Data Processing Addendum

Effective date: April 29, 2025

1 — Definitions (Additions)

"Client Credentials" means any usernames, passwords, session tokens, API keys, OAuth grants, multi-factor codes, security questions, or other access mechanisms supplied or authorized by Customer to enable Zoca to access a Third-Party Platform on Customer's behalf.

"Third-Party Platform" means any third-party booking, scheduling, calendar, point-of-sale, payment, customer-record, marketing, listing, messaging, social-media, or similar online platform that Customer connects to the Services, including without limitation GlossGenius, Vagaro, Mindbody, Acuity Scheduling,
Square Appointments, and Fresha.

"Third-Party Platform Terms" means the then-current terms of service, acceptable-use policy, developer terms, API terms, partner program terms, privacy policy, or other governing rules of any Third-Party Platform.

2.1 — Roles

The parties acknowledge that, with respect to Customer Personal Data:

(a) End-Customer Personal Data.

For Personal Data of Customer's end customers (callers, appointment recipients, leads) that Zoca processes on Customer's behalf as part of the Services, Customer is the Controller (or Business under CCPA) and Zoca is the Processor (or Service Provider).

(b) Customer Personnel Data.

For Personal Data of Customer's own personnel (account administrators, signatories, billing contacts), Zoca is an independent Controller under its Privacy Policy. This DPA does not
apply to that processing.

(c) Third-Party Platform Data.

Where Customer directs Zoca to access a Third-Party Platform on
Customer's behalf using Client Credentials, Customer is the Controller (or Business) of the Personal Data Zoca retrieves from, sends to, or modifies on such Third-Party Platform on Customer's behalf, and Zoca acts solely as Customer's Processor (or Service Provider) for such data. The Third-Party Platform is a separate Controller in its own right under its own privacy policy and is not a Sub processor of Zoca for purposes of
this DPA.

3.1 — Documented Instructions; Customer Direction

(a) Zoca will process Customer Personal Data only on Customer's documented instructions, including with regard to transfers to a third country, unless required to do otherwise by applicable law (in which case Zoca will inform Customer of that legal requirement before processing, unless that law prohibits such information on important grounds of public interest).

(b) The Agreement (including the Master Services Agreement or Terms of Service, this DPA, the Privacy Policy, Customer's onboarding intake, and Customer's in-app configuration) constitutes Customer's documented instructions to Zoca.

Customer's documented instructions specifically include:

  1. Customer's authorization for Zoca to access Third-Party Platforms on Customer's behalf using Client Credentials, for the purposes of operating the Services as configured by Customer (the "Third-Party Platform Access Instruction");
  2. Customer's direction to retrieve specified categories of Customer Personal Data from such Third-Party Platforms, including booking records, customer-record data, calendar data, and configuration data;
  3. Customer's direction to send specified categories of Customer Personal Data to such Third-Party Platforms, including booking creations, modifications, and cancellations, and configuration updates;
  4. Customer's direction to enable the Conversational AI and/or Loyalty Agent Services (where applicable) to contact Customer's end customers as authorized by Customer; and
  5. any further written instructions Customer provides to Zoca from time to time.


(c) Customer's Representations Concerning Instructions. Customer represents, warrants, and covenants on a continuing basis that:

  1. The Third-Party Platform Access Instruction and all related instructions are lawful and within Customer's authority to give;
  2. Customer has obtained any consents, notices, and lawful-basis assessments required under applicable Data Protection Law in respect of such instructions;
  3. The Third-Party Platform Access Instruction is consistent with the then-current Third-Party Platform Terms of each relevant Third-Party Platform, or Customer is willing to accept the risk if it is not; and
  4. Customer has the legal right and authority to grant Zoca access to Customer's account on each Third-Party Platform via Client Credentials.

(d) Zoca's Compliance with Instructions Is Not an Endorsement. Zoca's execution of Customer's instructions does not constitute Zoca's review, endorsement, or representation that the instructions are lawful or consistent with any Third-Party Platform Terms. Zoca is entitled to rely on Customer's
representations under (c) above.

4.7 — Third-Party Platform Data (CCPA Service-Provider Terms)

The restrictions in this Section 4 apply to Customer Personal Data Zoca retrieves from, sends to, or modifies on a Third-Party Platform on Customer's behalf in the same manner as they apply to other Customer Personal Data. Zoca will not retain, use, or disclose such data for any purpose other than the Business Purposes set forth in Section 4.1.

5.6 — Third-Party Platforms Are Not Subprocessors

For the avoidance of doubt:
(a) Third-Party Platforms to which Zoca connects on Customer's behalf using Client Credentials, including without limitation Gloss Genius, Vagaro, Mindbody, Acuity Scheduling, Square Appointments, and Fresha, are not Sub processors for purposes of this DPA, the EU SCCs, or any analogous transfer instrument.
Customer's relationship with each Third-Party Platform is a separate controller-to-controller (or controller-to-third party) relationship governed by the Third-Party Platform's own privacy policy and terms.

(b) Zoca's obligations under Sections 5.1–5.5 (notice of Subprocessor changes, objection rights, flow-down)do not apply to Third-Party Platforms. Customer's recourse with respect to any Third-Party Platform is Customer's direct relationship with that Third-Party Platform.

(c) Where Customer instructs Zoca to integrate with a new Third-Party Platform, Zoca will treat that instruction as a current documented instruction under Section 3.1, not as a new Sub processor engagement.

6.4 — Third-Party Platform Breaches

A security incident involving Customer Personal Data while it resides on a Third-Party Platform (and not in Zoca's environment or in transit to/from a Sub processor of Zoca) is not a "Security Incident" affecting Zoca under this Section 6. Such an incident is a security incident of the Third-Party Platform and/or of Customer, and the Third-Party Platform and Customer (each as Controllers in their own right) are responsible for the corresponding notification obligations. Zoca will reasonably cooperate with Customer's inquiry into such an incident as further described in Section 8 (Audits).