Legal

Data Processing Addendum

Last updated: 17 July 2026

Template — not legal advice. This DPA is a starting point provided for convenience. Have it reviewed by qualified counsel and complete the bracketed fields before relying on it. Nothing here is a representation that ProposalBolt holds any particular certification. For an executed DPA, contact us.

This Data Processing Addendum ("DPA") forms part of the agreement between [Customer legal name] ("Controller") and [ProposalBolt operating entity] ("Processor") for the use of the ProposalBolt service (the "Service").

1. Roles & scope

The Controller determines the purposes and means of processing personal data submitted to the Service; the Processor processes that data only on the Controller's documented instructions, including as set out in the agreement and this DPA, except where required by law.

2. Subject matter & nature of processing

The Processor processes personal data to provide the Service — creating, sending, tracking, e-signing and collecting payment on proposals and related documents — for the duration of the agreement.

3. Categories of data & data subjects

Data subjects: the Controller's users, and the clients/recipients the Controller sends documents to. Personal data: names, email addresses, document content the Controller chooses to include, signature records (including IP address, timestamp and a signature certificate) and payment-related records.

4. Subprocessors

The Controller authorises the Processor to engage the subprocessors listed at /subprocessors, each under written terms imposing data-protection obligations. The Processor will make the current list available and, on request under an Enterprise agreement, give advance notice of additions so the Controller may object on reasonable data-protection grounds.

5. Security measures

The Processor maintains technical and organisational measures appropriate to the risk, including: encryption in transit (TLS) and at rest; tenant isolation enforced at the database with row-level security; role-based access control; two-factor authentication for administrative access; signed, verified payment and webhook handling; a strict content-security policy and input sanitisation; and append-only audit logging of privileged actions. A fuller description is at /security.

6. Confidentiality

Personnel authorised to process personal data are bound by appropriate confidentiality obligations.

7. Data subject rights

Taking into account the nature of the processing, the Processor will assist the Controller by appropriate measures, insofar as possible, in responding to data-subject requests (access, correction, deletion, portability). The Service provides self-serve data export and account deletion to support this.

8. Personal data breach

The Processor will notify the Controller without undue delay after becoming aware of a personal data breach affecting the Controller's data, and provide information reasonably available to help the Controller meet its notification obligations.

9. International transfers

Where personal data is transferred across borders (see the hosting locations at /subprocessors), the parties will rely on a lawful transfer mechanism as required by applicable law, including standard contractual clauses where relevant. [Specify governing data-protection law — e.g. India DPDP Act 2023 / GDPR.]

10. Return & deletion

On termination, the Processor will delete or return the Controller's personal data within a commercially reasonable period, except where retention is required by law. Backups are purged on their normal cycle.

11. Audits

The Processor will make available information reasonably necessary to demonstrate compliance with this DPA and, on reasonable prior notice and subject to confidentiality, respond to the Controller's reasonable audit requests.

12. Liability & governing law

This DPA is subject to the liability and governing-law terms of the agreement. [Governing law / jurisdiction.]

To execute a DPA, or to discuss Enterprise terms, contact our team.

ProposalBolt