Data Processing Agreement
1. Parties and scope
This DPA is intended to form part of the future agreement between the customer as controller and the Doklavio operator as processor. It applies when Doklavio processes personal data contained in customer templates, assets, API records or generated documents on the customer's behalf.
2. Processing details
| Subject | Hosting document templates and assets; rendering documents from customer-provided records; team sharing; support and deletion |
|---|---|
| Duration | For the service term and the limited period needed to complete deletion and legally required retention |
| Nature and purpose | Storage, organisation, retrieval, transmission, rendering, security, troubleshooting and deletion as instructed through the service |
| Data subjects | Customer personnel, customers, suppliers, contractors and other people represented in customer content |
| Data types | Any fields selected by the customer, potentially including identity, contact, employment, transaction and document information |
| Sensitive data | Not intended for special-category, criminal-conviction, medical, payment-card, authentication-secret or similarly high-risk data unless separately agreed in writing |
3. Processor duties
The Doklavio operator will process personal data only on documented customer instructions, including instructions expressed through use of the service, unless EU or Member State law requires otherwise. It will ensure authorised personnel are bound by confidentiality and will implement appropriate technical and organisational measures.
4. Security measures
- Encrypted transport and provider-managed encryption at rest
- Authentication, tenant-aware authorisation and private object storage
- Protected API credentials, durable quotas, rate limits and idempotency controls
- Restricted service identities and an isolated, network-contained PDF renderer
- Security logging, dependency review, deletion workflows and tested account isolation
- Input, output, resource and rendering limits intended to reduce abuse
5. Subprocessors
| Provider | Purpose | Transfer protection |
|---|---|---|
| Google services, including Firebase and Google Cloud | Authentication, hosting, database, storage, security and server processing | Applicable adequacy decisions and contractual safeguards |
| Stripe | Subscription billing and payment administration | Applicable adequacy decisions and contractual safeguards |
Doklavio will provide reasonable notice of a new subprocessor and an opportunity for the customer to object on data-protection grounds.
6. Assistance
Taking into account the nature of processing, the operator will reasonably assist the customer with data-subject requests, security obligations, breach notifications, impact assessments and supervisory-authority consultations. The customer remains responsible for responding as controller.
7. Personal-data breaches
The operator will notify the customer without undue delay after becoming aware of a personal-data breach affecting customer data and will provide available information reasonably required for the customer's assessment and notification duties.
8. Deletion and return
At the end of services, the operator will delete or return customer personal data as selected or required by the service agreement, unless applicable law requires retention. API inputs are not persisted; replay PDFs become eligible for deletion after 24 hours.
9. Audits
The operator will make information reasonably necessary to demonstrate GDPR Article 28 compliance available to the customer and permit proportionate audits subject to confidentiality, security, notice and non-disruption safeguards.
10. International transfers and precedence
Personal data will not be transferred outside the EEA without a lawful transfer mechanism and any supplementary safeguards required by applicable law. If this DPA conflicts with the main service agreement regarding personal-data processing, the completed DPA will prevail.
11. Parties and acceptance
The customer details are those associated with the accepting account or order. Doklavio's legal operator, registration, address and privacy contact details will be added when registration is complete. This DPA applies when incorporated into an agreement or accepted through an authorised service flow.