Commit Graph
18 Commits
Author SHA1 Message Date
Pamela Chia c4c58ef3e3 feat: remove pandadoc dpa request flow (#48525)
Terms of Service v3 (effective August 1, 2026, #48482) incorporates the
Data Processing Addendum by reference, so customers no longer sign a
separate DPA. Legal confirmed the PandaDoc signing flow can go;
previously signed DPAs remain binding. This removes the frontend flow
only. I'll remove the platform endpoint (`POST
/platform/organizations/{slug}/documents/dpa`) separately once the
PandaDoc contract conversation wraps.

**Changed:**

- **Dashboard DPA card no longer requests PandaDoc documents**: the
Request DPA button and confirm modal are replaced with a View DPA link
to the canonical legal page, with evergreen copy explaining the DPA is
part of the Terms. Tracked via the same `document_view_button_clicked`
event the other document cards use.
- **Legacy `/legal/dpa` page retired**: the page told users to request a
signed DPA from the dashboard, which no longer exists. It now
permanently redirects to
`/legal/customer-resources/data-processing-addendum` (the follow-up
already flagged in #48483), and the footer link is removed. The
`dpa_pdf_opened` and `dpa_request_button_clicked` events are removed
with their last call sites. The latest privacy version links the
canonical page directly; archived v1/v2 keep their original `/legal/dpa`
link, served by the redirect.
- **Orphaned DPA PDFs removed**: the four dated `Supabase+DPA+*.pdf`
files under `/downloads/docs` had zero remaining references once the
signing flow is gone. No redirect: nothing links these URLs, so they
404.
- **Subscription tracking**: the subprocessor updates form now fires
`www_subprocessor_updates_subscribed` on successful submit, so we can
measure uptake of the notification list that replaces per-customer DPA
emails.

## To test

Verified on the Vercel previews (Playwright):

- [x] Studio: `/org/_/documents` shows the DPA card with the
incorporation copy and a working View DPA link (href = canonical page);
no Request DPA button, no PandaDoc mention; TIA/SOC2/ISO27001/HIPAA
cards unaffected
- [x] www: `/legal/dpa` permanently redirects to
`/legal/customer-resources/data-processing-addendum`; footer no longer
shows DPA; zero console errors
- [x] www: subscribing on the subprocessor page succeeds (200 from the
form route, profile created with topic_4) and fires
`www_subprocessor_updates_subscribed` (201 from the telemetry endpoint);
test profile unsubscribed afterwards
- [x] www: `/downloads/docs/Supabase+DPA+260601.pdf` returns 404 with no
redirect; DPA card copy verified without the effective date

## Linear

- fixes GROWTH-1068
2026-07-31 16:18:25 +08:00
Pamela Chia bf81e46173 chore: update DPA to June 2026 version (#46558) 2026-06-05 17:29:40 +08:00
Stephen Morgan d49da89517 feat: update to DPA Q1 2026 (#43843)
Only one change to this DPA in the addition of Braintrust as a
sub-processor

Fixes SEC-757
2026-03-17 07:34:40 +01:00
a61927e790 feat: update dpa retrieval (#37563)
* feat: update dpa retrieval

* add tracking for other legal docs

* ci: Autofix updates from GitHub workflow

* update api types

* update pdf

* Refactor DPA with text confirm modal

* Nit consistency with using a and buttons

* Update TextConfirmModal

---------

Co-authored-by: pamelachia <26612111+pamelachia@users.noreply.github.com>
Co-authored-by: Joshen Lim <joshenlimek@gmail.com>
2025-08-07 16:12:54 +08:00
Pamela Chia 6747d078e0 fix: docx extension (#34825) 2025-04-08 11:30:29 +02:00
Stephen Morgan 884743ac30 Chore: Update TiA and DPA (#34367)
* Updates to DPA with new Vendors

* Updates to TIA with new Vendors
2025-03-25 11:27:09 +13:00
Pamela Chia 888a77d631 chore: update TIA address (#30181) 2024-10-31 13:58:47 +08:00
Pamela Chia c5d2590fc0 chore: update TIA doc and policy (#29783) 2024-10-09 18:24:08 +08:00
Pamela Chia 3dab4fd5f7 Chore/add billing processing in docs (#28365)
* chore: add billing in privacy policy

* chore: add billing processing to TIA
2024-08-05 14:32:01 +08:00
Pamela Chia fe1e165bbf chore: remove services from docs (#25989)
* chore: remove services from docs

* fix: prettier
2024-05-10 18:25:59 +08:00
Pamela Chia 87b43acfba chore: update TIA (#22367) 2024-04-01 16:05:46 +07:00
Pamela Chia 49561167dd feat: Add TIA to legal docs (#20700) 2024-01-25 14:45:17 +08:00
Pamela Chia a88ad43f2d chore: update DPA (#19536) 2023-12-10 10:11:29 +01:00
Pamela Chia c6d0d9a81b fix: change dpa doc title (#17720) 2023-09-27 14:42:42 +08:00
Pamela Chia 433dc5261a chore: remove old dpa doc 2023-09-14 19:40:28 +08:00
Pamela Chia 12befc4f89 feat: add dpa doc sep 2023 2023-09-07 12:14:41 +08:00
Joshen Lim 3a77f99ab8 Rename DPA doc 2022-10-13 17:24:55 +08:00
Joshen Lim bbecb30aa5 Set up DPA and SOC2 pages 2022-10-12 19:03:32 +08:00