DCDocuCircuit← Home
Legal

Data Processing Agreement

Last updated: September 2026

Draft for review. This is a starting point, not a lawyer-reviewed agreement. Fill the bracketed items and have counsel adapt it — especially the SCC / UK Addendum mechanics and any jurisdiction-specific terms — before signing a customer.

This Data Processing Agreement (“DPA”) forms part of the Terms of Service between [legal entity name] (“DocuCircuit,” the “Processor”) and the customer that accepts it (the “Controller”). It governs processing of personal data that the Controller’s users enter into DocuCircuit.

1. Roles

For customer content, the Controller is the controller and DocuCircuit is the processor.DocuCircuit processes personal data only on the Controller’s documented instructions, which include the Terms of Service, this DPA, and the configuration choices the Controller makes in the product (routing rules, retention period, the people it invites).

2. Subject matter, duration, nature and purpose

  • Subject matter: provision of the DocuCircuit recurring-forms and reporting service.
  • Duration: for the term of the subscription, plus the deletion period in section 8.
  • Nature and purpose: storing, organizing, routing, and displaying the Controller’s inspection and reporting records; sending transactional email; producing and retaining electronic-signature evidence.

3. Types of personal data and data subjects

  • Data subjects: the Controller’s employees, contractors, and other workers it invites or who are named in its records.
  • Personal data: name, work email, organizational role and department; content the user enters into forms; electronic-signature evidence (account, typed name, server timestamp, IP address, browser, and — if the device permits — approximate location); activity-log entries (actor, action, timestamp, IP).
  • Special-category data: incident and near-miss reports may contain information about injuries or health. The Controller is responsible for having a lawful basis and any required safeguards for entering such data.

4. Processor obligations

  • Process personal data only on the Controller’s documented instructions.
  • Ensure that personnel authorized to process personal data are bound by confidentiality.
  • Implement the technical and organizational measures in section 6.
  • Not use customer content to train AI models or to build features for other customers, and not sell personal data.
  • Assist the Controller, taking into account the nature of processing, with data-subject requests, security, breach notification, and data-protection impact assessments.
  • Make available information needed to demonstrate compliance and allow for audits (see section 9).

5. Sub-processors

The Controller authorizes DocuCircuit to engage the sub-processors listed at /legal/subprocessors. DocuCircuit will update that page before adding or replacing a sub-processor and, on request, will notify the Controller so it can object on reasonable data-protection grounds. DocuCircuit remains responsible for its sub-processors’ performance of these obligations.

6. Security measures

  • Encryption of personal data in transit (TLS) and at rest.
  • Logical isolation of each Controller’s data, enforced in the application on every query.
  • Append-only storage with a cryptographic integrity seal for signed records and the activity log, so unauthorized alteration is detectable.
  • Passwordless authentication; role-based access within each organization.
  • Least-privilege administrative access; access and change logging.
  • Regular backups with point-in-time recovery of the database.

7. Personal data breach

DocuCircuit will notify the Controller without undue delay after becoming aware of a personal data breach affecting the Controller’s content, and will provide the information the Controller reasonably needs to meet its own notification obligations.

8. Return and deletion

Throughout the term, the Controller can export its complete record set from the product. On termination, the Controller may export within the grace period stated in the Terms; after that DocuCircuit will delete the Controller’s personal data, except (a) a single tamper-proof record that deletion occurred, and (b) data DocuCircuit is required by law to retain, which will remain protected and isolated. A legal hold placed by the Controller suspends deletion.

9. Audits

DocuCircuit will respond to the Controller’s reasonable written questions about its processing and security, no more than once per year absent a specific concern or a regulator’s request. As DocuCircuit matures it intends to provide a third-party security report (e.g. SOC 2) to satisfy audit rights.

10. International transfers

Processing takes place in the United States. Where personal data of EEA or UK data subjects is transferred, the parties agree that the applicable Standard Contractual Clauses (and the UK International Data Transfer Addendum, where relevant) are incorporated into this DPA, with DocuCircuit as data importer and the Controller as data exporter. [Confirm module selection and annexes with counsel.]

11. Liability and precedence

Liability under this DPA is subject to the limitations in the Terms of Service. If this DPA conflicts with the Terms on the processing of personal data, this DPA controls.

12. Contact

Data-protection contact: wesleymaupin@gmail.com.

Your dataPrivacy PolicyTerms of ServiceData Processing AgreementSub-processors