Template awaiting legal review — not yet binding.
Data Processing Agreement
Last updated 10 October 2026
Parties and roles
The customer is the controller of personal data in its workspace; [Company legal name] is its processor. This agreement forms part of the Terms of Service.
Instructions
We process customer personal data only on the customer's documented instructions — using the service as configured is such an instruction — unless the law requires otherwise.
Confidentiality and staff
Our staff are bound by confidentiality. They access a workspace only through time-limited support access the customer can see and end, recorded in the workspace's audit log.
Security measures
Separate database and encryption key per workspace; secrets encrypted with keys protected by AWS KMS; TLS everywhere; two-factor sign-in; IP allowlists; least-privilege access to customer AWS accounts within a permissions boundary that forbids reading data contents; audit logging; nightly encrypted backups with restore tests; vulnerability patching and monitoring of our infrastructure.
Sub-processors
As listed in the Privacy Policy. We give 30 days' notice of new sub-processors; the customer may object and terminate if we can't accommodate the objection.
Assistance and breaches
We help the customer answer data-subject requests and carry out impact assessments. We notify the customer without undue delay (target: within 48 hours) after becoming aware of a personal data breach affecting its data.
Return and deletion
At the end of the service the customer can export its data; we then delete the workspace and destroy its encryption key, and backups expire within about 35 days.
Audits
We make available the information needed to demonstrate compliance and allow reasonable audits, once a year, with 30 days' notice.