Data Processing Agreement
Last updated: 18 June 2026 · Article 28 GDPR
This Data Processing Agreement (DPA) forms part of the Terms of Service between the firm ("Controller") and PaperOrg ("Processor"). It governs PaperOrg's processing of personal data on the firm's behalf. Where it conflicts with the Terms on data protection, this DPA prevails.
1. Roles
The firm is the Controller of the personal data in the documents and client records it uploads. PaperOrg is the Processor and processes that data only to provide the service.
2. Subject matter, nature & purpose
PaperOrg processes the Controller's data to ingest, store (encrypted), extract and validate accounting fields from, organise, and make securely accessible the documents the Controller uploads — for as long as the Controller uses the service.
3. Data & data subjects
Categories of data: identification and contact details, financial and accounting data (invoices, VAT, amounts, IBANs), and any personal data the Controller chooses to include in uploaded documents. Data subjects: the Controller's clients, their counterparties, and the Controller's own staff.
4. Processor obligations
- Process personal data only on the Controller's documented instructions, including the use of the service itself.
- Ensure personnel are bound by confidentiality.
- Implement the technical and organisational measures in the Annex (Article 32).
- Assist the Controller, as far as possible, with data-subject requests and with its security, breach and impact-assessment duties.
- Delete or return personal data at the end of the service, except where retention is legally required.
- Make available the information needed to demonstrate compliance.
5. Sub-processors
The Controller gives general authorisation for PaperOrg to engage the sub-processors listed in our Privacy Policy (EU hosting, Cloudflare R2 for encrypted storage and backups, Anthropic for AI extraction, and an EU email provider). PaperOrg imposes equivalent data-protection obligations on each, and gives reasonable notice of any intended addition or replacement so the Controller may object.
6. International transfers
Documents and backups are stored in the EU. Where a sub-processor processes data outside the EEA (e.g. AI extraction), the transfer is covered by EU Standard Contractual Clauses and appropriate safeguards. Document content sent for AI extraction is processed transiently and is not used to train models.
7. Security measures (Annex, Article 32)
- Encryption of documents at rest (XChaCha20-Poly1305) and of all traffic in transit (TLS).
- Default-deny access control: explicit, revocable, per-client and per-folder grants.
- Full audit logging of access and changes (who, what, when, from where).
- Two-factor authentication available for all accounts.
- Encrypted, off-site EU backups and tested recovery.
- Logical tenant isolation so one firm can never reach another firm's data.
8. Personal-data breach
PaperOrg will notify the Controller without undue delay after becoming aware of a personal-data breach affecting the Controller's data, with the information the Controller needs to meet its own notification duties.
9. Audit
On reasonable request and notice, PaperOrg will provide information to demonstrate compliance with this DPA and allow for audits, subject to confidentiality and to not compromising other firms' security.
10. Deletion & return
On termination, the Controller may export its documents for a reasonable period; thereafter PaperOrg deletes the Controller's personal data from active systems, and it rotates out of backups, unless retention is legally required.
Contact
Data-protection queries: dpo@paperorg.com.