CTRL / PROC
LEGAL / DPA WORKING TEMPLATE
A transparent DPA template for future customer agreements.
This working template maps the clauses a completed Data Processing Addendum must contain. It is not signed, effective or ready for execution until the contracting party and schedules are completed.
Ask about the DPA template↗01
Template status and completion
Before this template can be used, it must identify the legal parties, addresses, effective date, governing arrangement and authorised signatories. The completed document should receive jurisdiction-specific legal review.
- 01No contracting party inserted↗
- 02No signature or effective date↗
- 03Legal review required before execution↗
02
Proposed roles and instructions
The intended model treats the customer as controller for workspace content and the service operator as processor. Final language must limit processing to documented, lawful instructions needed to provide, secure and support the service.
- 01Customer determines purpose↗
- 02Processor follows documented instructions↗
- 03Unlawful instructions must be rejected↗
03
Processing schedule
A completed schedule must specify data subjects, data categories, purposes, processing activities, duration and retention. Likely categories include account, membership, task, contact, time, finance, support and service-log data.
- 01Data subjects and categories↗
- 02Purpose and processing activity↗
- 03Duration, retention and deletion↗
04
Security and confidentiality schedule
The final schedule must describe technical and organisational measures that accurately reflect the service at signing. Public security information is context, not a certification or substitute for the completed schedule.
- 01Need-to-know access↗
- 02Confidentiality obligations↗
- 03Verified technical and organisational measures↗
05
Subprocessors and transfers
Before execution, the template must list the actual providers used for hosting, database, email, payment or support, together with purpose, processing region, contractual safeguards and the change-notification process.
- 01Current provider list↗
- 02Purpose and processing region↗
- 03Transfer and change safeguards↗
06
Rights, incidents and end of service
The completed DPA must define assistance with data-subject requests, incident notification, deletion or return, compliance evidence and proportionate audit conditions without exposing other customers or system security.
- 01Request and incident cooperation↗
- 02Deletion or return terms↗
- 03Controlled verification rights↗
CLEAR TERMS / DIRECT CONTACT
Need a precise answer? Ask us directly.