Data Processing Agreement

Version 1.1 · Last updated 2026-07-25

This Data Processing Agreement (“DPA”) is between the customer (“Controller”, “you”) and Zerodoc — the trading name of Rocsoft Ltd, a limited company incorporated in the Isle of Man (“Processor”, “we”) — for use of the Zerodoc document-extraction API (the “Service”). It is incorporated into our Terms of Service by reference and applies automatically to all customers — no signature is required.

Download (Markdown)

1. Subject matter and roles

For customer documents submitted to the Service, you are the Controller and Zerodoc is the Processor. We process such documents solely to provide the Service (OCR and structured field extraction) on your instructions.

2. Nature and purpose of processing

  • Purpose: extracting text and structured fields from documents you submit.
  • Processing model: documents are processed in memory only and discarded immediately after the API response. No document or extracted content is written to disk or retained.
  • Duration: the duration of each API request only.

3. Categories of data and data subjects

You determine the content of submitted documents and therefore the categories of personal data they may contain (e.g. names, addresses, financial details on invoices). Because we do not retain documents, we hold no record of these beyond the request lifecycle.

4. Data we retain (as Processor/Controller for account data)

We retain only: account email, a one-way hash of your API key, and usage metadata (page counts, timestamps, status). We do not retain document content.

5. Sub-processors

Sub-processorPurposeLocation
CloudflareAuth, billing & usage metadataEU data localization
StripePayment processingEU/US (SCCs)
ResendTransactional emailEU/US (SCCs)
netcupStateless document processingEU (Germany)

We will give notice of new sub-processors and provide an opportunity to object.

6. Security measures

  • Documents processed in memory only; no disk persistence; in-memory buffers cleared on completion.
  • TLS in transit; API keys stored only as SHA-256 hashes.
  • Per-key rate limiting and quotas; least-privilege access to metadata systems.

7. International transfers

Document processing occurs in the EU. Where personal data is processed outside the UK/EEA by a sub-processor, transfers are governed by Standard Contractual Clauses and/or the provider’s data-localization options.

8. Data subject requests & assistance

Because we do not retain documents, requests relating to document content are fulfilled by you as Controller. We will assist with requests relating to account data we hold.

9. Breach notification

We will notify you without undue delay after becoming aware of a personal data breach affecting data we process on your behalf.

10. Deletion

Documents are never retained, so there is nothing to delete post-processing. Account data is deleted on request or on account closure, subject to legal retention requirements.

11. Audit

We will make available information reasonably necessary to demonstrate compliance, including relevant certifications as our compliance programme matures (SOC 2 Type II is on our roadmap).

12. Term and governing law

This DPA applies for as long as we process documents on your behalf under the Terms of Service, and is governed by the same law and jurisdiction as those terms (Isle of Man).

Questions, or a countersigned copy for your records: privacy@zerodoc.io. See also our Privacy Policy and Security pages.