Data processing
Data Processing Addendum
The contractual commitments that apply when Doqubox processes personal data on behalf of your organization.
Last updated: 6 October 2026
1. Purpose and status
This DPA forms part of the terms of service between the customer organization and Aer Software Solutions B.V. (Doqubox, KvK 27332530). It governs processing on the customer's behalf under Article 28 GDPR and takes precedence over conflicting terms on that processing.
2. Parties and roles
- Customer: controller for personal data processed on its behalf.
- Doqubox: processor for documents, metadata, recipient verification, workspace users, permissions, activity records, and security supporting that processing.
- Outside this DPA: Doqubox is an independent controller for its own customer relationships, billing, legal obligations, website analytics, and platform security and abuse prevention where it independently determines the purposes.
3. Subject matter and duration
Processing includes receiving, storing, transmitting, retrieving, and deleting documents and related data for document exchange, requests, verification, retention, notifications, and support. It lasts for the customer relationship and the period needed for deletion or legally required storage.
4. Processing instructions
Doqubox processes personal data only on documented customer instructions, including the agreement, product settings, user actions, and support requests. This includes transfers outside the EEA.
Processing required by Union or Member State law is permitted; Doqubox will inform the customer beforehand unless legally prohibited. If an instruction appears to infringe GDPR or other Union or Member State data-protection law, Doqubox will immediately inform the customer and suspend that instruction pending resolution.
5. Data subjects and data categories
Data subjects include workspace users, senders, recipients, and people named in customer documents, such as clients, employees, applicants, patients, and suppliers.
Data includes files and metadata, contact and user details, roles, document requests, messages, verification records, activity logs, and support communications processed for the customer. The customer determines the document content.
6. Security measures
Doqubox applies risk-appropriate technical and organizational measures under Article 32 GDPR: end-to-end encryption of files and their metadata, encryption in transit and encrypted file storage, access controls, passkeys, retention controls, and monitoring. See the security page.
7. Confidentiality
Authorized personnel are bound by confidentiality and receive access only as needed for their duties.
8. Subprocessors
The customer gives general written authorization for the subprocessors in the subprocessor list. Doqubox imposes the same data-protection obligations on them by written agreement and remains fully responsible for their performance.
Doqubox will email account administrators at their registered addresses at least 14 calendar days before adding or replacing a subprocessor or changing its processing locations. The notice describes the change, proposed start date, and information needed to assess it. This also covers subprocessors engaged by our subprocessors for customer data. Doqubox also updates the public list; this does not replace email notice.
If a subprocessor gives insufficient notice, Doqubox will notify customers without delay and suspend the affected processing where possible to give them the full notice and objection periods. Where suspension is not possible, the customer may terminate the affected subscription with immediate effect by emailing support@doqubox.com, without penalty and with a refund of prepaid fees for the period after termination.
Customers may object within 14 calendar days of the notice by emailing support@doqubox.com with their data-protection concerns. Without an objection, the change is authorized after that period. Doqubox will seek a workable solution and will not apply the disputed change to that customer's data while the objection remains unresolved, suspending affected processing where possible.
If no solution is agreed within 14 calendar days after Doqubox receives the objection, the affected subscription ends without penalty at that deadline, unless the customer withdraws its objection. Doqubox will confirm the deadline when acknowledging the objection by email, allowing the customer to retrieve data before termination. Ordinary cancellation deadlines do not apply; prepaid fees for the period after termination are refunded.
9. Data subject requests
Taking account of the processing, Doqubox will assist the customer, through appropriate technical and organizational measures insofar as possible, with requests to exercise data-subject rights. It will promptly forward requests it receives and assist through account functions and relevant records. The customer decides how to respond.
10. Personal data breaches and compliance assistance
Doqubox will notify affected customers without undue delay after becoming aware of a personal data breach. It will provide available details of affected data, likely consequences, and remedial measures, with updates as information becomes available.
Taking account of the processing and information available, Doqubox will assist with GDPR Articles 32-36: security, breach notifications, data protection impact assessments, and prior consultation with supervisory authorities.
11. Deletion and retention
Doqubox applies the agreed retention periods. When the service ends, Doqubox, at the customer's choice, returns or deletes all personal data held on the customer's behalf and deletes existing copies, unless Union or Member State law requires storage.
Data may be returned through the retrieval functions available in the service, including document downloads. The customer should retrieve data before the service ends and before the applicable retention periods expire. For data that cannot be retrieved through those functions, or to arrange retrieval at termination, contact support@doqubox.com. Doqubox will coordinate a reasonable opportunity to retrieve data still held before deleting it. Retrieval of end-to-end encrypted files and metadata requires the customer's authorized access and decryption in the browser, as Doqubox has no readable copy. Copies in backups are deleted as those backups rotate out.
During the service, documents also expire under the agreed retention periods. The retention policy explains expiry and backup rotation and does not override this DPA. Data processed for Doqubox's own purposes follows the privacy policy.
12. Audit and information support
Doqubox will provide all information necessary to demonstrate Article 28 compliance and allow and contribute to customer audits, including inspections by appointed auditors.
Audits are normally limited to one per twelve months, during business hours and with at least 30 days' written notice. Additional audits, with notice appropriate to the circumstances, are allowed for reasonable concerns about non-compliance, an authority's requirement, or a breach affecting customer data.
The customer bears the costs of audits it conducts or commissions. Parties coordinate scope, timing, confidentiality, and security to protect other customers and limit disruption. Doqubox may reasonably reject an auditor competing directly with Doqubox or an audited subprocessor and require a confidentiality agreement.
For subprocessors, Doqubox first supplies available certifications and independent audit reports and arranges further audit access where reasonably necessary to demonstrate compliance. These arrangements do not prevent exercise of the customer's audit rights.
13. International transfers
Application hosting, databases, object storage, backups, and outbound email infrastructure are in the EU. Other processing locations are in the subprocessor list. Transfers outside the EEA use appropriate safeguards where required, such as adequacy decisions or Standard Contractual Clauses. Subprocessor changes follow section 8.
14. Customer responsibilities
The customer determines lawful purposes and legal bases, requests only necessary data, manages access and recipients, and downloads documents before expiry. It must promptly flag sensitive or urgent data-protection issues to Doqubox.
15. Changes to this DPA
The current DPA can be saved or printed from this page.
Doqubox may reasonably update this DPA without expanding processing purposes or scope, materially increasing customer obligations, or materially reducing security or customer rights and protections. Other changes require separate agreement.
Account administrators receive at least 14 calendar days' email notice, including the revised wording, an explanation, the effective date, and termination rights. Permitted updates take effect on that date without an acceptance reply. Customers with a substantiated material objection to an update may terminate the affected service before then by emailing support@doqubox.com and explaining their objection, without penalty or ordinary cancellation deadlines.
Editorial corrections that do not change rights or obligations need no advance notice. Mandatory law remains applicable. Subprocessor changes follow section 8.
For requests under this DPA or a signed copy, contact support@doqubox.com.