Data Processing Agreement
Version 2026-07-14 · Last updated: 14 July 2026
This DPA sets out how DocDrawer processes personal data on your behalf. It forms part of, and is subject to, the DocDrawer Terms & Conditions (the "Main Agreement").
Between: the Customer (the agency or letting business using DocDrawer) and DocDrawer Limited ("DocDrawer", "we", "us"), a company registered in England (company number 12730020), registered office Flass Hall, Esh, Durham, DH7 9QD.
Effective date: the date the Customer signs (or accepts via the in-app DPA confirmation) — the "DPA Effective Date".
1. Definitions
Terms not defined here have the meanings given in the UK GDPR and the Data Protection Act 2018.
- "Customer Personal Data" — personal data (as defined in UK GDPR Article 4) provided by the Customer to DocDrawer, or generated by the Customer's use of the Service, that DocDrawer processes on the Customer's behalf.
- "Sub-processor" — a third party engaged by DocDrawer to process Customer Personal Data in connection with the Service.
- "Personal Data Breach" — a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, Customer Personal Data.
2. Roles and scope of processing
The Customer is the Controller of Customer Personal Data. DocDrawer is the Processor.
DocDrawer processes Customer Personal Data only to the extent necessary to provide the Service, on documented instructions from the Customer. The Customer's use of the Service constitutes those instructions.
Subject matter
Property-management invoice handling, document storage, payment-instruction publishing, and related accounting workflow.
Duration
For the term of the Main Agreement, plus the retention period in §8.
Nature and purpose
Receiving supplier invoices, extracting structured data, routing approvals, publishing payment instructions to PayProp and your connected accounting platform (Xero, QuickBooks or Sage) on the Customer's behalf.
Categories of data subjects
- The Customer's staff (Owner, Manager, Publisher, Reviewer roles)
- The Customer's landlords (where the landlord portal is used)
- The Customer's suppliers / contractors
- Tenants of properties managed by the Customer (limited to names + property assignment; no rent or tenancy financials)
Types of personal data
- Names, email addresses, work phone numbers
- Property addresses
- Landlord / supplier names and (where stored by the Customer) Companies House registration numbers + VAT numbers
- Invoice content (which may incidentally contain personal data depending on the invoice)
- Sign-in records, audit timestamps, IP addresses, user-agent strings
Data explicitly NOT processed
- Full supplier bank account numbers — these are entered directly into PayProp by the Customer. DocDrawer's supplier-create flow strips bank-shaped fields before any data leaves the browser, and DocDrawer never writes bank details to PayProp. For fraud detection on inbound invoices, DocDrawer stores only the sort code (6 digits) and last 4 digits of the account number — the same shape PayProp's own API surfaces back to us. Full account numbers exist in memory only for the duration of the per-invoice mismatch check, then are discarded.
- Tenant deposit details / rent ledgers
- Special-category personal data (Article 9 UK GDPR)
3. DocDrawer's obligations
DocDrawer will:
- Process Customer Personal Data only on the Customer's documented instructions (use of the Service constitutes those instructions, subject to applicable law).
- Ensure that personnel authorised to process Customer Personal Data are bound by confidentiality.
- Take all measures required under UK GDPR Article 32 (security of processing) — see §5.
- Engage Sub-processors only under the conditions in §6.
- Assist the Customer in fulfilling its obligations to respond to data-subject rights requests (§7).
- Assist the Customer with its obligations under Articles 32–36 UK GDPR (security, breach notification, DPIA).
- Delete or return Customer Personal Data on termination, per §8.
- Make available the information necessary to demonstrate compliance with this DPA and allow for audits per §9.
4. Customer's obligations
The Customer warrants that:
- It has the lawful basis under UK GDPR Article 6 to instruct DocDrawer to process Customer Personal Data.
- Its data-subject privacy notices accurately describe DocDrawer's role.
- It will not instruct DocDrawer to process Customer Personal Data in a way that would breach UK GDPR or any other applicable law.
5. Security measures
DocDrawer implements the technical and organisational measures described on our security page, including but not limited to:
- Encryption in transit — TLS 1.2+ on every endpoint, HSTS enforced.
- Encryption at rest — AES-256-GCM on third-party OAuth tokens; AWS-managed AES-256 on the underlying database storage.
- Access control — mandatory two-factor authentication on every user account; role-based access at the company level; row-level security at the database layer.
- Logging and audit — sensitive administrative actions (impersonation, MFA reset, role changes) are recorded with the acting admin, target, timestamp, IP, and user-agent.
- Sub-processor restriction — sub-processors are limited to those listed in §6, each of which maintains its own appropriate security certifications.
- Vulnerability management — automated dependency scanning, code review on every change, and a full internal code-and-architecture security review.
DocDrawer will update these measures over time to maintain a level of security appropriate to the risk, and will not materially lower the level of security during the term of the Main Agreement.
6. Sub-processors
The Customer authorises DocDrawer to engage the Sub-processors listed on our security page for the purposes described there.
DocDrawer will:
- Notify the Customer of any new Sub-processor at least 30 days in advance, by email and via the sub-processor list on the security page.
- Impose data-protection obligations on each Sub-processor that are no less onerous than those in this DPA.
- Remain liable to the Customer for any failure by a Sub-processor to fulfil its obligations.
The Customer may object in writing to a new Sub-processor within 30 days of notification on reasonable, data-protection-related grounds. If DocDrawer cannot accommodate the objection, the Customer may terminate the Main Agreement on 30 days' notice.
Sub-processor list as of the DPA Effective Date
| Sub-processor | Purpose | Region |
| Amazon Web Services | Underlying compute and storage (via Supabase + Vercel) | EU (eu-west-2) |
| Supabase | Database, authentication, file storage | EU (eu-west-2) |
| Wasabi | Document storage and encrypted offsite backups (Object Lock Compliance, 30-day immutability) | EU |
| Vercel | Application hosting, serverless API runtime | EU + global edge |
| Resend | Transactional email (inbound and outbound) | EU + US |
| Anthropic | AI-assisted document extraction (Claude) | US |
| Plain | In-app customer support widget | EU + US |
| Sentry | Error tracking and observability (PII scrubbed) | EU |
| Upstash | Rate-limit counters (Redis); keyed by user ID / IP, no invoice or document content | EU |
| Voyage AI | Text embeddings of invoice content for supplier and property matching | US |
| PayProp | Property-management integration (customer-controlled) | EU + global |
| Xero | Accounting integration (customer-controlled) | EU + global |
| QuickBooks (Intuit) | Accounting integration (customer-controlled) | US + global |
| Sage | Accounting integration (customer-controlled) | EU + global |
7. Data-subject rights
If a data subject makes a request to DocDrawer that should be handled by the Customer (e.g. access, correction, deletion), DocDrawer will:
- Forward the request to the Customer without undue delay.
- Not respond to the request directly without the Customer's instruction, unless legally required.
- Provide reasonable assistance to enable the Customer to respond within the UK GDPR timeframe.
The Customer can export or delete its data at any time via the in-app tools or by emailing support@docdrawer.co.uk.
8. Retention, return, and deletion
- During the term of the Main Agreement, DocDrawer retains Customer Personal Data for as long as the Customer uses the Service.
- On termination, DocDrawer will (at the Customer's choice) either return or delete all Customer Personal Data within 90 days.
- Backups follow the retention schedule in DocDrawer's Disaster Recovery Plan (available on request): point-in-time recovery for 7 days, immutable offsite backups for 30 days.
- DocDrawer may retain Customer Personal Data after termination where legally required (e.g. for tax records under HMRC obligations).
9. Audits
DocDrawer will, on the Customer's reasonable request and no more than once per 12-month period, provide:
- A copy of its current security posture documentation (the security page + this DPA + the Disaster Recovery Plan).
- Any third-party penetration test report, where one has been carried out (redacted of confidential findings, with reasonable notice).
- Sub-processor SOC 2 reports where available (current list on the security page).
Where the above is insufficient to demonstrate compliance, the Customer may, at its own expense and on reasonable notice, audit DocDrawer's processing of Customer Personal Data. Audits must be conducted during business hours, with reasonable notice, and not unreasonably interfere with the Service.
10. Personal Data Breach notification
DocDrawer will notify the Customer without undue delay and within 72 hours of becoming aware of a Personal Data Breach affecting Customer Personal Data, by email to the Customer's nominated contact and via the security-page incident response process.
The notification will include:
- The nature of the breach, including categories and approximate numbers of affected data subjects and records
- The likely consequences
- The measures taken or proposed to address the breach and mitigate its possible adverse effects
DocDrawer will document each Personal Data Breach and make documentation available to the Customer on request.
11. International transfers
DocDrawer processes Customer Personal Data primarily in the United Kingdom and the European Economic Area. Where processing occurs outside the UK / EEA (e.g. Anthropic and other US-based Sub-processors), DocDrawer relies on:
- The UK Government's data-adequacy decisions where in force; OR
- The UK International Data Transfer Addendum to the EU Standard Contractual Clauses (IDTA) signed with the relevant Sub-processor.
12. Liability
DocDrawer's liability under this DPA is subject to the limitations in the Main Agreement.
13. Governing law
This DPA is governed by the laws of England and Wales. Disputes are subject to the exclusive jurisdiction of the English courts.
14. Order of precedence
In the event of a conflict between this DPA and the Main Agreement, this DPA prevails to the extent of the conflict in relation to the processing of Customer Personal Data.
How to sign
Email privacy@docdrawer.co.uk with the subject DPA — [your company name]. DocDrawer will counter-sign and return a PDF for your records. Most customers find an email exchange referencing this DPA is sufficient; an e-signature is available on request.