Data Protection Addendum (DPA) by Bonterms

BontermsUpdated 10 Nov 2025

This Data Protection Addendum (DPA) outlines the responsibilities of a service provider (Processor) when handling customer personal data on behalf of a customer (Controller). It ensures compliance with various data protection laws, including GDPR, CCPA, UK GDPR, and FADP. The DPA covers critical aspects such as data security, subprocessing, data subject requests, and cross-border data transfers.

Other names:Data Protection PolicyGDPR PolicyPrivacy Notice

Bonterms Data Protection Addendum (DPA) (Version 1.0)

DPA Setup Page

By executing this DPA Setup Page, Customer and Provider enter into the Bonterms Data Protection Addendum (DPA) (Version 1.0) (available at https://bonterms.com/forms/data-protection-addendum-v1/) by this reference. A reference copy may be attached. The DPA includes the contents of this DPA Setup Page, including the Key Terms, Schedules and any Additional Terms set forth below. Capitalized terms not defined in this DPA Setup Page have the meanings given in the Bonterms Data Protection Addendum.

Key Terms

Agreement

This DPA is an Attachment to the Agreement between Customer and Provider identified below:

[include name and date of agreement between customer and provider to which this dpa becomes an attachment]

DPA Effective Date

[fill in date]

Subprocessor List

[attach or link to location of provider’s subprocessor list and specify method of notification of changes (or state “none”)]

Schedules (attach)

The following Schedules are incorporated into this DPA:

Schedule 1: Subject Matter and Details of Processing

Schedule 2: Technical and Organizational Measures

Schedule 3: Cross-Border Transfer Mechanisms

Schedule 4: Region-Specific Terms

Additional Terms

The following additions to or modifications of the Bonterms Data Protection Addendum are agreed by the parties and control in the event of any conflicts:

 

Signatures

Agreed to as of the DPA Effective Date by each party’s authorized representative:

Customer:


Signature:

Name and Title: [customer name], [customer title]

Company: [customer company]

Date:

Provider:


Signature:

Name and Title: [provider name], [provider title]

Company: [provider company]

Date:

5.0 out of 5 on Google

Read reviews

As seen in

Law360
Artificial Lawyer
Insider
Axios Pro
San Francisco Business Times
Built In
Startups Magazine
Business Reporter
Tech.eu

California note

This version is drafted for California. US contract and employment rules vary by state, so it will not transfer cleanly elsewhere. Tell GitLaw where the parties are and it adjusts the draft.

Jurisdiction
California (US)
England & Wales
United States of America
Document info
HTML document. Document created on Wed Sep 10th, 2025. Last updated on Mon Nov 10th, 2025.
This document is public
Licensed under CC BY 4.0 (Attribution).
Come to agreements faster
Write, review, negotiate, and manage legal contracts
Related documents
US
Basecamp 4 Account Ownership (Basecamp)
This policy explains that individuals, not organizations, own accounts and the data within them. It outlines owner rights, such as exporting data and managing billing, and specifies the process for transferring ownership when an existing owner is unavailable.
Updated 13 Aug 2026
England & Wales
Data Protection Addendum (DPA)
This data protection addendum establishes the legal framework for processing personal data in connection with a cloud services agreement. It defines the roles of Controller and Processor while setting out specific obligations for subprocessor management, security incident response, and cross-border data transfers.
Updated 13 Aug 2026
FeaturedUS
Acceptable Use Policy by Mozilla
This policy defines prohibited activities for users of a company's digital services and products. It establishes clear boundaries against illegal acts, harassment, malware distribution, and intellectual property infringement while reserving the right to suspend users who violate these terms.
Updated 13 Aug 2026
FeaturedUS
Cloud Service Agreement by Common Paper
This template establishes terms for providing and accessing software-as-a-service, incorporating an order form, framework terms, and a service level agreement. It includes specific sections for machine learning data usage, variable liability caps, and uptime commitments with corresponding service credits.
Updated 13 Aug 2026
California (US)
Github Open Source Applications Terms And Conditions (GitHub)
These terms govern the use of executable code for open source applications provided by a software company. They clarify that while source code is under separate open source licenses, the executable version is subject to these specific conditions, including trademark restrictions on logos and auto-update service limitations.
Updated 13 Aug 2026
General
Service Level Agreement (SLA) (Basecamp)
This document establishes a performance guarantee for software uptime, ensuring high availability for users of a specific service. It provides for automatic account credits if service availability falls below a defined percentage, calculated as ten times the hourly rate for downtime exceeding five minutes.
Updated 13 Aug 2026

Frequently asked questions

A template isn't binding on its own - like any contract, it becomes binding once it's properly completed and signed. Templates in our curated library are professionally drafted for US or UK law; review any template before you sign it.

Yes. Chat with GitLaw to edit any section, or make changes directly in the editor.

Yes, read about team plans here.

Describe what you need in the chat and GitLaw will draft it for you.

Templates in our curated library are professionally drafted for US or UK law. The wider library comes from the GitLaw community and public sources - a solid starting point, but check any template fits your situation before you rely on it.

Mostly US and UK law. Some templates use general commercial terms that work across jurisdictions, and many note which law they're written for.

It depends on the situation. Templates work well for routine business agreements. For anything involving significant money, complex IP, employment, or areas you're unsure about, it's worth getting professional advice before you sign. GitLaw provides templates and tools, not legal advice.

Open any template in GitLaw and describe the change you want in the chat — 'make clause 4 mutual' or 'add a 30-day notice period', for example. GitLaw drafts the revised language and shows it as a suggested edit. You accept, reject, or keep editing from there.

Yes. Upload a Word, PDF, or Markdown file and GitLaw will open it in the editor. You can review, edit, or chat with GitLaw about it the same way you would with any template from the library.

Trusted by 5,000+ businesses

Nexus logoMlabs logoTechstars logo

From template to signed, in one place

Every template opens in an editor with an AI agent alongside it.

1

Open

Pick a template and open it. Nothing to download, and no credit card to start.

Free to open

2

Edit with AI

Describe your situation in chat and the agent adapts the wording, clause by clause.

Tracked changes you can review

3

Send and sign

Share it for negotiation, then collect signatures without leaving GitLaw.

eSign included

Built for your legal work,
with practicing lawyers

Trained on 5,500+ clauses and specialist areas of law. Built with a standards committee of independent lawyers.

As seen in

Law360
Artificial Lawyer
Insider
Axios Pro
San Francisco Business Times
Built In
Startups Magazine
Business Reporter
Tech.eu

Ready to get started?

No sales calls, no credit card. Just chat with GitLaw.

GitLaw provides templates and tools, not legal advice. Templates are a starting point, not a substitute for advice on your situation - for anything significant, speak to a qualified lawyer.