Data Processing Agreement
Agreement Portal | SaaS Product Co UAB | Last updated: 2026.06.22
1. Introduction
This Data Processing Agreement (“DPA”) forms part of the Terms of Service between SaaS Product Co UAB, a company incorporated in Lithuania (“Agreement Portal”, “Processor”, “we”, “us”, or “our”), and the customer using the Agreement Portal Service (“Customer”, “Controller”, or “you”).
This DPA applies where Agreement Portal processes personal data on behalf of the Customer in connection with the Agreement Portal platform and related services.
This DPA is intended to satisfy the requirements of Article 28 of the EU General Data Protection Regulation (“GDPR”).
In the event of a conflict between this DPA and the Terms of Service, this DPA takes precedence in relation to data protection matters only. The Terms of Service continue to apply to commercial, liability, intellectual property, payment, and general contractual matters.
2. Definitions
Terms such as “personal data”, “processing”, “controller”, “processor”, “data subject”, “personal data breach”, and “supervisory authority” have the meanings given to them in the GDPR.
For the purposes of this DPA:
-
Controller means the Customer that determines the purposes and means of processing personal data contained in Customer Data.
-
Processor means SaaS Product Co UAB, which processes personal data on behalf of the Controller.
-
Customer Data means contracts, documents, extracted data, metadata, account data, and other information uploaded to, generated in, or processed through the Service by or on behalf of the Customer.
-
Customer Personal Data means any personal data contained in Customer Data and processed by Agreement Portal on behalf of the Customer.
-
Service means the Agreement Portal contract intelligence platform and related services.
-
Subprocessor means any third party engaged by Agreement Portal to process Customer Personal Data on behalf of the Customer.
-
Data Protection Laws means the GDPR and any applicable national data protection laws.
3. Subject Matter, Nature, and Purpose of Processing
Agreement Portal processes Customer Personal Data to provide, operate, secure, maintain, and support the Service.
The processing includes:
-
uploading, storing, and organising contracts and related business documents;
-
AI-assisted and automated extraction of contract data;
-
structuring, indexing, and displaying contract information;
-
enabling search, filtering, reporting, dashboards, reminders, and workflow functionality;
-
managing user accounts, roles, permissions, and authentication;
-
supporting customer-enabled integrations, where enabled by the Customer;
-
providing customer support and technical troubleshooting;
-
monitoring, securing, maintaining, and backing up the Service;
-
complying with applicable legal obligations.
Agreement Portal shall not process Customer Personal Data for its own independent purposes, except where required by applicable law or where Agreement Portal acts as an independent controller as described in its Privacy Policy.
4. Duration of Processing
Agreement Portal processes Customer Personal Data for the duration of the Customer’s use of the Service and for any additional period required to return, export, delete, or retain data in accordance with the Terms of Service, this DPA, or applicable law.
After termination or expiry of the Terms of Service, Customer Personal Data will be returned, exported, deleted, or anonymised as described in Section 13 of this DPA.
5. Types of Personal Data
Customer Personal Data may include:
-
names;
-
business email addresses;
-
business phone numbers;
-
job titles and roles;
-
company names;
-
signatures, if included in uploaded documents;
-
contact details of contract parties, employees, contractors, suppliers, customers, and representatives;
-
personal data contained in contracts, agreements, addenda, order forms, statements of work, service agreements, and related documents;
-
user account data, login activity, permissions, and support communication;
-
contract metadata and extracted fields that relate to identifiable individuals.
The exact personal data processed depends on the content uploaded by the Customer and the way the Customer configures and uses the Service.
6. Categories of Data Subjects
Customer Personal Data may relate to:
-
Customer employees;
-
Customer contractors and consultants;
-
Customer representatives and authorised users;
-
representatives of the Customer’s customers, suppliers, vendors, partners, and counterparties;
-
signatories and contacts named in contracts or related documents;
-
other individuals whose personal data appears in Customer Data uploaded to the Service.
7. Special Category Data
The Service is not intended for processing special category personal data under GDPR Article 9, including health data, biometric data, political opinions, religious beliefs, trade union membership, or similar sensitive data.
The Customer must not upload documents containing special category personal data unless this has been expressly agreed with Agreement Portal in writing and appropriate safeguards have been agreed.
If Agreement Portal becomes aware that special category personal data has been uploaded without prior agreement, it may request deletion, restrict processing, or suspend processing of the affected data where reasonably necessary to manage legal or security risk.
8. Customer Instructions
Agreement Portal shall process Customer Personal Data only on documented instructions from the Customer.
The Customer’s documented instructions include:
-
this DPA;
-
the Terms of Service;
-
the Customer’s configuration and use of the Service;
-
user actions within the Service;
-
customer-enabled integrations;
-
support requests and other written instructions agreed by the parties.
If Agreement Portal is required by EU or Member State law to process Customer Personal Data outside the Customer’s instructions, Agreement Portal shall inform the Customer before processing, unless prohibited by law.
If Agreement Portal reasonably believes that an instruction infringes Data Protection Laws, it shall notify the Customer and may suspend processing of the affected data until the instruction is clarified or modified.
9. Customer Responsibilities
The Customer is responsible for:
-
complying with applicable Data Protection Laws in its use of the Service;
-
ensuring it has a lawful basis to upload and process Customer Personal Data;
-
providing required privacy notices to data subjects;
-
ensuring Customer Data is accurate, lawful, and appropriate for processing through the Service;
-
deciding which contracts and documents are uploaded;
-
managing user access, roles, and permissions within its organisation;
-
reviewing and verifying AI-extracted or automated outputs before relying on them;
-
responding to data subject requests where the Customer acts as controller;
-
not uploading special category data unless expressly agreed in writing.
The Customer remains responsible for determining whether the Service is appropriate for its intended processing activities.
10. Processor Obligations
Agreement Portal shall:
-
process Customer Personal Data only on documented instructions from the Customer;
-
ensure that persons authorised to process Customer Personal Data are bound by confidentiality obligations;
-
implement appropriate technical and organisational measures to protect Customer Personal Data;
-
assist the Customer with data subject rights requests, taking into account the nature of processing;
-
assist the Customer with security, breach notification, data protection impact assessments, and prior consultation obligations, taking into account the nature of processing and the information available to Agreement Portal;
-
maintain records of processing activities where required by Data Protection Laws;
-
notify the Customer of personal data breaches in accordance with this DPA;
-
use subprocessors only in accordance with this DPA;
-
return, delete, or anonymise Customer Personal Data in accordance with this DPA.
11. Security Measures
Agreement Portal shall implement appropriate technical and organisational measures designed to protect Customer Personal Data against unauthorised access, accidental or unlawful destruction, loss, alteration, unauthorised disclosure, or misuse.
These measures may include, where applicable:
-
encryption in transit using HTTPS/TLS;
-
encryption at rest where supported by the relevant infrastructure;
-
role-based access controls;
-
least-privilege access principles;
-
user authentication and permission management;
-
restricted internal access to Customer Data;
-
access logging and monitoring;
-
backup and recovery procedures;
-
secure software development practices;
-
vulnerability management and risk-based patching;
-
monitoring for suspicious activity;
-
incident response procedures;
-
confidentiality obligations for personnel with access to Customer Personal Data;
-
review of key service providers and subprocessors.
Further details are set out in Schedule 2: Security Measures.
No online service can be guaranteed to be completely secure. Agreement Portal shall maintain a level of security appropriate to the nature, scope, context, and purpose of the processing and the risks to data subjects.
12. Subprocessors
The Customer gives Agreement Portal general written authorisation to engage subprocessors to process Customer Personal Data for the purpose of providing, hosting, securing, maintaining, supporting, and improving the Service.
The subprocessors approved as of the date of this DPA are listed in Schedule 1: Subprocessor List.
Agreement Portal may engage reputable infrastructure, cloud, AI, security, monitoring, support, and other service providers as subprocessors. For large-scale cloud, infrastructure, AI, and similar providers, Agreement Portal’s due diligence may be based on reasonably available information, including the provider’s data processing agreement, security documentation, certifications, audit reports or summaries, technical and organisational measures, transfer safeguards, published subprocessor lists, and other compliance materials made available by the provider.
Agreement Portal shall:
-
conduct appropriate, risk-based due diligence on subprocessors before engagement and periodically thereafter;
-
enter into written terms with each subprocessor imposing data protection obligations that provide a substantially equivalent level of protection for Customer Personal Data as required under this DPA, taking into account the nature of the services provided by the subprocessor;
-
ensure subprocessors process Customer Personal Data only for the purposes necessary to provide the Service and in accordance with Agreement Portal’s documented instructions;
-
remain responsible to the Customer for the performance of its subprocessors’ data protection obligations, subject to the limitations of liability in the Terms of Service;
-
maintain an up-to-date list of subprocessors in Schedule 1 or another location made available to the Customer.
Agreement Portal shall notify the Customer of any intended addition or replacement of a subprocessor by updating the Subprocessor List or by other reasonable written means. Agreement Portal shall use commercially reasonable efforts to provide notice before the change takes effect where practicable.
The Customer may object to a new or replacement subprocessor on reasonable data protection grounds within 15 days of receiving notice. The parties shall work in good faith to resolve the objection. Where commercially reasonable, Agreement Portal may offer an alternative configuration, workaround, or restriction of the affected processing.
If the objection cannot be resolved and the affected Service cannot reasonably be provided without the relevant subprocessor, either party may terminate the affected part of the Service in accordance with the Terms of Service.
13. Customer-Enabled Third-Party Integrations
The Service may allow the Customer to enable integrations with third-party services, such as CRM platforms, including HubSpot.
Where the Customer enables an integration with its own third-party account:
-
the Customer instructs Agreement Portal to transmit relevant Customer Data to the selected third-party service;
-
the Customer is responsible for configuring the integration, permissions, and data sync settings;
-
the third-party service processes data under its own terms, privacy policy, and data processing agreement with the Customer;
-
Agreement Portal is responsible for the secure transmission of data from the Service to the integration endpoint, but is not responsible for the third party’s processing after receipt;
-
the Customer may disable the integration at any time.
Unless Agreement Portal uses the third-party provider to process Customer Personal Data on Agreement Portal’s behalf, the provider is treated as a customer-enabled third-party integration and not as Agreement Portal’s subprocessor.
14. AI-Assisted Processing
The Service uses automated and AI-assisted tools to extract, structure, and organise information from uploaded contracts and related documents.
This processing may include the use of third-party AI service providers listed in Schedule 1 where required to provide the extraction functionality.
Agreement Portal shall not use Customer Personal Data, uploaded contracts, extracted contract data, or AI outputs to train AI models, improve models for other customers, benchmark customer data, or create insights for third parties.
AI-assisted extraction may contain errors, omissions, or misinterpretations. The Customer is responsible for reviewing and verifying extracted data before relying on it for legal, financial, billing, operational, or business decisions.
15. Personal Data Breach Notification
Agreement Portal shall notify the Customer without undue delay after becoming aware of a personal data breach affecting Customer Personal Data.
Where reasonably available, the notification shall include:
-
the nature of the breach;
-
the categories and approximate number of data subjects affected;
-
the categories and approximate number of records affected;
-
the likely consequences of the breach;
-
measures taken or proposed to address and mitigate the breach;
-
the contact point for further information.
Where not all information is immediately available, Agreement Portal may provide the information in phases.
Agreement Portal shall provide reasonable assistance to the Customer in meeting its breach notification obligations under Data Protection Laws, taking into account the nature of processing and the information available to Agreement Portal.
16. Data Subject Rights
Agreement Portal shall provide reasonable assistance to the Customer, taking into account the nature of processing, to help the Customer respond to requests from data subjects exercising their rights under Data Protection Laws.
If Agreement Portal receives a request directly from a data subject relating to Customer Personal Data, Agreement Portal shall, unless legally prohibited, forward the request to the Customer or instruct the data subject to contact the Customer directly.
Agreement Portal shall not respond to such requests on behalf of the Customer unless instructed to do so by the Customer or required by law.
17. Data Protection Impact Assessments and Regulatory Assistance
Agreement Portal shall provide reasonable assistance to the Customer with data protection impact assessments and prior consultation with supervisory authorities where required under Data Protection Laws, taking into account the nature of processing and the information available to Agreement Portal.
This assistance may include providing information about the Service, processing activities, subprocessors, security measures, and international transfer safeguards.
18. Audit and Information Rights
Agreement Portal shall make available to the Customer information reasonably necessary to demonstrate compliance with this DPA and Article 28 GDPR.
Agreement Portal’s primary means of demonstrating compliance may include:
-
this DPA;
-
the Subprocessor List;
-
the Security Measures schedule;
-
records of processing activities where applicable;
-
responses to reasonable security or privacy questionnaires;
-
summaries of independent third-party audits or certifications, where available.
-
If the information provided is not reasonably sufficient to demonstrate compliance, the Customer may request an audit, subject to the following conditions:
-
the Customer must provide at least 60 days’ prior written notice;
-
audits may be conducted no more than once in any 12-month period, unless required by a supervisory authority, applicable law, or following a personal data breach materially affecting Customer Personal Data;
-
audits must take place during normal business hours and with minimal disruption;
-
the Customer and any auditor must sign appropriate confidentiality obligations before the audit;
-
any auditor must be independent, suitably qualified, and not a competitor of Agreement Portal;
-
audits must not compromise the security, confidentiality, or availability of data belonging to other customers;
-
audits must not require access to source code, trade secrets, commercially sensitive information, or multi-tenant infrastructure;
-
the Customer bears its own audit costs and Agreement Portal’s reasonable costs of supporting the audit, unless the audit reveals a material breach of this DPA by Agreement Portal.
Nothing in this section limits the rights of a competent supervisory authority under applicable law.
19. International Data Transfers
Customer Personal Data is hosted and processed in the European Union where supported by Agreement Portal’s infrastructure setup.
Some subprocessors may process Customer Personal Data outside the European Economic Area as described in Schedule 1.
Where Agreement Portal transfers Customer Personal Data outside the European Economic Area to a country that does not benefit from an adequacy decision, Agreement
Portal shall use appropriate safeguards required by Data Protection Laws. These may include:
-
Standard Contractual Clauses approved by the European Commission;
-
EU-US Data Privacy Framework certification, where applicable;
-
adequacy decisions;
-
supplementary technical and organisational measures, where required.
Agreement Portal shall maintain information about relevant transfer safeguards in Schedule 1 or otherwise make it available to the Customer on reasonable request.
20. Return, Export, and Deletion of Data
Upon termination or expiry of the Terms of Service, the Customer may request export of Customer Data within the period stated in the Terms of Service.
Where technically available, export may include uploaded documents and extracted data in a commonly used format.
At the Customer’s written request, or after the applicable export period, Agreement Portal shall delete or anonymise Customer Personal Data unless retention is required by applicable law.
Backup copies may remain in encrypted backups for a limited period and will be deleted according to Agreement Portal’s normal backup retention procedures.
Agreement Portal may retain limited account, billing, security, and legal records where required by law or necessary to establish, exercise, or defend legal claims.
For clarity, this DPA governs the return and deletion of Customer Personal Data. The Terms of Service govern return and deletion of Customer Data more broadly, including uploaded contracts, extracted commercial data, and non-personal business information.
21. Confidentiality
Agreement Portal shall ensure that personnel authorised to process Customer Personal Data are subject to appropriate confidentiality obligations.
Agreement Portal shall not disclose Customer Personal Data except as necessary to provide the Service, comply with the Customer’s instructions, use approved subprocessors, comply with law, or exercise rights under the Terms of Service.
22. Liability
Liability arising under this DPA is subject to the limitations and exclusions of liability set out in the Terms of Service, except to the extent such limitation is prohibited by applicable Data Protection Laws.
Nothing in this DPA limits either party’s liability where such limitation is not permitted by applicable law.
23. Changes to This DPA
Agreement Portal may update this DPA from time to time where necessary to reflect changes in the Service, Data Protection Laws, subprocessors, transfer safeguards, or security measures.
Where changes materially affect the processing of Customer Personal Data or the Customer’s rights under this DPA, Agreement Portal shall provide reasonable notice before the changes take effect.
Continued use of the Service after the effective date of updated terms constitutes acceptance of the updated DPA, unless a separate written agreement applies.
24. Changes to This DPA
This DPA is governed by the laws of the Republic of Lithuania.
Disputes relating to this DPA are subject to the jurisdiction set out in the Terms of Service, subject to any mandatory rights or protections under applicable Data Protection Laws.
25. Contact
SaaS Product Co UAB
Email: privacy@agreementportal.com
Address: V. Žalakevičiaus str. 29-12, Vilnius, Lithuania
Schedule 1: Subprocessor List