Data Processing Addendum
Last updated: [EFFECTIVE DATE]
This is a template, not legal advice.
Every bracketed placeholder below (company name, jurisdiction, notice address, effective date, sub-processor list) needs to be filled in, and the whole document needs review by a licensed attorney in your jurisdiction — including EU/UK counsel if you have or expect clients there — before it governs a real customer relationship.
This Data Processing Addendum (“DPA”) forms part of the Terms of Servicebetween [LEGAL COMPANY NAME] (“Processor”, “we”) and the business using the Service (“Controller”, “Customer”). It applies whenever Processor processes personal data on Customer’s behalf in the course of providing the [PRODUCT NAME] Service — specifically, the names, phone numbers, and order records Customer’s own end-customers generate inside Customer’s account. It is drafted to reflect Article 28 of the EU General Data Protection Regulation (GDPR) and equivalent UK GDPR obligations; a Customer subject to other data-protection regimes (e.g. US state privacy laws) should confirm with counsel whether an equivalent addendum is separately required.
1. Roles
For the personal data described above, Customer is the data controller and Processor acts only as processor, processing that data solely on Customer’s documented instructions (given through Customer’s use of the Service’s features) and for no other purpose, except where required by law.
2. Subject matter, nature, and duration of processing
- Subject matter: provision of the [PRODUCT NAME] rental-management Service.
- Nature and purpose: storage, retrieval, and display of booking/order records so Customer can operate its rental business.
- Duration: for as long as Customer’s account is active, plus the retention period in Section 8.
- Categories of data subjects:Customer’s own end-customers (people who rent from Customer).
- Categories of personal data: name, phone number, and rental/order history. Processor does not require, and Customer should not enter, special categories of data (GDPR Art. 9) into free-text fields.
3. Processor obligations
Processor shall:
- process personal data only on Customer’s documented instructions;
- ensure personnel with access are bound by confidentiality obligations;
- implement appropriate technical and organizational security measures (see Section 6), taking into account the state of the art and the risk to data subjects;
- assist Customer, insofar as reasonably possible, in responding to data subject rights requests;
- assist Customer with its own obligations around security, breach notification, and impact assessments, to the extent Processor’s processing makes that relevant;
- notify Customer without undue delay after becoming aware of a personal data breach affecting Customer’s data (see Section 7);
- at Customer’s choice, delete or return all personal data on termination (see Section 8), except where retention is required by law;
- make available information reasonably necessary to demonstrate compliance with this DPA, and allow for audits as described in Section 9.
4. Sub-processors
Customer authorizes Processor to engage the sub-processors listed in the Privacy Policy(application hosting, database hosting, and related infrastructure providers). Processor will impose data-protection obligations on each sub-processor materially equivalent to this DPA, and remains responsible for their performance. Processor will give Customer [NOTICE PERIOD, e.g. 30 days’] notice of any new sub-processor via [NOTIFICATION METHOD, e.g. email or a change log], during which Customer may object on reasonable data-protection grounds.
5. International transfers
[State here whether Customer data is kept in a single region (e.g. the EU) or may be transferred elsewhere. If data is transferred outside the EEA/UK, this section needs the actual transfer mechanism relied on — e.g. the EU Standard Contractual Clauses (Controller-to-Processor module) incorporated by reference, or an adequacy decision — inserted here by counsel, not assumed.]
6. Security measures
Processor maintains the following measures (adjust to match what is actually implemented):
- encryption of data in transit (HTTPS/TLS);
- per-customer database isolation — each Customer’s data lives in a separate database, not a shared table;
- hashed, salted password storage; no plaintext credentials at rest;
- role-based access control and audit logging of administrative actions within the Service;
- rate-limited authentication and, where enabled, two-factor authentication for account holders;
- regular backups. [Confirm actual backup frequency/retention and whether backups are stored offsite before publishing.]
7. Breach notification
Processor will notify Customer without undue delay, and in any event within [TIME PERIOD, e.g. 72 hours] of becoming aware, of any confirmed personal data breach affecting Customer’s data, providing the information reasonably available to help Customer meet its own notification obligations (including to supervisory authorities and data subjects, where Customer determines that is required).
8. Deletion and return of data
On termination of the Service, Customer may export all of its data (including end-customer data) via the Service’s built-in export feature. Processor will delete Customer’s data, including end-customer data, within [RETENTION PERIOD, e.g. 30 days] of termination, except to the extent retention is required by applicable law.
9. Audits
Processor will make available information reasonably necessary to demonstrate compliance with this DPA and, on reasonable prior notice and no more than [FREQUENCY, e.g. once per year], allow for and contribute to an audit conducted by Customer or an auditor it appoints, subject to confidentiality and reasonable scheduling constraints.
10. Liability
Liability under this DPA is subject to the limitations and exclusions in the Terms of Service, except where such limitations are not permitted by applicable data-protection law.
11. Contact
Data protection queries: [CONTACT EMAIL]. [If a Data Protection Officer is appointed, name/contact here.]
