PRE-LAUNCH REVIEW DRAFT
Data Processing Addendum
The structure that will govern FileMentra’s processing of customer personal data under business customer instructions.
Not yet effective. The operator legal name, registered address, privacy contact, governing law and launch subprocessors must be confirmed before production. This draft describes the product as currently implemented and must receive jurisdiction-specific legal review.
- Status
- Internal review
- Last revised
- August 18, 2026
Scope and roles
The customer is controller (or processor for its own customer) and FileMentra is processor or subprocessor for customer content. Processing is limited to providing, securing, supporting and deleting the service under the agreement and documented customer instructions.
Core commitments
- Confidentiality obligations for authorized personnel.
- Technical and organizational measures covering access control, tenant isolation, encryption, logging, resilience, incident response and secure deletion.
- Subprocessor diligence, written commitments and advance notice.
- Reasonable assistance with rights requests, DPIAs, regulator consultations and breach obligations.
- Return or deletion after services end, subject to law and valid legal hold.
- Audit information and a proportionate independent audit path.
International transfers and annexes
The final DPA must include the parties, duration, processing subject, data categories, data subjects, approved subprocessors, security measures, deletion/backup timetable and the applicable EU Standard Contractual Clauses or UK addendum where required. A contract-ready template is maintained in the repository for counsel completion.