Data processing agreement template

Version 3 October 2026. This template is available for customer review. It becomes an agreement only when completed and signed by both parties, or expressly incorporated into a separately signed agreement. Request an execution copy through privacy contact.

Parties and scope

This Data Processing Agreement (DPA) supplements the agreement for Blank between Happy Kamper Co., LLC, doing business as Blank (Blank), and the customer identified in the signature schedule (Customer). It governs personal data Blank processes on Customer's behalf (Customer Data). For that data, Customer is the controller, or a processor authorized by its controller, and Blank is the processor or subprocessor. Applicable data protection law means the privacy and data protection laws that apply to this processing.

For Customer Data, this DPA prevails over conflicting service terms. A mandatory transfer agreement prevails over conflicting DPA provisions. Account administration and billing data processed for Blank's own purposes are described in the Privacy Policy; this DPA does not change those roles.

Instructions and confidentiality

Customer's agreement, configuration, and written requests define the instructions. Blank will use Customer Data to provide the configured service and will flag instructions it believes unlawful. Customer is responsible for deployment authority and required workforce notices. Authorized personnel must keep Customer Data confidential. Legally compelled processing will be disclosed to Customer where permitted. Blank will not sell Customer Data or use it for advertising or model training.

Security and assistance

Blank will maintain measures appropriate to the processing risks, including those in the security schedule. Customer controls its administrator access, enrollment tokens, and monitoring settings. For rights requests and compliance assessments, Blank will provide relevant exports, deletion assistance, processing information, and reasonable help with security, breach notification, impact assessment, and regulator consultation. Customer decides the response; Blank forwards requests concerning Customer Data unless law requires otherwise.

Security incidents

Blank will notify Customer without undue delay after becoming aware of a personal data breach affecting Customer Data. Notification will describe the affected processing, known impact, containment steps, and contact for follow-up. Information may arrive in stages as the investigation progresses. Blank will help Customer meet its own notification duties and will not wait for a completed investigation to send the initial notice.

Subprocessors

Customer authorizes the Blank-appointed subprocessors in the current list, recorded with the signed agreement. Blank remains responsible for their performance and must impose corresponding protection duties. Blank will give 30 days' advance written notice of additions or replacements. Customer may object within that period on reasonable data protection grounds. The parties will seek a solution; if none is possible, Customer may end the affected service before the new provider processes its data, with unused prepaid fees for that service returned.

Return and deletion

Customer can export service data and request deletion. On termination, Customer chooses return or deletion; absent instructions, Blank deletes Customer Data under the agreed retention schedule. Organization deletion has a reversible 30-day period before the scheduled purge. Copies must also be deleted unless law requires retention; any legally retained data remains protected and restricted to that purpose. The execution schedule must record any applicable backup deletion period. Billing cancellation alone does not request organization deletion.

Information and audits

Blank will provide information reasonably needed to demonstrate compliance with this DPA and allow Customer or its appointed auditor to verify it, including inspections where needed. The parties will coordinate scope, confidentiality, and timing to protect other customers and service availability. Coordination must not prevent an audit required by law or a competent regulator. Blank will inform Customer if it can no longer meet this DPA and cooperate on remediation.

International transfers

Blank operates from the United States. The database region and provider processing locations are in the provider list. Before a transfer that requires additional safeguards, the parties must complete the applicable mechanism and its annexes, including EU Standard Contractual Clauses, a UK Addendum or IDTA, or Swiss adaptations where required. This template does not itself incorporate or execute those instruments. Customer instructions cannot authorize a transfer that applicable law prohibits.

Processing schedule

Detail Agreed service scope
Subject and purpose Managed browser security: discover AI-tool use, detect sensitive-data risks locally, report findings, apply customer policy, and provide dashboards, alerts, and exports.
Nature and frequency Continuous local inspection on managed devices; metadata collection, storage, analysis, display, and customer-directed disclosure or deletion.
Data subjects Customer's employees, contractors, managed-device users, and administrators; individuals identifiable through customer-supplied configuration.
Personal data Device identifiers or pseudonyms, browser and OS metadata, tool domains, finding categories and severities, timestamps, match positions and lengths, counts, confidence, enforcement and feedback records, installed-extension inventory, administrator identities, and SSO or SCIM roster data.
Local content Supported fields and outbound content can contain credentials, financial information, or other sensitive personal data. Inspection happens locally; typed or pasted text and matched values are not transmitted to Blank. Customer must account for this local processing in its instructions and notices.
Duration and retention The service term plus agreed deletion periods. Event defaults: Free 30 days, Team 365 days, Business 396 days, subject to an agreed configuration. Paid-to-Free transitions hold existing event and feedback data for 30 days before Free retention applies. Explicit deletion can remove data sooner.
Customer-directed disclosures Configured alerts, evidence summaries, exports, SSO, SCIM, and customer integration destinations.

Security schedule

Blank's service measures include HTTPS transport; server-side organization and role checks; database access restricted to service operations; pseudonymized dashboard and export identities by default; targeted re-identification requiring a second administrator and expiring after 24 hours; append-only audit records; signed catalog and policy bundles; and scheduled event retention and organization purge. Local inspection reports finding metadata rather than raw matched content. These measures do not constitute a claim of SOC 2 certification or a guarantee that detection prevents every incident.

Execution schedule

Complete these details in the execution copy. Any customer-specific changes must be agreed in writing.

Required detail To complete at signature
Customer legal name, address, and organization Customer entry
Blank legal address and authorized representative Blank entry
Customer controller or processor role Customer entry, including upstream authorization where relevant
Effective date and service agreement Both parties
Customer privacy and incident contact Name and monitored email
Blank privacy and incident contact Contacts in the support directory
Authorized subprocessor list Dated copy attached to the agreement
Retention variations and any backup deletion period Both parties
Transfer mechanism and completed annexes, where required Both parties before the relevant transfer
Customer signature, name, title, and date Customer entry
Blank signature, name, title, and date Blank entry

The processor-contract framework is described in GDPR Article 28 and the European Data Protection Board's controller and processor guidance. The product scope and schedules above describe Blank specifically.

View this page as Markdown →