Data Processing Agreement (DPA)

Effective from: 1 June 2026 · Version 1.0

This data processing agreement (the "Agreement") is entered into between:

The controller:
the company or person who, as a business customer, uses LegalDock (the "Customer" / "the controller"), and
The processor:
LegalDock ApS, company reg. (CVR) no. [•], [address], Copenhagen, Denmark ("LegalDock" / "the processor").

The Agreement is entered into pursuant to Article 28(3) of the General Data Protection Regulation (GDPR) and forms an integral part of the terms the Customer accepts when using LegalDock as a business customer. By creating and using a business account, the Customer accepts this Agreement. In the event of conflict, this Agreement prevails over any conflicting data processing provisions in the general terms.

§ 1. Subject-matter and duration

1.1LegalDock processes personal data on behalf of the Customer in connection with the provision of LegalDock's platform for creating, completing, storing and electronically signing documents.

1.2The processing continues for as long as the Customer has an active account with LegalDock, and for the subsequent period necessary for deletion or return under § 10.

1.3The nature, purpose, types of personal data and categories of data subjects are described in Annex A.

§ 2. Instructions

2.1LegalDock processes personal data only on documented instructions from the Customer, including with regard to transfers to third countries, unless required to do so by EU or Member State law to which LegalDock is subject. In such a case, LegalDock informs the Customer of that legal requirement before processing, unless that law prohibits such information on important grounds of public interest.

2.2The Customer's use of the platform in accordance with the Agreement and LegalDock's documentation constitutes the documented instructions. Any other or additional instructions are agreed in writing.

2.3LegalDock informs the Customer without undue delay if, in LegalDock's opinion, an instruction infringes the data protection rules.

§ 3. Confidentiality

3.1LegalDock ensures that persons authorised to process the personal data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality, and that access is limited to what is necessary to provide the service.

§ 4. Security of processing (Art. 32)

4.1

LegalDock implements the technical and organisational measures necessary to ensure a level of security appropriate to the risk, cf. GDPR Article 32. The measures include, among others:

  • encryption of personal data in transit (TLS) and at rest,
  • hosting and storage of document and signer data within the EU/EEA (payment data is processed via Stripe, cf. Annex B and § 8),
  • access control based on the least-privilege principle and authentication,
  • logging and separation of customers' data,
  • regular backups and procedures for restoring availability,
  • regular testing and evaluation of the effectiveness of the measures.

§ 5. Sub-processors

5.1The Customer grants LegalDock a general authorisation to use sub-processors. The sub-processors currently used are set out in Annex B.

5.2LegalDock informs the Customer of intended changes concerning the addition or replacement of sub-processors with at least 30 days' notice, so that the Customer can object. If the Customer objects on reasonable grounds and the parties cannot find a solution, the Customer may terminate the affected services.

5.3LegalDock imposes on any sub-processor, by way of a contract, the same data protection obligations as set out in this Agreement, and LegalDock remains liable to the Customer for the sub-processor's performance of its obligations.

§ 6. Assistance to the Customer

6.1

Taking into account the nature of the processing and the information available to LegalDock, LegalDock assists the Customer by appropriate technical and organisational measures in fulfilling the Customer's obligations regarding:

  • responding to requests for exercising the data subjects' rights (GDPR Chapter III),
  • security of processing (Art. 32),
  • notification of a personal data breach to the Danish Data Protection Agency (Art. 33) and communication to the data subjects (Art. 34),
  • data protection impact assessments (Art. 35) and prior consultation (Art. 36).

§ 7. Personal data breach

7.1LegalDock notifies the Customer without undue delay, and no later than 48 hours after becoming aware of a personal data breach, providing the information necessary for the Customer to fulfil its own obligation to notify the Danish Data Protection Agency within 72 hours.

§ 8. Transfers to third countries

8.1Document and signer data is processed and stored within the EU/EEA. Payment and billing data is processed via Stripe (cf. Annex B), whereby data may be transferred to the USA. The transfer takes place on a valid transfer basis under GDPR Chapter V, including the European Commission's Standard Contractual Clauses (SCCs) and Stripe's certification under the EU-US Data Privacy Framework. Any other transfer to countries outside the EU/EEA takes place only on the Customer's instructions and on a valid transfer basis.

§ 9. Audit and inspection

9.1LegalDock makes available to the Customer all information necessary to demonstrate compliance with Article 28, and allows for and contributes to audits, including inspections, conducted by the Customer or an auditor mandated by the Customer.

9.2LegalDock may fulfil this obligation by making relevant documentation, including any audit reports, available. The Customer's audit must be announced with reasonable notice and must not unduly disrupt LegalDock's operations.

§ 10. Termination

10.1On termination of the Agreement, LegalDock, at the Customer's choice, deletes or returns all personal data processed on behalf of the Customer, and deletes existing copies, unless EU or Member State law requires continued storage.

10.2For a period of 30 days after termination, the Customer may request an export of the data. After that, data is deleted in accordance with LegalDock's standard procedures.

§ 11. Liability and governing law

11.1The parties' liability follows from the GDPR and the general terms between the parties.

11.2The Agreement is governed by Danish law, and disputes are settled by the Danish courts.


Annex A — Description of the processing

Subject-matter:
Provision of LegalDock's platform for creating, completing, storing and electronically signing documents.
Duration:
For as long as the Customer has an active account, cf. § 1.2.
Nature and purpose:
Collection, recording, storage, structuring, display, transfer (to signatories) and deletion of personal data for the purpose of enabling the Customer to generate, share and have documents signed, and to maintain an audit trail for signatures.
Types of personal data:
Name, email address, optionally phone number, IP address, timestamps, signature data, and the personal data the Customer chooses to include in the content of the documents. The Customer should not include special categories of data (Art. 9) unless necessary and lawful.
Categories of data subjects:
The Customer's signatories and counterparties, employees, and other natural persons whose data the Customer includes in its documents.

Annex B — Approved sub-processors

Sub-processorPurposeLocation
SupabaseHosting, database and file storageEU/EEA
StripePayment and billing processingEU + USA (SCCs + EU-US Data Privacy Framework)
ResendSending transactional emails (e.g. signing requests)EU/EEA

For payment data, Stripe also acts as an independent data controller under its own terms. The Customer may at any time request an updated list of sub-processors.