ProofSyncer

Controller–processor draft

Data Processing Addendum

Effective 3 September 2026. A review-ready DPA structure for business customers. It is not effective until completed and signed by the contracting parties. Qualified legal review remains required before paid general availability.

Parties and status

This is a review draft for a customer data-processing addendum. The customer is controller and ProofSyncer is processor for personal data submitted through customer documents and workflows. ProofSyncer remains controller for its own account, billing and security administration.

Subject, duration and purpose

Processing covers receiving, storing, extracting, validating, presenting, correcting, exporting, delivering and deleting customer documents and structured results for the subscription term plus the agreed return/deletion period.

Documented instructions

ProofSyncer processes customer personal data only on the customer's documented instructions, including workspace configuration, retention selection and enabled destinations, unless applicable law requires otherwise. ProofSyncer should notify the customer before legally required processing where permitted.

Data and people

Data may include names, business contact details, supplier/customer identifiers, addresses, invoice and shipment details, product and quality information, and other fields selected by the customer. Data subjects may include customer personnel, suppliers, customers, carriers and business contacts. Prohibited sensitive categories require a separate written assessment.

Confidentiality and access

Personnel and subprocessors with access must be bound by confidentiality and limited to what their role requires. Workspace roles, scoped API keys, encrypted connection credentials and audit records support this obligation.

Security measures

Technical measures include tenant authorization, role checks, bounded upload validation, opaque storage keys, signed source access, encryption for dedicated S3, server-side local PDF rendering, credential hashing/encryption, same-origin protection, rate limiting, idempotency, DNS-pinned HTTPS delivery and signed webhooks. The security schedule must be updated as controls change.

Subprocessors and transfers

ProofSyncer must maintain a named subprocessor register, provide advance notice of material additions, remain responsible for equivalent data-protection terms, and document lawful international-transfer safeguards. Those schedules require provider-location verification before execution.

Data-subject requests

Taking account of the processing, ProofSyncer will provide reasonable technical and organizational assistance for access, correction, deletion, restriction, portability and objection requests. The customer remains responsible for determining the response and communicating with the data subject.

Incidents and assessments

ProofSyncer will notify the customer without undue delay after confirming a personal-data breach affecting customer data and provide available information needed for legal notifications. Reasonable assistance for impact assessments and regulator consultation may be subject to the agreed order and fees.

Return and deletion

On request or termination, ProofSyncer will return available structured results and delete customer data according to the order, legal retention duties and storage mode. Verified physical source deletion requires dedicated storage; managed-reference revocation must not be described as verified byte deletion.

Audit information

ProofSyncer will provide current security documentation and reasonable audit cooperation under confidentiality and agreed frequency/scope. Independent certifications must not be claimed until obtained. Customer testing requires written authorization and rules of engagement.

Completion required

Before signature, counsel must add the parties, contact details, governing law, liability/order relationship, security schedule, named subprocessors, processing locations, transfer mechanism, return/deletion timing and any sector-specific requirements.