Data Processing Addendum (DPA)

Data Processing Addendum (DPA)

Website: https://www.woodseitlanderson.com/

Effective Date: July 22, 2026

1. Purpose

This Data Processing Addendum (“DPA”) forms part of any agreement (“Agreement”) between Wood Seitl & Anderson (“Processor,” “Service Provider,” “we,” “our,” or “us”) and any client or business partner (“Controller,” “Customer,” or “you”) where we process Personal Data on your behalf.

This DPA establishes the parties’ obligations regarding the processing of Personal Data in accordance with applicable data protection and privacy laws.


2. Definitions

For purposes of this DPA:

Applicable Privacy Laws means all applicable privacy and data protection laws, including, where applicable:

  • General Data Protection Regulation (EU) 2016/679 (“GDPR”)
  • UK GDPR
  • California Consumer Privacy Act, as amended by the California Privacy Rights Act (“CCPA/CPRA”)
  • Other applicable U.S. federal and state privacy laws

Controller means the entity determining the purposes and means of processing Personal Data.

Processor means the entity processing Personal Data on behalf of the Controller.

Personal Data means any information relating to an identified or identifiable individual as defined under applicable law.

Processing means any operation performed on Personal Data, including collection, storage, use, disclosure, transmission, or deletion.


3. Scope

This DPA applies whenever Wood Seitl & Anderson processes Personal Data on behalf of a client in connection with legal services or other professional services provided under the Agreement.


4. Nature and Purpose of Processing

Processing activities may include:

  • Receiving client communications
  • Managing legal matters
  • Preparing legal documents
  • Communicating with clients
  • Managing consultations
  • Maintaining client records
  • Responding to legal inquiries
  • Providing professional legal services
  • Complying with legal obligations

5. Categories of Personal Data

Depending on the services provided, Personal Data may include:

  • Names
  • Addresses
  • Email addresses
  • Telephone numbers
  • Business information
  • Client communications
  • Billing information
  • Case-related information
  • Government-issued identification (where required)
  • Other information voluntarily provided by clients

The specific categories processed depend upon the services requested.


6. Categories of Data Subjects

Personal Data may relate to:

  • Current clients
  • Prospective clients
  • Former clients
  • Employees
  • Contractors
  • Vendors
  • Opposing parties
  • Witnesses
  • Business contacts
  • Website visitors
  • Other individuals whose information is provided in connection with legal representation

7. Processor Obligations

Wood Seitl & Anderson agrees to:

  • Process Personal Data only as instructed by the Controller or as otherwise required by law
  • Maintain the confidentiality of Personal Data
  • Ensure authorized personnel are subject to appropriate confidentiality obligations
  • Implement appropriate technical and organizational security measures
  • Assist the Controller with applicable legal obligations where required
  • Notify the Controller of confirmed Personal Data breaches where legally required
  • Return or securely delete Personal Data upon completion of services where appropriate and legally permissible

8. Controller Responsibilities

The Controller agrees to:

  • Ensure a lawful basis exists for processing Personal Data
  • Provide legally required notices to individuals
  • Obtain any necessary consents
  • Ensure instructions provided to the Processor comply with applicable law
  • Maintain responsibility for the accuracy of Personal Data provided

9. Confidentiality

Wood Seitl & Anderson maintains strict confidentiality regarding client information and Personal Data in accordance with:

  • Applicable law
  • Professional ethical obligations
  • Attorney-client privilege where applicable
  • Internal confidentiality policies

Employees, contractors, and service providers with access to Personal Data are required to maintain confidentiality.


10. Security Measures

We implement commercially reasonable administrative, technical, and physical safeguards designed to protect Personal Data against accidental or unlawful:

  • Destruction
  • Loss
  • Alteration
  • Unauthorized disclosure
  • Unauthorized access

Security measures may include:

  • Secure hosting environments
  • Encryption where appropriate
  • Access controls
  • Password management
  • Multi-factor authentication where available
  • Network security monitoring
  • Regular software updates
  • Employee security awareness practices

Because no method of electronic transmission or storage is completely secure, absolute security cannot be guaranteed.


11. Subprocessors

We may engage trusted third-party service providers (“Subprocessors”) to assist in providing our services.

Examples may include:

  • Website hosting providers
  • Cloud storage providers
  • Email providers
  • IT support providers
  • Practice management software vendors
  • Document management platforms
  • Payment processors

We require Subprocessors to maintain appropriate confidentiality and security measures consistent with applicable law.


12. International Data Transfers

Where Personal Data is transferred outside the jurisdiction in which it was collected, Wood Seitl & Anderson will take commercially reasonable steps to ensure appropriate safeguards are implemented where required by applicable law.


13. Data Subject Requests

Where legally required, and taking into account the nature of the processing, Wood Seitl & Anderson will provide reasonable assistance to the Controller in responding to verified requests relating to:

  • Access
  • Correction
  • Deletion
  • Restriction
  • Data portability
  • Objection to processing

Individuals should generally submit requests directly to the Controller unless otherwise instructed.


14. Personal Data Breaches

If Wood Seitl & Anderson becomes aware of a confirmed Personal Data breach affecting information processed on behalf of a Controller, we will provide notification without undue delay where required by applicable law.

Notification may include:

  • Nature of the incident
  • Categories of affected data
  • Measures taken
  • Recommended mitigation steps where appropriate

15. Data Retention

Personal Data will be retained only for:

  • The duration necessary to provide legal services
  • Compliance with applicable laws
  • Ethical and professional obligations
  • Record retention requirements
  • Resolution of disputes
  • Enforcement of legal rights

Upon expiration of applicable retention periods, Personal Data may be securely deleted, anonymized, or archived where legally required.


16. Audits

Upon reasonable written request and where required by applicable law or contractual obligation, Wood Seitl & Anderson may provide information reasonably necessary to demonstrate compliance with this DPA, subject to:

  • Attorney-client privilege
  • Confidentiality obligations
  • Security requirements
  • Applicable law

17. Limitation of Liability

Except as prohibited by applicable law, each party’s liability under this DPA shall be subject to the liability limitations contained in the underlying Agreement.


18. Governing Law

This DPA shall be governed by the laws specified in the underlying Agreement or, if none are specified, the laws of the State of Florida, without regard to conflict of law principles.


19. Amendments

Wood Seitl & Anderson may update this DPA from time to time to reflect changes in applicable privacy laws, regulatory guidance, or our business practices.

The revised version will become effective upon publication unless otherwise required by law.


20. Contact Information

Questions regarding this Data Processing Addendum may be directed to:

Wood Seitl & Anderson

Website: https://www.woodseitlanderson.com/

Email: jonathan@wsa-law.com

Phone: (941) 954-5772

Mailing Address:

3665 Bee Ridge Road, Suite 300
Sarasota, FL 34233