This technical scaffold is not a legal document, must not be accepted as one, and does not permit production signup to be enabled. It requires drafting and approval by qualified legal counsel.
Legal
Provisional Data Processing Addendum scaffold
Buyers ask for a DPA before they can pay. This page states plainly what is not yet agreed, so nobody relies on a document that does not exist. It is not a DPA, cannot be executed, and creates no obligations.
- Working version
2026-08-21- Status
- Draft; not effective
- Legal approval
- Pending
- Owner
- Unassigned; legal owner required
What the addendum must establish
Counsel must draft, and both parties must agree, accurate language for:
- the contracting entities, and which of them is controller and which is processor
- the subject matter, duration, nature and purpose of the processing
- the categories of personal data and of data subjects involved
- the customer's instructions, and the limits of processing outside them
Obligations that need drafting, not assumption
No position is approved on:
- confidentiality undertakings for personnel with access
- the security measures committed to, as opposed to those described on the security page
- breach notification: what is reported, to whom, and within what period
- assistance with data subject requests, impact assessments and audits
- deletion and return of data at the end of the relationship
Subprocessors and transfers
The current vendor list is published on the subprocessors page. The addendum must still settle the authorisation mechanism, how changes are notified, how objections are handled, and the transfer safeguards relied on for any processing outside the EEA.
Until it is signed
CitePatch will not represent that a DPA is in place. If your organisation requires one before purchase, say so and it will be treated as a blocker rather than a formality.