Disclaimer: This template is for informational purposes only and does not constitute formal legal advice. Consult an attorney before use.
Purpose & Importance of This Legal Document in B2B Business
In the rapidly evolving landscape of B2B SaaS, establishing a clear, legally sound foundation for service delivery is paramount. A Master Services Agreement (MSA) serves as the overarching contractual framework governing the relationship between a SaaS provider and its business customer. It streamlines future engagements by setting out general terms and conditions that apply to all subsequent orders or statements of work (SOWs), avoiding the need to renegotiate core terms for every new project or service offering.
The integration of a Data Processing Addendum (DPA) into the MSA is no longer optional but a critical necessity, especially when dealing with personal data. With stringent global privacy regulations like the General Data Protection Regulation (GDPR) in Europe and the California Consumer Privacy Act (CCPA) in the United States, businesses must meticulously define how personal data is collected, processed, stored, and protected. An integrated DPA ensures that both parties understand their roles (e.g., Controller and Processor under GDPR, or Business and Service Provider under CCPA) and responsibilities regarding data privacy, mitigating significant legal, financial, and reputational risks associated with non-compliance.
This comprehensive guide and template are designed to equip SaaS providers and their B2B clients with a robust legal instrument that fosters clarity, trust, and regulatory adherence, laying the groundwork for successful, long-term partnerships.
Key Clauses Explained in Plain English
Understanding the core components of an MSA with an integrated DPA is crucial for effective negotiation and compliance. Here’s a breakdown of essential clauses:
Master Services Agreement (MSA) Core Clauses:
- Services: This clause defines the scope of the SaaS offering, detailing what services will be provided. It usually references specific Order Forms or Statements of Work (SOWs) for detailed descriptions.
- Fees & Payment: Outlines pricing, payment terms, invoicing procedures, and consequences of late payments. Clarity here prevents future financial disputes.
- Term & Termination: Specifies the duration of the agreement and the conditions under which either party can terminate it (e.g., breach of contract, insolvency, for convenience).
- Confidentiality: Protects proprietary information shared between the parties, defining what constitutes confidential information and how it must be handled.
- Intellectual Property (IP): Determines ownership of existing IP and any IP created during the provision of services. Typically, the SaaS provider retains IP over its platform, while the customer owns its data.
- Warranties: Guarantees made by each party, often including service level uptime, compliance with laws, and non-infringement of third-party rights.
- Indemnification: Specifies which party will defend and pay for losses incurred by the other due to specific events (e.g., IP infringement claims, breach of confidentiality).
- Limitation of Liability: Sets caps on the financial exposure of each party in the event of damages, often excluding certain types of damages (e.g., indirect or consequential).
- Governing Law & Dispute Resolution: Designates the jurisdiction whose laws will govern the contract and the process for resolving disputes (e.g., arbitration, litigation).
Data Processing Addendum (DPA) Integrated Clauses (GDPR & CCPA Focus):
- Roles & Scope of Processing: Clearly defines the roles (e.g., Controller/Business and Processor/Service Provider) and outlines the subject matter, duration, nature, purpose, types of personal data, and categories of data subjects involved in the processing.
- Instructions & Compliance: Mandates that the Processor (SaaS provider) only processes personal data according to the documented instructions of the Controller (customer) and in compliance with applicable data protection laws (GDPR, CCPA).
- Security Measures: Requires the Processor to implement appropriate technical and organizational measures to ensure a level of security appropriate to the risk, including data encryption, access controls, and regular testing.
- Sub-processors: Addresses the use of third-party sub-processors. It typically requires the Controller's prior written authorization, imposing similar data protection obligations on sub-processors.
- Data Subject Rights Assistance: Obligates the Processor to assist the Controller in responding to requests from data subjects (e.g., access, rectification, erasure).
- Data Breach Notification: Defines the Processor's obligation to notify the Controller without undue delay upon becoming aware of a personal data breach.
- International Data Transfers: Addresses the legal mechanisms for transferring personal data outside the EEA or UK (for GDPR) or to non-compliant jurisdictions, such as Standard Contractual Clauses (SCCs).
- Audit Rights: Grants the Controller the right to conduct audits or inspections to verify the Processor's compliance with the DPA.
- Data Return & Deletion: Upon termination, specifies the Processor's obligation to return or delete personal data, unless otherwise required by law.
- CCPA Specifics: For CCPA, explicitly states the SaaS provider acts as a "Service Provider," is prohibited from selling personal information, retains, uses, or discloses personal information only for the business purpose specified, and certifies its understanding of these restrictions.
Complete Ready-to-Use Template: B2B SaaS Master Services Agreement (MSA) with Integrated Data Processing Addendum (DPA)
MASTER SERVICES AGREEMENT
This Master Services Agreement ("Agreement") is entered into as of [Effective Date] ("Effective Date") by and between:
[Company Name], a [State/Country] corporation with its principal place of business at [Company Address] ("Provider");
and
[Client Company Name], a [State/Country] corporation with its principal place of business at [Client Company Address] ("Client").
Provider and Client are sometimes referred to herein individually as a "Party" and collectively as the "Parties."
RECITALS
WHEREAS, Provider offers certain software-as-a-service ("SaaS") solutions and related services;
WHEREAS, Client desires to subscribe to and use Provider's SaaS solutions and services, and Provider desires to provide such solutions and services, all subject to the terms and conditions set forth herein;
WHEREAS, the Parties acknowledge that in the course of providing and receiving the Services, certain Personal Data (as defined below) may be processed, and the Parties desire to establish their respective rights and obligations regarding such processing in compliance with applicable data protection laws, including GDPR and CCPA.
NOW, THEREFORE, in consideration of the mutual covenants and agreements contained herein, the Parties agree as follows:
ARTICLE I: DEFINITIONS
1.1. "Confidential Information" means any non-public information, whether oral, written, or visual, disclosed by one Party (the "Disclosing Party") to the other Party (the "Receiving Party"), which is designated as confidential or which, by its nature, would reasonably be understood to be confidential. It includes, without limitation, trade secrets, business plans, product roadmaps, customer data, and technical data.
1.2. "Client Data" means all electronic data, information, or material submitted by Client to the Services.
1.3. "Order Form" means a document executed by both Parties, referencing this Agreement, that specifies the Services to be provided by Provider, the fees, and other transaction-specific details.
1.4. "Personal Data" has the meaning ascribed to it in the GDPR or "Personal Information" as defined in the CCPA, as applicable, and refers to any information relating to an identified or identifiable natural person that Provider processes on behalf of Client in connection with the Services.
1.5. "Services" means the SaaS solutions and any related professional services provided by Provider to Client as described in an Order Form.
1.6. "SOW" (Statement of Work) means a document executed by both Parties, referencing this Agreement, that describes specific professional services to be performed by Provider.
1.7. Other capitalized terms shall have the meanings ascribed to them where first used in this Agreement.
ARTICLE II: SERVICES
2.1. Provision of Services. Provider will make the Services available to Client pursuant to this Agreement and the relevant Order Forms. Client's use of the Services shall be subject to Provider's acceptable use policy, if any, made available to Client.
2.2. Service Levels. Any service level agreements ("SLAs") applicable to the Services will be set forth in an Order Form or a separate exhibit referenced therein.
2.3. Client Responsibilities. Client is responsible for its users' compliance with this Agreement and for the accuracy, quality, and legality of Client Data and the means by which Client acquired Client Data.
ARTICLE III: FEES AND PAYMENT
3.1. Fees. Client shall pay Provider the fees specified in each Order Form.
3.2. Invoicing and Payment. All fees are due and payable [e.g., 30 days] from the invoice date. Unpaid amounts are subject to a finance charge of [e.g., 1.5]% per month on any outstanding balance, or the maximum permitted by law, whichever is lower, plus all expenses of collection.
3.3. Taxes. All fees are exclusive of applicable taxes. Client is responsible for paying all applicable taxes, duties, and government assessments, excluding taxes based on Provider's net income.
ARTICLE IV: TERM AND TERMINATION
4.1. Term of Agreement. This Agreement commences on the Effective Date and continues until all Order Forms hereunder have expired or been terminated, or until terminated earlier as provided herein.
4.2. Term of Order Forms. The term of each Order Form shall be as specified in the Order Form.
4.3. Termination for Cause. Either Party may terminate this Agreement or any Order Form for cause: (a) upon 30 days written notice to the other Party of a material breach if such breach remains uncured at the expiration of such period; or (b) if the other Party becomes the subject of a petition in bankruptcy or any other proceeding relating to insolvency, receivership, liquidation, or assignment for the benefit of creditors.
4.4. Effect of Termination. Upon termination, Client shall cease all use of the Services and Provider shall cease providing Services. Client will pay all outstanding fees. The provisions of Articles I, III, IV.4, V, VI, VII, VIII, IX, X, XI, and XII shall survive any termination or expiration of this Agreement.
ARTICLE V: CONFIDENTIALITY
5.1. Obligations. The Receiving Party shall: (a) use the Disclosing Party's Confidential Information only to exercise its rights and fulfill its obligations under this Agreement; (b) take all reasonable measures to protect the Disclosing Party's Confidential Information from unauthorized disclosure, at least to the same extent it protects its own similar information; and (c) not disclose any Confidential Information to any third party except to its employees, affiliates, agents, or subcontractors who have a need to know and are bound by confidentiality obligations no less stringent than those herein.
5.2. Exclusions. Confidential Information does not include information that: (a) is or becomes publicly known through no fault of the Receiving Party; (b) was known to the Receiving Party prior to disclosure by the Disclosing Party without breach of any obligation owed to the Disclosing Party; (c) is disclosed to the Receiving Party by a third party without breach of any obligation owed to the Disclosing Party; or (d) is independently developed by the Receiving Party without reference to the Disclosing Party's Confidential Information.
5.3. Compelled Disclosure. The Receiving Party may disclose Confidential Information to the extent required by law or court order, provided it promptly notifies the Disclosing Party (if legally permitted) to allow the Disclosing Party to seek a protective order.
ARTICLE VI: DATA PROCESSING (GDPR & CCPA DPA)
6.1. Roles of the Parties. For the purpose of the GDPR and CCPA, to the extent Provider processes Personal Data on behalf of Client in the provision of the Services, Client is the "Controller" (or "Business") and Provider is the "Processor" (or "Service Provider"). The processing of Personal Data under this Agreement is for the purpose of providing the Services as set forth in the relevant Order Form.
6.2. Details of Processing.
a. Subject Matter and Duration: The subject matter of the processing is the Personal Data provided by Client to Provider for the purpose of using the Services. The duration of processing shall be for the term of the Agreement and relevant Order Forms, and as otherwise specified herein.
b. Nature and Purpose: The nature and purpose of processing are to provide the Services as described in the Agreement and Order Forms, which may involve storage, retrieval, analysis, and transmission of Personal Data.
c. Types of Personal Data: [Specify types of Personal Data, e.g., contact details, identifiers, professional data, financial data, health data, web usage data - BE SPECIFIC TO YOUR SERVICE]
d. Categories of Data Subjects: [Specify categories of data subjects, e.g., Client's employees, Client's customers, end-users of Client's services]
6.3. Processor's Obligations. Provider shall:
a. Lawful Instructions. Process Personal Data only on the documented instructions of Client, unless required to do so by applicable law, in which case Provider shall inform Client of that legal requirement before processing, unless that law prohibits such information on important grounds of public interest.
b. Confidentiality. Ensure that persons authorized to process the Personal Data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality.
c. Security Measures. Implement appropriate technical and organizational measures to ensure a level of security appropriate to the risk, including, as appropriate, the measures referred to in Article 32(1) of the GDPR. These measures shall include, but not be limited to: [E.g., pseudonymisation and encryption of Personal Data; the ability to ensure the ongoing confidentiality, integrity, availability and resilience of processing systems and services; the ability to restore the availability and access to Personal Data in a timely manner in the event of a physical or technical incident; a process for regularly testing, assessing and evaluating the effectiveness of technical and organizational measures for ensuring the security of the processing.]
d. Sub-processors. Not engage another processor ("Sub-processor") without prior specific or general written authorization of the Client. In the case of general authorization, Provider shall inform Client of any intended changes concerning the addition or replacement of other Sub-processors, thereby giving Client the opportunity to object to such changes. Where Provider engages a Sub-processor, Provider shall impose on that Sub-processor data protection obligations that are no less protective than those set out in this Section VI. Provider shall remain fully liable to Client for the performance of the Sub-processor's obligations.
e. Assistance to Controller. Take into account the nature of the processing, assist Client by appropriate technical and organizational measures, insofar as this is possible, for the fulfilment of Client's obligation to respond to requests for exercising Data Subject Rights under the GDPR or CCPA.
f. Data Breach Notification. Notify Client without undue delay (and in no event later than [e.g., 48] hours) after becoming aware of a Personal Data breach affecting Client's Personal Data. Provider shall reasonably cooperate with Client in investigating, mitigating, and remedying the breach.
g. Deletion or Return of Data. At the choice of Client, delete or return all Personal Data to Client after the end of the provision of Services relating to processing, and delete existing copies unless applicable law requires storage of the Personal Data.
h. Audits. Make available to Client all information necessary to demonstrate compliance with the obligations laid down in this Section VI and allow for and contribute to audits, including inspections, conducted by Client or another auditor mandated by Client, at Client's sole expense and with reasonable notice, provided such audits do not interfere with Provider’s normal business operations.
6.4. Client's Obligations as Controller/Business. Client represents and warrants that:
a. It has all necessary rights and consents to provide the Personal Data to Provider for processing under this Agreement.
b. Its instructions to Provider for the processing of Personal Data comply with applicable data protection laws, including GDPR and CCPA.
6.5. CCPA Specifics for Service Provider. For Personal Information subject to the CCPA, Provider, as a Service Provider, agrees that it:
a. Is prohibited from selling Personal Information (as defined by the CCPA).
b. Is prohibited from retaining, using, or disclosing Personal Information for any purpose other than for the specific business purpose of providing the Services specified in this Agreement, or as otherwise permitted by CCPA.
c. Is prohibited from retaining, using, or disclosing Personal Information outside of the direct business relationship between Provider and Client.
d. Shall not combine the Personal Information received from Client with Personal Information that Provider receives from or on behalf of another person or collects from its own interaction with the consumer, except as permitted by CCPA.
e. Certifies that it understands the restrictions and prohibitions on the sale, retention, use, and disclosure of Personal Information under the CCPA and this Agreement.
6.6. International Data Transfers. If Personal Data originating from the European Economic Area ("EEA") or the United Kingdom ("UK") is transferred to Provider or a Sub-processor located outside the EEA or UK in a country not deemed to provide an adequate level of data protection, the Parties agree that such transfers shall be governed by the standard contractual clauses for the transfer of personal data to third countries pursuant to Regulation (EU) 2016/679 of the European Parliament and of the Council (the "SCCs"), as adopted by the European Commission, and as amended or replaced from time to time by the competent authorities, which are hereby incorporated by reference and deemed executed by the Parties. [Alternatively, specify a different valid transfer mechanism, e.g., Binding Corporate Rules, UK IDTA/Addendum, etc.] The Parties agree to execute any further documentation required to ensure such transfers are compliant with applicable data protection laws.
ARTICLE VII: INTELLECTUAL PROPERTY RIGHTS
7.1. Provider's IP. Provider retains all right, title, and interest in and to the Services, including all related intellectual property rights. This Agreement does not grant Client any rights to Provider’s intellectual property except for the limited right to use the Services as expressly permitted herein.
7.2. Client's IP. Client retains all right, title, and interest in and to Client Data. Client grants Provider a limited, non-exclusive, non-transferable license to use Client Data solely for the purpose of providing the Services under this Agreement.
ARTICLE VIII: WARRANTIES AND DISCLAIMERS
8.1. Mutual Warranties. Each Party warrants that it has the legal power and authority to enter into this Agreement.
8.2. Provider Warranties. Provider warrants that (a) it will provide the Services in a professional and workmanlike manner; (b) the Services will perform materially in accordance with the specifications set forth in the relevant Order Form; and (c) it will comply with all applicable laws and regulations in its provision of the Services.
8.3. Disclaimer. EXCEPT AS EXPRESSLY PROVIDED HEREIN, PROVIDER MAKES NO WARRANTIES OF ANY KIND, WHETHER EXPRESS, IMPLIED, STATUTORY OR OTHERWISE, AND SPECIFICALLY DISCLAIMS ALL IMPLIED WARRANTIES, INCLUDING ANY WARRANTIES OF MERCHANTABILITY OR FITNESS FOR A PARTICULAR PURPOSE, TO THE MAXIMUM EXTENT PERMITTED BY APPLICABLE LAW.
ARTICLE IX: INDEMNIFICATION
9.1. Provider Indemnification. Provider shall defend Client against any third-party claim alleging that Client's use of the Services (as authorized herein) infringes a third party's patent, copyright, or trademark, or misappropriates a trade secret, and shall indemnify Client for any damages finally awarded against Client, and for reasonable attorney’s fees, in connection with such claim, provided that Client (a) promptly gives Provider written notice of the claim; (b) gives Provider sole control of the defense and settlement of the claim; and (c) provides Provider all reasonable assistance.
9.2. Client Indemnification. Client shall defend Provider against any claim arising out of or relating to (a) Client Data, including any claim alleging that the Client Data infringes a third party's rights or violates applicable law; or (b) Client's use of the Services in violation of this Agreement, and shall indemnify Provider for any damages finally awarded against Provider, and for reasonable attorney’s fees, in connection with such claim, provided that Provider (a) promptly gives Client written notice of the claim; (b) gives Client sole control of the defense and settlement of the claim; and (c) provides Client all reasonable assistance.
ARTICLE X: LIMITATION OF LIABILITY
10.1. Limitation of Liability. TO THE MAXIMUM EXTENT PERMITTED BY APPLICABLE LAW, IN NO EVENT SHALL EITHER PARTY'S AGGREGATE LIABILITY ARISING OUT OF OR RELATED TO THIS AGREEMENT, WHETHER IN CONTRACT, TORT OR UNDER ANY OTHER THEORY OF LIABILITY, EXCEED THE TOTAL AMOUNT PAID BY CLIENT TO PROVIDER UNDER THIS AGREEMENT DURING THE TWELVE (12) MONTHS IMMEDIATELY PRECEDING THE EVENT GIVING RISE TO THE CLAIM. THE FOREGOING LIMITATION WILL NOT APPLY TO A PARTY'S INDEMNIFICATION OBLIGATIONS, BREACH OF CONFIDENTIALITY, OR FRAUD.
10.2. Exclusion of Consequential and Related Damages. IN NO EVENT WILL EITHER PARTY HAVE ANY LIABILITY TO THE OTHER PARTY FOR ANY LOST PROFITS, REVENUES OR DATA, OR FOR ANY INDIRECT, SPECIAL, INCIDENTAL, CONSEQUENTIAL, COVER OR PUNITIVE DAMAGES, HOWEVER CAUSED, WHETHER IN CONTRACT, TORT OR UNDER ANY OTHER THEORY OF LIABILITY, AND WHETHER OR NOT THE PARTY HAS BEEN ADVISED OF THE POSSIBILITY OF SUCH DAMAGES. THE FOREGOING DISCLAIMER WILL NOT APPLY TO THE EXTENT PROHIBITED BY APPLICABLE LAW.
ARTICLE XI: GOVERNING LAW AND DISPUTE RESOLUTION
11.1. Governing Law. This Agreement shall be governed by and construed in accordance with the laws of [Jurisdiction, e.g., the State of Delaware, USA], without regard to its conflict of laws principles.
11.2. Dispute Resolution. The Parties agree to first attempt to resolve any dispute arising out of or relating to this Agreement through good faith negotiation. If the dispute cannot be resolved through negotiation within [e.g., thirty (30)] days, the Parties agree to [e.g., submit the dispute to binding arbitration administered by the American Arbitration Association in accordance with its Commercial Arbitration Rules, and judgment on the award rendered by the arbitrator(s) may be entered in any court having jurisdiction thereof. The arbitration shall take place in [City, State].] OR [bring any legal action or proceeding in the courts of [Jurisdiction], and each Party irrevocably submits to the exclusive jurisdiction of such courts.]
ARTICLE XII: MISCELLANEOUS
12.1. Entire Agreement. This Agreement, including all executed Order Forms and SOWs, constitutes the entire agreement between the Parties and supersedes all prior and contemporaneous agreements, proposals, or representations, written or oral, concerning its subject matter.
12.2. Amendments. No amendment or modification of this Agreement shall be effective unless in writing and signed by authorized representatives of both Parties.
12.3. Assignment. Neither Party may assign any of its rights or obligations hereunder, whether by operation of law or otherwise, without the prior written consent of the other Party (not to be unreasonably withheld), except in the case of a merger, acquisition, or sale of substantially all of its assets.
12.4. Notices. All notices required or permitted under this Agreement will be in writing and delivered by email, personal delivery, overnight courier, or certified mail to the addresses specified at the beginning of this Agreement, or such other address as either Party may specify by notice to the other Party.
12.5. Force Majeure. Neither Party shall be liable for any failure or delay in performance under this Agreement due to causes beyond its reasonable control, including, but not limited to, acts of God, war, terrorism, riots, embargoes, acts of civil or military authorities, fire, floods, accidents, strikes, or shortages of transportation, facilities, fuel, energy, labor or materials.
122.6. Severability. If any provision of this Agreement is held by a court of competent jurisdiction to be contrary to law, the provision will be deemed null and void, and the remaining provisions of this Agreement will remain in effect.
12.7. Counterparts. This Agreement may be executed in counterparts, each of which shall be deemed an original, but all of which together shall constitute one and the same instrument.
IN WITNESS WHEREOF, the Parties have executed this Master Services Agreement as of the Effective Date.
PROVIDER:
[Company Name]
By: ______________________________
Name: [Authorized Signatory Name]
Title: [Authorized Signatory Title]
CLIENT:
[Client Company Name]
By: ______________________________
Name: [Authorized Signatory Name]
Title: [Authorized Signatory Title]
Best Practices for Execution using Electronic Signature SaaS (DocuSign, Adobe Sign)
Executing B2B legal documents like MSAs and DPAs digitally using electronic signature platforms has become the industry standard for efficiency and legal enforceability. Platforms like DocuSign and Adobe Sign offer robust solutions. Here are best practices:
- Choose a Reputable Platform: Ensure the e-signature provider complies with relevant laws like the ESIGN Act (U.S.), UETA (U.S.), and eIDAS Regulation (EU), ensuring legal validity and enforceability of signatures.
- Clear Document Preparation: Upload a final, reviewed version of the MSA and DPA. Ensure all fields for signatures, dates, and initials are clearly marked for both parties.
- Identity Verification: Utilize the platform's features for identity verification beyond a simple click. Options include email verification, SMS authentication, or even more advanced methods for high-value agreements.
- Audit Trail & Records: Ensure the platform generates a comprehensive audit trail, recording every action taken on the document (viewed, signed, IP addresses, timestamps). This trail is crucial for proving the authenticity and integrity of the agreement in case of a dispute. Download and securely store this certificate of completion.
- Controlled Access: Restrict access to the signing process to authorized individuals within each organization. Ensure only the designated signatories receive the signing link.
- Final Review: Before sending for signature, conduct a final legal and business review of the entire document to catch any last-minute errors or omissions.
- Retention Policy: Establish a clear policy for retaining fully executed copies of the MSA and DPA. Both parties should receive and archive a copy of the final, signed document.
Frequently Asked Questions (FAQs)
1. What is the difference between an MSA and an SOW/Order Form?
An MSA (Master Services Agreement) is a foundational contract that establishes the general terms and conditions for all present and future services between two parties. It covers broad legal points like warranties, indemnification, confidentiality, and dispute resolution. An SOW (Statement of Work) or Order Form is a separate document that references the MSA and outlines the specific details of a particular project or service engagement, including scope, deliverables, timelines, and fees. The MSA provides the legal 'umbrella,' while SOWs/Order Forms detail the 'work orders' under that umbrella.
2. Why is an integrated DPA important for SaaS companies, even for small businesses?
An integrated DPA is crucial for SaaS companies of all sizes because most SaaS solutions involve processing some form of personal data on behalf of clients (e.g., user login data, customer contact info, analytics). Data protection laws like GDPR and CCPA mandate specific contractual terms between a data controller (your client) and a data processor (your SaaS company) to ensure data is handled securely and lawfully. Failure to have a compliant DPA can lead to significant fines, reputational damage, and loss of client trust, regardless of the company's size.
3. Can this template be used for services outside of SaaS?
While this template is specifically tailored for B2B SaaS, many of its core MSA clauses (e.g., confidentiality, indemnification, general service terms) are applicable across various service industries. However, the "Services" article and the integrated "Data Processing" article are highly specific to SaaS and data processing roles under GDPR/CCPA. If adapting for non-SaaS services, these sections would require significant modification to accurately reflect the nature of the services and any associated data handling, or potentially be removed entirely if no personal data is processed. Always consult with legal counsel for adaptation.
Comments
Post a Comment