Last updated: 7 September 2026
Between Zapfalcon Ltd (Companies House 17183793, ICO registration ZC217044), Apartment 407 Tayleur Apartments, Waterman Walk, Salford, Greater Manchester, M50 3AQ, United Kingdom (“Zapfalcon”, the “Processor”)
and the customer named in the Pilot Order (the “Customer”, the “Controller”).
This Agreement forms part of the Zapfalcon Pilot Terms of Service. It is structured on Article 28(3) of the UK GDPR. Where it and the Terms conflict on data protection, this Agreement prevails.
1. Roles and definitions
1.1 For personal data the Customer’s team captures and manages in the Service (“Customer Data”), the Customer is the controller and Zapfalcon is the processor.
1.2 “UK GDPR”, “personal data”, “processing”, “data subject”, “personal data breach” and “sub-processor” have the meanings given in the UK GDPR and the Data Protection Act 2018.
1.3 Annex I describes the processing. Annex II describes Zapfalcon’s security measures. Annex III lists sub-processors.
2. Processing on the Customer’s instructions
2.1 Zapfalcon processes Customer Data only on the Customer’s documented instructions. The Customer’s instructions are: the Terms, this Agreement, Annex I, and the settings the Customer chooses in the Service (for example: which integrations to connect, the sync scope, the owner policy, and whether email notifications are paused).
2.2 If a law requires Zapfalcon to process Customer Data otherwise, Zapfalcon will tell the Customer before doing so, unless the law prohibits that.
2.3 Zapfalcon will tell the Customer promptly if it believes an instruction breaches the UK GDPR.
3. Confidentiality
3.1 Zapfalcon ensures that any person it authorises to access Customer Data is bound by confidentiality. At the date of this Agreement Zapfalcon’s only personnel with production access is its director.
4. Security
4.1 Zapfalcon implements the technical and organisational measures in Annex II. Zapfalcon may improve these measures over time but will not materially reduce them during the term.
4.2 Annex II states plainly which common measures are not in place. The Customer accepts the Service on that basis.
5. Sub-processors
5.1 The Customer gives general authorisation for the sub-processors in Annex III.
5.2 Zapfalcon will give the Customer at least 30 days’ written notice by email before adding or replacing a sub-processor. The Customer may object within that period on reasonable data protection grounds. If the objection cannot be resolved, the Customer may end the Terms without penalty.
5.3 Zapfalcon has a written contract with each sub-processor imposing data protection obligations equivalent to this Agreement, and remains responsible to the Customer for each sub-processor’s performance.
5.4 Not a sub-processor: the Customer’s own CRM (for example HubSpot) and any webhook destination the Customer configures. Data sent there is sent on the Customer’s instruction to a system the Customer controls under the Customer’s own contract with that provider.
6. International transfers
6.1 Customer Data is stored in the European Union (Frankfurt) on Supabase. Some processing takes place in the United States by OpenAI (transcription and AI briefs) and may take place in the United States or other countries by Google (business-card text recognition) and Vercel (application hosting).
6.2 Each transfer outside the UK is covered by the transfer mechanism listed in Annex III, being the UK International Data Transfer Addendum to the EU Standard Contractual Clauses, or the vendor’s equivalent UK-recognised safeguard, under Zapfalcon’s contract with that sub-processor.
6.3 Zapfalcon will not transfer Customer Data to any other country without the Customer’s authorisation under Section 5.
7. Assisting with data subject rights
7.1 The Service lets the Customer directly: export any lead (including notes, transcript and AI brief) as CSV; correct any lead field; and delete any lead, which removes the lead and all attached records and writes an audit entry (Annex I, section 6).
7.2 If Zapfalcon receives a request from a data subject relating to Customer Data, it will not respond except to direct the person to the Customer, and will notify the Customer without undue delay.
7.3 For anything the Service does not let the Customer do itself (for example, exporting or deleting an entire workspace), Zapfalcon will do it on written request within 30 days.
8. Assisting with security, breaches and impact assessments
8.1 Zapfalcon will assist the Customer, taking into account the nature of the processing and the information available to it, in meeting the Customer’s obligations on security, breach notification and data protection impact assessments, by providing the information in this Agreement, the Annexes, and reasonable further information on request.
9. Personal data breach
9.1 Zapfalcon will notify the Customer without undue delay after becoming aware of a personal data breach affecting Customer Data, by email to the Customer’s admin address, with the information Zapfalcon then has and further information as it becomes available.
9.2 Honest statement of capability: Zapfalcon’s breach awareness currently depends on its own audit logs and the monitoring and notification of its sub-processors, each of whom is contractually bound to notify Zapfalcon without undue delay. Zapfalcon does not operate a dedicated intrusion-detection system. Zapfalcon will pass on any sub-processor notification to the Customer promptly.
10. Deletion and return
10.1 During the term, deletion in the Service is immediate and complete for the deleted lead and its attached records (Annex I, section 6). Voice recordings are never retained beyond transcription.
10.2 At the end of the Terms, the Customer may export its data for 30 days. After that period Zapfalcon deletes the Customer’s workspace data, except (a) audit records of deletions, which contain only the identifying details needed to evidence that a deletion occurred, and (b) anything Zapfalcon is legally required to keep. Deletion from sub-processors follows each sub-processor’s contractual deletion period (Annex III).
11. Audit
11.1 Zapfalcon will make available the information reasonably necessary to demonstrate compliance with this Agreement, including the Annexes and, on request, the audit-trail report of actions taken on the Customer’s data.
11.2 No more than once a year, on 30 days’ notice, the Customer or an independent auditor may audit Zapfalcon’s compliance with this Agreement, at the Customer’s cost, during business hours, subject to confidentiality and to not disrupting other customers.
12. Customer obligations
12.1 The Customer is responsible for: having a lawful basis to collect each lead’s personal data; giving data subjects the information the UK GDPR requires; ensuring voice notes are recorded lawfully; the accuracy of Customer Data; and the lawfulness of any attendee list it uploads.
12.2 The Customer confirms that its instructions to Zapfalcon comply with the UK GDPR.
13. Liability, term and law
13.1 Liability under this Agreement is subject to the limits in the Terms.
13.2 This Agreement lasts as long as Zapfalcon processes Customer Data.
13.3 This Agreement is governed by the law of England and Wales.
Annex I: Details of processing
1. Subject matter. Provision of the Zapfalcon Service: capturing leads at business events, routing them to follow-up owners, tracking follow-up, reporting, and syncing to the Customer’s CRM where configured.
2. Duration. The term of the Terms, plus the 30-day export period, plus the time needed to complete deletion.
3. Nature and purpose. Storage; transcription of voice notes to text; generation of a short AI summary and tag suggestions; optical character recognition of business cards; routing and task creation; email notifications to the Customer’s users and follow-up owners; export; synchronisation to the Customer’s CRM and webhook destinations on the Customer’s instruction.
4. Categories of data subjects.
- Leads: people the Customer’s team meets at events (prospects, attendees).
- Customer users: the Customer’s admins and reps.
- Follow-up owners: people the Customer designates to follow up, who may not be users.
- Attendee list contacts: people on organiser lists the Customer uploads.
5. Categories of personal data.
- Leads: name, email, phone, company, job title, badge or QR scan content, notes typed by the rep, transcript of the rep’s voice note (the recording itself is deleted after transcription), AI-generated summary and tags, interest and outcome tags, score, capture time and method, the capturing user’s identity, and the Customer’s follow-up status and outcome. Business-card images are sent for text recognition and are not stored.
- Customer users: name, email, role, password hash (held by Supabase Auth and never visible to Zapfalcon), device identifier for offline sync, actions recorded in the audit log.
- Follow-up owners: name, email, an encrypted personal portal token.
- Attendee list contacts: whatever the Customer uploads, typically name, email, company, title and phone.
6. Deletion behaviour. Deleting a lead removes the lead record and, by database cascade, its transcript, AI brief, tag suggestions, tags, attention items and tasks. A database trigger writes one audit record containing the lead’s email, name, company, score and capture date so the deletion can be evidenced. Voice recordings are deleted by the transcription function at completion, whether transcription succeeds or permanently fails; none are retained. Copies the Customer synced to its own CRM are not touched.
7. Retention. Customer Data is retained for the term and deleted under Section 10. Zapfalcon does not apply shorter automatic retention windows.
Annex II: Technical and organisational measures
In place:
- Tenant isolation. Every record carries a workspace identifier. Row-level security policies in the database restrict every read and write to the requesting user’s workspace and, for reps, to events they are assigned to. Storage objects are scoped to workspace membership by policy. Isolation is enforced by the database, not by application code.
- Encryption in transit. All connections use TLS.
- Encryption at rest. Provided by the hosting provider (Supabase, AWS eu-central-1). Follow-up owners’ portal tokens are additionally encrypted at application level (AES-256-GCM) and stored as hashes for lookup.
- Authentication. Passwords are hashed and managed by Supabase Auth; a minimum of 12 characters with mixed character types is enforced; email confirmation is required at signup; bot protection (Cloudflare Turnstile) and rate limiting apply to signup.
- Authenticated automation. Internal background functions require a shared secret and reject requests without it. Outbound webhooks can be signed with HMAC-SHA256.
- Audit trail. Lead creation, edits, score changes, archive and restore, deletion (by database trigger), event status and membership changes, integration connections and setting changes, exports, and every notification decision are logged. Audit records survive deletion of the records they describe.
- Erasure. As described in Annex I, section 6.
- Sub-processor contracts. Data processing agreements with each sub-processor in Annex III, including UK transfer safeguards.
- AI provider controls. Data sharing with OpenAI for model training is disabled at organisation level; audio is deleted after transcription; only the text summary is retained.
- Secrets. Held in environment configuration, never in source code.
Not in place, disclosed plainly:
- No multi-factor authentication for admin accounts.
- No SOC 2, ISO 27001 or equivalent certification of Zapfalcon itself. Sub-processors hold their own.
- No independent penetration test completed yet.
- No dedicated intrusion-detection or security-event alerting beyond provider dashboards and Zapfalcon’s audit log.
- Data held on a rep’s mobile device while offline is obfuscated but not strongly encrypted. Device security (PIN, biometrics, device encryption) is the Customer’s responsibility.
- The Customer’s HubSpot key is stored under database access controls but is not separately encrypted at application level.
- No documented backup and restore procedure beyond the hosting provider’s defaults.
Annex III: Sub-processors
| Sub-processor | What it does | Data it receives | Location | Transfer mechanism |
|---|---|---|---|---|
| Supabase, Inc. | Database, authentication, storage, background functions | All Customer Data | EU (Frankfurt, AWS eu-central-1) | DPA on file; data at rest remains in the EU |
| Vercel, Inc. | Hosts the web admin and its API routes | Customer Data in transit while the admin is used | Served from London and EU edge; US company | DPA on file including UK-recognised safeguards |
| OpenAI OpCo, LLC | Voice-note transcription; AI brief and tag suggestions; business-card field extraction | Voice recording (transient), lead name, company and title, rep notes, transcript, card text | United States | DPA signed 18 August 2026 with EU SCCs as amended by the UK Addendum; training on Customer Data disabled |
| Google Cloud (Vision API) | Business-card text recognition | Card image (transient) | Global (Google facilities) | Google Cloud Data Processing Addendum incorporated into Zapfalcon’s Google Cloud agreement |
| Zoho Corporation (ZeptoMail) | Transactional email: alerts, portal links, briefs, summaries | Recipient name and email; lead name, company and deadline inside notification text | EU | DPA countersigned and on file |
| Cloudflare, Inc. (Turnstile) | Bot protection on signup only | Visitor IP and browser signals at signup | Global | DPA on file |
Not sub-processors (Customer-instructed destinations under the Customer’s own contracts): the Customer’s HubSpot account, and any webhook destination the Customer configures.
Planned, not yet active: Stripe, Inc. (payments). No Customer Data is processed by Stripe until paid billing begins, at which point only the Customer’s billing contact details will be shared and this Annex will be updated with 30 days’ notice.