Data Processing Agreement (DPA)
Self-serve the DPA and supporting compliance documents for your workspace.
Data Processing Agreement (DPA)
If your legal or procurement team needs a signed Data Processing Agreement as part of a vendor review, you can generate one at any time — no sales call, no ticket, no back-and-forth.
Download the standard DPA
The current template is pre-filled with your workspace details:
- PDF — Download DPA (PDF)
- DOCX — Download DPA (DOCX)
The PDF is pre-signed by Crove; you countersign and return a copy to us only if your compliance team requires the countersignature on file.
What's in it
The template covers:
- Roles & responsibilities — Crove as processor, your workspace as controller
- Subject matter, duration, nature of processing — auto-filled from your workspace
- Categories of personal data processed — respondent names, emails, and any fields you collect via forms
- Sub-processors — the full list (AWS, Neon, Stripe, Resend, Sentry, PostHog) with their hosting regions
- Security measures — TLS in transit, encryption at rest, SOC 2 Type II controls
- Incident notification — 72h breach notification with contact details
- Data deletion — on workspace deletion (self-serve via Settings → General → Danger Zone) or on request
- International transfers — Standard Contractual Clauses where applicable
Supplementary documents
Questions
If your legal team needs changes to the standard template (e.g. extra representations, named reviewer, different SCC modules), email legal@crove.app with the redlined version and we'll review within 2 business days.