Data Processing Agreement (template)
DPA template offered to enterprise clients — SCCs, sub-processors, security commitments.
⚠️ DRAFT — Reviewed by counsel: [pending]. Effective date: [YYYY-MM-DD — set on publish]. Do not rely on this as legal advice.
This is a template Data Processing Agreement ("DPA") LeadAdvisors can offer to enterprise clients who ask "do you have a DPA?". It is intentionally LeadAdvisors-favorable in defaults; redlines should be expected and counsel should approve any signed version.
This Data Processing Agreement ("DPA") forms part of the master services agreement between [Client legal entity] ("Client", Controller) and LeadAdvisors ("LeadAdvisors", Processor), each a "Party" and together the "Parties".
1. Purpose and scope
LeadAdvisors performs business-process outsourcing services for the Client (the "Services"). In doing so, LeadAdvisors may process personal data on behalf of the Client. This DPA sets out the Parties' obligations regarding such processing under applicable data protection law, including the EU GDPR, the UK GDPR, the California Consumer Privacy Act / California Privacy Rights Act (CCPA/CPRA), the Philippine Data Privacy Act (DPA), and Mexico's LFPDPPP, as relevant.
2. Definitions
Unless defined here, terms used in this DPA carry the meanings given in the EU GDPR (or, where the data subject is located in a different jurisdiction, the substantively equivalent local term). "Personal Data" means any data processed under this DPA that identifies or is reasonably linkable to a natural person.
3. Roles
3.1 Controller and processor. The Client is the Controller; LeadAdvisors is the Processor. LeadAdvisors processes Personal Data only on documented instructions from the Client, including with regard to international transfers, except as required by law (in which case LeadAdvisors will inform the Client unless the law forbids it).
3.2 CCPA/CPRA. For California residents, LeadAdvisors is a "service provider" and will not (a) sell or share Personal Data, (b) retain, use, or disclose Personal Data outside the direct business relationship with the Client, or (c) combine Personal Data with information from other sources except as permitted under § 1798.140(ag) and the regulations.
4. Subject matter, duration, nature, and purpose
| Item | Description |
|---|---|
| Subject matter | Provision of the Services described in the master agreement |
| Duration | The term of the master agreement plus any post-termination period required for return / deletion |
| Nature and purpose | Personal-data processing necessary to deliver the Services (e.g., agent calls, data entry, customer support, lead handling) |
| Categories of data subjects | The Client's customers, prospects, leads, employees, or end-users, as relevant to the Services |
| Categories of personal data | Identifiers (name, contact details), call recordings (where lawfully captured by the Client's tools), order / account information, and any other category the Client transmits to LeadAdvisors for processing |
| Special categories | None unless explicitly listed in the master agreement / order form. LeadAdvisors will not knowingly accept special categories without an addendum |
5. LeadAdvisors's obligations
LeadAdvisors will:
- Process Personal Data only on the Client's documented instructions and only for the purposes set out in §4.
- Ensure that personnel authorized to process Personal Data are bound by confidentiality.
- Implement appropriate technical and organizational measures as set out in Schedule 2 (Security).
- Assist the Client in fulfilling data-subject rights and regulatory obligations in proportion to the nature of the processing.
- Inform the Client of any binding legal request for Personal Data unless the law prohibits.
- Make available information necessary to demonstrate compliance and allow audits as set out in §10.
6. Sub-processors
6.1 General authorization. The Client gives a general authorization for LeadAdvisors to engage Sub-processors as listed in Schedule 1 (Sub-processors). LeadAdvisors will give the Client at least 30 days prior notice (by updating the Sub-processor list at leadadvisors.com/[Anthony to confirm: subprocessors page URL] or by direct email) of any addition or replacement, allowing the Client to object on reasonable data-protection grounds. If the Parties cannot resolve the objection, the Client may terminate the affected Services without penalty.
6.2 Flow-down. LeadAdvisors will impose on each Sub-processor materially equivalent data-protection obligations to those in this DPA.
6.3 Liability. LeadAdvisors remains fully liable for the acts and omissions of its Sub-processors as if they were its own.
7. International transfers
Where Personal Data is transferred from the EEA, UK, Switzerland, the Philippines, Mexico, or any jurisdiction with cross-border-transfer rules, the Parties will rely on a valid transfer mechanism, including (as relevant):
- The EU Standard Contractual Clauses (SCCs) — 2021/914 (Module 2, Controller-to-Processor; Module 3 where the Sub-processor is engaged), incorporated by reference, with the optional clauses noted in Schedule 3 (Transfers).
- The UK International Data Transfer Addendum to the EU SCCs.
- The Swiss Federal Data Protection Act addendum.
- For Philippines outbound transfers, the obligations of NPC Circular 16-02.
- For Mexico outbound transfers, art. 36-37 LFPDPPP and its regulations.
The Parties agree the Module 2 SCCs are incorporated as set out in Schedule 3 with the Client as data exporter and LeadAdvisors as data importer.
8. Security
LeadAdvisors will implement and maintain the technical and organizational measures set out in Schedule 2 designed to protect Personal Data against unauthorized or unlawful processing, accidental loss, destruction, or damage. The measures will be reviewed regularly and updated as risks evolve.
9. Personal data breach notification
LeadAdvisors will notify the Client without undue delay, and in any event within 72 hours, after becoming aware of a Personal Data Breach affecting Client Personal Data. The notification will include the information available to LeadAdvisors at that time and will be supplemented as more information becomes available.
10. Audits
The Client may, on 30 days' prior written notice (or sooner if required by a regulator), audit LeadAdvisors's compliance with this DPA, no more than once per 12-month period (and additionally at any time after a Personal Data Breach). Audits must be conducted during business hours, with reasonable scope, and at the Client's cost. The Client may rely on a recent independent third-party audit report (for example, SOC 2, ISO 27001) [Anthony to confirm: which certifications LeadAdvisors holds — current portal does not yet hold a SOC 2; align as we ship].
11. Data subject rights and assistance
LeadAdvisors will, taking the nature of processing into account, assist the Client by appropriate technical and organizational measures (insofar as possible) for the fulfilment of the Client's obligation to respond to data-subject requests. If LeadAdvisors receives a data-subject request directly, it will redirect the data subject to the Client and notify the Client without undue delay.
12. Return or deletion at the end
On expiry or termination, LeadAdvisors will, at the Client's choice, delete or return all Client Personal Data within 30 days (or longer if reasonably needed for orderly termination), and delete remaining copies, except where retention is required by law.
13. Liability
The Parties' liability is governed by the master agreement. Nothing in this DPA limits liability that, by law, cannot be limited.
14. Order of precedence
In the event of conflict, this DPA controls over the master agreement on data-protection matters.
15. Governing law
The law of the master agreement governs this DPA, except where mandatory data-protection law applies a different rule.
Schedule 1 — Sub-processors
LeadAdvisors's current sub-processors are listed in the Privacy Policy §6. The list as of the Last updated date includes (non-exhaustively): Vercel, Inc. (hosting / analytics), Neon (Postgres), Resend (transactional email), Sentry (error monitoring), Time Doctor (time tracking), Five9 / Ytel / Vici (dialers), and [Anthony to confirm: payout processor].
Schedule 2 — Security measures
LeadAdvisors will maintain measures including:
- Access control: role-based access in the portal; super-admin allowlist; recruiters blocked from compensation data; SSO / NextAuth; bcrypt-hashed passwords; least-privilege provisioning.
- Network security: TLS in transit, hosted database with TLS, no public DB exposure, platform-level DDoS / WAF protection by Vercel.
- Encryption at rest: managed database encryption at the storage layer (Neon).
- Logging and monitoring: Sentry error monitoring; Vercel logs; portal
audit_logfor sensitive actions [Anthony to confirm: audit-log roll-out per Module B1]. - Backups: managed daily backups by the Neon platform; tested restore procedure [Anthony to confirm: documented RTO / RPO].
- Personnel: confidentiality undertakings; security awareness; screening commensurate with role.
- Incident response: documented playbook, notify within 72 hours per §9.
- Vendor management: subprocessor due diligence; flow-down DPAs.
Schedule 3 — Transfers
The Parties incorporate the EU SCCs Module 2 (Controller-to-Processor), with:
- Clause 7 (docking): included.
- Clause 9(a): general written authorization, with 30 days notice as set out in §6.
- Clause 11(a): independent dispute resolution body not chosen.
- Clause 17: governing law of [Anthony to confirm: an EU member-state of the data exporter's establishment, e.g., Ireland].
- Clause 18(b): competent courts of [Anthony to confirm: same EU member-state].
The UK IDTA and Swiss addendum are incorporated by reference where the data subject is located in those jurisdictions.
Signatures
Client: ____________________________ Date: ______________
LeadAdvisors: ____________________________ Date: ______________
[Anthony to confirm: authorized signer name and title]
Questions or rights requests: legal@leadadvisors.net.