Legal
Data Processing Agreement
The terms that govern personal information in the documents you process through DocoMatic: who plays which role, what we process and why, how it is protected, who else handles it, and what happens when the agreement ends.
Effective date: September 16, 2026Version 1.0
The English version governs. Translations are provided for convenience.
1. Parties and roles
1.1
This Data Processing Agreement ("DPA") is between the customer and Monocubed, Inc., a company registered in Delaware with its business address at 651 North Broad Street, Suite 206, Middletown, DE 19709, United States ("DocoMatic"). For personal information in customer documents and connected systems, the customer is the controller — the organization accountable for the information (or a processor acting for its own controllers) — and DocoMatic is the processor, acting only on the customer's behalf.
1.2
This DPA forms part of the Terms of Service. For the handling of personal information, it prevails over the Terms of Service where they conflict. A signed agreement between the parties, including any data privacy agreement the customer's law requires, prevails over both.
1.3
In this DPA, "personal information" means information about an identifiable individual. It includes what applicable laws call "personal data" or "personally identifiable information".
2. Scope of processing
2.1
Subject matter: document accessibility remediation, verification, monitoring and related reporting.
2.2
Duration: the term of the agreement, and afterwards until customer data is deleted as described in section 9.
2.3
Nature and purpose: analyzing, converting, tagging and verifying documents supplied by the customer, and producing reports and audit records.
2.4
Categories of data: any personal information contained in customer documents, which may include identifiers and, depending on the customer, education records or health information (see sections 10 and 11); plus the customer's authorized user accounts.
2.5
Data subjects: individuals appearing in customer documents, and the customer's users.
3. Processing on instructions
3.1
DocoMatic processes customer documents only on the customer's documented instructions — uploading a document, configuring a connector or calling the API is such an instruction — and never for its own purposes. Customer documents are never used to train AI models, and personal information in them is never sold.
3.2
If DocoMatic believes an instruction breaks applicable data protection law, it tells the customer before processing.
3.3
DocoMatic personnel may access customer data only when they need to in order to provide or support the service, and are bound by confidentiality obligations.
4. Security measures
4.1
DocoMatic maintains technical and organizational measures appropriate to the risk. They include:
- encryption in transit (TLS 1.2 or higher) and at rest (AES-256, with keys managed in AWS Key Management Service);
- tenant isolation enforced with database row-level security and application-level scoping, tested in continuous integration by a cross-tenant test suite;
- role-based access control, multi-factor authentication for DocoMatic's staff console, and audit logging;
- malware scanning of every upload before it is processed;
- outside AI providers used only under a contract that forbids training on customer documents and keeps no copy of them, and a customer setting that turns outside AI off entirely, so that only DocoMatic's own software processes the customer's documents.
4.2
The current description of these measures, including which are still being put in place, is published on the security page. DocoMatic does not currently hold any third-party security certification or audit report.
5. Sub-processors
5.1
The customer authorizes the sub-processors listed on the security page. DocoMatic imposes data protection obligations on every sub-processor that are at least as protective as this DPA, and remains responsible for their performance.
5.2
DocoMatic gives at least 30 days' notice before adding or replacing a sub-processor that processes customer data, by updating the security page and emailing the customer's account administrators. Within that period the customer may object on reasonable data-protection grounds. The parties will then discuss the concern in good faith; if it cannot be resolved, the customer may end the affected service and receive a refund of fees prepaid for the unused period.
5.3
If a sub-processor must be replaced urgently to protect security or keep the service running, DocoMatic gives notice as soon as it can, and the customer keeps the same right to object.
6. Breach notice
6.1
DocoMatic notifies the customer without undue delay, and in any event within 72 hours, after confirming a security breach that affects customer data.
6.2
The notice describes, as far as is then known, what happened, the categories and approximate amount of information and the number of individuals affected, the likely consequences, the measures taken or proposed, and a contact person. DocoMatic updates the customer as it learns more, and cooperates with the customer's investigation and notification duties.
6.3
The customer decides whether and how to notify individuals and regulators, unless the law requires DocoMatic to notify them itself. Notices go to the customer's account administrators. To report a suspected incident to DocoMatic, email [email protected].
7. Where data is stored, and transfers
7.1
DocoMatic stores customer data in the United States, on Amazon Web Services (US East, with encrypted backups in US West). Any access to customer data by DocoMatic personnel or sub-processors, wherever they are located, is subject to this DPA.
7.2
Canadian customers. Personal information in a Canadian customer's documents is stored and processed in the United States and may be accessible to US courts, law enforcement and national security authorities under US law. This DPA is the contract through which DocoMatic provides a level of protection comparable to the one the customer must provide. That supports customers subject to the Personal Information Protection and Electronic Documents Act (PIPEDA), which keeps an organization responsible for personal information it transfers to a third party for processing (Schedule 1, clause 4.1.3). Most public bodies are instead subject to their province's public-sector privacy law, and some provincial laws limit storage of, or access to, personal information outside Canada. The customer is responsible for confirming that its law allows storage in the United States before uploading documents.
7.3
Customers in Quebec. Before personal information is communicated outside Quebec, Quebec law requires a privacy impact assessment and a written agreement: section 17 of the Act respecting the protection of personal information in the private sector, and section 70.1 of the Act respecting Access to documents held by public bodies and the Protection of personal information, both as amended in 2021 (Law 25). The customer carries out that assessment. DocoMatic provides the information the customer reasonably needs for it, including this DPA, the security page and the sub-processor list, and this DPA serves as the written agreement.
7.4
Other countries. DocoMatic does not currently offer processing of personal information transferred from the European Union, the European Economic Area, the United Kingdom or Switzerland, and does not offer standard contractual clauses. Customers must not upload personal information that is subject to the GDPR.
8. Assistance and audits
8.1
DocoMatic assists the customer with requests from individuals — including helping to locate the documents that concern a person — and with security and privacy impact assessments, taking into account the nature of the processing.
8.2
Security information. Once a year, and after any security breach that affects the customer, the customer may ask for DocoMatic's current security documentation and for answers to a reasonable security questionnaire. DocoMatic provides them, under confidentiality, within a reasonable time.
8.3
Audits. If that information is not enough to show that DocoMatic complies with this DPA, the customer, or an independent auditor bound by confidentiality who is not a DocoMatic competitor, may audit that compliance: no more than once a year, with at least 30 days' written notice, during normal business hours, at the customer's cost, under confidentiality, and without disrupting the service or accessing other customers' data. The parties agree the scope in advance. Cloud providers are covered by their own published audit reports rather than by site visits.
8.4
Regulators. DocoMatic cooperates with an audit or inquiry by a regulator that has authority over the customer, as the law requires. The once-a-year limit does not apply to those.
9. Deletion and return
9.1
The customer can download documents, outputs and reports at any time, and DocoMatic assists with a complete export on request. During the agreement, DocoMatic deletes customer data when the customer asks, and provides a record of the deletion on request. Automatic deletion at the end of a plan's retention period is not switched on yet (see Privacy Policy, section 5); until it is, deletion happens on request.
9.2
When the agreement ends, the customer has 30 days to export its data. DocoMatic's operations team then deletes the customer's documents, outputs and reports within 60 days, sooner if the customer asks, and confirms the deletion in writing on request.
9.3
DocoMatic keeps customer data longer only where the law requires it or a legal hold applies; a legal hold pauses deletion until it is lifted. Data kept for those reasons stays protected by this DPA. Copies in encrypted backups are deleted as those backups expire in the normal backup cycle.
10. Education records (FERPA)
10.1
Where the customer is an educational agency or institution subject to the Family Educational Rights and Privacy Act (20 U.S.C. § 1232g; 34 CFR Part 99), the customer designates DocoMatic as a school official with a legitimate educational interest under 34 CFR § 99.31(a)(1)(i)(B), solely to provide the service. DocoMatic performs an institutional service for which the customer would otherwise use its own employees, and is under the customer's direct control with respect to the use and maintenance of education records.
10.2
DocoMatic uses personally identifiable information from education records only for the purpose for which it was disclosed. It does not redisclose that information except as the customer directs or as 34 CFR § 99.33 permits, and does not use it for advertising, for building profiles of students, or for training AI models. In addition, DocoMatic:
- limits access to education records to personnel who need it to provide the service;
- provides role-based permissions that help the customer control which of its own users can see which documents;
- deletes education records when the customer asks, and at the end of the agreement as section 9 describes;
- refers to the customer any request for education records it receives from a parent, a student or anyone else, unless the law prohibits that.
10.3
Many states have their own student-privacy laws, and many districts use a standard data privacy agreement to meet them. On request, DocoMatic will sign the Student Data Privacy Consortium's National Data Privacy Agreement, including the supplemental terms for the customer's state, or another data privacy agreement that the customer's state law requires.
10.4
Where such an agreement is signed, it prevails over this section for student data.
11. Protected health information (HIPAA)
11.1
No protected health information without a Business Associate Agreement. A customer that is a covered entity or business associate under HIPAA (45 CFR Parts 160 and 164) must not upload protected health information to DocoMatic unless both parties have first signed a Business Associate Agreement. DocoMatic does not agree to receive protected health information on any other basis.
11.2
A Business Associate Agreement is available on request from [email protected]. As 45 CFR § 164.504(e) requires, it limits DocoMatic's use and disclosure of protected health information to providing the service, requires safeguards that meet the Security Rule, requires DocoMatic to report breaches of unsecured protected health information (45 CFR § 164.410), binds sub-processors to the same restrictions, and requires the information to be returned or destroyed at termination where feasible.
11.3
Most documents that healthcare organizations publish — blank forms, notices, instructions — contain no protected health information, and DocoMatic's monitoring service crawls only public web content.