DOCSUPRA Open the Enterprise Studio

DOCSUPRATrust center › DPA

Data Processing Addendum · version 18 September 2026

Data Processing Addendum

This Addendum forms part of the agreement between the customer (“Customer”) and DocVerifyPro, a sole proprietorship registered in Puerto Rico, United States (“Provider”) for the DocVerifyPro software (the “Service”). It applies whenever Provider processes personal data on Customer’s behalf.

Scope note. The Service processes documents inside the Customer’s own browsers. Provider never receives document content, so document content is outside this Addendum entirely: there is no processing of it by Provider to regulate. The personal data actually processed by Provider is limited to the categories in Annex 1.

1. Definitions

“Data Protection Law” means the EU General Data Protection Regulation 2016/679 (GDPR), the UK GDPR and Data Protection Act 2018, the Swiss Federal Act on Data Protection, and the California Consumer Privacy Act as amended (CCPA), each as applicable. “Personal Data”, “Controller”, “Processor”, “Data Subject”, “Processing” and “Sub-processor” have the meanings in Data Protection Law. “SCCs” means the Standard Contractual Clauses adopted by the European Commission in Decision 2021/914, Module Two (controller to processor), with the UK Addendum where the UK GDPR applies.

2. Roles

Customer is the Controller of Customer Personal Data (Annex 1). Provider is the Processor. Where Provider processes billing data for its own accounting and tax obligations, it acts as an independent Controller under its Privacy Policy.

3. Processing instructions

Provider processes Customer Personal Data only on documented instructions from Customer, which are: to operate the Service, authorise downloads against the licence, count seats, maintain the organisation’s member list and usage report, record audit-log metadata where the organisation enables it, send invoices and receipts, and provide support. Provider informs Customer if an instruction infringes Data Protection Law.

4. Confidentiality

Persons authorised to process Customer Personal Data are bound by confidentiality. Provider is a single-operator organisation; the operator is so bound.

5. Security measures

Provider implements the technical and organisational measures in Annex 2, which Customer has assessed as appropriate given that no document content is processed.

6. Sub-processors

Customer authorises the Sub-processors listed at docsupra.com/subprocessors. Provider gives 30 days’ notice of any addition or replacement by email to Customer’s billing contact. Customer may object on reasonable grounds within that period; if the objection cannot be resolved, Customer may terminate the affected subscription effective at the end of the paid period. Provider remains liable for its Sub-processors’ performance.

7. Data subject rights

Provider assists Customer with requests from Data Subjects, taking into account the nature of the processing. Requests received directly by Provider are forwarded to Customer within 5 business days without response, unless Customer instructs otherwise.

8. Personal data breach

Provider notifies Customer without undue delay and in any case within 72 hours of becoming aware of a Personal Data Breach affecting Customer Personal Data, providing the information reasonably required for Customer’s own notifications, and updates as it becomes available.

9. Assistance

Provider assists Customer with data protection impact assessments and prior consultations to the extent they relate to Provider’s processing.

10. Deletion and return

On termination, Provider deletes Customer Personal Data within 30 days except billing records it must retain under tax law, and seat records that expire automatically within 400 days. Because no document content is held, there is nothing to return.

11. Audit

Provider makes available the information necessary to demonstrate compliance with Article 28 and allows for and contributes to audits, including inspections, conducted by Customer or an auditor mandated by Customer, once per year on 30 days’ notice, during business hours, and without access to other customers’ data. The published controls at /security are the starting point.

12. International transfers

Provider is established in Puerto Rico, United States. Transfers of Customer Personal Data from the EEA, UK or Switzerland are governed by the SCCs, which are incorporated by reference with Customer as data exporter and Provider as data importer; Annex 1 and Annex 2 below serve as the SCC annexes; the UK Addendum applies to UK transfers; and the supervisory authority is that of the Customer’s establishment. Clause 7 (docking) is included; Clause 11 optional language is not; Clause 17 selects the law of Ireland and Clause 18 the courts of Ireland for the SCCs only.

13. CCPA

Where the CCPA applies, Provider is a service provider, does not sell or share Personal Data, processes it only for the business purposes above, and certifies that it understands these restrictions.

14. Liability and precedence

This Addendum is subject to the liability terms of the governing agreement (the Terms of Service or, where signed, the Enterprise Subscription Agreement). In case of conflict on data-protection matters, this Addendum prevails; in case of conflict with the SCCs, the SCCs prevail.

Annex 1 — Description of processing

ItemDescription
Data subjectsCustomer’s billing contact and administrators, and the members the Customer invites (work email address).
Categories of personal dataName and email of the billing contact; company name, VAT/EIN and address for invoices; plan, amounts and dates; licence tokens and per-person seat identifiers; where the organisation log is enabled: file names, SHA-256 hashes, dimensions, verdicts, member email and time of each audit batch (never the image); connection data on API calls (IP, time), stored only as a daily-salted hash for 48 hours.
Special categoriesNone. Document content (which may contain special categories) is never transmitted to Provider.
Nature and purposeOperating a paid software licence: authorising downloads, counting seats, invoicing, support, and producing usage reports for the Customer’s administrators.
DurationLife of the subscription plus retention periods in section 10.
FrequencyContinuous while the subscription is active.

Annex 2 — Technical and organisational measures

Execution

This Addendum is accepted by the parties when Customer references it in a purchase order or signed agreement, or by countersignature below. A countersigned PDF is available from security@docsupra.com.

Customer — name, title, date
DocVerifyPro — Soelys Muñoz, owner, date