Data Processing Agreement (DPA)
This DPA is entered into between:
Data Controller: [Client Name]
Data Processor: Job Done Marketing LLC, operator of euPDF.com
1. Subject Matter and Duration
The Processor will process personal data on behalf of the Controller for the purpose of providing PDF processing services via euPDF.com. The duration of processing corresponds to the duration of the Controller's use of the service.
2. Nature and Purpose of Processing
- Uploading, converting, merging, splitting, compressing, OCR, and other document operations.
- Temporary storage during active session.
- Automatic deletion after session end or inactivity.
3. Types of Personal Data
- Uploaded documents (content may include personal data).
- IP addresses and technical logs.
- Session identifiers.
4. Categories of Data Subjects
Employees, customers, or other individuals whose data is contained in uploaded documents.
5. Obligations of the Processor
The Processor shall:
- Process personal data only on documented instructions from the Controller.
- Ensure confidentiality of personnel authorised to process data.
- Implement appropriate technical and organisational measures (see Security Measures below).
- Assist the Controller in responding to data subject requests.
- Notify the Controller without undue delay after becoming aware of a personal data breach.
- Delete or return all personal data at the choice of the Controller upon termination of the service, unless retention is required by law.
- Make available to the Controller all information necessary to demonstrate compliance with GDPR.
6. Sub‑Processors
The Controller authorises the engagement of the following sub‑processors:
| Sub‑Processor | Purpose | Location |
| Stripe, Inc. | Payment processing | USA (DPF) |
| Airwallex | Payment processing | Global |
| Webdock | Hosting infrastructure | EU |
The Processor will inform the Controller of any intended changes to the list of sub‑processors and allow the Controller to object.
7. Security Measures
The Processor has implemented:
- Isolation: Each processing task runs in a separate Docker container.
- Encryption: TLS 1.3 for data in transit.
- Auto‑deletion: Files are deleted immediately upon session end or after 15 minutes of inactivity.
- Access control: Strict user permissions and no public access to uploaded files.
- Logging: Minimal logs retained for 7 days.
8. Data Subject Rights
The Processor will assist the Controller in fulfilling data subject requests (access, rectification, erasure, portability) insofar as possible.
9. Audit Rights
The Controller may, upon reasonable notice and at its own expense, audit the Processor's compliance with this DPA. The Processor will provide necessary information and access.
10. Governing Law
This DPA shall be governed by the laws of [Controller's jurisdiction / EU member state].