Template — review by legal counsel before launch; bracketed fields must be completed.
Data Processing Agreement
Last updated: [DATE]
This Data Processing Agreement ("DPA") forms part of the agreement between [COMPANY LEGAL NAME] ("Processor", "we") and the customer identified in the applicable order or account ("Controller", "you") for use of capsend. It reflects the requirements of Article 28 of the EU General Data Protection Regulation (GDPR) and applies whenever we process personal data on your behalf as part of the Service.
1. Roles of the Parties
You act as the data controller for personal data you upload to your workspace and for personal data your recipients provide when viewing your links (for example, an email address entered at an email gate). We act as the data processor, processing such personal data only on your documented instructions, as set out in this DPA and our Terms of Service.
2. Subject Matter and Duration
The subject matter of processing is the provision of the capsend Service — hosting, transmitting, and analyzing workspace content and viewer interactions with shared links. This DPA remains in effect for as long as we process personal data on your behalf under the Terms of Service, and terminates automatically when that processing ends.
3. Nature and Purpose of Processing
We process personal data to: store and serve the decks, files, and data rooms you upload; generate per-slide and per-visitor view analytics; apply dynamic watermarks and record NDA acceptance where you enable those features; send view notifications and digests to your team; and operate account, billing, and support functions for your workspace.
4. Categories of Data Subjects and Personal Data
Processing under this DPA may concern:
- Data subjects: your workspace members, and the recipients/viewers of your shared links.
- Personal data: names and email addresses of workspace members; email addresses and coarse location of viewers who open a gated link; content of uploaded decks, files, and data rooms to the extent it contains personal data; and access/analytics logs (timestamps, IP-derived location, slide/page engagement).
5. Subprocessors
You authorize us to engage the following subprocessors, each bound by data protection terms materially equivalent to this DPA:
| Processor | Location |
|---|---|
| Vercel — hosting | USA / EU |
| Neon — database | DE (Frankfurt) |
| Cloudflare R2 — object storage | EU |
| Stripe — payments | USA / IE |
| Resend — transactional email | USA / EU |
| Upstash — rate limiting | EU |
We will notify you of any intended change concerning the addition or replacement of subprocessors, giving you the opportunity to object on reasonable data-protection grounds within [NOTICE PERIOD] days, by writing to [DATA PROTECTION CONTACT EMAIL].
6. Technical and Organisational Measures
We maintain technical and organisational measures ("TOMs") appropriate to the risk, including: encryption of data in transit (TLS) and at rest; access controls limiting data access to personnel who need it to operate the Service; logical isolation of customer workspaces; hosting of primary database and file storage within the EU (Frankfurt, DE and EU object storage regions); and regular review of subprocessor security posture. We ensure that personnel authorized to process personal data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality (Art. 28(3)(b) GDPR). A detailed TOMs annex is available on request at [DATA PROTECTION CONTACT EMAIL].
7. Assistance with Data Subject Rights
Taking into account the nature of the processing, we will assist you, insofar as reasonably possible, in responding to requests from data subjects exercising their rights under Chapter III of the GDPR, and in meeting your obligations under Articles 32 to 36 GDPR (security, breach notification, impact assessments, and consultation with supervisory authorities).
8. Personal Data Breach Notification
We will notify you without undue delay after becoming aware, and in any event within [BREACH NOTIFICATION PERIOD] hours, of a personal data breach affecting data processed under this DPA, and will provide the information reasonably necessary for you to meet your own notification obligations.
9. Audit Rights
We will make available to you all information reasonably necessary to demonstrate compliance with this DPA and Article 28 GDPR, and will allow for and contribute to audits, including inspections, conducted by you or an auditor you mandate, subject to reasonable advance notice, confidentiality, and no more than [AUDIT FREQUENCY] per year unless required by a supervisory authority.
10. Deletion and Return of Data
On termination of the Service, we will, at your choice, delete or return all personal data processed on your behalf, and delete existing copies, within [DELETION PERIOD] days, unless applicable law requires continued storage.
11. International Transfers
Where a subprocessor listed above processes personal data outside the EEA, we rely on Standard Contractual Clauses or another valid transfer mechanism recognized under GDPR Chapter V.
12. Liability and Governing Law
Liability under this DPA is governed by the limitation of liability provisions in the underlying Terms of Service. This DPA is governed by the laws of [GOVERNING LAW], consistent with the Terms of Service.
Countersigned Copy
This template DPA applies by reference to your use of the Service. If your organization requires a countersigned copy for internal records, request one at [DATA PROTECTION CONTACT EMAIL] and we will return a signed version with your entity details completed.