Last updated: 6 July 2026 · List of sub-processors
1.1 This data processing agreement ("DPA") forms part of Doclane's terms of service or other agreement between the parties regarding the customer's use of the service ("the main agreement"). By using the service, the customer accepts this DPA.
1.2 In the event of any inconsistency between this DPA and the main agreement regarding the processing of personal data, this DPA prevails.
1.3 This DPA applies where the customer is the controller (or a processor acting on behalf of another controller) and Doclane processes personal data on the customer's behalf in connection with the delivery of the service.
2.1 Supplier (processor): Doclane, company reg. no. 35682821, Åbogade 14, 8200 Aarhus N, Denmark ("Doclane" or "the processor").
2.2 The customer (controller): the legal entity identified as the customer in the main agreement.
2.3 The parties agree that the customer is the controller and Doclane is the processor, as those terms are used in the General Data Protection Regulation (Regulation (EU) 2016/679, "GDPR").
3.1 Subject matter. Doclane processes personal data on the customer's behalf in order to deliver the Doclane platform and related services as described in the main agreement.
3.2 Duration. This DPA applies for as long as Doclane processes personal data on the customer's behalf under the main agreement, and until all personal data has been deleted or returned in accordance with this DPA.
4.1 Doclane processes personal data for the following purposes:
4.2 The nature of the processing includes, as applicable: collection, recording, organisation, structuring, storage, adaptation, retrieval, use, disclosure by transmission (e.g. to sub-processors), alignment, restriction, erasure or destruction.
5.1 Types of personal data. Depending on the customer's configuration and use, the following may be processed:
5.2 Special categories. The service is not intended for the processing of special categories of personal data under GDPR art. 9 (e.g. health, political opinions, religion) or data relating to criminal convictions. The customer must ensure that such data is not knowingly sent to the service.
5.3 Data subjects. The data subjects may include: the customer's end customers and suppliers; the customer's employees, consultants and agents; and other individuals whose personal data forms part of the customer's data.
6.1 Doclane processes personal data only on documented instructions from the customer, including with regard to transfers to third countries, unless required otherwise by EU or Member State law. In such a case, Doclane informs the customer of the legal requirement before processing, unless prohibited by law.
6.2 The main agreement (including this DPA) and the customer's configuration and use of the service constitute the customer's complete and final instruction to Doclane.
6.3 If Doclane reasonably believes an instruction infringes the GDPR or other applicable data protection law, Doclane informs the customer without undue delay.
6.4 The customer is responsible for: the lawfulness of the processing; providing appropriate information to data subjects; obtaining any necessary consents; and ensuring that the personal data sent to the service is adequate, relevant and limited to what is necessary.
7.1 Doclane ensures that persons authorised to process personal data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality.
8.1 Taking into account the state of the art, the costs of implementation and the nature, scope and purposes of the processing as well as the risks to data subjects, Doclane implements appropriate technical and organisational measures, including as applicable:
8.2 Doclane may implement specific measures through its infrastructure suppliers and sub-processors (e.g. data centre security, network security, backup). The entire infrastructure is hosted in the EU.
8.3 The customer is responsible for appropriate security in its own environment, including secure use of the service (e.g. account management, access control, configuration).
9.1 The customer authorises Doclane to engage other processors ("sub-processors") for the processing described in this DPA.
9.2 Doclane ensures that every sub-processor is bound by written data protection obligations no less protective than those in this DPA.
9.3 The current list of sub-processors is published at sub-processors and may be updated from time to time.
9.4 Doclane notifies the customer of intended changes by email (to the registered billing address) with at least 30 days' notice and gives the customer the opportunity to object on reasonable data protection grounds. If the parties cannot agree on an alternative, the customer may terminate the affected part of the service with 30 days' written notice.
10.1 The customer's data is stored within the European Economic Area (EEA).
10.2 Doclane's entire technology stack, including AI processing, is located in the EU/EEA. No personal data is transferred to third countries outside the EEA. Should such a transfer exceptionally become necessary, it will take place only with appropriate safeguards under GDPR Chapter V (e.g. Standard Contractual Clauses).
11.1 Taking into account the nature of the processing, Doclane assists the customer with appropriate technical and organisational measures in fulfilling the customer's obligation to respond to requests from data subjects (e.g. access, rectification, erasure, restriction, portability, objection).
11.2 If Doclane receives a request directly from a data subject concerning personal data processed on the customer's behalf, Doclane will (unless prohibited by law) forward the request to the customer without undue delay and will not respond directly unless the customer has approved it or the law requires it.
12.1 In the event of a personal data breach affecting personal data processed on the customer's behalf, Doclane notifies the customer without undue delay after becoming aware of the breach.
12.2 The notification includes the information reasonably available to Doclane, including the nature of the breach, the categories and approximate number of affected data subjects and data records, the likely consequences and the measures taken or proposed.
12.3 Where it is not possible to provide all information at the same time, it may be provided in phases without undue delay.
12.4 The customer is responsible for determining whether the supervisory authority and/or data subjects must be notified, and for making such notifications, unless otherwise agreed.
13.1 Taking into account the nature of the processing and the information available to Doclane, Doclane assists the customer (against reasonable payment where relevant) with data protection impact assessments (DPIAs) relating to the service and prior consultations with supervisory authorities where required.
14.1 Doclane makes available all information reasonably necessary to demonstrate compliance with the obligations in GDPR art. 28.
14.2 This may take the form of documentation of security and data protection measures, external audit reports or certifications (where available) and responses to reasonable written questionnaires.
14.3 With reasonable prior notice and no more than once per 12 months (unless required by an authority, or following a security breach), the customer or an independent auditor may conduct an audit of Doclane's practices relating to the service. Any such audit is limited to relevant systems, is subject to Doclane's confidentiality and security policies, is carried out during normal business hours and may be subject to a reasonable fee.
15.1 On termination of the service, Doclane will, at the customer's choice and subject to applicable law, delete all personal data processed on the customer's behalf, or return it to the customer and then delete existing copies.
15.2 Unless the customer requests earlier deletion or return, Doclane may retain personal data for up to 30 days after termination so that the customer can export data. Thereafter, Doclane may delete or anonymise the data, subject to any statutory retention requirements.
15.3 Doclane may retain copies where required by law, or in backup systems for a limited period until they are overwritten in the ordinary course of operations. Such data remains covered by the protections in this DPA.
15.4 Exceptions. The following may be retained for longer where necessary and proportionate: data that must be retained by law; information necessary to establish or defend legal claims; security logs for fraud and abuse monitoring; and accounting, tax and payment data.
16.1 The limitations of liability set out in the main agreement also apply to this DPA to the extent permitted by law.
16.2 Nothing in this DPA limits mandatory liability under the GDPR where such limitation is not permitted.
17.1 This DPA is governed by the same law as the main agreement, namely Danish law, without regard to conflict-of-law rules.
17.2 Any dispute is settled at the same venue as the main agreement (the Danish courts, with the District Court of Aarhus as the court of first instance, unless mandatory law provides otherwise).
18.1 This DPA forms part of the main agreement and does not change its general commercial terms, fees or limitations of liability beyond what is stated herein.
18.2 If a provision is invalid or unenforceable, the remaining provisions remain in full force, and the invalid provision is replaced by a valid one that best reflects the parties' intention.
18.3 Doclane may update this DPA with at least 30 days' notice (by email or in the product). Material changes will be clearly identified. Continued use after the notice period constitutes acceptance of the updated DPA.
19.1 Use of AI models. Doclane uses language models and related AI models via an EU-based supplier, see the list of sub-processors, to deliver the AI functionality in the service, including reading, classifying and extracting data from documents.
19.2 Categories of data processed by AI models. Depending on the customer's configuration, personal data sent to AI models may include identifiers (name, email, order number), document content, order and transaction details, and limited technical metadata for context.
19.3 AI sub-processors are listed under sub-processors and are covered by the same notification and objection mechanism as other sub-processors (section 9).
19.4 Limited retention. AI sub-processors retain data only to the extent and for the short period technically necessary for the processing, and never for any other purpose. The processing takes place in the EU.
19.5 No training. The customer's data is not used to train or improve the underlying AI models, whether by Doclane, by AI sub-processors or by the underlying model providers. This applies to all plans.
19.6 Customer-specific improvement. Doclane may store the customer's own corrections and document templates in order to improve extraction from that customer's future documents. This data is stored in isolation per customer, is not shared across customers and is not used to train underlying AI models.
19.7 The EU AI Act. Doclane designs and operates the AI functionality so that end users are informed where required under the EU AI Act. The customer remains responsible for its own obligations as a deployer, including appropriate human oversight.
Questions about this data processing agreement? Write to hello@doclane.ai or Doclane, Åbogade 14, 8200 Aarhus N, Denmark. Company reg. no. 35682821.