Data Processing Addendum for Sagaris ROS
These are the processor commitments that apply when SAGARIS handles customer-controlled personal data inside the ROS platform. They are stated plainly for the customers and reviewers who rely on them.
Last updated · September 29, 2026
How this addendum applies
This Data Processing Addendum (DPA) supplements the SAGARIS Terms of Service. It applies when SAGARIS Inc ("SAGARIS") processes Customer Personal Data on behalf of a customer using the Sagaris ROS platform.
For Customer Personal Data, the customer is the controller or business that determines the purposes and means of processing. SAGARIS acts as processor or service provider for that data. SAGARIS processes that data only to provide, secure, support, and improve the service according to the customer's documented instructions. SAGARIS does not use Customer Personal Data to train or fine-tune models shared across customers. Where "improve the service" appears in this addendum, it means operating, maintaining and securing the service for that customer, and deriving the de-identified aggregate statistics described below. It does not mean building a cross-customer training set.
Unless the customer opts out of network learning in workspace settings, SAGARIS derives de-identified aggregate statistics from workspace outcomes by industry, company-size band, channel and persona. A statistic is released only when at least fifty distinct workspaces contributed to it, is perturbed with statistical noise, and contains no Customer Personal Data, no message content and no workspace identifiers.
Subject matter, duration, and purpose
The subject matter is the hosting and operation of Sagaris ROS: CRM records, outbound sequences, email and call activity, SMS and voice workflows, AI-assisted drafts and summaries, integrations, compliance logs, and related operational telemetry.
Processing lasts for the term of the customer's workspace or written agreement, plus any retention period required for security, billing, legal compliance, backup integrity, or documented customer instructions.
- Categories of data subjects may include the customer's users, prospects, leads, contacts, customers, and people who communicate with them.
- Categories of personal data may include names, business contact details, job information, CRM notes, communication content and metadata, call recordings or transcripts when enabled, consent and suppression records, audit events, and integration identifiers.
- Sensitive data should not be uploaded unless the customer has a lawful basis and the feature has been explicitly configured for that use.
Customer instructions and lawful use
The customer instructs SAGARIS to process Customer Personal Data as needed to provide the service, comply with the Terms, and perform support and security work. It also instructs SAGARIS to process that data as needed to follow written configuration or support instructions from authorized workspace administrators.
SAGARIS will promptly inform the customer if an instruction appears to violate applicable data protection law, unless legally prohibited from doing so. The customer remains responsible for the lawfulness of its data sources, outreach, and use of the service.
Personnel and confidentiality
SAGARIS restricts access to Customer Personal Data to personnel and contractors who need it to operate, secure, support, or improve the service. Those personnel are bound by confidentiality obligations and receive access appropriate to their role.
Workspace isolation, role-based application authorization, audit logging, and fail-closed authentication controls are part of the platform design. They are described further on the Trust & Security page.
Security measures
SAGARIS maintains technical and organizational measures designed to protect Customer Personal Data against unauthorized access, loss, misuse, alteration, or disclosure.
- Google Identity Platform authentication with secure session cookies and company-email confirmation codes.
- TLS in transit, GCP-managed encryption at rest, and additional AES-256-GCM application-layer encryption for high-value OAuth tokens.
- Workspace-scoped authorization, row-level access policies where applicable, and server-side route checks for workspace data access.
- Structured logging, audit trails for high-risk actions, webhook signature verification, outbound consent guardrails, and production incident response procedures.
- Backups, restore procedures, retention controls, and deploy rollback procedures documented in the public trust and runbook materials.
Subprocessors and third-party services
SAGARIS may use subprocessors to provide hosting, infrastructure, AI processing, messaging, billing, analytics, and customer-selected integrations. Examples include Google Cloud Platform, Vertex AI Gemini, Stripe, PostHog, communications providers, and CRM or mailbox integrations the customer connects.
SAGARIS remains responsible for subprocessors it appoints for service delivery and will require materially similar data protection obligations from them. Customer-enabled integrations process data under the customer's relationship with those third-party providers.
International transfers
SAGARIS is operated from the United States and stores the platform in the United States by default. Customer Personal Data may be processed in the United States and in countries where SAGARIS or its subprocessors operate.
Where transfer safeguards are required, SAGARIS will support appropriate contractual transfer mechanisms through the customer agreement or a mutually executed addendum.
Data subject requests and compliance assistance
Taking into account the nature of the processing and the information available to SAGARIS, SAGARIS will assist customers with data subject access, correction, deletion, export, objection, and restriction requests.
The platform includes:
- GDPR erasure support.
- Hashed suppression records to prevent silent re-import.
- Contact-aware export audit logs.
- DSAR activity tracking.
- A dedicated subject-access export path for customer-controlled records.
Security incidents
SAGARIS will notify affected customers without undue delay after confirming a security incident that compromises Customer Personal Data. The notice will include available information about the nature of the incident, affected data, mitigation steps, and points of contact.
Customers are responsible for determining whether notifications to regulators, data subjects, or other third parties are required for their processing activities. SAGARIS will provide reasonable assistance based on the information available.
Return, deletion, and audit information
At the end of the service relationship, SAGARIS will return, export, delete, or anonymize Customer Personal Data, unless law or legitimate security and compliance needs require retention. It will do so according to the customer's instructions and the retention limits in the Privacy Policy.
SAGARIS will make reasonable information available to demonstrate compliance with this DPA. This includes trust materials, subprocessor information, audit logs, incident documentation, and written answers to security review questions.
Questions about this DPA or requests for an executed copy can be sent to support@sagaris.ai.
In this topic
Security, privacy and procurement
- The Trust CenterWhat is done, what is in progress and what is not in place yet, stated plainly.
- Privacy PolicyHow SAGARIS collects, uses, shares and protects personal data.
- Terms of ServiceThe agreement that governs your use of Sagaris ROS.
- Refund and cancellation policyHow billing, cancellation and refunds work on a paid plan.