Data Processing Addendum
Processor-style data protection terms for customer-controlled workspace content.
- Effective
- July 28, 2026
- Updated
- July 28, 2026
- Owner
- [Your LLC Legal Name]
Status
This Data Processing Addendum is a framework draft for attorney review. It should be attached to a signed customer agreement before it is relied on for GDPR, UK GDPR, Swiss FADP, U.S. state privacy laws, or other data-protection obligations.
The processor or service provider is [Your LLC Legal Name]. The customer is the controller, business, or equivalent party for customer-controlled workspace content unless a signed agreement states otherwise.
Processing instructions
The provider will process customer personal data only to provide, secure, support, maintain, bill, improve, and administer the Service; comply with documented customer instructions; prevent abuse; and satisfy legal obligations.
Customer instructions include the agreement, workspace configuration, lifecycle policies, deletion settings, legal holds, administrator actions, support requests, and documented integration settings.
Security measures
Security measures may include access controls, tenant isolation, encryption, TLS, secret boundaries, policy enforcement, lifecycle controls, rate limiting, malware scanning, audit metadata, deletion orchestration, independent verification adapters, monitoring, vulnerability management, and least-privilege provider configuration.
The production DPA should attach a security schedule that matches the actually deployed infrastructure and excludes unverified or aspirational controls.
Subprocessors
The provider may use subprocessors for hosting, storage, authentication, database, payment, email, AI, malware scanning, monitoring, security, KMS/HSM, deletion verification, and support. Subprocessors must be bound by written obligations appropriate to their role.
The provider should maintain a current subprocessor list, provide required notices of material changes, and offer objection mechanisms where required by contract or law.
Assistance and requests
The provider will provide reasonable assistance, taking into account the nature of processing and information available, for data-subject requests, security obligations, data-protection impact assessments, breach response, and deletion or return of customer personal data.
The customer remains responsible for validating the legal basis, notices, consents, records of processing, data-subject response obligations, and use of the Service for the customer's specific environment.
Breach notice
The provider should notify affected customers without undue delay after confirming a security incident involving customer personal data, subject to law enforcement delay, security needs, and reasonable investigation.
A final DPA should define notice channels, required content, timing, cooperation, remediation responsibilities, and exclusions for unsuccessful attacks or customer-caused incidents.
Deletion and return
At termination or on documented instruction, the provider will delete or return customer personal data according to the Service's deletion controls, backup limits, legal holds, security needs, and legal obligations.
Metadata-only evidence may be retained where necessary for billing, security, audit integrity, legal, tax, accounting, dispute, compliance, or non-reconstructive deletion-verification purposes.
International transfers
If personal data is transferred internationally, the final DPA should include the appropriate standard contractual clauses, UK addendum, transfer impact assessment process, supplementary measures, and subprocessor transfer commitments.
No international transfer mechanism is implied by this draft until counsel has reviewed the actual provider stack and customer geography.