Data Processing Addendum
Version: 1.0 Effective date: September 15, 2026
This Data Processing Addendum (“DPA”) forms part of the agreement governing a customer’s use of the FillFaster Service (the “Agreement”) whenever FillFaster processes Customer Personal Data on the customer’s behalf.
The FillFaster contracting party is FillFaster LLC (“FillFaster”). The customer party to the Agreement is referred to as “Customer.”
1. Definitions
In this DPA:
- “Applicable Data Protection Law” means all data protection and privacy, cybersecurity, and data-security laws applicable to the Processing of Customer Personal Data under the Agreement, including, where applicable, the GDPR, UK GDPR, Israeli Privacy Protection Law and regulations, and applicable U.S. State Privacy Laws.
- “Customer Personal Data” means Personal Data contained in Customer Content or otherwise Processed by FillFaster on Customer's behalf in connection with the provision, security, maintenance, support, and use of the Service. Customer Personal Data does not include Personal Data that FillFaster Processes as an independent Controller, including business-contact, billing, account-administration, website, and product-usage data, as described in FillFaster's applicable privacy notice.
- “Customer Content” means forms, templates, documents, fields, submissions, signatures, attachments, files, and related information submitted to or generated through the Service by or for Customer.
- “Controller,” “Processor,” “Data Subject,” “Personal Data,” “Process,” and “Supervisory Authority” have the meanings given by Applicable Data Protection Law.
- “Personal Data Breach” means a breach of security leading to accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to Customer Personal Data processed by FillFaster.
- “Subprocessor” means a third party engaged by FillFaster to process Customer Personal Data on Customer’s behalf.
2. Scope and Roles
2.1 This DPA applies only where FillFaster Processes Customer Personal Data as a Processor. Customer is the Controller or, where Customer processes Personal Data for another Controller, a Processor authorized by the Controller to appoint FillFaster as a Subprocessor and to bind that Controller to the relevant terms of this DPA.
2.2 Each party will comply with its obligations under Applicable Data Protection Law. Customer is responsible for the lawfulness, accuracy, and quality of Customer Personal Data and for providing all required notices, obtaining required permissions, and issuing lawful instructions.
2.3 The Processing details are described in Schedule 1. The Agreement, this DPA, Customer’s configuration and use of the Service, and additional written instructions accepted by FillFaster constitute Customer’s documented instructions, provided that such instructions are lawful, consistent with the Agreement and this DPA, within the intended functionality of the Service, and reasonably capable of being performed by FillFaster
2.4 U.S. State Privacy Laws. To the extent Customer Personal Data is subject to applicable U.S. State Privacy Laws, Customer discloses such Customer Personal Data to FillFaster for the limited and specified business purposes of providing, securing, maintaining, supporting, and improving the Service as permitted by the Agreement. FillFaster acts as a Service Provider, Contractor, Processor, or equivalent regulated service provider, as applicable, and will not: (a) Sell or Share Customer Personal Data; (b) retain, use, or disclose Customer Personal Data for any purpose other than the business purposes specified in the Agreement and this DPA, including as otherwise permitted by applicable U.S. State Privacy Laws; (c) retain, use, or disclose Customer Personal Data outside the direct business relationship between Customer and FillFaster except as permitted by applicable law; (d) combine Customer Personal Data with Personal Data received from other sources except as permitted by applicable law; or (e) use Sensitive Personal Information for purposes other than those permitted by applicable U.S. State Privacy Laws. FillFaster will notify Customer if it determines that it can no longer meet its obligations under this paragraph and will permit Customer to take reasonable and appropriate steps, subject to confidentiality, security, and Service-integrity requirements, to stop and remediate unauthorized use of Customer Personal Data.
3. Processing Instructions
3.1 FillFaster will process Customer Personal Data only:
- to provide, secure, maintain, and support the Service;
- as configured or instructed by Customer and its authorized users;
- as described in the Agreement and this DPA; or
- as required by applicable law. Where legally permitted, FillFaster will inform Customer before processing required by law.
3.2 FillFaster will promptly inform Customer if, in its opinion, an instruction infringes Applicable Data Protection Law. FillFaster may suspend or limit the affected Processing only to the extent reasonably necessary while the parties resolve the issue.
3.3 Customer will not instruct FillFaster to process Customer Personal Data in violation of law or outside the intended functionality of the Service.
FillFaster may Process Customer Personal Data in aggregated or de-identified form only where such information can no longer reasonably identify Customer, a Data Subject, or another person, directly or indirectly, and may use that aggregated or de-identified information for lawful analytics, security, Service improvement, and business operations.
FillFaster will not use Customer Content or Customer Personal Data to train, fine-tune, or improve a general-purpose artificial-intelligence or machine-learning model unless Customer has expressly opted in to that use. Where Customer elects to use an artificial-intelligence feature made available through the Service, FillFaster will Process Customer Personal Data for that feature only in accordance with Customer’s documented instructions, this DPA, and the applicable feature terms.
4. Confidentiality
FillFaster will ensure that persons authorized to process Customer Personal Data are bound by confidentiality obligations and receive access only as necessary for their duties.
5. Security
5.1 FillFaster will maintain appropriate technical and organizational measures designed to protect Customer Personal Data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure, or access, taking into account the nature, scope, context, and purposes of Processing and the risks to Data Subjects. Current measures are summarized in Schedule 2.
5.2 Customer is responsible for using available security features appropriately, managing its users and permissions, protecting credentials, and evaluating whether the Service is suitable for the Customer Personal Data it chooses to process.
5.3 FillFaster may update its security measures as technology and risks evolve, provided that the overall level of protection is not materially reduced.
6. Subprocessors
6.1 Customer provides general authorization for FillFaster to use the Subprocessors listed at fillfaster.com/subprocessors/.
6.2 FillFaster will impose written data-protection obligations on each Subprocessor that are appropriate to the services it provides and no less protective in material respects than the relevant obligations in this DPA. FillFaster remains responsible for its Subprocessors’ performance of those obligations to the extent required by Applicable Data Protection Law.
6.3 FillFaster will provide at least 10 days' advance notice of a new or replacement Subprocessor by updating the Subprocessors page and, where required by Applicable Data Protection Law, by direct notice to Customer. A shorter notice period may apply where a change is reasonably to address an urgent security, legal, or Service-availability issue; in that case, FillFaster will provide notice as soon as reasonably practicable.
6.4 Customer may object to a new or replacement Subprocessor before the change takes effect on reasonable, and documented data-protection grounds by contacting info@fillfaster.com. The parties will work in good faith to address the objection including by considering a commercially reasonable alternative. If no commercially reasonable solution is available, Customer may discontinue the affected feature or terminate the affected Service upon written notice before the new or replacement Subprocessor begins Processing Customer Personal Data. Customer's right to discontinue the affected feature or terminate the affected Service is its sole and exclusive remedy for an objection under this Section. This Section does not require FillFaster to disclose confidential terms with a Subprocessor or to provide a service without a necessary Subprocessor.
7. Data Subject Requests
Taking into account the nature of the processing, FillFaster will provide reasonable assistance through Service functionality and appropriate technical or organizational measures so Customer can respond to requests to exercise data-subject rights. If FillFaster receives a request relating to Customer Personal Data, it will redirect the requester to Customer or notify Customer, unless prohibited by law, and will not respond substantively except on Customer’s documented instruction or as legally required.
8. Security Incidents
8.1 FillFaster will notify Customer without undue delay after becoming aware of a Personal Data Breach affecting Customer Personal Data.
8.2 As information becomes available, FillFaster's notice will describe the nature of the Personal Data breach, the categories of and approximate number of affected Data Subjects and records, likely consequences, measures taken or proposed, and a contact for follow-up. FillFaster may provide information in phases and will take reasonable steps to contain, investigate, and mitigate the Personal Data breach.
8.3 Notification does not constitute an admission of fault or liability. Customer is responsible for determining whether it must notify a Supervisory Authority, affected individuals, or others, and FillFaster will provide reasonable assistance with those obligations.
9. Compliance Assistance
Taking into account the nature of processing and information available to it, FillFaster will provide reasonable assistance with Customer’s obligations concerning security, breach notifications, data-protection impact assessments, transfer assessments, and prior consultation with a Supervisory Authority. Customer is responsible for its own compliance determinations and for reasonable costs of assistance that goes beyond standard Service functionalityor information ordinarily made available by FillFaster.
10. Return and Deletion
10.1 During the term, Customer may access, export, or delete Customer Personal Data using available Service functionality or by contacting FillFaster.
10.2 Cancelling a paid subscription or moving to a free plan does not by itself instruct FillFaster to delete the account or Customer Personal Data.
10.3 Upon Customer’s explicit account-deletion request or termination of the Agreement, FillFaster will, at Customer’s choice and subject to available functionality, return or delete Customer Personal Data. Customer is responsible for exporting Customer Personal Data using available Service functionality before requesting deletion,Unless retention is required by law or reasonably necessary to establish, exercise, or defend legal claim FillFaster will delete Customer Personal Data from active systems within 30 days after the applicable deletion instruction or the end of the Agreement.
10.4 Encrypted backup copies are deleted through FillFaster's ordinary backup-overwrite cycle and remain protected and isolated from routine use until deletion, and will not be restored except where necessary for disaster recovery, business continuity, or legal compliance.
11. Information and Audits
11.1 FillFaster will make available information reasonably necessary to demonstrate compliance with this DPA, including relevant independent audit reports or certifications available, subject to confidentiality security, and access restrictions. FillFaster’s private Trust Center and assurance documents are available to eligible customers upon request and under appropriate confidentiality terms.
11.2 Customer will ordinarily rely on that documentation. made available under Section 11.1. If that documentation is insufficient and Applicable Data Protection Law requires an audit, Customer may request one audit in a 12-month period, unless a Personal Data Breach or Supervisory Authority requires more frequent review. Audits must be conducted by an independent qualified auditor bound by written confidentiality obligations, during normal business hours, with reasonable advance written notice and in a manner that does not disrupt the Service. FillFaster's confidential information, systems, security controls, source code, or other customers' data. Audits may not include penetration testing, vulnerability scanning, access to production systems, or testing that could impair the security or availability of the Service. Customer bears its audit costs and FillFaster's reasonable internal costs of supporting an audit to the extent permitted by Applicable Data Protection Law. The parties will agree reasonable scope, timing, security, and confidentiality controls before the audit.
12. International Transfers
12.1 Customer authorizes FillFaster and its Subprocessors to process Customer Personal Data in the countries identified on the Subprocessors page, subject to this Section and Applicable Data Protection Law..
12.2 For a restricted transfer of Customer Personal Data from the EEA to a country not recognized as providing an adequate level of protection the parties incorporate the European Commission Standard Contractual Clauses adopted by Decision (EU) 2021/914 ( the “EU SCCs”) as follows:
- Module Two applies where Customer is a Controller and FillFaster is a Processor.
- Module Three applies where Customer is a Processor and FillFaster is a Subprocessor.
- Clause 7 (docking) applies; in Clause 9, Option 2 (general written authorization) applies and the notice process in Section 6 of this DPA is the agreed period; the optional language in Clause 11 does not apply.
- For Clause 17, the law of the EEA Member State where the data exporter is established applies if it permits third-party beneficiary rights; otherwise, Irish law applies. Under Clause 18, the corresponding courts have jurisdiction.
- Annexes I and II are completed by Schedules 1 and 2 of this DPA and the Subprocessors page. The competent Supervisory Authority is determined under Clause 13.
12.3 For a restricted transfer subject to UK data-protection law, the then-current UK International Data Transfer Addendum to the EU SCCs sued by the UK Information Commissioner's Office is incorporated. For purposes of that Addendum, Tables 1, 2, and 3 are completed using the parties, transfer details, selected modules, and technical and organizational measures in this DPA, its Schedules, and the Subprocessors page. Either party may terminate the Addendum in accordance with its mandatory terms.
12.4 If another valid transfer mechanism applies to a transfer, the parties may rely on that mechanism. If a transfer is invalidated,suspended, or otherwise becomes unavailable, the parties will cooperate in good faith to implement a lawful replacement transfer mechanism or supplementary measures.
13. Liability and Order of Precedence
The liability provisions of the Agreement apply to this DPA, except to the extent prohibited by Applicable Data Protection Law or the EU SCCs. If documents conflict regarding processing of Customer Personal Data, the order of precedence is: applicable SCCs or mandatory transfer terms, this DPA, and then the Agreement.
14. Term and Changes
This DPA remains in effect while FillFaster Processes Customer Personal Data. FillFaster may update this DPA where reasonably necessary to reflect changes in law regulatory guidance, security practices or the Service, provided that an update does not materially reduce the protection of Customer Personal Data. Material changes will be notified as required by the Agreement or Applicable Data Protection Law and, unless a shorter period is required by law, will take effect no earlier than 30 days after notice.
Schedule 1 - Processing Details
Parties
Data exporter: Customer and any authorized affiliate using the Service. Contact details are those in the Agreement or Customer account. Role: Controller or Processor, as applicable.
Data importer: FillFaster LLC, 30 N Gould St Ste R, Sheridan, WY 82801, USA. Contact: info@fillfaster.com. Role: Processor or Subprocessor.
Subject Matter and Duration
Processing Customer Personal Data to provide, secure, maintain, and support the Service for the term of the Agreement and the deletion period described in Section 10.
Nature and Purpose
Collection, receipt, organization, hosting, storage, retrieval, transmission, display, generation, conversion, signing, delivery, support, security monitoring, backup, export, and deletion of Customer Personal Data as configured and instructed by Customer.
Categories of Data Subjects
Customer’s users, administrators, employees, contractors, clients, prospects, form recipients, signers, submission participants, and other individuals whose data Customer chooses to process through the Service.
Types of Personal Data
Account identifiers; names; business and personal contact details; IP addresses and device information; authentication and audit data; form fields and responses; documents, templates, attachments, and files; signatures and signing evidence; transaction and workflow metadata; and any other personal data Customer chooses to include in Customer Content.
Special-category or sensitive data may be processed only where Customer chooses to submit it, has a valid legal basis and, where required, has obtained any necessary explicit consent or other authorization and implemented appropriate safeguards. Customer will not submit special-category or sensitive data unless the Service is suitable for the intended Processing and Customer has configured and uses the Service in a manner consistent with Applicable Data Protection Law.
Transfer Frequency
Continuous, as initiated by Customer, its authorized users, or automated Service functionality during the term of the Agreement.
Retention Period
For the term of the Agreement and thereafter in accordance with Section 10 of this DPA, unless a longer retention period is required by applicable law or reasonably necessary to establish, exercise, or defend legal claims.
Schedule 2 - Security Measures
FillFaster’s measures include, as appropriate to the Service and risk:
- encryption of data in transit using TLS and storage-level encryption at rest;
- role-based and least-privilege access controls, strong authentication, and periodic access review;
- production network restrictions, managed cloud infrastructure, and separation of duties;
- application, infrastructure, audit, and security logging with monitoring and alerting;
- vulnerability, dependency, patch, and change-management processes;
- backups, resilience, and disaster-recovery procedures;
- incident-response procedures and escalation paths;
- confidentiality and security obligations for authorized personnel and providers;
- vendor and Subprocessor review; and
- independent assurance, reports or certifications maintained by FillFaster or its relevant infrastructure providers, if any, which may be made available under appropriate confidentiality terms.