Establishing secure connection…Loading editor…Preparing document…

Data Storage IPFS Agreement

This template is fully customizable. Edit the text, fill out the fields, and send it for signature. Give it a try!

DATA STORAGE IPFS AGREEMENT

This Data Storage IPFS Agreement (the Agreement) is entered into as of Effective Date: by and between Service Provider Name: with address and Client Name: with address .

RECITALS

WHEREAS, Service Provider maintains distributed content-addressable storage services utilizing the InterPlanetary File System (IPFS) and ancillary services to store, pin, and replicate client data; and

WHEREAS, Client desires to engage Service Provider to store certain Data Assets on IPFS subject to the terms and conditions set forth in this Agreement, and Service Provider desires to provide such services on the terms herein;

WHEREAS, the parties intend to set forth the scope, compensation, security, retention, and liability allocation for the storage of Data Assets on IPFS as described below.

DEFINITIONS

For the purposes of this Agreement: (a) "Data Assets" means the files, data sets and metadata that Client transmits to Service Provider for storage; (b) "Pinning" means the process of retaining a copy of content on IPFS nodes such that the content remains available; (c) "Confidential Information" has the meaning set forth in the Confidentiality section below.

SCOPE OF WORK

Service Provider shall: (i) accept Data Assets from Client, (ii) persist Data Assets on IPFS and implement Pinning and replication as described in the Scope of Work, (iii) provide access endpoints or content identifiers (CIDs) to Client, and (iv) maintain reasonable operational measures to preserve availability and integrity of Data Assets in accordance with this Agreement.

PAYMENT TERMS

Payment is due in accordance with the Payment Schedule. Overdue amounts shall accrue interest at the rate set forth below until paid in full.

TERM AND TERMINATION

This Agreement commences on Start Date: and continues until End Date: unless earlier terminated in accordance with this Section.

Either party may terminate for material breach if such breach is not cured within thirty (30) days after written notice. Termination shall not relieve Client of its obligation to pay for services rendered or costs incurred prior to the effective date of termination. Upon termination, Service Provider will, at Client's written direction and subject to payment of outstanding fees, either transfer Data Assets to a Client-designated location or delete Data Assets as described in the Data Retention and Deletion clause.

CONFIDENTIALITY

Each party shall treat as Confidential Information all non-public information disclosed by the other party in connection with this Agreement, including Data Assets and any encryption keys or access credentials. Confidential Information shall remain confidential during the Term and for a period of years thereafter. Confidential Information does not include information that is or becomes generally known to the public other than through a breach of this Agreement, or is rightfully received from a third party without restriction.

DATA HANDLING, SECURITY AND RETENTION

Service Provider will implement commercially reasonable technical and organizational measures to protect Data Assets against unauthorized access, disclosure, alteration and loss. Client acknowledges that IPFS is a distributed network and that CIDs reference content-addressed data. Service Provider shall:

  1. Provide Pinning and replication consistent with the Scope of Work to facilitate availability of Data Assets.
  2. Support encryption-at-rest and encryption-in-transit where applicable; Client is responsible for managing encryption keys unless otherwise agreed in writing.
  3. Maintain reasonable backup and redundancy practices; however Service Provider does not guarantee immutable perpetual storage unless specifically contracted.

Upon Client's written request and subject to payment of any outstanding fees, Service Provider will make commercially reasonable efforts to export and deliver Client's Data Assets in a commonly used format or to remove Client Data from Service Provider-maintained pins and replicas. Due to the distributed nature of IPFS, Service Provider does not and cannot guarantee removal of copies of Data Assets that have been independently replicated by third parties.

INTELLECTUAL PROPERTY AND DATA OWNERSHIP

Client retains all right, title and interest in and to Client's Data Assets. Service Provider shall not acquire any ownership rights in Client Data by virtue of providing storage services. Service Provider is granted a limited license to copy, cache, replicate and display Data Assets solely to the extent necessary to perform its obligations under this Agreement.

LIMITATION OF LIABILITY AND INDEMNIFICATION

Except for breaches of confidentiality or willful misconduct, in no event shall either party be liable for consequential, incidental, special or punitive damages arising out of or related to this Agreement. Service Provider's aggregate liability for any claim arising from or related to this Agreement shall not exceed the total fees paid by Client to Service Provider under this Agreement in the twelve (12) months preceding the claim. Client shall indemnify and hold harmless Service Provider from third-party claims arising from Client's content, infringement, or unlawful use of Data Assets.

COMPLIANCE WITH LAWS

Each party shall comply with applicable laws, regulations and industry standards in the performance of its obligations under this Agreement. Client represents that it has all rights and consents necessary to store the Data Assets on IPFS and to transmit them to Service Provider.

GOVERNING LAW

This Agreement shall be governed by and construed in accordance with the laws of the State of without regard to its conflicts of law principles.

ENTIRE AGREEMENT

This Agreement, together with any exhibits or appendices expressly incorporated by reference, constitutes the entire agreement between the parties with respect to the subject matter hereof and supersedes all prior and contemporaneous agreements, proposals and communications, whether written or oral. No amendment or waiver shall be effective unless in writing and signed by authorized representatives of both parties.

MISCELLANEOUS

Assignment: Neither party may assign this Agreement without the prior written consent of the other party, except that Service Provider may assign to an affiliate or in connection with a merger or sale of substantially all its assets. Force Majeure: Neither party shall be liable for delays due to causes beyond its reasonable control.

Pin maintenance and monitoring
Optional key management services
Priority support and expedited retrieval

Service Provider:

By:

Date:

Client:

By:

Date:

Enter text✕

What a Data Storage IPFS Agreement Is and when it applies

A Data Storage IPFS Agreement is a contract that sets out the terms governing storage, retrieval, access control, and responsibilities for data placed on the InterPlanetary File System (IPFS). It clarifies who provides storage nodes or pinning services, how content addressing and content identifiers (CIDs) are handled, data availability expectations, uptime or pinning commitments, encryption and key management responsibilities, permitted use and takedown procedures, liability allocation, and data ownership or licensing. For U.S. contexts the agreement should also address regulatory obligations such as HIPAA for protected health information or financial recordkeeping requirements when applicable.

Why a tailored IPFS storage agreement matters for risk and compliance

A purpose-built agreement creates clear obligations for storage providers and data owners, reduces operational ambiguity around pinning and persistence, and documents security responsibilities needed for regulatory compliance such as HIPAA or IRS requirements. It supports legal enforceability by recording intent, consent, attribution, and retention capabilities consistent with ESIGN and UETA.

Why a tailored IPFS storage agreement matters for risk and compliance

Who typically uses a Data Storage IPFS Agreement

Organizations and individuals who place regulated or business-critical files onto distributed storage platforms rely on a formal agreement to define service levels and legal responsibilities.

  • Technology companies and SaaS providers managing decentralized file distribution and pinning services.
  • Healthcare organizations and vendors when patient data or PHI is involved and HIPAA protections apply.
  • Legal and financial firms that need chain-of-custody, retention, and access controls for records.

The agreement helps each party understand operational steps, risk allocation, and the recordkeeping obligations necessary to satisfy internal controls and applicable U.S. laws.

Filling out a Data Storage IPFS Agreement — step-by-step

Follow this sequence to complete the agreement accurately and consistently.

  • 01
    Identify Parties: Enter full legal names for data owner and storage provider.
  • 02
    Define Scope: List data types, CIDs, and services covered by the agreement.
  • 03
    Security Duties: Specify encryption, key custody, and access controls.
  • 04
    Retention Terms: State retention periods, deletion triggers, and export processes.

Common questions about completing and enforcing an IPFS storage agreement

Answers to frequent questions clarify legal validity, signing, and common operational issues in U.S. deployments.


Need help? Contact support

Core clauses to include in a professional IPFS storage agreement

These provisions form the backbone of a robust agreement and reduce ambiguity across operations, security, and liability.

Service Scope

Define services (pinning, replication, gateway access), specific CIDs or dataset IDs covered, and any excluded content or activities.

Availability and SLAs

Specify uptime targets, pin persistence guarantees, measurable metrics, and credits or remedies for SLA breaches.

Security Controls

Document encryption standards, authentication, key management responsibilities, logging, and breach notification processes.

Data Access and Rights

Clarify who may request or retrieve content, any search or indexing allowances, and licensing terms for derivative use.

Compliance and Audits

Identify applicable laws (HIPAA, state privacy laws), audit rights, and evidence the provider must retain to demonstrate compliance.

Liability and Indemnity

Allocate responsibility for data loss, unauthorized disclosure, and third-party claims; include caps and carve-outs for gross negligence.

Security, privacy, and technical controls to document

Encryption in Transit: TLS 1.2/1.3
Encryption at Rest: AES-256
Access Controls: Role-based access
Audit Trail: Timestamped logs
Certifications: SOC 2, ISO 27001
HIPAA Support: BAA available

Common legal and operational risks to address explicitly

Data Loss: Potential unrecoverable content
Unauthorized Access: Exposure of sensitive data
Regulatory Fines: HIPAA or financial penalties
Breach Notification: Timing and liabilities
Intellectual Property: Ownership disputes
Service Termination: Retention and export obligations

Practical pitfalls teams commonly encounter

  • Overbroad storage commitments that promise indefinite persistence without defining pinning methods or measurable redundancy can create false expectations and later disputes.
  • Failing to specify key custody and recovery procedures leaves data owners exposed to permanent loss if keys are misplaced or destroyed.
  • Ambiguous incident response timelines and notification thresholds delay remediation and can increase exposure to regulatory penalties or contractual damages.
  • Not aligning retention terms with statutory requirements (for example HIPAA or IRS rules) can result in noncompliance and added legal risk.

Typical eSignature vendor pricing and capability snapshot for agreement execution

Comparison of starter pricing and selected capability flags across common eSignature providers. signNow is listed first per vendor ordering rules.

signNow DocuSign Adobe Sign PandaDoc HelloSign
Starting Price $8/user/mo $15/user/mo $14/user/mo $19/user/mo $15/user/mo
Free Trial 7-day free trial Varies by plan Varies by plan Varies by plan Varies by plan
Bulk Send Yes (Premium tier) Yes Yes Yes No
Audit Trail Yes Yes Yes Yes Yes
HIPAA Compliant Yes Yes Yes No No
Envelope Cap No cap 100 envelopes/user/year Varies by plan Varies by plan Varies by plan

Configuring an online signing workflow for the agreement

Typical configuration settings when preparing the document for electronic signing and eSubmission.

Upload Document PDF or DOCX file upload; preserve original formatting.
Add Signature Fields Place signature, initials, and date fields for each signer.
Set Authentication Choose email, SMS code, or knowledge-based options.
Signer Order Set serial or parallel signing as required.
Enable Audit Trail Record timestamps, IP addresses, and certificate.

How eSigning and eSubmission works for the IPFS agreement

The operational flow below shows the common steps from preparation to archival.

  • Prepare: Draft and attach exhibits such as CID lists and security addenda.
  • Invite: Send signing links or email invitations to parties.
  • Authenticate: Signer confirms identity via chosen method and reviews terms.
  • Complete: Signed copy and audit trail are generated and stored.
be ready to get more
Join over 28 million airSlate SignNow users