← Legal center

DocVex — Legal

Data Processing Agreement

The standard agreement under Article 28 GDPR between your organization (the controller) and DocVex (the processor), covering the personal data DocVex processes on your behalf.

Last updated: 18 July 2026 · Version 1.0

1. Parties & scope

Who this agreement binds.

This Data Processing Agreement ("DPA") forms part of the Terms & Conditions between DocVex ("Processor") and the customer organization using the Service ("Customer" or "Controller"). It applies wherever DocVex processes personal data contained in Customer Content on behalf of the Customer within the meaning of Art. 28 GDPR.

It does not apply to personal data for which DocVex is itself the controller (account registration data, billing, support) — that processing is described in the Privacy Policy. In case of conflict between this DPA and the Terms, this DPA prevails for data-protection matters.

To execute a countersigned copy of this DPA for your organization's records, email docvexteam@docvex.ro.

2. Definitions

Terms used in this DPA.

  • "GDPR" — Regulation (EU) 2016/679. "Personal data", "processing", "controller", "processor", "data subject", and "personal data breach" have the meanings given there.
  • "Customer Content" — data the Customer and its users submit to the Service: project data, chat and direct messages, invitee details, and content submitted to AI features.
  • "Sub-processor" — a third party engaged by the Processor to process Customer Content.
  • "SCCs" — the Standard Contractual Clauses adopted by Commission Implementing Decision (EU) 2021/914.

3. Details of the processing

Art. 28(3) particulars.

Subject matter & duration

Provision of the DocVex collaboration service to the Customer, for the duration of the Customer's use of the Service plus the deletion period in Section 11.

Nature & purpose

Hosting, storage, transmission, and display of Customer Content for team collaboration; transient AI processing (summarisation, review, drafting, extraction, transcription) of content the Customer's users explicitly submit; delivery of related notifications and emails.

Categories of data subjects

  • The Customer's users (employees, partners, contractors);
  • persons invited to the Customer's projects;
  • third parties whose personal data appears in Customer Content (e.g. clients, counterparties, persons named in documents or messages).

Categories of personal data

Identification and contact data, professional data, communication content, and any personal data the Customer's users include in Customer Content — which, given the legal domain, may include special categories of data (Art. 9 GDPR). The Customer is responsible for having a lawful basis for such data.

Important scope note

Project files are stored locally on the Customer's own devices and are not processed by DocVex at all unless a user invokes a feature (such as AI analysis) that transmits selected content for transient processing.

4. Processor obligations

Art. 28(3)(a)–(h) commitments.

DocVex shall:

  1. process Customer Content only on documented instructions from the Customer — given through the Service's features and settings — including for international transfers, unless required otherwise by EU or member-state law (in which case DocVex informs the Customer unless prohibited);
  2. ensure persons authorised to process the data are bound by confidentiality obligations;
  3. implement the technical and organisational measures in Section 7 (Art. 32);
  4. respect the sub-processor conditions in Section 5;
  5. assist the Customer with data-subject requests and with its Art. 32–36 obligations (Section 9);
  6. delete or return Customer Content at end of service (Section 11);
  7. make available the information necessary to demonstrate compliance and allow audits (Section 10); and
  8. inform the Customer immediately if, in its opinion, an instruction infringes the GDPR.

5. Sub-processors

General authorisation with notice.

The Customer grants general authorisation to engage the sub-processors below. DocVex imposes data-protection obligations on each sub-processor equivalent to this DPA and remains fully liable for their performance.

Sub-processorProcessingLocationTransfer basis
Supabase (on AWS)Database, authentication, realtime sync, serverless functionsEU — Ireland (eu-west-1)EEA processing
Anthropic, PBCAI text processing (Claude) when a user invokes an AI featureUnited StatesEU–US DPF / SCCs
OpenAI, LLCAudio transcription (Whisper) when a user invokes transcriptionUnited StatesEU–US DPF / SCCs
ResendTransactional email delivery (invitations, notifications)United States / EUEU–US DPF / SCCs
Google LLC / Microsoft Corp.Mailbox synchronisation — only for users who connect Gmail/OutlookUnited States / EUEU–US DPF / SCCs

Changes. DocVex will give at least 30 days' notice of any intended addition or replacement (by updating this page and notifying account owners), during which the Customer may object on reasonable data-protection grounds. If no resolution is found, the Customer may terminate the affected service and Section 11 applies.

6. International transfers

Chapter V compliance.

Customer Content is stored in the EEA. Transfers to sub-processors outside the EEA occur only as shown in Section 5 and are protected by the EU–US Data Privacy Framework adequacy decision (for certified recipients) or the SCCs (module 3, processor-to-processor, or module 2 as applicable), together with supplementary measures where needed. DocVex will not transfer Customer Content to any other third country without ensuring an Art. 44-compliant basis.

7. Technical & organisational measures

Art. 32 summary.

  • Encryption of data in transit (TLS) and at rest; additional AES-256-GCM application-layer encryption for mailbox tokens.
  • Database-enforced row-level security scoping every read/write to project membership; role- and capability-based authorisation evaluated server-side.
  • PKCE-based authentication with rotating refresh tokens and global revocation.
  • Data minimisation by architecture: project files remain on Customer devices; AI processing is transient and user-initiated.
  • Secrets held in a managed vault; production access restricted to the DocVex team on a need-to-use basis.
  • Signed, verified application releases distributed only through official channels.

The Security Policy describes these measures in detail and is incorporated by reference; DocVex may improve measures over time but will not materially reduce the protection.

8. Personal data breaches

Art. 33(2).

DocVex will notify the Customer without undue delay after becoming aware of a personal data breach affecting Customer Content, providing (as information becomes available) the nature of the breach, categories and approximate numbers of data subjects and records, likely consequences, and measures taken or proposed. DocVex will cooperate with the Customer's own notification obligations and document all breaches.

9. Assistance to the controller

Data-subject rights and DPIAs.

Taking into account the nature of the processing, DocVex will assist the Customer with appropriate technical and organisational measures in fulfilling data-subject requests (access, rectification, erasure, restriction, portability, objection) — much of which is self-service in the app — and, considering the information available to it, with the Customer's obligations under Arts. 32–36 (security, breach notification, data-protection impact assessments, prior consultation). If a data subject contacts DocVex directly about Customer Content, DocVex will refer the request to the Customer without undue delay.

10. Audits & information

Art. 28(3)(h).

On request (no more than once per year, absent a supervisory-authority requirement or a material incident), DocVex will make available the information reasonably necessary to demonstrate compliance with this DPA — documentation, sub-processor terms, and summaries of security measures. Where this is insufficient, the Customer may conduct (directly or via an independent auditor bound to confidentiality) an audit with at least 30 days' notice, during business hours, without disrupting the Service, at the Customer's cost.

11. Return & deletion

End of processing.

Project files already reside with the Customer — no return step is needed for them. Upon termination of the Service or deletion of a project or account, DocVex will delete the associated Customer Content held on its infrastructure (project records, messages, invitations, usage metadata) within 30 days, unless EU or member-state law requires longer storage. Residual copies in encrypted backups are purged on the backup rotation cycle and are not restored to active systems.

12. General terms

Liability, law, precedence.

Each party's liability under this DPA is subject to the limitations in the Terms & Conditions, except where the GDPR mandates otherwise (Art. 82). This DPA is governed by the same law as the Terms (Romania). If any provision is invalid, the remainder stays in force; the parties will replace the invalid provision with one that best achieves its purpose. This DPA takes effect when the Customer first uses the Service in a business capacity or, if earlier, upon countersignature.

The operating legal entity's registered details will be added upon incorporation, and a signable PDF version will be provided on request. This template has not yet been reviewed by counsel and does not constitute legal advice.