Skip to main content

    This DPA forms part of the agreement between Draftless (Processor) and the Customer (Controller) and applies wherever Draftless processes personal data on the Customer's behalf.

    1. Definitions

    "Personal Data", "Processing", "Controller", "Processor", "Data Subject" and "Supervisory Authority" have the meanings given in the GDPR. "Sub-processor" means any third party engaged by the Processor to process Personal Data.

    2. Subject matter and duration

    • Subject matter — processing necessary to provide the Draftless platform.
    • Duration — the term of the agreement plus any retention period under "Return and deletion".
    • Nature and purpose — hosting, generating, storing and managing creative assets and account data through the platform and its AI sub-processors.
    • Categories of data subjects — the Customer's authorised users and their end users.
    • Types of personal data — account identifiers (name, email), authentication data, usage and telemetry, billing identifiers, and any content the Customer uploads or generates.

    3. Processor obligations

    The Processor shall: (a) process personal data only on documented instructions from the Controller; (b) ensure persons authorised to process are bound by confidentiality; (c) implement the technical and organisational measures below; (d) assist the Controller with data-subject requests and data protection impact assessments; (e) delete or return personal data as set out below; and (f) make available the information necessary to demonstrate compliance.

    4. Sub-processors

    The Controller gives general authorisation for the sub-processors published on our Sub-processors page. The Processor notifies the Controller of intended changes and imposes data-protection terms on each sub-processor no less protective than this DPA.

    5. International transfers

    Where personal data is transferred outside the EEA or the UK, the parties rely on the applicable Standard Contractual Clauses together with any required supplementary measures.

    6. Security measures

    Encryption in transit; row-level security and least-privilege access; JWT authentication; centralised rate limiting; error sanitisation; SSRF guards; audit logging of sensitive operations; access controls on backups; regular dependency scanning and scheduled third-party penetration testing.

    7. Personal data breach

    The Processor notifies the Controller without undue delay, and in any case within 72 hours of becoming aware of a personal data breach, providing the information the Controller needs for its own notification obligations.

    8. Return and deletion

    On termination, or at the Controller's request, the Processor deletes or returns all personal data and deletes existing copies, except where law requires continued storage. Account deletion cascades through the Customer's data; financial records required for tax and audit are retained for the statutory period and then purged.

    9. Audits

    The Processor makes evidence of compliance available and permits audits, including inspections, by the Controller or its mandated auditor on reasonable notice and subject to confidentiality.

    10. Requesting a signed copy

    To execute this DPA for your organisation, or to request the Standard Contractual Clauses annexes:

    Email: legal@draftless.dev

    Draftless
    Legal

    © 2026 Draftless. All rights reserved.