DocDrawer

Data Processing Agreement

Version 2026-07-14 · Last updated: 14 July 2026

This DPA sets out how DocDrawer processes personal data on your behalf. It forms part of, and is subject to, the DocDrawer Terms & Conditions (the "Main Agreement").

Between: the Customer (the agency or letting business using DocDrawer) and DocDrawer Limited ("DocDrawer", "we", "us"), a company registered in England (company number 12730020), registered office Flass Hall, Esh, Durham, DH7 9QD.
Effective date: the date the Customer signs (or accepts via the in-app DPA confirmation) — the "DPA Effective Date".

1. Definitions

Terms not defined here have the meanings given in the UK GDPR and the Data Protection Act 2018.

2. Roles and scope of processing

The Customer is the Controller of Customer Personal Data. DocDrawer is the Processor.

DocDrawer processes Customer Personal Data only to the extent necessary to provide the Service, on documented instructions from the Customer. The Customer's use of the Service constitutes those instructions.

Subject matter

Property-management invoice handling, document storage, payment-instruction publishing, and related accounting workflow.

Duration

For the term of the Main Agreement, plus the retention period in §8.

Nature and purpose

Receiving supplier invoices, extracting structured data, routing approvals, publishing payment instructions to PayProp and your connected accounting platform (Xero, QuickBooks or Sage) on the Customer's behalf.

Categories of data subjects

Types of personal data

Data explicitly NOT processed

3. DocDrawer's obligations

DocDrawer will:

4. Customer's obligations

The Customer warrants that:

5. Security measures

DocDrawer implements the technical and organisational measures described on our security page, including but not limited to:

DocDrawer will update these measures over time to maintain a level of security appropriate to the risk, and will not materially lower the level of security during the term of the Main Agreement.

6. Sub-processors

The Customer authorises DocDrawer to engage the Sub-processors listed on our security page for the purposes described there.

DocDrawer will:

The Customer may object in writing to a new Sub-processor within 30 days of notification on reasonable, data-protection-related grounds. If DocDrawer cannot accommodate the objection, the Customer may terminate the Main Agreement on 30 days' notice.

Sub-processor list as of the DPA Effective Date

Sub-processorPurposeRegion
Amazon Web ServicesUnderlying compute and storage (via Supabase + Vercel)EU (eu-west-2)
SupabaseDatabase, authentication, file storageEU (eu-west-2)
WasabiDocument storage and encrypted offsite backups (Object Lock Compliance, 30-day immutability)EU
VercelApplication hosting, serverless API runtimeEU + global edge
ResendTransactional email (inbound and outbound)EU + US
AnthropicAI-assisted document extraction (Claude)US
PlainIn-app customer support widgetEU + US
SentryError tracking and observability (PII scrubbed)EU
UpstashRate-limit counters (Redis); keyed by user ID / IP, no invoice or document contentEU
Voyage AIText embeddings of invoice content for supplier and property matchingUS
PayPropProperty-management integration (customer-controlled)EU + global
XeroAccounting integration (customer-controlled)EU + global
QuickBooks (Intuit)Accounting integration (customer-controlled)US + global
SageAccounting integration (customer-controlled)EU + global

7. Data-subject rights

If a data subject makes a request to DocDrawer that should be handled by the Customer (e.g. access, correction, deletion), DocDrawer will:

The Customer can export or delete its data at any time via the in-app tools or by emailing support@docdrawer.co.uk.

8. Retention, return, and deletion

9. Audits

DocDrawer will, on the Customer's reasonable request and no more than once per 12-month period, provide:

Where the above is insufficient to demonstrate compliance, the Customer may, at its own expense and on reasonable notice, audit DocDrawer's processing of Customer Personal Data. Audits must be conducted during business hours, with reasonable notice, and not unreasonably interfere with the Service.

10. Personal Data Breach notification

DocDrawer will notify the Customer without undue delay and within 72 hours of becoming aware of a Personal Data Breach affecting Customer Personal Data, by email to the Customer's nominated contact and via the security-page incident response process.

The notification will include:

DocDrawer will document each Personal Data Breach and make documentation available to the Customer on request.

11. International transfers

DocDrawer processes Customer Personal Data primarily in the United Kingdom and the European Economic Area. Where processing occurs outside the UK / EEA (e.g. Anthropic and other US-based Sub-processors), DocDrawer relies on:

12. Liability

DocDrawer's liability under this DPA is subject to the limitations in the Main Agreement.

13. Governing law

This DPA is governed by the laws of England and Wales. Disputes are subject to the exclusive jurisdiction of the English courts.

14. Order of precedence

In the event of a conflict between this DPA and the Main Agreement, this DPA prevails to the extent of the conflict in relation to the processing of Customer Personal Data.

How to sign

Email privacy@docdrawer.co.uk with the subject DPA — [your company name]. DocDrawer will counter-sign and return a PDF for your records. Most customers find an email exchange referencing this DPA is sufficient; an e-signature is available on request.