Data Processing Agreement
Effective 1 October 2026
1. Scope and how this DPA applies
1.1 This Data Processing Agreement (the “DPA”) is between you and [LEGAL_ENTITY], business ID [BUSINESS_ID], [ADDRESS] (“Doquill”, “we”, “us”). It forms part of our Terms of Service (the “Terms”) and applies automatically whenever you use the Service. You do not need to sign anything.
1.2 “Your Content” means your templates, sample data, uploaded assets, the data you send in render requests, and the documents the Service generates from them, as defined in section 4.1 of the Terms. This DPA applies to personal data contained in Your Content that we process on your behalf when providing the Service (“Customer Personal Data”). Personal data we process for our own purposes, such as your account, billing and support data, is covered by our Privacy Policy instead.
1.3 For Customer Personal Data you are the controller and we are your processor. If you are yourself processing the data on behalf of another controller, such as your own customer, we are your sub-processor, and you confirm that your controller has authorised you to engage us on the terms of this DPA.
1.4 Terms such as “personal data”, “processing”, “controller”, “processor”, “data subject”, “personal data breach” and “supervisory authority” have the meaning given in the General Data Protection Regulation (EU) 2016/679 (the “GDPR”). “Data Protection Law” means the GDPR and any other data protection law of the European Union or its member states that applies to the processing. Capitalised terms not defined here have the meaning given in the Terms.
1.5 The details of the processing, including its subject matter, nature, purpose, duration and the types of personal data and data subjects involved, are set out in Annex I.
2. Processing on your instructions
2.1 We process Customer Personal Data only on your documented instructions. The Terms, this DPA and the way you use and configure the Service, through the web application or the API, are your complete instructions. Additional instructions need our written agreement.
2.2 We will tell you if, in our opinion, an instruction infringes Data Protection Law. We are not obliged to carry out an instruction we reasonably consider unlawful.
2.3 If European Union or member state law requires us to process Customer Personal Data other than on your instructions, we will tell you before doing so, unless that law prohibits it on important grounds of public interest.
2.4 We do not use Customer Personal Data for our own purposes, do not sell it, and do not use it to train machine-learning models.
3. Your responsibilities
3.1 You decide what personal data goes into the Service and why. You are responsible for having a lawful basis for the processing, for giving data subjects any notices required, and for the accuracy of the data.
3.2 The Service is built to generate business documents and is not designed for special categories of personal data under Article 9 of the GDPR or data relating to criminal convictions under Article 10. If you submit such data, you are responsible for ensuring that doing so is lawful and that the measures in Annex II are appropriate for it.
4. Confidentiality
4.1 We give access to Customer Personal Data only to personnel who need it to operate, secure or support the Service. Everyone with access is bound by a contractual or statutory duty of confidentiality.
5. Security
5.1 We implement the technical and organisational measures described in Annex II to protect Customer Personal Data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure or access.
5.2 We may update these measures as technology and threats change, provided the overall level of protection is not reduced.
6. Sub-processors
6.1 You give us general authorisation to engage sub-processors to process Customer Personal Data. The sub-processors we currently use are listed on our sub-processors page.
6.2 We will tell you about any new sub-processor at least 30 days before it starts processing Customer Personal Data, by email to the owners of your workspace. The sub-processors page will also show the upcoming change.
6.3 You may object to a new sub-processor on reasonable grounds relating to data protection by writing to privacy@doquill.com before the notice period ends. We will discuss your concerns in good faith. If we cannot resolve them, you may terminate the affected part of the Service by written notice before the change takes effect. Fees already paid are not refunded.
6.4 We impose on each sub-processor, by written contract, data protection obligations that offer at least the same level of protection as this DPA. We remain responsible to you for the performance of our sub-processors’ obligations.
7. Where data is processed
7.1 We store Customer Personal Data in Helsinki, Finland, within the European Economic Area.
7.2 Requests to the web application and the API pass through the content delivery network of BunnyWay d.o.o., which terminates encrypted connections at the edge location nearest to the sender, and which may be outside the European Economic Area. API traffic is passed through to our servers and is not cached.
7.3 We transfer Customer Personal Data outside the European Economic Area only where the transfer complies with Chapter V of the GDPR, for example under an adequacy decision of the European Commission or the standard contractual clauses adopted by the Commission, together with any supplementary measures needed.
7.4 Sending a generated document, a webhook or other output to an endpoint you configure is a transfer made on your instructions. You are responsible for that destination.
8. Assistance
8.1 Taking into account the nature of the processing, we will assist you with appropriate technical and organisational measures in responding to requests from data subjects exercising their rights under Chapter III of the GDPR. Most such requests can be handled directly in the Service, because you control your templates, assets and stored documents and can view, change and delete them yourself. Templates, and assets used by a published template version, are hidden when you delete them but kept until your workspace is deleted. If you need one removed permanently sooner, for example to fulfil an erasure request, ask us at privacy@doquill.com and we will remove it within 30 days.
8.2 If a data subject contacts us directly about Customer Personal Data, we will not respond to the substance of the request ourselves. We will refer them to you, and tell you without undue delay if we can identify you.
8.3 We will provide reasonable information and assistance to help you meet your obligations under Articles 32 to 36 of the GDPR, including data protection impact assessments and prior consultations with a supervisory authority, to the extent you cannot meet them with information already available to you.
8.4 Assistance is free of charge unless requests are manifestly unfounded or excessive, in which case we may charge a reasonable fee based on our costs, agreed with you in advance.
9. Personal data breaches
9.1 We will notify you without undue delay, and in any event within 48 hours, after becoming aware of a personal data breach affecting Customer Personal Data. We send notifications to the email addresses of your workspace owners.
9.2 Our notification will describe, as far as the information is available at the time, the nature of the breach, the categories and approximate number of data subjects and records concerned, the likely consequences, the measures we have taken or propose to take, and a contact for more information. Where we cannot provide everything at once, we will provide it in phases without undue further delay.
9.3 We will take reasonable steps to contain the breach, mitigate its effects and prevent it from recurring, and we will cooperate with you as reasonably needed for you to meet your own notification obligations.
9.4 Notifying you of a breach is not an acknowledgement of fault or liability.
10. Deletion and return
10.1 You can export and delete Customer Personal Data in the Service at any time, through the web application or the API. We do not provide a separate return service, so export what you need before your workspace is deleted. Data you change or delete in our databases remains in database backups for up to 31 days.
10.2 When your workspace is deleted, whether at your request or on termination of the Terms, we delete Customer Personal Data from our active systems within 30 days. Database backups are kept for up to 31 days, so copies in backups are gone no later than 31 days after that. Until then they are not restored into active use except to recover from an incident.
10.3 We may keep Customer Personal Data where European Union or member state law requires us to, in which case this DPA continues to apply to it for as long as we keep it.
11. Audits and information
11.1 On request, we will make available to you the information reasonably necessary to demonstrate our compliance with Article 28 of the GDPR and this DPA. This includes answering a reasonable written security questionnaire no more than once in any 12-month period, unless a supervisory authority requires otherwise or a personal data breach has occurred.
11.2 If the information we provide is not enough to demonstrate compliance, or a supervisory authority requires it, you may carry out an audit, including an inspection, yourself or through an independent auditor bound by confidentiality who is not our competitor. You must give us at least 30 days’ written notice, agree the scope with us in advance, and conduct the audit during business hours without unreasonably disrupting our operations or compromising the security or confidentiality of other customers’ data. You bear the costs of the audit.
11.3 Information we provide under this section is our confidential information and may be used only to assess our compliance with this DPA.
12. Liability, precedence and term
12.1 Each party’s liability under or in connection with this DPA is subject to the limitations and exclusions of liability in the Terms, including those that apply to the Free plan. This does not limit either party’s liability to data subjects under Article 82 of the GDPR.
12.2 If this DPA conflicts with the Terms, this DPA prevails for the processing of Customer Personal Data. Where standard contractual clauses apply to a transfer, they prevail over this DPA for that transfer.
12.3 This DPA remains in force for as long as we process Customer Personal Data, and ends automatically when that processing ends. Obligations that by their nature should continue, such as confidentiality and deletion, survive.
12.4 We may update this DPA in the same way as the Terms, as described in section 11.3 of the Terms. We will not make changes that reduce the protection of Customer Personal Data below what Data Protection Law requires.
12.5 This DPA is governed by the same law, and disputes under it are settled in the same court, as the Terms.
Annex I: Details of processing
Subject matter. Processing of personal data contained in Your Content in order to provide the Service.
Nature and purpose. Hosting and storage of templates, sample data and assets; rendering templates with data supplied in requests into PDF, DOCX, PNG, JPEG or HTML documents; storing documents produced by render jobs; delivering results and notifications to endpoints you configure; and the backup, security, troubleshooting and support activities needed to operate the Service.
Duration. For as long as you use the Service, and afterwards until deletion under section 10.
Categories of data subjects. Determined by you. Typically your customers, prospects, employees, contractors, suppliers and other business contacts, and individuals who appear in the documents you generate.
Categories of personal data. Determined by you. Typically identification and contact details such as names, addresses, email addresses and phone numbers; business details such as job titles and company affiliations; transaction details such as order, invoice and payment information; and any other content you place in templates, sample data, assets or render requests.
Special categories of data. None intended. See section 3.2.
Retention.
- Data in a synchronous render request, and the document generated from it, are not stored.
- Data in a render job request is deleted when the job finishes. The job’s status, including any error message, is kept for 30 days.
- Documents produced by render jobs, uploaded assets, templates and sample data are kept until you delete them or your workspace is deleted. Deleted templates, and deleted assets still used by a published template version, are hidden immediately and removed when your workspace is deleted, or sooner on request under section 8.1.
- Render logs record which workspace, API key, template and template version were involved, and any error message. They do not contain template content or request data.
Annex II: Technical and organisational measures
Encryption. All traffic to the Service and between its components is encrypted with TLS. Databases are stored on encrypted disk volumes, and object storage, including backups, is encrypted at rest with AES-256.
Network isolation. The Service runs on a private network in which per-service network policies allow only the connections each component needs.
Renderer isolation. Document renderers run without access to the public internet, to our internal systems or to other workspaces’ data. Each render receives only the template, assets and data of the workspace that requested it.
Workspace separation. Every request is authorised against a single workspace, and access to templates, assets, documents and keys is checked against that workspace’s permissions.
Authentication. Users sign in with one-time codes sent by email, passkeys, a third-party identity provider or their workspace’s single sign-on. We store no user passwords. API keys are stored only as hashes and can be revoked at any time.
Access control. Access to production systems is limited to the personnel who operate the Service, uses individual credentials, and follows the principle of least privilege. Actions taken through our administrative tools are recorded in an audit log.
Logging and monitoring. We collect logs, metrics and traces for security and reliability, and alert on abnormal conditions. Template content and request data are not written to logs. Logs are kept for 30 days and traces for 14 days.
Backups and recovery. Databases are backed up daily, with continuous archiving of changes in between, to object storage in Finland. Backups are kept for up to 31 days. We maintain documented recovery procedures.
Secure development. Changes are version-controlled and tested before deployment. Dependencies are pinned and updated regularly.
Incident response. We maintain a process for detecting, investigating, containing and notifying personal data breaches in line with section 9.
Sub-processor diligence. We assess the security and data protection practices of each sub-processor before engaging it, and bind it by written contract as required by section 6.4.
Annex III: Sub-processors
The current list of sub-processors, with what they do and where they process data, is kept on our sub-processors page.