Data Protection Addendum (DPA)

OLOpen Legal LibraryUpdated 10 Nov 2025

The Data Protection Addendum (DPA) is a modular, lawyer-vetted addendum that supplements core SaaS or cloud service agreements to address data processing obligations, cross-border transfers, security, and privacy compliance. It is part of OLL’s widely trusted library of open, lawyer-vetted standard agreements.

Other names:Data Protection PolicyGDPR PolicyPrivacy Notice

Data Protection Addendum (DPA) (Version 1.0)

DPA Setup Page

By executing this DPA Setup Page, Customer and Provider enter into the Data Protection Addendum (DPA) (Version 1.0). The DPA includes the contents of this DPA Setup Page, including the Key Terms, Schedules and any Additional Terms set forth below. Capitalized terms not defined in this DPA Setup Page have the meanings given in the Data Protection Addendum.

Key Terms

Agreement

This DPA is an Attachment to the Agreement between Customer and Provider identified below:

[include name and date of agreement between customer and provider to which this dpa becomes an attachment]

DPA Effective Date

[fill in date]

Subprocessor List

[attach or link to location of provider’s subprocessor list and specify method of notification of changes (or state “none”)]

Schedules (attach)

The following Schedules are incorporated into this DPA:

Schedule 1: Subject Matter and Details of Processing

Schedule 2: Technical and Organizational Measures

Schedule 3: Cross-Border Transfer Mechanisms

Schedule 4: Region-Specific Terms

Additional Terms

The following additions to or modifications of the Data Protection Addendum are agreed by the parties and control in the event of any conflicts:

Signatures

Agreed to as of the DPA Effective Date by each party’s authorized representative:

Customer:

Signature:

Name and Title: [customer signatory]

Company: [customer company]

Date: [customer sign date]

Provider:

Signature:

Name and Title: [provider signatory]

Company: [provider company]

Date: [provider sign date]

Standard Terms

This Data Protection Addendum (“DPA”) is an Attachment to the Agreement. Customer and Provider enter into this DPA by executing a DPA Setup Page. Capitalized terms not defined in this DPA are defined in the Agreement or DPA Setup Page.

Definitions.

Agreement” means the Agreement between Customer and Provider incorporating the Cloud Terms (Version 1.0) which is specified on the DPA Setup Page.

Audit” and “Audit Parameters” are defined in Section 9.3 below.

Audit Report” is defined in Section 9.2 below.

Controller” means the natural or legal person, public authority, agency or other body which, alone or jointly with others, determines the purposes and means of Processing of Personal Data.

Customer Instructions” is defined in Section 3.1 below.

Customer Personal Data” means Personal Data in Customer Data (as defined in the Agreement).

Data Protection Laws” means all laws and regulations applicable to the Processing of Customer Personal Data under the Agreement, including, as applicable: (i) the California Consumer Privacy Act, as amended by the California Privacy Rights Act, and any binding regulations promulgated thereunder (“CCPA”), (ii) the General Data Protection Regulation (Regulation (EU) 2016/679) (“EU GDPR” or “GDPR”), (iii) the Swiss Federal Act on Data Protection (“FADP”), (iv) the EU GDPR as it forms part of the law of England and Wales by virtue of section 3 of the European Union (Withdrawal) Act 2018 (the “UK GDPR”) and (v) the UK Data Protection Act 2018; in each case, as updated, amended or replaced from time to time.

Data Subject” means the identified or identifiable natural person to whom Customer Personal Data relates.

DPA Effective Date” is specified on the DPA Setup Page.

DPA Setup Page” means a separate document executed by Customer and Provider which causes this DPA to become an Attachment to their Agreement.

EEA” means European Economic Area.

Key Terms” means Agreement, DPA Effective Date and Subprocessor List as specified by the parties on the DPA Setup Page.

Personal Data” means information about an identified or identifiable natural person or which otherwise constitutes "personal data", "personal information", "personally identifiable information" or similar terms as defined in Data Protection Laws.

Processing” and inflections thereof refer to any operation or set of operations that is performed on Personal Data or on sets of Personal Data, whether or not by automated means, such as collection, recording, organization, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction.

Processor” means a natural or legal person, public authority, agency or other body which Processes Personal Data on behalf of the Controller.

Restricted Transfer” means: (i) where EU GDPR applies, a transfer of Customer Personal Data from the EEA to a country outside the EEA that is not subject to an adequacy determination, (ii) where UK GDPR applies, a transfer of Customer Personal Data from the United Kingdom to any other country that is not subject to an adequacy determination or (iii) where FADP applies, a transfer of Customer Personal Data from Switzerland to any other country that is not subject to an adequacy determination.

Schedules” means one or more schedules incorporated by the parties in their DPA Setup Page. The default Schedules for this DPA are:

Schedule 1

Subject Matter and Details of Processing

Schedule 2

Technical and Organizational Measures

Schedule 3

Cross-Border Transfer Mechanisms

Schedule 4

Region-Specific Terms

Security Incident” means any breach of security that leads to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, Customer Personal Data being Processed by Provider.

Specified Notice Period” is 48 hours.

Subprocessor” means any third party authorized by Provider to Process any Customer Personal Data.

Subprocessor List” means the list of Provider’s Subprocessors as identified or linked to on the DPA Setup Page.

Scope and Duration.

Roles of the Parties. This DPA applies to Provider as a Processor of Customer Personal Data and to Customer as a Controller or Processor of Customer Personal Data.

Scope of DPA. This DPA applies to Provider’s Processing of Customer Personal Data under the Agreement to the extent such Processing is subject to Data Protection Laws. This DPA is governed by the governing law of the Agreement unless otherwise required by Data Protection Laws.

Duration of DPA. This DPA commences on the DPA Effective Date and terminates upon expiration or termination of the Agreement (or, if later, the date on which Provider has ceased all Processing of Customer Personal Data).

Order of Precedence. In the event of any conflict or inconsistency among the following documents, the order of precedence will be: (1) any Standard Contractual Clauses or other measures to which the parties have agreed in Schedule 3 (Cross-Border Transfer Mechanisms) or Schedule 4 (Region-Specific Terms), (2) this DPA and (3) the Agreement. To the fullest extent permitted by Data Protection Laws, any claims brought in connection with this DPA (including its Schedules) will be subject to the terms and conditions, including, but not limited to, the exclusions and limitations, set forth in the Agreement.

Processing of Personal Data.

Customer Instructions.

Provider will Process Customer Personal Data as a Processor only: (i) in accordance with Customer Instructions or (ii) to comply with Provider's obligations under applicable laws, subject to any notice requirements under Data Protection Laws.

Customer Instructions” means: (i) Processing to provide the Cloud Service and perform Provider's obligations in the Agreement (including this DPA) and (ii) other reasonable documented instructions of Customer consistent with the terms of the Agreement.

Details regarding the Processing of Customer Personal Data by Provider are set forth in Schedule 1 (Subject Matter and Details of Processing).

Provider will notify Customer if it receives an instruction that Provider reasonably determines infringes Data Protection Laws (but Provider has no obligation to actively monitor Customer's compliance with Data Protection Laws).

Confidentiality.

Provider will protect Customer Personal Data in accordance with its confidentiality obligations as set forth in the Agreement.

Provider will ensure personnel who Process Customer Personal Data either enter into written confidentiality agreements or are subject to statutory obligations of confidentiality.

Compliance with Laws.

Provider and Customer will each comply with Data Protection Laws in their respective Processing of Customer Personal Data.

Customer will comply with Data Protection Laws in its issuing of Customer Instructions to Provider. Customer will ensure that it has established all necessary lawful bases under Data Protection Laws to enable Provider to lawfully Process Customer Personal Data for the purposes contemplated by the Agreement (including this DPA), including, as applicable, by obtaining all necessary consents from, and giving all necessary notices to, Data Subjects.

Changes to Laws. The parties will work together in good faith to negotiate an amendment to this DPA as either party reasonably considers necessary to address the requirements of Data Protection Laws from time to time.

Subprocessors.

Use of Subprocessors.

Customer generally authorizes Provider to engage Subprocessors to Process Customer Personal Data. Customer further agrees that Provider may engage its Affiliates as Subprocessors.

Provider will: (i) enter into a written agreement with each Subprocessor imposing data Processing and protection obligations substantially the same as those set out in this DPA and (ii) remain liable for compliance with the obligations of this DPA and for any acts or omissions of a Subprocessor that cause Provider to breach any of its obligations under this DPA.

Subprocessor List. Provider will maintain an up-to-date list of its Subprocessors, including their functions and locations, as specified in the Subprocessor List.

Notice of New Subprocessors. Provider may update the Subprocessor List from time to time. At least 30 days before any new Subprocessor Processes any Customer Personal Data, Provider will add such Subprocessor to the Subprocessor List and notify Customer through email or other means specified on the DPA Setup Page.

Objection to New Subprocessors.

If, within 30 days after notice of a new Subprocessor, Customer notifies Provider in writing that Customer objects to Provider's appointment of such new Subprocessor based on reasonable data protection concerns, the parties will discuss such concerns in good faith.

If the parties are unable to reach a mutually agreeable resolution to Customer's objection to a new Subprocessor, Customer, as its sole and exclusive remedy, may terminate the Order for the affected Cloud Service for convenience and Provider will refund any prepaid, unused fees for the terminated portion of the Subscription Term.

Security.

Security Measures. Provider will implement and maintain reasonable and appropriate technical and organizational measures, procedures and practices, as appropriate to the nature of the Customer Personal Data, that are designed to protect the security, confidentiality, integrity and availability of Customer Personal Data and protect against Security Incidents, in accordance with Provider’s Security Measures referenced in the Agreement and as further described in Schedule 2 (Technical and Organizational Measures). Provider will regularly monitor its compliance with its Security Measures and Schedule 2 (Technical and Organizational Measures).

Incident Notice and Response.

Provider will implement and follow procedures to detect and respond to Security Incidents.

Provider will: (i) notify Customer without undue delay and, in any event, not later than the Specified Notice Period, after becoming aware of a Security Incident affecting Customer and (ii) make reasonable efforts to identify the cause of the Security Incident, mitigate the effects and remediate the cause to the extent within Provider's reasonable control.

Upon Customer's request and taking into account the nature of the applicable Processing, Provider will assist Customer by providing, when available, information reasonably necessary for Customer to meet its Security Incident notification obligations under Data Protection Laws.

Customer acknowledges that Provider's notification of a Security Incident is not an acknowledgement by Provider of its fault or liability.

Security Incidents do not include unsuccessful attempts or activities that do not compromise the security of Customer Personal Data, including unsuccessful login attempts, pings, port scans, denial of service attacks or other network attacks on firewalls or networked systems.

Customer Responsibilities.

Customer is responsible for reviewing the information made available by Provider relating to data security and making an independent determination as to whether the Cloud Service meets Customer's requirements and legal obligations under Data Protection Laws.

Customer is solely responsible for complying with Security Incident notification laws applicable to Customer and fulfilling any obligations to give notices to government authorities, affected individuals or others relating to any Security Incidents.

Data Protection Impact Assessment. Upon Customer's request and taking into account the nature of the applicable Processing, to the extent such information is available to Provider, Provider will assist Customer in fulfilling Customer's obligations under Data Protection Laws to carry out a data protection impact or similar risk assessment related to Customer's use of the Cloud Service, including, if required by Data Protection Laws, by assisting Customer in consultations with relevant government authorities.

Data Subject Requests.

Assisting Customer. Upon Customer's request and taking into account the nature of the applicable Processing, Provider will assist Customer by appropriate technical and organizational measures, insofar as possible, in complying with Customer's obligations under Data Protection Laws to respond to requests from individuals to exercise their rights under Data Protection Laws, provided that Customer cannot reasonably fulfill such requests independently (including through use of the Cloud Service).

Data Subject Requests. If Provider receives a request from a Data Subject in relation to the Data Subject's Customer Personal Data, Provider will notify Customer and advise the Data Subject to submit the request to Customer (but not otherwise communicate with the Data Subject regarding the request except as may be required by Data Protection Laws), and Customer will be responsible for responding to any such request.

Data Return or Deletion.

During Subscription Term. During the Subscription Term, Customer may, through the features of the Cloud Service or such other means specified on the DPA Setup Page, access, return to itself or delete Customer Personal Data.

Post Termination.

Following termination or expiration of the Agreement, Provider will, in accordance with its obligations under the Agreement, delete all Customer Personal Data from Provider's systems.

Deletion will be in accordance with industry-standard secure deletion practices. Provider will issue a certificate of deletion upon Customer's request.

Notwithstanding the foregoing, Provider may retain Customer Personal Data: (i) as required by Data Protection Laws or (ii) in accordance with its standard backup or record retention policies, provided that, in either case, Provider will (x) maintain the confidentiality of, and otherwise comply with the applicable provisions of this DPA with respect to, retained Customer Personal Data and (y) not further Process retained Customer Personal Data except for such purpose(s) and duration specified in such applicable Data Protection Laws.

Audits.

Provider Records Generally. Provider will keep records of its Processing in compliance with Data Protection Laws and, upon Customer's request, make available to Customer any records reasonably necessary to demonstrate compliance with Provider's obligations under this DPA and Data Protection Laws.

Third-Party Compliance Program.

Provider will describe its third-party audit and certification programs (if any) and make summary copies of its audit reports (each, an “Audit Report”) available to Customer upon Customer's written request at reasonable intervals (subject to confidentiality obligations).

Customer may share a copy of Audit Reports with relevant government authorities as required upon their request.

Customer agrees that any audit rights granted by Data Protection Laws will be satisfied by Audit Reports and the procedures of Section 9.3 (Customer Audit) below.

Customer Audit.

Subject to the terms of this Section 9.3, Customer has the right, at Customer's expense, to conduct an audit of reasonable scope and duration pursuant to a mutually agreed-upon audit plan with Provider that is consistent with the Audit Parameters (an “Audit”).

Customer may exercise its Audit right: (i) to the extent Provider's provision of an Audit Report does not provide sufficient information for Customer to verify Provider's compliance with this DPA or the parties' compliance with Data Protection Laws, (ii) as necessary for Customer to respond to a government authority audit or (iii) in connection with a Security Incident.

Each Audit must conform to the following parameters (“Audit Parameters”): (i) be conducted by an independent third party that will enter into a confidentiality agreement with Provider, (ii) be limited in scope to matters reasonably required for Customer to assess Provider's compliance with this DPA and the parties' compliance with Data Protection Laws, (iii) occur at a mutually agreed date and time and only during Provider's regular business hours, (iv) occur no more than once annually (unless required under Data Protection Laws or in connection with a Security Incident), (v) cover only facilities controlled by Provider, (vi) restrict findings to Customer Personal Data only and (vii) treat any results as confidential information to the fullest extent permitted by Data Protection Laws.

Cross-Border Transfers/Region-Specific Terms.

Cross-Border Data Transfers.

Provider (and its Affiliates) may Process and transfer Customer Personal Data globally as necessary to provide the Cloud Service.

If Provider engages in a Restricted Transfer, it will comply with Schedule 3 (Cross-Border Transfer Mechanisms).

Region-Specific Terms. To the extent that Provider Processes Customer Personal Data protected by Data Protection Laws in one of the regions listed in Schedule 4 (Region-Specific Terms), then the terms specified therein with respect to the applicable jurisdiction(s) will apply in addition to the terms of this DPA.

5.0 out of 5 on Google

Read reviews

As seen in

Law360
Artificial Lawyer
Insider
Axios Pro
San Francisco Business Times
Built In
Startups Magazine
Business Reporter
Tech.eu
Jurisdiction
General
Source
B
Data Protection Addendum (DPA) by Bonterms
from Bonterms
Document info
HTML document. Document created on Fri Sep 12th, 2025. Last updated on Mon Nov 10th, 2025.
This document is public
Licensed under CC BY 4.0 (Attribution).
Come to agreements faster
Write, review, negotiate, and manage legal contracts
Related documents
FeaturedEngland & Wales
Executive Service Agreement (UK) by Seedsummit
This executive service agreement establishes the terms of employment for a high-level executive or company director within a UK-based firm. It defines key obligations regarding director duties, intellectual property ownership, and restrictive covenants such as non-compete and non-solicitation clauses.
Updated 13 Aug 2026
US
Basecamp 4 Account Ownership (Basecamp)
This policy explains that individuals, not organizations, own accounts and the data within them. It outlines owner rights, such as exporting data and managing billing, and specifies the process for transferring ownership when an existing owner is unavailable.
Updated 13 Aug 2026
Letter of Intent by EasyLegalDocs
This Letter of Intent outlines preliminary terms for a proposed action such as a business collaboration or real estate purchase. It establishes a non-binding framework for negotiations while including legally binding non-disclosure provisions to protect sensitive information exchanged between the parties.
Updated 13 Aug 2026
General
Service Level Agreement (SLA) (Basecamp)
This document establishes a performance guarantee for software uptime, ensuring high availability for users of a specific service. It provides for automatic account credits if service availability falls below a defined percentage, calculated as ten times the hourly rate for downtime exceeding five minutes.
Updated 13 Aug 2026
General
Landscaping Contract by EasyLegalDocs
This landscaping services agreement establishes the terms for garden maintenance, design, and installation work at a client's property. It covers recurring service schedules, payment terms, and technical requirements for project modifications.
Updated 13 Aug 2026
England & Wales
Intellectual Property (IP) Transfer Agreement (UK) by Seedsummit
Transfer ownership of all intellectual property created by an individual or entity to another party. This document facilitates the legal handover of rights for a nominal consideration of £1.00 under the laws of England and Wales.
Updated 13 Aug 2026

Frequently asked questions

A template isn't binding on its own - like any contract, it becomes binding once it's properly completed and signed. Templates in our curated library are professionally drafted for US or UK law; review any template before you sign it.

Yes. Chat with GitLaw to edit any section, or make changes directly in the editor.

Yes, read about team plans here.

Describe what you need in the chat and GitLaw will draft it for you.

Templates in our curated library are professionally drafted for US or UK law. The wider library comes from the GitLaw community and public sources - a solid starting point, but check any template fits your situation before you rely on it.

Mostly US and UK law. Some templates use general commercial terms that work across jurisdictions, and many note which law they're written for.

It depends on the situation. Templates work well for routine business agreements. For anything involving significant money, complex IP, employment, or areas you're unsure about, it's worth getting professional advice before you sign. GitLaw provides templates and tools, not legal advice.

Open any template in GitLaw and describe the change you want in the chat — 'make clause 4 mutual' or 'add a 30-day notice period', for example. GitLaw drafts the revised language and shows it as a suggested edit. You accept, reject, or keep editing from there.

Yes. Upload a Word, PDF, or Markdown file and GitLaw will open it in the editor. You can review, edit, or chat with GitLaw about it the same way you would with any template from the library.

Trusted by thousands of businesses

“I found GitLaw to be extremely useful and convenient in helping draft a contract. It has tracking, an easy to understand and familiar interface and has saved thousands of dollars in fees.”

MH

Michael Hawkes

Read more on Google

“I found GitLaw useful to review my medical contract. I was able to check differences from previous contract and tell me which parts are not standard.”

PM

Priyanka Mandal

Read more on Google

“Needed contracts for the brewery. Worked well, very timely, good comms. A+”

CE

Craig Edmunds

Read more on Google

“GitLaw saves us hours when reviewing contracts. The AI suggestions are useful, and the platform is easy to adopt even for non-lawyers”

BB

Bojana Banjac

Read more on Google

“GitLaw stands out because it combines AI with a practical legal workflow. It helped me understand contract terms much faster and made the review process much more efficient.”

KL

Kristijan Lazic

Read more on Google

“A thoughtfully designed legal AI platform. Whether you’re creating new agreements or reviewing existing ones, GitLaw makes the process smoother and easier to understand.”

AM

Andjela Milovanovic

Read more on Google

“I needed this! I own a small business and I wrote all my contracts by myself from templates I saw online, later switched to chatGPT, but when I found gitlaw I was genuinely blown away by it. Great value for the price!!”

RD

Romana Dražić

Read more on Google

“I’ve used this to analyse a number of contracts recently, and my initial concerns were quickly allayed. It picked up on inconsistencies that would have taken me far longer to spot on my own”

“Super useful service! I’ve used it to review a few contracts and I really like how it explains and highlights parts of the documents to review more closely or question.”

MK

Marc Kimmel

Read more on Google

“GitLaw is building an AI Legal Companion that's actually grounded in law.”

GG

Greg Gretsch

Managing Director

“They save time, reduce cost, and make legal work more accessible. It's still early days for AI in law, but the progress is already impressive.”

AB

Aleksandar Blazhev

Entrepreneur

“I found GitLaw to be extremely useful and convenient in helping draft a contract. It has tracking, an easy to understand and familiar interface and has saved thousands of dollars in fees.”

MH

Michael Hawkes

Read more on Google

“I found GitLaw useful to review my medical contract. I was able to check differences from previous contract and tell me which parts are not standard.”

PM

Priyanka Mandal

Read more on Google

“Needed contracts for the brewery. Worked well, very timely, good comms. A+”

CE

Craig Edmunds

Read more on Google

“GitLaw saves us hours when reviewing contracts. The AI suggestions are useful, and the platform is easy to adopt even for non-lawyers”

BB

Bojana Banjac

Read more on Google

“GitLaw stands out because it combines AI with a practical legal workflow. It helped me understand contract terms much faster and made the review process much more efficient.”

KL

Kristijan Lazic

Read more on Google

“A thoughtfully designed legal AI platform. Whether you’re creating new agreements or reviewing existing ones, GitLaw makes the process smoother and easier to understand.”

AM

Andjela Milovanovic

Read more on Google

“I needed this! I own a small business and I wrote all my contracts by myself from templates I saw online, later switched to chatGPT, but when I found gitlaw I was genuinely blown away by it. Great value for the price!!”

RD

Romana Dražić

Read more on Google

“I’ve used this to analyse a number of contracts recently, and my initial concerns were quickly allayed. It picked up on inconsistencies that would have taken me far longer to spot on my own”

“Super useful service! I’ve used it to review a few contracts and I really like how it explains and highlights parts of the documents to review more closely or question.”

MK

Marc Kimmel

Read more on Google

“GitLaw is building an AI Legal Companion that's actually grounded in law.”

GG

Greg Gretsch

Managing Director

“They save time, reduce cost, and make legal work more accessible. It's still early days for AI in law, but the progress is already impressive.”

AB

Aleksandar Blazhev

Entrepreneur

“I used git.law to prepare my documents for the French prefecture and it made the whole process so much easier. Everything was clear and well organized and I felt confident submitting my file. Highly recommend!”

MA

Maryia Alenina

Read more on Google

“Excellent! Really happy I found this. Easy to use and has saved me so much time”

NM

Nishant Mandal

Read more on Google

“Really impressed with the user experience. GitLaw simplifies complex legal tasks without sacrificing quality. Highly recommended”

AR

Aleksandra Radin

Read more on Google

“One of the most practical AI legal tools I’ve tried. Clean interface, helpful features, and a team that’s clearly focused on solving real business problems”

“I’ve been impressed by GitLaw’s approach to contract management. The platform is easy to use, and the AI suggestions are practical and well thought out”

AV

Anisija Vrućinić

Read more on Google

“I love it!!”

JD

Jelena Drazic

Read more on Google

“Love the founder and this company. Very beneficial for startups like ours since we can review contracts and get stuff done easily and quicker.”

TG

Tejas Gupta

Read more on Google

“The amount of time (and headaches) this saves is unreal. There’s an endless supply of templates to start from, and no futzing around with layout and formatting.”

TD

Thomas Daly

Read more on Google

“Love this! Huge opportunity to increase productivity and efficiency within SMEs who rely on regulatory compliance.”

AC

Alex Cole

Founder, TIN Ventures

“Tried the AI chat and I must say, solid UX and impressive prompt interpretation. The multi-user collaboration workflow is a clear win for in-house teams. 👏”

MB

Mrinal Bhatt

HR, People & Culture @ Peakflo

“This is so cool. I remember seeing the template library before, and pivoting to an AI agent that uses them as a foundation is genius.”

CH

Chris Hicken

Co-Founder & CEO of TheySaid

“I used git.law to prepare my documents for the French prefecture and it made the whole process so much easier. Everything was clear and well organized and I felt confident submitting my file. Highly recommend!”

MA

Maryia Alenina

Read more on Google

“Excellent! Really happy I found this. Easy to use and has saved me so much time”

NM

Nishant Mandal

Read more on Google

“Really impressed with the user experience. GitLaw simplifies complex legal tasks without sacrificing quality. Highly recommended”

AR

Aleksandra Radin

Read more on Google

“One of the most practical AI legal tools I’ve tried. Clean interface, helpful features, and a team that’s clearly focused on solving real business problems”

“I’ve been impressed by GitLaw’s approach to contract management. The platform is easy to use, and the AI suggestions are practical and well thought out”

AV

Anisija Vrućinić

Read more on Google

“I love it!!”

JD

Jelena Drazic

Read more on Google

“Love the founder and this company. Very beneficial for startups like ours since we can review contracts and get stuff done easily and quicker.”

TG

Tejas Gupta

Read more on Google

“The amount of time (and headaches) this saves is unreal. There’s an endless supply of templates to start from, and no futzing around with layout and formatting.”

TD

Thomas Daly

Read more on Google

“Love this! Huge opportunity to increase productivity and efficiency within SMEs who rely on regulatory compliance.”

AC

Alex Cole

Founder, TIN Ventures

“Tried the AI chat and I must say, solid UX and impressive prompt interpretation. The multi-user collaboration workflow is a clear win for in-house teams. 👏”

MB

Mrinal Bhatt

HR, People & Culture @ Peakflo

“This is so cool. I remember seeing the template library before, and pivoting to an AI agent that uses them as a foundation is genius.”

CH

Chris Hicken

Co-Founder & CEO of TheySaid

From template to signed, in one place

Every template opens in an editor with an AI agent alongside it.

1

Open

Pick a template and open it. Nothing to download, and no credit card to start.

Free to open

2

Edit with AI

Describe your situation in chat and the agent adapts the wording, clause by clause.

Tracked changes you can review

3

Send and sign

Share it for negotiation, then collect signatures without leaving GitLaw.

eSign included

Built for your legal work, with practicing lawyers

Trained on 5.5K+ clauses and specialist areas of law. Built with a standards committee of independent lawyers.

Portrait headshots of the independent lawyers on the GitLaw standards committee

As seen in

Law360
Artificial Lawyer
Insider
Axios Pro
San Francisco Business Times
Built In
Startups Magazine
Business Reporter
Tech.eu

Start free

No sales calls, no credit card. Just chat with GitLaw.

GitLaw provides templates and tools, not legal advice. Templates are a starting point, not a substitute for advice on your situation - for anything significant, speak to a qualified lawyer.