Data Processing Addendum (DPA)
Last updated: 31 August 2026
This Art. 28 GDPR Data Processing Addendum (Danish: databehandleraftale) covers personal data in documents you process with Northdocs. Version 2026-08-31.
Organization administrators can accept this DPA electronically or upload a wet-ink / countersigned PDF under Settings → Compliance. For negotiated paper originals, email legal@northdocs.com. Settings → Compliance.
How to execute
- Download the DPA PDF (version 2026-08-31). It includes a signature block at the end.
- Review the Subprocessors register (Schedule 1) and Security Overview. Subprocessors register · Security Overview.
- Either (a) sign electronically in-app as an org admin, or (b) sign the PDF and upload it under Settings → Compliance, or (c) request counter-signature from legal@northdocs.com.
1. Parties and roles
This Data Processing Addendum ("DPA") forms part of the agreement between Northdocs ApS ("Processor", "Northdocs", "we") and the customer organization that subscribes to the Northdocs service ("Controller", "Customer", "you").
For documents and related content the Customer uploads to Northdocs, the Customer is the controller (or acts on behalf of a controller) and Northdocs is the processor under Article 28 of the EU General Data Protection Regulation (GDPR), and where applicable the UK GDPR, together with corresponding Danish data-protection law.
For account, billing, and service-administration data, Northdocs acts as an independent controller as described in the Privacy Policy (https://northdocs.com/privacy). That processing is outside the scope of this DPA except where it overlaps with security and breach obligations.
2. Definitions
"Customer Personal Data" means personal data contained in documents, conversation transcripts and meeting audio, detections, redaction or pseudonymization outputs, case metadata, share links, audit events tied to Customer content, Outbound Guard telemetry (mailbox, finding counts, destination class, and domains; not message bodies), and any other personal data processed by Northdocs solely on the Customer's documented instructions through the Service.
"Service" means the Northdocs document redaction and pseudonymization platform, including Cases / Redact, Conversation Redact, optional Outbound Guard (Outlook), Prompt Guard, APIs, connectors, and related support.
Terms such as "personal data", "processing", "controller", "processor", "sub-processor", and "personal data breach" have the meanings given in the GDPR (and UK GDPR where applicable).
3. Subject matter, duration, nature and purpose
Subject matter: provision of AI-assisted and rules-based detection, review, redaction, pseudonymization, binder/export tooling, conversation redaction, optional Outlook send-time protection, connectors, and audit features.
Duration: for the term of the Customer's subscription and any post-termination retention window configured by the Customer or required by law, after which Customer Personal Data is deleted or returned in accordance with this DPA.
Nature and purpose: storage, transmission, parsing, OCR, optional speech-to-text, detection, human review collaboration, irreversible redaction or reversible pseudonymization (as configured), export, optional send-time inspection of Outlook compose, and related security/logging, solely to provide the Service to the Customer.
Types of personal data: whatever the Customer chooses to upload or, for Outbound Guard, inspect in Outlook. Typical categories for legal and public-sector customers include names, contact details, national identifiers, case references, health or special-category data, employee data, and data relating to criminal proceedings where lawfully included in source documents. Outbound Guard telemetry is limited to mailbox, finding counts, destination class, and domains (not message bodies).
Data subjects: individuals identified or identifiable in Customer documents (clients, counterparties, employees, citizens, patients, witnesses, and others), plus the Customer's authorized users of the Service.
4. Customer instructions
Northdocs shall process Customer Personal Data only on documented instructions from the Customer, including via configuration in the Service (retention, data region, AI detection on/off, category modes, connectors, exports) and this DPA, unless required to do otherwise by EU or Member State law (or UK law where applicable), in which case Northdocs will inform the Customer unless legally prohibited.
The Customer warrants that it has a lawful basis (and any required notices or consents) for the processing of Customer Personal Data in the Service, including special-category data where applicable, and that its instructions comply with data-protection law.
If Northdocs reasonably believes an instruction infringes the GDPR, UK GDPR, or other applicable law, it will promptly inform the Customer and may suspend execution of that instruction until clarified.
5. Confidentiality
Northdocs ensures that persons authorized to process Customer Personal Data are bound by appropriate confidentiality obligations (contractual or statutory) and receive data-protection and security training proportionate to their role.
6. Security measures
Taking into account the state of the art, implementation costs, and the nature, scope, context and purposes of processing as well as the risk to individuals, Northdocs implements appropriate technical and organizational measures as summarized in the Security Overview (https://northdocs.com/security), including at least:
(a) encryption in transit (TLS) and encryption at rest for document object storage (OVH Object Storage platform encryption), with optional Enterprise per-document envelope encryption and optional Enterprise Azure Key Vault bring-your-own-key (customer CMK wraps the organization encryption key; Northdocs does not store the CMK); (b) tenant isolation by organization identifiers and storage key namespacing; (c) role-based access control within organizations and admin-gated settings; (d) fail-closed export controls that block download if sensitive strings survive anywhere a reviewer did not deliberately keep them, and that block incomplete redacted downloads where detections remain pending (unless explicitly overridden by an authorized user); (e) audit logging of key actions; (f) configurable retention with automated deletion; (g) optional disablement of third-party AI detection, including Conversation Redact speech-to-text; (h) vulnerability management and least-privilege operational access; and (i) backup and continuity controls provided by the underlying EU cloud infrastructure.
The Customer is responsible for managing its user accounts, SSO configuration (where used), connector authorizations, optional Azure Key Vault BYOK keys and access policies (where used), and final human review before external disclosure of redacted materials.
7. Sub-processors
The Customer provides a general authorization for Northdocs to engage sub-processors listed in the Subprocessors register (https://northdocs.com/subprocessors), which is incorporated by reference as Schedule 1 to this DPA.
Transactional email (Scaleway TEM) receives recipient addresses and operational notification text. It does not receive uploaded documents, document filenames, extracted text, detections, or case file contents.
Northdocs will publish updates to this list before authorizing a new subprocessor to process Customer Personal Data (other than emergency replacements needed to maintain security or continuity). Customers may subscribe to notices by emailing legal@northdocs.com with subject “Subprocessor notices”. If a customer reasonably objects to a new subprocessor on documented data-protection grounds within 30 days of notice, the parties will discuss alternatives in good faith; if no resolution is reached, the customer may terminate the affected services as its sole remedy.
Northdocs shall impose data-protection obligations on sub-processors that are substantially no less protective than those in this DPA, and remains responsible to the Customer for sub-processor performance.
Customer-configured integrations (for example Microsoft 365, iManage, HighQ, Datasite) are engaged under the Customer's own instructions and vendor agreements; Northdocs does not appoint those vendors as Northdocs sub-processors merely by offering a connector.
8. International transfers
Customer documents and derived content are stored and processed in the European Union by default. The Customer may view the configured data region under Settings → Organization (US residency is not offered at the date of this DPA).
Where a sub-processor processes personal data outside the EEA/UK in a country without an adequacy decision, Northdocs relies on appropriate safeguards such as the EU Standard Contractual Clauses (SCCs), and supplementary measures where required.
Optional AI features (NER, Magic Redact, identity linking, cover summaries, Prompt Guard names, Outbound Guard names, Conversation Redact speech-to-text, and rule suggestions) may send document snippets, detection text, Outlook compose snippets, or audio to OVHcloud AI Endpoints when AI detection is enabled. That processing stays in the EU under the OVHcloud DPA, over HTTPS from the EU-hosted application. The Customer may disable AI / ML detection under Settings → Organization. See also the Enterprise AI Policy (https://northdocs.com/ai-policy).
9. Assistance to the Controller
Taking into account the nature of processing, Northdocs shall assist the Customer by appropriate technical and organizational measures, insofar as possible, for the fulfilment of the Customer's obligations to respond to data-subject requests under GDPR Chapter III (and UK GDPR equivalents where applicable).
Northdocs shall assist the Customer with security, breach notification, data-protection impact assessments, and prior consultation with supervisory authorities, taking into account the information available to Northdocs. Reasonable assistance beyond standard product features may be chargeable on Enterprise plans or under a separate statement of work.
10. Personal data breaches
Northdocs shall notify the Customer without undue delay after becoming aware of a personal data breach affecting Customer Personal Data, and shall provide information reasonably required for the Customer to meet its own notification obligations, as such information becomes available.
Notification is sent to the Customer's organization administrators and billing or admin contacts on file. Northdocs may also escalate via privacy@northdocs.com and security@northdocs.com as appropriate.
11. Deletion and return
During the subscription, the Customer may export redacted or pseudonymized outputs and certain audit data through the Service. Upon termination or expiry, or upon written request, Northdocs will delete Customer Personal Data from active systems within the configured retention schedule and commercially reasonable cleanup windows, unless EU or Member State law (or UK law where applicable) requires storage.
Default retention for documents and extracted data is 60 days unless the Customer configures a different retention period of up to 90 days (including per-case overrides where available). Deletion from object storage and databases is permanent and irreversible for redacted source materials once executed.
Northdocs may retain anonymized or aggregated usage metrics that do not identify data subjects or the Customer's confidential document content.
12. Audit and information rights
Northdocs shall make available to the Customer information necessary to demonstrate compliance with Article 28 GDPR, including this DPA, the Security Overview, the Subprocessors register, the Enterprise AI Policy, Architecture overview, and in-product audit logs or exports available on eligible plans.
The Customer may request an audit (no more than once per 12 months, unless required by a supervisory authority or following a confirmed breach), on 30 days' notice, during business hours, under confidentiality, and without disrupting other customers. Audits may be satisfied by providing up-to-date third-party certifications, penetration-test summaries, or questionnaire responses where available. On-site or invasive audits, if agreed, may be chargeable.
13. Liability
Liability under this DPA is subject to the limitations and exclusions in the Terms of Sale & Service (https://northdocs.com/terms), except that nothing excludes liability that cannot be limited under applicable law (including under GDPR Article 82 as applicable to each party's own fault).
Each party remains responsible for damages corresponding to its part of responsibility for any infringement of data-protection law.
14. Order of precedence and governing law
If there is a conflict between this DPA and other commercial terms regarding data-protection obligations for Customer Personal Data, this DPA prevails. If the Customer has a separately negotiated DPA or MSA signed with Northdocs, that negotiated document prevails over this standard DPA to the extent of conflict.
This DPA is governed by Danish law. The parties submit to the jurisdiction of the courts of Copenhagen, Denmark, without prejudice to data subjects' or supervisory authorities' rights under the GDPR (and UK GDPR where applicable).
15. Execution
This DPA version 2026-08-31 (published 31 August 2026) may be accepted (a) by an authorized organization administrator electronically in Northdocs under Settings → Compliance, or (b) by downloading, signing, and uploading a signed copy, or (c) by mutual exchange of signed PDF or email counter-signature with legal@northdocs.com.
Electronic acceptance records the accepting user's identity, name, title, email, IP address, timestamp, and DPA version, and constitutes a signed writing for the purposes of this DPA.
Contact: legal@northdocs.com · Northdocs ApS, Rådhuspladsen 1, 1550 København, Denmark.
Schedule 1: Sub-processors
The living Schedule 1 is published at /subprocessors. The downloadable DPA PDF embeds a snapshot of the list as of version 2026-08-31. /subprocessors.