Incorporation
This Data Processing Addendum (“DPA”) is between the Organization that uses TeamDots (“Customer”) and SoftAge Systems, Inc. d/b/a TeamDots (“Company,” “SoftAge,” “we,” “us,” or “our”). It forms part of the TeamDots Terms of Service and any Order. If Customer and SoftAge sign a separate DPA, that signed document controls.
This DPA applies only to SoftAge’s processing of personal data in Customer Data as a processor (or subprocessor to Customer’s processor). It does not apply to SoftAge’s independent controller processing described in the Privacy Policy (for example, Website visitors or SoftAge billing contacts).
Definitions
“Data Protection Law” means GDPR, UK GDPR, and other laws that apply to the processing of personal data under this DPA. “Personal Data,” “processing,” “controller,” “processor,” “subprocessor,” and “data subject” have the meanings in Data Protection Law. Other capitalized terms follow the Terms.
Roles
Customer is the controller of Personal Data in Customer Data (or a processor that engages SoftAge as a subprocessor). SoftAge is the processor. Each party will comply with Data Protection Law in its role.
Customer’s instructions are: (a) process Personal Data to provide, secure, maintain, and support the Service as configured by Customer; (b) process as documented in the Terms, this DPA, and the product; and (c) process as required by law, in which case SoftAge will notify Customer unless the law forbids notice.
Details of processing
Subject matter, duration, nature, and purpose follow the Service and the subscription term, plus a commercially reasonable deletion period afterward.
Typical data subjects and types (as Customer chooses to submit)
- Users, members, employees, contractors, customers, vendors, prospects, form respondents, signers, and other contacts
- Identity and contact data, business records, documents, messages, calendar and work data, form submissions, signature audit records, and usage/security logs related to the workspace
Personnel
SoftAge will ensure people authorized to process Personal Data are bound by confidentiality and receive security training appropriate to their role.
Security
SoftAge will implement appropriate technical and organizational measures designed to protect Personal Data, consistent with the Security page and the nature of the Service. Customer is responsible for configuring available workspace controls and for deciding whether those measures are appropriate for Customer’s risk.
Subprocessors
Customer authorizes SoftAge to engage subprocessors to provide hosting, email, storage, payments, CAPTCHA, document rendering, model inference, and similar infrastructure. SoftAge will impose data-protection terms on subprocessors that are no less protective of Personal Data than this DPA in all material respects, and remains responsible for their performance as processor.
A current list of core subprocessors is published at /subprocessors. SoftAge will give Customer notice of a material addition or replacement of a core subprocessor (by email to an Administrator, in the product, or on that page) and a reasonable opportunity to object on data-protection grounds. If the parties cannot resolve an objection, Customer may terminate the affected Service as in the Terms.
International transfers
SoftAge may process Personal Data in the United States and other countries where SoftAge or its subprocessors operate. Where Data Protection Law requires a transfer mechanism, SoftAge will use an approved mechanism (such as standard contractual clauses) or another lawful basis, including as exporter or importer as the clauses require.
Assistance
Taking into account the nature of processing, SoftAge will assist Customer by appropriate technical and organizational measures, insofar as possible, with Customer’s obligations to respond to data-subject requests, and with security, breach, data-protection impact assessments, and consultations with authorities, in each case related to Personal Data in the Service.
Customer is responsible for the substance of responses to data subjects. SoftAge will not respond to a data-subject request about Customer Data except to direct the person to Customer, unless required by law.
Personal data breach
SoftAge will notify Customer without undue delay after becoming aware of a personal data breach affecting Customer Data, and will provide information Customer reasonably needs to meet its own notification duties. Target timing is 72 hours where GDPR applies and SoftAge is the processor, subject to investigation constraints. Notification is not an admission of fault.
Return and deletion
During the term, Customer may export Customer Data using available product tools. After the Service ends, SoftAge will delete Personal Data from active systems after a commercially reasonable period, unless law requires retention (including backups and legal holds, which expire on their ordinary cycle).
Audits
On written request no more than once per 12 months (unless a competent authority or a documented breach requires sooner), SoftAge will make available information reasonably necessary to demonstrate compliance with this DPA, which may include security summaries or, if SoftAge holds a current independent report (for example SOC 2), that report under NDA. On-site audits are only by mutual agreement, during business hours, and at Customer’s expense unless the audit reveals a material DPA breach by SoftAge.
This DPA does not represent that SoftAge currently holds SOC 2, HIPAA, PCI DSS, or similar certifications.
Liability
Liability under this DPA is subject to the limitations and exclusions in the Terms, except where Data Protection Law forbids that limitation as between the parties.
Contact
DPA and subprocessor questions: info@softage.com. Notices: 300 S. Duval Street, Ste. 410, Tallahassee, FL 32301, United States. Email: info@softage.com
SoftAge Systems, Inc.
d/b/a TeamDots
300 S. Duval Street, Ste. 410
Tallahassee, FL 32301
United States
Effective August 28, 2026.
Related: Terms of Service · Privacy Policy · Subprocessors · Contact about the DPA