Effective Date: May 31, 2026 | Template for GDPR & CCPA-aligned review
Legal Notice
This DPA template should be reviewed by qualified legal counsel before being shown to enterprise customers to ensure it matches actual data handling practices and applicable laws, including GDPR, CCPA, and other regional regulations.
1. Introduction and Definitions
This Data Processing Agreement ("DPA") forms part of the Terms of Service between ContractLab ("Processor" or "we") and you ("Controller" or "Customer") and governs the processing of Personal Data in accordance with applicable Data Protection Laws, including the EU General Data Protection Regulation (GDPR) and California Consumer Privacy Act (CCPA).
Definitions:
"Personal Data" means any information relating to an identified or identifiable natural person that is processed by Processor on behalf of Controller in connection with the Services.
"Data Protection Laws" means all applicable laws and regulations relating to privacy and data protection, including GDPR, CCPA, and equivalent laws.
"Data Subject" means the individual to whom Personal Data relates.
"Processing" means any operation performed on Personal Data, including collection, storage, use, disclosure, or deletion.
"Sub-processor" means any third party engaged by Processor to process Personal Data on behalf of Controller.
2. Scope and Roles
Controller Responsibilities:
You, as the Controller, are responsible for:
Determining the purposes and means of processing Personal Data
Ensuring you have a valid legal basis for processing Personal Data
Obtaining necessary consents from Data Subjects
Providing required notices to Data Subjects
Ensuring accuracy of Personal Data provided to us
Processor Responsibilities:
We, as the Processor, will:
Process Personal Data only on documented instructions from you
Implement appropriate technical and organizational security measures
Assist you in responding to Data Subject requests
Notify you of any Personal Data breaches without undue delay
Delete or return Personal Data upon termination of services
3. Processing Instructions
We will process Personal Data only in accordance with your documented instructions, which include:
Processing necessary to provide the Services as described in our Terms of Service
Processing initiated by you or your authorized users through use of the Services
Processing specified in this DPA
Other written instructions as may be agreed upon in writing
If we believe an instruction violates applicable Data Protection Laws, we will inform you without undue delay.
4. Types of Personal Data and Data Subjects
Categories of Personal Data
Contact information (name, email, phone)
Account credentials
Usage data and analytics
Contract documents and metadata
Payment information (processed by third-party)
Communication records
IP addresses and device information
Categories of Data Subjects
Customer employees and authorized users
Customer's clients and contractors
Individuals named in contracts
Prospective customers
Website visitors
Support ticket submitters
5. Security Measures
We implement appropriate technical and organizational measures to protect Personal Data:
Encryption
AES-256 encryption at rest, TLS 1.3 in transit
Access Controls
Role-based access, multi-factor authentication, least privilege principle
Data Segregation
Customer data logically segregated in multi-tenant environment
Security Audits
SOC 2 Type II certified, annual penetration testing
6. Sub-processors
We may engage Sub-processors to assist in providing the Services. Current Sub-processors include:
Sub-processor
Purpose
Location
Amazon Web Services
Cloud hosting
US, EU
Stripe
Payment processing
US
SendGrid
Email delivery
US
OpenAI
AI contract analysis
US
We will notify you of any new Sub-processors at least 30 days in advance. You may object to new Sub-processors on reasonable grounds relating to data protection.
7. International Data Transfers
Personal Data may be transferred to and processed in countries outside the European Economic Area (EEA). We ensure adequate protection through:
Standard Contractual Clauses (SCCs) approved by the European Commission
Adequacy decisions for certain jurisdictions
Binding Corporate Rules where applicable
Additional safeguards as required by applicable laws
8. Data Subject Rights
We will assist you in responding to Data Subject requests, including:
Access: Providing copies of Personal Data
Rectification: Correcting inaccurate Personal Data
Erasure: Deleting Personal Data ("right to be forgotten")
Restriction: Limiting processing of Personal Data
Portability: Providing Personal Data in machine-readable format
Objection: Objecting to certain types of processing
If we receive a Data Subject request directly, we will promptly inform you and await your instructions before responding.
9. Data Breach Notification
In the event of a Personal Data breach, we will:
Notify you without undue delay and no later than 24 hours after becoming aware
Provide details of the breach, including affected Data Subjects and data categories
Describe likely consequences and mitigation measures taken
Cooperate with you in any required notifications to supervisory authorities
Provide regular updates as investigation progresses
10. Data Retention and Deletion
Upon termination or expiration of the Services:
We will delete or return all Personal Data within 30 days unless prohibited by law
You may request data export in standard format before deletion
Backup copies will be securely destroyed within 90 days
We may retain metadata for legitimate business purposes (e.g., financial records) as required by law
11. Audit Rights
Upon reasonable notice and no more than once per year, you may audit our compliance with this DPA through:
Review of our SOC 2 Type II reports and security certifications
Written questionnaires about our data protection practices
On-site audits (at your expense) subject to confidentiality obligations
12. Liability and Indemnification
Each party's liability under this DPA is subject to the limitations and exclusions set forth in the Terms of Service. We will indemnify you against fines and penalties imposed by supervisory authorities resulting solely from our breach of this DPA, subject to the terms of our Terms of Service.
13. Term and Termination
This DPA will remain in effect for as long as we process Personal Data on your behalf. Upon termination, the data deletion provisions in Section 10 will apply.
14. Contact Information
For DPA-related inquiries:
Data Protection Officer: dpo@contractlab.dev
Privacy Team: privacy@contractlab.dev
Mailing Address: ContractLab, Data Protection Team, [Address]