DocMaster Data Processing Agreement
Last updated: 24 September 2026
This Data Processing Agreement (“DPA“) forms part of the DocMaster Terms of Service (“Terms“) between SIA DocMaster, registration No. 40203699978, Ceriņu iela 5, Lielvārde, LV-5070, Latvia (“DocMaster“, the processor) and the Customer (the controller). It applies whenever DocMaster processes personal data contained in Customer Data on the Customer’s behalf, and it meets the requirements of Article 28 of the General Data Protection Regulation (EU) 2016/679 (“GDPR“).
Terms not defined here have the meaning given in the Terms or in the GDPR.
1. Roles and scope
1.1 For personal data in Customer Data, the Customer is the controller and DocMaster is the processor.
1.2 This DPA does not cover personal data for which DocMaster is itself the controller (for example user accounts, billing contacts and support correspondence). That processing is described in our Privacy Policy.
1.3 The details of the processing (subject matter, duration, nature, purpose, types of data and categories of data subjects) are set out in Annex I.
2. Instructions
2.1 DocMaster processes personal data only on the Customer’s documented instructions. The Terms, this DPA and the Customer’s use and configuration of the Service are the Customer’s instructions.
2.2 DocMaster will tell the Customer if, in its opinion, an instruction breaches data protection law. If DocMaster is required by law to process personal data otherwise, it will inform the Customer first, unless the law prohibits this.
3. Confidentiality
DocMaster ensures that everyone it authorises to process personal data is bound by confidentiality, and that access is limited to those who need it to provide, secure or support the Service.
4. Security
DocMaster implements the technical and organisational measures described in Annex II. DocMaster may update these measures as long as the overall level of protection is not reduced.
5. Subprocessors
5.1 General authorisation. The Customer authorises DocMaster to engage subprocessors. The current subprocessors are listed at docmaster.ai/legal/subprocessors.
5.2 Changes. DocMaster will notify the Customer’s administrators by email at least 30 days before adding or replacing a subprocessor. Where a subprocessor must be replaced urgently (for security reasons or because a provider fails), DocMaster will notify as soon as possible.
5.3 Objection. The Customer may object to a change on reasonable data protection grounds within the notice period, by writing to support@docmaster.ai. The parties will discuss the objection in good faith. If it cannot be resolved, the Customer may cancel the affected subscription before the change takes effect, and DocMaster will refund any prepaid fees for the period after cancellation.
5.4 Flow-down. DocMaster imposes data protection obligations on each subprocessor that are no less protective than those in this DPA, and remains responsible to the Customer for its subprocessors’ performance.
6. International transfers
Customer Data is stored and processed in the European Economic Area. Where a subprocessor processes personal data outside the EEA, DocMaster ensures an appropriate safeguard under Chapter V GDPR, such as an adequacy decision (including the EU–US Data Privacy Framework) or the European Commission’s Standard Contractual Clauses. The location and safeguard for each subprocessor are shown on the subprocessors page.
7. Assistance
7.1 Data subject requests. DocMaster will promptly forward any request it receives from a data subject about Customer Data to the Customer, and will help the Customer respond to such requests, taking into account the nature of the processing.
7.2 Other assistance. DocMaster will provide reasonable help with the Customer’s obligations regarding security, personal data breach notification, data protection impact assessments and prior consultation with a supervisory authority, taking into account the nature of the processing and the information available to DocMaster.
8. Personal data breaches
8.1 DocMaster will notify the Customer without undue delay, and no later than 48 hours after becoming aware of a personal data breach affecting Customer Data.
8.2 The notification is sent to the Customer’s administrators by email. It describes, as far as then known, the nature of the breach, the categories and approximate number of data subjects and records concerned, the likely consequences, and the measures taken or proposed. Where not all information is available at once, DocMaster provides it in stages.
8.3 DocMaster will take reasonable steps to contain the breach and limit its consequences.
9. Deletion and return
9.1 During the subscription, the Customer can ask DocMaster to delete specific Customer Data, or all of it, by writing to support@docmaster.ai. DocMaster carries out such requests within 30 days.
9.2 Before the subscription ends, the Customer can retrieve Output through the Service. DocMaster deletes all Customer Data within 90 days after the subscription ends, unless the Customer asks for earlier deletion or the law requires DocMaster to keep it.
9.3 Copies in backups are removed as the backups rotate, and are not restored except to recover the Service.
10. Audits
10.1 DocMaster will make available the information reasonably necessary to demonstrate compliance with Article 28 GDPR, including answers to the Customer’s reasonable written security questions.
10.2 Where that information is not sufficient, or a supervisory authority requires it, the Customer may carry out an audit, itself or through an independent auditor bound by confidentiality, with at least 30 days’ notice, during business hours and not more than once a year (except after a personal data breach or at the request of a supervisory authority). Each party bears its own costs.
11. Liability and term
11.1 Liability under this DPA is subject to the limitations in the Terms.
11.2 This DPA applies for as long as DocMaster processes personal data in Customer Data.
11.3 If this DPA and the Terms conflict, this DPA prevails in matters of personal data protection.
Annex I: Details of the processing
| Subject matter | Providing the DocMaster Service: processing the documents the Customer uploads and producing Output from them. |
| Duration | The term of the subscription, plus the deletion period in section 9. |
| Nature and purpose | Storage of uploaded documents; conversion and preparation of documents for reading; automated extraction and analysis by AI models (for example reading invoice data or reviewing financial statements); storing and displaying Output to the Customer’s Users; security, troubleshooting and support. |
| Types of personal data | Whatever personal data the Customer’s documents contain. Typically: names of individuals (such as contact persons, signatories, sole traders), business contact details (addresses, email addresses, phone numbers), identification and registration numbers, bank account details, and transaction details (amounts, dates, items). File names, and job names (given by the Customer’s Users or derived by the Service from the documents). |
| Special categories | None intended. The Customer should not upload documents containing special categories of personal data (Article 9 GDPR) or data about criminal convictions unless this is necessary and lawful. |
| Data subjects | Individuals named in the Customer’s documents: the Customer’s suppliers, customers, employees and other business contacts. |
| Frequency | Continuous, whenever the Customer’s Users submit documents. |
Annex II: Technical and organisational measures
Hosting and location
- Application servers and databases in Microsoft Azure, Sweden Central (EU). Document storage in Google Cloud, europe-west4 (Netherlands, EU). AI processing through Google Vertex AI with EU data residency.
Encryption
- All connections to the Service use HTTPS/TLS.
- Stored data (databases, document storage, backups) is encrypted at rest by the cloud providers.
Access control
- Stored documents and results can be opened only by the Service’s own service identities; no DocMaster staff member has standing access to them. A DocMaster administrator, signed in with their own personal account and working from the EU, opens a Customer’s documents only when the Customer asks for help with them or to deal with a security incident, through a temporary access grant that is removed afterwards. The grant is recorded in the cloud provider’s audit log.
- The Service authenticates to Google Cloud without long-lived keys (workload identity federation).
- Access to the document store is restricted by a network perimeter (Google VPC Service Controls) to the Service’s servers and named administrator addresses.
- Databases are reachable only from the Service’s private network.
- Administrative access to cloud accounts requires multi-factor authentication.
- Customer Data is kept separate per Organisation: it is stored under the Organisation’s own path, and every read is checked against the requesting user’s Organisation.
Logging and monitoring
- Every read and write of stored documents and results, by the Service or by a person, is recorded in an audit log kept for 400 days. On request, we give the Customer the entries for its own documents.
- Application and server logs record identifiers and error codes, not document contents or file names, and are kept for 30 days.
- Automated alerts notify DocMaster of errors and unusual conditions.
AI processing
- Documents are sent to the AI model for the processing request only. Data caching on the AI provider’s side is switched off. Google may retain prompts for a limited period for abuse monitoring under its terms of service.
- Customer Data is not used to train AI models.
Resilience
- Databases are backed up automatically, and backups are kept for 7 days. Deleted documents can be recovered for 7 days, after which they are permanently removed.
Organisational
- Everyone at DocMaster with access to Customer Data is bound by confidentiality.
- Access is reviewed when roles change and removed when no longer needed.
- Personal data breaches are handled under an internal procedure that includes the notification in section 8.