Data Processing Addendum
Effective 26 July 2026
This addendum applies whenever Datavanta Labs Limited processes personal data on your behalf through Doc2api. It forms part of our Terms of Service, and takes effect automatically as soon as you use the Service to process personal data. You don’t need to sign anything for it to apply.
If your procurement process needs a countersigned copy, or your own paper with specific clauses, email privacy@doc2api.co.
1.Roles and scope
For the personal data inside your documents and form submissions, you’re the controller and we’re the processor. You decide what data is collected, from whom, and why; we process it to provide the Service, following your instructions. Configuring a template, embedding a form, calling the API and setting up a webhook are all instructions.
For our own account, billing, security and usage records we act as controller — that’s covered by the Privacy Policy, not this addendum.
“Personal data”, “processing”, “controller”, “processor” and “data subject” carry the meanings given in the GDPR, and equivalent meanings under other applicable data protection law.
2.Our obligations
- We process personal data only to provide the Service and only on your instructions, unless the law requires otherwise, in which case we’ll tell you first, if we’re permitted to.
- We don’t sell your data, and we don’t use it to train machine-learning models.
- We keep it confidential, and only people who need access to run the Service have it, under confidentiality obligations.
- We maintain the technical and organisational measures in Annex II, and won’t materially weaken them during the term.
- We help you meet your own obligations, from responding to data subject requests, carrying out impact assessments, and demonstrating compliance, and will give you the information you reasonably need for that.
- We tell you without undue delay if we become aware of a personal data breach affecting your data, with what we know and what we’re doing about it.
- If we believe an instruction from you breaches data protection law, we’ll tell you.
3.Your obligations
- You have a lawful basis for the data you collect through the Service, and you’ve given the people concerned the notices their law requires.
- Your instructions to us are lawful, and your use doesn’t require us to do anything we’ve not agreed to.
- You keep your API keys secure and control who has access to your workspace, and you configure the embed origin allowlist if you need embedding restricted.
- You don’t put data through the Service that it’s not built for: payment card data, or health information subject to HIPAA. See the Privacy Policy.
- You are responsible for what happens to a document once it reaches your webhook endpoint or someone you gave a signed URL to.
4.Sub-processors
You authorise us to use the sub-processors in Annex III to provide the Service. We impose data protection obligations on each of them no less protective than this addendum, and we remain responsible to you for their performance.
We’ll give notice before adding or replacing a sub-processor, by updating Annex III and, where the change is material, by email to your account address. If you have a reasonable objection on data protection grounds, tell us within 30 days and we’ll work with you on an alternative; if there’s none, you may stop using the affected feature or terminate the affected subscription without penalty for the unused period.
5.Data subject requests
The Service gives you direct access to the data you hold in it: you can read, export and delete templates and submission records yourself from the dashboard and the API, which is usually the fastest way to satisfy a request. If someone contacts us directly about data that belongs to your workspace, we won’t respond on your behalf — we’ll refer them to you and tell you about it. Where you need help we can’t provide through the product, email privacy@doc2api.co.
6.International transfers
Our sub-processors operate internationally, so personal data may be processed outside your country, including outside the EEA and the UK. Where personal data is transferred out of those regions, the transfer is made under an appropriate safeguard, typically the European Commission’s Standard Contractual Clauses (with the UK Addendum where relevant), which are incorporated into this addendum by reference for those transfers. Annex I and Annex II supply the details those clauses require.
7.Audits and information
On reasonable written request, and no more than once a year unless a supervisory authority or a breach requires otherwise, we’ll provide the information you need to verify our compliance with this addendum. We’ll answer a reasonable security questionnaire rather than granting physical access to infrastructure we don’t own.
8.Deletion and return
You can delete data at any time from the dashboard or the API. Retention periods are set out in Annex I. When your account closes we delete the personal data we process for you within a commercially reasonable period, except where the law requires us to keep it, and backups age out on their own cycle. Ask before you close the account if you need an export.
9.Liability and precedence
The liability limits in the Terms of Service apply to this addendum. If this addendum conflicts with those terms on the processing of personal data, this addendum governs. If it conflicts with the Standard Contractual Clauses where those apply, the Clauses govern.
10.Annex I — details of the processing
| Subject matter | Provision of Doc2api: storing your documents, filling and rendering them, running your embedded forms and delivering results to you. |
| Duration | For as long as your account is open, plus the retention periods below. |
| Nature and purpose | Storage, rendering, form-filling, signature stamping and cryptographic signing, watermarking (trial workspaces), webhook delivery, and (where enabled for your workspace) AI-assisted field detection on documents you run it on. |
| Categories of data subject | Whoever your forms are about or completed by: your customers, patients, clients, employees or applicants. We have no direct relationship with them. |
| Types of personal data | Whatever your documents contain. Typically names, contact details, dates of birth, identifiers and reference numbers, signatures, and free text. Plus any extra params you attach to a submission. |
| Special category data | Only if your documents contain it (health data on a medical form, for example). You decide whether to put it through the Service and are responsible for the lawful basis; we apply the same measures to it as to all document data. |
| Retention | Templates and documents until you delete them. Submission records by plan: Free 3 days, Starter 7 days, Pro 30 days, Business 90 days. Trial workspaces 24 hours. PDFs linked from a webhook delivery 24 hours. |
| Frequency | Continuous, for as long as you use the Service. |
11.Annex II — technical and organisational measures
- Encryption in transit for all traffic; documents stored in private storage, never public buckets.
- Access to a document only through an authenticated request or a short-lived signed URL that expires.
- Workspace isolation, with every request checked against the workspace that owns the template, plus row-level security in the database.
- Separate per-template keys for filling, browser embedding and administration, each independently rotatable with immediate effect.
- Optional origin allowlisting for embedded forms, enforced by both a frame-ancestors policy and key-origin checks.
- HMAC-signed webhook deliveries with per-endpoint secrets, and validation of outbound URLs to prevent the Service being pointed at private or internal addresses.
- Rate limiting and per-plan quotas to bound abuse.
- Security headers on application responses; administrative pages aren’t embeddable.
- Automated deletion of trial workspaces, expired webhook files, and submissions past their retention window.
- Error monitoring configured not to collect personal data.
- Least-privilege access for our own staff, under confidentiality obligations.
12.Annex III — sub-processors
| Sub-processor | Purpose | Personal data processed |
|---|---|---|
| Supabase | Database, file storage and authentication | Account details, uploaded documents, submitted field values, API keys |
| Vercel | Application hosting and content delivery | Request metadata (IP address, user agent) and anything in transit |
| Sentry | Error monitoring | Error reports and stack tracesConfigured with personal data collection switched off (sendDefaultPii: false) |
| Brevo | Welcome email, team invitations, and our mailing list | Email address; on an invitation, the name of the person inviting you and the name of their workspaceCreating an account adds your address to our mailing list — every message has an unsubscribe link |
| Paddle | Merchant of record: checkout, payment, invoicing, and sales tax | Email address, billing name and address, and payment detailsPaddle sells the subscription to you and is who your card is charged by. Card details go straight to them and are never held by us |
| Anthropic | AI field detection | Page images and text of the document being analysedOnly when AI detection is enabled for your workspace, and only for documents you run it on |
This list is current as of the effective date at the top of this page.
Datavanta Labs Limited · RC 7395140 · Ikeja, Lagos, Nigeria