Calmer Days Ahead Terms
Data Processing Agreement

Their data, in your workspace,
handled properly.

The formal agreement covering how we process personal data on your behalf — clearly, and in writing.

Effective 9 July 2026 · Version 1.0 · Forms part of our Terms of Service — no signature needed

01Roles and scope

In short: for the data you put in your Workspace, you're the controller. We're your processor, and we only act on your instructions.

This DPA forms part of the Terms of Service between We Are Zacapa Ltd ("Zacapa", "we") and the Customer ("you"). It applies to personal data submitted to the Service by you, your Team Members and Portal Users ("Customer Personal Data") and takes effect automatically when you accept the Terms of Service.

For Customer Personal Data, you are the controller and Zacapa is the processor. Processing details are in Annex 1. "UK GDPR", "controller", "processor", "personal data", "processing" and "data subject" carry the meanings in UK data protection law (UK GDPR and the Data Protection Act 2018).

Where you act as a processor for your own clients, you confirm you have authority to appoint Zacapa as a sub-processor, and our obligations under this DPA apply to us in that role.

02What we commit to

Zacapa will:

03Sub-processors

In short: we use a short list of infrastructure providers (Annex 3), we stay liable for them, and you get 30 days' notice before we add one.

You give general written authorisation for the sub-processors in Annex 3. We will:

04International transfers

Customer Personal Data is hosted with Supabase in the Asia-Pacific (Singapore) region, and some sub-processors process data in the United States. Wherever processing involves a transfer of UK personal data outside the UK, we ensure a valid transfer mechanism is in place — an adequacy decision where available, or the UK International Data Transfer Addendum to the EU Standard Contractual Clauses (or the UK IDTA) with the relevant sub-processor, plus any supplementary measures needed.

05Security

We implement the measures in Annex 2 and keep them under review. You're responsible for using the Service securely on your side — managing Team Member and Portal User access, and choosing what to share via the client portal.

06If something goes wrong

In short: if there's a personal data breach affecting your data, we tell you without undue delay, with the detail you need for your own notifications.

We'll notify you without undue delay after becoming aware of a personal data breach affecting Customer Personal Data, and provide what you reasonably need to meet your own notification obligations: the nature of the breach, the categories and approximate numbers of data subjects and records affected, the likely consequences, and the measures taken or proposed. Notification goes to your account owner's email.

07Audit

No more than once in any 12-month period (except after a personal data breach), you may audit our compliance with this DPA by writing to privacy@calmerdaysahead.com. We respond first with documentation — our security overview, sub-processor terms, and the available third-party attestations of our hosting providers. If that doesn't reasonably satisfy the request, we'll agree scope, timing and cost of a further audit, run with minimum disruption and under confidentiality.

08Deletion and return

In short: export any time while subscribed. After the end: 30 days to export, deletion from live systems within 60 days, backups within 90.

During your subscription, you can export Customer Content using the Service's export features. On termination or expiry, we'll make Customer Content available for export for 30 days on request, then delete Customer Personal Data from live systems within 60 days and from backups in line with the backup rotation cycle (no later than 90 days), except where the law requires retention.

09General

This DPA is governed by the laws of England and Wales. If it conflicts with the Terms of Service on the processing of personal data, this DPA prevails. Liability under this DPA is subject to the limits in the Terms of Service. We may update this DPA to reflect changes in law or the Service, following the change process in the Terms.

A1Annex 1 — Processing details

ItemDescription
Subject matterProvision of the Calmer Days Ahead project management service.
DurationThe subscription term plus the deletion period in §8.
Nature and purposeHosting, storage, transmission and display of Customer Content; task assignment and notifications; calendar synchronisation where enabled; client approvals via the portal; reporting.
Data subjectsYour Team Members; Portal Users (your clients); other individuals referenced in Customer Content — e.g. contacts named in tasks, comments or files.
Personal dataNames, email addresses, profile data; task, project, comment and approval content; file attachments; calendar event data where sync is enabled; usage metadata. The Service isn't designed for special category data, and you agree not to submit it.

A2Annex 2 — Security measures

A3Annex 3 — Sub-processor list

Sub-processorPurposeLocation
Supabase, Inc.Database, authentication, file storage, serverless functionsSingapore (hosting); USA (entity)
Netlify, Inc.Application and website hosting, content deliveryUSA / global CDN
AC PM, LLC (Postmark)Transactional email — invites, notifications, reportsUSA
Google LLCSign-in (OAuth) and calendar synchronisation, where you enable itUSA / global

This list lives at calmerdaysahead.com/dpa.html#annex3. For change notices, email privacy@calmerdaysahead.com.

Questions about this DPA? Write to privacy@calmerdaysahead.com — a human reads it. Need a countersigned copy for your records? Just ask.

We Are Zacapa Ltd · Registered in England & Wales, company no. 11278191 · Registered office: 35 Emmeline Lodge, 27 Kingston Avenue, Leatherhead, KT22 7FU