Privacy documentation for your SaaS clients
SaaS clients: the documents their customers ask for
A software company is asked for its DPA, its subprocessor list and a security questionnaire before every larger deal. Prepare them from one interview and keep them current as its vendors change.
A DPA its customers can sign
The processor terms of Article 28, with the security measures and subprocessors taken from the client's confirmed facts and vendor list.
Subprocessors from a registry
Legal entity, country, transfer mechanism and DPA link for each vendor, and a flag on every client that uses a vendor when that vendor changes its terms.
Questionnaires from the documents
The security questionnaires its customers send are drafted from the client's own documents, each answer marked confirmed, to check or gap.
The pack for a client like this
With GDPR, UK GDPR enabled. NIS2 and the AI Act are add-on modules, enabled per client once you confirm they apply.
- Privacy policy
- Cookie policy
- Data processing agreement
- Subprocessor list
- Records of processing activities
- Retention schedule
- Data subject request procedure
- Access control policy
- Incident response policy
- Business continuity and disaster recovery policy
- Secure development policy
- Vendor management policy
- Acceptable use policy
- Security overview
Not covered
Said here rather than found out later.
- SOC 2 or ISO 27001 certification
- Monitoring of the client's infrastructure or collection of evidence
See what changed since your clients' policies were written
Enter up to ten client websites. Free, no sign-up, the first report in about a minute.