Data Processing Addendum
For SS Doc Pro Plan Users
Last updated: September 30, 2025
Important Notice
This Data Processing Addendum ("DPA") applies to Pro plan users of SS Doc who process personal data through document collections. By using our Pro service, you agree to the terms set forth in this DPA, which supplements our main Terms of Service and Privacy Policy.
1. Definitions and Scope
1.1 Definitions
For the purposes of this DPA:
- "Controller" means you, the Pro plan user, who determines the purposes and means of processing personal data
- "Processor" means SS Doc (SoftSolvez), acting on behalf of the Controller
- "Personal Data" means any information relating to an identified or identifiable natural person
- "Processing" means any operation performed on personal data
- "Data Subject" means the individual whose personal data is being processed
- "GDPR" means the General Data Protection Regulation (EU) 2016/679
- "Services" means SS Doc's document collection and management platform
1.2 Scope
This DPA applies when you use SS Doc Pro services to collect, store, or process personal data through document collections. It does not apply to your own account data, which is covered by our Privacy Policy.
2. Data Processing Instructions
2.1 Processing Authority
SS Doc processes personal data only on your documented instructions as the Controller. These instructions include:
- Configuration of document collection settings
- Access controls and permissions
- Retention and deletion requirements
- Export and data subject access requests
2.2 Prohibited Processing
SS Doc will not process personal data for any purpose other than providing the Services as instructed by you. We will not sell, share, or use personal data for our own commercial purposes.
3. Controller Responsibilities
As the Controller, you are responsible for:
Legal Compliance
- • Ensuring lawful basis for processing
- • Obtaining necessary consents
- • Complying with data minimization principles
- • Meeting retention requirements
Data Subject Rights
- • Providing privacy notices
- • Handling access requests
- • Managing consent withdrawal
- • Responding to complaints
Data Accuracy
- • Ensuring data accuracy
- • Updating incorrect information
- • Deleting outdated data
- • Validating collection requirements
Risk Assessment
- • Conducting impact assessments
- • Evaluating processing risks
- • Implementing safeguards
- • Regular compliance reviews
4. Security Measures
4.1 Technical Safeguards
SS Doc implements the following technical security measures:
Encryption
- • AES-256 encryption at rest
- • TLS 1.3 encryption in transit
- • Encrypted database storage
- • Secure key management
Access Controls
- • Multi-factor authentication
- • Role-based access control
- • Regular access reviews
- • Audit logging
4.2 Organizational Measures
- Staff training on data protection and security
- Regular security assessments and penetration testing
- Incident response and breach notification procedures
- Secure development lifecycle practices
- Business continuity and disaster recovery planning
5. Sub-processors
5.1 Current Sub-processors
SS Doc may engage the following categories of sub-processors:
Service Provider | Purpose | Location |
---|---|---|
Amazon Web Services | Cloud infrastructure and storage | Multiple regions |
Convex | Database and backend services | United States |
Clerk | Authentication services | United States |
5.2 Sub-processor Changes
We will provide 30 days' advance notice of any changes to sub-processors. If you object to a new sub-processor, you may terminate your Pro subscription without penalty within the notice period.
6. International Transfers
When personal data is transferred outside the EEA, we ensure appropriate safeguards:
- Standard Contractual Clauses: We use EU Commission-approved SCCs for transfers to third countries
- Adequacy Decisions: We rely on adequacy decisions where available
- Additional Safeguards: We implement supplementary measures where required
- Transfer Impact Assessments: We conduct assessments for high-risk transfers
7. Data Subject Rights Support
SS Doc will assist you in fulfilling data subject rights requests:
Automated Support
- • Data export functionality
- • Document search and filtering
- • Bulk deletion tools
- • Access logging
Manual Assistance
- • Technical support for complex requests
- • Guidance on data location
- • Assistance with data format conversion
- • Support for legal compliance
Response time: We will assist with data subject requests within 10 business days of your request.
8. Data Breach Notification
8.1 Notification Timeline
In case of a personal data breach, SS Doc will notify you without undue delay and, where feasible, within 72 hours of becoming aware of the breach.
8.2 Notification Content
Breach notifications will include:
- Nature and categories of personal data affected
- Approximate number of data subjects affected
- Likely consequences of the breach
- Measures taken or proposed to address the breach
- Contact information for further details
9. Return and Deletion of Data
9.1 Upon Termination
Upon termination of your Pro subscription, we will:
- Provide 30 days to export your data
- Delete all personal data after the export period
- Confirm deletion in writing upon request
- Retain only what's required by law
9.2 Data Deletion Requests
You may request deletion of specific data at any time. We will implement deletions within 30 days unless legally required to retain the data.
10. Audit Rights
10.1 Information Provision
SS Doc will provide information necessary to demonstrate compliance with this DPA, including security certifications, audit reports, and compliance documentation.
10.2 Audit Cooperation
We will reasonably cooperate with audits conducted by you or an independent auditor mandated by you, subject to confidentiality obligations and reasonable advance notice.
11. Liability and Indemnification
Each party's liability under this DPA is subject to the limitation of liability provisions in the main Terms of Service. However, this limitation does not apply to:
- Violations of data protection laws
- Unauthorized disclosure of personal data
- Failure to implement required security measures
- Breach of confidentiality obligations
12. Term and Termination
This DPA takes effect when you subscribe to SS Doc Pro and remains in effect for the duration of your subscription and any period during which we process personal data on your behalf. The provisions regarding data return, deletion, and confidentiality survive termination.
13. Contact Information
For questions about this DPA or to exercise your rights under it, contact:
- Data Protection Officer: [email protected]
- Legal Department: [email protected]
- Emergency Contact: Available 24/7 for data breach notifications
- Response Time: We respond to DPA-related inquiries within 5 business days