Last updated: [DATE]
This Data Processing Agreement (“DPA”) is entered into between [COMPANY NAME] (“Processor”, “we”), based in [JURISDICTION], and the business entity that has registered a tenant account for the Service (“Controller”, “you”). It supplements and is incorporated by reference into our Terms of Service, and applies whenever we process personal data on your behalf as part of the Service.
The subject matter, duration, nature, and purpose of processing, the categories of data subjects, and the categories of Personal Data are set out in Appendix A. This DPA remains in effect for as long as we process End Customer Data on your behalf under the Terms of Service.
We will:
You authorize us to engage the Sub-processors listed in Appendix B as of the date of this DPA. We will give you notice of any intended addition or replacement of a Sub-processor at least [NOTICE PERIOD, e.g. 30 days] in advance (e.g. by email or in-app notice), giving you an opportunity to object on reasonable data-protection grounds. Each Sub-processor is bound by written terms that impose data protection obligations no less protective than this DPA, and we remain liable for each Sub-processor’s performance of those obligations.
Where processing of End Customer Data involves a transfer outside the EEA/UK, such transfer will be made subject to an appropriate safeguard recognized under Applicable Data Protection Law (e.g. the EU Standard Contractual Clauses, the UK International Data Transfer Addendum, or an adequacy decision) — [CONFIRM ACTUAL MECHANISM WITH COUNSEL AND EACH SUB-PROCESSOR’S OWN TRANSFER TERMS before relying on this clause].
We will notify you without undue delay, and in any event within [TIMEFRAME, e.g. 72 hours] of becoming aware, after becoming aware of a Personal Data Breach affecting End Customer Data, and will provide information reasonably necessary for you to meet any breach-notification obligations you have to a supervisory authority or affected data subjects.
[Liability, indemnification, and limitation-of-liability terms for this DPA — coordinate with the Limitation of Liability clause in the Terms of Service and get counsel review. Not drafted here; a generic clause risks either under-protecting you or creating unintended exposure.]
This DPA takes effect on the date you accept the Terms of Service and continues until the Service is terminated and all End Customer Data has been deleted or returned under §3.
This DPA is governed by the laws of [JURISDICTION], consistent with the Terms of Service.
Questions about this DPA, Sub-processor changes, or to exercise an audit right: [SUPPORT EMAIL].
This list must be kept in sync with the subprocessor list in the Privacy Policy — treat one as the source of truth and link the other, rather than maintaining both independently.