Legal
Data Processing Addendum
Last updated: August 3, 2026
If your organization is subject to the GDPR, UK GDPR, or similar data protection law, you may need a signed Data Processing Addendum (DPA) with Filepad, Inc. to cover our processing of personal data on your behalf. This page summarizes what our DPA covers; email us to request the full agreement for signature.
What the DPA covers
- Filepad's role as a data processor acting on your instructions as data controller
- The categories of personal data and processing activities involved in operating Filepad
- Our subprocessors — the AI, storage, and infrastructure providers listed in our Privacy Policy — and our obligation to flag material changes to that list
- Security measures, including encryption of secrets at rest and application-level workspace isolation
- Assistance with data subject rights requests (access, deletion, export)
- International transfer mechanisms, such as Standard Contractual Clauses, where applicable
- Breach notification commitments
Who needs one
If you're an individual or small team using Filepad for your own work, you generally don't need a separate DPA. If your organization processes personal data belonging to others (customers, employees, patients) through Filepad, and you're subject to GDPR, UK GDPR, or a similar regime, a DPA formalizes the terms already described in our Privacy Policy into a document your legal or compliance team can rely on.
Requesting the DPA
Email admin@filepad.ai with your organization name and we'll send the current version for review and signature.