Data Processing Agreement (DPA) — TEMPLATE, version 0.1, August 2026.
⚠️ This is a starting-point template, not final legal advice. Have it reviewed by a qualified privacy/commercial lawyer, and confirm the specifics (governing law, SCC modules, sub-processor list, and security measures) before offering it to customers or publishing it. Bracketed […] items are placeholders.
1. Parties and scope
This Data Processing Agreement (“DPA”) forms part of the Terms of Service (the “Agreement”) between meshnmeet (“Processor”, “we”) and the customer agreeing to the Agreement (“Controller”, “you”). It applies where meshnmeet processes Personal Data on your behalf in providing the Service. Where you install the self-hosted WordPress plugin, participant data stays in your own database and you are the sole controller; this DPA then governs only the limited data meshnmeet processes (e.g. license validation and update checks).
2. Definitions
“Personal Data”, “processing”, “controller”, “processor”, “data subject”, and “supervisory authority” have the meanings given in applicable Data Protection Law (including the EU/UK GDPR and, where applicable, the CCPA/CPRA). “Sub-processor” means a third party engaged by the Processor to process Personal Data.
3. Roles and instructions
- You are the controller and meshnmeet is the processor of the Personal Data described in Annex 1. For US state-privacy-law purposes, meshnmeet acts as a “service provider”/“processor” and does not sell or share Personal Data or use it for cross-context behavioral advertising.
- meshnmeet will process Personal Data only on your documented instructions, including as set out in the Agreement and this DPA, unless required by law (in which case we will inform you unless legally prohibited).
4. Nature, purpose and duration
The subject matter, nature and purpose of processing, categories of data subjects, and types of Personal Data are described in Annex 1. Processing continues for the term of the Agreement plus any legally required retention period.
5. Confidentiality
meshnmeet ensures that personnel authorized to process Personal Data are bound by appropriate confidentiality obligations.
6. Security
meshnmeet implements appropriate technical and organizational measures to protect Personal Data, as described in Annex 2 and summarized on our Security page, taking into account the state of the art, the costs of implementation, and the nature and risks of the processing.
7. Sub-processors
- You provide general authorization for meshnmeet to engage the Sub-processors listed in Annex 3.
- meshnmeet imposes data-protection obligations on each Sub-processor that are no less protective than those in this DPA, and remains responsible for their performance.
- meshnmeet will give reasonable prior notice of the addition or replacement of a Sub-processor to controllers who have subscribed to notifications, and you may object on reasonable data-protection grounds.
8. Assistance to the controller
Taking into account the nature of the processing, meshnmeet will assist you, by appropriate technical and organizational measures and insofar as possible, in fulfilling your obligations to respond to data-subject rights requests and to ensure security, breach notification, data protection impact assessments, and prior consultation.
9. Personal data breach
meshnmeet will notify you without undue delay, and in any event within [72] hours of becoming aware of a Personal Data breach affecting your data, and will provide the information reasonably needed for you to meet your notification obligations.
10. International transfers
Where processing involves transferring Personal Data across borders, the parties will rely on an appropriate transfer mechanism (for example, the EU Standard Contractual Clauses and/or the UK Addendum), which are incorporated by reference where applicable. [Confirm which SCC modules and any UK/Swiss addenda apply.]
11. Audits
meshnmeet will make available information reasonably necessary to demonstrate compliance with this DPA and will allow for and contribute to audits, including inspections, conducted by you or an auditor you mandate, subject to reasonable notice, confidentiality, and frequency limits. Where available, third-party reports or certifications may be provided to satisfy audit requests.
12. Deletion or return
On termination of the Service, meshnmeet will, at your choice, delete or return the Personal Data and delete existing copies, unless retention is required by law. Standard product behavior: deleted polls are purged after 90 days; account deletion erases account and poll data; billing records are retained as legally required.
13. Liability and precedence
Each party’s liability under this DPA is subject to the limitations and exclusions of liability in the Agreement. In case of conflict between this DPA and the Agreement on data-protection matters, this DPA prevails.
Annex 1 — Details of processing
- Subject matter: provision of the meshnmeet polling/scheduling Service.
- Duration: the term of the Agreement plus legally required retention.
- Nature and purpose: hosting, storing, processing, and displaying polls and responses; sending invitations and transactional email; account and billing administration.
- Categories of data subjects: the Controller’s account users/organizers; poll participants; co-organizers; support contacts.
- Types of Personal Data: names; email addresses; poll content and responses/votes; any additional information the Controller chooses to collect at vote (e.g. phone, guest count, custom fields); technical/usage data (IP address, device/browser, logs); limited billing metadata (via Paddle).
- Special-category data: none is required or requested; the Controller must not use custom questions to collect special-category data without its own lawful basis and safeguards.
Annex 2 — Technical and organizational measures
TLS/HTTPS in transit; salted-hashed passwords; least-privilege access controls and role-based staff permissions; bot protection (Cloudflare Turnstile) and rate limiting; error monitoring; regular external, secured backups with tested restores; no storage of full card data (handled by Paddle). See the Security page for the current description. [Expand to match your actual, verified controls.]
Annex 3 — Approved sub-processors
- Paddle — payments, subscriptions, tax (merchant of record).
- Postmark — transactional and invitation email.
- Cloudflare — bot protection.
- Microsoft Clarity — anonymized analytics/session replay (meshnmeet.com only).
- Sentry — error monitoring.
- [Hosting provider] — hosting and storage.
- [Backup storage provider] — encrypted backups.
Keep this list current; publish updates and honor the notice commitment in Section 7.