Data Processing Agreement
Last updated: Draft (pending review)
This Data Processing Agreement (DPA) forms part of the Terms of Service and governs doxio's processing of personal data on your behalf under the GDPR.
1. Roles of the parties
For document content and recipient data you upload, your organization is the controller and doxio is the processor acting on your documented instructions.
2. Scope and instructions
doxio processes personal data only to provide the service and as instructed through the product, and will not use it for any other purpose.
3. Sub-processors
You authorize the sub-processors listed on our Sub-processors page. We impose data-protection obligations on each and remain responsible for their performance.
4. Security measures
doxio implements technical and organizational measures including tenant isolation, hashed secrets, gated file access, an append-only audit log, and least-privilege access.
5. Data subject rights and deletion
doxio assists you in responding to data-subject requests and, on termination, deletes or returns personal data following the schedule in our Privacy Policy: a 30-day grace period, then erasure of document files and account data, then retention of signing evidence (the signer's name, e-mail address, IP address and browser identifier, and the share recipient's name and e-mail address) together with the tamper-evident audit log for 7 years, after which it is permanently erased.