption at rest, and additional AES-256-GCM application-layer encryption for high-value OAuth tokens.
- Workspace-scoped authorization, row-level access policies where applicable, and server-side route checks for workspace data access.
- Structured logging, audit trails for high-risk actions, webhook signature verification, outbound consent guardrails, and production incident response procedures.
- Backups, restore procedures, retention controls, and deploy rollback procedures documented in the public trust and runbook materials.
Subprocessors and third-party services
Sagaris may use subprocessors to provide hosting, infrastructure, AI processing, messaging, billing, analytics, and customer-selected integrations. Examples include Google Cloud Platform, Vertex AI Gemini, Stripe, PostHog, communications providers, and CRM or mailbox integrations the customer connects.
Sagaris remains responsible for subprocessors it appoints for service delivery and will require materially similar data protection obligations from them. Customer-enabled integrations process data under the customer's relationship with those third-party providers.
International transfers
Sagaris is operated from the United States and stores the platform in the United States by default. Customer Personal Data may be processed in the United States and in countries where Sagaris or its subprocessors operate.
Where transfer safeguards are required, Sagaris will support appropriate contractual transfer mechanisms through the customer agreement or a mutually executed addendum.
Data subject requests and compliance assistance
Taking into account the nature of the processing and the information available to Sagaris, Sagaris will assist customers with data subject access, correction, deletion, export, objection, and restriction requests.
The platform includes GDPR erasure support, hashed suppression records to prevent silent re-import, contact-aware export audit logs, DSAR activity tracking, and a dedicated subject-access export path for customer-controlled records.
Security incidents
Sagaris will notify affected customers without undue delay after confirming a security incident that compromises Customer Personal Data. The notice will include available information about the nature of the incident, affected data, mitigation steps, and points of contact.
Customers are responsible for determining whether notifications to regulators, data subjects, or other third parties are required for their processing activities. Sagaris will provide reasonable assistance based on the information available.
Return, deletion, and audit information
At the end of the service relationship, Sagaris will return, export, delete, or anonymize Customer Personal Data according to the customer's instructions and the retention limits in the Privacy Policy, unless law or legitimate security and compliance needs require retention.
Sagaris will make reasonable information available to demonstrate compliance with this DPA, including trust materials, subprocessor information, audit logs, incident documentation, and written answers to security review questions.
Questions about this DPA or requests for an executed copy can be sent to support@sagaris.ai.