Zolaymi LLC legal section
Data Processing Agreement
This Data Processing Agreement applies when Zolaymi processes personal data as a processor, service provider or similar role for a business client.
Contents
- 1. Parties and relationship
- 2. Scope, duration and instructions
- 3. Controller responsibilities
- 4. Processor responsibilities
- 5. Confidentiality, personnel and security measures
- 6. Subprocessors and technology providers
- 7. International transfers
- 8. Data-subject requests and security incidents
- 9. Compliance assistance, audits and information
- 10. Return, deletion, liability and order of precedence
- 11. Processing annex
- 12. Contact and signatures
1. Parties and relationship
This Data Processing Agreement ("DPA") forms part of the agreement between Zolaymi LLC and the business client when Zolaymi processes personal data on the client's behalf. The client is the controller or business, and Zolaymi is the processor, service provider or equivalent role, depending on applicable law.
This DPA does not apply where Zolaymi acts as an independent controller, such as when it manages its own website, billing records, enquiries, marketing, legal records or customer accounts.
2. Scope, duration and instructions
Zolaymi will process personal data only to provide the agreed Services, follow documented client instructions, comply with law, protect security, handle support, and meet obligations under the main agreement. The duration of processing is the term of the applicable Project or service plus any retention period required for legal, security, backup, dispute or accounting purposes.
The client's documented instructions include the Order, quotation, statement of work, support tickets, onboarding responses, written approvals and lawful configuration instructions. Zolaymi may decline instructions that appear unlawful, unsafe, outside scope or prohibited by third-party terms.
3. Controller responsibilities
The client is responsible for determining the lawful basis for processing, providing privacy notices, obtaining consents where required, responding to data-subject requests, maintaining lawful customer communication rules, ensuring data accuracy, limiting personal data supplied to Zolaymi, and confirming that instructions are lawful.
The client must not provide unnecessary special-category data, payment-card data, secrets or large customer exports unless expressly required for the service and transferred securely.
4. Processor responsibilities
Zolaymi will process personal data according to documented instructions, ensure persons authorized to process personal data are subject to confidentiality obligations, apply proportionate security measures, assist with data-subject requests where reasonably possible, notify the client of security incidents as described below, and make reasonable information available to demonstrate compliance with this DPA.
5. Confidentiality, personnel and security measures
Zolaymi restricts personal-data access to personnel, contractors or providers who need it for the agreed service. Access should use individual accounts, least-privilege permissions and revocation when no longer needed.
| Measure | Implementation |
|---|---|
| Accounts | Individual user accounts and named temporary access where practical. |
| Access control | Least-privilege access, role limits and access revocation after completion. |
| Authentication | Strong passwords and multifactor authentication where supported. |
| Transmission | Encrypted connections and secure credential transfer where available. |
| Devices | Reasonable device security and malware protection. |
| Backups | BlogVault independent off-site backups where within scope; 30 daily backups and 12 monthly backups, with automatic deletion after 12 months. |
| Logging | Use of available access logs, system logs and project records where relevant. |
| Incident response | Escalation, containment, investigation and client notification procedures. |
| Data minimization | Use only data reasonably necessary for the agreed service. |
| Vendor review | Reasonable review of vendors used for the Services. |
6. Subprocessors and technology providers
Zolaymi currently reports no confirmed human subcontractors for publication purposes, but technology providers may act as subprocessors where they process client personal data. Current or expected subprocessors may include Kinsta, Cloudflare, Google, Meta, Microsoft, Stripe, PayPal, Google Workspace, Postmark, Calendly, BlogVault, Brevo, Crisp, Twilio, Prighter, and every active SaaS or plugin vendor that receives personal data.
The client gives advance general authorization for Zolaymi to use subprocessors needed to provide the Services, subject to a method for notifying business clients of material subprocessor changes. Zolaymi will require subprocessors to provide appropriate confidentiality and data-protection commitments for the processing they perform.
7. International transfers
Zolaymi is based in the United States. Client personal data may be processed in the United States and other countries. Where legally required, transfer mechanisms may include EU Standard Contractual Clauses, the UK International Data Transfer Addendum or IDTA, adequacy decisions, and Data Privacy Framework participation where valid and applicable.
8. Data-subject requests and security incidents
If Zolaymi receives a request from a person relating to client personal data, Zolaymi will, where appropriate, direct the person to the client or notify the client unless legally prohibited. Zolaymi will reasonably assist the client with data-subject requests, deletion, access, correction, portability or objection requests to the extent the information is available to Zolaymi and the assistance is within scope or reasonably chargeable.
Zolaymi will notify the client without undue delay after becoming aware of a security incident affecting client personal data processed by Zolaymi. The notice should include available information about the nature of the incident, affected data, likely consequences and steps taken or proposed, subject to ongoing investigation and legal limits.
9. Compliance assistance, audits and information
Zolaymi will provide reasonable assistance with security, breach assessment, data protection impact assessments and consultations with regulators where required by law and reasonably related to the Services. Assistance outside normal scope may be charged at agreed rates.
Zolaymi will make reasonable information available to demonstrate compliance with this DPA. Audits must be reasonable, proportionate, subject to confidentiality, limited to relevant systems, scheduled in advance, and designed to avoid disruption, exposure of other customers' information or security risk.
10. Return, deletion, liability and order of precedence
At the end of the Services, Zolaymi will return or delete client personal data in its possession where reasonably possible, unless retention is required for legal, accounting, security, backup, dispute or legitimate business purposes. Client-system access should be revoked by the client after completion unless ongoing access is agreed.
Liability under this DPA is subject to the liability provisions in the main agreement unless mandatory law requires otherwise. If there is a conflict, this DPA controls for processor obligations, the Privacy Policy controls Zolaymi controller processing, and the main agreement controls commercial terms.
This DPA is governed by the same law as the main agreement, subject to mandatory data-protection rights and remedies. It may be accepted electronically, by signature, by accepting a quotation referencing it, or by continuing Services that require processor access after notice of the DPA.
11. Processing annex
| Item | Details |
|---|---|
| Subject matter | Remote WordPress and WooCommerce technical services, support, implementation, troubleshooting, monitoring and related ecommerce systems work. |
| Duration | For the Project or recurring service period, plus limited retention required for legal, backup, security, dispute or accounting purposes. |
| Nature of processing | Accessing, viewing, configuring, testing, transferring, storing, backing up, deleting, documenting and troubleshooting personal data in client systems. |
| Purpose | Providing the agreed Services and related support, security, testing and handover. |
| Data subjects | Client customers, prospective customers, account holders, abandoned-cart contacts, support contacts, review participants, staff, contractors and website users. |
| Personal data | Names, emails, addresses, phone numbers, order data, account data, payment status, shipping data, support tickets, cart data, event data, IP addresses, logs and technical identifiers. |
| Special-category data | Not intentionally requested. Client must notify Zolaymi before providing any special-category data. |
| Frequency | As needed for the agreed service, support request or managed-service schedule. |
| Processing locations | United States and the provider locations used by Kinsta, Cloudflare, Google, Meta, Microsoft, Stripe, PayPal, Google Workspace, Postmark, Calendly, BlogVault, Brevo, Crisp, Twilio, Prighter and any active SaaS or plugin vendor that receives personal data. |
| Retention and deletion | As stated in the Privacy Policy, the Order, or documented client instruction, subject to legal and backup constraints. |
| Approved subprocessors | Kinsta, Cloudflare, Google, Meta, Microsoft, Stripe, PayPal, Google Workspace, Postmark, Calendly, BlogVault, Brevo, Crisp, Twilio, Prighter, WooCommerce, WordPress, and every active SaaS or plugin vendor that receives personal data. |
| Transfer mechanisms | EU Standard Contractual Clauses, the UK International Data Transfer Addendum or IDTA, adequacy decisions, and Data Privacy Framework participation where valid and applicable. |
12. Contact and signatures
Business clients may request a signed DPA copy or provide an approved version for review. Electronic acceptance may be recorded through checkout, quotation approval, email confirmation or signature workflow.
Zolaymi LLC can be contacted using the details below. Do not send passwords, API keys, payment-card information, full customer exports, or other sensitive information through ordinary email unless a secure transfer method has been agreed.
- General support: [email protected]
- Privacy and data-rights requests: [email protected]
- Legal notices: [email protected]
- Telephone: +1 602 661 9771
- Website: https://www.zolaymi.com
- Public business mailing address: Zolaymi uses a Wyoming CMRA virtual business mailbox with a unique suite number and mail forwarding. The registered-agent address is not used as the public mailing address.
Policy contact
Questions, legal notices, privacy requests and support requests should be sent to the correct Zolaymi contact address so they can be handled properly.
- General support: [email protected]
- Privacy and data-rights requests: [email protected]
- Legal notices: [email protected]
- Telephone: +1 602 661 9771
- Public business mailing address: Zolaymi uses a Wyoming CMRA virtual business mailbox with a unique suite number and mail forwarding. The registered-agent address is not used as the public mailing address.