DocVex — Legal
The standard agreement under Article 28 GDPR between your organization (the controller) and DocVex (the processor), covering the personal data DocVex processes on your behalf.
Last updated: 18 July 2026 · Version 1.0
Who this agreement binds.
This Data Processing Agreement ("DPA") forms part of the Terms & Conditions between DocVex ("Processor") and the customer organization using the Service ("Customer" or "Controller"). It applies wherever DocVex processes personal data contained in Customer Content on behalf of the Customer within the meaning of Art. 28 GDPR.
It does not apply to personal data for which DocVex is itself the controller (account registration data, billing, support) — that processing is described in the Privacy Policy. In case of conflict between this DPA and the Terms, this DPA prevails for data-protection matters.
To execute a countersigned copy of this DPA for your organization's records, email docvexteam@docvex.ro.
Terms used in this DPA.
Art. 28(3) particulars.
Provision of the DocVex collaboration service to the Customer, for the duration of the Customer's use of the Service plus the deletion period in Section 11.
Hosting, storage, transmission, and display of Customer Content for team collaboration; transient AI processing (summarisation, review, drafting, extraction, transcription) of content the Customer's users explicitly submit; delivery of related notifications and emails.
Identification and contact data, professional data, communication content, and any personal data the Customer's users include in Customer Content — which, given the legal domain, may include special categories of data (Art. 9 GDPR). The Customer is responsible for having a lawful basis for such data.
Project files are stored locally on the Customer's own devices and are not processed by DocVex at all unless a user invokes a feature (such as AI analysis) that transmits selected content for transient processing.
Art. 28(3)(a)–(h) commitments.
DocVex shall:
General authorisation with notice.
The Customer grants general authorisation to engage the sub-processors below. DocVex imposes data-protection obligations on each sub-processor equivalent to this DPA and remains fully liable for their performance.
| Sub-processor | Processing | Location | Transfer basis |
|---|---|---|---|
| Supabase (on AWS) | Database, authentication, realtime sync, serverless functions | EU — Ireland (eu-west-1) | EEA processing |
| Anthropic, PBC | AI text processing (Claude) when a user invokes an AI feature | United States | EU–US DPF / SCCs |
| OpenAI, LLC | Audio transcription (Whisper) when a user invokes transcription | United States | EU–US DPF / SCCs |
| Resend | Transactional email delivery (invitations, notifications) | United States / EU | EU–US DPF / SCCs |
| Google LLC / Microsoft Corp. | Mailbox synchronisation — only for users who connect Gmail/Outlook | United States / EU | EU–US DPF / SCCs |
Changes. DocVex will give at least 30 days' notice of any intended addition or replacement (by updating this page and notifying account owners), during which the Customer may object on reasonable data-protection grounds. If no resolution is found, the Customer may terminate the affected service and Section 11 applies.
Chapter V compliance.
Customer Content is stored in the EEA. Transfers to sub-processors outside the EEA occur only as shown in Section 5 and are protected by the EU–US Data Privacy Framework adequacy decision (for certified recipients) or the SCCs (module 3, processor-to-processor, or module 2 as applicable), together with supplementary measures where needed. DocVex will not transfer Customer Content to any other third country without ensuring an Art. 44-compliant basis.
Art. 32 summary.
The Security Policy describes these measures in detail and is incorporated by reference; DocVex may improve measures over time but will not materially reduce the protection.
Art. 33(2).
DocVex will notify the Customer without undue delay after becoming aware of a personal data breach affecting Customer Content, providing (as information becomes available) the nature of the breach, categories and approximate numbers of data subjects and records, likely consequences, and measures taken or proposed. DocVex will cooperate with the Customer's own notification obligations and document all breaches.
Data-subject rights and DPIAs.
Taking into account the nature of the processing, DocVex will assist the Customer with appropriate technical and organisational measures in fulfilling data-subject requests (access, rectification, erasure, restriction, portability, objection) — much of which is self-service in the app — and, considering the information available to it, with the Customer's obligations under Arts. 32–36 (security, breach notification, data-protection impact assessments, prior consultation). If a data subject contacts DocVex directly about Customer Content, DocVex will refer the request to the Customer without undue delay.
Art. 28(3)(h).
On request (no more than once per year, absent a supervisory-authority requirement or a material incident), DocVex will make available the information reasonably necessary to demonstrate compliance with this DPA — documentation, sub-processor terms, and summaries of security measures. Where this is insufficient, the Customer may conduct (directly or via an independent auditor bound to confidentiality) an audit with at least 30 days' notice, during business hours, without disrupting the Service, at the Customer's cost.
End of processing.
Project files already reside with the Customer — no return step is needed for them. Upon termination of the Service or deletion of a project or account, DocVex will delete the associated Customer Content held on its infrastructure (project records, messages, invitations, usage metadata) within 30 days, unless EU or member-state law requires longer storage. Residual copies in encrypted backups are purged on the backup rotation cycle and are not restored to active systems.
Liability, law, precedence.
Each party's liability under this DPA is subject to the limitations in the Terms & Conditions, except where the GDPR mandates otherwise (Art. 82). This DPA is governed by the same law as the Terms (Romania). If any provision is invalid, the remainder stays in force; the parties will replace the invalid provision with one that best achieves its purpose. This DPA takes effect when the Customer first uses the Service in a business capacity or, if earlier, upon countersignature.
The operating legal entity's registered details will be added upon incorporation, and a signable PDF version will be provided on request. This template has not yet been reviewed by counsel and does not constitute legal advice.