Effective Date: 1 September 2023
Last Updated: 8 September 2026
This Data Processing Agreement ("DPA") is entered into between:
1. Documentero
("Data Processor," "Processor," "we," "us," or "our"), and
2. the Customer using the Documentero service
("Data Controller," "Controller," "you," or "your").
This DPA supplements and forms part of the Terms of Service and any other agreement governing the Customer's use of the Documentero SaaS document generation service (the "Service") (together, the "Agreement"). It applies where and to the extent Documentero processes Personal Data on behalf of the Customer in connection with the Service, and is intended to meet the requirements of Article 28 of the General Data Protection Regulation (EU) 2016/679 ("GDPR"). Capitalized terms not defined in this DPA have the meaning given in the Agreement. In the event of a conflict between this DPA and the Agreement regarding the processing of Personal Data, this DPA prevails.
This DPA becomes binding when the Customer accepts the Agreement or uses the Service.
The Customer is the Data Controller of Personal Data contained in Customer Content and of Personal Data relating to Customer End Users. Documentero processes such Personal Data as Data Processor, solely on behalf of and in accordance with the documented instructions of the Customer, as set out in this DPA and the Agreement and as given through the Customer's configuration and use of the Service.
This DPA does not apply to Personal Data that Documentero processes as an independent Data Controller for its own purposes, such as account and authentication data of the Customer's users, billing and subscription records, usage statistics, security and abuse-prevention data, administrative support correspondence, and website analytics. Such processing is described in the Privacy Policy. Customer Content provided to Documentero solely for troubleshooting remains subject to this DPA.
Third-party platforms that the Customer connects to the Service using its own API key or credentials act on the Customer's instructions and are not Subprocessors of Documentero. Where the Customer uses AI Features with its own AI provider key ("Bring Your Own Key"), the AI provider processes data under the Customer's own agreement with that provider.
Documentero processes Personal Data on behalf of the Customer for the purpose of providing the Service, which includes:
Categories of data subjects. Users of the Customer's Documentero account; Customer End Users (for example persons submitting the Customer's shareable forms or receiving generated documents); and any other natural persons whose Personal Data the Customer includes in templates, form submissions, or data submitted for document generation.
Special categories of data. The Service is not designed for the processing of special categories of Personal Data (Article 9 GDPR), data relating to criminal convictions, or data subject to sector-specific regulation such as HIPAA. The Customer shall not submit such data unless Documentero has agreed to the processing in writing and the Customer has established an appropriate lawful basis and safeguards.
Depending on the Customer's configuration and the content the Customer submits, the Personal Data processed may include:
Processing continues for the duration of the Agreement and for any additional period necessary to complete deletion in accordance with Section 13, unless otherwise instructed by the Customer or required by law. Personal Data is generally retained for the following periods:
Documentero shall:
Taking into account the nature of the processing and the information available to Documentero, Documentero will assist the Customer, by appropriate technical and organisational measures, in fulfilling the Customer's obligations to respond to requests from data subjects exercising their rights under the GDPR, including the rights of access, rectification, erasure, restriction of processing, data portability, and objection. In the first instance, the Customer should use the available self-service functions of the Service, such as editing or deleting templates and forms or managing its users.
If Documentero receives a request directly from a data subject relating to Personal Data processed on behalf of the Customer, Documentero will, where legally permitted, promptly forward the request to the Customer and will not respond to it except on the Customer's documented instructions or where required by law.
Documentero will further provide reasonable assistance to the Customer in ensuring compliance with the Customer's obligations under Articles 32 to 36 GDPR (security of processing, breach notification, data protection impact assessments, and prior consultation), to the extent relevant to the Service and to the information available to Documentero. Documentero may charge a reasonable fee for assistance that goes beyond the self-service functions of the Service and the information already made available in this DPA, the Privacy Policy, and Documentero's documentation, unless the assistance is required as a result of Documentero's breach of this DPA.
The Customer is responsible for: (a) ensuring that it has a lawful basis for the processing of Personal Data through the Service and for making that Personal Data available to Documentero; (b) providing all required notices to data subjects and obtaining consent where required, including for Customer End Users who submit the Customer's shareable forms or receive generated documents; (c) ensuring that its instructions to Documentero comply with applicable law; (d) the content of Customer Content and the accuracy of data it submits; (e) the confidentiality of its account credentials and API keys, the management of its users' access, and the configuration of the Service (including recipients of emails and public availability of shareable forms); and (f) complying with the restrictions in Section 3 regarding special categories of data.
The Customer provides general authorisation for Documentero to engage the Subprocessors listed below to process Personal Data on the Customer's behalf:
| Subprocessor | Purpose | Personal Data involved | Location |
|---|---|---|---|
| Google Cloud | Hosting, authentication, database, file storage, compute, and technical logging for the Service | All categories listed in Section 4 | European Union regions selected by Documentero |
| Brevo | Email delivery, including delivery of generated documents where instructed by the Customer | Recipient email addresses, message content, and attached generated documents | European Union |
| OpenAI (optional; AI Credits mode only) | Processing of AI-assisted features (content generation, template editing, document-to-template conversion, form configuration) | Template content, form configurations, prompts, and related context submitted when an AI Feature is used. No data is sent to OpenAI when AI Features are set to "Disabled". | United States (transfers under EU Standard Contractual Clauses) |
Each Subprocessor is bound by written data protection obligations appropriate to the processing. Documentero remains responsible to the Customer for the performance of its Subprocessors' obligations as required by applicable data protection law.
Changes to Subprocessors. Documentero may add or replace Subprocessors. Consistent with Article 28(2) GDPR, intended changes are communicated through this page or another reasonable electronic method, giving the Customer an opportunity to object on reasonable data protection grounds. If an objection cannot be resolved, the Customer may discontinue the affected part of the Service in accordance with the Agreement.
Payment processing is performed by Paddle, acting as Documentero's reseller and merchant of record. Paddle processes payment data as an independent data controller under its own privacy policy, and is not a Subprocessor under this DPA. Analytics and other tools used by Documentero in its capacity as an independent Data Controller are listed in the Privacy Policy.
Taking into account the state of the art, the costs of implementation, and the nature, scope, context, and purposes of processing, Documentero implements and maintains appropriate technical and organisational measures to ensure a level of security appropriate to the risk, including:
Documentero does not currently hold external security certifications (such as ISO 27001 or SOC 2) and does not represent this DPA as a formal compliance attestation. Documentero may update these measures from time to time, provided that the overall level of security is not materially reduced.
Documentero will notify the Customer without undue delay after becoming aware of a Personal Data Breach affecting Personal Data processed on behalf of the Customer. The notification will, to the extent the information is available to Documentero, include:
Where it is not possible to provide all information at the same time, Documentero will provide it in phases without undue further delay. Notification of, or response to, a Personal Data Breach is not an acknowledgement by Documentero of any fault or liability. The Customer is responsible for any notifications to supervisory authorities or data subjects required of it under Articles 33 and 34 GDPR.
Documentero configures the Google Cloud resources used to host Customer Content in European Union regions.
Where a Subprocessor processes Personal Data outside the European Economic Area (see Section 9), the transfer takes place only subject to appropriate safeguards under Chapter V GDPR, such as the European Commission's Standard Contractual Clauses or an adequacy decision. Changes affecting transfer locations are addressed in accordance with Section 9.
Transfers that result from the Customer's own choices — for example the Customer's use of a third-party integration platform, the Customer's own AI provider key, or the delivery of generated documents to recipients located outside the EEA — are carried out on the Customer's instruction and are the Customer's responsibility.
The Customer may delete templates, form configurations, and other Customer Content at any time through the Service, and may download its templates and generated documents through the Service for as long as they are available.
Upon termination of the Agreement, the Customer may instruct Documentero to return or delete Personal Data processed on its behalf. Any return is subject to reasonable technical arrangements agreed by the parties. If the Customer does not provide an instruction within 30 days after termination, or submits a confirmed account deletion request, Documentero will delete the Personal Data from active systems. Following return, Documentero will delete remaining copies unless applicable law requires retention. Personal Data retained in backups, where applicable, remains protected and is deleted through the applicable backup-rotation process. Generated documents are deleted in accordance with Section 5.
The Service is not intended to serve as the Customer's backup or archival system. The Customer remains responsible for retaining its own copies of templates, source data, and generated documents to the extent it requires them, and for the content and accuracy of the data it transmits to the Service.
Each party is liable for damage caused by its own processing in violation of the GDPR or this DPA, in accordance with Article 82 GDPR. To the maximum extent permitted by applicable law, the liability of each party arising out of or in connection with this DPA is subject to the exclusions and limitations of liability set out in the Agreement, which apply to this DPA as if set out in full herein. Nothing in this DPA limits either party's liability towards data subjects under Article 82 GDPR.
Upon the Customer's written request, and no more than once in any 12-month period unless required by a supervisory authority, following a Personal Data Breach affecting the Customer, or where the Customer has reasonable grounds to suspect material non-compliance with this DPA, Documentero will make available the information reasonably necessary to demonstrate compliance. Such information may include this DPA, the description of technical and organisational measures in Section 10, the current list of Subprocessors, and summaries of relevant third-party assessments where available.
Where the Customer can reasonably demonstrate that the information provided is insufficient to verify compliance, or where an inspection is required by applicable law or a supervisory authority, the Customer (or an independent auditor bound by confidentiality and reasonably acceptable to Documentero) may conduct an audit of Documentero's relevant processing activities. Any such audit shall: (a) be limited in scope to the processing of Personal Data under this DPA; (b) take place during normal business hours on at least 30 days' prior written notice, except where a supervisory authority or urgent circumstances reasonably require shorter notice; (c) not unreasonably interfere with Documentero's business operations; (d) not extend to systems or data of other customers; and (e) be subject to appropriate confidentiality obligations. The Customer bears its own audit costs, and Documentero may charge a reasonable fee for assistance exceeding one working day, except to the extent the audit identifies a material breach of this DPA by Documentero.
This DPA remains in force for as long as Documentero processes Personal Data on behalf of the Customer. Documentero may update it to reflect changes in applicable law, the Service, or its Subprocessors, provided that an update does not materially reduce the protection of Personal Data. The "Last Updated" date identifies the current version. A change that materially alters the nature or purpose of processing requires the Customer's agreement.
This DPA is governed by the laws of the Republic of Poland and, to the extent applicable, the law of the European Union, and any disputes arising from or related to this DPA shall be subject to the exclusive jurisdiction of the courts in Poland, without prejudice to the rights of data subjects and supervisory authorities under the GDPR.
For any questions or concerns related to this DPA, please contact us at:
Support Email (support@documentero.com)