1.Scope and roles
This Data Processing Addendum (“DPA”) supplements the Terms of Service between you (“Customer”) and Adam Kabessa (“GroundZones”). It applies where GroundZones processes Customer Personal Data on Customer’s behalf and that processing is subject to European Data Protection Law or another applicable data protection law.
Customer is the controller and GroundZones is the processor in respect of Customer Personal Data. Where Customer is itself a processor for a third-party controller, GroundZones is a subprocessor and Customer warrants it has authority to engage us.
For personal data about Customer’s own account holders - names, email addresses, billing and usage records - GroundZones acts as a controller, and that processing is governed by our Privacy Policy rather than this DPA.
This DPA is incorporated into the Terms and takes effect automatically when you accept them. If your organisation requires a countersigned copy, email legal@groundzones.com.
2.Definitions
“European Data Protection Law” means the EU General Data Protection Regulation 2016/679 (“GDPR”), the UK GDPR and Data Protection Act 2018, and the Swiss Federal Act on Data Protection, each as amended.
“Customer Personal Data” means personal data contained in Customer Data that GroundZones processes on Customer’s behalf. “Controller”, “processor”, “data subject”, “personal data”, “processing”, and “personal data breach” have the meanings given in the GDPR. “Subprocessor” means a third party engaged by GroundZones to process Customer Personal Data.
3.Processing details (Annex I)
| Item | Detail |
|---|---|
| Subject matter | Provision of the GroundZones geocoding, distance, and zone-assignment platform. |
| Duration | The term of the Terms of Service, plus the deletion period in Section 11. |
| Nature and purpose | Hosting, storage, geocoding, distance and route calculation, boundary matching, zone assignment, export, and related support - performed to deliver the Service to Customer. |
| Categories of data subjects | Individuals whose details appear in Customer’s uploaded property records - typically business contacts at hotels and venues, and Customer’s own personnel who use the Service. |
| Categories of personal data | Business names and contact details, street addresses and postal codes, geographic coordinates, and any additional fields Customer chooses to include in an upload. |
| Special category data | None. Customer must not upload special category data (Art. 9 GDPR) or criminal offence data (Art. 10 GDPR) to the Service. |
| Frequency | Continuous for the duration of the Service. |
4.Customer’s obligations
- Customer is responsible for the lawfulness of the personal data it uploads, for having a valid lawful basis, and for providing any required notices to data subjects.
- Customer instructs GroundZones to process Customer Personal Data only as set out in this DPA and the Terms.
- Customer must not upload special category or criminal offence data, and must not upload personal data beyond what is necessary for the Service - in particular, the Service is designed for business premises, not individuals’ home addresses.
- Customer is responsible for the accuracy of the personal data it uploads and for configuring access controls within its workspaces appropriately.
5.GroundZones’ processing obligations
- Documented instructions (Art. 28(3)(a)). We process Customer Personal Data only on Customer’s documented instructions, including the Terms, this DPA, and Customer’s use of Service features - except where required by law, in which case we will inform Customer first unless the law prohibits it. We will tell Customer if we believe an instruction infringes European Data Protection Law.
- Confidentiality (Art. 28(3)(b)). Personnel authorised to process Customer Personal Data are bound by confidentiality obligations and are granted access on a least-privilege, need-to-know basis.
- Security (Art. 32). We implement the measures in Section 6.
- No independent use. We do not sell Customer Personal Data, use it for advertising, or use it to train machine learning models. We do not use it for our own purposes other than providing and securing the Service.
6.Security measures (Annex II)
Technical and organisational measures include:
- Encryption of data in transit using TLS, and server-side encryption (AES-256) for uploaded files in object storage.
- Passwords stored using bcrypt, a slow salted one-way hash; credentials never stored in readable form.
- Short-lived access tokens with rotating, httpOnly, path-scoped refresh tokens and replay detection.
- Rate limiting and constant-time credential comparison on authentication endpoints.
- Workspace-scoped authorisation enforced server-side on every request, so tenants cannot read one another’s data.
- Audit logging of authentication, administrative, and billing events, with request correlation identifiers.
- Sensitive values - tokens, cookies, passwords, authorization headers - filtered from logs and error reports.
- Least-privilege administrative access to production systems.
- Regular dependency updates and automated checks in our build pipeline.
- Backups with defined retention, and documented restore procedures.
These measures may be updated as the Service evolves, provided the overall level of security is not reduced.
7.Subprocessors
7.1 General authorisation
Customer gives general written authorisation for GroundZones to engage subprocessors. The current list is published at https://groundzones.com/subprocessors.
7.2 Changes and objection
We will give at least 30 days’ notice before adding or replacing a subprocessor, by updating that page and notifying customers who subscribe to notifications there. Customer may object on reasonable data protection grounds within that period. If we cannot offer a reasonable alternative, Customer may terminate the affected part of the Service and receive a pro-rata refund of prepaid fees.
7.3 Flow-down and liability
We impose data protection obligations on each subprocessor that are no less protective than this DPA, and we remain fully liable to Customer for a subprocessor’s performance.
8.International transfers
GroundZones is established in the United States. Where this DPA involves a transfer of Customer Personal Data out of the EEA, UK, or Switzerland to a country without an adequacy decision, the parties agree that:
- the European Commission’s Standard Contractual Clauses (Decision 2021/914), Module Two (controller to processor) - or Module Three where Customer is itself a processor - are incorporated by reference and apply to the transfer;
- for UK transfers, the ICO’s International Data Transfer Addendum to the SCCs applies;
- for Swiss transfers, the SCCs apply with references to the GDPR read as references to the Swiss FADP and the Swiss Federal Data Protection and Information Commissioner as competent authority;
- Annex I of the SCCs is populated by Section 3 and the parties’ details in Section 13 of this DPA, and Annex II by Section 6; and
- the optional docking clause applies, and for Clause 17 the governing law is that of Ireland, with Clause 18 venue in Ireland.
In the event of any conflict between the SCCs and this DPA, the SCCs prevail.
9.Assistance to Customer
- Data subject requests (Art. 28(3)(e)). The Service provides self-service export and deletion. Where Customer cannot fulfil a request through the Service, we will provide reasonable assistance. If a data subject contacts us directly about Customer Personal Data, we will refer them to Customer and not respond substantively without Customer’s authorisation.
- DPIAs and prior consultation (Art. 28(3)(f), 35, 36). We will provide reasonable assistance and the information necessary for Customer to carry out data protection impact assessments.
10.Personal data breach
We will notify Customer without undue delay after becoming aware of a personal data breach affecting Customer Personal Data, and in any event in time to allow Customer to meet its own notification obligations. The notification will describe the nature of the breach, the categories and approximate number of data subjects and records affected, the likely consequences, and the measures taken or proposed - providing information in phases where it is not all available at once.
Notification is not an acknowledgement of fault or liability. We will not notify supervisory authorities or data subjects on Customer’s behalf unless Customer requests it in writing.
11.Deletion and return
On termination, Customer may export Customer Data through the Service. At Customer’s choice, we will delete or return Customer Personal Data within 30 days of termination, and delete existing copies, unless law requires continued storage.
Residual copies in routine backups age out on a rolling basis: daily database backups are retained for 5 days, and our hosting provider’s daily whole-server backups for 7 days, so residual copies are typically gone within two weeks. While retained, they remain protected by this DPA and are not accessed for any purpose other than restore or legal obligation.
12.Audits
We will make available the information necessary to demonstrate compliance with Article 28 and allow for and contribute to audits, including inspections, by Customer or an independent auditor Customer mandates.
Audits are limited to once per twelve months (unless required by a supervisory authority or following a personal data breach), require at least 30 days’ notice, must be conducted during business hours without unreasonably disrupting our operations, and are subject to confidentiality. Customer bears its own costs and our reasonable costs for audits beyond providing standard documentation.
13.California - service provider terms
Where the CCPA/CPRA applies, GroundZones is a service provider. We are prohibited from, and will not: sell or share personal information; retain, use, or disclose it for any purpose other than performing the Service specified in the Terms; retain, use, or disclose it outside the direct business relationship; or combine it with personal information from other sources except as permitted by the CCPA. We certify that we understand and will comply with these restrictions, and we will notify Customer if we determine we can no longer meet them.
14.General
Order of precedence. In case of conflict, the SCCs prevail over this DPA, and this DPA prevails over the rest of the Terms, in each case only as to the subject matter of data protection.
Liability. Each party’s liability under this DPA is subject to the limitations and exclusions in the Terms, except where those limitations are not permitted by applicable data protection law.
Contact. Data protection matters: privacy@groundzones.com
Adam Kabessa, Mailing address to be published, New Jersey, United States