Effective date: June 21, 2026
This Data Processing Addendum ("DPA") applies when DocsQA processes personal data on behalf of a customer through the DocsQA platform, including personal data contained in uploaded documents, widget conversations, playground chats, demo documents, and related service content.
This DPA supplements our Terms of Service and Privacy Policy. If there is a conflict, this DPA controls for customer personal data processed on behalf of the customer.
For customer-uploaded documents, widget conversations, and customer-controlled content, the customer is the controller or business responsible for deciding why and how the data is processed. DocsQA acts as a processor or service provider and processes that data only to provide, secure, maintain, and improve the DocsQA service.
For account registration, billing, security, fraud prevention, and platform operations,DocsQA may act as an independent controller as described in the Privacy Policy.
Customer instructs DocsQA to process customer personal data as necessary to provide DocsQA, including document parsing, indexing, retrieval, AI response generation, widget delivery, storage, support, troubleshooting, abuse prevention, and security monitoring.
Customer is responsible for ensuring that it has all required rights, consents, notices, and lawful basis to upload and process personal data through DocsQA.
Customer is also responsible for determining whether its use of DocsQA is subject to GDPR, UK GDPR, CCPA/CPRA, sector-specific privacy rules, employment data rules, or other local laws, and for configuring its website, notices, consent flows, and uploaded content accordingly.
DocsQA uses reasonable technical and organisational measures designed to protect customer personal data, including TLS encryption in transit, tenant isolation, role-based access controls, rate limiting, access-token controls, domain allowlists, operational logging, and restricted administrative access.
Security measures may evolve as the platform changes, but we will not materially reduce the overall protection of customer personal data during an active subscription.
Customer authorises DocsQA to use subprocessors needed to operate DocsQA, including AI inference, embedding, reranking, document parsing, hosting, database, cache, networking, payment, authentication, and transactional email providers.
We remain responsible for subprocessors processing customer personal data on our behalf and require them to process data only for the services they provide to DocsQA.
If DocsQA becomes aware of a security incident involving customer personal data, we will investigate, take reasonable containment steps, and notify affected customers without undue delay where required by applicable law.
On customer request, account closure, or document deletion, DocsQA will delete or make unavailable customer personal data according to product functionality and retention rules, subject to backups, audit logs, legal obligations, security needs, and dispute resolution.
Customer personal data may be processed in countries where DocsQA and its providers operate. Where legally required, DocsQA will use appropriate safeguards for international transfers, such as contractual protections, provider data processing terms, and transfer mechanisms required by applicable data protection laws.
If standard contractual clauses, a transfer impact review, or similar transfer support is required for a customer's jurisdiction, the customer should contact [email protected] so the appropriate commercial and legal terms can be reviewed.
Taking into account the nature of the service, DocsQA will provide reasonable assistance for customer privacy requests, security inquiries, and compliance questions sent to [email protected].