Draft — pending legal review
This document is a working draft prepared for review by WriteStuff's owner and legal counsel. It is not yet a binding agreement, may change substantially, and will be replaced by a reviewed version before WriteStuff accepts paying customers. Text in [square brackets] is a placeholder.
Data Processing Addendum Draft
Draft prepared September 25, 2026. Not yet in effect.
This addendum applies when WriteStuff processes personal data on behalf of a business customer in the course of providing the service. It sets out each party's obligations under applicable data-protection law, including the GDPR and UK GDPR where they apply.
1. Parties and scope
This Data Processing Addendum (“DPA”) forms part of the Terms of Service between [LEGAL ENTITY NAME] (“Processor”) and the customer (“Controller”). It applies to personal data contained in Customer Content and account data of the Controller's users that the Processor processes on the Controller's behalf (“Customer Personal Data”).
2. Details of processing
| Subject matter | Provision of the WriteStuff content workflow service |
|---|---|
| Duration | The term of the agreement plus the post-termination export and deletion period |
| Nature and purpose | Hosting, storage, collaboration, export, import and integration of Customer Content, as instructed by the Controller |
| Data subjects | The Controller's workspace users, and individuals mentioned in Customer Content |
| Categories of data | Names, email addresses, roles, activity and audit records, and any personal data the Controller includes in content or files |
| Special categories | Not intended. The Controller should not store special-category data unless agreed in writing. |
3. Processor obligations
- Process Customer Personal Data only on the Controller's documented instructions, including these Terms and the Controller's configuration of the service.
- Ensure that personnel with access are bound by confidentiality.
- Implement the technical and organizational measures in Annex A.
- Help the Controller respond to data-subject requests and with security, breach notification, impact assessments and prior consultation, taking into account the nature of the processing.
- Notify the Controller without undue delay, and in any case within [48] hours, after becoming aware of a personal-data breach affecting Customer Personal Data.
- At the end of the service, delete or return Customer Personal Data as described in the Terms, unless the law requires it to be kept.
- Make available the information needed to demonstrate compliance, and allow audits as set out in section 6.
4. Subprocessors
The Controller authorizes the subprocessors listed in the Privacy Policy. The Processor will give at least [30] days' notice of new subprocessors, and the Controller may object on reasonable data-protection grounds. The Processor stays responsible for its subprocessors' performance.
5. International transfers
[TRANSFER MECHANISM, e.g. EU Standard Contractual Clauses (Module 2/3) and the UK Addendum, incorporated by reference, TO BE CONFIRMED BY COUNSEL.]
6. Audits
[AUDIT RIGHTS AND FREQUENCY TO BE DRAFTED BY COUNSEL, e.g. questionnaire first, on-site audit on reasonable notice no more than once a year.]
Annex A: Technical and organizational measures
- Encryption in transit (TLS with HSTS). Integration credentials and webhook secrets encrypted at rest with AES-256-GCM. API keys stored only as hashes.
- Passwords hashed with scrypt and a unique salt. Single-use, expiring email tokens. Session revocation on password change.
- Tenant isolation enforced on every request, with automated cross-workspace denial tests for every tenant-scoped route.
- Role-based access control with per-project restrictions. Audit logging of security-relevant events.
- CSRF origin checks, rate limiting, a strict Content Security Policy and hardened response headers.
- Outgoing requests to customer-supplied URLs guarded against internal-network access (SSRF protection).
- Nightly database backups with [14]-day retention. [CONFIRM WHETHER BACKUPS ARE ENCRYPTED AT REST]
- [ADDITIONAL ORGANIZATIONAL MEASURES: access reviews, incident response plan, staff training.]