Legal

Data Processing Agreement

Template — for client engagements

Draft — for legal review before use with a real client. This DPA is scoped narrower than a typical SaaS vendor's, because Optima Lab's actual relationship with a client is narrower: we audit and advise, we don't sit in a client's data pipeline the way a consent management platform does. Read Section 1 carefully and adjust if a specific engagement's scope changes what data is actually touched.

Agreement between [Client Legal Name](“Controller”) and [Optima Lab Legal Entity Name](“Processor”)

1. Subject and scope

This Agreement covers two distinct categories of processing, and only these:

(a) Client account and business contact data. In the ordinary course of delivering an audit or fix engagement, the Processor collects and processes the Controller's own business contact details (name, email, company, billing information) as necessary to deliver, document, and invoice the engagement.

(b) Limited incidental access during fix implementation. If a specific engagement's scope includes implementing changes directly (for example, configuring a consent tool inside the Controller's own analytics or CMS account), the Processor may incidentally access systems that contain the Controller's end-user personal data, solely to complete the agreed configuration work, and not for any other purpose.

The Processor does not otherwise act as a processor of the Controller's website visitors' or customers' personal data. The compliance audit itself is an assessment of the Controller's practices, not a data processing service performed on the Controller's behalf. Where clarity matters, the Controller remains the sole controller of its own end-users' data throughout.

Duration corresponds to the term of the underlying engagement, plus any period data is retained under Section 6.

2. Type of data and data subjects

Business contact data: name, email, phone, company name, billing address.

Incidental end-user data (Section 1(b) engagements only): whatever categories exist within the specific system being configured, as described in that engagement's scope document. The Processor does not export, copy, or retain this data beyond what's needed to complete the configuration task.

Data subjects: the Controller's employees and contacts (business contact data); the Controller's website visitors or customers (incidental access only, where applicable).

3. Controller's instructions

The Processor acts only on the Controller's documented instructions, which are the engagement scope document, this Agreement, and any written instructions given during the engagement.

If the Processor believes an instruction would violate applicable data protection law, it will say so and may pause that specific instruction until clarified.

4. Confidentiality

All personnel with access to Controller data are bound by confidentiality obligations that survive the end of the engagement.

5. Security measures

The Processor maintains reasonable technical and organizational measures appropriate to the data it actually handles, primarily business contact data, including access controls, encrypted transmission, and least-privilege access for any incidental system access under Section 1(b). [Attach a technical measures summary once your actual hosting and access-control setup is finalized, matching what's really in place, not a generic list.]

6. Retention and deletion

Business contact data is retained per the retention schedule in our Privacy Policy. Upon request at engagement close, the Processor will confirm deletion of any incidentally accessed end-user data, since none should have been retained in the first place.

7. Subprocessors

Current subprocessors: [hosting provider], [email delivery provider]. The Processor will notify the Controller of any new subprocessor with material access to Controller data at least [15] days before engagement, and the Controller may object on reasonable data-protection grounds.

8. Data subject rights

The Processor will support the Controller in responding to data subject requests concerning business contact data. Requests concerning the Controller's own end-users should be directed to the Controller directly, since the Processor is not the appropriate party to respond to them.

9. Breach notification

The Processor will notify the Controller without undue delay, and in any case within 48 hours of becoming aware, of any breach affecting data processed under this Agreement.

10. Audit rights

The Controller may request documentation demonstrating the Processor's compliance with this Agreement. Given the limited scope of processing described in Section 1, an on-site audit will rarely be necessary or proportionate; the parties agree to discuss in good faith if one is requested.

11. Liability

Governed by the liability terms in the underlying engagement agreement, and by applicable law, including GDPR Art. 82 where relevant.

12. Governing law

[Jurisdiction], matching the governing law clause in the Terms of Service.

Signed for the Controller:Date:
Signed for the Processor:Date: