Data Processing Agreement (DPA)

This Data Processing Agreement governs the processing of personal data under GDPR, CCPA, and other applicable privacy laws.

GDPR/CCPA Compliance: This DPA ensures compliance with international data protection laws and defines our roles and responsibilities when processing personal data on your behalf.

1. Definitions

For the purposes of this DPA:

2. Scope and Application

This DPA applies when SaaS Launchpad processes personal data on behalf of the Client, including:

3. Roles and Responsibilities

3.1 Controller Responsibilities (Client)

3.2 Processor Responsibilities (SaaS Launchpad)

4. Categories of Data and Processing Activities

4.1 Categories of Personal Data

4.2 Categories of Data Subjects

4.3 Processing Activities

5. Security Measures

5.1 Technical Safeguards

5.2 Organizational Safeguards

6. Sub-Processing

6.1 Authorized Sub-Processors

SaaS Launchpad may engage the following categories of sub-processors:

6.2 Sub-Processor Requirements

All sub-processors must:

6.3 Changes to Sub-Processors

7. International Data Transfers

7.1 Transfer Mechanisms

Personal data may be transferred internationally using:

7.2 Transfer Safeguards

8. Data Subject Rights

8.1 Assistance with Rights Requests

SaaS Launchpad will assist the Client in responding to data subject requests for:

8.2 Response Timeline

9. Data Breach Notification

9.1 Notification Requirements

9.2 Breach Response

10. Audits and Compliance

10.1 Audit Rights

10.2 Audit Documentation

SaaS Launchpad will provide:

11. Data Retention and Deletion

11.1 Retention Periods

11.2 Data Return and Deletion

Upon termination of services:

12. Liability and Indemnification

12.1 Data Protection Liability

12.2 Regulatory Fines and Penalties

13. Term and Termination

13.1 Duration

13.2 Termination Rights

14. Amendments and Updates

This DPA may be updated to reflect:

Material changes require written agreement from both parties.

15. Governing Law and Jurisdiction


Last updated: 9/2/2025

Effective date: 9/2/2025

This DPA ensures compliance with international data protection laws and provides a framework for responsible personal data processing. It forms an integral part of our service agreements and demonstrates our commitment to privacy protection.

Annex: Authorized Subprocessors — Resend, Calendly

Data Processing Addendum (DPA)

This DPA applies when we process personal data on your behalf in connection with our services. For most US customers, this page serves as a summary. A signed DPA is available on request and will be incorporated into your agreement. If GDPR/UK GDPR applies to your use of the Services, our SCCs and the GDPR terms will govern international transfers.

To request a signed copy, contact us via the details in our Privacy Policy. We maintain appropriate technical and organizational measures and require the same from our subprocessors.

Current Subprocessors

We will notify customers of material changes to this list as required by applicable law.