Data Processing Addendum · {{COMPANY_NAME}}

Last updated: 2026-06-02 · v2.0 · This DPA forms part of the Agreement between you and {{COMPANY_NAME}}

Background. This Data Processing Addendum ("DPA") sets out the terms governing the processing of personal data under the GDPR and applies where {{COMPANY_NAME}} processes personal data on behalf of the Customer in connection with the services provided under the Agreement. This DPA prevails over any conflicting terms in the Agreement.

1. Parties and Definitions

1.1 Definitions

In this DPA, the following terms have the meanings set out below:

1.2 Roles

The parties acknowledge and agree that:

2. Scope and Applicability

This DPA applies to the processing of Personal Data in connection with the services described in the Agreement. It applies to all processing activities where {{COMPANY_NAME}} acts as data processor for the Customer.

This DPA does not apply where the Customer processes Personal Data as a data processor (acting on behalf of its own customers) — in such cases, the Customer remains responsible for ensuring it has the necessary agreements in place with its own customers.

3. Processing Obligations

3.1 Instructions

{{COMPANY_NAME}} shall process Personal Data only on the documented instructions of the Customer. Processing outside the scope of the Agreement (including any amendments agreed in writing) requires prior written consent from the Customer.

3.2 Purpose Limitation

{{COMPANY_NAME}} shall process Personal Data only for the specific purposes of providing the services under the Agreement: account management, service delivery, technical support, billing, and security. Processing for any other purpose requires the Customer's written consent.

3.3 Data Minimization

{{COMPANY_NAME}} shall process only the minimum Personal Data necessary for the purposes of the Agreement. Where technically feasible, Personal Data shall be anonymized or pseudonymized to reduce risk.

3.4 Accuracy

{{COMPANY_NAME}} is not responsible for ensuring the accuracy of Personal Data. The Customer is responsible for ensuring that Personal Data is accurate and up to date before submitting it for processing.

3.5 Storage Limitation

Personal Data shall not be retained beyond the periods specified in the Agreement and Privacy Policy, subject to legal retention obligations. Upon termination or Customer request, {{COMPANY_NAME}} shall delete or return Personal Data as specified in Section 10.

3.6 Documentation

{{COMPANY_NAME}} shall maintain records of processing activities in accordance with GDPR Art. 30, including: the name and contact details of the controller and processor, the categories of processing, the categories of data subjects, the categories of Personal Data, the purposes of processing, and the security measures applied.

4. Sub-Processors

4.1 Authorized Sub-Processors

The Customer authorizes {{COMPANY_NAME}} to engage the following categories of Sub-processors: cloud infrastructure providers (e.g., Cloudflare), payment processors (e.g., Stripe), email delivery providers (e.g., Resend), and AI model providers (e.g., OpenAI, Anthropic, Google).

A complete list of Sub-processors is available at /sub-processors and is updated at least annually. Notification of material changes to the Sub-processor list will be provided at least 30 days in advance.

4.2 Sub-processor Obligations

{{COMPANY_NAME}} shall impose data protection obligations on Sub-processors that are at least as stringent as those in this DPA, including requiring them to provide appropriate technical and organizational security measures (GDPR Art. 32).

4.3 Objection Right

The Customer may object to a new Sub-processor by notifying {{COMPANY_NAME}} in writing within 14 days of receiving notice of the new Sub-processor. {{COMPANY_NAME}} will work with the Customer in good faith to find an alternative solution or waive the objection.

5. Security Measures

5.1 Technical Measures

{{COMPANY_NAME}} implements appropriate technical security measures, including:

5.2 Organizational Measures

5.3 Security Certifications

{{COMPANY_NAME}} maintains the following security certifications and assessments: [List applicable certifications, e.g., SOC 2 Type II, ISO 27001, annual penetration test results — insert if available].

6. Data Subject Rights

6.1 Assistance

{{COMPANY_NAME}} shall, taking into account the nature of the processing, assist the Customer in fulfilling its obligations under GDPR Arts. 12–22 to respond to data subject requests, including:

The Customer may request assistance by contacting {{CONTACT_EMAIL}}. {{COMPANY_NAME}} shall respond to assistance requests within 7 business days.

6.2 Automated Decision-Making

If {{COMPANY_NAME}} performs processing that constitutes automated decision-making (including profiling) with legal or similarly significant effects, {{COMPANY_NAME}} shall implement mechanisms to allow data subjects to request human intervention, express their point of view, and contest the decision, in accordance with GDPR Art. 22.

7. Data Breach Notification

7.1 Notification

{{COMPANY_NAME}} shall notify the Customer without undue delay and at the latest within 48 hours of becoming aware of a Personal Data Breach, providing:

7.2 Documentation

{{COMPANY_NAME}} shall document all Personal Data Breaches, including their nature, effects, and remedial actions taken, and make this documentation available to the supervisory authority upon request.

8. International Transfers

8.1 Transfer Mechanisms

Personal Data shall not be transferred to a country outside the EEA unless one of the following legal mechanisms is in place:

A copy of the applicable SCCs is available upon request at {{CONTACT_EMAIL}}.

8.2 Transfer Documentation

{{COMPANY_NAME}} shall maintain records of transfers of Personal Data outside the EEA, including the transfer mechanism used, the destination country, and the safeguards applied.

9. Audits and Inspections

9.1 Audit Rights

The Customer is entitled to verify {{COMPANY_NAME}}'s compliance with this DPA through:

9.2 Audit Response

{{COMPANY_NAME}} shall provide the Customer with all information necessary to demonstrate compliance with this DPA and allow for and contribute to audits, including inspections, conducted by the Customer or an independent auditor mandated by the Customer.

10. Termination and Deletion

10.1 Termination

This DPA remains in effect for the duration of the Agreement. Upon termination, {{COMPANY_NAME}} shall, at the Customer's election:

10.2 Retention Exception

{{COMPANY_NAME}} may retain Personal Data beyond termination solely where required by EU or national law, and only for the minimum period necessary. {{COMPANY_NAME}} shall notify the Customer of any such required retention.

11. Liability

{{COMPANY_NAME}}'s liability under this DPA and the GDPR shall be limited in accordance with the liability provisions in the Agreement, subject to the following:

{{COMPANY_NAME}} shall be liable for damages arising from its processing in violation of the GDPR, where {{COMPANY_NAME}} acted without instructions from the Customer or acted outside those instructions.

{{COMPANY_NAME}} shall be exempt from liability if it proves it is not at fault, in particular where the Customer failed to provide accurate instructions or the damage was caused by the Customer or a third party.

12. Governing Law

This DPA is governed by the same law and jurisdiction as the Agreement. Disputes arising from this DPA shall be resolved in the courts specified in the Agreement.

The parties agree to cooperate in good faith to resolve any disputes relating to this DPA, including engaging in the dispute resolution procedures specified in the Agreement before commencing litigation.

13. Signatures

Accepted and agreed by:

{{COMPANY_NAME}}
Name: ___________________________
Title: ___________________________
Date: ___________________________
Signature: ___________________________

Customer:
Company: ___________________________
Name: ___________________________
Title: ___________________________
Date: ___________________________
Signature: ___________________________

v2.0 · 2026-06-02 · Legal Templates by Mimo for {{COMPANY_NAME}}'s multi-company portfolio