[{"data":1,"prerenderedAt":432},["ShallowReactive",2],{"legal-\u002Flegal\u002Fdpa":3},{"id":4,"title":5,"body":6,"description":422,"extension":423,"meta":424,"navigation":425,"order":426,"path":427,"seo":428,"stem":429,"updated":430,"__hash__":431},"legal\u002Flegal\u002Fdpa.md","Data Processing Agreement",{"type":7,"value":8,"toc":403},"minimark",[9,19,22,27,62,66,73,81,84,87,91,94,98,110,125,129,136,140,143,151,154,158,161,165,168,190,193,197,200,204,211,215,221,225,228,231,235,273,277,280,342,349,353],[10,11,12,13,18],"p",{},"This Data Processing Agreement (\"DPA\") is between VectorForge LLC (\"Docabra\", \"we\", \"us\") and the customer identified in the Docabra account (\"Customer\", \"you\"). It forms part of, and is incorporated into, the ",[14,15,17],"a",{"href":16},"\u002Flegal\u002Fterms","Terms of Service"," (together with this DPA, the \"Agreement\"). By accepting the Terms of Service, you enter into this DPA.",[10,20,21],{},"This DPA applies where Docabra processes personal data on your behalf as a processor — that is, personal data contained in the documents you upload and the tables extracted from them (\"Customer Personal Data\").",[23,24,26],"h2",{"id":25},"_1-definitions","1. Definitions",[28,29,30,38,44,50,56],"ul",{},[31,32,33,37],"li",{},[34,35,36],"strong",{},"\"Data Protection Laws\""," means all laws applicable to the processing of Customer Personal Data under the Agreement, including the EU and UK GDPR, the Swiss FADP, and US state privacy laws such as the CCPA\u002FCPRA.",[31,39,40,43],{},[34,41,42],{},"\"Personal data\", \"controller\", \"processor\", \"data subject\", \"processing\""," (and their cognates) have the meanings given in the GDPR.",[31,45,46,49],{},[34,47,48],{},"\"SCCs\""," means the European Commission's Standard Contractual Clauses for the transfer of personal data to third countries (Decision (EU) 2021\u002F914).",[31,51,52,55],{},[34,53,54],{},"\"Data Incident\""," means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to Customer Personal Data in our possession or control.",[31,57,58,61],{},[34,59,60],{},"\"Services\""," means the Docabra service described in the Terms of Service.",[23,63,65],{"id":64},"_2-roles-and-scope","2. Roles and scope",[10,67,68,69,72],{},"You are the controller of Customer Personal Data; Docabra is your processor. The subject matter, duration, nature and purpose of the processing, and the categories of data and data subjects, are described in ",[34,70,71],{},"Exhibit A",".",[10,74,75,76,80],{},"For data we process for our own purposes — your account data, billing records, and usage data — Docabra is an independent controller, and our ",[14,77,79],{"href":78},"\u002Flegal\u002Fprivacy","Privacy Policy"," (not this DPA) governs that processing.",[10,82,83],{},"We will process Customer Personal Data only on your documented instructions, which are: your use of the Services as described in the Agreement, plus any further written instructions you give that are consistent with the Agreement. We will tell you if we believe an instruction violates Data Protection Laws.",[10,85,86],{},"You are responsible for the lawfulness of the Customer Personal Data you upload, including having a valid legal basis and giving any notices required for us to process it on your behalf.",[23,88,90],{"id":89},"_3-confidentiality-and-personnel","3. Confidentiality and personnel",[10,92,93],{},"We restrict access to Customer Personal Data to personnel and contractors who need it to provide the Services, and we bind them to confidentiality obligations at least as protective as this DPA. We are responsible for their compliance.",[23,95,97],{"id":96},"_4-sub-processors","4. Sub-processors",[10,99,100,101,105,106,109],{},"You give us general written authorization to engage the sub-processors listed on our ",[14,102,104],{"href":103},"\u002Flegal\u002Fsubprocessors","subprocessors page"," (incorporated as ",[34,107,108],{},"Exhibit B","). We will:",[111,112,113,116,119,122],"ol",{},[31,114,115],{},"Update that page at least 30 days before adding or replacing a sub-processor, and notify subscribers as described there;",[31,117,118],{},"Give you 30 days to object in writing on reasonable data protection grounds — if we cannot resolve your objection, you may terminate the affected Services as your sole and exclusive remedy;",[31,120,121],{},"Impose on each sub-processor data protection obligations no less protective than this DPA; and",[31,123,124],{},"Remain fully liable to you for each sub-processor's performance.",[23,126,128],{"id":127},"_5-security","5. Security",[10,130,131,132,135],{},"We maintain the technical and organizational measures described in ",[34,133,134],{},"Exhibit C",", designed to protect Customer Personal Data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure, or access. We may update those measures over time, provided the overall level of protection does not decrease.",[23,137,139],{"id":138},"_6-data-subject-requests-and-assistance","6. Data subject requests and assistance",[10,141,142],{},"Taking into account the nature of the processing, we will assist you — at your cost where the request is disproportionate — in meeting your obligations under Data Protection Laws, including:",[28,144,145,148],{},[31,146,147],{},"Responding to data subject requests (access, correction, deletion, portability, objection). The Services let you delete documents and projects and export your tables directly, and we ask that you use those controls first; we will handle what they cannot.",[31,149,150],{},"Conducting data protection impact assessments and consulting regulators, where the Services' processing is concerned.",[10,152,153],{},"If a data subject or regulator contacts us directly about Customer Personal Data, we will promptly redirect them to you and, unless legally prohibited, notify you.",[23,155,157],{"id":156},"_7-data-incidents","7. Data Incidents",[10,159,160],{},"We will notify you without undue delay after becoming aware of a Data Incident, and will provide the information reasonably required for you to meet your own notification obligations. Our notice to you is not an acknowledgement of fault or liability.",[23,162,164],{"id":163},"_8-international-transfers","8. International transfers",[10,166,167],{},"Our processing occurs in the United States. For Customer Personal Data protected by the EU GDPR, the UK GDPR, or the Swiss FADP, the parties are deemed to have entered into:",[28,169,170,181,187],{},[31,171,172,173,176,177,180],{},"the ",[34,174,175],{},"SCCs, Module 2"," (controller to processor), and where you are yourself a processor, ",[34,178,179],{},"Module 3"," (processor to sub-processor), completed with the information in Exhibits A and B, with the optional docking clause included, governed by the law of Ireland, with disputes before the courts of Ireland;",[31,182,172,183,186],{},[34,184,185],{},"UK International Data Transfer Addendum"," to the SCCs, where the UK GDPR applies; and",[31,188,189],{},"equivalent protections under Swiss law, where the FADP applies.",[10,191,192],{},"Where required, we will provide supplementary measures for government access requests: we will challenge unlawful or disproportionate requests where permitted, notify you of any request unless prohibited, and disclose only the minimum data compelled.",[23,194,196],{"id":195},"_9-audits","9. Audits",[10,198,199],{},"We will make available the information reasonably necessary to demonstrate compliance with this DPA — security documentation and written responses to a reasonable security questionnaire, no more than once per rolling 12 months. If that is demonstrably insufficient (for example, following a Data Incident or a regulator's order), you may conduct an audit, at your expense, on 30 days' notice, during business hours, in a way that does not compromise other customers' data.",[23,201,203],{"id":202},"_10-us-state-privacy-laws","10. US state privacy laws",[10,205,206,207,210],{},"For Customer Personal Data subject to the CCPA\u002FCPRA and similar US state laws: we act as a ",[34,208,209],{},"service provider \u002F contractor",". We will not sell or share Customer Personal Data, will not retain, use, or disclose it for any purpose other than providing the Services, will not retain, use, or disclose it outside the direct business relationship between us, and will not combine it with personal data received from other sources except as those laws permit. We certify that we understand these restrictions and will comply with them.",[23,212,214],{"id":213},"_11-return-and-deletion","11. Return and deletion",[10,216,217,218,220],{},"On termination of the Agreement, or on your earlier written request, we will delete Customer Personal Data (or return it, at your request made before deletion) on the schedule in the ",[14,219,79],{"href":78}," — from active systems within 30 days — except where the law requires retention. On request, we will confirm deletion in writing.",[23,222,224],{"id":223},"_12-precedence-and-liability","12. Precedence and liability",[10,226,227],{},"If this DPA conflicts with the Terms of Service, this DPA controls for the processing of Customer Personal Data. If the SCCs conflict with this DPA or the Terms of Service, the SCCs control. Liability under this DPA is subject to the limitations of liability in the Terms of Service.",[229,230],"hr",{},[23,232,234],{"id":233},"exhibit-a-description-of-the-processing","Exhibit A — Description of the processing",[28,236,237,243,249,255,261,267],{},[31,238,239,242],{},[34,240,241],{},"Subject matter:"," Processing of Customer Personal Data to provide the Services.",[31,244,245,248],{},[34,246,247],{},"Duration:"," The term of the Agreement, plus the deletion windows in Section 11.",[31,250,251,254],{},[34,252,253],{},"Nature and purpose:"," Storage, hosting, and organization of documents uploaded by Customer; transmission of page images and text to our AI sub-processor for extraction; generation, display, editing, and export of structured tables; backup and security of the foregoing.",[31,256,257,260],{},[34,258,259],{},"Categories of data subjects:"," Determined by Customer — typically Customer's suppliers, customers, employees, candidates, and counterparties named in the uploaded documents.",[31,262,263,266],{},[34,264,265],{},"Categories of personal data:"," Determined by Customer — whatever the uploaded business documents contain (for example names, contact details, commercial terms, prices, dates). The Services are not intended for special categories of personal data (health, biometric, and similar data), and Customer should not upload them.",[31,268,269,272],{},[34,270,271],{},"Processing operations:"," Collection (upload), storage, organization, retrieval, transmission to sub-processors, disclosure by transmission, erasure.",[23,274,276],{"id":275},"exhibit-b-sub-processors","Exhibit B — Sub-processors",[10,278,279],{},"The sub-processors engaged as of the date of this DPA:",[281,282,283,302],"table",{},[284,285,286],"thead",{},[287,288,289,293,296,299],"tr",{},[290,291,292],"th",{},"Vendor",[290,294,295],{},"Purpose",[290,297,298],{},"Categories of data",[290,300,301],{},"Location",[303,304,305,320,331],"tbody",{},[287,306,307,311,314,317],{},[308,309,310],"td",{},"OpenAI",[308,312,313],{},"AI extraction of document content",[308,315,316],{},"Content of documents Customer submits for processing (API processing)",[308,318,319],{},"United States",[287,321,322,325,327,329],{},[308,323,324],{},"Anthropic",[308,326,313],{},[308,328,316],{},[308,330,319],{},[287,332,333,336,338,340],{},[308,334,335],{},"Google",[308,337,313],{},[308,339,316],{},[308,341,319],{},[10,343,344,345,348],{},"The current Customer Content subprocessor list is maintained at ",[14,346,347],{"href":103},"docabra.com\u002Flegal\u002Fsubprocessors",", and additions or replacements are announced there subject to the notice and objection mechanism in Section 4.",[23,350,352],{"id":351},"exhibit-c-technical-and-organizational-measures","Exhibit C — Technical and organizational measures",[111,354,355,361,367,373,379,385,391,397],{},[31,356,357,360],{},[34,358,359],{},"Encryption."," TLS for all data in transit; encryption at rest for stored documents, databases, and backups.",[31,362,363,366],{},[34,364,365],{},"Access control."," Unique credentials for personnel; least-privilege access to production systems; production data access limited to personnel who need it to operate the Services.",[31,368,369,372],{},[34,370,371],{},"Credential and session hygiene."," Passwords stored only as scrypt hashes; session tokens, one-time codes, and reset tokens stored only as hashes; password reset revokes all existing sessions; sessions expire after 30 days.",[31,374,375,378],{},[34,376,377],{},"Availability."," Regular backups; the ability to restore availability of Customer Personal Data in a timely manner after an incident.",[31,380,381,384],{},[34,382,383],{},"Separation."," Customer Content addressed by content hash and served only to the accounts that uploaded it.",[31,386,387,390],{},[34,388,389],{},"Personnel."," Confidentiality obligations for all personnel and contractors with access to Customer Personal Data.",[31,392,393,396],{},[34,394,395],{},"Sub-processor oversight."," Security and privacy assessment before engagement; data processing agreements with all sub-processors; the change-notification process in Section 4.",[31,398,399,402],{},[34,400,401],{},"Testing."," Regular evaluation of the effectiveness of these measures.",{"title":404,"searchDepth":405,"depth":405,"links":406},"",2,[407,408,409,410,411,412,413,414,415,416,417,418,419,420,421],{"id":25,"depth":405,"text":26},{"id":64,"depth":405,"text":65},{"id":89,"depth":405,"text":90},{"id":96,"depth":405,"text":97},{"id":127,"depth":405,"text":128},{"id":138,"depth":405,"text":139},{"id":156,"depth":405,"text":157},{"id":163,"depth":405,"text":164},{"id":195,"depth":405,"text":196},{"id":202,"depth":405,"text":203},{"id":213,"depth":405,"text":214},{"id":223,"depth":405,"text":224},{"id":233,"depth":405,"text":234},{"id":275,"depth":405,"text":276},{"id":351,"depth":405,"text":352},"The terms under which Docabra processes personal data on your behalf — roles, security measures, international transfers, and audits.","md",{},true,4,"\u002Flegal\u002Fdpa",{"title":5,"description":422},"legal\u002Fdpa","2026-08-10","MSFMSrhRVr_XyzZ7zbrUHTPy9eODzXbYOuSnj8HNeIE",1786355080590]