Data Processing Addendum

Version 1.1 · Last Updated: September 2026

This Data Processing Addendum ("DPA") forms part of the DocuPotion Terms and Conditions and applies automatically to every customer whose use of DocuPotion involves us processing personal data on their behalf. A countersigned copy is available on request: email support@docupotion.com.

1. Introduction and Roles

Cranford Tech Limited (trading as DocuPotion), company number 15069364, with registered office at 3rd Floor, 86-90 Paul Street, London, England, EC2A 4NE ("we", "us", "DocuPotion") provides a software-as-a-service platform for creating, generating, and delivering documents.

When you upload spreadsheets, connect data sources (such as your CRM), generate documents, deliver documents by email or to connected storage, or send documents for electronic signature, the data you supply or instruct us to access may contain personal data about people other than you, such as your students, trainees, employees, customers, or document signers. For that data, you are the controller and DocuPotion is your processor under applicable Data Protection Laws. This DPA sets out the terms required by Article 28(3) UK GDPR and, where applicable, Article 28(3) EU GDPR for that processing.

For personal data about you as our customer (your account, billing, and usage data), we are an independent controller, and our Privacy Policy applies instead.

2. Definitions

  • "Customer Data" means personal data you provide to us, or which is provided at your direction, for processing through DocuPotion. It includes data in your spreadsheets and connected data sources (such as records in your connected CRM), data submitted through our API, the contents of documents generated from that data, the email addresses of document recipients, and the details of the signers you designate for electronic signature (including their signatures and the signing audit trail).
  • "Data Subject" means the individual the personal data relates to, for example a student, parent, trainee, employee, or document signer.
  • "Sub-processor" means a third party we engage to process Customer Data on your behalf.
  • "Data Protection Laws" means, as applicable to the processing: the UK GDPR and the Data Protection Act 2018; the EU General Data Protection Regulation (EU) 2016/679 ("EU GDPR"); and the Swiss Federal Act on Data Protection.
  • Terms such as "controller", "processor", "personal data", and "processing" have the meanings given in the applicable Data Protection Laws.

3. Details of Processing

  • Subject matter: generation of documents from Customer Data and, where you enable it, delivery of those documents to recipients by email, attachment of documents to records in your connected CRM, saving of copies to your connected storage, and collection of electronic signatures on those documents.
  • Duration: the term of your DocuPotion account, plus the retention periods in section 9.
  • Nature and purpose: ingesting structured data (spreadsheets, API calls, and, on your instruction, records read from your connected data sources such as the Attio CRM), merging it into document templates, rendering PDF documents, storing generated documents where applicable, sending them to recipients you designate, attaching them to your CRM records, saving copies to your connected Google Drive, and running the electronic-signature process (sending signature requests, presenting the document for signing, sealing the completed document, and maintaining a signing audit trail).
  • Categories of data subjects: the individuals in your data, typically students, parents or guardians, trainees, employees, or customers; contacts in your connected CRM; and the signers of documents you send for electronic signature.
  • Categories of personal data: whatever your data contains, typically names, contact details (including email addresses), dates, identifiers, and the contents of the documents you generate; and, for electronic signatures, the signer's name, email address, signature, IP address, and signing-event timestamps. You control what your data fields contain. You should not submit special category data unless you have a lawful basis to do so as controller.

4. Our Obligations as Processor

We will:

  • process Customer Data only on your documented instructions, which are given through your use of the service (uploading data, configuring runs, enabling deliveries), unless we are required to process it by law, in which case we will tell you before processing unless the law prevents us;
  • ensure everyone we authorise to process Customer Data is bound by a duty of confidentiality;
  • implement the technical and organisational security measures in section 6;
  • engage Sub-processors only under section 7;
  • taking into account the nature of the processing, assist you with responding to Data Subject rights requests (section 8);
  • assist you with your security, breach notification, and data protection impact assessment obligations, taking into account the information available to us;
  • delete or return Customer Data in accordance with section 9; and
  • make available the information necessary to demonstrate compliance with this DPA and allow for audits as described in section 11.

5. Your Obligations as Controller

You are responsible for:

  • having a lawful basis for the processing you instruct, including for emailing documents to recipients;
  • providing any privacy notices Data Subjects are entitled to;
  • the accuracy and lawfulness of the data you upload, including that recipient email addresses are legitimately held. Purchased or scraped contact lists must not be used;
  • using email delivery only to deliver documents to their intended recipients, not for marketing or bulk correspondence unrelated to a generated document.

6. Security Measures

  • Customer Data is encrypted in transit (TLS) and at rest.
  • Access to production systems is restricted by role-based IAM policies scoped to least privilege, with credentials for third-party integrations stored encrypted under managed keys (AWS KMS).
  • Generated documents are private by default. Document access is authenticated, and download links are short-lived and minted per request rather than long-lived.
  • Email delivery is protected by per-account sending limits, automatic suppression of addresses that bounce or complain, and a service-wide capability to suspend email delivery immediately in an incident.
  • Infrastructure-level monitoring and alerting cover the document generation and email delivery pipelines.

7. Sub-processors

You give us general written authorisation to engage the Sub-processors below. We will impose data protection obligations on each Sub-processor equivalent to those in this DPA and remain responsible to you for their performance.

Sub-processorPurposeLocation
Amazon Web Services (AWS)Cloud hosting, document generation and storage, email delivery (Amazon SES)United States (us-east-1); Ireland (eu-west-1)
Bubble Group, Inc.Application platform hosting the DocuPotion appUnited States
Supabase, Inc.Authentication and account/usage databaseEuropean Union (eu-central-1, Frankfurt)
Cloudflare, Inc.Edge network and request processingGlobal network
OpenRouter, Inc. (request routing), Anthropic, PBC and Google LLC (AI model providers)AI-assisted template features: generating and editing templates from your prompts (including template content, attached reference files, and sample data), matching your prompt to a library template, and analyzing PDFs you upload to detect and map their fields (the uploaded document is sent for analysis)United States
Documenso, Inc.Electronic-signature infrastructure, only when you send documents for signature: the document to be signed, signer names and email addresses, signatures, signer IP addresses, and the signing audit trailUnited States

AI features and model training: Customer Data submitted to AI features is used to provide those features. It is not used by DocuPotion, OpenRouter, Anthropic, or Google to train artificial intelligence models. We will update the table above before enabling any additional model provider.

Your own connected services are not Sub-processors. Where DocuPotion, on your instruction, reads data from or writes documents to a service under your own account and agreement, such as attaching a document to a record in your Attio workspace or saving a copy to your Google Drive, that service acts for you, not for us. Your agreement with that provider governs its processing.

Stripe (payments) and Loops (product email to account holders) process your account data as described in our Privacy Policy; they do not process Customer Data.

We will give you at least 30 days' notice of any new Sub-processor of Customer Data by updating this page and notifying account holders by email. If you reasonably object on data protection grounds, you may terminate the affected service and receive a pro-rata refund of prepaid fees.

8. International Transfers

Customer Data is processed in the United States and the European Union, in the locations shown per Sub-processor above. Where a restricted transfer to the United States takes place, we rely on the following mechanisms, together with any supplementary measures needed for the transfer to be lawful: for transfers of UK personal data, the UK Extension to the EU-US Data Privacy Framework for recipients certified under it (including AWS), and otherwise the UK International Data Transfer Addendum to the EU Standard Contractual Clauses; for transfers of EU personal data, the EU-US Data Privacy Framework for certified recipients, and otherwise the EU Standard Contractual Clauses; and for transfers of Swiss personal data, the Swiss-US Data Privacy Framework for certified recipients, and otherwise the EU Standard Contractual Clauses as adapted for Swiss law.

9. Retention, Deletion, and Return

  • Batch-generated documents (spreadsheet runs) are retained for 12 months from generation, then deleted automatically.
  • Documents generated via the API's single-document endpoint are retained for 7 days, then deleted automatically.
  • Uploaded spreadsheets are staged for up to 24 hours for processing; a copy is retained with your saved run configuration so runs can be repeated, and is deleted when the configuration or your account is deleted.
  • Email delivery records (per-recipient delivery status) are retained with the associated run. Addresses that hard-bounce or register a spam complaint are retained on a suppression list for as long as needed to prevent further emails to them; this protects both recipients and email deliverability, and is in the legitimate interest of all parties.
  • Documents generated through CRM automations are not stored by DocuPotion. They are rendered, delivered to your connected services (and, where enabled, to the e-signature process), and discarded from our systems. We retain a run history for each generated document: its name, delivery status, and, for e-signed documents, the signer email addresses and signature statuses, for the term of your account.
  • Integration connection credentials (for services you connect, such as Attio and Google) are stored encrypted and deleted when you disconnect the service or your account is deleted.
  • Electronic-signature envelopes (the document sent for signature and its audit trail) are retained by our e-signature Sub-processor while the signature process is active and thereafter as evidence records, until you request their deletion or your account is deleted.
  • On termination of your account, or on written request, we will, at your choice, delete or return all Customer Data in our possession within 30 days, except where law requires longer retention. Return is provided as an export of your documents and data in a commonly used format; you can also export your documents yourself at any time before deletion.

10. Personal Data Breach

We will notify you without undue delay, and in any event within 48 hours, after becoming aware of a personal data breach affecting Customer Data. Where the full details are not yet known, our initial notice will contain the information then available and we will provide the remainder in phases as our investigation progresses, including the nature of the breach, the categories and approximate numbers of Data Subjects and records affected, likely consequences, and the measures taken or proposed. This is intended to give you the earliest practicable start on your own notification obligations.

11. Audit

On written request, no more than once in any 12-month period, we will make available information reasonably necessary to demonstrate compliance with this DPA, including summaries of our security measures and Sub-processor arrangements. Where this is insufficient, we will allow an audit by you or your appointed auditor, on reasonable notice, during business hours, without disruption to our services, and subject to confidentiality obligations.

12. General

  • This DPA is subject to the limitations of liability in our Terms and Conditions.
  • If there is a conflict between this DPA and the Terms and Conditions regarding the processing of Customer Data, this DPA prevails.
  • This DPA is governed by the law governing the Terms and Conditions.

13. Contact

Questions about this DPA, requests for a countersigned copy, deletion requests, and data protection enquiries: support@docupotion.com.