DocAccessible

Legal & trust

Data Processing Addendum

This DPA governs DocAccessible's processing of personal data contained in Customer Content on behalf of a business customer.

Effective July 18, 2026Version 2026-07-18

This DPA forms part of the Terms of Service or applicable customer order when data-protection law requires controller–processor terms. The customer is the controller or processor that determines the permitted instructions; DocAccessible is its processor or subprocessor.

1. Definitions and priority

“Customer Personal Data” means personal data in Customer Content processed by DocAccessible on the customer's behalf. “Data Protection Law” means privacy and data-protection law applicable to that processing, including the GDPR, UK GDPR, California privacy law, or India's Digital Personal Data Protection framework where applicable. “Security Incident” means a confirmed breach of security leading to accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to Customer Personal Data.

This DPA controls over inconsistent online Terms only for its subject matter. A signed order or negotiated DPA controls where it expressly replaces a clause.

2. Instructions and purpose limitation

DocAccessible will process Customer Personal Data only to provide, secure, support, and maintain the service; follow documented customer configuration and requests; comply with this DPA and applicable orders; or comply with law. The Terms, selected plan, workspace settings, support requests, and documented use of features are the customer's instructions. If we believe an instruction violates Data Protection Law, we will notify the customer unless prohibited.

3. Customer responsibilities

The customer determines the lawful purpose, legal basis, notices, permissions, accuracy, retention, and data-subject responses for Customer Personal Data. It will not instruct DocAccessible to process data unlawfully and will minimize sensitive or regulated information. The customer is responsible for workspace membership, publication settings, recipient links, connected websites, and other configuration under its control.

4. Confidentiality and personnel

Personnel authorized to process Customer Personal Data are subject to confidentiality obligations and receive access only where needed for their role. Support access to a customer account must be authorized, time-limited, reason-bound, visibly indicated, and auditable. DocAccessible remains responsible for personnel performance of these obligations.

5. Security

DocAccessible will maintain appropriate technical and organizational measures considering the nature, scope, context, and risk of processing. Current measures are described in Annex II below and the Security Overview. We may update measures as technology and risk change, provided the overall level of protection is not materially reduced during a paid term.

6. Subprocessors

The customer gives general authorization for the providers on the Subprocessor List. DocAccessible will impose data-protection obligations appropriate to each provider's role and remains responsible for its subprocessors to the extent required by law. A customer may object to a new subprocessor on reasonable data-protection grounds within 15 days after notice. The parties will work in good faith on a reasonable alternative; if none is available, either party may terminate only the affected feature or service without penalty for the unused prepaid affected period.

7. Data-subject requests

Taking into account the nature of processing, DocAccessible will provide reasonable assistance for access, correction, deletion, restriction, objection, portability, and similar requests. If a request clearly concerns Customer Personal Data, we will direct it to the customer unless law requires another response. The customer can use product export, editing, access, and deletion functions for many requests.

8. Security Incidents

DocAccessible will notify the customer without undue delay after confirming a Security Incident affecting its Customer Personal Data. Notice will include information reasonably available about the nature of the incident, affected data and people, likely consequences, containment and remediation, and a contact for follow-up. Notice is not an admission of fault. The customer is responsible for regulator or individual notices unless law assigns them to us.

9. Assessments, consultation, and audits

We will provide information reasonably necessary to demonstrate compliance with applicable processor obligations and assist with proportionate data protection impact assessments and regulator consultation. Customers should first use current policies, security responses, and independent evidence we make available. Additional audits must be legally required or reasonably justified, no more than once per year unless an incident or regulator requires more, subject to confidentiality, reasonable notice, minimal disruption, and reimbursement of extraordinary costs.

10. Return and deletion

During the service term, authorized users can export or download supported content. At termination or on documented instruction, DocAccessible will delete or return Customer Personal Data unless law requires retention. Account deletion uses a durable private-object deletion process. Redacted audit evidence, non-identifying tombstones, fraud records, and backup copies may remain only for integrity, security, legal, or recovery purposes and are isolated from ordinary use.

11. International transfers

If Customer Personal Data is transferred across a border and Data Protection Law requires a safeguard, the parties will use an applicable adequacy decision, standard contractual clauses, addendum, or other valid mechanism. For a restricted EEA transfer that is not otherwise covered, the parties will enter the then-current EU controller-to-processor or processor-to-processor Standard Contractual Clauses as appropriate. For a UK restricted transfer, the parties will use the applicable UK addendum or replacement mechanism. Contact us if an executed transfer instrument or location-specific annex is required; we do not promise a data location that is not stated in a signed order.

12. Duration and liability

This DPA starts when DocAccessible first processes Customer Personal Data and continues until that processing ends. Liability under this DPA is subject to the limitations in the Terms or applicable order, except where Data Protection Law prohibits a limitation.

Annex I — Processing details

  • Subject matter: document checking, remediation, publishing, review, monitoring, program intake, Exchange, delivery, support, and related platform operations.
  • Duration:the customer's service term plus the controlled deletion and backup period.
  • Nature and purpose:collection, upload, storage, organization, extraction, analysis, transformation, generation, review, sharing, retrieval, transmission, support, and deletion at the customer's direction.
  • People: customer personnel, document authors and subjects, constituents, students, patients, applicants, vendors, reviewers, requesters, recipients, site contacts, and other people represented in Customer Content.
  • Data: contact and account details, document text and images, accessibility attributes, comments, evidence, workflow metadata, URLs, logs, identifiers, and any other personal data the customer chooses to include.
  • Sensitive data: not required by default. Customer documents may contain sensitive or special-category data; the customer must minimize it and provide any legally required instruction or safeguard.
  • Frequency: continuous or event-driven according to customer use during the service term.

Annex II — Technical and organizational measures

  • private object storage and application-authorized file delivery;
  • role, workspace, ownership, state, and entitlement checks at trusted server boundaries;
  • hashed credentials, scoped tokens, secure production cookies, rate limits, and request-origin safeguards;
  • file type and signature validation plus required production malware scanning;
  • versioned documents, outputs, reviews, approvals, evidence, and Exchange revisions;
  • isolated background processing with bounded execution and terminal job states;
  • outbound URL restrictions and webhook destination validation;
  • restricted, reason-bound, time-limited, and audited support access;
  • PII-scrubbed monitoring, readiness checks, backup rotation, and deletion retry tracking; and
  • incident investigation, containment, recovery, and customer notification procedures.

Annex III — Contact

The customer contact is the account owner or person named in its order. The DocAccessible privacy contact is available through the DPA and privacy inquiry form.