← Back to DocSentinel

Data Processing Agreement

For Enterprise Customers | January 2026

This Data Processing Agreement ("DPA") governs the processing of Personal Data by DocSentinel Limited ("Processor") on behalf of the Customer ("Controller").

1. Scope and Purpose

The Processor shall process Personal Data only for the purpose of providing the Services and in accordance with the Controller's documented instructions.

2. Processor Obligations

2.1 Security Measures

We implement appropriate technical and organizational measures, including:

2.2 Sub-processors

We engage the following authorized sub-processors:

Sub-processor Purpose Location
Google Cloud Infrastructure EEA (Belgium, Germany)
Supabase Database/Auth EEA (Belgium, Germany)
Vertex AI AI Processing EU

2.3 Breach Notification

We will notify you without undue delay (within 48 hours) of any Personal Data breach and assist with your notification obligations.

3. Data Transfers

Personal Data is processed within the European Economic Area (EEA). We will not transfer data outside the EEA without your consent and appropriate safeguards.

4. Data Retention

Upon termination, you may request the return of your data within 30 days, after which it will be securely deleted.

This is a summary of our standard DPA. To sign a formal DPA, please contact legal@docsentinel.io.