01Roles and scope
This DPA forms part of the Terms of Service between We Are Zacapa Ltd ("Zacapa", "we") and the Customer ("you"). It applies to personal data submitted to the Service by you, your Team Members and Portal Users ("Customer Personal Data") and takes effect automatically when you accept the Terms of Service.
For Customer Personal Data, you are the controller and Zacapa is the processor. Processing details are in Annex 1. "UK GDPR", "controller", "processor", "personal data", "processing" and "data subject" carry the meanings in UK data protection law (UK GDPR and the Data Protection Act 2018).
Where you act as a processor for your own clients, you confirm you have authority to appoint Zacapa as a sub-processor, and our obligations under this DPA apply to us in that role.
02What we commit to
Zacapa will:
- process Customer Personal Data only on your documented instructions (including the Terms and your use of Service features and settings), unless the law requires otherwise — in which case we'll tell you, unless legally prohibited;
- tell you if, in our opinion, an instruction infringes data protection law;
- ensure everyone authorised to process Customer Personal Data is bound by confidentiality;
- implement and maintain the technical and organisational measures in Annex 2;
- assist you, taking the nature of the processing into account, with data subject requests and with your obligations under Articles 32–36 UK GDPR (security, breach notification, DPIAs);
- delete or return Customer Personal Data at the end of the engagement, as set out in §8;
- make available the information reasonably needed to demonstrate compliance, and allow audits as set out in §7.
03Sub-processors
You give general written authorisation for the sub-processors in Annex 3. We will:
- impose data protection obligations on each sub-processor no less protective than this DPA;
- remain liable for their acts and omissions;
- give you at least 30 days' notice (by email or in-app) before adding or replacing one. If you reasonably object on data protection grounds and we can't resolve it, you may terminate the affected services with a pro-rata refund of prepaid fees.
04International transfers
Customer Personal Data is hosted with Supabase in the Asia-Pacific (Singapore) region, and some sub-processors process data in the United States. Wherever processing involves a transfer of UK personal data outside the UK, we ensure a valid transfer mechanism is in place — an adequacy decision where available, or the UK International Data Transfer Addendum to the EU Standard Contractual Clauses (or the UK IDTA) with the relevant sub-processor, plus any supplementary measures needed.
05Security
We implement the measures in Annex 2 and keep them under review. You're responsible for using the Service securely on your side — managing Team Member and Portal User access, and choosing what to share via the client portal.
06If something goes wrong
We'll notify you without undue delay after becoming aware of a personal data breach affecting Customer Personal Data, and provide what you reasonably need to meet your own notification obligations: the nature of the breach, the categories and approximate numbers of data subjects and records affected, the likely consequences, and the measures taken or proposed. Notification goes to your account owner's email.
07Audit
No more than once in any 12-month period (except after a personal data breach), you may audit our compliance with this DPA by writing to privacy@calmerdaysahead.com. We respond first with documentation — our security overview, sub-processor terms, and the available third-party attestations of our hosting providers. If that doesn't reasonably satisfy the request, we'll agree scope, timing and cost of a further audit, run with minimum disruption and under confidentiality.
08Deletion and return
During your subscription, you can export Customer Content using the Service's export features. On termination or expiry, we'll make Customer Content available for export for 30 days on request, then delete Customer Personal Data from live systems within 60 days and from backups in line with the backup rotation cycle (no later than 90 days), except where the law requires retention.
09General
This DPA is governed by the laws of England and Wales. If it conflicts with the Terms of Service on the processing of personal data, this DPA prevails. Liability under this DPA is subject to the limits in the Terms of Service. We may update this DPA to reflect changes in law or the Service, following the change process in the Terms.
A1Annex 1 — Processing details
| Item | Description |
|---|---|
| Subject matter | Provision of the Calmer Days Ahead project management service. |
| Duration | The subscription term plus the deletion period in §8. |
| Nature and purpose | Hosting, storage, transmission and display of Customer Content; task assignment and notifications; calendar synchronisation where enabled; client approvals via the portal; reporting. |
| Data subjects | Your Team Members; Portal Users (your clients); other individuals referenced in Customer Content — e.g. contacts named in tasks, comments or files. |
| Personal data | Names, email addresses, profile data; task, project, comment and approval content; file attachments; calendar event data where sync is enabled; usage metadata. The Service isn't designed for special category data, and you agree not to submit it. |
A2Annex 2 — Security measures
- Access control — authentication via Supabase Auth (email/password and Google OAuth); row-level security on every database table, isolating each Workspace's data at the database layer; role-restricted access for Portal Users (Dashboard, Plan and Approvals only); sensitive data such as team rates restricted by owner-only policies.
- Encryption — in transit (TLS) and at rest via the hosting provider.
- Infrastructure — managed hosting with Supabase (database, auth, storage, functions) and Netlify (application delivery), each running their own certified security programmes.
- Backups & resilience — automated database backups with point-in-time recovery capability.
- Secrets management — separation of publishable and secret keys; rotation on personnel change or suspected exposure.
- Account security — security notification emails on sign-in and credential changes; leaked-password protection.
- Organisational — production access limited to authorised personnel; confidentiality obligations for all staff; documented breach response runbook; UK GDPR Article 30 record of processing maintained.
A3Annex 3 — Sub-processor list
| Sub-processor | Purpose | Location |
|---|---|---|
| Supabase, Inc. | Database, authentication, file storage, serverless functions | Singapore (hosting); USA (entity) |
| Netlify, Inc. | Application and website hosting, content delivery | USA / global CDN |
| AC PM, LLC (Postmark) | Transactional email — invites, notifications, reports | USA |
| Google LLC | Sign-in (OAuth) and calendar synchronisation, where you enable it | USA / global |
This list lives at calmerdaysahead.com/dpa.html#annex3. For change notices, email privacy@calmerdaysahead.com.
Questions about this DPA? Write to privacy@calmerdaysahead.com — a human reads it. Need a countersigned copy for your records? Just ask.
We Are Zacapa Ltd · Registered in England & Wales, company no. 11278191 · Registered office: 35 Emmeline Lodge, 27 Kingston Avenue, Leatherhead, KT22 7FU