Legal
Data Processing Agreement
Draft prepared: August 2026
This is a draft, prepared as a starting point and not yet reviewed by a lawyer. It is not binding and should not be relied on as an actual legal document until reviewed and published.
When this applies
If a consulting engagement involves us processing personal data on your behalf — for example, building a system that handles your users' data — and you or your users are covered by a data-protection law like the EU/UK's GDPR or California's CCPA, a Data Processing Agreement (DPA) is signed alongside the service agreement for that engagement.
What it typically covers
- What categories of personal data we'll process, and for what purpose — scoped to the engagement, nothing broader
- That we only process data on your documented instructions
- Confidentiality obligations for anyone on our side with access to the data
- Security measures appropriate to the data involved
- Sub-processor disclosure — if any third-party tool touches the data, you're told which one and why
- What happens to the data at the end of the engagement (deletion or return)
- How we'd assist with a data-subject request or a breach notification, if one occurs
What this page isn't
Same as our NDA and MSA pages — this describes the shape of the agreement, not the agreement itself. The real DPA is a specific, reviewed document, tailored to the actual data involved in your engagement.
Get started
If your project involves personal data covered by GDPR, CCPA, or a similar law, mention that when you reach out so we scope the DPA alongside the rest of the agreement from the start.