Data Processing Addendum

Version 1.0 · Last Updated: July 2026

This Data Processing Addendum ("DPA") forms part of the DocuPotion Terms and Conditions and applies automatically to every customer whose use of DocuPotion involves us processing personal data on their behalf. A countersigned copy is available on request: email support@docupotion.com.

1. Introduction and Roles

Cranford Tech Limited (trading as DocuPotion), company number 15069364, with registered office at 3rd Floor, 86-90 Paul Street, London, England, EC2A 4NE ("we", "us", "DocuPotion") provides a software-as-a-service platform for creating, generating, and delivering documents.

When you upload spreadsheets, connect data sources, generate documents, or deliver documents by email, the data you supply may contain personal data about people other than you, such as your students, trainees, employees, or customers. For that data, you are the controller and DocuPotion is your processor under applicable Data Protection Laws. This DPA sets out the terms required by Article 28(3) UK GDPR and, where applicable, Article 28(3) EU GDPR for that processing.

For personal data about you as our customer (your account, billing, and usage data), we are an independent controller, and our Privacy Policy applies instead.

2. Definitions

  • "Customer Data" means personal data you provide to us, or which is provided at your direction, for processing through DocuPotion. It includes data in your spreadsheets and connected data sources, data submitted through our API, the contents of documents generated from that data, and the email addresses of document recipients.
  • "Data Subject" means the individual the personal data relates to, for example a student, parent, trainee, or employee.
  • "Sub-processor" means a third party we engage to process Customer Data on your behalf.
  • "Data Protection Laws" means, as applicable to the processing: the UK GDPR and the Data Protection Act 2018; the EU General Data Protection Regulation (EU) 2016/679 ("EU GDPR"); and the Swiss Federal Act on Data Protection.
  • Terms such as "controller", "processor", "personal data", and "processing" have the meanings given in the applicable Data Protection Laws.

3. Details of Processing

  • Subject matter: generation of documents from Customer Data and, where you enable it, delivery of those documents to recipients by email.
  • Duration: the term of your DocuPotion account, plus the retention periods in section 9.
  • Nature and purpose: ingesting structured data (spreadsheets, API calls, connected sources), merging it into document templates, rendering PDF documents, storing generated documents, and sending them to recipients you designate.
  • Categories of data subjects: the individuals in your data, typically students, parents or guardians, trainees, employees, or customers.
  • Categories of personal data: whatever your data contains, typically names, contact details (including email addresses), dates, identifiers, and the contents of the documents you generate. You control what these fields contain. You should not submit special category data unless you have a lawful basis to do so as controller.

4. Our Obligations as Processor

We will:

  • process Customer Data only on your documented instructions, which are given through your use of the service (uploading data, configuring runs, enabling deliveries), unless we are required to process it by law, in which case we will tell you before processing unless the law prevents us;
  • ensure everyone we authorise to process Customer Data is bound by a duty of confidentiality;
  • implement the technical and organisational security measures in section 6;
  • engage Sub-processors only under section 7;
  • taking into account the nature of the processing, assist you with responding to Data Subject rights requests (section 8);
  • assist you with your security, breach notification, and data protection impact assessment obligations, taking into account the information available to us;
  • delete or return Customer Data in accordance with section 9; and
  • make available the information necessary to demonstrate compliance with this DPA and allow for audits as described in section 11.

5. Your Obligations as Controller

You are responsible for:

  • having a lawful basis for the processing you instruct, including for emailing documents to recipients;
  • providing any privacy notices Data Subjects are entitled to;
  • the accuracy and lawfulness of the data you upload, including that recipient email addresses are legitimately held. Purchased or scraped contact lists must not be used;
  • using email delivery only to deliver documents to their intended recipients, not for marketing or bulk correspondence unrelated to a generated document.

6. Security Measures

  • Customer Data is encrypted in transit (TLS) and at rest.
  • Access to production systems is restricted by role-based IAM policies scoped to least privilege, with credentials for third-party integrations stored encrypted under managed keys (AWS KMS).
  • Generated documents are private by default. Document access is authenticated, and download links are short-lived and minted per request rather than long-lived.
  • Email delivery is protected by per-account sending limits, automatic suppression of addresses that bounce or complain, and a service-wide capability to suspend email delivery immediately in an incident.
  • Infrastructure-level monitoring and alerting cover the document generation and email delivery pipelines.

7. Sub-processors

You give us general written authorisation to engage the Sub-processors below. We will impose data protection obligations on each Sub-processor equivalent to those in this DPA and remain responsible to you for their performance.

Sub-processorPurposeLocation
Amazon Web Services (AWS)Cloud hosting, document generation and storage, email delivery (Amazon SES)United States (us-east-1)
Bubble Group, Inc.Application platform hosting the DocuPotion appUnited States
Supabase, Inc.Authentication and account/usage databaseUnited States
Cloudflare, Inc.Edge network and request processingGlobal network
OpenRouter, Inc. (request routing), Anthropic, PBC and Google LLC (AI model providers)AI template generation, only when you use AI features on content containing Customer DataUnited States

AI features and model training: Customer Data submitted to AI features is processed solely to generate the output you requested. It is not used by DocuPotion, OpenRouter, Anthropic, or Google to train artificial intelligence models. We will update the table above before enabling any additional model provider.

Stripe (payments) and Loops (product email to account holders) process your account data as described in our Privacy Policy; they do not process Customer Data.

We will give you at least 30 days' notice of any new Sub-processor of Customer Data by updating this page and notifying account holders by email. If you reasonably object on data protection grounds, you may terminate the affected service and receive a pro-rata refund of prepaid fees.

8. International Transfers

Customer Data is processed in the United States by the Sub-processors listed above. Where a restricted transfer takes place, we rely on the following mechanisms, together with any supplementary measures needed for the transfer to be lawful: for transfers of UK personal data, the UK Extension to the EU-US Data Privacy Framework for recipients certified under it (including AWS), and otherwise the UK International Data Transfer Addendum to the EU Standard Contractual Clauses; for transfers of EU personal data, the EU-US Data Privacy Framework for certified recipients, and otherwise the EU Standard Contractual Clauses; and for transfers of Swiss personal data, the Swiss-US Data Privacy Framework for certified recipients, and otherwise the EU Standard Contractual Clauses as adapted for Swiss law.

9. Retention, Deletion, and Return

  • Batch-generated documents (spreadsheet runs) are retained for 12 months from generation, then deleted automatically.
  • Documents generated via the API's single-document endpoint are retained for 7 days, then deleted automatically.
  • Uploaded spreadsheets are staged for up to 24 hours for processing; a copy is retained with your saved run configuration so runs can be repeated, and is deleted when the configuration or your account is deleted.
  • Email delivery records (per-recipient delivery status) are retained with the associated run. Addresses that hard-bounce or register a spam complaint are retained on a suppression list for as long as needed to prevent further emails to them; this protects both recipients and email deliverability, and is in the legitimate interest of all parties.
  • On termination of your account, or on written request, we will, at your choice, delete or return all Customer Data in our possession within 30 days, except where law requires longer retention. Return is provided as an export of your documents and data in a commonly used format; you can also export your documents yourself at any time before deletion.

10. Personal Data Breach

We will notify you without undue delay, and in any event within 48 hours, after becoming aware of a personal data breach affecting Customer Data. Where the full details are not yet known, our initial notice will contain the information then available and we will provide the remainder in phases as our investigation progresses, including the nature of the breach, the categories and approximate numbers of Data Subjects and records affected, likely consequences, and the measures taken or proposed. This is intended to give you the earliest practicable start on your own notification obligations.

11. Audit

On written request, no more than once in any 12-month period, we will make available information reasonably necessary to demonstrate compliance with this DPA, including summaries of our security measures and Sub-processor arrangements. Where this is insufficient, we will allow an audit by you or your appointed auditor, on reasonable notice, during business hours, without disruption to our services, and subject to confidentiality obligations.

12. General

  • This DPA is subject to the limitations of liability in our Terms and Conditions.
  • If there is a conflict between this DPA and the Terms and Conditions regarding the processing of Customer Data, this DPA prevails.
  • This DPA is governed by the law governing the Terms and Conditions.

13. Contact

Questions about this DPA, requests for a countersigned copy, deletion requests, and data protection enquiries: support@docupotion.com.