Legal
DocumentMS data processing addendum
The data processing addendum forms part of your contract and sets out how DocumentMS processes personal data on your instructions: the subject matter and duration, the security measures applied, sub-processor approval, transfer safeguards, your audit rights and our breach notification obligations.
Processing particulars
| Particular | Detail |
|---|---|
| Subject matter | Provision of the DocumentMS document management service |
| Duration | The term of the subscription, plus the 90-day post-termination export window |
| Nature and purpose | Storage, indexing, optical character recognition, search, workflow routing, signature capture, retention enforcement and audit logging, carried out on the controller’s instructions |
| Types of personal data | Whatever the controller places in its tenant. Commonly names, contact details, employment data, financial data; may include special category data where the controller’s use case involves it |
| Categories of data subject | Determined by the controller — typically employees, customers, suppliers, patients, students or clients |
| Special category data | Permitted. The controller must have its own Article 9 condition and identify the use case to us in advance, so that encryption, access review and retention settings are configured for it. For health data under HIPAA we execute a business associate agreement before any protected health information is uploaded |
Our obligations as processor
- Process personal data only on your documented instructions, including on international transfers
- Ensure personnel authorised to process are bound by confidentiality
- Implement the technical and organisational measures described in the trust centre, appropriate to the risk
- Engage sub-processors only under written terms no less protective, with prior notice of changes and a right to object
- Assist you in responding to data subject requests, taking into account the nature of the processing
- Assist with data protection impact assessments and prior consultation, on request
- Notify you without undue delay and in any event within 48 hours of becoming aware of a personal data breach
- Delete or return personal data at the end of the service, at your election
- Make available the information necessary to demonstrate compliance. You may audit once in any 12-month period on 30 days’ written notice, during business hours, under NDA and at your cost, or more often where a supervisory authority requires it or following a breach. A completed security questionnaire, our penetration test summary and the control documentation in the trust centre satisfy most audits without an on-site visit, and we would rather send those than schedule one
Sub-processors and transfers
Our current sub-processors are published on the sub-processors page, which this addendum incorporates by reference. We give 30 days’ notice before a new sub-processor starts processing, by email to your named administrators and by updating that page. You may object within those 30 days on reasonable data protection grounds; if we cannot resolve the objection, you may terminate the affected part of the service without penalty and receive a pro-rata refund.
Transfers out of the UK or EEA rely on the Standard Contractual Clauses (Decision 2021/914, modules two and three) for EEA data and the UK International Data Transfer Addendum for UK data, each supported by a transfer risk assessment. Where the Enterprise tier is used with your own S3 bucket or Azure container, document bytes remain in the region you nominate, which materially narrows the transfer question. Metadata, the search index and audit records are still processed in our platform region, and that exception is stated here rather than left implied — it is the detail a thorough review will find on its own.
آخر مراجعة: 2026-07-15