Data processing agreement
Standard DPA, version 3.4 · in force from 1 March 2026. Signed as-is by most customers; a signable PDF is available on request.
Annex I — Subject matter and duration
DocShare B.V. ("Processor") processes personal data on behalf of the Customer ("Controller") for the sole purpose of sealing, delivering and evidencing the release of documents that the Controller chooses to send. Processing lasts for the term of the main agreement, plus the retention periods set out in Annex III.
Categories of data subject
- Recipients of documents sent by the Controller
- Individuals whose personal data appears inside those documents
- The Controller's own personnel who use the sender console or API
Categories of personal data
| Category | Form held by Processor |
|---|---|
| Document content, whatever it contains | Ciphertext only (AES-256-GCM) |
| Recipient email address or mobile number | Plaintext, encrypted at rest |
| Sender name, department, role | Plaintext, encrypted at rest |
| Document file name and page count | Plaintext in the signed manifest |
| Verification and release metadata | Plaintext in the audit chain |
| Source IP, coarse geolocation, user agent class | Plaintext in the audit chain |
Special categories of personal data (Article 9) and criminal-offence data (Article 10) may appear inside document content. Because that content is held only as ciphertext to which the Processor has no key, the Processor's exposure to such data is nil by design. The Controller remains responsible for its lawful basis.
Annex II — Technical and organisational measures
| Measure | Implementation |
|---|---|
| Encryption at rest | AES-256-GCM per document, keys wrapped under a tenant master key in a FIPS 140-2 Level 3 HSM |
| Encryption in transit | TLS 1.3 only, forward secrecy mandatory, HSTS preloaded |
| Pseudonymisation | Share references are random GUIDs carrying no derivable information |
| Access control | Least privilege, hardware-token MFA, just-in-time elevation with a four-hour ceiling, four-eyes approval for production change |
| Key management | Dual-control ceremonies, split custody, non-exportable master keys, 90-day rotation |
| Logging | Hash-chained audit records, sealed hourly with eIDAS qualified timestamps |
| Resilience | Two Dutch data centres, RTO 4 hours, RPO 15 minutes, restore tested monthly |
| Testing | Twice-yearly independent penetration test, continuous private bug bounty, annual ISO 27001 surveillance |
| Personnel | Pre-employment screening (VOG), confidentiality undertakings, annual security training |
| Deletion | Key destruction on expiry renders ciphertext permanently unrecoverable |
Annex III — Retention and deletion
Encrypted documents are retained until the share expires or is revoked. Audit records are retained for the period the Controller configures, seven years by default. On termination, data is exported and then destroyed within ninety days. Backups holding ciphertext roll off within thirty-five days.
Annex IV — Sub-processor register
The Processor engages the following sub-processors. Controllers are notified at least thirty days before any addition, and may object on reasonable data-protection grounds, in which case either party may terminate the affected service without penalty.
| Sub-processor | Purpose | Location | Access to content |
|---|---|---|---|
| Amstelveen Datacenters B.V. | Primary hosting and colocation | Amsterdam, NL | Ciphertext only |
| Brainport Facilities B.V. | Secondary hosting and colocation | Eindhoven, NL | Ciphertext only |
| Lage Landen Telecom B.V. | SMS dispatch of one-time passphrases | Utrecht, NL | None |
| Polder Mail Services B.V. | Transactional email delivery of share links | Rotterdam, NL | None — links carry no key |
| Kwaliteitszegel Trust B.V. | eIDAS qualified timestamping | The Hague, NL | Digests only |
No sub-processor is established outside the European Economic Area, and none has access to plaintext document content. The register is republished on every change; the current version always governs.
Annex V — Audit rights
The Controller may satisfy its audit obligations through our ISO 27001 certificate, SOC 2 Type II report and penetration test summaries, released under NDA. Beyond that, Enterprise customers may conduct one on-site audit per year with thirty days' notice, at their own cost, subject to confidentiality and to not disrupting other customers. Regulators exercising a statutory power of inspection are accommodated without notice periods.