Data Processing Addendum (DPA)
This DPA supplements the Master Services Agreement (MSA) or SOW and sets out the terms under which Processor (LSJ) will process personal data on behalf of the Controller (the Client). This DPA is effective as of 2026-03-10.
1. Roles & scope
Where LSJ processes personal data on behalf of a client, the client is the Controller and LSJ is the Processor. If LSJ acts as Controller for any service, that role should be specified in the applicable MSA or SOW.
2. Categories of personal data & data subjects
Categories of data processed may include contact and identity data, account and authentication metadata, billing/payment metadata, project documents, and technical logs. Data subjects may include end users, client staff, creators, contractors, and admins.
3. Processor obligations
- Process personal data only on documented instructions from the Controller.
- Implement appropriate technical and organizational measures to protect personal data.
- Ensure personnel with access are bound by confidentiality obligations.
- Assist the Controller with data subject requests and regulatory cooperation where applicable.
- Notify the Controller without undue delay after becoming aware of a personal data breach affecting Controller data.
4. Subprocessors
LSJ may engage subprocessors such as hosting, analytics, communications, storage, or payment providers. LSJ will provide a list of subprocessors on request and will require subprocessors to take on obligations appropriate to the services they perform. The Controller may object to a new subprocessor on reasonable grounds.
5. Security measures
LSJ applies a baseline of security controls including:
- Access control and least-privilege administration
- MFA for privileged accounts
- Encryption in transit (TLS) and encryption at rest where supported
- Logging and monitoring, vulnerability assessment, and periodic security testing
- Backups and recovery procedures appropriate to the service
6. International transfers
Where personal data is transferred outside the Controller’s jurisdiction, LSJ will implement lawful safeguards such as adequacy decisions, Standard Contractual Clauses, or other applicable measures, and will provide information about safeguards relevant to the service upon reasonable request.
7. Data subject rights & breach notification
LSJ will assist the Controller in responding to data subject requests and will notify the Controller without undue delay about security incidents that materially affect Controller data. LSJ will provide reasonable information to support the Controller’s regulatory obligations.
8. Audit & compliance
LSJ will provide reasonable attestations or compliance information where available and will cooperate with Controller audit requests subject to confidentiality, security, and operational constraints.
9. Return or deletion
On termination, LSJ will, at the Controller’s choice, return or securely delete personal data processed on the Controller’s behalf within a reasonable timeframe, unless retention is required by law.
10. Liability & governing law
Liability for DPA obligations is governed by the MSA. The DPA is governed by the law and dispute-resolution provisions set out in the MSA or applicable order documents.
Note: This DPA is a general template. Parties may need to add sector-specific or jurisdiction-specific clauses, including GDPR, UK data protection, or CCPA-specific terms, where applicable.