Vordex
13 processing inputs15-section first passFrom £7.99

Build the DPA around the actual data flow

Vordex converts the controller-processor record into a traceable first pass: defined intake fields, visible fallback tests, a fixed clause sequence and a returned package that keeps warnings beside the draft.

The page describes the supplied deterministic DPA implementation. It does not claim role classification, live legal checking, security assurance, transfer approval or guaranteed compliance.

Fallbacks stay visibleMissing supported facts become warnings or section states.
The section order is disclosedThe current builder returns the same 15-section architecture.
Existing wording takes another routeAnalysis switches intent and removes the generation plan.

Processing Flow Diagram

Follow every transformation from answer payload to DPA package

The generation path is shown as a six-node system rather than a generic three-step marketing workflow. Each node identifies what enters, what the supplied implementation does and what it emits next.

system node

Receive the processing record

Receives

Controller, processor, service, processing schedule, controls, vendor-chain, transfer, incident, audit and special-term answers.

Confirmed operation

The entrypoint accepts the submitted answer payload together with jurisdiction, perspective and selected plan context.

01
EmitsOne raw DPA generation request.
system node

Collapse aliases into stable fields

Receives

Alternative labels such as customer, provider, data_categories, security and international_transfers.

Confirmed operation

The extractor chooses the first usable value for each of 13 canonical DPA fields and inserts a disclosed fallback where no usable value exists.

02
EmitsA normalised DPA data model.
system node

Resolve drafting context

Receives

Controller, Processor or Neutral perspective plus England and Wales, Scotland, Northern Ireland or broad UK wording.

Confirmed operation

Perspective is stored in prompt context. Jurisdiction selects the final governing-law wording or remains explicitly unresolved.

03
EmitsPerspective and jurisdiction labels attached to the run.
system node

Test supported completion gaps

Receives

The normalised values and the exact fallback strings used by the playbook.

Confirmed operation

Eleven top-level warning conditions are evaluated. Section-level fallback tests are then used to set draft or needs_input.

04
EmitsWarnings plus a state for every generated section.
system node

Assemble the clause sequence

Receives

The normalised fields, standard playbook wording and selected legal system.

Confirmed operation

The current deterministic builder produces the same 15-section architecture on every run and inserts the supplied values into their defined destinations.

05
EmitsFifteen ordered section objects.
system node

Package an inspectable result

Receives

Sections, warnings, run context, original answers and generator metadata.

Confirmed operation

Vordex returns structured content and a plain-text rendering together, keeping the completion evidence beside the draft.

06
EmitsA first-pass DPA package, not a compliance certificate.

Controller vs Processor Builder

Set the drafting lens without pretending it decides the legal role

Choose a perspective to inspect the stored context and practical priorities. The component makes the implementation boundary explicit: perspective is recorded, while the deterministic clause bodies remain on the same 15-section track.

Choose a drafting lens
Selected lens

Controller perspective

Use this context when the customer determines the purpose and essential means of the processing and is commissioning a processor.

stored context
What the generator records

The stored prompt note emphasises documented instructions, sub-processing control, security, transfers, incident support and end-of-processing control.

Define what the supplier may process and why
Record approval or notification around sub-processors
Make security, breach and audit expectations operational
Keep deletion or return under the controller's direction
Implementation boundary: The supplied deterministic section bodies do not branch into a controller-only clause set.

Data Mapping

Thirteen canonical fields drive the disclosed clause destinations

Every row joins the accepted data labels to the exact fallback, the supported warning or state behaviour and the section that receives the value. This is the generator's real data boundary, not a broad UK GDPR checklist.

controllerName

Controller legal name

controller_namecontrollercustomer
Fallbackthe ControllerWarning or state effect

Top-level warning and Parties needs_input while the fallback label remains.

section route

01 · Parties

processorName

Processor legal name

processor_nameprocessorprovider
Fallbackthe ProcessorWarning or state effect

Top-level warning and Parties needs_input while the fallback label remains.

section route

01 · Parties

services

Service description

serviceDescriptionservice_description
Fallbackthe services described in the main agreementWarning or state effect

No separate top-level warning; Roles and Services becomes needs_input when the fallback remains.

section route

02 · Roles and Services

processingSubjectMatter

Processing subject matter

processing_subject_mattersubjectMattersubject_matter
Fallbackthe processing subject matter described in the service descriptionWarning or state effect

No separate top-level warning; Subject Matter becomes needs_input when the fallback remains.

section route

03 · Subject Matter

personalDataCategories

Personal data categories

personal_data_categoriesdataCategoriesdata_categories
Fallbackpersonal data categories to be confirmedWarning or state effect

Top-level warning and Data Categories and Data Subjects needs_input.

section route

06 · Data Categories and Data Subjects

dataSubjects

Data subject groups

data_subjects
Fallbackdata subjects to be confirmedWarning or state effect

Top-level warning and Data Categories and Data Subjects needs_input.

section route

06 · Data Categories and Data Subjects

duration

Processing duration

termprocessingDurationprocessing_duration
Fallbackthe duration of the processing stated in the main agreementWarning or state effect

Top-level warning and Duration needs_input.

section route

04 · Duration

securityMeasures

Technical and organisational measures

security_measuressecurity
Fallbackappropriate technical and organisational measures to be confirmedWarning or state effect

Top-level warning and Security needs_input.

section route

07 · Security

subProcessors

Sub-processor position

sub_processorssubprocessors
Fallbacksub-processor arrangements to be confirmedWarning or state effect

Top-level warning and Sub-processors needs_input.

section route

08 · Sub-processors

transfers

International transfer position

internationalTransfersinternational_transfers
Fallbackinternational transfer arrangements to be confirmedWarning or state effect

Top-level warning and International Transfers needs_input.

section route

09 · International Transfers

breachNotice

Processor incident notice

breach_noticeincidentNoticeincident_notice
Fallbackbreach notification timing to be confirmedWarning or state effect

Top-level warning and Breach Notice needs_input.

section route

10 · Breach Notice

audit

Audit assistance position

auditRightsaudit_rights
Fallbackaudit assistance arrangements to be confirmedWarning or state effect

Top-level warning and Audits needs_input.

section route

12 · Audits

specialTerms

Additional instructions

special_termsadditionalTermsadditional_terms
Fallbacknone statedWarning or state effect

No top-level warning; Special Terms becomes needs_input while none stated remains.

section route

14 · Special Terms

Jurisdiction controlEngland and Wales, Scotland and Northern Ireland receive specific final wording. Broad UK wording remains unresolved, creates a warning and leaves section 15 needing input.
Perspective controlController, Processor and Neutral are stored in the run context. They do not create three different deterministic section inventories.

Clause Generation

Fifteen clauses move through four processing lanes

The first half shows the exact section manifest. The legal trace registry then maps every authority mentioned on this page to the supported input, completion trigger, returned output and explicit non-check.

RELATIONSHIP

Name the parties and the processing job

The opening lane links the commercial service to the controller-processor arrangement without deciding whether the labels are legally correct in practice.

01Input-dependent

Parties

Built from: Controller and processor names

02Input-dependent

Roles and Services

Built from: Service description

03Input-dependent

Subject Matter

Built from: Processing subject matter

04Input-dependent

Duration

Built from: Processing duration

INSTRUCTIONS

Set the permitted processing framework

This lane combines standard playbook wording with the data schedule supplied through the intake.

05Always returned as draft

Controller Instructions

Built from: Standard playbook wording

06Input-dependent

Data Categories and Data Subjects

Built from: Categories and subject groups

07Input-dependent

Security

Built from: Security measures

OPERATIONS

Connect vendors, transfers and incidents

Operational answers are preserved as drafting positions. The builder does not validate the underlying supplier list, transfer mechanism or incident process.

08Input-dependent

Sub-processors

Built from: Sub-processor arrangements

09Input-dependent

International Transfers

Built from: Transfer arrangements

10Input-dependent

Breach Notice

Built from: Incident notice timing

11Always returned as draft

Assistance

Built from: Standard playbook wording

12Input-dependent

Audits

Built from: Audit arrangements

EXIT

Close the processing and choose the legal system

The final lane covers return or deletion, exceptional instructions and the selected UK governing-law wording.

13Always returned as draft

Deletion or Return

Built from: Standard playbook wording

14Input-dependent

Special Terms

Built from: Additional instructions

15Input-dependent

Governing Law and Jurisdiction

Built from: Normalised jurisdiction

Legal reference trace registry

Authority → supported input → trigger → returned result → boundary

Every legal reference used by the page is attached to a confirmed generator behaviour. A reference explains the drafting context; it does not imply that Vordex fetches the source or performs the excluded checks during generation.

Read each path from left to right. The final cell states what the current product does not analyse or guarantee.
01
UK GDPR Article 28(3) — processing particularsRequired description of the processing
Open official source ↗
What Vordex reads

Services, processing subject matter, duration, personal data categories and data subject groups supplied in the intake.

Warning or state trigger

Duration, data categories and data subjects can create top-level warnings. Services and subject matter instead affect their section states.

Returned output

Roles and Services, Subject Matter, Duration, and Data Categories and Data Subjects sections, with warning and needs_input evidence where defined.

Not analysed or guaranteed

No legal classification of the relationship, no verification of nature or purpose, and no confirmation that the schedule is complete for the real processing.

02
UK GDPR Article 28(3)(a) and Article 29 — documented instructionsProcessing only on authorised instructions
Open official source ↗
What Vordex reads

No dedicated instruction field. The builder uses disclosed standard wording for the instruction clause.

Warning or state trigger

No top-level warning and no input-dependent fallback test for Controller Instructions.

Returned output

Controller Instructions is always returned with draft state in the current section builder.

Not analysed or guaranteed

Vordex does not inspect operational instruction channels, decide whether an instruction is lawful or detect processing outside instructions.

03
UK GDPR Article 28(3)(b), Article 28(3)(c) and Article 32Confidentiality and security measures
Open official source ↗
What Vordex reads

The technical and organisational measures text entered as securityMeasures.

Warning or state trigger

The unconfirmed security fallback creates a top-level warning and sets Security to needs_input.

Returned output

Security section plus the matching completion signal in the warning list and section state.

Not analysed or guaranteed

No control test, certification check, security evidence review, risk assessment or conclusion that the measures are appropriate.

04
UK GDPR Article 28(2) and Article 28(4) — sub-processorsAuthorisation and equivalent downstream terms
Open official source ↗
What Vordex reads

The supplied sub-processor arrangement or vendor-chain position.

Warning or state trigger

An unconfirmed sub-processor position creates a top-level warning and a needs_input state.

Returned output

Sub-processors section carrying the stated arrangement and the unresolved-input signal where applicable.

Not analysed or guaranteed

No vendor discovery, authorisation audit, list comparison or inspection of the processor-to-sub-processor contract.

05
UK GDPR Article 28(3)(e) and Article 28(3)(f) — assistanceSupport for rights, security, breaches and DPIAs
Open official source ↗
What Vordex reads

No dedicated assistance field in the 13-field extractor; standard playbook wording supplies the clause.

Warning or state trigger

No top-level warning and no needs_input fallback for the Assistance section.

Returned output

Assistance is always returned as draft within the 15-section sequence.

Not analysed or guaranteed

No data-subject request workflow review, DPIA assessment, regulator-consultation check or proof that the processor can provide the promised help.

06
UK GDPR Article 33(2) — processor breach notificationNotice to the controller without undue delay
Open official source ↗
What Vordex reads

The breach or incident notification timing supplied through breachNotice.

Warning or state trigger

The unconfirmed timing fallback creates a top-level warning and sets Breach Notice to needs_input.

Returned output

Breach Notice section plus the related warning and state in the generation package.

Not analysed or guaranteed

No incident classification, no live breach assessment and no decision about the controller's separate 72-hour reporting obligation.

07
UK GDPR Article 28(3)(h) — information and auditsEvidence of compliance and audit support
Open official source ↗
What Vordex reads

The audit assistance or audit-rights position entered in the intake.

Warning or state trigger

The unconfirmed audit fallback creates a top-level warning and sets Audits to needs_input.

Returned output

Audits section and its completion signal in the returned warnings and section state.

Not analysed or guaranteed

No inspection of certifications, reports, evidence rooms, audit frequency, cost allocation or practical access rights.

08
UK GDPR Article 28(3)(g) — deletion or returnEnd-of-processing treatment of personal data
Open official source ↗
What Vordex reads

No dedicated deletion field. Standard playbook wording supplies the current clause.

Warning or state trigger

No top-level warning and no input-dependent fallback for Deletion or Return.

Returned output

Deletion or Return is always returned with draft state.

Not analysed or guaranteed

No retention schedule, backup-deletion analysis, legal-hold check, deletion certificate or confirmation that return is technically possible.

09
UK GDPR Chapter V, including Articles 44–49 — international transfersRestricted-transfer safeguards
Open official source ↗
What Vordex reads

The international transfer arrangement described in the transfers field.

Warning or state trigger

An unconfirmed transfer position creates a top-level warning and sets International Transfers to needs_input.

Returned output

International Transfers section recording the stated position and indicating that an appropriate mechanism may be required.

Not analysed or guaranteed

No restricted-transfer identification, adequacy analysis, IDTA, UK Addendum, transfer risk assessment or supplementary-measures review is generated.

Compliance Limits

Keep the first pass inside the boundary of the supplied playbook

These limits are part of the product specification. They separate a supported drafting action from role analysis, operational verification, live regulatory checking and connected documents that the current generator does not produce.

8

declared product boundaries

A visible limit is more useful than a broad compliance promise the implementation cannot support.

01

The party labels are not a role decision

Supported

The generator records a controller and processor name and can store Controller, Processor or Neutral drafting perspective.

Outside the generator

It does not determine who decides the purposes and essential means for each activity, identify joint controllership or classify mixed roles.

Practical action

Resolve the real data-role analysis before relying on the draft architecture.

Route uncertain roles to wider review
02

A DPA is not a controller-to-controller sharing agreement

Supported

The current playbook is built around a controller instructing a processor.

Outside the generator

Independent controllers and joint controllers need different allocation, transparency and lawful-basis work.

Practical action

Use the document type that matches the actual relationship.

Open Vordex DPA information
03

No live regulatory lookup runs during generation

Supported

The builder uses the disclosed field map, fallback tests and fixed section sequence.

Outside the generator

It does not fetch legislation, ICO guidance or transfer updates during an individual run.

Practical action

Treat official links as external verification points for current requirements.

04

Security text is not security assurance

Supported

The securityMeasures answer feeds section 07 and can produce a warning when unresolved.

Outside the generator

The generator does not test controls, inspect certificates, compare the measures with the risk or validate supplier evidence.

Practical action

Attach or review the real security schedule and evidence separately.

Read the Vordex security overview
05

Transfer wording does not create a transfer mechanism

Supported

The transfers answer is preserved in the International Transfers section and unresolved wording is surfaced.

Outside the generator

The playbook does not produce an IDTA, UK Addendum, TRA or a finding that a safeguard is valid.

Practical action

Complete the separate transfer work where a restricted transfer exists.

06

Standard clauses do not prove operational capability

Supported

Controller Instructions, Assistance and Deletion or Return are always returned as draft using standard playbook wording.

Outside the generator

No workflow, staffing, tooling, retention or incident evidence is examined before those sections receive draft state.

Practical action

Verify that the organisation can perform the obligations written into the agreement.

07

Special terms remain review material

Supported

Additional instructions are carried into a dedicated Special Terms section and can be marked needs_input.

Outside the generator

The deterministic builder does not convert every exceptional instruction into a bespoke set of linked clauses.

Practical action

Review unusual liability, sector, public-sector, AI, biometric or children's-data requirements separately.

Review the wider service agreement
08

The supplied facts are not independently verified

Supported

Fallbacks and warnings expose missing supported answers.

Outside the generator

Vordex does not confirm that names, categories, security measures, vendor lists, transfer descriptions or timings are accurate.

Practical action

Validate the processing record against the real service and data flows before signature.

Generation Output

Receive the draft, completion evidence and run context together

The return package is designed to remain inspectable. Structured sections, warning metadata, context, original answers and plain text are kept together so the first pass can be traced back to the supplied processing record.

DPA generation response
01{
02"status": "draft",
03"jurisdiction": "England and Wales",
04"perspective": "Controller",
05"content": {
06"schemaVersion": "generator.contract.v1",
07"playbook": "dpa",
08"sections": [15 section objects]
09},
10"metadata": { warnings, promptContext, generator… },
11"answers": { original submitted payload },
12"plainText": "Data Processing Agreement Draft…"
13}
The response shape is illustrative of the confirmed fields. A draft state describes assembly status; it is not legal approval.
content.schemaVersion

Stable response version

The structured content identifies the generator contract schema used by the returned draft.

content.playbook

DPA playbook identity

The response records that the dpa playbook produced the section set.

content.sections[]

Fifteen section objects

Each section carries its identifier, heading, body, category and draft or needs_input state.

metadata.warnings

Top-level completion warnings

The package preserves the supported missing-input messages calculated before section assembly.

jurisdiction + perspective

Run context

The selected legal system and drafting perspective remain visible beside the generated content.

promptContext

Prompt-building context

Plan, contract type, perspective, jurisdiction and selected answers are retained as generation context.

answers

Original submitted payload

The raw answer object remains attached so the first pass can be traced back to the submitted inputs.

plainText

Readable text rendering

The title, headings and section bodies are joined into a portable plain-text representation.

No Word export, PDF export, e-signature flow or browser editor is claimed here because those capabilities are not confirmed by the supplied DPA page and playbook description.

Pricing

Choose the DPA route before authentication

Both actions preserve the DPA contract type, this source page and generation intent. The selected plan key is stored for the next step without inventing a different clause inventory or legal-check engine that the supplied implementation does not expose.

Basic generation route
£7.99

Basic DPA Builder

Open the lower-priced generation route for a new deterministic Data Processing Agreement first pass.

Plangenerate_basic_gbp_799
Intentgenerate
Contract typedpa
Sourcedpa-generator
Open the Basic DPA · £7.99
Plan disclosure. The selected plan id can be carried into generation context, but the supplied 15-section builder and warning function do not expose a separate Basic and Detailed clause manifest. No plan-specific compliance conclusion, export or approval is promised on this page.

FAQ

DPA generator answers tied to the current implementation

The answers describe the supported field model, warning behaviour, clause assembly, legal-reference mapping, output package and route wiring without claiming live compliance analysis or capabilities that are not confirmed.

What does the Vordex DPA Generator create?
It creates a deterministic first-pass Data Processing Agreement with 15 ordered sections. The result includes structured section objects, draft or needs_input states, warnings, jurisdiction, perspective, generation context, original answers and a plain-text rendering.
Which information does the DPA intake normalise?
Thirteen fields: controller name, processor name, services, processing subject matter, personal data categories, data subjects, duration, security measures, sub-processors, international transfers, breach notice, audit arrangements and special terms. Most accept several alternative answer labels.
Which missing answers create top-level warnings?
Warnings can appear for broad UK jurisdiction, either missing party name, missing duration, and unconfirmed data categories, data subjects, security measures, sub-processors, transfers, breach timing or audit position. Services, subject matter and special terms can instead affect section state without their own top-level warning.
What does needs_input mean?
It means the section still matches its defined fallback or the jurisdiction remains unresolved. It is a drafting-completion signal, not a legal finding. Controller Instructions, Assistance and Deletion or Return are always returned as draft in the current builder.
Does Controller or Processor perspective change every clause?
No. The choice is normalised, labelled and stored in prompt context. The supplied deterministic section builder uses the same 15-section sequence and does not branch every clause body by perspective.
Does Vordex determine whether the parties really are controller and processor?
No. The generator accepts the party model supplied to it. It does not assess who determines purposes and means for each activity, identify joint controllers or decide whether a separate data-sharing agreement is required.
Does the security section confirm Article 32 compliance?
No. Vordex records the supplied security measures and flags an unresolved fallback. It does not test the controls, review evidence or decide whether the measures are appropriate for the real processing risk.
Can the generator create an IDTA, UK Addendum or transfer risk assessment?
No. The transfers field records the stated position and can trigger a completion warning. A separate restricted-transfer analysis and instrument may still be required.
Which UK governing-law choices are recognised?
England and Wales, Scotland and Northern Ireland receive specific wording. A general UK selection remains United Kingdom, jurisdiction to be confirmed, creates a warning and leaves the final section needing input. Wales maps to England and Wales in the current normaliser.
What changes between the £7.99 and £17.99 buttons?
The Basic route carries generate_basic_gbp_799 and the Detailed route carries generate_full_gbp_1799. Both preserve intent=generate, source=dpa-generator and contractType=dpa. The supplied page and playbook do not expose a different 15-section inventory or warning engine by plan, so no plan-specific legal checks are claimed here.
What happens after a generation button is selected?
The page routes to authentication with the selected plan, generation intent, DPA source and dpa contract type. It also stores the contract type, journey intent, checkout intent, source slug and selected plan in sessionStorage for the next step.
When should I use existing-document analysis instead?
Use analysis when a DPA or service contract already exists and the job is to inspect wording rather than create another first pass. The analysis action switches intent to analyse, preserves the DPA contract type and source, and does not attach a generation plan.
Does the generated document guarantee UK GDPR compliance?
No. The generator structures supplied information, applies disclosed fallbacks and exposes supported completion gaps. It does not verify facts, classify roles, inspect operational evidence, generate every related instrument or guarantee compliance, enforceability or suitability.
When should the first pass go to specialist review?
Escalate role uncertainty, joint controllership, special-category or criminal-offence data, children's data, extensive overseas access, public-sector processing, AI training rights, complex liability, disputed audit rights or conflicting terms across the service, security, transfer and DPA documents.
Start the correct DPA job

Turn the processing record into a first pass you can inspect

Generate when the controller-processor model and core processing facts are understood. Review every warning and needs_input section, then verify the operational, transfer and role questions that sit outside the deterministic builder.