Zum Hauptinhalt springen
DocumentMS

Compliance

GDPR document management obligations

Under the GDPR, DocumentMS is a processor acting on your documented instructions as controller. That means a signed data processing addendum, transparency about sub-processors and transfer mechanisms, support for subject access and erasure requests, and retention rules you configure rather than we impose.

Our role: processor, not controller

For the documents you place in DocumentMS, you are the controller and we are the processor. You decide what is stored, why, and for how long; we process it on your documented instructions and for no other purpose. That distinction determines who is responsible for what, and it is the first thing a data protection officer will want confirmed.

There is a second relationship that people conflate with the first. For website visitors, demo requesters, trial users and job applicants, DocumentMS is a controller in its own right — and that is governed by our privacy notice rather than by the data processing addendum. Keeping the two separate avoids the common confusion where a customer asks us to exercise a data subject right over their own tenant, which we cannot lawfully do without their instruction.

Who does what

The allocation of responsibility under the GDPR, stated so there is no ambiguity when a request arrives.
Controller and processor responsibilities
ObligationController (you)Processor (DocumentMS)
Establishing a lawful basisDetermines the lawful basis for holding each category of documentNot applicable — we do not determine purposes
Responding to a subject access requestReceives, assesses and responds to the requestProvides the search and export tooling to locate and produce the material
Erasure requestsDecides whether erasure applies or a retention obligation prevailsSurfaces the retention rule and any legal hold at the point of deletion, and records the decision
Retention periodsSets the schedule and the trigger eventsEnforces the configured rules and raises disposition reviews
Security of processing (Article 32)Assesses whether our measures are appropriate to the riskImplements and evidences the technical and organisational measures described in the trust centre
Breach notificationNotifies the supervisory authority and data subjects where requiredNotifies you without undue delay, per the data processing addendum
Sub-processor engagementObjects to a proposed sub-processor if it wishesPublishes the list, gives notice of changes and remains liable for their performance

Where erasure and retention collide

A right to erasure is not absolute, and in a document system the conflict is common rather than exceptional. An employment record, a financial record or a clinical record held under a statutory retention obligation generally cannot be deleted on request, and a system that deletes on request without checking will put you in breach of one law while complying with another.

DocumentMS surfaces the retention rule and any active legal hold at the point a deletion is attempted, so the conflict is visible before a decision is made rather than discovered afterwards. The decision itself and the reasoning behind it are recorded in the audit trail — which is precisely the evidence you will need if the requester complains to a supervisory authority.

That is the whole of the product’s contribution here. The judgement about whether an obligation prevails is yours and needs a person; what a system can do is make sure the person has the relevant facts in front of them.

International transfers

Where data leaves the UK or EEA, and on what basis.
  • Document bytes sit in the storage backend you configure — on Enterprise, that can be your own S3 bucket or Azure container in a region you choose, which removes the transfer question for the documents themselves
  • Every sub-processor is listed with its location and the transfer safeguard relied on, on the sub-processors page
  • Transfers to recipients outside the UK or EEA rely on the Standard Contractual Clauses (Decision 2021/914) for EEA data and the UK International Data Transfer Addendum for UK data. The mechanism relied on for each recipient is named in the final column of the sub-processor list
  • A transfer impact assessment is maintained for every recipient outside the UK or EEA and is available to customers on request under NDA
  • Metadata, the search index and the audit trail are held in the platform region selected at provisioning — including where document bytes sit in your own S3 bucket or Azure container. This is the exception residency commitments most often hide, so it is stated here rather than discovered during a review

FAQ

GDPR questions

Will you sign our data processing addendum?

Our standard data processing addendum is published in full before contract, incorporates the Standard Contractual Clauses and the UK IDTA, and is offered for signature on every tier. On Enterprise we will work from your paper and negotiate the addendum; on Starter and Business the standard terms apply unchanged, which is what keeps those tiers self-serve. Publishing it before contract rather than after is deliberate: it is the document that most often stalls a procurement when it appears late.

How do we answer a subject access request?

Search across document contents and metadata to locate everything associated with the individual, including scanned correspondence, then apply the exemptions that fit. Because the audit trail records reads as well as changes, an accounting of who accessed the material is derived from the record rather than maintained separately.

Can we delete a document permanently?

Yes. Deletion moves a document to an administrator-only recycle bin; permanent deletion is a separate, logged action. That two-stage model exists precisely because erasure requests require genuine destruction while accidental deletion requires recovery, and one mechanism cannot serve both.

Do you use customer documents to train AI models?

No. Customer data is never used to train, fine-tune or evaluate models, and that is a term of the data processing addendum rather than only a statement on a page — under the GDPR, processing for a purpose you did not instruct would be processing outside the instruction, so the commitment needs contractual force to mean anything. AI features process your documents to return a result to you and retain nothing afterwards; the model provider is engaged under zero-retention terms and is named in the sub-processor list.

What happens to our data when we terminate?

Complete export with folder structure, metadata and version history, then deletion on the schedule set out in the data processing addendum: the tenant stays available for export for 90 days after termination, live data is deleted 30 days after that window closes, and backup copies age out within a further 35 days. The 90 days can be shortened on written request where you need deletion sooner, and we will confirm completion in writing.

Send us the questions. Where an answer is still being finalised we will say so rather than writing something that reads well and fails on inspection.