Data Processing Addendum
The Article 28 terms that govern personal data we process on your behalf — consent records, privacy rights requests and site scans. It applies automatically to every customer; you do not need to sign anything, though we will countersign a copy if your procurement process needs one.
Scope, parties and precedence
This Data Processing Addendum (DPA) forms part of the Terms of Service (the Agreement) between [to be confirmed before launch], trading as iLawForms (Processor, we) and the customer accepting them (Controller, Customer, you).
It applies where we process personal data on your behalf, and it takes effect automatically when you accept the Agreement. No signature is required. If your procurement process needs a countersigned copy, email privacy@ilawforms.com and we will return one on these terms.
Order of precedence
In the event of conflict, the order is: (1) the Standard Contractual Clauses and the UK Addendum incorporated by International transfers; (2) this DPA; (3) the rest of the Agreement.
Which law applies
Data Protection Law means, as applicable: Regulation (EU) 2016/679 (GDPR); the GDPR as incorporated into UK law by the European Union (Withdrawal) Act 2018 together with the Data Protection Act 2018 (UK GDPR); the Swiss Federal Act on Data Protection; the California Consumer Privacy Act as amended by the CPRA (CCPA); and other US state privacy laws applicable to the processing. Terms such as controller, processor, personal data, processing, data subject and personal data breach have the meanings given in the applicable law.
Roles of the parties
For the personal data described in Annex I, you are the controller and we are the processor. Where you are yourself a processor acting for another controller, we are a sub-processor and you warrant that you have that controller’s authority to appoint us on these terms.
Where we process personal data about you — your account, your billing, your use of the product — we are the controller, this DPA does not apply, and the Privacy Policy governs instead.
Under the CCPA we act as a service provider, and never as a third party. Our specific commitments in that capacity are in California.
Your obligations as controller
You are responsible for, and warrant that:
- you have a lawful basis for the personal data you put into, or route through, the Service;
- you have given data subjects the notices they are entitled to, and obtained any consent required;
- your instructions to us do not require us to breach Data Protection Law;
- the personal data is accurate, and limited to what the purpose needs; and
- you will not use the Service to process special category data under Article 9, criminal offence data under Article 10, or the personal data of children, except where the feature is designed for it and you have told us in advance.
You decide what the Service processes. We have no visibility of, and cannot control, what a visitor types into a free-text field on your site.
Processing only on documented instructions
We process personal data only on your documented instructions, including as to transfers to a third country, unless required to do otherwise by law — in which case we will tell you before processing, unless that law prohibits it on important grounds of public interest.
The Agreement, this DPA, and your use of the Service’s features and settings are your complete documented instructions. Additional instructions outside them must be agreed in writing, and we may charge for work they require.
We will tell you if, in our opinion, an instruction infringes Data Protection Law. We are not obliged to give legal advice about your instructions, and telling you is not advice.
We do not sell personal data, do not use it for our own purposes, do not use it for advertising or profiling, and do not use it to train machine-learning models. It is processed to provide the Service to you, and for nothing else.
Confidentiality
We ensure that everyone authorised to process personal data under this DPA is bound by a duty of confidentiality that survives the end of their engagement, is trained on their obligations, and has access limited to what their role requires. Staff access to production data is individually authenticated and written to an audit log.
Security measures
We implement appropriate technical and organisational measures under Article 32, taking account of the state of the art, the cost of implementation, and the nature, scope, context and purposes of processing, as well as the risk to data subjects. The measures are set out in Annex II and described in more detail on the Security page.
We may update the measures as technology develops. We will not make a change that materially reduces the overall level of protection.
Sub-processors
You give general written authorisation for us to engage sub-processors. The current list, with the processing each performs and where it is located, is at ilawforms.com/legal/subprocessors, which forms Annex III.
Notice and objection
We will give at least 30days’ notice before a new sub-processor starts processing, by email to the address on your account if you have subscribed to notifications on that page, and by updating the page in any event.
You may object on reasonable data-protection grounds within that period. We will work with you in good faith to find an alternative. If we cannot, you may terminate the affected part of the Service without penalty and receive a pro-rata refund of prepaid fees for the unused remainder of your term.
Our responsibility
Each sub-processor is engaged under a written contract imposing data protection obligations no less protective than this DPA. We remain fully liable to you for a sub-processor’s performance of its obligations.
Assisting with data subject requests
Taking account of the nature of the processing, we assist you by appropriate technical and organisational measures, insofar as possible, in fulfilling your obligation to respond to requests to exercise data subject rights. The Service is built for this: the rights-request queue, the consent record export and the document export exist so that you can answer most requests yourself, immediately, without asking us.
If a data subject contacts us directly about personal data we process for you, we will not respond to the substance. We will tell them to contact you, and tell you promptly — unless we are prohibited from doing so.
Personal data breach
We notify you without undue delay, and in any event within 48 hours of becoming aware of a personal data breach affecting personal data we process for you.
Our notification will describe, to the extent known:
- the nature of the breach, including the categories and approximate number of data subjects and records concerned;
- the likely consequences;
- the measures taken or proposed to address it and to mitigate its effects; and
- a contact point for more information.
Where we cannot provide all of that at once, we provide it in phases without further undue delay. We will not delay notification to complete an investigation first.
Notifying you is not an admission of fault. Notifying supervisory authorities and data subjects under Articles 33 and 34 is your responsibility as controller; we will give you the information and assistance you reasonably need to do it in time.
Assistance with impact assessments
Taking account of the nature of processing and the information available to us, we provide reasonable assistance with your data protection impact assessments under Article 35 and prior consultations with a supervisory authority under Article 36. In most cases the information on this page, the Security page and the Sub-processors page is what an assessment needs; if it is not, ask.
Deletion and return
On termination of the Service, and at your choice, we delete or return the personal data we process for you, and delete existing copies, unless law requires us to retain it.
You can export your data yourself at any time while the account is open, which is the fastest route and does not depend on us. Absent a contrary instruction within 30 days of termination, we delete it. Deletion completes within 30 days of the instruction, and data in encrypted backups is overwritten as the 35-day backup cycle ages out. Backups are not restored to serve a request, and any restored backup remains subject to this DPA.
Information and audits
We make available the information necessary to demonstrate compliance with Article 28 and allow for and contribute to audits, including inspections, conducted by you or an auditor you mandate.
In the first instance we will answer a reasonable written security questionnaire, and provide documentation of our measures, within 30 days. Where that is genuinely insufficient, you may conduct an audit on at least 30 days’ written notice, no more than once in any twelve months (unless required by a supervisory authority or following a confirmed breach), during business hours, without unreasonable disruption, and subject to confidentiality. You bear your own costs; we may charge for time beyond one business day.
An audit may not access the data of another customer, and may not include penetration testing of shared infrastructure without our written agreement.
International transfers
We are established in the United States. Where personal data is transferred out of the EEA, the UK or Switzerland to a country without an adequacy decision, the transfer is made under the following, which are incorporated into this DPA by reference and which each party is deemed to have signed:
EU Standard Contractual Clauses
The Standard Contractual Clauses annexed to Commission Implementing Decision (EU) 2021/914, completed as follows:
- Module Two (controller to processor) applies where you are a controller; Module Three (processor to processor) applies where you are a processor acting for another controller.
- Clause 7 (docking clause) applies.
- Clause 9: Option 2, general written authorisation, with the notice period in Sub-processors.
- Clause 11: the optional independent dispute resolution language does not apply.
- Clause 17: Option 1; the Clauses are governed by the law of Ireland.
- Clause 18(b): disputes are resolved before the courts of Ireland.
- Annexes I, II and III to the Clauses are Annex I, Annex II and Annex III below. You are the data exporter; [to be confirmed before launch] is the data importer. The contact details and signature of each party are those in the Agreement.
UK transfers
The International Data Transfer Addendum to the EU Standard Contractual Clauses, version B.1.0, issued by the Information Commissioner under section 119A of the Data Protection Act 2018, applies to transfers subject to the UK GDPR. Table 1 is completed with the parties’ details in the Agreement; Tables 2 and 3 with the Clauses and Annexes above; and in Table 4, neither party may end the Addendum as set out in section 19 of it.
Swiss transfers
For transfers subject to Swiss law, the Standard Contractual Clauses apply with the Federal Data Protection and Information Commissioner as competent supervisory authority, references to the GDPR read as references to the Swiss Federal Act on Data Protection, and the term “member state” read so as not to deprive data subjects in Switzerland of the right to sue in their place of habitual residence.
Government access requests
If we receive a legally binding request from a public authority for personal data we process for you, we will notify you unless prohibited by law; if prohibited, we will use reasonable efforts to obtain a waiver and will document our efforts. We review every such request, challenge those that are overbroad or unlawful, and disclose only the minimum the request lawfully requires. We publish no transparency report at this scale; ask us and we will tell you what we have received.
California — service provider terms
To the extent we process personal information subject to the CCPA on your behalf, you disclose it to us solely for the limited and specified purpose of performing the Service, and we certify that we:
- will not sell or share it, as those terms are defined in the CCPA;
- will not retain, use or disclose it for any purpose other than performing the Service, or as otherwise permitted by the CCPA — including not for our own commercial purposes;
- will not retain, use or disclose it outside the direct business relationship between us;
- will not combine it with personal information received from another source, except as the CCPA permits a service provider to do;
- will comply with the obligations the CCPA places on a service provider and provide the same level of protection it requires;
- will notify you promptly if we determine we can no longer meet these obligations; and
- grant you the right to take reasonable and appropriate steps to stop and remediate unauthorised use.
You may monitor our compliance through the information and audit rights in Information and audits. These terms apply equally where another US state privacy law imposes comparable obligations on a processor or service provider.
Liability and term
Each party’s liability under this DPA is subject to the limitations and exclusions of liability in the Agreement, except where Data Protection Law does not permit that limitation — in particular a data subject’s rights under Clause 12 of the Standard Contractual Clauses, which are not limited by the Agreement.
This DPA takes effect when you accept the Agreement and continues for as long as we process personal data for you. Obligations that by their nature should survive — confidentiality, deletion, transfer safeguards — do.
We may update this DPA to reflect a change in law, a new approved transfer mechanism, or a change to the Service, on 30 days’ notice, provided the update does not materially reduce your protections.
Annex I — description of the processing
A. List of parties
Data exporter:the Customer, as identified in the Agreement, acting as controller (or as processor for another controller). Contact: the account owner’s email address. Activities: use of the Service as described in the Agreement.
Data importer: [to be confirmed before launch], trading as iLawForms, [to be confirmed before launch]. Contact: privacy@ilawforms.com. Activities: provision of the Service, acting as processor.
B. Description of transfer
| Activity | Data subjects | Personal data | Purpose |
|---|---|---|---|
| Consent records | Visitors to the Customer's website | An opaque first-party identifier generated by the banner, the consent categories chosen, the method of choice, the policy version displayed, a salted hash of the IP address, the browser user-agent string, and timestamps. | To record and evidence a consent decision, and to honour it on subsequent visits. |
| Privacy rights requests | Individuals making a request to the Customer | Name, email address, the request type and framework, free-text details supplied by the requester, a hashed verification token, a salted hash of the IP address, and the audit trail of how the request was handled. | To receive, verify and track requests to their statutory deadline, and to evidence the response. |
| Site scans | Not directed at individuals; incidental personal data may appear in scanned page content | Cookie names, script and host names, page URLs, and the identifier of the user who requested the scan. | To report trackers and third-party hosts on a domain the Customer has claimed. |
| Document generation and hosting | The Customer's personnel named in a document | Business contact details the Customer enters — legal entity name, contact email, domain. | To render and publish the Customer's legal documents. |
- Special category data: none. The Service is not designed for it and you agree not to submit it.
- Frequency: continuous, for as long as the Service is used.
- Nature of processing: collection, recording, organisation, storage, retrieval, use, disclosure to sub-processors, restriction and erasure, by automated means.
- Duration: the term of the Agreement, plus the deletion periods in Deletion and return.
- Sub-processors: as listed in Annex III, for the duration and purpose stated there.
C. Competent supervisory authority
Determined under Clause 13 of the Standard Contractual Clauses: the supervisory authority of the member state in which the exporter is established, or — where the exporter is not established in the EEA but has designated an Article 27 representative — the authority of the member state where that representative is established. For UK transfers, the Information Commissioner’s Office. For Swiss transfers, the FDPIC.
Annex II — technical and organisational measures
The measures below are those we apply to all personal data processed under this DPA. The Security page describes them in more detail and is incorporated here.
- Pseudonymisation and minimisation — IP addresses in consent and rights-request records are stored as salted hashes rather than as addresses; consent subjects are identified by an opaque first-party identifier that is not linked to any account; verification tokens are stored hashed and never in the clear.
- Encryption — TLS for all data in transit, including between internal services; encryption at rest for databases and backups.
- Confidentiality and access control — individually authenticated staff accounts, least-privilege roles, no shared credentials, and an immutable audit log of administrative access to customer data.
- Integrity — published documents are immutable and content-hashed, so a change to a served document is detectable rather than a matter of trust.
- Availability and resilience — hosted policy serving is isolated from the rest of the platform so that an outage in the product does not take a customer's live legal document offline.
- Restoration — encrypted automated backups on a 35-day rolling cycle, with periodic restore testing.
- Testing and evaluation — dependency and vulnerability scanning in continuous integration, code review before merge, and error monitoring configured to strip credentials and personal data before an event is stored.
- Secure development — separate development, staging and production environments; production secrets injected at run time and never committed; no production personal data in non-production environments.
- Sub-processor governance — written contracts imposing equivalent obligations, and review before engagement.
- Incident response — a documented process with defined roles, the 48-hour notification commitment above, and post-incident review.
Annex III — sub-processors
The authorised sub-processors, the processing each carries out, and the country in which each processes personal data, are listed at ilawforms.com/legal/subprocessors. That page is maintained as the current version of this Annex, and changes to it follow the notice and objection process in Sub-processors.