Legal
Data Processing Addendum
Processor terms for personal data in a DueFiles workspace.
Last updated 13 September 2026
This Data Processing Addendum ("DPA") is part of the Terms of Service or other agreement under which DueFiles provides the Service (the "Agreement"). If you need a signed copy, email privacy@duefiles.com with your legal entity name, notice address, and whether you require Standard Contractual Clauses.
Capitalized terms not defined here have the meaning in the Agreement or in applicable Data Protection Laws (including the GDPR, UK GDPR, and the CCPA/CPRA as a service-provider / processor relationship).
1. Roles
Customer is the controller (or a processor acting for a controller) of personal data submitted to the Service ("Customer Personal Data"). DueFiles is the processor (or sub-processor). Each party will comply with Data Protection Laws that apply to its role. Customer is responsible for the accuracy of Customer Personal Data and for providing all notices and obtaining all permissions required to submit it to the Service.
2. Details of processing
Subject matter: hosting and processing insurance-compliance documents and related workspace data. Duration: the term of the Agreement plus the deletion period in section 8. Nature and purpose: storage, retrieval, extraction, verification against Customer templates, reminders, audit logging, support, and security. Types of personal data: names, work contact details, signatures, addresses, taxpayer identifiers that appear on W-9s, driver's license numbers that appear on licenses, policy numbers, and other data that happens to appear on uploaded documents. Categories of data subjects: Customer's employees and contractors, vendors, subcontractors, brokers, and other third parties whose information Customer stores.
DueFiles does not intentionally collect special categories of data. Customer shall not submit such data unless a document image incidentally contains it, in which case it is processed only as part of that document.
3. Instructions
DueFiles will process Customer Personal Data only on documented instructions from Customer (including configuration in the Service and this DPA) unless required by law, in which case we will notify Customer unless legally prohibited. The Agreement, this DPA, and Customer's use of product controls are the complete instructions. Additional written instructions require our agreement and may be billed as professional services.
4. Confidentiality and personnel
People who process Customer Personal Data for DueFiles are bound by confidentiality and are limited to those who need access to provide the Service, support, or security.
5. Security
DueFiles will implement appropriate technical and organizational measures, taking into account the state of the art, cost, and the nature of the data. Current measures are described at /security and include encryption in transit and at rest, access control, tenant isolation, logging, and vulnerability management. Customer is responsible for user permissions inside the workspace and for protecting portal links it distributes.
6. Subprocessors
Customer authorizes DueFiles to engage subprocessors listed at /subprocessors. We will impose data-protection terms no less protective than this DPA. We remain responsible for subprocessors' performance. We will post material subprocessor changes and give Customer 15 days to object on reasonable data-protection grounds. If we cannot reasonably accommodate an objection, Customer may terminate the affected Service for a pro-rata refund of prepaid unused fees.
7. Assistance, rights requests, and DPIAs
Taking into account the nature of processing, DueFiles will assist Customer (through product controls where possible, otherwise on written request) with data-subject requests, DPIAs, and consultations with supervisory authorities. If we receive a request directly relating to Customer Personal Data, we will direct the person to Customer unless legally required to respond.
8. Breach notice, return, and deletion
DueFiles will notify Customer without undue delay, and in any event within 72 hours of becoming aware, of a personal-data breach affecting Customer Personal Data, and will provide information reasonably available to us to help Customer meet its own notice duties.
At termination, Customer may export data using product tools. Upon written request we will delete Customer Personal Data from production systems within 30 days, except copies retained as required by law or remaining in backups until expiry. Certification of deletion is available on request.
9. International transfers
Where a transfer of Customer Personal Data from the EEA, UK, or Switzerland to the United States (or another third country) requires a transfer tool, the parties enter the European Commission's Standard Contractual Clauses (Module 2 controller-to-processor, and Module 3 where Customer is a processor), including the UK IDTA addendum, with DueFiles as data importer. The clauses are completed with the details in this DPA and the subprocessor list. Customer authorizes DueFiles to enter SCCs with subprocessors on Customer's behalf as needed.
10. Audits
Upon reasonable written notice, no more than once per 12 months unless a supervisory authority or a documented breach requires more, Customer may request information reasonably necessary to demonstrate compliance with this DPA, including summaries of independent assessments we have. On-site audits are permitted if that information is insufficient, during business hours, under confidentiality, and at Customer's expense. We may reduce the scope to protect other customers.
11. Liability and order of precedence
Liability under this DPA is subject to the limitations in the Agreement. If this DPA conflicts with the Agreement on data-protection issues, this DPA controls. If SCCs conflict with this DPA, the SCCs control for the relevant transfer.
Last updated 13 September 2026.