d2adoc2api

Data Processing Addendum

Effective 26 July 2026

This addendum applies whenever Datavanta Labs Limited processes personal data on your behalf through doc2api. It forms part of our Terms of Service, and takes effect automatically when you use the Service to process personal data — you do not need to sign anything for it to apply.

If your procurement process needs a countersigned copy, or your own paper with specific clauses, email privacy@doc2api.co.

1.Roles and scope

For the personal data inside your documents and form submissions, you are the controller and we are the processor. You decide what data is collected, from whom, and why; we process it to provide the Service, following your instructions. Configuring a template, embedding a form, calling the API and setting up a webhook are all instructions.

For our own account, billing, security and usage records we act as controller — that is covered by the Privacy Policy, not this addendum.

“Personal data”, “processing”, “controller”, “processor” and “data subject” carry the meanings given in the GDPR, and equivalent meanings under other applicable data protection law.

2.Our obligations

  • We process personal data only to provide the Service and only on your instructions, unless the law requires otherwise — in which case we will tell you first, if we are permitted to.
  • We do not sell your data, and we do not use it to train machine-learning models.
  • We keep it confidential, and only people who need access to run the Service have it, under confidentiality obligations.
  • We maintain the technical and organisational measures in Annex II, and will not materially weaken them during the term.
  • We help you meet your own obligations — responding to data subject requests, carrying out impact assessments, and demonstrating compliance — and will give you the information you reasonably need for that.
  • We tell you without undue delay if we become aware of a personal data breach affecting your data, with what we know and what we are doing about it.
  • If we believe an instruction from you breaches data protection law, we will tell you.

3.Your obligations

  • You have a lawful basis for the data you collect through the Service, and you have given the people concerned the notices their law requires.
  • Your instructions to us are lawful, and your use does not require us to do anything we have not agreed to.
  • You keep your API keys secure and control who has access to your workspace, and you configure the embed origin allowlist if you need embedding restricted.
  • You do not put data through the Service that it is not built for — payment card data, or health information subject to HIPAA. See the Privacy Policy.
  • You are responsible for what happens to a document once it reaches your webhook endpoint or someone you gave a signed URL to.

4.Sub-processors

You authorise us to use the sub-processors in Annex III to provide the Service. We impose data protection obligations on each of them no less protective than this addendum, and we remain responsible to you for their performance.

We will give notice before adding or replacing a sub-processor — by updating Annex III and, where the change is material, by email to your account address. If you have a reasonable objection on data protection grounds, tell us within 30 days and we will work with you on an alternative; if there is none, you may stop using the affected feature or terminate the affected subscription without penalty for the unused period.

5.Data subject requests

The Service gives you direct access to the data you hold in it: you can read, export and delete templates and submission records yourself from the dashboard and the API, which is usually the fastest way to satisfy a request. If someone contacts us directly about data that belongs to your workspace, we will not respond on your behalf — we will refer them to you and tell you about it. Where you need help we cannot provide through the product, email privacy@doc2api.co.

6.International transfers

Our sub-processors operate internationally, so personal data may be processed outside your country, including outside the EEA and the UK. Where personal data is transferred out of those regions, the transfer is made under an appropriate safeguard — typically the European Commission’s Standard Contractual Clauses (with the UK Addendum where relevant), which are incorporated into this addendum by reference for those transfers. Annex I and Annex II supply the details those clauses require.

7.Audits and information

On reasonable written request, and no more than once a year unless a supervisory authority or a breach requires otherwise, we will provide the information you need to verify our compliance with this addendum. We will answer a reasonable security questionnaire rather than granting physical access to infrastructure we do not own.

8.Deletion and return

You can delete data at any time from the dashboard or the API. Retention periods are set out in Annex I. When your account closes we delete the personal data we process for you within a commercially reasonable period, except where the law requires us to keep it, and backups age out on their own cycle. Ask before you close the account if you need an export.

9.Liability and precedence

The liability limits in the Terms of Service apply to this addendum. If this addendum conflicts with those terms on the processing of personal data, this addendum governs. If it conflicts with the Standard Contractual Clauses where those apply, the Clauses govern.

10.Annex I — details of the processing

Subject matterProvision of doc2api: storing your documents, filling and rendering them, running your embedded forms and delivering results to you.
DurationFor as long as your account is open, plus the retention periods below.
Nature and purposeStorage, rendering, form-filling, signature stamping and cryptographic signing, watermarking (trial workspaces), webhook delivery, and — where enabled for your workspace — AI-assisted field detection on documents you run it on.
Categories of data subjectWhoever your forms are about or completed by — your customers, patients, clients, employees or applicants. We have no direct relationship with them.
Types of personal dataWhatever your documents contain. Typically names, contact details, dates of birth, identifiers and reference numbers, signatures, and free text. Plus any extra params you attach to a submission.
Special category dataOnly if your documents contain it (health data on a medical form, for example). You decide whether to put it through the Service and are responsible for the lawful basis; we apply the same measures to it as to all document data.
RetentionTemplates and documents until you delete them. Submission records by plan: Free 1 day, Starter 7 days, Pro 90 days, Business until you delete it. Trial workspaces 24 hours. PDFs linked from a webhook delivery 24 hours.
FrequencyContinuous, for as long as you use the Service.

11.Annex II — technical and organisational measures

  • Encryption in transit for all traffic; documents stored in private storage, never public buckets.
  • Access to a document only through an authenticated request or a short-lived signed URL that expires.
  • Workspace isolation, with every request checked against the workspace that owns the template, plus row-level security in the database.
  • Separate per-template keys for filling, browser embedding and administration, each independently rotatable with immediate effect.
  • Optional origin allowlisting for embedded forms, enforced by both a frame-ancestors policy and key-origin checks.
  • HMAC-signed webhook deliveries with per-endpoint secrets, and validation of outbound URLs to prevent the Service being pointed at private or internal addresses.
  • Rate limiting and per-plan quotas to bound abuse.
  • Security headers on application responses; administrative pages are not embeddable.
  • Automated deletion of trial workspaces, expired webhook files, and submissions past their retention window.
  • Error monitoring configured not to collect personal data.
  • Least-privilege access for our own staff, under confidentiality obligations.

12.Annex III — sub-processors

Sub-processorPurposePersonal data processed
SupabaseDatabase, file storage and authenticationAccount details, uploaded documents, submitted field values, API keys
VercelApplication hosting and content deliveryRequest metadata (IP address, user agent) and anything in transit
SentryError monitoringError reports and stack tracesConfigured with personal data collection switched off (sendDefaultPii: false)
BrevoTransactional email (sign-in and account notices)Email address
AnthropicAI field detectionPage images and text of the document being analysedOnly when AI detection is enabled for your workspace, and only for documents you run it on

This list is current as of the effective date at the top of this page.