Data Processing Agreement

Last updated: Draft (pending review)

Draft template — not yet reviewed by legal counsel. Do not rely on this text until it is finalized.

This Data Processing Agreement (DPA) forms part of the Terms of Service and governs doxio's processing of personal data on your behalf under the GDPR.

1. Roles of the parties

For document content and recipient data you upload, your organization is the controller and doxio is the processor acting on your documented instructions.

2. Scope and instructions

doxio processes personal data only to provide the service and as instructed through the product, and will not use it for any other purpose.

3. Sub-processors

You authorize the sub-processors listed on our Sub-processors page. We impose data-protection obligations on each and remain responsible for their performance.

4. Security measures

doxio implements technical and organizational measures including tenant isolation, hashed secrets, gated file access, an append-only audit log, and least-privilege access.

5. Data subject rights and deletion

doxio assists you in responding to data-subject requests and, on termination, deletes or returns personal data following the schedule in our Privacy Policy: a 30-day grace period, then erasure of document files and account data, then retention of signing evidence (the signer's name, e-mail address, IP address and browser identifier, and the share recipient's name and e-mail address) together with the tamper-evident audit log for 7 years, after which it is permanently erased.