Draft. These documents are not final. Text in [brackets] is filled in once the business details are set, and a lawyer should review everything before paid plans launch.

Data Processing Addendum

Last updated September 24, 2026

This Data Processing Addendum (“DPA”) is part of the Terms of Service between the Customer and [Company legal name] (“we”, “us”). It applies automatically whenever we process Customer Personal Data. Customers who need a countersigned copy can ask at [support email].

1. Definitions

  • Customer Personal Data means personal data or personal information within Customer Data that we process for the Customer.
  • Data Protection Laws means the laws that apply to that processing, including the California Consumer Privacy Act as amended and its regulations (“CCPA”), and where they apply, the EU and UK General Data Protection Regulations.
  • Terms such as controller, processor, business, service provider, and personal data breach have the meanings given in the Data Protection Laws. Other capitalized terms have the meanings in the Terms.

2. Roles and instructions

  • The Customer is the controller and business. We are the processor and service provider.
  • We process Customer Personal Data only on the Customer's documented instructions: the Terms, this DPA, and the Customer's use and settings of the Service. We will tell the Customer if we believe an instruction breaks the law.
  • Annex 1 describes the processing.

3. California service provider terms

The Customer discloses Customer Personal Data to us only for the limited and specified purpose of providing the Service. We will:

  1. not sell or share Customer Personal Data;
  2. not retain, use, or disclose it for any purpose, including any commercial purpose, other than providing the Service as specified in the Terms, or as the CCPA otherwise permits;
  3. not retain, use, or disclose it outside the direct business relationship between us and the Customer;
  4. not combine it with personal information we receive from others or collect from our own interactions with people, except as the CCPA permits;
  5. comply with the CCPA and provide the same level of privacy protection the CCPA requires of businesses;
  6. notify the Customer if we decide we can no longer meet our CCPA obligations; and
  7. let the Customer take reasonable and appropriate steps to make sure we use Customer Personal Data consistently with the Customer's CCPA obligations and, after notice, to stop and fix any unauthorized use.

We certify that we understand these restrictions and will comply with them.

4. Confidentiality

Anyone we authorize to process Customer Personal Data is bound by confidentiality and has access only as needed to provide the Service.

5. Security

We maintain appropriate technical and organizational measures to protect Customer Personal Data, including those summarized in Annex 2 and on our Security page.

6. Subprocessors

  • The Customer authorizes us to use the subprocessors listed on our Subprocessors page.
  • We bind each subprocessor to data protection terms at least as protective as this DPA and remain responsible for its performance.
  • We update the list before a new subprocessor handles Customer Personal Data. The Customer may object on reasonable data protection grounds within 30 days. If we can't resolve the objection, the Customer may end the affected Service and receive a refund of prepaid fees for the rest of the term.

7. Help with requests and assessments

  • The Service lets the Customer export and delete data directly. We will forward any request we receive from an individual about Customer Personal Data to the Customer, and help the Customer respond as reasonably needed.
  • We will give reasonable help with data protection impact assessments and consultations with regulators about the Service.

8. Personal data breaches

We will notify the Customer without undue delay, and no later than 72 hours after becoming aware of a personal data breach affecting Customer Personal Data. The notice will include the information reasonably available to us, and we will take reasonable steps to contain and fix the breach.

9. Return and deletion

The Customer can export its data at any time. When the Customer deletes its workspace or the Terms end, we delete Customer Personal Data from our live systems right away and from backups within 30 days, unless the law requires us to keep it.

10. Audits

We will provide the information reasonably needed to show compliance with this DPA, such as answers to a security questionnaire. Once a year, with 30 days' notice, an Enterprise customer may audit our compliance at its own cost, under confidentiality, in a way that does not disrupt the Service or expose other customers' data.

11. International transfers

Customer Personal Data is stored and processed in the United States. Where Data Protection Laws require a transfer mechanism for data from the European Economic Area, the United Kingdom, or Switzerland, the European Commission's Standard Contractual Clauses are incorporated into this DPA, with the Customer as data exporter and us as data importer, using Module 2 (controller to processor) or Module 3 (processor to processor) as applicable. For the Clauses: Clause 7 applies; Clause 9 uses option 2, with the notice period in section 6; the optional wording in Clause 11 does not apply; Clauses 17 and 18 select Irish law and the courts of Ireland; and Annexes I and II are Annexes 1 and 2 of this DPA. For UK data, the UK International Data Transfer Addendum applies, and for Swiss data, the Clauses apply with the amendments the Swiss Federal Data Protection and Information Commissioner requires.

12. Liability and order of precedence

Each party's liability under this DPA is subject to the limits in the Terms. If this DPA conflicts with the Terms, this DPA controls for the processing of Customer Personal Data.

Annex 1: Description of the processing

  • Subject matter: providing the Service to the Customer.
  • Duration: the term of the Terms, plus the deletion period in section 9.
  • Nature and purpose: hosting, storing, displaying, and transmitting data to provide the Service.
  • People concerned: the Customer's Authorized Users, such as employees and contractors, and anyone the Customer names in its templates.
  • Types of data: names, work email addresses, roles, time zones, preferences, activity such as template copies and last active time, IP addresses used for security, and any personal data the Customer puts in templates.
  • Sensitive data: none is intended. The Customer should not put sensitive personal data into templates.
  • Frequency: continuous, while the Customer uses the Service.

Annex 2: Security measures

  • Encryption of data in transit with TLS and at rest by our infrastructure providers.
  • Passwords hashed with bcrypt. Session tokens stored only as SHA-256 hashes.
  • Rate limits on sign-in, signup, and contact forms.
  • Every query scoped to the Customer's workspace, and access checks on every page, action, and export.
  • Template content sanitized against an allowlist before it is stored.
  • Managed database backups with point-in-time recovery.
  • Access to production systems limited to the people who run the Service.