# Zerodoc — Data Processing Agreement

**Version 1.0 · Last updated 2026-07-15**

This Data Processing Agreement ("DPA") forms part of the agreement between the customer
("Controller", "you") and Zerodoc, operated by an Isle of Man company ("Processor", "we"),
for use of the Zerodoc document-extraction API (the "Service").

## 1. Subject matter and roles

For customer documents submitted to the Service, you are the Controller and Zerodoc is the
Processor. We process such documents solely to provide the Service (OCR and structured
field extraction) on your instructions.

## 2. Nature and purpose of processing

- **Purpose:** extracting text and structured fields from documents you submit.
- **Processing model:** documents are processed **in memory only** and discarded immediately
  after the API response. No document or extracted content is written to disk or retained.
- **Duration:** the duration of each API request only.

## 3. Categories of data and data subjects

You determine the content of submitted documents and therefore the categories of personal
data they may contain (e.g. names, addresses, financial details on invoices). Because we do
not retain documents, we hold no record of these beyond the request lifecycle.

## 4. Data we retain (as Processor/Controller for account data)

We retain only: account email, a one-way hash of your API key, and usage metadata (page
counts, timestamps, status). We do not retain document content.

## 5. Sub-processors

| Sub-processor | Purpose | Location |
|---|---|---|
| Cloudflare | Auth, billing & usage metadata | EU data localization |
| Stripe | Payment processing | EU/US (SCCs) |
| Resend | Transactional email | EU/US (SCCs) |
| Hetzner | Stateless document processing | EU |

We will give notice of new sub-processors and provide an opportunity to object.

## 6. Security measures

- Documents processed in memory only; no disk persistence; in-memory buffers cleared on completion.
- TLS in transit; API keys stored only as SHA-256 hashes.
- Per-key rate limiting and quotas; least-privilege access to metadata systems.

## 7. International transfers

Document processing occurs in the EU. Where personal data is processed outside the UK/EEA by
a sub-processor, transfers are governed by Standard Contractual Clauses and/or the provider's
data-localization options.

## 8. Data subject requests & assistance

Because we do not retain documents, requests relating to document content are fulfilled by you
as Controller. We will assist with requests relating to account data we hold.

## 9. Breach notification

We will notify you without undue delay after becoming aware of a personal data breach affecting
data we process on your behalf.

## 10. Deletion

Documents are never retained, so there is nothing to delete post-processing. Account data is
deleted on request or on account closure, subject to legal retention requirements.

## 11. Audit

We will make available information reasonably necessary to demonstrate compliance, including
relevant certifications as our compliance programme matures (SOC 2 Type II is on our roadmap).

---

*Contact: privacy@zerodoc.io*
