Skip to main content

Data Processing Agreement

Effective date: 1 October 2026 · Version: 1.0

This Data Processing Agreement (the "DPA") forms part of the Terms of Service, or of a Master Services Agreement and its Order Forms where one is signed (in either case, the "Agreement"), between AI Fabric Limited, a company incorporated in Cyprus with registration number HE 495826, whose registered office is at Leonidou 6, Flat/Office 102, Latsia, 2236, Nicosia, Cyprus, trading as DocAI Fabric ("AI Fabric", "we", "us"), and the customer that accepted the Agreement ("Customer").

This DPA applies automatically whenever we process personal data on Customer's behalf under the Agreement. It is pre-signed by us and needs no further signature to take effect. Customers that require a countersigned copy may download it at docaifabric.com/docs/legal/dpa, sign it and return it to legal@docaifabric.com; the countersigned copy has the same terms.

1. Definitions

1.1 "Customer Content" has the meaning given in the Agreement: the documents Customer uploads to the Service and the data the Service extracts, derives or generates from them.

1.2 "Customer Personal Data" means personal data contained in Customer Content that we process on Customer's behalf.

1.3 "Data Protection Law" means all laws that apply to the processing of Customer Personal Data under this DPA, including, as applicable: the GDPR (Regulation (EU) 2016/679) and the laws of EU Member States implementing it, including Cyprus Law 125(I)/2018; the UK GDPR and the Data Protection Act 2018; the Australian Privacy Act 1988 (Cth) and the Australian Privacy Principles ("APPs"); and US state privacy laws, including the California Consumer Privacy Act as amended ("CCPA").

1.4 "Region" means the hosting location Customer selected for its account. We offer the Regions listed on the Data Handling page; at the date of this DPA they are the United States and Australia; a European Union Region is planned and will be added to that page when it is available.

1.5 "Sub-processor" means a third party we engage to process Customer Personal Data.

1.6 "SCCs" means the standard contractual clauses for the transfer of personal data to third countries adopted by the European Commission in Decision (EU) 2021/914, and "UK Addendum" means the International Data Transfer Addendum to the SCCs issued by the UK Information Commissioner.

1.7 "Security Incident" means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, Customer Personal Data.

1.8 "Controller", "processor", "data subject", "personal data", "processing" and "supervisory authority" have the meanings given in the GDPR, and their equivalents under other Data Protection Law ("business" and "service provider" under the CCPA; "APP entity" under the Privacy Act) are read accordingly.

2. Roles and scope

2.1 Customer is the controller of Customer Personal Data and we are its processor. Where Customer itself acts as a processor for its own clients, Customer is our instructing party, we are a sub-processor, and Customer warrants that its instructions to us reflect the instructions of the relevant controller.

2.2 This DPA covers all processing of Customer Personal Data in the Service. It does not cover Account Data (data about Customer's users and account), for which we are the controller under our Privacy Policy.

2.3 Customer is responsible for: the lawfulness of Customer Content and its instructions; the accuracy of Customer Content; providing any notices and obtaining any consents required to upload it; and configuring the Service (retention, access, review settings, integrations) appropriately for its data.

2.4 Customer must not upload special categories of personal data (Article 9 GDPR), criminal-offence data, or data subject to sector rules that require terms not in this DPA (such as protected health information under HIPAA) unless we have agreed in writing.

3. Processing on instructions

3.1 We process Customer Personal Data only on Customer's documented instructions, which are: the Agreement, this DPA, the configuration Customer sets in the Service, and Customer's use of the Service's features (uploading, processing, reviewing, exporting, deleting, connecting integrations). We may also process where EU or Member State law requires it, in which case we inform Customer before processing unless the law prohibits it.

3.2 We will tell Customer if, in our opinion, an instruction infringes Data Protection Law. We are not obliged to review Customer's instructions for legal compliance.

3.3 We do not use Customer Personal Data to train or improve machine-learning models used for anyone other than Customer. Learning features in the Service use Customer Content only to improve results within Customer's own account, and only as configured by Customer.

3.4 We do not sell Customer Personal Data, share it for cross-context behavioural advertising, or combine it with data from other customers or sources, except as necessary to provide the Service.

4. Details of the processing

4.1 The subject matter, duration, nature and purpose of the processing, the types of personal data and the categories of data subjects are set out in Annex 1.

5. Confidentiality of personnel

5.1 We ensure that everyone we authorise to process Customer Personal Data is bound by a contractual or statutory duty of confidentiality and has received data-protection training.

5.2 Our personnel access Customer Content only where needed to operate, support or secure the Service, or on Customer's request, and such access is logged.

6. Security

6.1 We implement and maintain the technical and organisational measures in Annex 2, taking into account the state of the art, the costs of implementation, the nature, scope, context and purposes of processing, and the risks to data subjects.

6.2 We may update those measures over time, provided the overall level of protection is not materially reduced. The current description is on our Trust Center.

6.3 Customer is responsible for the security of its own systems and accounts, including user management, multi-factor authentication for its users, API-key handling and the integrations it connects.

7. Sub-processors

7.1 Customer gives us general authorisation to engage Sub-processors. Our current Sub-processors, with their purpose and the Region in which they process, are listed in Annex 3 and at docaifabric.com/docs/trust/subprocessors, which prevails if it is more recent.

7.2 We will give Customer at least 30 days' notice before adding or replacing a Sub-processor that processes Customer Personal Data, by updating the published list and emailing the account's administrators.

7.3 Customer may object in writing within the notice period on reasonable data-protection grounds. We will work with Customer in good faith to resolve the objection. If we cannot within 30 days, Customer may terminate the Agreement, or the affected part of it, on notice, and we refund any prepaid fees for the unexpired term. This is Customer's sole remedy for an objection.

7.4 We impose on each Sub-processor written data-protection obligations that are no less protective than this DPA, and we remain responsible to Customer for each Sub-processor's performance.

8. Data subject requests

8.1 The Service allows Customer to search, access, correct, export and delete Customer Personal Data, which Customer should use to answer requests from data subjects.

8.2 If a data subject contacts us directly about Customer Personal Data, we will not respond except to refer the person to Customer, and we will notify Customer without undue delay.

8.3 Where Customer cannot fulfil a request with the Service's own features, we will provide reasonable assistance, taking into account the nature of the processing. We may charge for assistance that requires material effort beyond that.

9. Assistance

9.1 Taking into account the nature of the processing and the information available to us, we will assist Customer in meeting its obligations under Articles 32 to 36 GDPR and their equivalents: security, breach notification, data protection impact assessments and prior consultation with a supervisory authority. We may charge for assistance that requires material effort.

10. Security Incidents

10.1 We will notify Customer's account administrators without undue delay, and in any event within 48 hours, after becoming aware of a Security Incident affecting Customer Personal Data, so that Customer has the remainder of any 72-hour period Data Protection Law gives it for its own notifications. The initial notice may be given with the information then available and completed under clause 10.2.

10.2 The notification will describe, to the extent then known, the nature of the incident, the categories and approximate number of data subjects and records concerned, the likely consequences, the measures taken or proposed, and a contact point. We will update Customer as further information becomes available.

10.3 We will take reasonable steps to contain, investigate and remediate the incident, and will cooperate with Customer's own investigation and notifications. Our notification is not an admission of fault or liability.

10.4 Customer is responsible for any notification to data subjects, supervisory authorities or other regulators that Data Protection Law requires of it as controller.

11. Deletion and return

11.1 During the term, Customer controls deletion of Customer Personal Data through the Service: by the retention period it sets for each project, by deleting documents, projects or its account, and through the export features.

11.2 On termination or expiry of the Agreement, or on Customer's earlier request, we delete Customer Personal Data in accordance with the deletion terms of the Agreement. Before deletion, Customer may export Customer Content using the Service's export features.

11.3 Deleted data may persist in encrypted backups until they are overwritten in the ordinary course, for no longer than 90 days, being the Recovery Window stated in the SLA, and remains protected by this DPA while it does. We may retain data where EU or Member State law requires, subject to continuing confidentiality.

11.4 On written request we will confirm deletion in writing.

12. Audits

12.1 We will make available to Customer the information reasonably necessary to demonstrate our compliance with this DPA, including our Trust Center documentation and, when available, third-party audit reports and certifications (for example ISO/IEC 27001 or SOC 2), which Customer accepts as the primary means of audit.

12.2 Customer, or an independent auditor it appoints who is bound by confidentiality and is not our competitor, may audit our compliance with this DPA, including by inspection, as Data Protection Law entitles it to. An audit is conducted on at least 30 days' written notice, no more than once in any 12-month period unless required by a supervisory authority or following a Security Incident, during business hours, remotely where the scope allows, at Customer's cost, without unreasonable disruption to our operations, and without access to the data of other customers. Its scope is limited to matters not already covered by the information provided under clause 12.1; where a third-party audit report covers a matter, Customer relies on that report unless it has reasonable grounds to doubt it. The Parties agree the scope and plan in advance, Customer shares its findings with us, and both treat the findings as Confidential Information. Audits of our Sub-processors are conducted through the audit mechanisms those Sub-processors provide.

13. Regions and international transfers

13.1 Data stays in the Region. We store Customer Content, including backups, in the Region Customer selected, and we process it, including OCR and AI model inference, within that Region, except that where a Region's AI models are offered by our cloud provider only within a wider geographic data zone that contains the Region, inference runs within that data zone and nowhere else. At the date of this DPA this applies to the Australia Region, whose AI inference runs in Microsoft's Asia-Pacific data zone: Azure regions in Asia-Pacific countries only, and never in the United States or Europe. The Data Handling page states, per Region, where each processing step runs and which models are available. We do not move Customer Content to another Region, or route processing through another Region, without Customer's written agreement.

13.2 Personnel access across Regions. Our personnel operate and support the Service from the locations where they are based: employees in the European Union (Cyprus and other Member States) and individual contractors in the United States and Australia. Personnel may access Customer Content in any Region for the purposes in clause 5.2, from those locations only, through the Service's administrative tooling, which keeps the data within its Region; Customer Content is not copied to personnel devices or to another Region for that purpose. Such access is by named account with multi-factor authentication, limited to a small operations group, logged, and subject to this DPA. Contractors are bound by written confidentiality and data-protection obligations no less protective than those we impose on employees, and, where they are located outside the EEA, by the transfer mechanism in clause 13.4. Where the Order Form so states, we restrict access to Customer Content to personnel located in the European Union; response targets under the Support Policy then apply during European business hours only.

13.3 Sub-processor support access. Our Sub-processors provide support and operations for their services under their own agreements with us, which include the transfer safeguards listed in Annex 3.

13.4 Customers subject to the GDPR or UK GDPR (including EU and UK customers using the US or Australia Region). Where processing under this DPA involves a transfer of Customer Personal Data to a country outside the EEA or the UK that is not covered by an adequacy decision, the transfer is governed by the SCCs (Module Two, controller to processor, or Module Three, processor to processor, as applicable) and, for UK data, the UK Addendum, which are incorporated into this DPA with the choices in Annex 4. Because we are established in the EU, transfers to our Sub-processors outside the EEA are made under the mechanisms in Annex 3 (adequacy, including the EU-US Data Privacy Framework for certified recipients, or the SCCs), together with transfer impact assessments where required. Remote access to Customer Content by our personnel located in the United States or Australia under clause 13.2 is a transfer to a third country. It is made under the SCCs (Module Three) concluded between us and each such contractor, with the supplementary measures in clause 13.2 (access through in-Region tooling only, no copying, named accounts, multi-factor authentication and logging), and is covered by the transfer impact assessment we maintain for those locations, available on request. Customer may exclude it by electing EU-only access in the Order Form.

13.5 Customers subject to the Australian Privacy Act. Customer Content in the Australia Region is stored and processed in Australia. Customer acknowledges that our personnel may access it from the European Union and the United States, as well as from Australia, for the purposes in clause 5.2, and that access from outside Australia is a disclosure to an overseas recipient for the purposes of APP 8. We handle Customer Personal Data in a manner consistent with the APPs, and this DPA is the contractual arrangement by which Customer takes reasonable steps under APP 8.1. We comply with the Notifiable Data Breaches scheme in cooperation with Customer under clause 10.

13.6 Customers subject to the CCPA and other US state privacy laws. We act as Customer's service provider or processor. We will not: sell or share Customer Personal Data; retain, use or disclose it for any purpose other than the business purposes in the Agreement, or outside the direct business relationship with Customer; or combine it with personal information from other sources except as the CCPA permits for service providers. We will comply with the CCPA, provide the same level of privacy protection it requires, notify Customer if we can no longer meet our obligations, and allow Customer to take reasonable steps to stop and remediate unauthorised use. We certify that we understand these restrictions.

14. Liability

14.1 Each party's liability arising out of or in connection with this DPA is subject to the exclusions and limitations of liability in the Agreement, and counts towards any cap there. Nothing in this DPA limits liability that Data Protection Law does not allow to be limited, or liability owed directly to a data subject or supervisory authority by operation of law.

15. Term, precedence and general

15.1 This DPA takes effect when Customer accepts the Agreement, or when we first process Customer Personal Data, whichever is earlier, and continues until we have deleted all Customer Personal Data under clause 11.

15.2 On data protection matters, this DPA prevails over the rest of the Agreement. Where the SCCs apply, they prevail over this DPA to the extent of any conflict.

15.3 We may update this DPA to reflect changes in Data Protection Law, in our Sub-processors, or in the Service, in accordance with the change mechanism of the Agreement. Previous versions are archived at docaifabric.com/docs/legal/dpa.

15.4 This DPA is governed by the law that governs the Agreement. Where the SCCs apply, they are governed by the law, and subject to the courts, chosen in Annex 4, whatever law governs the Agreement: Clause 17 of the SCCs requires the law of an EU Member State that allows third-party beneficiary rights, and a change to the governing law of the Agreement does not change that choice.

Annex 1. Details of the processing

ItemDetail
Subject matterCustomer Content that Customer uploads to the Service for classification, data extraction, validation, review, export and integration with Customer's other systems.
DurationThe term of the Agreement, then until deletion under clause 11.
Nature of processingStorage; conversion and OCR; classification; extraction of fields and tables by AI models; application of validation and business rules; presentation to Customer's users for review and correction; the AI assistant answering questions about Customer's documents and configuration; export to formats and destinations Customer configures; deletion.
PurposeTo provide the Service to Customer as described in the Documentation.
Types of personal dataWhatever appears in the documents Customer uploads. For typical business documents (invoices, purchase orders, delivery notes, contracts, forms, correspondence): names, job titles, business and private contact details, addresses, signatures, identification numbers, tax and VAT numbers, bank account and payment details, order and transaction details. Customer determines the actual content. Special categories are excluded unless agreed under clause 2.4.
Categories of data subjectsCustomer's employees, contractors and users; employees and contacts of Customer's suppliers, customers, partners and counterparties; other individuals named in the documents. Where Customer embeds the Service in its own application for its clients: those clients' users, and the individuals named in the documents those clients submit.
RegionThe Region Customer selected for its account.
FrequencyContinuous, as Customer uses the Service.

Annex 2. Technical and organisational measures

AreaMeasures
Hosting and isolationThe Service runs on Microsoft Azure in the selected Region. Each customer's data is logically isolated by tenant in storage, queues and the application; every request is authorised against the tenant and the user's grants.
EncryptionTLS 1.2 or higher for all data in transit. Encryption at rest for all stored Customer Content, backups and secrets, using the cloud provider's managed encryption.
Access controlRole-based access with granular grants inside the Service; authentication of Customer's users by password with session controls, with single sign-on and multi-factor authentication to follow as the Security Overview page announces; least-privilege, named accounts and multi-factor authentication for our personnel; production access limited to a small operations group and logged.
SecretsCredentials and keys held in a managed secrets vault; no secrets in code or images; rotation on personnel change or suspected exposure.
Logging and monitoringSecurity audit log of user and administrative actions, retained for 400 days by default and available to Customer in the Service; platform monitoring and alerting; log forwarding available to Customer's SIEM.
Vulnerability managementDependency and container scanning in the build pipeline; regular security testing, with findings tracked to closure; timely patching of the platform.
Secure developmentCode review, automated tests and license checks before release; separation of test and production environments; deployment through version-controlled pipelines.
Backup and resilienceRegular encrypted backups within the Region; tested restoration; capacity to restore availability and access in a timely manner after an incident.
Incident responseDocumented incident-response process; customer notification without undue delay and within 48 hours under clause 10; post-incident review.
Data minimisation and retentionCustomer-controlled retention per project; deletion tools for documents, projects and accounts; redaction features for export.
Sub-processor managementWritten contracts, security assessment before engagement, published list with notice of changes.
PersonnelConfidentiality undertakings, background checks where lawful, data-protection and security training at onboarding and annually.
Business continuityMulti-replica deployment within the Region; documented recovery procedures.

Annex 3. Sub-processors

All Sub-processors that process Customer Content do so in the Region Customer selected. The list at docaifabric.com/docs/trust/subprocessors is authoritative and shows the current entry per Region.

Sub-processorPurposeLocation of processingTransfer safeguard
Microsoft Ireland Operations Ltd (Microsoft Azure)Compute, storage, queue, secrets, backups; OCR (Azure AI Document Intelligence); AI models for classification, extraction and the assistant (Azure OpenAI; Azure AI Foundry model catalogue, including Anthropic Claude where available in the Region)US Region: United States. Australia Region: Australia. EU Region: European Union. Support staff may access from Microsoft's global support locations under Microsoft's data-protection termsMicrosoft Products and Services DPA, EU-US Data Privacy Framework certification, SCCs
Resend, Inc.Transactional email (invitations, notifications, alerts). Receives recipient email addresses and message text only; never documents or extracted dataUnited StatesEU-US Data Privacy Framework and UK Extension (certified March 2025, participant 8907); SCCs where the DPF does not apply
Tally BVIn-app feedback and bug-report form. Receives only what a user types or attaches in the form, which loads only when openedBelgium (EU)Not a transfer (EU)

Our personnel (employees of AI Fabric Limited in the European Union, and individual contractors in the United States and Australia) are not Sub-processors but access Customer Content under clause 13.2; contractors outside the EEA are engaged under the SCCs, Module Three, as clause 13.4 states.

Annex 4. Standard Contractual Clauses: choices

Where clause 13.4 applies, the SCCs are incorporated with the following choices:

  • Module Two (controller to processor) where Customer is a controller; Module Three (processor to processor) where Customer is a processor.
  • Clause 7 (docking clause): included.
  • Clause 9 (sub-processors): Option 2, general written authorisation, with the notice period in clause 7.2 of this DPA.
  • Clause 11 (redress): the optional independent dispute-resolution language is not included.
  • Clause 13 and Clause 17 (governing law): the law of the Republic of Cyprus, an EU Member State whose law allows third-party beneficiary rights. This choice stands regardless of the law governing the Agreement (clause 15.4).
  • Clause 18 (forum): the courts of Cyprus.
  • Annex I.A (parties): Customer as data exporter, with the details in its account; AI Fabric Limited or the relevant Sub-processor as data importer.
  • Annex I.B (description of transfer): Annex 1 of this DPA.
  • Annex I.C (competent supervisory authority): the authority of the EU Member State where Customer is established, or, where Customer is outside the EU, the Cyprus Commissioner for Personal Data Protection.
  • Annex II (technical and organisational measures): Annex 2 of this DPA.
  • UK Addendum: Table 1 as above; Table 2, the SCCs with the choices above; Table 3, Annexes 1 to 3 of this DPA; Table 4, either party may end the UK Addendum as set out in its section 19.

Signature

Pre-signed on behalf of AI Fabric Limited.

Name: Nikita Tikhonov Title: Director Date: 1 October 2026

Customers requiring a countersigned copy:

For [Customer legal name]
Name:
Title:
Signature:
Date: