> ## Documentation Index
> Fetch the complete documentation index at: https://help-center-starter-replace-template-content.mintlify.site/llms.txt
> Use this file to discover all available pages before exploring further.

# Data processing addendum

> Mintlify's data processing addendum for GDPR and enterprise compliance.

Mintlify offers a Data Processing Addendum (DPA) for customers who need to formalize the data processing relationship under GDPR or other data protection regulations.

## When you need a DPA

You may need a DPA if:

* Your organization is subject to GDPR (you're based in the EU or process data of EU residents).
* Your organization's security or legal team requires a signed data processing agreement with vendors.
* Your procurement process requires formal documentation of data processing relationships.

## Getting a signed DPA

**Self-serve (Growth plans):** Download and sign Mintlify's standard DPA from **Settings → Legal → DPA**. The standard DPA covers the most common requirements for GDPR compliance.

**Custom DPA (Enterprise):** Enterprise customers can negotiate custom DPA terms. Contact [legal@mintlify.com](mailto:legal@mintlify.com) with your requirements.

## What the DPA covers

Mintlify's DPA addresses:

* Roles: Mintlify acts as a data processor; you act as the controller.
* Processing purposes and lawful basis.
* Technical and organizational security measures.
* Subprocessor obligations and change notification.
* Data subject rights and breach notification procedures.
* Cross-border data transfer mechanisms (SCCs for EU-US transfers).

## Subprocessors

Mintlify uses third-party subprocessors to deliver the service. See [Subprocessors](/support/legal/privacy/subprocessors) for the current list. Mintlify notifies customers of subprocessor changes with 30 days' notice.
