Data Processing Addendum (DPA)
Website: https://www.woodseitlanderson.com/
Effective Date: July 22, 2026
1. Purpose
This Data Processing Addendum (“DPA”) forms part of any agreement (“Agreement”) between Wood Seitl & Anderson (“Processor,” “Service Provider,” “we,” “our,” or “us”) and any client or business partner (“Controller,” “Customer,” or “you”) where we process Personal Data on your behalf.
This DPA establishes the parties’ obligations regarding the processing of Personal Data in accordance with applicable data protection and privacy laws.
2. Definitions
For purposes of this DPA:
Applicable Privacy Laws means all applicable privacy and data protection laws, including, where applicable:
- General Data Protection Regulation (EU) 2016/679 (“GDPR”)
- UK GDPR
- California Consumer Privacy Act, as amended by the California Privacy Rights Act (“CCPA/CPRA”)
- Other applicable U.S. federal and state privacy laws
Controller means the entity determining the purposes and means of processing Personal Data.
Processor means the entity processing Personal Data on behalf of the Controller.
Personal Data means any information relating to an identified or identifiable individual as defined under applicable law.
Processing means any operation performed on Personal Data, including collection, storage, use, disclosure, transmission, or deletion.
3. Scope
This DPA applies whenever Wood Seitl & Anderson processes Personal Data on behalf of a client in connection with legal services or other professional services provided under the Agreement.
4. Nature and Purpose of Processing
Processing activities may include:
- Receiving client communications
- Managing legal matters
- Preparing legal documents
- Communicating with clients
- Managing consultations
- Maintaining client records
- Responding to legal inquiries
- Providing professional legal services
- Complying with legal obligations
5. Categories of Personal Data
Depending on the services provided, Personal Data may include:
- Names
- Addresses
- Email addresses
- Telephone numbers
- Business information
- Client communications
- Billing information
- Case-related information
- Government-issued identification (where required)
- Other information voluntarily provided by clients
The specific categories processed depend upon the services requested.
6. Categories of Data Subjects
Personal Data may relate to:
- Current clients
- Prospective clients
- Former clients
- Employees
- Contractors
- Vendors
- Opposing parties
- Witnesses
- Business contacts
- Website visitors
- Other individuals whose information is provided in connection with legal representation
7. Processor Obligations
Wood Seitl & Anderson agrees to:
- Process Personal Data only as instructed by the Controller or as otherwise required by law
- Maintain the confidentiality of Personal Data
- Ensure authorized personnel are subject to appropriate confidentiality obligations
- Implement appropriate technical and organizational security measures
- Assist the Controller with applicable legal obligations where required
- Notify the Controller of confirmed Personal Data breaches where legally required
- Return or securely delete Personal Data upon completion of services where appropriate and legally permissible
8. Controller Responsibilities
The Controller agrees to:
- Ensure a lawful basis exists for processing Personal Data
- Provide legally required notices to individuals
- Obtain any necessary consents
- Ensure instructions provided to the Processor comply with applicable law
- Maintain responsibility for the accuracy of Personal Data provided
9. Confidentiality
Wood Seitl & Anderson maintains strict confidentiality regarding client information and Personal Data in accordance with:
- Applicable law
- Professional ethical obligations
- Attorney-client privilege where applicable
- Internal confidentiality policies
Employees, contractors, and service providers with access to Personal Data are required to maintain confidentiality.
10. Security Measures
We implement commercially reasonable administrative, technical, and physical safeguards designed to protect Personal Data against accidental or unlawful:
- Destruction
- Loss
- Alteration
- Unauthorized disclosure
- Unauthorized access
Security measures may include:
- Secure hosting environments
- Encryption where appropriate
- Access controls
- Password management
- Multi-factor authentication where available
- Network security monitoring
- Regular software updates
- Employee security awareness practices
Because no method of electronic transmission or storage is completely secure, absolute security cannot be guaranteed.
11. Subprocessors
We may engage trusted third-party service providers (“Subprocessors”) to assist in providing our services.
Examples may include:
- Website hosting providers
- Cloud storage providers
- Email providers
- IT support providers
- Practice management software vendors
- Document management platforms
- Payment processors
We require Subprocessors to maintain appropriate confidentiality and security measures consistent with applicable law.
12. International Data Transfers
Where Personal Data is transferred outside the jurisdiction in which it was collected, Wood Seitl & Anderson will take commercially reasonable steps to ensure appropriate safeguards are implemented where required by applicable law.
13. Data Subject Requests
Where legally required, and taking into account the nature of the processing, Wood Seitl & Anderson will provide reasonable assistance to the Controller in responding to verified requests relating to:
- Access
- Correction
- Deletion
- Restriction
- Data portability
- Objection to processing
Individuals should generally submit requests directly to the Controller unless otherwise instructed.
14. Personal Data Breaches
If Wood Seitl & Anderson becomes aware of a confirmed Personal Data breach affecting information processed on behalf of a Controller, we will provide notification without undue delay where required by applicable law.
Notification may include:
- Nature of the incident
- Categories of affected data
- Measures taken
- Recommended mitigation steps where appropriate
15. Data Retention
Personal Data will be retained only for:
- The duration necessary to provide legal services
- Compliance with applicable laws
- Ethical and professional obligations
- Record retention requirements
- Resolution of disputes
- Enforcement of legal rights
Upon expiration of applicable retention periods, Personal Data may be securely deleted, anonymized, or archived where legally required.
16. Audits
Upon reasonable written request and where required by applicable law or contractual obligation, Wood Seitl & Anderson may provide information reasonably necessary to demonstrate compliance with this DPA, subject to:
- Attorney-client privilege
- Confidentiality obligations
- Security requirements
- Applicable law
17. Limitation of Liability
Except as prohibited by applicable law, each party’s liability under this DPA shall be subject to the liability limitations contained in the underlying Agreement.
18. Governing Law
This DPA shall be governed by the laws specified in the underlying Agreement or, if none are specified, the laws of the State of Florida, without regard to conflict of law principles.
19. Amendments
Wood Seitl & Anderson may update this DPA from time to time to reflect changes in applicable privacy laws, regulatory guidance, or our business practices.
The revised version will become effective upon publication unless otherwise required by law.
20. Contact Information
Questions regarding this Data Processing Addendum may be directed to:
Wood Seitl & Anderson
Website: https://www.woodseitlanderson.com/
Email: jonathan@wsa-law.com
Phone: (941) 954-5772
Mailing Address:
3665 Bee Ridge Road, Suite 300
Sarasota, FL 34233
