Data Processing Agreement (DPA)
Last updated About 13 hours ago
This Data Processing Agreement ("DPA") forms part of and supplements the SAGA Terms and Conditions between Workflow Associates LLC ("Workflow" or "Processor"), 30 North Gould Street, Sheridan, WY 82801, USA, and the customer contracting for the SAGA services ("Controller"). This DPA applies whenever SAGA processes personal data on behalf of the Controller.
1. Roles and Scope
Where the Controller uses SAGA to manage its own end-customers’ and prospects’ personal data (for example contact and lead data entered into SAGA), the Controller is the data controller and Workflow is the data processor in respect of that personal data. To the extent SAGA is also provided to a Controller who acts as a processor for its own customers, SAGA acts as a sub-processor under the Controller’s instructions.
This DPA does not apply to personal data that Workflow processes as an independent controller, such as data required to provide, secure and operate the SAGA service and to comply with legal obligations.
2. Details of Processing
2.1 Subject matter: The provision of the SAGA CRM and sales-automation platform (including its online interfaces, APIs and integrations).
2.2 Nature and purpose: Storing, organising, retrieving, analysing, updating and exporting the Controller’s contacts, leads, prospects, sales activities and related data so the Controller can operate its CRM and sales processes.
2.3 Duration: For the duration of the applicable subscription, plus such further period as required to comply with legal retention obligations, after which personal data is deleted or anonymised in accordance with Section 9.
2.4 Categories of data subjects: End-customers and prospects of the Controller, and the Controller’s own users (members, leads, and representatives) who use SAGA.
2.5 Categories of personal data: Contact information (name, email, phone, social handles, location), sales and membership status (lead membership, sale step, pipeline state), notes and interactions, communication history (emails, calls, WhatsApp), and, to the extent added by the Controller, any other personal data the Controller uploads. SAGA generally processes no special-category data under Art. 9 GDPR unless the Controller expressly adds it; the Controller must ensure it has a lawful basis for any such data.
3. Obligations of the Processor
Workflow shall process personal data only on documented instructions from the Controller, unless required to do so by applicable law (in which case Workflow will inform the Controller of that legal requirement before processing, unless the law prohibits such information on important grounds of public interest). In particular, Workflow shall:
process personal data only for the purposes described in this DPA or as otherwise instructed in writing by the Controller;
ensure persons authorised to process personal data have committed themselves to confidentiality;
implement and maintain appropriate technical and organisational measures (TOMs) in accordance with Section 7;
assist the Controller, by appropriate technical and organisational measures, in fulfilling its obligation to respond to requests from data subjects;
make available to the Controller all information necessary to demonstrate compliance with Art. 28 GDPR and allow for and contribute to audits, subject to Section 8;
immediately inform the Controller if, in Workflow’s opinion, an instruction infringes the GDPR or other applicable data-protection law.
4. Controller Responsibilities
The Controller is responsible for ensuring it has a lawful basis for the processing carried out through SAGA, including any special-category data, and for determining appropriate instructions. The Controller warrants that the personal data it uploads to SAGA is collected and used lawfully and in accordance with the Privacy Policy.
5. Sub-processors
The Controller authorises Workflow to engage sub-processors to assist in providing the service, provided that each sub-processor is bound by a written agreement imposing obligations equivalent to those in this DPA. A current list of sub-processors is set out in Annex B below.
Workflow shall give the Controller reasonable notice, via the SAGA service or email, of any material change to this list. The Controller may object to a new sub-processor within 14 days of notice on reasonable grounds; if the parties cannot resolve the objection, the Controller may terminate the affected part of the service in accordance with the Terms and Conditions.
6. International Transfers (DPF / SCCs)
Where personal data of individuals in the EEA, UK or Switzerland is transferred to Workflow’s operations or sub-processors located outside these regions, Workflow ensures such transfers are protected by a valid legal mechanism.
Workflow Associates LLC, and each of its sub-processors listed in Annex B where applicable, participates in the EU–US Data Privacy Framework (DPF), the UK Extension to the DPF, and/or the Swiss–US DPF, which the European Commission has recognised as providing an adequate level of protection. For any transfer not covered by the DPF, Workflow enters into and relies on the European Commission’s Standard Contractual Clauses (SCCs) (including the UK Addendum where applicable), together with an appropriate transfer risk assessment.
Questions regarding the applicable transfer mechanism may be directed to support at https://thesaga.app/supportCenter.
7. Security (Technical and Organisational Measures)
Workflow implements appropriate TOMs to protect personal data against unauthorised or unlawful processing, accidental loss, destruction or damage. These include:
Encryption: encryption of data in transit (TLS) and at rest;
Access control: role-based access, authentication and authorisation, and revocation of access on departure;
API security: per-user API keys (`saga_`-prefixed) used as bearer credentials, each revocable by the Controller;
Monitoring and logging: monitoring of infrastructure, error tracking and incident management;
Incident management: documented incident-response and breach-notification procedures;
Business continuity: backups, automated backup and restoration procedures;
Sub-processor diligence: contractual security commitments from all sub-processors and third-party processors.
8. Audits
Upon written request and no more than once per calendar year, Workflow shall make available to the Controller information reasonably necessary to demonstrate compliance with this DPA, subject to confidentiality and security requirements. The Controller may exercise its audit rights under Art. 28 GDPR via a mutually agreed independent auditor provided this does not unreasonably interfere with Workflow’s business. Any audit-related costs are borne by the Party requesting the audit.
9. Data Retention and Deletion
The Controller can export and delete personal data at any time through the SAGA interface. On termination of the subscription, Workflow will, at the Controller’s option, delete or return the personal data within a reasonable period, unless retention is required by applicable law. Deletion follows an irreversible deletion process. Backups and logs may persist for a limited additional period consistent with applicable legal and retention requirements.
10. Personal Data Breach Notification
Workflow will notify the Controller without undue delay after becoming aware of a personal data breach affecting personal data processed under this DPA, providing such information as is reasonably available to enable the Controller to meet its own notification obligations. Workflow will reasonably cooperate with the Controller and take reasonable steps to mitigate the effects of the breach.
11. Data Subject Rights
Workflow will assist the Controller in fulfilling its obligations to respond to requests by data subjects exercising their rights under the GDPR (access, rectification, erasure, restriction, portability, objection, and the right not to be subject to automated decision-making), by making available the relevant personal data and the tools and controls offered by the SAGA service.
12. Liability
Except as otherwise expressly set out in the Terms and Conditions, the parties’ aggregate liability under or in connection with this DPA is subject to the liability provisions of the SAGA Terms and Conditions. Each party shall be liable for damages caused by its own failure to comply with obligations arising under the GDPR.
13. Governing Law and Contact
This DPA is governed by the laws applicable to the SAGA Terms and Conditions. Requests, objections and other notices under this DPA should be sent to Workflow Support through the SAGA app Support Center: https://thesaga.app/supportCenter.
Annex A – Parties
Processor: Workflow Associates LLC, 30 North Gould Street, Sheridan, WY 82801, USA.
Controller: The customer entity that subscribes to SAGA and/or its authorised users who use the SAGA service to manage personal data.
Annex B – Sub-processor List
The following sub-processors process personal data in connection with the SAGA service. Processor location and transfer basis are indicated. This list can be updated by Workflow in accordance with Section 5.
Annex C – Notes for Customers using the SAGA API / MCP
Customers who connect SAGA to their own systems (for example via the SAGA API or MCP endpoint) are solely responsible for the security and lawfulness of any data they export from, or send to, SAGA, including any onward processing in the customer’s own systems. API keys are secrets and must be stored and handled securely; keys may be revoked by the Controller at any time. See Integrate SAGA with other tools for API documentation.