Data Processing Addendum

The processor commitments that apply when Sagaris handles customer-controlled personal data inside the ROS platform.

Last updated July 5, 2026

01Scope

How this addendum applies

This Data Processing Addendum (DPA) supplements the Sagaris Terms of Service and applies when Sagaris processes Customer Personal Data on behalf of a customer using the Sagaris ROS platform.

For Customer Personal Data, the customer is the controller or business that determines the purposes and means of processing, and Sagaris acts as processor or service provider. Sagaris processes that data only to provide, secure, support, and improve the service according to the customer's documented instructions.

02Processing

Subject matter, duration, and purpose

The subject matter is the hosting and operation of Sagaris ROS: CRM records, outbound sequences, email and call activity, SMS and voice workflows, AI-assisted drafts and summaries, integrations, compliance logs, and related operational telemetry.

Processing lasts for the term of the customer's workspace or written agreement, plus any retention period required for security, billing, legal compliance, backup integrity, or documented customer instructions.

  • Categories of data subjects may include the customer's users, prospects, leads, contacts, customers, and people who communicate with them.
  • Categories of personal data may include names, business contact details, job information, CRM notes, communication content and metadata, call recordings or transcripts when enabled, consent and suppression records, audit events, and integration identifiers.
  • Sensitive data should not be uploaded unless the customer has a lawful basis and the feature has been explicitly configured for that use.
03Instructions

Customer instructions and lawful use

The customer instructs Sagaris to process Customer Personal Data as needed to provide the service, comply with the Terms, perform support and security work, and follow written configuration or support instructions from authorized workspace administrators.

Sagaris will promptly inform the customer if an instruction appears to violate applicable data protection law, unless legally prohibited from doing so. The customer remains responsible for the lawfulness of its data sources, outreach, and use of the service.

04Confidentiality

Personnel and confidentiality

Sagaris restricts access to Customer Personal Data to personnel and contractors who need it to operate, secure, support, or improve the service. Those personnel are bound by confidentiality obligations and receive access appropriate to their role.

Workspace isolation, role-based application authorization, audit logging, and fail-closed authentication controls are part of the platform design and are described further on the Trust & Security page.

05Security

Security measures

Sagaris maintains technical and organizational measures designed to protect Customer Personal Data against unauthorized access, loss, misuse, alteration, or disclosure.

  • Google Identity Platform authentication with secure session cookies and company-email confirmation codes.
  • TLS in transit, GCP-managed encryption at rest, and additional AES-256-GCM application-layer encryption for high-value OAuth tokens.
  • Workspace-scoped authorization, row-level access policies where applicable, and server-side route checks for workspace data access.
  • Structured logging, audit trails for high-risk actions, webhook signature verification, outbound consent guardrails, and production incident response procedures.
  • Backups, restore procedures, retention controls, and deploy rollback procedures documented in the public trust and runbook materials.
06Subprocessors

Subprocessors and third-party services

Sagaris may use subprocessors to provide hosting, infrastructure, AI processing, messaging, billing, analytics, and customer-selected integrations. Examples include Google Cloud Platform, Vertex AI Gemini, Stripe, PostHog, communications providers, and CRM or mailbox integrations the customer connects.

Sagaris remains responsible for subprocessors it appoints for service delivery and will require materially similar data protection obligations from them. Customer-enabled integrations process data under the customer's relationship with those third-party providers.

07Transfers

International transfers

Sagaris is operated from the United States and stores the platform in the United States by default. Customer Personal Data may be processed in the United States and in countries where Sagaris or its subprocessors operate.

Where transfer safeguards are required, Sagaris will support appropriate contractual transfer mechanisms through the customer agreement or a mutually executed addendum.

08Assistance

Data subject requests and compliance assistance

Taking into account the nature of the processing and the information available to Sagaris, Sagaris will assist customers with data subject access, correction, deletion, export, objection, and restriction requests.

The platform includes GDPR erasure support, hashed suppression records to prevent silent re-import, contact-aware export audit logs, DSAR activity tracking, and a dedicated subject-access export path for customer-controlled records.

09Incidents

Security incidents

Sagaris will notify affected customers without undue delay after confirming a security incident that compromises Customer Personal Data. The notice will include available information about the nature of the incident, affected data, mitigation steps, and points of contact.

Customers are responsible for determining whether notifications to regulators, data subjects, or other third parties are required for their processing activities. Sagaris will provide reasonable assistance based on the information available.

10Deletion

Return, deletion, and audit information

At the end of the service relationship, Sagaris will return, export, delete, or anonymize Customer Personal Data according to the customer's instructions and the retention limits in the Privacy Policy, unless law or legitimate security and compliance needs require retention.

Sagaris will make reasonable information available to demonstrate compliance with this DPA, including trust materials, subprocessor information, audit logs, incident documentation, and written answers to security review questions.

Questions about this DPA or requests for an executed copy can be sent to support@sagaris.ai.

Sagaris

DPA requests: support@sagaris.ai