Guide
GDPR DPA generator for indie SaaS
A DPA (data processing agreement) is the Article 28 GDPR contract between a controller and its processor. As soon as a business customer puts data in your app, they may ask for it — often with the list of further processors.
StackLégal generates a DPA in this language, written for the GDPR in general: subject matter, instructions, security (no invented ISO/SOC 2), breach notice without undue delay, audits, deletion or export, transfers, and an Annex 3 built from the boxes you tick (Vercel, Stripe, Clerk, Supabase, Resend, PostHog, Plausible, Google Analytics, OpenAI, Anthropic, Cloudflare).
The assistant asks ten questions. The legal notice and the public list stay readable without paying. The DPA, terms of use, terms of sale and privacy policy are already filled in: 39 € incl. VAT unlocks them as a ZIP (Markdown + App Router pages).
This is not legal advice. Templates in this language are dated 6 October 2026 and follow the GDPR in general. The French pack follows CNIL guidance and is dated 26 August 2026. Review before you sign.
The vendor entries (data, DPA, Data Privacy Framework, clause to paste) are on /en/gdpr — for example Vercel, Stripe, Clerk, Supabase. To assemble several clauses: check your stack.