Data Processing Agreement

Version 2026-07-29. This is our standard Art. 28 GDPR processing addendum for Docracy account / paid use. It has not been individually negotiated. For a countersigned PDF, email sales@docracy.io. See also Trust and Privacy.

1. Parties

Processor: RELACON GmbH, Elisabethstraße 15/5b, 1010 Vienna, Austria ("Docracy", "we", "us").

Controller: the customer entity that creates a Docracy account or paid workspace and determines the purposes of processing personal data uploaded to or collected through that workspace ("Customer", "you").

Anonymous, no-account signing chains where Docracy alone decides means of processing are described in Privacy; this DPA applies when you use account, team, template, connector, or paid features as Controller.

2. Subject matter & duration

We process personal data on your behalf to provide the Docracy e-signature and related workspace services for the term of your account, and until data is deleted per retention rules or your deletion request.

3. Nature & purpose of processing

Hosting PDFs and form field data; sending signing invitations and reminders; recording audit-trail events; storing workspace metadata (contacts, templates, team members); optional cloud upload when you connect a connector; billing via Stripe for paid plans.

4. Types of personal data & data subjects

Do not upload special-category data or PHI unless we have expressly agreed in writing (we currently do not offer HIPAA).

5. Processor obligations

6. Subprocessors

You authorize us to engage the subprocessors listed on Trust & security. We will post material changes to that list and give reasonable notice for objection where feasible. Cloud connectors you enable are engaged at your instruction.

7. International transfers

Where personal data is transferred outside the EEA/UK/Switzerland, we rely on appropriate safeguards (e.g. EU Standard Contractual Clauses with subprocessors, or adequacy decisions) as offered by those providers. Details of hosting are summarized on the Trust page.

8. Security incidents

We will notify you without undue delay after becoming aware of a personal-data breach affecting your workspace data, and provide information reasonably available to help you meet your own notification duties.

9. Audits

You may request information and evidence of our security measures (including this Trust page and, when available, third-party reports). On-site audits are by mutual agreement, limited to once per year unless a material incident warrants more, and at your expense unless we are in material breach.

10. Liability & precedence

Liability under this DPA follows the limitations in our Terms, except where mandatory data-protection law says otherwise. If this DPA conflicts with the Terms on data-protection matters, this DPA controls.

11. Contact

Privacy / DPA: founder@docracy.io · Countersignature requests: sales@docracy.io