Doklavio.Back to Doklavio
LegalPrivacy PolicyTerms of UseCookie PolicyData Processing Agreement

Data Processing Agreement

Last updated: 20 August 2026

1. Parties and scope

This DPA is intended to form part of the future agreement between the customer as controller and the Doklavio operator as processor. It applies when Doklavio processes personal data contained in customer templates, assets, API records or generated documents on the customer's behalf.

2. Processing details

SubjectHosting document templates and assets; rendering documents from customer-provided records; team sharing; support and deletion
DurationFor the service term and the limited period needed to complete deletion and legally required retention
Nature and purposeStorage, organisation, retrieval, transmission, rendering, security, troubleshooting and deletion as instructed through the service
Data subjectsCustomer personnel, customers, suppliers, contractors and other people represented in customer content
Data typesAny fields selected by the customer, potentially including identity, contact, employment, transaction and document information
Sensitive dataNot intended for special-category, criminal-conviction, medical, payment-card, authentication-secret or similarly high-risk data unless separately agreed in writing

3. Processor duties

The Doklavio operator will process personal data only on documented customer instructions, including instructions expressed through use of the service, unless EU or Member State law requires otherwise. It will ensure authorised personnel are bound by confidentiality and will implement appropriate technical and organisational measures.

4. Security measures

  • Encrypted transport and provider-managed encryption at rest
  • Authentication, tenant-aware authorisation and private object storage
  • Protected API credentials, durable quotas, rate limits and idempotency controls
  • Restricted service identities and an isolated, network-contained PDF renderer
  • Security logging, dependency review, deletion workflows and tested account isolation
  • Input, output, resource and rendering limits intended to reduce abuse

5. Subprocessors

ProviderPurposeTransfer protection
Google services, including Firebase and Google CloudAuthentication, hosting, database, storage, security and server processingApplicable adequacy decisions and contractual safeguards
StripeSubscription billing and payment administrationApplicable adequacy decisions and contractual safeguards

Doklavio will provide reasonable notice of a new subprocessor and an opportunity for the customer to object on data-protection grounds.

6. Assistance

Taking into account the nature of processing, the operator will reasonably assist the customer with data-subject requests, security obligations, breach notifications, impact assessments and supervisory-authority consultations. The customer remains responsible for responding as controller.

7. Personal-data breaches

The operator will notify the customer without undue delay after becoming aware of a personal-data breach affecting customer data and will provide available information reasonably required for the customer's assessment and notification duties.

8. Deletion and return

At the end of services, the operator will delete or return customer personal data as selected or required by the service agreement, unless applicable law requires retention. API inputs are not persisted; replay PDFs become eligible for deletion after 24 hours.

9. Audits

The operator will make information reasonably necessary to demonstrate GDPR Article 28 compliance available to the customer and permit proportionate audits subject to confidentiality, security, notice and non-disruption safeguards.

10. International transfers and precedence

Personal data will not be transferred outside the EEA without a lawful transfer mechanism and any supplementary safeguards required by applicable law. If this DPA conflicts with the main service agreement regarding personal-data processing, the completed DPA will prevail.

11. Parties and acceptance

The customer details are those associated with the accepting account or order. Doklavio's legal operator, registration, address and privacy contact details will be added when registration is complete. This DPA applies when incorporated into an agreement or accepted through an authorised service flow.

HomeDocumentationPrivacyTermsCookiesDPA© 2026 Doklavio. All rights reserved.