Data processing
Data processing agreement
Does docivault offer a data processing agreement?
In preparation. No date is promised.
Current position
What we actually do with your data, stated plainly
We process the data you and your workspace put into docivault only to run the service — your account, your workspace membership, your authentication data, and the documents you upload together with the comments and categories on them — and we enforce who can see what. Some access by your contacts is recorded, and workspace activity is recorded; a complete audit record of every view and download by every kind of user is not built yet. We do not sell your data, and we do not use it to train anything. Every third party that touches it is named on the subprocessors page, along with what it does and where it runs. Data is stored in India today; it is not stored in the EU.
What a DPA would need to cover
The shape a signable agreement with us would take, once one exists
A data processing agreement with docivault would need to name the categories of data processed, list the subprocessors above with a mechanism to notify you of changes to that list, state the security measures actually in place rather than a certification we do not hold, commit to a breach-notification timeline, describe deletion of your data on account or workspace termination, and address the current data location in India rather than imply an EU location we cannot back.
Status
Not drafted yet — email us if you need one before you can proceed
A signable DPA is in preparation, with no date promised. If a DPA is a requirement for you today, email privacy@docivault.com and tell us what it needs to cover — that is genuinely useful input into drafting it, rather than a request we can fulfil immediately.