Data Processing Agreement (DPA)
This Data Processing Agreement ("DPA") forms part of the Terms of Service between you ("Customer", the controller) and DocuTract ("DocuTract", the processor). It governs DocuTract's processing of personal data contained in the documents, scans and templates you upload ("Customer Personal Data") and reflects the requirements of Article 28 of the EU General Data Protection Regulation (GDPR).
Roles of the parties
The Customer is the controller and determines the purposes and means of processing Customer Personal Data. DocuTract is the processor and processes Customer Personal Data only on the Customer's documented instructions, including those given through normal use of the service. Where DocuTract acts as controller for account and billing data, the Privacy Policy applies instead.
Subject matter and duration
The subject matter is the processing necessary to provide DocuTract - extracting fields from uploaded scans and generating filled documents. Processing lasts for the term of the Terms of Service and until Customer Personal Data is deleted in accordance with this DPA.
Nature and purpose of processing
DocuTract processes Customer Personal Data to receive uploaded files, perform automated extraction, populate templates, generate output documents, and store those documents and scans on the Customer's behalf.
Categories of data and data subjects
The Customer controls what it uploads. Customer Personal Data may include identity, contact, identification-document, financial and other details contained in the Customer's source files. Data subjects may include the Customer's clients, employees, counterparties and any individuals named in the Customer's documents.
Special categories of data
DocuTract is not designed for special categories of personal data (Article 9 GDPR, such as health data) or for data relating to criminal convictions and offences (Article 10 GDPR). The Customer will not upload such data unless it has a valid legal basis for that processing and has informed DocuTract in writing in advance, so that the parties can agree any additional safeguards.
DocuTract's obligations
DocuTract will:
- process Customer Personal Data only on the Customer's documented instructions;
- ensure persons authorised to process the data are bound by confidentiality;
- implement the technical and organisational measures described below;
- not use Customer Personal Data to train machine-learning models or for any purpose other than providing the service;
- assist the Customer, taking into account the nature of processing, with data-subject requests and with its security, breach-notification and impact-assessment obligations.
Security measures
DocuTract maintains appropriate technical and organisational measures, including encryption in transit (TLS) and at rest (the database and the file storage are encrypted by their providers), access controls with least privilege and authentication, two-factor authentication for users (which a workspace owner can make mandatory) and mandatory two-factor authentication for DocuTract administrators, private file storage that is never publicly accessible and is exposed only via short-lived signed URLs scoped to a workspace, logical separation of each workspace's data, an append-only access log of changes to and reads of Customer Personal Data and of every administrator access, PDF rendering on DocuTract's own servers, and regular review of these measures.
Sub-processors
The Customer authorises DocuTract to engage sub-processors to provide the service. DocuTract imposes data-protection obligations on each sub-processor no less protective than those in this DPA, and remains responsible for their performance. The current sub-processors are:
- Anthropic Ireland, Limited (Ireland) - AI recognition of text and fields in uploaded scans and analysis of uploaded templates. It receives file contents only - no file names or account identifiers. Anthropic stores data in the United States, may process it in other countries where it operates, keeps inputs and outputs for up to 30 days and does not use them to train models.
- Hetzner Online GmbH (Germany) - server hosting in a data centre in Falkenstein, Germany: the application, job queues and PDF rendering.
- Supabase, Inc. (United States) - database, user sign-in and private file storage (templates, scans and generated documents), hosted in Ireland (EU) and encrypted at rest.
- Stripe (Stripe, Inc. and its affiliates, including Stripe Payments Europe, Limited) - subscription billing and one-off payments (account and billing data only, never document content).
- Zone Media OÜ (Zone.eu, Estonia) - the mail hosting DocuTract sends email through, including the email with the links to a paid document (the recipient's address, the subject and body; the document itself is not attached).
- PostHog, Inc. (product analytics) - privacy-friendly website analytics, hosted in the EU and active only with the visitor's consent, with all text and inputs masked. It does not process the content of uploaded documents or scans.
DocuTract will give advance notice of any intended addition or replacement of a sub-processor so the Customer may object on reasonable data-protection grounds.
International transfers
Some sub-processors process Customer Personal Data outside the EEA - in particular Anthropic, which stores data in the United States, and Stripe, which is established in the United States. Supabase hosts our data in Ireland but is established in the United States, so remote access from there is treated as a transfer. For each such transfer DocuTract relies on the European Commission's Standard Contractual Clauses incorporated into the sub-processor's data-processing terms or, where available, an adequacy decision (such as the EU-US Data Privacy Framework), together with the technical measures set out above.
Personal data breach
DocuTract will notify the Customer without undue delay after becoming aware of a personal data breach affecting Customer Personal Data, with the information the Customer reasonably needs to meet its own notification obligations.
Return and deletion
On termination of the service, or on the Customer's written request to legal@docutract.online, DocuTract will delete or return Customer Personal Data and delete existing copies within 30 days, except where storage is required by law. Copies held by sub-processors are deleted within their own retention periods (for Anthropic, up to 30 days after processing).
Audits
DocuTract makes available the information necessary to demonstrate compliance with this DPA and will contribute to audits, including inspections, conducted by the Customer or an auditor it mandates, on reasonable notice and subject to confidentiality.
Liability and precedence
If any conflict arises between this DPA and the Terms of Service on the subject of personal-data processing, this DPA prevails. Questions about this DPA? Write to legal@docutract.online.