Skip to content

Legal

Data Processing Addendum

Last updated: August 3, 2026

If your organization is subject to the GDPR, UK GDPR, or similar data protection law, you may need a signed Data Processing Addendum (DPA) with Filepad, Inc. to cover our processing of personal data on your behalf. This page summarizes what our DPA covers; email us to request the full agreement for signature.

What the DPA covers

  • Filepad's role as a data processor acting on your instructions as data controller
  • The categories of personal data and processing activities involved in operating Filepad
  • Our subprocessors — the AI, storage, and infrastructure providers listed in our Privacy Policy — and our obligation to flag material changes to that list
  • Security measures, including encryption of secrets at rest and application-level workspace isolation
  • Assistance with data subject rights requests (access, deletion, export)
  • International transfer mechanisms, such as Standard Contractual Clauses, where applicable
  • Breach notification commitments

Who needs one

If you're an individual or small team using Filepad for your own work, you generally don't need a separate DPA. If your organization processes personal data belonging to others (customers, employees, patients) through Filepad, and you're subject to GDPR, UK GDPR, or a similar regime, a DPA formalizes the terms already described in our Privacy Policy into a document your legal or compliance team can rely on.

Requesting the DPA

Email admin@filepad.ai with your organization name and we'll send the current version for review and signature.