Establishing secure connection…Loading editor…Preparing document…

Processor Services Agreement

This template is fully customizable. Edit the text, fill out the fields, and send it for signature. Give it a try!

PROCESSOR SERVICES AGREEMENT

This Processor Services Agreement (the "Agreement") is entered into as of Effective Date: by and between Client Name: , a Corporation LLC Other, with principal place of business at (\"Client\"); and Processor Name: , a Corporation LLC Other, with principal place of business at (\"Processor\").

RECITALS

WHEREAS, Client engages Processor to perform certain data processing, operational and technical services as described herein; and

WHEREAS, Processor has represented that it has the personnel, procedures, systems and security controls necessary to perform such services in compliance with applicable law and the terms of this Agreement; and

WHEREAS, the parties desire to set forth the terms and conditions under which Processor will provide such services and will process Client Data.

NOW, THEREFORE, in consideration of the mutual promises set forth below, the parties agree as follows:

1. DEFINITIONS

For purposes of this Agreement, the following terms shall have the following meanings:

"Services" means the processing, hosting, maintenance, analytics and other services to be performed by Processor for Client as described in Section 2 and in the Services Description.

"Client Data" means all data, including personal data, provided by or on behalf of Client to Processor for processing in connection with the Services.

"Applicable Law" means any law, regulation, or regulatory requirement applicable to the collection, use, processing, storage, disclosure or transfer of Client Data.

2. SERVICES

2.1 Scope. Processor shall provide Services to Client in accordance with the Service Description below and subject to the terms of this Agreement. Processor shall perform the Services in a professional and workmanlike manner consistent with industry standards.

2.2 Service Levels. Processor will use commercially reasonable efforts to meet service levels set forth in the Service Description. If Processor fails to meet material service levels, Client may seek remedies as set forth in the Service Description or, if none provided, the parties will agree in writing on appropriate credits.

3. TERM AND TERMINATION

3.1 Term. The term of this Agreement shall commence on the Effective Date and continue for a period of unless earlier terminated in accordance with this Agreement.

3.2 Termination for Cause. Either party may terminate this Agreement for material breach by the other party if such breach remains uncured thirty (30) days after written notice specifying the breach.

3.3 Termination for Convenience. Client may terminate this Agreement for convenience upon days' prior written notice and payment of all fees due for Services rendered through the effective date of termination.

4. FEES AND PAYMENT

4.1 Fees. Client shall pay Processor the fees set forth below or on invoices delivered in accordance with this Section. Fees are due net days from the date of invoice.

4.2 Taxes. Fees do not include taxes. Client shall be responsible for sales, use, value added or similar taxes, excluding taxes based on Processor's income.

5. DATA PROTECTION AND SECURITY

5.1 Processing. Processor shall process Client Data only on documented instructions from Client and shall not process Client Data for any purpose other than to provide the Services unless required by Applicable Law, in which case Processor shall notify Client to the extent permitted by law.

5.2 Security Measures. Processor shall implement and maintain appropriate technical and organizational measures to protect Client Data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure or access. These measures shall include, at a minimum, those described in the Service Description and the following selected standards: SOC 2 ISO 27001 Other

6. CONFIDENTIALITY

Each party shall maintain in confidence and shall not disclose Confidential Information of the other party, except as necessary to perform its obligations under this Agreement. Confidential Information includes Client Data and any non-public business or technical information. Obligations of confidentiality shall survive termination for a period of five (5) years, except for trade secrets which shall survive for as long as they remain trade secrets.

7. INTELLECTUAL PROPERTY

Client retains all right, title and interest in Client Data and any intellectual property owned or provided by Client. Processor retains all right, title and interest in Processor's pre-existing tools, software and methodologies. Any intellectual property developed exclusively for Client as a deliverable under this Agreement shall be owned by Client upon full payment; Processor may retain background know-how.

8. REPRESENTATIONS AND WARRANTIES

Each party represents and warrants that it has the full power and authority to enter into this Agreement and to perform its obligations hereunder. Processor warrants that it will perform the Services in accordance with this Agreement and with materially applicable industry standards.

9. INDEMNIFICATION

Processor shall indemnify, defend and hold harmless Client from and against any third-party claims arising out of Processor's breach of its confidentiality or data protection obligations, or Processor's negligence or willful misconduct in performing the Services. Client shall indemnify Processor for claims arising from Client Data that infringes a third party's intellectual property.

10. LIMITATION OF LIABILITY

Except for liability resulting from wilful misconduct, gross negligence, indemnification obligations or breach of confidentiality, each party's aggregate liability arising under or related to this Agreement shall not exceed the total fees paid by Client to Processor under this Agreement in the twelve (12) months preceding the event giving rise to liability. Neither party shall be liable for lost profits, loss of data or indirect, incidental, punitive or consequential damages.

11. INSURANCE

Processor shall maintain commercially reasonable insurance coverage including, at a minimum, commercial general liability and cyber liability insurance in amounts not less than USD and shall provide certificates upon request.

12. AUDIT AND INSPECTION

Client, or an independent auditor engaged by Client, shall have the right to audit Processor's relevant records and facilities to verify compliance with this Agreement upon reasonable prior written notice not less than days and during normal business hours. Such audits shall be conducted no more than once annually unless required by Applicable Law or a material breach.

13. SUBPROCESSORS

Processor may engage subprocessors to perform parts of the Services provided that Processor imposes written obligations on any subprocessor that are no less protective than those contained in this Agreement. Processor shall provide Client with notice of any intended new subprocessor and shall obtain Client's written consent where required by Applicable Law.

14. NOTICES

All notices, requests, consents and other communications required or permitted under this Agreement shall be in writing and delivered to the addresses set forth below or as otherwise notified in writing by a party.

15. ASSIGNMENT

Neither party may assign this Agreement without the prior written consent of the other party, except that either party may assign this Agreement in connection with a merger, acquisition or sale of substantially all of its assets, provided the assignee assumes all obligations hereunder.

16. AMENDMENTS; WAIVER

No amendment, modification or waiver of any provision of this Agreement shall be effective unless in writing and signed by authorized representatives of both parties. A waiver of any breach shall not be deemed a waiver of any subsequent breach.

17. GOVERNING LAW; VENUE

This Agreement shall be governed by and construed in accordance with the laws of the jurisdiction specified below. The parties submit to the exclusive jurisdiction of the courts located in such jurisdiction for any disputes arising under this Agreement.

18. ENTIRE AGREEMENT; SEVERABILITY; COUNTERPARTS

This Agreement, together with any exhibits or attachments hereto, constitutes the entire agreement between the parties with respect to the subject matter hereof and supersedes all prior agreements and understandings. If any provision is held invalid or unenforceable, the remaining provisions shall remain in full force and effect. This Agreement may be executed in counterparts, each of which shall be deemed an original and all of which together shall constitute one and the same instrument.

MISCELLANEOUS

The headings used in this Agreement are for convenience only and shall not affect interpretation. Each party shall comply with all Applicable Law in performing its obligations under this Agreement.

Client Printed Name:

By:

Date:

Processor Printed Name:

By:

Date:

Enter text✕

What a Processor Services Agreement Covers

A Processor Services Agreement is a contract that defines the relationship between a data controller (the party that determines the purposes and means of processing) and a data processor (the party that processes personal data on behalf of the controller). It sets the permitted processing activities, security and privacy obligations, breach notification procedures, audit and subcontractor rules, liability allocation, and term and termination mechanics. In U.S. contexts the agreement should also address regulatory requirements such as HIPAA for health data, PCI obligations for card data, and provisions that ensure enforceability under ESIGN and applicable state laws.

Why this agreement matters for compliance and risk control

A Processor Services Agreement clarifies responsibilities and reduces regulatory, operational, and contractual risk by documenting security controls, incident response, and data-handling limits. It helps meet ESIGN/UETA requirements for electronic contracting and supports HIPAA/PCI compliance where applicable, providing documentation regulators and partners expect.

Why this agreement matters for compliance and risk control

Who typically completes a Processor Services Agreement

Organizations use these agreements when one party will process personal or sensitive information on behalf of another; multiple teams typically contribute to completion.

  • Corporate legal teams and contract managers coordinating terms, indemnities, and liability allocations.
  • Security or privacy officers specifying technical and organizational controls and audit rights.
  • Procurement and vendor management teams reviewing SLAs, subcontractor rules, and termination rights.

Final signatures are usually provided by authorized signatories (general counsel, VP of operations, or an officer) after legal, security, and procurement approvals.

Core sections to include in a professional agreement

A comprehensive Processor Services Agreement contains distinct clauses that allocate duties, define limits, and create measurable obligations between controller and processor.

Scope of Processing

Describe precisely what data is processed, why processing is necessary, permitted activities, and any prohibited uses; narrow scopes reduce compliance and liability risk.

Security Measures

Specify technical and organizational controls such as encryption, access control, vulnerability management, and monitoring, including minimum baselines and audit rights.

Subprocessors

Define whether subprocessors are allowed, notification or approval processes, and flow-down obligations that ensure subcontractors meet the same requirements.

Incident Response

Set timelines and responsibilities for breach detection, notification to the controller, cooperation steps, forensic efforts, and regulatory reporting support.

Audit and Records

Include rights to audit or request evidence, frequency limits, remediation windows, and acceptable formats for audit results and evidence.

Termination and Return

Provide post-termination handling: secure return or destruction of data, certification of destruction, and transitional assistance to avoid data loss or service interruption.

Essential identification and administrative details

Processor Legal Name: Full registered entity name
Controller Name: Full legal entity name
Contact Information: Mailing address and primary email
Effective Date: MM/DD/YYYY
Scope Summary: High-level service description
Signature Block: Authorized signatory name and title

Filling out a Processor Services Agreement: step-by-step

Follow these sequential steps to prepare, review, and finalize the agreement with minimal rework.

  • 01
    Draft Scope: Define data categories, processing purposes, and duration clearly.
  • 02
    Specify Controls: List security measures and certification obligations required of the processor.
  • 03
    Review Liability: Agree on indemnities, caps, and exclusions with legal counsel.
  • 04
    Sign and Record: Execute with authorized signatures and retain an auditable copy.

Configuring an online signing workflow

Set up digital workflows so signatures, evidence, and routing are consistent and auditable before sending to signers.

Field Configuration
Signature Block Require signer name, title, date fields; make signature required.
Authentication Use email + SMS code or stronger verification for high-risk signers.
Order Set signer sequence when approvals must be sequential.
Retention Automatically archive signed PDF and audit trail on completion.

Where to send the completed agreement

Identify final destinations and internal routing to ensure legal and security records are maintained.

  • Legal Repository: Store executed PDF and audit trail in contract management system.
  • Security Team: Provide copy for SOC/Security reviews and retention logs.
  • Vendor Records: Processor keeps a signed copy and subcontractor list.
  • Privacy Officer: Forward for breach-response planning and training updates.

Digital signing and submission requirements

Use platforms that create a verifiable audit trail, support intended authentication strength, and preserve signed records in industry-standard files.

  • File Types: PDF or PDF/A preferred for long-term retention
  • Authentication: Email + code or stronger KBA/2FA for sensitive agreements
  • Audit Trail: Include IP, timestamp, and action history

Select an eSignature vendor that supports exportable audit records, optional stronger signer authentication, and the ability to attach BAAs or data processing addenda when required.

Key timeline items and typical deadlines

Common timing items that should appear in the agreement and internal workflows are listed below.

Effective Date:

Date parties agree obligations begin; use MM/DD/YYYY.

Term Length:

Set defined term or 'until terminated' plus notice terms.

Termination Notice:

Typical notice: 30–90 days depending on risk and SLAs.

Breach Notification:

Processor must notify controller promptly; often within 72 hours.

Data Return/Deletion:

Complete return or certified deletion within 30–90 days after termination.

Common mistakes to avoid when preparing the agreement

  • Leaving the scope vague, which can lead to unexpected processing and regulatory exposure.
  • Failing to require subprocessors to follow the same security and contractual obligations as the processor.
  • Omitting clear timelines and responsibilities for breach notification and remediation.
  • Not defining data return or destruction procedures, risking residual copies and compliance gaps.

Key risks and potential penalties

Regulatory Fines: HIPAA and state privacy fines
Contract Damages: Breach may trigger indemnity and liability exposure
Operational Disruption: Termination can interrupt service delivery
Reputational Harm: Public breaches harm trust and business
Mandatory Reporting: Notification obligations to affected individuals
Enforcement Costs: Legal and remediation expenses

Typical authorized signatory roles

Authorized Signatory

General counsel or corporate officer: signs for legal acceptance, binds the company to indemnities, liability caps, and compliance obligations; typically provides company title and authority statement.

Data Protection Officer

Security or privacy lead: reviews technical controls and breach processes, certifies security attestations, and coordinates operational onboarding and audits.

Key milestones from negotiation through decommission

These stages track the agreement lifecycle from drafting to final data disposition and transitional support.

01

Drafting and Internal Review

Legal and security review completed; negotiate key terms.

02

Execution

Authorized signatures obtained and auditable copy stored.

03

Onboarding and Audit

Security assessments and evidence exchanged; subprocessors confirmed.

04

Termination and Data Return

Data returned or securely destroyed per contract timelines.

Typical eSignature vendor comparison for executing agreements

Platform pricing and feature differences affect cost, compliance, and operational fit. signNow is listed first for orientation.

signNow DocuSign Adobe Sign PandaDoc HelloSign
Starting Price $8/user/mo $15/user/mo $14/user/mo $19/user/mo $15/user/mo
Free Trial 7-day free trial Varies Varies Varies Varies
Bulk Send Yes Yes Yes Yes No
Audit Trail Yes Yes Yes Yes Yes
HIPAA Compliant Yes Yes Yes No No
Envelope Cap No cap 100 envelopes/user/year Varies Varies Varies

Frequently asked questions about Processor Services Agreements

Answers to common legal, technical, and operational questions encountered when preparing and executing these agreements.


Need help? Contact support

be ready to get more
Join over 28 million airSlate SignNow users