Version 2026-07-29. This is our standard Art. 28 GDPR processing addendum for Docracy account / paid use. It has not been individually negotiated. For a countersigned PDF, email sales@docracy.io. See also Trust and Privacy.
Processor: RELACON GmbH, Elisabethstraße 15/5b, 1010 Vienna, Austria ("Docracy", "we", "us").
Controller: the customer entity that creates a Docracy account or paid workspace and determines the purposes of processing personal data uploaded to or collected through that workspace ("Customer", "you").
Anonymous, no-account signing chains where Docracy alone decides means of processing are described in Privacy; this DPA applies when you use account, team, template, connector, or paid features as Controller.
We process personal data on your behalf to provide the Docracy e-signature and related workspace services for the term of your account, and until data is deleted per retention rules or your deletion request.
Hosting PDFs and form field data; sending signing invitations and reminders; recording audit-trail events; storing workspace metadata (contacts, templates, team members); optional cloud upload when you connect a connector; billing via Stripe for paid plans.
Do not upload special-category data or PHI unless we have expressly agreed in writing (we currently do not offer HIPAA).
You authorize us to engage the subprocessors listed on Trust & security. We will post material changes to that list and give reasonable notice for objection where feasible. Cloud connectors you enable are engaged at your instruction.
Where personal data is transferred outside the EEA/UK/Switzerland, we rely on appropriate safeguards (e.g. EU Standard Contractual Clauses with subprocessors, or adequacy decisions) as offered by those providers. Details of hosting are summarized on the Trust page.
We will notify you without undue delay after becoming aware of a personal-data breach affecting your workspace data, and provide information reasonably available to help you meet your own notification duties.
You may request information and evidence of our security measures (including this Trust page and, when available, third-party reports). On-site audits are by mutual agreement, limited to once per year unless a material incident warrants more, and at your expense unless we are in material breach.
Liability under this DPA follows the limitations in our Terms, except where mandatory data-protection law says otherwise. If this DPA conflicts with the Terms on data-protection matters, this DPA controls.
Privacy / DPA: founder@docracy.io · Countersignature requests: sales@docracy.io