ContractLabBack to ContractLab

Data Processing Agreement

Effective Date: May 31, 2026 | Template for GDPR & CCPA-aligned review

Legal Notice

This DPA template should be reviewed by qualified legal counsel before being shown to enterprise customers to ensure it matches actual data handling practices and applicable laws, including GDPR, CCPA, and other regional regulations.

1. Introduction and Definitions

This Data Processing Agreement ("DPA") forms part of the Terms of Service between ContractLab ("Processor" or "we") and you ("Controller" or "Customer") and governs the processing of Personal Data in accordance with applicable Data Protection Laws, including the EU General Data Protection Regulation (GDPR) and California Consumer Privacy Act (CCPA).

Definitions:

  • "Personal Data" means any information relating to an identified or identifiable natural person that is processed by Processor on behalf of Controller in connection with the Services.
  • "Data Protection Laws" means all applicable laws and regulations relating to privacy and data protection, including GDPR, CCPA, and equivalent laws.
  • "Data Subject" means the individual to whom Personal Data relates.
  • "Processing" means any operation performed on Personal Data, including collection, storage, use, disclosure, or deletion.
  • "Sub-processor" means any third party engaged by Processor to process Personal Data on behalf of Controller.

2. Scope and Roles

Controller Responsibilities:

You, as the Controller, are responsible for:

  • Determining the purposes and means of processing Personal Data
  • Ensuring you have a valid legal basis for processing Personal Data
  • Obtaining necessary consents from Data Subjects
  • Providing required notices to Data Subjects
  • Ensuring accuracy of Personal Data provided to us

Processor Responsibilities:

We, as the Processor, will:

  • Process Personal Data only on documented instructions from you
  • Implement appropriate technical and organizational security measures
  • Assist you in responding to Data Subject requests
  • Notify you of any Personal Data breaches without undue delay
  • Delete or return Personal Data upon termination of services

3. Processing Instructions

We will process Personal Data only in accordance with your documented instructions, which include:

  • Processing necessary to provide the Services as described in our Terms of Service
  • Processing initiated by you or your authorized users through use of the Services
  • Processing specified in this DPA
  • Other written instructions as may be agreed upon in writing

If we believe an instruction violates applicable Data Protection Laws, we will inform you without undue delay.

4. Types of Personal Data and Data Subjects

Categories of Personal Data

  • Contact information (name, email, phone)
  • Account credentials
  • Usage data and analytics
  • Contract documents and metadata
  • Payment information (processed by third-party)
  • Communication records
  • IP addresses and device information

Categories of Data Subjects

  • Customer employees and authorized users
  • Customer's clients and contractors
  • Individuals named in contracts
  • Prospective customers
  • Website visitors
  • Support ticket submitters

5. Security Measures

We implement appropriate technical and organizational measures to protect Personal Data:

Encryption

AES-256 encryption at rest, TLS 1.3 in transit

Access Controls

Role-based access, multi-factor authentication, least privilege principle

Data Segregation

Customer data logically segregated in multi-tenant environment

Security Audits

SOC 2 Type II certified, annual penetration testing

6. Sub-processors

We may engage Sub-processors to assist in providing the Services. Current Sub-processors include:

Sub-processorPurposeLocation
Amazon Web ServicesCloud hostingUS, EU
StripePayment processingUS
SendGridEmail deliveryUS
OpenAIAI contract analysisUS

We will notify you of any new Sub-processors at least 30 days in advance. You may object to new Sub-processors on reasonable grounds relating to data protection.

7. International Data Transfers

Personal Data may be transferred to and processed in countries outside the European Economic Area (EEA). We ensure adequate protection through:

  • Standard Contractual Clauses (SCCs) approved by the European Commission
  • Adequacy decisions for certain jurisdictions
  • Binding Corporate Rules where applicable
  • Additional safeguards as required by applicable laws

8. Data Subject Rights

We will assist you in responding to Data Subject requests, including:

  • Access: Providing copies of Personal Data
  • Rectification: Correcting inaccurate Personal Data
  • Erasure: Deleting Personal Data ("right to be forgotten")
  • Restriction: Limiting processing of Personal Data
  • Portability: Providing Personal Data in machine-readable format
  • Objection: Objecting to certain types of processing

If we receive a Data Subject request directly, we will promptly inform you and await your instructions before responding.

9. Data Breach Notification

In the event of a Personal Data breach, we will:

  • Notify you without undue delay and no later than 24 hours after becoming aware
  • Provide details of the breach, including affected Data Subjects and data categories
  • Describe likely consequences and mitigation measures taken
  • Cooperate with you in any required notifications to supervisory authorities
  • Provide regular updates as investigation progresses

10. Data Retention and Deletion

Upon termination or expiration of the Services:

  • We will delete or return all Personal Data within 30 days unless prohibited by law
  • You may request data export in standard format before deletion
  • Backup copies will be securely destroyed within 90 days
  • We may retain metadata for legitimate business purposes (e.g., financial records) as required by law

11. Audit Rights

Upon reasonable notice and no more than once per year, you may audit our compliance with this DPA through:

  • Review of our SOC 2 Type II reports and security certifications
  • Written questionnaires about our data protection practices
  • On-site audits (at your expense) subject to confidentiality obligations

12. Liability and Indemnification

Each party's liability under this DPA is subject to the limitations and exclusions set forth in the Terms of Service. We will indemnify you against fines and penalties imposed by supervisory authorities resulting solely from our breach of this DPA, subject to the terms of our Terms of Service.

13. Term and Termination

This DPA will remain in effect for as long as we process Personal Data on your behalf. Upon termination, the data deletion provisions in Section 10 will apply.

14. Contact Information

For DPA-related inquiries:

  • Data Protection Officer: dpo@contractlab.dev
  • Privacy Team: privacy@contractlab.dev
  • Mailing Address: ContractLab, Data Protection Team, [Address]

Related Documents

Privacy PolicySecurity PracticesTerms of ServiceService Level Agreement