انتقل إلى المحتوى الرئيسي
DocumentMS

Legal

DocumentMS data processing addendum

The data processing addendum forms part of your contract and sets out how DocumentMS processes personal data on your instructions: the subject matter and duration, the security measures applied, sub-processor approval, transfer safeguards, your audit rights and our breach notification obligations.

Effective 13 September 2026. The data processing addendum forms part of your contract and governs personal data we process on your behalf as a processor.

Processing particulars

Article 28(3) requires the subject matter, duration, nature, purpose, data types and categories of data subject to be specified. This is that specification.
Details of processing carried out by DocumentMS as processor
ParticularDetail
Subject matterProvision of the DocumentMS document management service
DurationThe term of the subscription, plus the 90-day post-termination export window
Nature and purposeStorage, indexing, optical character recognition, search, workflow routing, signature capture, retention enforcement and audit logging, carried out on the controller’s instructions
Types of personal dataWhatever the controller places in its tenant. Commonly names, contact details, employment data, financial data; may include special category data where the controller’s use case involves it
Categories of data subjectDetermined by the controller — typically employees, customers, suppliers, patients, students or clients
Special category dataPermitted. The controller must have its own Article 9 condition and identify the use case to us in advance, so that encryption, access review and retention settings are configured for it. For health data under HIPAA we execute a business associate agreement before any protected health information is uploaded

Our obligations as processor

The Article 28 commitments, stated as obligations rather than as descriptions.
  • Process personal data only on your documented instructions, including on international transfers
  • Ensure personnel authorised to process are bound by confidentiality
  • Implement the technical and organisational measures described in the trust centre, appropriate to the risk
  • Engage sub-processors only under written terms no less protective, with prior notice of changes and a right to object
  • Assist you in responding to data subject requests, taking into account the nature of the processing
  • Assist with data protection impact assessments and prior consultation, on request
  • Notify you without undue delay and in any event within 48 hours of becoming aware of a personal data breach
  • Delete or return personal data at the end of the service, at your election
  • Make available the information necessary to demonstrate compliance. You may audit once in any 12-month period on 30 days’ written notice, during business hours, under NDA and at your cost, or more often where a supervisory authority requires it or following a breach. A completed security questionnaire, our penetration test summary and the control documentation in the trust centre satisfy most audits without an on-site visit, and we would rather send those than schedule one

Sub-processors and transfers

Our current sub-processors are published on the sub-processors page, which this addendum incorporates by reference. We give 30 days’ notice before a new sub-processor starts processing, by email to your named administrators and by updating that page. You may object within those 30 days on reasonable data protection grounds; if we cannot resolve the objection, you may terminate the affected part of the service without penalty and receive a pro-rata refund.

Transfers out of the UK or EEA rely on the Standard Contractual Clauses (Decision 2021/914, modules two and three) for EEA data and the UK International Data Transfer Addendum for UK data, each supported by a transfer risk assessment. Where the Enterprise tier is used with your own S3 bucket or Azure container, document bytes remain in the region you nominate, which materially narrows the transfer question. Metadata, the search index and audit records are still processed in our platform region, and that exception is stated here rather than left implied — it is the detail a thorough review will find on its own.