On Page Navigation
Last updated August 27, 2026
This Data Processing Agreement ("DPA") forms part of the Terms and Conditions between Cascadia Web Services, LLC, a Delaware limited liability company registered to do business in the State of Oregon ("Cascadia," "Processor," "we," "us"), and the client identified in the applicable Statement of Work ("Client," "Controller," "you").
This DPA applies where and to the extent that Cascadia processes Personal Data on your behalf in the course of providing the Services. It does not apply to Personal Data that Cascadia processes as a controller in its own right, such as your billing contacts, account administrators, and marketing preferences, which are described in our Privacy Policy.
Roles. For the purposes of the GDPR and UK GDPR, you are the Controller and Cascadia is the Processor. For the purposes of the CCPA as amended by the CPRA, you are the Business and Cascadia is a Service Provider. Where you are yourself acting as a processor for another controller, you warrant that you have the authority of that controller to instruct Cascadia as set out in this DPA, and references to Controller apply to you as that controller's representative.
Acceptance. This DPA is incorporated automatically into the Terms and Conditions and takes effect without separate signature. Where you require a countersigned copy, or where your own DPA template must be used, contact us and we will arrange execution.
"Data Protection Laws" means all laws applicable to the processing of Personal Data under this DPA, including the EU General Data Protection Regulation 2016/679 ("GDPR"), the UK GDPR and Data Protection Act 2018, the Swiss Federal Act on Data Protection, the California Consumer Privacy Act as amended by the California Privacy Rights Act ("CCPA"), and other applicable U.S. state privacy laws.
"Personal Data" means any information relating to an identified or identifiable natural person that Cascadia processes on your behalf under the Services, as further described in Annex I.
"Personal Data Breach" means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to Personal Data.
"Subprocessor" means any third party engaged by Cascadia to process Personal Data on your behalf.
"Standard Contractual Clauses" or "SCCs" means the standard contractual clauses for the transfer of personal data to third countries adopted by the European Commission in Decision 2021/914, together with the UK International Data Transfer Addendum issued by the UK Information Commissioner.
Terms such as "controller," "processor," "data subject," "processing," "business," "service provider," and "sell" have the meanings given in the applicable Data Protection Laws.
Cascadia will process Personal Data only on your documented instructions, including with regard to international transfers, unless required to do otherwise by applicable law. Where Cascadia is required by law to process Personal Data other than on your instructions, it will inform you of that legal requirement before processing, unless the law prohibits such notification on important grounds of public interest.
Your documented instructions consist of this DPA, the Terms and Conditions, the applicable Statement of Work, and any subsequent written instruction you give through the client portal, a support ticket, or written communication from an authorized contact.
Cascadia will inform you if, in its opinion, an instruction infringes Data Protection Laws, and may suspend performance of that instruction until it is withdrawn, amended, or confirmed. Cascadia is not obliged to conduct a legal review of your instructions and does not do so.
Prohibited processing. Cascadia will not sell or share Personal Data as those terms are defined under the CCPA, will not retain, use, or disclose Personal Data for any purpose other than performing the Services or as otherwise permitted by Data Protection Laws, will not retain, use, or disclose Personal Data outside the direct business relationship between the parties, and will not combine Personal Data received under this DPA with personal information received from other sources except as permitted under the CCPA. Cascadia certifies that it understands and will comply with these restrictions.
Your responsibilities. You are responsible for the lawfulness of the Personal Data you provide and of your instructions, including establishing a valid legal basis, providing required notices to data subjects, obtaining and recording any required consent, and honoring data subject rights. This includes contact lists supplied for email or messaging services and any data you direct Cascadia to transmit to an AI model provider.
Prohibited data categories. Unless the parties agree otherwise in writing and implement appropriate additional safeguards, you will not provide Cascadia with, or store within systems Cascadia manages, protected health information subject to HIPAA, payment card data outside a compliant processor environment, biometric identifiers, precise geolocation, government-issued identification numbers, children's data subject to COPPA, or data revealing racial or ethnic origin, political opinions, religious beliefs, trade union membership, genetic data, sex life, sexual orientation, or criminal convictions.
Cascadia will ensure that all personnel, contractors, and subprocessor staff authorized to process Personal Data are bound by an appropriate obligation of confidentiality, whether contractual or statutory, that survives the end of their engagement.
Cascadia limits access to Personal Data to those personnel who require access to perform the Services, applies role-based access controls, and revokes access promptly when it is no longer required.
Cascadia will implement and maintain appropriate technical and organizational measures to ensure a level of security appropriate to the risk, taking into account the state of the art, the costs of implementation, the nature, scope, context, and purposes of processing, and the risk to data subjects. Those measures are described in Annex II.
Cascadia may update its security measures from time to time provided that the updated measures do not materially reduce the overall level of protection.
You are responsible for assessing whether the measures in Annex II are appropriate for the Personal Data you provide, and for configuring the security options available to you within Client Systems, including access permissions, authentication settings, and retention configuration.
You grant Cascadia general written authorization to engage Subprocessors to process Personal Data in connection with the Services. Cascadia's current Subprocessors are listed in Annex III.
Cascadia will impose on each Subprocessor data protection obligations substantially equivalent to those in this DPA by written contract, and remains fully liable to you for the performance of each Subprocessor's obligations.
Notice and objection. Cascadia will provide at least thirty (30) days' notice before adding or replacing a Subprocessor that will process Personal Data, by updating Annex III and notifying account contacts by email or portal notice. You may object on reasonable data protection grounds within that period by written notice describing your grounds. The parties will discuss the objection in good faith. If Cascadia is unable to make a reasonable alternative available, you may terminate the affected Service without penalty, and Cascadia will refund any prepaid fees covering the period after termination. This is your sole and exclusive remedy for an objection.
Cascadia may engage a new Subprocessor without advance notice where necessary to address an urgent security, availability, or legal risk, and will notify you as soon as reasonably practicable afterward.
Taking into account the nature of the processing, Cascadia will assist you by appropriate technical and organizational measures, insofar as this is possible, in fulfilling your obligation to respond to requests from data subjects exercising their rights of access, rectification, erasure, restriction, portability, objection, and rights relating to automated decision-making.
Where Cascadia receives a request directly from a data subject relating to Personal Data processed on your behalf, Cascadia will not respond substantively other than to acknowledge receipt and direct the data subject to you, and will notify you of the request without undue delay.
Where the Services provide self-service tools enabling you to access, correct, export, or delete Personal Data, you will use those tools in the first instance. Assistance beyond the use of available self-service tools may be charged at Cascadia's then-current hourly rate where the request is unreasonable, repetitive, or requires significant engineering effort.
Cascadia will notify you without undue delay, and in any event within seventy-two (72) hours, after becoming aware of a Personal Data Breach affecting Personal Data processed on your behalf.
The notification will describe, to the extent known at the time and supplemented as further information becomes available: the nature of the breach including where possible the categories and approximate number of data subjects and records concerned; the likely consequences of the breach; the measures taken or proposed to address the breach and mitigate its effects; and a contact point for further information.
Cascadia will take reasonable steps to contain and investigate the breach and will cooperate with you and provide reasonable assistance in connection with your own notification obligations to supervisory authorities and data subjects.
You are responsible for determining whether a Personal Data Breach requires notification to a supervisory authority or to data subjects, and for making any such notification. Cascadia's notification to you is not an acknowledgement of fault or liability.
Taking into account the nature of the processing and the information available to Cascadia, Cascadia will provide reasonable assistance to you in carrying out data protection impact assessments and in any prior consultation with a supervisory authority, where such assessment or consultation relates to processing carried out by Cascadia on your behalf.
Assistance under this Section beyond the provision of existing documentation may be charged at Cascadia's then-current hourly rate.
Cascadia retains Personal Data only for as long as necessary to provide the Services and as set out below.
Hosting backups. Backups of hosted environments are retained for thirty (30) days on a rolling basis, after which they are overwritten or deleted in the ordinary course.
Maintenance backups. Backups taken under a maintenance plan are retained for one hundred eighty (180) days, after which they are overwritten or deleted in the ordinary course. This period applies to backups only.
System logs and monitoring data. Access logs, error logs, monitoring records, and change records are retained for ninety (90) days, except where a longer period is required to investigate a security incident or to comply with a legal obligation.
On termination. On termination or expiry of the Services, Cascadia will, at your election, delete or return Personal Data processed on your behalf. You must make that election in writing within thirty (30) days of termination. If you make no election within that period, Cascadia may delete the Personal Data.
Residual copies. Cascadia may retain Personal Data to the extent required by applicable law, and copies of Personal Data may persist in routine backup media until overwritten in the ordinary backup cycle described above. Any such retained data remains subject to this DPA for as long as it is retained, and Cascadia will not process it for any purpose other than storage and legal compliance.
On written request, Cascadia will provide written confirmation that deletion has been completed.
Cascadia will make available to you information reasonably necessary to demonstrate compliance with its obligations under this DPA, including a description of its technical and organizational measures and, where available, third-party assessments or certifications.
Where that information is insufficient to demonstrate compliance, you may request an audit no more than once in any twelve (12) month period, subject to the following: you provide at least thirty (30) days' written notice; the audit takes place during normal business hours and without unreasonable disruption; the scope is limited to Cascadia's processing of your Personal Data; any auditor is bound by confidentiality obligations and is not a competitor of Cascadia; and you bear your own costs and reimburse Cascadia's reasonable costs at its then-current hourly rate.
Cascadia may satisfy an audit request by providing an existing report or completed security questionnaire where that reasonably addresses your concerns. Cascadia is not required to disclose information that would compromise the security or confidentiality of other clients.
You may request an audit without the notice period above following a confirmed Personal Data Breach affecting your Personal Data, or where required by a supervisory authority.
Cascadia is established in the United States and processes Personal Data in the United States. Certain Subprocessors may process Personal Data in other jurisdictions as indicated in Annex III.
Where Personal Data subject to the GDPR is transferred from the European Economic Area to a country not benefiting from an adequacy decision, the parties agree that the Standard Contractual Clauses are incorporated into this DPA by reference and apply as follows: Module Two (controller to processor) applies where you are a controller; Module Three (processor to processor) applies where you are a processor acting on behalf of another controller; Clause 7 (docking clause) applies; in Clause 9, Option 2 (general written authorization) applies with the notice period stated in Section 6; in Clause 11, the optional independent dispute resolution language does not apply; in Clause 17, the governing law is the law of Ireland; in Clause 18(b), the forum is the courts of Ireland; Annex I, II, and III to the SCCs are populated by Annexes I, II, and III to this DPA respectively.
Where Personal Data subject to the UK GDPR is transferred, the UK International Data Transfer Addendum applies to the SCCs, with Tables 1 to 3 populated by the corresponding information in this DPA, and with the importer and exporter each able to terminate under Section 19 of the Addendum. Where Personal Data subject to Swiss law is transferred, references to the GDPR are read as references to the Swiss Federal Act on Data Protection, the competent authority is the Swiss Federal Data Protection and Information Commissioner, and the term "member state" does not prevent data subjects in Switzerland from exercising rights in their place of habitual residence.
If the SCCs or the Addendum are superseded, invalidated, or replaced, the parties will work in good faith to implement an alternative lawful transfer mechanism without undue delay.
Each party's liability arising out of or relating to this DPA is subject to the exclusions and limitations of liability set out in the Terms and Conditions, except to the extent that Data Protection Laws prohibit such limitation.
Nothing in this DPA limits or excludes either party's liability to a data subject under Data Protection Laws, or affects the rights of data subjects under the Standard Contractual Clauses.
This DPA takes effect when you first accept the Terms and Conditions or begin receiving Services involving the processing of Personal Data, and continues until Cascadia ceases to process Personal Data on your behalf. Provisions that by their nature should survive termination will do so.
In the event of a conflict, the following order of precedence applies with respect to the processing of Personal Data: (1) the Standard Contractual Clauses; (2) this DPA; (3) the Terms and Conditions; (4) any other agreement between the parties.
Cascadia may update this DPA where necessary to reflect changes in Data Protection Laws, changes to the Services, or the addition of Subprocessors. Material changes will be notified in accordance with the Terms and Conditions.
If any provision of this DPA is held invalid or unenforceable, the remainder continues in effect and the parties will replace the affected provision with a valid provision achieving the closest possible commercial and legal effect.
Data exporter. The Client identified in the applicable Statement of Work, acting as controller (or as processor on behalf of its own controller). Contact details are those held in the Client's account record.
Data importer. Cascadia Web Services, LLC, Portland, Oregon, United States, acting as processor. Contact details are published at cascadiawebservices.com.
Subject matter. Provision of managed and professional services across website hosting and development, business software administration, email and messaging infrastructure, marketing, operations, and AI and automation services.
Duration. For the term of the applicable Statement of Work, plus the retention periods described in Section 10.
Nature and purpose. Hosting, storage, backup, configuration, administration, migration, transmission, analysis, troubleshooting, and deletion of Personal Data as necessary to deliver the Services.
Frequency. Continuous, for the duration of the Services.
Categories of data subjects may include, depending on the Services taken: the Client's employees, contractors, and administrators; the Client's customers, prospects, and leads; website visitors and form submitters; email and SMS recipients; job applicants where recruitment modules are administered; and suppliers and vendors of the Client.
Categories of Personal Data may include, depending on the Services taken: identifiers such as name, email address, postal address, telephone number, and account identifiers; employment and role information; customer relationship records, notes, and communications history; transaction, invoice, and payment status records excluding full payment card numbers; email and message content and metadata including delivery, bounce, and engagement data; website analytics and technical data including IP address, device, and browser information; support tickets and correspondence; content submitted through forms; and credentials and access records for systems administered on the Client's behalf.
Sensitive data. None is intended or permitted. See Section 3.
Competent supervisory authority for the purposes of Clause 13 of the SCCs is determined by the data exporter's place of establishment, or where the exporter is not established in the EEA, the supervisory authority of the member state in which the exporter's representative is established or in which the relevant data subjects are located.
Access control. Multi-factor authentication is required on all administrative accounts held by Cascadia. Access is granted on a least-privilege, role-based basis and is reviewed and revoked when no longer required. Credentials are held in a managed password vault, separated per client. Shared logins are not used, and credentials are not transmitted by email.
Encryption. Data in transit is protected using TLS. Administrative access occurs over SSH, SFTP, or HTTPS; plain FTP is not used. Provider credentials supplied to the MCP Router are encrypted at rest and are not retrievable in plaintext by Cascadia.
Infrastructure security. Hosted environments are hardened, sit behind a firewall, and are subject to continuous malware scanning. Core, plugin, and dependency updates are applied on a defined schedule with vulnerability disclosures tracked.
Availability and resilience. Backups run automatically on the schedules described in Section 10 and are tested. A restore point is created before planned changes. Systems are monitored with alerting on change and failure conditions.
Segregation. Client environments and credentials are logically separated. Personal Data processed for one client is not combined with that of another.
Personnel. Personnel with access to Personal Data are bound by confidentiality obligations and receive guidance on data protection responsibilities appropriate to their role.
Incident response. Cascadia maintains a process for identifying, containing, investigating, and reporting security incidents, including the notification obligations in Section 8.
Subprocessor assurance. Subprocessors are subject to written data protection terms substantially equivalent to this DPA.
Deletion. Personal Data is deleted in accordance with Section 10 and the retention periods stated there.
The following Subprocessors may process Personal Data in connection with the Services. Not all apply to every engagement; the applicable set depends on the Services taken.
Anthropic, PBC - United States - AI model processing for automation and AI services.
Frappe Technologies Pvt. Ltd. (Frappe Cloud) - India - hosting of our own website, client portal, and ERPNext environments.
Rocket.net - United States - managed WordPress hosting infrastructure for client websites, and rolling 30-day backups.
BlogVault - backup service - off-site retention of 180-day maintenance backups.
Cloudflare, Inc. - United States, global edge network - DNS, domain registration, content delivery, security, and email routing.
Zoho Corporation - United States, India - business application hosting, and transactional email delivery via ZeptoMail.
Postmark (ActiveCampaign, LLC) - United States - marketing and bulk email delivery.
Twilio Inc. - United States - SMS and messaging delivery.
Stripe, Inc. - United States - payment processing.
Zoho Payments - payment processing, currently being retired and replaced by Stripe.
Enzuzo - Canada - cookie consent management on our website.
Ahrefs Pte. Ltd. - Singapore - cookieless website analytics.
Cascadia will update this Annex in accordance with Section 6 before adding or replacing a Subprocessor.
Questions regarding this DPA, or requests for a countersigned copy, may be directed to:
Cascadia Web Services, LLC
Portland, Oregon, United States
Telephone: +1.800.610.3575
Web: cascadiawebservices.com