Compliance
GDPR document management obligations
Under the GDPR, DocumentMS is a processor acting on your documented instructions as controller. That means a signed data processing addendum, transparency about sub-processors and transfer mechanisms, support for subject access and erasure requests, and retention rules you configure rather than we impose.
Our role: processor, not controller
For the documents you place in DocumentMS, you are the controller and we are the processor. You decide what is stored, why, and for how long; we process it on your documented instructions and for no other purpose. That distinction determines who is responsible for what, and it is the first thing a data protection officer will want confirmed.
There is a second relationship that people conflate with the first. For website visitors, demo requesters, trial users and job applicants, DocumentMS is a controller in its own right — and that is governed by our privacy notice rather than by the data processing addendum. Keeping the two separate avoids the common confusion where a customer asks us to exercise a data subject right over their own tenant, which we cannot lawfully do without their instruction.
Who does what
| Obligation | Controller (you) | Processor (DocumentMS) |
|---|---|---|
| Establishing a lawful basis | Determines the lawful basis for holding each category of document | Not applicable — we do not determine purposes |
| Responding to a subject access request | Receives, assesses and responds to the request | Provides the search and export tooling to locate and produce the material |
| Erasure requests | Decides whether erasure applies or a retention obligation prevails | Surfaces the retention rule and any legal hold at the point of deletion, and records the decision |
| Retention periods | Sets the schedule and the trigger events | Enforces the configured rules and raises disposition reviews |
| Security of processing (Article 32) | Assesses whether our measures are appropriate to the risk | Implements and evidences the technical and organisational measures described in the trust centre |
| Breach notification | Notifies the supervisory authority and data subjects where required | Notifies you without undue delay, per the data processing addendum |
| Sub-processor engagement | Objects to a proposed sub-processor if it wishes | Publishes the list, gives notice of changes and remains liable for their performance |
Where erasure and retention collide
A right to erasure is not absolute, and in a document system the conflict is common rather than exceptional. An employment record, a financial record or a clinical record held under a statutory retention obligation generally cannot be deleted on request, and a system that deletes on request without checking will put you in breach of one law while complying with another.
DocumentMS surfaces the retention rule and any active legal hold at the point a deletion is attempted, so the conflict is visible before a decision is made rather than discovered afterwards. The decision itself and the reasoning behind it are recorded in the audit trail — which is precisely the evidence you will need if the requester complains to a supervisory authority.
That is the whole of the product’s contribution here. The judgement about whether an obligation prevails is yours and needs a person; what a system can do is make sure the person has the relevant facts in front of them.
International transfers
- Document bytes sit in the storage backend you configure — on Enterprise, that can be your own S3 bucket or Azure container in a region you choose, which removes the transfer question for the documents themselves
- Every sub-processor is listed with its location and the transfer safeguard relied on, on the sub-processors page
- Transfers to recipients outside the UK or EEA rely on the Standard Contractual Clauses (Decision 2021/914) for EEA data and the UK International Data Transfer Addendum for UK data. The mechanism relied on for each recipient is named in the final column of the sub-processor list
- A transfer impact assessment is maintained for every recipient outside the UK or EEA and is available to customers on request under NDA
- Metadata, the search index and the audit trail are held in the platform region selected at provisioning — including where document bytes sit in your own S3 bucket or Azure container. This is the exception residency commitments most often hide, so it is stated here rather than discovered during a review
FAQ
GDPR questions
Will you sign our data processing addendum?
Our standard data processing addendum is published in full before contract, incorporates the Standard Contractual Clauses and the UK IDTA, and is offered for signature on every tier. On Enterprise we will work from your paper and negotiate the addendum; on Starter and Business the standard terms apply unchanged, which is what keeps those tiers self-serve. Publishing it before contract rather than after is deliberate: it is the document that most often stalls a procurement when it appears late.
How do we answer a subject access request?
Search across document contents and metadata to locate everything associated with the individual, including scanned correspondence, then apply the exemptions that fit. Because the audit trail records reads as well as changes, an accounting of who accessed the material is derived from the record rather than maintained separately.
Can we delete a document permanently?
Yes. Deletion moves a document to an administrator-only recycle bin; permanent deletion is a separate, logged action. That two-stage model exists precisely because erasure requests require genuine destruction while accidental deletion requires recovery, and one mechanism cannot serve both.
Do you use customer documents to train AI models?
No. Customer data is never used to train, fine-tune or evaluate models, and that is a term of the data processing addendum rather than only a statement on a page — under the GDPR, processing for a purpose you did not instruct would be processing outside the instruction, so the commitment needs contractual force to mean anything. AI features process your documents to return a result to you and retain nothing afterwards; the model provider is engaged under zero-retention terms and is named in the sub-processor list.
What happens to our data when we terminate?
Complete export with folder structure, metadata and version history, then deletion on the schedule set out in the data processing addendum: the tenant stays available for export for 90 days after termination, live data is deleted 30 days after that window closes, and backup copies age out within a further 35 days. The 90 days can be shortened on written request where you need deletion sooner, and we will confirm completion in writing.
Dernière revue: 2026-09-01