Data Processing Agreement

Last updated: 2026-08-09

1. Overview and parties

This Data Processing Agreement (“DPA”) forms part of the Dynamite Docs Terms of Service and governs the processing of personal data that Dynamite Docs (“Processor”) carries out on behalf of its customers (“Controller”) when the Controller uploads documents to the Service. This DPA reflects the parties’ agreement under the EU General Data Protection Regulation (GDPR), the UK GDPR, and comparable laws. Where the Service is used under a paid plan, this DPA is incorporated by reference into the applicable agreement between the parties. The private document AI guide maps these terms to browser storage, cloud files, provider routing, BYOK, and local inference.

2. Roles and responsibilities

The Controller determines the purposes and means of processing of the personal data contained in the documents it uploads. The Processor processes personal data only on the Controller’s documented instructions, as described in the Privacy Policy and these Terms, and never for its own independent purposes. The Processor will not use personal data to profile data subjects or for marketing.

3. Details of processing

  • Categories of data subjects. Individuals whose personal data appears in documents uploaded by the Controller (for example, signatories, customers, employees, or counterparties).
  • Categories of personal data. Names, contact details, identifiers, financial or other information contained in the documents the Controller chooses to upload and process.
  • Purposes. Providing the document extraction service requested by the Controller, including deterministic parsing, AI-based extraction, review, correction, storage, export, and support.
  • Special categories. The Controller must not upload documents containing special-category data (such as health, biometric, or trade-union data) without first enabling the appropriate policy controls and ensuring a lawful basis and appropriate safeguards exist.

4. Data subject rights

To the extent required by applicable law, the Processor will assist the Controller in responding to requests from data subjects exercising their rights (access, rectification, erasure, restriction, portability, and objection). The Controller may request erasure of documents and account data as described in the Privacy Policy, and the Processor will process such requests promptly and in any event within the time required by law.

5. Confidentiality and security

The Processor will maintain the confidentiality of personal data and ensure that its personnel who process personal data are subject to confidentiality obligations. The Processor applies appropriate technical and organizational measures, including encryption in transit (TLS) and at rest, encrypted storage of API keys, access controls on production systems, and security monitoring.

6. Sub-processing

The Processor uses subprocessors to provide the Service, including AI inference providers, hosting and storage providers, and email and analytics providers. The Processor remains responsible to the Controller for the acts and omissions of its subprocessors and obliges each subprocessor to protect personal data to the standard required by this DPA. The Controller may object to a new subprocessor by emailing info@dynamitedocs.com.

7. International data transfers

Where personal data is transferred outside the EEA or the UK, the Processor relies on appropriate safeguards, including Standard Contractual Clauses or adequacy decisions. On Pro and Ultra, the Controller can select provider, training-policy, and data-residency controls for AI inference in the AI settings panel.

8. Data breach notification

Upon becoming aware of a personal data breach affecting the Controller’s data, the Processor will notify the Controller without undue delay (and, where required by law, no later than 72 hours after becoming aware) and provide reasonable information to help the Controller comply with its own notification obligations.

9. Retention, deletion, and return

Personal data is retained while the Controller’s account is active and is removed when the Controller deletes it or requests deletion, as described in the Privacy Policy. On request, the Processor will delete or anonymize the Controller’s data within 30 days, except where law requires retention.

10. Audit

Upon written request and subject to confidentiality, the Processor will make available the information reasonably necessary to demonstrate compliance with this DPA, provided that on-premises or code-level audits are generally excluded and may only be agreed separately in writing.

11. Liability

Liability under this DPA is governed by the limitation of liability clause in the Terms of Service. Nothing in this DPA limits or excludes liability to the extent that such limitation or exclusion is prohibited by law.

12. Duration and termination

This DPA applies from the date the Controller first uses the Service and remains in effect until the Controller’s data is deleted in accordance with this DPA and the Privacy Policy, whichever is later. The Controller’s continued use of the Service after changes to this DPA constitutes acceptance of the revised terms.

13. Contact

DPA or data protection questions: info@dynamitedocs.com.

Open the Dynamite Docs app or return to the homepage.

Loading Dynamite Docs… This page is taking longer than expected. Reload page.