Data Processing Agreement

Version 1.0 · Last updated 2026-07-15

This Data Processing Agreement (“DPA”) forms part of the agreement between the customer (“Controller”, “you”) and Zerodoc, operated by an Isle of Man company (“Processor”, “we”), for use of the Zerodoc document-extraction API (the “Service”).

Download (Markdown)

1. Subject matter and roles

For customer documents submitted to the Service, you are the Controller and Zerodoc is the Processor. We process such documents solely to provide the Service (OCR and structured field extraction) on your instructions.

2. Nature and purpose of processing

  • Purpose: extracting text and structured fields from documents you submit.
  • Processing model: documents are processed in memory only and discarded immediately after the API response. No document or extracted content is written to disk or retained.
  • Duration: the duration of each API request only.

3. Categories of data and data subjects

You determine the content of submitted documents and therefore the categories of personal data they may contain (e.g. names, addresses, financial details on invoices). Because we do not retain documents, we hold no record of these beyond the request lifecycle.

4. Data we retain (as Processor/Controller for account data)

We retain only: account email, a one-way hash of your API key, and usage metadata (page counts, timestamps, status). We do not retain document content.

5. Sub-processors

Sub-processorPurposeLocation
CloudflareAuth, billing & usage metadataEU data localization
StripePayment processingEU/US (SCCs)
ResendTransactional emailEU/US (SCCs)
HetznerStateless document processingEU

We will give notice of new sub-processors and provide an opportunity to object.

6. Security measures

  • Documents processed in memory only; no disk persistence; in-memory buffers cleared on completion.
  • TLS in transit; API keys stored only as SHA-256 hashes.
  • Per-key rate limiting and quotas; least-privilege access to metadata systems.

7. International transfers

Document processing occurs in the EU. Where personal data is processed outside the UK/EEA by a sub-processor, transfers are governed by Standard Contractual Clauses and/or the provider’s data-localization options.

8. Data subject requests & assistance

Because we do not retain documents, requests relating to document content are fulfilled by you as Controller. We will assist with requests relating to account data we hold.

9. Breach notification

We will notify you without undue delay after becoming aware of a personal data breach affecting data we process on your behalf.

10. Deletion

Documents are never retained, so there is nothing to delete post-processing. Account data is deleted on request or on account closure, subject to legal retention requirements.

11. Audit

We will make available information reasonably necessary to demonstrate compliance, including relevant certifications as our compliance programme matures (SOC 2 Type II is on our roadmap).

Questions or execution requests: privacy@zerodoc.io. See also our Privacy Policy and Security pages.