← All legal documents

Deal Pros Data Processing Addendum

Last updated: October 1, 2026 · Version 2026-10-01

This Data Processing Addendum (the "DPA") forms part of the Platform Terms of Service between Deal Pros, LLC ("Deal Pros") and the Customer. The Customer accepts it by accepting the Subscription Agreement. Capitalized terms not defined here have the meanings in the Platform Terms.

1. Definitions

  • "Personal Information" means information within Customer Data that identifies, relates to, or could reasonably be linked with an individual. Examples are names, contact details, financial details and employee information about a client's business.
  • "Data Protection Laws" means U.S. federal and state privacy, data-protection and data-security laws that apply to the processing of Personal Information under the Platform Terms. These include, where applicable, the California Consumer Privacy Act as amended (CCPA), other comprehensive state privacy laws, and state data-breach notification laws such as Wis. Stat. § 134.98.
  • "Security Incident" means a confirmed breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, Personal Information that Deal Pros processes. It does not include unsuccessful attempts or activities that do not compromise the security of Personal Information, such as blocked logins, pings, port scans or denial-of-service attempts.
  • "Subprocessor" means a third party that Deal Pros engages and that processes Personal Information on Deal Pros' behalf to provide the Service.

2. Roles

2.1 For Personal Information in Customer Data, the Customer is the business or controller and Deal Pros is the service provider or processor.

2.2 For account, billing and Usage Data about Users, Deal Pros acts as an independent business or controller, as described in the Platform Privacy Notice.

2.3 When the Customer connects a third-party service, such as Microsoft Outlook or Dropbox, that service is the Customer's provider, not Deal Pros' Subprocessor. Deal Pros processes data from it on the Customer's instructions.

3. Processing on instructions

3.1 Deal Pros will process Personal Information only to provide the Service and only on the Customer's documented instructions. Those instructions are:

  • the Platform Terms;
  • this DPA;
  • the Customer's configuration of the Service, including its organization AI policy, Data Room AI Protection settings, access permissions and retention settings;
  • other reasonable written instructions consistent with the Platform Terms.

3.2 Deal Pros will not:

  • (a) sell or share Personal Information, as "sell" and "share" are defined in the CCPA;
  • (b) retain, use or disclose Personal Information for any purpose other than providing the Service, including for any commercial purpose other than the business purposes in the Platform Terms;
  • (c) retain, use or disclose it outside the direct business relationship between Deal Pros and the Customer;
  • (d) combine it with personal information Deal Pros receives from other sources, except as the Service's features require for the Customer, or as Data Protection Laws permit;
  • (e) use it to train artificial-intelligence or machine-learning models.

3.3 Deal Pros will tell the Customer if it believes an instruction violates Data Protection Laws, or if it can no longer meet its obligations under them.

3.4 Details of processing.

ItemDescription
Subject matterProviding the Service.
DurationThe subscription term plus the export and deletion periods in Platform Terms Sections 4.6 and 4.7.
Nature and purposeHosting, storage, organization, transmission, display, e-signature, communication, reporting, AI-assisted drafting and analysis where permitted, support and security.
Data subjectsThe Customer's Users and Guests; the Customer's clients, prospects, buyers, sellers and contacts; and owners, employees and other people who appear in business and deal records and documents.
CategoriesContact details; professional details; business, transaction and financial information; documents and their contents; communications; signatures and signature evidence; account and access logs.
Sensitive informationThe Service is not designed to hold government ID numbers, health information, or financial-account credentials. The Customer should store these only where its transaction requires it, and inside Data Rooms with AI Protection on.

4. Personnel

Deal Pros will make sure that anyone it authorizes to process Personal Information:

  • is bound by confidentiality obligations;
  • accesses it only as needed to provide the Service, support the Customer, or keep the Service secure.

5. Security

5.1 Deal Pros will maintain administrative, technical and physical safeguards appropriate to the nature of Personal Information. These include, at a minimum, the measures in Annex 1.

5.2 Deal Pros may update its safeguards, as long as the update does not materially reduce the overall protection of Personal Information.

6. Subprocessors

6.1 Authorization. The Customer authorizes Deal Pros to engage the Subprocessors on the Deal Pros Subprocessor List at dealpros.co/legal/subprocessors. Deal Pros will:

  • impose on each Subprocessor data-protection terms that protect Personal Information at least as much as this DPA, to the extent applicable to the service it provides;
  • remain responsible for each Subprocessor's performance.

6.2 Changes. Deal Pros will notify the Organization Owner by email or in the Service at least 30 days before adding or replacing a Subprocessor. In an emergency, such as replacing a failed provider to keep the Service running, Deal Pros will give notice as soon as practicable.

6.3 Objection. The Customer may object in writing to support@dealpros.co within the notice period, on reasonable data-protection grounds. The parties will discuss the objection in good faith. If Deal Pros cannot reasonably accommodate it, the Customer may terminate the affected part of the Service before the change takes effect and receive a refund under Platform Terms Section 7.6.

6.4 AI providers. AI providers are Subprocessors. They receive content only through Deal Pros' AI governance controls, and only for the categories of data each is approved to receive. No AI provider receives content from a Data Room with AI Protection turned on, or content marked Protected from AI.

7. Assistance

7.1 Individual requests. The Service lets the Customer access, correct, export and delete Personal Information in its Customer Data. If Deal Pros receives a request from an individual about Customer Data, it will:

  • refer the individual to the Customer;
  • not respond itself, except to confirm the referral or as required by law.

Where the Customer cannot fulfil a request using the Service, Deal Pros will provide reasonable assistance.

7.2 Assessments. Deal Pros will provide information the Customer reasonably needs for data-protection assessments or regulator inquiries about the Service. That includes the AI Governance compliance packet and governance reports.

8. Security Incidents

8.1 Deal Pros will notify the Customer without undue delay, and in any event within 72 hours after confirming a Security Incident affecting the Customer's Personal Information. Notice goes to the Organization Owner by email and phone where available.

8.2 The notice will describe, as far as is then known:

  • the nature of the incident;
  • the categories and approximate volume of data affected;
  • the likely consequences;
  • the measures taken or proposed;
  • a contact for more information.

Deal Pros will update the Customer as it learns more.

8.3 Deal Pros will take reasonable steps to contain, investigate and remedy the incident. It will reasonably cooperate with the Customer in meeting any notification obligations the Customer has to individuals or regulators.

8.4 Notifying a Security Incident is not an admission of fault or liability.

9. Return and deletion

At the end of the subscription, Deal Pros will make Customer Data available for export and then delete it, as set out in Platform Terms Sections 4.6 and 4.7. Retained records remain subject to this DPA for as long as they are retained.

10. Audits

10.1 Deal Pros will make available, on request, the information reasonably needed to demonstrate compliance with this DPA. That includes:

  • its security and AI governance documentation;
  • the AI Governance compliance packet;
  • the Customer's organization governance report;
  • written answers to reasonable security questionnaires, once per year.

10.2 If that information is not enough to meet a requirement of Data Protection Laws, the Customer may conduct an audit once every 12 months. The Customer must give at least 30 days' written notice. The audit is at the Customer's expense, during business hours, and limited to Deal Pros' processing of the Customer's Personal Information. It is subject to confidentiality obligations and must not access other customers' data.

11. Location

Deal Pros' primary database is hosted in the United States (AWS us-east-1). Deal Pros' server functions are set to run in us-east-1 for calls from the application and scheduled jobs. Some Subprocessors, including AI providers, may process data in other locations, as stated in the Subprocessor List and the compliance packet. Deal Pros will not represent that all processing occurs in the United States unless it has verified that it does.

12. Liability

Each party's liability under this DPA is subject to the limitations in Platform Terms Section 13, including the data-protection cap in Section 13.3.

13. Conflicts

If this DPA conflicts with the Platform Terms as to Personal Information, this DPA controls.


Annex 1 — Security measures

  1. Tenant isolation. Every database table that holds Customer Data enforces row-level security, so each organization can reach only its own records.

  2. Access control. Access is role-based. Users each have their own login. Two-factor authentication is required for Deal Pros platform staff and available to every User. Platform staff cannot turn off Data Room AI Protection.

  3. Encryption in transit. All connections to the Service use HTTPS/TLS.

  4. Private file storage. Data Room and other customer files are stored in private storage. They are reached through access-checked, time-limited links.

  5. AI governance. Every AI request goes through one fail-closed policy check that applies the following rules, with the most restrictive one winning:

    • organization policy and overrides;
    • Data Room AI Protection;
    • content protection and lineage;
    • provider eligibility.

    Decisions are logged as metadata, without content.

  6. Audit logging. Security-relevant actions are logged, including access changes, AI governance decisions and authorizations, and platform-staff direct edits. The AI governance and authorization logs are append-only.

  7. Environment separation. Test and production data are separated. Writes into production through internal tools are walled and logged.

  8. Backups. Daily database backups are kept for 7 days. File storage is not included in database backups.

  9. Secrets. Service credentials are kept in managed secret storage and not in application code.

  10. Personnel. Access to production data is limited to personnel who need it, and they are bound by confidentiality obligations.

  11. Incident response. Deal Pros maintains a documented incident-response procedure. That procedure includes the notification steps in Section 8.