meshnmeet is in beta — Premium features are free while we test. Spot a bug or have feedback? We'd love to hear it.
Beta

Data Processing Agreement (DPA) — TEMPLATE, version 0.1, August 2026.

⚠️ This is a starting-point template, not final legal advice. Have it reviewed by a qualified privacy/commercial lawyer, and confirm the specifics (governing law, SCC modules, sub-processor list, and security measures) before offering it to customers or publishing it. Bracketed […] items are placeholders.

1. Parties and scope

This Data Processing Agreement (“DPA”) forms part of the Terms of Service (the “Agreement”) between meshnmeet (“Processor”, “we”) and the customer agreeing to the Agreement (“Controller”, “you”). It applies where meshnmeet processes Personal Data on your behalf in providing the Service. Where you install the self-hosted WordPress plugin, participant data stays in your own database and you are the sole controller; this DPA then governs only the limited data meshnmeet processes (e.g. license validation and update checks).

2. Definitions

“Personal Data”, “processing”, “controller”, “processor”, “data subject”, and “supervisory authority” have the meanings given in applicable Data Protection Law (including the EU/UK GDPR and, where applicable, the CCPA/CPRA). “Sub-processor” means a third party engaged by the Processor to process Personal Data.

3. Roles and instructions

4. Nature, purpose and duration

The subject matter, nature and purpose of processing, categories of data subjects, and types of Personal Data are described in Annex 1. Processing continues for the term of the Agreement plus any legally required retention period.

5. Confidentiality

meshnmeet ensures that personnel authorized to process Personal Data are bound by appropriate confidentiality obligations.

6. Security

meshnmeet implements appropriate technical and organizational measures to protect Personal Data, as described in Annex 2 and summarized on our Security page, taking into account the state of the art, the costs of implementation, and the nature and risks of the processing.

7. Sub-processors

8. Assistance to the controller

Taking into account the nature of the processing, meshnmeet will assist you, by appropriate technical and organizational measures and insofar as possible, in fulfilling your obligations to respond to data-subject rights requests and to ensure security, breach notification, data protection impact assessments, and prior consultation.

9. Personal data breach

meshnmeet will notify you without undue delay, and in any event within [72] hours of becoming aware of a Personal Data breach affecting your data, and will provide the information reasonably needed for you to meet your notification obligations.

10. International transfers

Where processing involves transferring Personal Data across borders, the parties will rely on an appropriate transfer mechanism (for example, the EU Standard Contractual Clauses and/or the UK Addendum), which are incorporated by reference where applicable. [Confirm which SCC modules and any UK/Swiss addenda apply.]

11. Audits

meshnmeet will make available information reasonably necessary to demonstrate compliance with this DPA and will allow for and contribute to audits, including inspections, conducted by you or an auditor you mandate, subject to reasonable notice, confidentiality, and frequency limits. Where available, third-party reports or certifications may be provided to satisfy audit requests.

12. Deletion or return

On termination of the Service, meshnmeet will, at your choice, delete or return the Personal Data and delete existing copies, unless retention is required by law. Standard product behavior: deleted polls are purged after 90 days; account deletion erases account and poll data; billing records are retained as legally required.

13. Liability and precedence

Each party’s liability under this DPA is subject to the limitations and exclusions of liability in the Agreement. In case of conflict between this DPA and the Agreement on data-protection matters, this DPA prevails.


Annex 1 — Details of processing

Annex 2 — Technical and organizational measures

TLS/HTTPS in transit; salted-hashed passwords; least-privilege access controls and role-based staff permissions; bot protection (Cloudflare Turnstile) and rate limiting; error monitoring; regular external, secured backups with tested restores; no storage of full card data (handled by Paddle). See the Security page for the current description. [Expand to match your actual, verified controls.]

Annex 3 — Approved sub-processors

Keep this list current; publish updates and honor the notice commitment in Section 7.