Last updated: September 2026
This Data Processing Agreement (“DPA”) forms part of the Terms of Service between [legal entity name] (“DocuCircuit,” the “Processor”) and the customer that accepts it (the “Controller”). It governs processing of personal data that the Controller’s users enter into DocuCircuit.
For customer content, the Controller is the controller and DocuCircuit is the processor.DocuCircuit processes personal data only on the Controller’s documented instructions, which include the Terms of Service, this DPA, and the configuration choices the Controller makes in the product (routing rules, retention period, the people it invites).
The Controller authorizes DocuCircuit to engage the sub-processors listed at /legal/subprocessors. DocuCircuit will update that page before adding or replacing a sub-processor and, on request, will notify the Controller so it can object on reasonable data-protection grounds. DocuCircuit remains responsible for its sub-processors’ performance of these obligations.
DocuCircuit will notify the Controller without undue delay after becoming aware of a personal data breach affecting the Controller’s content, and will provide the information the Controller reasonably needs to meet its own notification obligations.
Throughout the term, the Controller can export its complete record set from the product. On termination, the Controller may export within the grace period stated in the Terms; after that DocuCircuit will delete the Controller’s personal data, except (a) a single tamper-proof record that deletion occurred, and (b) data DocuCircuit is required by law to retain, which will remain protected and isolated. A legal hold placed by the Controller suspends deletion.
DocuCircuit will respond to the Controller’s reasonable written questions about its processing and security, no more than once per year absent a specific concern or a regulator’s request. As DocuCircuit matures it intends to provide a third-party security report (e.g. SOC 2) to satisfy audit rights.
Processing takes place in the United States. Where personal data of EEA or UK data subjects is transferred, the parties agree that the applicable Standard Contractual Clauses (and the UK International Data Transfer Addendum, where relevant) are incorporated into this DPA, with DocuCircuit as data importer and the Controller as data exporter. [Confirm module selection and annexes with counsel.]
Liability under this DPA is subject to the limitations in the Terms of Service. If this DPA conflicts with the Terms on the processing of personal data, this DPA controls.
Data-protection contact: wesleymaupin@gmail.com.