Snapshot 25066
Normalized text
Scripts and page chrome removed; this is what change detection compares.
Start Free Trial Sign In Start Free Trial Dashboard Sign Out DocSpring Data Processing Agreement This Data Processing Agreement (DPA) forms part of the DocSpring Terms of Service or another service agreement that incorporates it (Agreement). Its parties are DocSpring, Inc., a Delaware corporation, with the correspondence address 9450 SW Gemini Dr, PMB 95273, Beaverton, Oregon 97008-7105, United States (Provider), and the person or legal entity identified as the customer in the Agreement and associated account or order records (Customer, also referred to below as Data Exporter). It takes effect when the Agreement incorporating this DPA takes effect and applies whenever Provider processes Customer Personal Data on Customer’s behalf. Provider’s privacy contact is [email protected] (attention: Privacy). Acceptance of the Agreement incorporates this DPA without a separate signature. An existing separately executed DPA continues to govern the processing it covers unless the parties amend or replace it in accordance with that agreement. It applies to personal data Provider processes on Customer’s behalf in providing those services. Customer Personal Data means personal data processed by Provider on Customer’s behalf under this DPA. Customer is the controller, or is a processor authorized by the relevant controller to appoint Provider as a subprocessor; the applicable role is determined as described in Schedule 1. Terms such as controller, processor, personal data and processing have the meanings given in Regulation (EU) 2016/679 (GDPR). Applicable Data Protection Laws means the GDPR and other data protection legislation applicable to the processing. Processing consists of receiving customer-selected document data and templates, generating and storing PDF documents, operating forms and electronic signatures where enabled, delivering results and providing related support, security and recovery functions under Customer’s instructions. The data subjects, data categories, duration, destinations and special-category conditions are described in Schedule 1. Processing for Provider’s independent account, billing and business-administration purposes is outside these processor instructions and is addressed in Provider’s Privacy Policy. Provider shall ensure that its authorized personnel and any third party or affiliate it appoints to process Customer Personal Data (Subprocessor) comply with the following requirements. 1. Commissioned processing Process personal data only for the purposes specifically authorized by Data Exporter and only under the documented instructions of Data Exporter. If Provider cannot comply with an instruction, or, if in Provider’s opinion any instruction issued by Data Exporter to Provider is in contravention of Applicable Data Protection Laws, it shall promptly notify Data Exporter. Provider is prohibited from processing personal data for other purposes, including for Provider’s own purposes. If Union or Member State law requires processing beyond Customer’s instructions, Provider shall inform Customer of that legal requirement before processing unless the law prohibits notification on important grounds of public interest. 2. Security of personal data Implement and maintain appropriate technical and organizational measures to protect Personal Data against (i) unauthorized or unlawful processing and (ii) against accidental loss, damage, destruction, alteration, unauthorized disclosure of, or access to personal data; that, at a minimum, meet the requirements set forth in the measures referred to in Article 32(1) of the EU GDPR. 3. Provider personnel Take reasonable steps to ensure the reliability of any employee, agent or contractor who may have access to personal data, ensuring in each case that access is strictly limited to those individuals who need to know or access the personal data, as strictly necessary for the provision of the Services, ensuring that all such individuals are subject to confidentiality undertakings or professional or statutory obligations of confidentiality. 4. Personal data breach Implement and maintain security incident management policies and procedures and notify Data Exporter without undue delay, and in any event within seventy-two (72) hours of becoming aware, of any: (i) breach or suspected breach of security that may have resulted in the compromise of personal data; or (ii) unauthorized (or suspected unauthorized) processing of personal data; Provider shall cooperate with Data Exporter to fully address the matter and comply with all Applicable Data Protection Laws. Provider shall provide all relevant information to Data Exporter, including the following: (i) a description of the nature of the incident; (ii) the name and contact information of a point of contact where additional information may be obtained; and (iii) a description of measures taken or proposed to be taken to remedy the incident, including measures to mitigate negative effects. 5. Data subject rights If Provider or a Subprocessor receives a request from a Data Subject whose personal data has been provided to it, including a request to directly exercise the Data Subject’s rights, Provider shall promptly inform Data Exporter of such request without responding to that request, allowing Data Exporter to handle these requests unless it has been otherwise authorized to do so by Data Exporter. Provider shall cooperate with Data Exporter as is necessary to respond to such requests. 6. Cooperation with Data Exporter Provider shall provide reasonable assistance to Data Exporter to facilitate Data Exporter personal data compliance, including keeping and maintaining a record of all processing activities undertaken on behalf of Data Exporter, assisting Data Exporter in carrying out data protection impact assessments, and prior consultations with data privacy authorities, where required by Applicable Data Protection Laws. 7. Audit Provider shall allow for and contribute to audits, including inspections, by Data Exporter or an auditor mandated by Data Exporter in relation to the processing of personal data by the Provider and shall cooperate with Data Exporter in any investigation of Data Exporter by a governmental or regulatory authority regarding the processing of personal data by the Provider. Data Exporter shall give Provider reasonable notice of any audit or inspection to be conducted and shall make reasonable endeavours to avoid causing any damage or disruption to premises, personnel and business in the course of such an audit or inspection. Such audit or inspection shall not be conducted (i) outside normal business hours, unless the audit or inspection needs to be conducted on an emergency basis and Data Exporter has given notice to Provider; and (ii) no more than once in any calendar year, except for any additional audits or inspections which Data Exporter reasonably considers necessary because of genuine concerns as to Provider's compliance with these terms or which Data Exporter is required to carry out by data privacy authorities and/or Applicable Data Protection Laws. Provider shall make available the information necessary to demonstrate compliance with Article 28 GDPR and this DPA. Audit arrangements shall not prevent an audit required by applicable law or an applicable SCC. 8. Cross-border transfers The parties shall identify the entities and countries involved in each transfer in Schedule 1. A transfer requiring a Chapter V GDPR mechanism must be covered by an applicable adequacy decision or another lawful safeguard before it occurs. For transfers falling within the scope of Commission Implementing Decision (EU) 2021/914, the standard contractual clauses in its Annex (SCCs) are incorporated without modification, using Module Two where Customer is a controller and Provider is a processor, or Module Three where Customer is a processor and Provider is a subprocessor. The applicable module, options and completed annexes form part of this DPA as set out in Schedule 1. If those SCCs do not cover a particular transfer, the parties must establish another applicable lawful mechanism before that transfer; merely referencing the SCCs does not extend their legal scope. New Zealand’s adequacy decision may cover qualifying transfers to recipients in New Zealand; it does not establish adequacy for Provider’s US entity or other US recipients. Provider shall document any required transfer assessment and supplementary measures and ensure that subprocessors provide appropriate safeguards. In a conflict, applicable SCCs prevail over this DPA and the Agreement. 9. Retention, return and deletion Provider shall process and retain Customer Personal Data only as necessary for the Services and Customer’s documented lawful instructions. Customer controls submission expiration during the Services. Automatic expiration is disabled by default; enabling template expiration defaults to seven days unless Customer chooses another period. Ordinary expiration removes the generated PDF and preview from normal access, clears submission and webhook payloads, and deletes ordinary submission images. It does not independently erase signatures, submission metadata or separately stored data request/event records. Provider shall assist Customer with separate lawful erasure instructions for those records. At the end of the Services or when the processing purpose ends, Provider shall, at Customer's choice, return or delete Customer Personal Data from active systems without undue delay and no later than 60 days, or earlier where required by applicable law or a binding lawful instruction. Independently retained billing or legal records must have an identified lawful basis and are not covered by an unrestricted exception for all customer content. Subject to applicable law and any stricter binding customer terms, residual copies in protected recovery systems may remain only until their scheduled expiry: automated database backups for up to 30 days, weekly snapshots for up to 90 days, monthly snapshots for up to 365 days, automated Redis snapshots for up to 7 days, and noncurrent document-object versions scheduled for deletion after 180 days. Database and Redis snapshot periods run from creation of the recovery copy; the document-version period runs from when the version becomes noncurrent. S3 lifecycle removal is asynchronous. One-off snapshots taken for maintenance, migration or incident response are encrypted, restricted in the same way, and deleted once the change is confirmed stable and no later than 30 days after their creation. After the corresponding active data is deleted, recovery copies shall be unavailable for ordinary use and accessed only for necessary disaster recovery or security restoration. Provider shall maintain the minimum erasure record needed to reapply completed erasures before restored data is returned to ordinary service. Provider shall not extend the retention period by copying or resnapshotting recovery-only data. Provider shall disclose residual retention when confirming an erasure and shall not certify destruction of all copies before that is established. Database and Redis recovery copies are point-in-time snapshots that cannot be selectively edited; they expire on the schedule above. Separately deletable copies outside those snapshots, such as noncurrent document-object versions, are removed on erasure where Provider’s tooling supports it and otherwise expire under the lifecycle schedule. Provider shall document any such limitation and apply the restricted-use and restore-time erasure safeguards above until the copy expires. This recovery provision does not override applicable SCCs, mandatory erasure rights, or a shorter agreed customer schedule. If those obligations cannot be met, Provider shall notify Customer and resolve the conflict before relying on the longer recovery period. Operational logs containing Customer Personal Data must be covered by an identified purpose and lawful retention schedule. 10. Subprocessors Customer gives general written authorization for the subprocessors identified in Schedule 1.D. Before engagement, Provider shall perform appropriate due diligence and enter into a written agreement imposing the same applicable data protection obligations as this DPA, including sufficient guarantees for appropriate security measures. Provider remains responsible to Customer for the performance of its subprocessors’ obligations. Provider shall maintain the list with each legal entity, service, location, personal-data scope and applicable safeguards, and give at least 30 days’ advance written notice of intended additions or replacements so Customer may object on reasonable data protection grounds. The parties shall work to resolve an objection before the affected processing begins; unresolved objections require an agreed alternative or termination of the affected service, with return or deletion under clause 9. Onward subprocessing remains subject to equivalent authorization, contract and transfer requirements. Applicable SCC requirements prevail in a conflict. 11. Compliance with law Comply with Applicable Data Protection Laws. Nothing in the Agreement limits mandatory data subject rights or obligations under the GDPR or applicable SCCs. Incorporation and customer particulars The parties enter into this DPA, including applicable incorporated SCCs, through acceptance of the Agreement. The Customer’s legal name, address and authorized contact are those in the Agreement, order and account records. The Customer’s acceptance date and Provider’s entry into the Agreement are the corresponding dates of execution; no separate execution page is required. Customer shall keep its particulars current and may designate a privacy contact by notifying [email protected]. Those particulars and Customer’s documented service instructions form part of Schedule 1. Schedule 1 — Processing and international transfers A. Parties and roles Customer/exporter: the Customer identified in the Agreement and associated account or order records, using the address and authorized privacy or account contact in those records. Activities: supplying personal data and instructions for the services described below. Customer acts as controller where it determines the purposes and means of processing, or as processor where it acts for another controller. The role follows the actual processing; Module Two applies to the former and Module Three to the latter where the SCCs apply. When acting as a processor, Customer must have authority from the relevant controller to appoint Provider and make that controller’s identity and applicable instructions available to Provider where needed to fulfil its obligations. Signature and date: acceptance of the Agreement as described above. Provider/importer: DocSpring, Inc.; address and privacy contact above. Activities: PDF generation, document storage, forms/signatures, support and customer-directed delivery. Role: processor or subprocessor, according to the applicable module. Provider’s EU representative is Rickert Rechtsanwaltsgesellschaft mbH, Colmantstraße 15, 53115 Bonn, Germany; [email protected]. Provider engages DocSpring NZ Limited, a separate New Zealand company, for development, operations and support. Authorized service personnel access Customer Personal Data primarily from New Zealand, under the subprocessor controls below. B. Description of processing and transfers Data subjects: persons identified in Customer’s templates, documents or form submissions; for example Customer’s users, employees, contractors, clients, applicants, signers and other end users. The categories applicable to a particular account are determined by the documents, forms and other personal data that Customer instructs Provider to process. Personal data: Customer-selected document contents and form answers, including names, addresses, contact details, account/reference identifiers, employment and financial information, identity-document details where instructed, signatures and related event information. Service context can include IP addresses, browser/device metadata, timestamps and account identifiers. The categories actually processed are those contained in Customer’s submissions and documented instructions; this list does not require Customer to submit any particular category. Special categories under Article 9 and offence/conviction information under Article 10 are not required to use the Service. They may be processed only to the extent included in Customer’s lawful instructions and permitted by the Agreement. Before submitting such information, Customer must identify the categories and any required additional safeguards to Provider and establish the necessary legal grounds and conditions. Access must be limited to authorized persons, the data minimized to what is necessary for the instructed purpose, and retention limited accordingly. An ordinary signature image is not automatically biometric special-category data. Cardholder data must not be sent as document-generation content; US protected health information requires an executed applicable BAA before processing. Frequency: continuous/as instructed during the service relationship. Nature: collection, receipt, validation, formatting, document generation, signature/form handling, storage, retrieval, delivery, debugging, expiration/deletion and recovery. Purpose: provide the services on Customer’s documented instructions, not to use customer document contents for unrelated purposes. Account region: the US or EU environment selected by Customer for its account. Production origin and recovery storage: US — AWS Northern Virginia; EU — AWS Frankfurt. The regional environments are independent, and EU database backups are configured to remain in Frankfurt. Authorized staff access is primarily from New Zealand. Global edge, notification and support processing is described in the applicable subprocessor list. Customer-directed webhook, storage and delivery destinations are those Customer configures or instructs Provider to use; Customer is responsible for its selection of those recipients and instructions, without limiting Provider’s own obligations under applicable law. Regional migration does not by itself confirm erasure of source-region account or document data. Source data may remain pending separate deletion, and recovery copies have their own retention periods. Customer’s documented instructions, this DPA and applicable retention requirements continue to govern those copies; migration does not create a new indefinite retention period. Duration and retention: processing continues for the service relationship and the limited return, deletion and recovery periods in clause 9. Recovery retention runs from backup creation or, for object versions, from becoming noncurrent; a recovery copy made shortly before active deletion may remain for almost another 365 days. Automated Redis snapshots are retained for up to 7 days in both regions. API/webhook database logs have a 90-day purge cutoff; Lambda worker logs are retained for 30 days. Infrastructure access and administrative gateway logs have configured retention of 2,555 and 2,557 days respectively for security investigation and access accountability. Security evidence is restricted to that purpose and is not a general exception to retain customer document content. Applicable law and stricter binding customer terms remain controlling. Backup retention applies separately to records included in database backups. For Module Three, the underlying controller processing consists of the Customer’s document-generation, form, signature and delivery activities described in this Schedule, for the purposes and duration of Customer’s authorized service instructions. Customer must communicate any further controller instructions or restrictions that apply to Provider’s part of that processing. Provider’s appointment does not authorize Customer to exceed its own mandate. C. SCC options and authority Where the 2021/914 SCCs legally apply, Module Two (controller to processor) or Module Three (processor to processor) applies according to the parties’ actual roles described in Schedule 1.A. No other module is incorporated for that transfer. Clause 7 docking applies. For Clause 9, Option 2 (general written authorization) applies with at least 30 days’ advance written notice of intended additions/replacements. The optional independent dispute-resolution provision in Clause 11 is not included. Clause 17: German law, which permits third-party beneficiary rights. Clause 18(b): courts of Germany. These choices govern the SCCs, not unrelated provisions of the Agreement. Annex I.A is completed by Schedule 1.A; Annex I.B by Schedule 1.B; Annex II by Schedule 2. For Annex I.C, the competent supervisory authority is determined by Clause 13: the authority responsible for Customer’s GDPR compliance where Customer is established in the EEA; the authority where Customer’s Article 27 representative is established when the second limb of Clause 13(a) applies; or, where the third limb applies, the authority in an EEA Member State in which affected data subjects are located, as designated by Customer. Customer’s establishment, representative and any necessary designation are recorded in its Agreement or written instructions. Provider’s German representative does not by itself determine Customer’s supervisory authority. Official unchanged SCC text: Commission Implementing Decision (EU) 2021/914. The parties shall document any transfer assessment and supplementary safeguards required by the applicable SCCs, including Clause 14, and provide the required cooperation and information. Where these SCCs are outside their legal scope, the parties must establish another applicable lawful transfer mechanism before the restricted transfer; their incorporation does not extend the scope of Decision 2021/914. D. Authorized subprocessors and other recipients The following providers are authorized for the functions described below, to the extent those functions involve Customer Personal Data. Core hosting and network services process service traffic and stored content. Notification, monitoring and support providers receive only the information needed for the relevant function; support tools may receive document contents or attachments when supplied for an authorized support request. A provider’s corporate address is not a promise that all processing takes place there. DocSpring NZ Limited Function and data: software development, infrastructure operations, technical support and quality assurance, including access to customer document/form/signature data, account identifiers and technical or support context where necessary for the authorized task. Personnel access is primarily from New Zealand; production origin storage remains in the customer-selected US or EU region. This is a separate service provider, not a subsidiary of DocSpring, Inc. Provider contact: [email protected]. The subprocessor is subject to Provider’s documented instructions, confidentiality, security and onward-processing requirements. Qualifying NZ transfers may rely on the European Commission’s New Zealand adequacy decision; this does not cover Provider’s US entity or every onward recipient. Amazon Web Services, Inc. (AWS) Function and data: computing, databases, document storage, logging and recovery for templates, document contents, form/signature data and related service records. Production origin and recovery storage: Northern Virginia, United States, for US accounts; Frankfurt, Germany, for EU accounts. Provider contact and onward-processing details: AWS contracting details and AWS subprocessors. Transfer terms: AWS Data Processing Addendum. Cloudflare, Inc. Address: 101 Townsend Street, San Francisco, CA 94107, United States. Function and data: network proxying, delivery and security, including IP addresses, request metadata and content transmitted through proxied services. Processing uses Cloudflare’s global network, including locations outside the EEA; the account’s document-storage region does not restrict this edge processing to that region. Locations: Cloudflare network. Processing and transfer terms: Cloudflare DPA. AC PM LLC (Postmark) Function and data: transactional email delivery, including recipient addresses, message contents, delivery metadata and customer-directed notifications. Delivery infrastructure is in the United States. Provider contact, infrastructure and onward-processing details: Postmark privacy and subprocessors. Processing and transfer terms: Postmark DPA. Intercom, Inc. Address: 55 2nd Street, 4th Floor, San Francisco, CA 94105, United States. Function and data: customer support and messaging, including user/account identifiers, contact details, conversations and support attachments. Processing may take place in the United States and other countries used by Intercom and its service providers; selecting DocSpring’s EU account region does not select an Intercom hosting region. Processing, transfer and onward-processing details: Intercom DPA. Functional Software, Inc. (Sentry) Address: 45 Fremont Street, 8th Floor, San Francisco, CA 94105, United States. Function and data: error monitoring and diagnosis, including account/user identifiers, request metadata and error context that may contain Customer Personal Data. Processing may take place in the United States and other countries used by Sentry and its service providers. Details: Sentry DPA and Sentry subprocessors. Google LLC (Google Workspace) Address: 1600 Amphitheatre Parkway, Mountain View, CA 94043, United States. Function and data: business email and restricted support documentation, including correspondence, customer-provided attachments and support records where needed to handle Customer’s instructions. Processing may take place in the United States and other countries in Google’s processing network. Details: Google Cloud Data Processing Addendum and Google Workspace subprocessors and locations. Slack Technologies, LLC (Slack) Address: Salesforce Tower, 415 Mission Street, San Francisco, CA 94105, United States. Function and data: internal coordination of customer support and service incidents, limited to relevant messages, identifiers and support context shared for that purpose. Processing may take place in the United States and other countries used by Slack and its service providers. Details: Slack data processing terms and Slack subprocessor information. Notion Labs, Inc. (Notion) Function and data: restricted support and operational documentation, limited to information shared to handle Customer’s service instructions or support requests. Processing may take place in the United States and other countries used by Notion and its service providers. Provider contact, processing and transfer details: Notion GDPR information and linked DPA and subprocessor list. The linked provider terms and location lists supply further information about those providers; they do not reduce Provider’s obligations under this DPA or authorize unrelated use of Customer Personal Data. Provider shall ensure binding processing terms and a lawful mechanism for each restricted onward transfer under clauses 8 and 10. Customer may request the applicable safeguards and copies of subprocessor agreements, with confidential material redacted where permitted by applicable law and SCCs, by contacting [email protected]. Changes to Provider’s subprocessors remain subject to the notice and objection procedure in clause 10. Customer-selected recipients, such as webhook endpoints and storage integrations, are destinations specified by Customer’s instructions. Services used solely for Provider’s independent account, billing, marketing or business-administration purposes are described in the Privacy Policy; this list does not authorize them to receive customer document contents for unrelated purposes. Schedule 2 — Technical and organisational measures Encryption and access HTTPS/TLS and HSTS protect public service connections. Submission/form payloads stored in RDS use application-level encryption; document storage and RDS databases use AWS KMS-backed encryption, and the Redis job queue and cache is encrypted at rest. Passwords are hashed. Customer/account access controls, authenticated API requests and restricted links protect access according to configuration. Encryption permits authorized processing needed to provide the Services. Infrastructure and administration US and EU production databases and document storage are separate. RDS Multi-AZ supports availability. Network security groups, distinct application/admin database privileges, SSO/RBAC, Tailscale administrative access, credential management and audit logging restrict access. AWS provides the physical data-centre controls. Personnel and operational controls Authorized personnel are subject to confidentiality duties and role-based access. Policies cover access, information handling, incident response, change management, training and vendor risk. Customer-content debugging is limited to the support purpose and Customer’s instructions. Endpoint and credential controls apply to the remote workforce. Recovery and deletion Regional encrypted database recovery copies and S3 versioning support recovery. Retention periods and return/deletion obligations are set out in clause 9 and Schedule 1. Access to recovery copies is restricted. Provider must handle erasure of retained signatures, form records and metadata separately from ordinary submission expiration and reapply relevant erasure instructions after restoration. Testing and assurance DocSpring completed a SOC 2 Type II audit covering July 24–October 22, 2025 for Security, Confidentiality and Availability. The report describes access reviews, security training, vulnerability scanning, incident procedures and backup monitoring. Provider shall maintain and review its security measures as systems change. Customers may request the SOC 2 report through the DocSpring Trust Portal, subject to confidentiality requirements. Privacy Contact For questions about this DPA or to request a separately signed copy, contact [email protected]. Last Modified: