ContextBoard

Data-processing agreement

Summary and how to execute one.

Last updated: 2026-08-14

Customers that need a formal Data Processing Agreement (DPA) -- for example, because Customer Content includes personal data subject to GDPR, UK GDPR, or similar regulations -- can request one through contact sales. This page summarizes what our standard DPA covers; the executed agreement, not this summary, is the controlling document.

Roles

For Customer Content containing personal data, the Customer acts as the data controller and ContextBoard acts as the data processor, processing personal data only on the Customer's documented instructions -- principally, to parse, extract, index, and serve the Customer's own documents back to the Customer.

Subprocessors

ContextBoard uses a limited set of subprocessors to operate the Service, published and kept current at the subprocessor list. The DPA includes a mechanism for advance notice of new subprocessors.

Security measures

The DPA incorporates the technical and organizational measures described on our security page, including row-level tenant isolation, encryption in transit and at rest, and scoped access controls.

Data subject requests

The DPA specifies how ContextBoard assists the Customer in responding to data subject requests (access, correction, deletion) regarding personal data within Customer Content.

International transfers

Where personal data is transferred internationally, the DPA incorporates appropriate transfer mechanisms, such as Standard Contractual Clauses, as applicable.

Requesting a DPA

Reach out through contact sales to request and execute a DPA for your organization.