Data Processing Addendum

Available for Business and Enterprise customers ยท GDPR Article 28 compliant

Overview

DocGovernance acts as a data processor when processing personal data on behalf of customers (controllers) in the course of providing the DocGovernance service. This Data Processing Addendum (DPA) governs that processing relationship in compliance with Article 28 of the GDPR.

What the DPA covers

Subprocessors

DocGovernance uses a limited number of subprocessors for cloud infrastructure, transactional email, and error monitoring. A current list is provided as part of the DPA and updated with 30 days' notice of changes. Customers have the right to object to new subprocessors.

Security measures

The DPA incorporates our technical and organizational security measures including: TLS encryption in transit, encryption at rest, tenant isolation, access controls, Ed25519 signing, SHA-256 integrity verification, vulnerability management, incident response, and backup/recovery procedures.

Audit rights

Business and Enterprise customers may request evidence of compliance (documentation, certifications) once per year. On-site audits are available to Enterprise customers under a confidentiality agreement.

Request the DPA

The full DPA is available to Business and Enterprise customers. Contact us to receive a copy for review and execution.

Request DPA โ†’