# Zerodoc — Data Processing Agreement

**Version 1.1 · Last updated 2026-07-25**

This Data Processing Agreement ("DPA") is between the customer ("Controller", "you") and
Zerodoc — the trading name of Rocsoft Ltd, a limited company incorporated in the Isle of Man
("Processor", "we") — for use of the Zerodoc document-extraction API (the "Service"). It is
incorporated into the Zerodoc Terms of Service (https://zerodoc.io/terms) by reference and
applies automatically to all customers — no signature is required.

## 1. Subject matter and roles

For customer documents submitted to the Service, you are the Controller and Zerodoc is the
Processor. We process such documents solely to provide the Service (OCR and structured
field extraction) on your instructions.

## 2. Nature and purpose of processing

- **Purpose:** extracting text and structured fields from documents you submit.
- **Processing model:** documents are processed **in memory only** and discarded immediately
  after the API response. No document or extracted content is written to disk or retained.
- **Duration:** the duration of each API request only.

## 3. Categories of data and data subjects

You determine the content of submitted documents and therefore the categories of personal
data they may contain (e.g. names, addresses, financial details on invoices). Because we do
not retain documents, we hold no record of these beyond the request lifecycle.

## 4. Data we retain (as Processor/Controller for account data)

We retain only: account email, a one-way hash of your API key, and usage metadata (page
counts, timestamps, status). We do not retain document content.

## 5. Sub-processors

| Sub-processor | Purpose | Location |
|---|---|---|
| Cloudflare | Auth, billing & usage metadata | EU data localization |
| Stripe | Payment processing | EU/US (SCCs) |
| Resend | Transactional email | EU/US (SCCs) |
| netcup | Stateless document processing | EU (Germany) |

We will give notice of new sub-processors and provide an opportunity to object.

## 6. Security measures

- Documents processed in memory only; no disk persistence; in-memory buffers cleared on completion.
- TLS in transit; API keys stored only as SHA-256 hashes.
- Per-key rate limiting and quotas; least-privilege access to metadata systems.

## 7. International transfers

Document processing occurs in the EU. Where personal data is processed outside the UK/EEA by
a sub-processor, transfers are governed by Standard Contractual Clauses and/or the provider's
data-localization options.

## 8. Data subject requests & assistance

Because we do not retain documents, requests relating to document content are fulfilled by you
as Controller. We will assist with requests relating to account data we hold.

## 9. Breach notification

We will notify you without undue delay after becoming aware of a personal data breach affecting
data we process on your behalf.

## 10. Deletion

Documents are never retained, so there is nothing to delete post-processing. Account data is
deleted on request or on account closure, subject to legal retention requirements.

## 11. Audit

We will make available information reasonably necessary to demonstrate compliance, including
relevant certifications as our compliance programme matures (SOC 2 Type II is on our roadmap).

## 12. Term and governing law

This DPA applies for as long as we process documents on your behalf under the Terms of
Service, and is governed by the same law and jurisdiction as those terms (Isle of Man).

---

*Questions, or a countersigned copy for your records: privacy@zerodoc.io*
