Argos OS Intelligent Automation, LLC
v2 · native switcher argos.intelamation.net
Account
Log in · Log out
Intelligent Automation ArgosCOUNSEL Argos Service
← All templates

Subprocessor Agreement (Data Processing Addendum)

subprocessor_agreement · v1 · inbound-procurement · NJ
Edit (new version) Use this template
Attorney review required. Agreements drafted from this template enter attorney_review automatically and cannot be sent to a counterparty until an authorised attorney approves them.

Persona prompts

The system prompts used by the Legal / CISO / CEO personas when drafting and reviewing this template. Inherited from the Intelligent Automation MSP-attorney baseline.

Legal persona
You are reviewing a Subprocessor / Data Processing Addendum. Focus on the breach-notification window enforceability, the further-subprocessor authorization mechanic (general vs specific), the SCC incorporation-by-reference language, and the audit-rights scope. Flag missing indemnification for data-protection violations by Subprocessor.
CISO persona
You are reviewing a Subprocessor DPA from a security perspective. Confirm coverage of: encryption at-rest/in-transit, MFA for admin access, audit logging, SOC 2 Type 2 or ISO 27001 minimum baseline, 48-hour breach notification (IA standard for downstream vendors). Flag missing patch-management commitment, missing penetration-testing cooperation, missing data-residency commitment, or missing right to receive third-party assessment reports.
CEO persona
You are reviewing a Subprocessor DPA commercially. Check that the breach-notification window (48 hours) does not create downstream liability that exceeds what IA owes its own customers. Flag any audit-cost asymmetry (Controller should bear its own audit cost; Subprocessor should bear remediation cost). Confirm termination-data-return provision protects IA's ability to migrate.

Merge fields

Filled in by the "New agreement" form before the AI personas draft.

effective_datetenant_namesubprocessor_namegoverning_state_name

Body preview

> ⚠️ **Drafted with AI assistance via Argos Counsel.** This document reflects standard commercial terms but may not address jurisdiction-specific requirements or the unique facts of your transaction. Both parties should obtain independent legal review before signing.

# Subprocessor Agreement (Data Processing Addendum)

This **Subprocessor Agreement** (this "DPA") is entered into as of **{{.effective_date}}** by and between **{{.tenant_name}}** ("Controller", on behalf of itself and its customers) and **{{.subprocessor_name}}** ("Subprocessor"), and supplements the underlying services agreement between the Parties (the "Underlying Agreement"). Capitalized terms used but not defined herein have the meanings set forth in the Underlying Agreement.

## 1. Subject Matter

The subject matter of the processing under this DPA is the performance by Subprocessor of the services described in the Underlying Agreement that involve the processing of Personal Data on behalf of Controller and Controller's customers.

## 2. Duration

This DPA shall remain in effect for the duration of the Underlying Agreement and shall continue thereafter for so long as Subprocessor retains any Personal Data of Controller or its customers, at which point the surviving obligations in Sections 6, 8, and 9 shall continue to apply.

## 3. Nature and Purpose of Processing

Subprocessor shall process Personal Data solely for the purpose of providing the services described in the Underlying Agreement and only on documented instructions from Controller, including with regard to transfers of Personal Data to a third country or international organization, unless required to do so by applicable law (in which case Subprocessor shall notify Controller before such processing unless that law prohibits such notification).

## 4. Type of Personal Data

The categories of Personal Data processed under this DPA include, but are not limited to: identifiers (name, email, phone, account ID), professional or business information, technical identifiers (IP address, device ID), and, where in scope of the Underlying Agreement, Protected Health Information (PHI) under HIPAA and cardholder data under PCI DSS v4. The specific categories applicable to a given processing activity shall be set forth in the Underlying Agreement or an SOW thereunder.

## 5. Categories of Data Subjects

The data subjects whose Personal Data is processed under this DPA include Controller's employees, contractors, customers, prospective customers, vendors, end-users of Controller's services, and patients (where Controller acts as a covered entity or business associate under HIPAA).

## 6. Subprocessor Obligations

**(a) Security Measures.** Subprocessor shall implement and maintain appropriate technical and organizational measures to protect Personal Data against unauthorized or unlawful processing, accidental loss, destruction, or damage, including: encryption of Personal Data at rest and in transit using industry-standard algorithms; access control with least-privilege and multi-factor authentication for administrative access; audit logging of access to Personal Data; secure development and change-management practices; vulnerability management and timely patching; and incident-response procedures. Subprocessor's security program shall, at minimum, conform to a recognized industry standard (SOC 2 Type 2, ISO 27001, or equivalent).

**(b) Breach Notification.** Subprocessor shall notify Controller of any Personal Data Breach (as defined under applicable law) without undue delay and in any event within **forty-eight (48) hours** after becoming aware of the Breach. Such notice shall include, to the extent known: the nature of the Breach, categories and approximate number of data subjects and records affected, likely consequences, and measures taken or proposed to address the Breach.

**(c) Further Subprocessor Controls.** Subprocessor shall not engage any further subprocessor to process Personal Data under this DPA without Controller's prior written authorization (which may be given through a general written authorization with a published list of approved subprocessors and a right of Controller to object). Where Subprocessor engages a further subprocessor, Subprocessor shall impose on that subprocessor the same data-protection obligations as set out in this DPA.

**(d) Confidentiality.** Subprocessor shall ensure that persons authorized to process Personal Data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality.

**(e) Assistance.** Subprocessor shall assist Controller, taking into account the nature of the processing, in fulfilling Controller's obligations to respond to requests from data subjects exercising their rights under applicable data-protection law.

## 7. Audit Rights

**(a)** Controller shall have the right, no more than once per twelve-month period (and additionally following a Personal Data Breach), to audit Subprocessor's compliance with this DPA, either directly or through an independent auditor acceptable to both Parties.

**(b)** Audits shall be conducted upon at least thirty (30) days' prior written notice, during normal business hours, and in a manner that does not unreasonably disrupt Subprocessor's operations.

**(c)** In lieu of an on-site audit, Subprocessor may provide Controller with copies of its current SOC 2 Type 2 report, ISO 27001 certification, or equivalent third-party attestation, which Controller shall accept as evidence of compliance with respect to the matters covered by such report.

## 8. International Transfers

Where the processing of Personal Data under this DPA involves transfers from the European Economic Area, United Kingdom, or Switzerland to a third country not subject to an adequacy decision, the Parties shall execute the appropriate Standard Contractual Clauses ("SCCs") as published by the European Commission (and the UK Addendum where applicable), which are incorporated by reference into this DPA. The Parties agree to cooperate to maintain appropriate transfer mechanisms in light of evolving legal requirements.

## 9. Termination Effects

Upon termination of this DPA or the Underlying Agreement, Subprocessor shall, at Controller's election: (i) return all Personal Data to Controller in a commercially reasonable format, or (ii) delete all Personal Data in Subprocessor's possession or control, and certify in writing to such return or deletion. Subprocessor may retain copies of Personal Data only to the extent required by applicable law, in which case the retained data shall remain subject to the confidentiality and security obligations of this DPA.

## 10. Governing Law

{{governing_clause}}

This DPA shall be governed by the laws of the State of **{{.governing_state_name}}**, without regard to its conflict-of-laws principles, except that the SCCs (where executed under Section 8) shall be governed by the law specified in those SCCs.

---

**CONTROLLER:** {{.tenant_name}}

By: __________________________     Date: __________
Name:
Title:

**SUBPROCESSOR:** {{.subprocessor_name}}

By: __________________________     Date: __________
Name:
Title: