Data processing agreement

Standard DPA, version 3.4 · in force from 1 March 2026. Signed as-is by most customers; a signable PDF is available on request.

Annex I — Subject matter and duration

DocShare B.V. ("Processor") processes personal data on behalf of the Customer ("Controller") for the sole purpose of sealing, delivering and evidencing the release of documents that the Controller chooses to send. Processing lasts for the term of the main agreement, plus the retention periods set out in Annex III.

Categories of data subject

  • Recipients of documents sent by the Controller
  • Individuals whose personal data appears inside those documents
  • The Controller's own personnel who use the sender console or API

Categories of personal data

CategoryForm held by Processor
Document content, whatever it containsCiphertext only (AES-256-GCM)
Recipient email address or mobile numberPlaintext, encrypted at rest
Sender name, department, rolePlaintext, encrypted at rest
Document file name and page countPlaintext in the signed manifest
Verification and release metadataPlaintext in the audit chain
Source IP, coarse geolocation, user agent classPlaintext in the audit chain

Special categories of personal data (Article 9) and criminal-offence data (Article 10) may appear inside document content. Because that content is held only as ciphertext to which the Processor has no key, the Processor's exposure to such data is nil by design. The Controller remains responsible for its lawful basis.

Annex II — Technical and organisational measures

MeasureImplementation
Encryption at restAES-256-GCM per document, keys wrapped under a tenant master key in a FIPS 140-2 Level 3 HSM
Encryption in transitTLS 1.3 only, forward secrecy mandatory, HSTS preloaded
PseudonymisationShare references are random GUIDs carrying no derivable information
Access controlLeast privilege, hardware-token MFA, just-in-time elevation with a four-hour ceiling, four-eyes approval for production change
Key managementDual-control ceremonies, split custody, non-exportable master keys, 90-day rotation
LoggingHash-chained audit records, sealed hourly with eIDAS qualified timestamps
ResilienceTwo Dutch data centres, RTO 4 hours, RPO 15 minutes, restore tested monthly
TestingTwice-yearly independent penetration test, continuous private bug bounty, annual ISO 27001 surveillance
PersonnelPre-employment screening (VOG), confidentiality undertakings, annual security training
DeletionKey destruction on expiry renders ciphertext permanently unrecoverable

Annex III — Retention and deletion

Encrypted documents are retained until the share expires or is revoked. Audit records are retained for the period the Controller configures, seven years by default. On termination, data is exported and then destroyed within ninety days. Backups holding ciphertext roll off within thirty-five days.

Annex IV — Sub-processor register

The Processor engages the following sub-processors. Controllers are notified at least thirty days before any addition, and may object on reasonable data-protection grounds, in which case either party may terminate the affected service without penalty.

Sub-processorPurposeLocationAccess to content
Amstelveen Datacenters B.V.Primary hosting and colocationAmsterdam, NLCiphertext only
Brainport Facilities B.V.Secondary hosting and colocationEindhoven, NLCiphertext only
Lage Landen Telecom B.V.SMS dispatch of one-time passphrasesUtrecht, NLNone
Polder Mail Services B.V.Transactional email delivery of share linksRotterdam, NLNone — links carry no key
Kwaliteitszegel Trust B.V.eIDAS qualified timestampingThe Hague, NLDigests only

No sub-processor is established outside the European Economic Area, and none has access to plaintext document content. The register is republished on every change; the current version always governs.

Annex V — Audit rights

The Controller may satisfy its audit obligations through our ISO 27001 certificate, SOC 2 Type II report and penetration test summaries, released under NDA. Beyond that, Enterprise customers may conduct one on-site audit per year with thirty days' notice, at their own cost, subject to confidentiality and to not disrupting other customers. Regulators exercising a statutory power of inspection are accommodated without notice periods.