Data Processing Agreement draft
Controller-processor terms for customer personal data handled through the DocKosha Cloud service.
DRAFT — pending legal review. Contact support@dockosha.com to execute a signed copy.
Last updated: July 29, 2026
This Data Processing Agreement ("DPA") forms part of the agreement governing the Customer's use of DocKosha Cloud (the "Main Agreement") once signed by the parties. If this DPA conflicts with the Main Agreement on the processing of Customer Personal Data, this DPA controls to the extent of that conflict.
1. Definitions
Applicable Data Protection Law means the privacy and data-protection law that applies to the processing covered by this DPA.
Customer Personal Data means personal data submitted to or collected through the service on the Customer's behalf.
Controller, Processor, Data Subject, Personal Data, Processing, and Subprocessor have the meanings given by Applicable Data Protection Law.
Security Incident means a confirmed breach of security leading to accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to Customer Personal Data.
2. Roles and instructions
The Customer is the Controller of Customer Personal Data, and DocKosha is the Processor, except where Applicable Data Protection Law assigns different roles. Each party will comply with the obligations applicable to its role.
DocKosha will process Customer Personal Data only on documented instructions from the Customer, including the Main Agreement, this DPA, the Customer's use and configuration of the service, and other written instructions agreed by the parties. If an instruction violates Applicable Data Protection Law, DocKosha will inform the Customer unless prohibited by law.
3. Processing details
Subject matter and duration. Processing necessary to provide, secure, support, and improve DocKosha Cloud for the term of the Main Agreement and any limited period required to delete or return data afterward.
Nature and purpose. Hosting, organizing, converting, displaying, sharing, securing, analyzing engagement with, and supporting documents and data rooms as configured by the Customer.
Data subjects. Customer personnel, workspace members, invited collaborators, public-link viewers, signatories or NDA acceptors, and people whose personal data appears in Customer content.
Data categories. Account identifiers, contact details, workspace and sharing metadata, uploaded document content, generated PDFs, viewer email addresses where collection is enabled, access and activity records, support communications, and billing or subscription metadata.
The Customer will not submit special-category or highly regulated personal data unless its use is lawful and compatible with the Main Agreement and configured safeguards.
4. Processor obligations
DocKosha will ensure that people authorized to process Customer Personal Data are bound by confidentiality obligations and access the data only as needed for their duties.
DocKosha will maintain technical and organizational measures appropriate to the risk. The implemented control baseline is described on the security page, including Supabase-managed TLS in transit and AES-256 at rest, row-level security, access controls, audit logging, gated sharing, and server-side watermarking.
Taking into account the nature of the processing, DocKosha will provide reasonable assistance with Data Subject requests, security assessments, breach obligations, and data-protection impact assessments where the requested information is not otherwise available to the Customer.
5. Subprocessors
The Customer provides general authorization for DocKosha to appoint Subprocessors needed to operate the service. The live Subprocessor list is Annex II to this DPA and identifies each provider's purpose, data category, and verified region when available.
DocKosha will impose data-protection obligations on each Subprocessor that are appropriate to the services it performs. DocKosha remains responsible for its Subprocessors' performance to the extent required by Applicable Data Protection Law.
If DocKosha materially changes the Subprocessor list, the Customer may raise a reasonable data-protection objection by contacting support. The parties will work in good faith to resolve the concern.
6. Security incidents
DocKosha will notify the Customer without undue delay after becoming aware of a Security Incident affecting Customer Personal Data. Notification will include available information reasonably needed for the Customer's legal obligations, such as the nature of the incident, likely consequences, affected data, and mitigation measures.
DocKosha will take reasonable steps to contain, investigate, and mitigate the Security Incident. Notification is not an admission of fault or liability.
7. Deletion or return
At the end of the services, and at the Customer's choice where technically available, DocKosha will delete or return Customer Personal Data unless retention is required by law. Data retained in managed backups will remain protected and be deleted through the provider's normal backup lifecycle.
Privacy and account-deletion requests may also be submitted through /data-request.
8. Audit and compliance information
On reasonable written request, DocKosha will provide information necessary to demonstrate compliance with this DPA. If that information is insufficient, the Customer may request an audit no more than once per year, unless a Security Incident or regulator requires otherwise.
Audits must be scoped to relevant systems, protect other customers and confidential information, avoid unreasonable disruption, and use an independent auditor bound by confidentiality. The parties will agree reasonable timing, access, and cost allocation before the audit begins.
9. International transfers
Where Customer Personal Data is transferred from the European Economic Area, United Kingdom, or Switzerland to a country that does not provide an adequate level of protection, the parties will use the applicable Standard Contractual Clauses or another lawful transfer mechanism. Any required UK Addendum or Swiss adaptations will apply.
The parties will cooperate on transfer assessments and supplementary measures reasonably required by Applicable Data Protection Law. Provider regions remain subject to verification on the live Subprocessor list.
10. Liability and precedence
Each party's liability arising from this DPA is subject to the exclusions and limitations in the Main Agreement, except where Applicable Data Protection Law does not permit that limitation. The current public Terms and Conditions are provided for reference; an executed Main Agreement controls where one exists.