Agmt Verbatim · Draft legal document
Data processing agreement
Parties and processing instructions
Controller: [Customer legal name, address, and authorized contact.]
Processor: [Confirm Agmt Verbatim contracting entity, address, and privacy contact.]
Instructions and agreement: [Counsel to define the processing subject matter, duration, nature, purpose, documented instructions, and the relationship to the approved service terms.]
The product specification describes Agmt as a processor. The parties and their roles must be confirmed for each customer relationship and applicable law.
Proposed processing description
- Purpose: process Word agreements to provide structured document output requested by the customer.
- Data subjects: [Customer to identify likely categories, which may include agreement parties, signatories, employees, representatives, and people named in comments or document properties.]
- Personal data: submitted document content and related metadata may include names, contact details, signatures, comments, employment or commercial details, and other information selected by the customer. [Counsel and customer to confirm categories and any special or sensitive data restrictions.]
- Processing period: [Set the service term and post-termination handling.]
Processing systems, storage, and location
The current product design specifies that document plaintext is parsed in Worker memory and is not written to application logs or databases. Optional browser uploads are stored as encrypted ciphertext; access ends after 15 minutes. Physical deletion is asynchronous, and no physical-deletion deadline has been verified for this deployment. Accordingly, this draft does not promise a physical-deletion deadline.
Processing is designed to occur in memory at the nearest Cloudflare location. Region pinning is not configured. The owner must verify the production architecture, transfer position, and any customer-specific location requirements.
The product specification lists retained metadata as email addresses, API key hashes, upload authorization and expiry records, keyed pseudonymous client identities, and document-deduplication hashes. These categories need defined purposes, access controls, and retention periods. No schedule is approved in this draft.
Subprocessors identified in the specification
- Cloudflare: compute and transient encrypted upload ciphertext.
- Resend: magic-link email addresses only.
[Confirm legal entities, service regions, applicable transfer mechanisms, subprocessors, notice periods, and customer objection process before approval.]
Security and assistance schedules to complete
The product specification requires that document plaintext not be written to application logs or databases and that optional uploads contain encrypted ciphertext. These design statements are not a completed security schedule or a substitute for evidence from the deployed service.
- [Document verified technical and organizational measures, access control, key management, backups, monitoring, and incident handling.]
- [Set breach notification timing, required contents, and cooperation procedures.]
- [Set assistance with data subject requests, impact assessments, regulator inquiries, and audits.]
- [Specify return/deletion instructions and any exceptions, with a verified physical-deletion process and deadline if one is to be promised.]
- [Counsel to confirm the terms needed under the India Digital Personal Data Protection Act 2023 and, where applicable, GDPR Article 28 and international transfer rules.]
Execution details
[Add the effective date, document precedence, term, signatures, and approved annexes. Do not present this draft as an available or signed agreement.]
Related review pages: privacy notice draft and terms draft.