Skip to main content

Data Processing Addendum (outline)

Draft outline — last updated for Phase 3C.

Template — not legal advice. This page is a starting-point draft, not a document a lawyer has reviewed or approved for this business. It must be reviewed by qualified counsel before this product is offered commercially, and nothing on this page should be taken as a claim of legal or regulatory compliance.

This is a structural OUTLINE of the sections a real Data Processing Addendum (DPA) would need — it is not a signable legal document. A Business-plan customer requiring a DPA should contact us directly; this outline exists to show what such an agreement would cover once drafted by counsel.

Anticipated sections

  1. Definitions — controller, processor, personal data, sub-processor, as defined by applicable law (e.g. GDPR Art. 4).
  2. Scope and roles — customer as controller, ProcessKit as processor, for the personal data customers submit as recorded-workflow content.
  3. Processing instructions — processing limited to providing the Service per the customer's configuration and these instructions.
  4. Confidentiality — personnel obligations.
  5. Security measures — reference to our documented security practices.
  6. Sub-processors — reference to the Subprocessors list, with a notice mechanism for changes.
  7. International transfers — mechanism (e.g. Standard Contractual Clauses) if applicable.
  8. Data subject requests — how the processor assists the controller in responding to them.
  9. Breach notification — timeline and process commitments.
  10. Deletion/return of data — reference to our documented account/organization deletion behavior and its 30-day recovery window.
  11. Audit rights — scope and process.

[Placeholder — none of the above is a commitment until a real DPA is drafted by qualified counsel, reviewed against applicable law, and signed by both parties.]

Contact

Request a DPA: support@processkit.local