Data Processing Addendum (DPA) — TEMPLATE
> THIS IS A TEMPLATE, NOT AN EXECUTED AGREEMENT. > It is provided as part of SiteRevive's SOC2-LITE evidence trail so a > prospective customer can review the shape of our data-processing commitments. > Bracketed […] fields are placeholders to be filled in and the document > reviewed by each party's counsel before signing. Nothing here is legal advice, > and an unsigned template creates no obligations.
_Template version: 2026-07-06_
---
1. Parties
- Controller ("Customer"):
[Customer legal entity name], of[address]. - Processor ("Provider"):
[SiteRevive operating entity], of[provider address].
This Addendum supplements the Agreement between the parties for the provision of the SiteRevive service (the "Service") and governs the Processor's Processing of Personal Data on behalf of the Controller.
2. Definitions
"Personal Data", "Processing", "Controller", "Processor", "Data Subject", and "Subprocessor" have the meanings given in [applicable data-protection law, e.g. GDPR / UK GDPR / CCPA]. Terms not defined here take the meaning in the Agreement.
3. Scope and roles
- The Controller determines the purposes and means of Processing.
- The Processor processes Personal Data only on the Controller's documented instructions (including via configuration of the Service) and as necessary to provide the Service.
- Nature and purpose of Processing: delivery of the SiteRevive lead- generation and outreach platform (lead sourcing, mockup generation, email/SMS outreach, scheduling, analytics, billing).
- Categories of Data Subjects: `[e.g. Customer's prospects and business contacts]`.
- Categories of Personal Data: `[e.g. business contact names, email addresses, phone numbers, public business listing data, engagement events]`.
- Duration: for the term of the Agreement plus the retention period in Section 8.
4. Processor obligations
The Processor shall:
- Process Personal Data only per documented instructions;
- ensure persons authorized to process are bound by confidentiality;
- implement the technical and organizational measures described in Section 6;
- respect the conditions in Section 5 for engaging Subprocessors;
- assist the Controller, insofar as possible, with Data Subject requests and with the Controller's own security, breach-notification, and impact- assessment obligations;
- at the Controller's choice, delete or return Personal Data at the end of the Service (see Section 8); and
- make available information reasonably necessary to demonstrate compliance with this Addendum.
5. Subprocessors
- The Controller authorizes the Processor to engage the Subprocessors listed in the Processor's current Subprocessor List, which is incorporated by reference.
- The Processor imposes data-protection terms on each Subprocessor no less protective than those in this Addendum, and remains responsible for its Subprocessors' performance.
- The Processor will provide a mechanism to notify the Controller of intended changes to Subprocessors, allowing the Controller to object on reasonable data-protection grounds:
[notification method / notice period].
6. Security measures
The Processor maintains technical and organizational measures appropriate to the risk, including those documented in the Processor's Encryption Inventory:
- Encryption of Personal Data at rest and in transit;
- logical tenant isolation (per-workspace scoping) on shared infrastructure;
- access logging of sensitive-data reads (evidence trail);
- secrets stored as environment variables and, where they authenticate a bearer, as one-way hashes; and
- signature verification of inbound webhooks.
7. Personal Data breach
The Processor shall notify the Controller without undue delay after becoming aware of a Personal Data breach affecting the Controller's Personal Data, and provide information reasonably available to help the Controller meet its own notification obligations. Notification address: [Controller contact].
8. Return and deletion
On termination or expiry of the Service, and at the Controller's choice, the Processor will delete or return the Controller's Personal Data within [X days], and delete existing copies unless retention is required by law. The Service provides a self-serve per-workspace data export and a workspace deletion path to support this.
9. Audit
The Processor will make available the evidence artifacts referenced above and respond to reasonable written questionnaires. On-site or third-party audits, if any, are subject to [agreed scope, notice, frequency, and cost terms]. Note: SiteRevive's compliance posture is an evidence trail, not a SOC 2 certification; this Section does not represent that a certification exists.
10. International transfers
Where Processing involves transfer of Personal Data across borders, the parties will rely on [transfer mechanism, e.g. Standard Contractual Clauses] as applicable.
11. Term, order of precedence, governing law
- This Addendum takes effect on
[effective date]and continues while the Processor processes Personal Data for the Controller. - In case of conflict on data-protection matters, this Addendum prevails over the Agreement.
- Governing law:
[jurisdiction].
---
Signatures _(to be completed on execution — this template is unsigned):_
| Controller | Processor | |---|---| | Name: […] | Name: […] | | Title: […] | Title: […] | | Date: […] | Date: […] |