Data Processing Agreement.
This page summarises how ASHDOCS acts as a data processor for its customers. A countersigned DPA is available on request via the contact page. Last updated: 1 August 2026.
Scope and roles
For documents you upload, you (the customer) are the data controller and ASHDOCS is the data processor. We process personal data contained in your documents only on your instructions — i.e., to run the tool you invoked — and never for our own purposes.
Nature and purpose of processing
Automated document processing: format conversion, editing, OCR, redaction and structured data extraction. Data subjects are typically your end-users or counterparties whose information appears in the documents you submit.
Sub-processors
Current sub-processors: Cloudflare (object storage and CDN), Razorpay (billing — customer account data only, never document contents), Anthropic (AI extraction, only when an extraction tool is used), Google (OAuth sign-in and optional Drive delivery), PostHog (product analytics — usage metadata only, never document contents). We will give notice before adding a sub-processor that touches document contents.
Security measures
TLS 1.2+ in transit, AES-256 at rest, Fernet-encrypted third-party credentials, ClamAV scanning of every upload, SSRF guards on URL-fetching endpoints, and per-request or account-wide zero-retention. Details on the security page.
Data subject requests
If a data subject request reaches us that concerns data you control, we forward it to you and assist with access or deletion — most simply via zero-retention mode and the 24-hour default purge, which mean ASHDOCS usually holds no document data to disclose.
Data transfers
Processing runs on cloud infrastructure operated by the sub-processors above. Where transfers of EU/UK personal data occur, we rely on the sub-processors' standard contractual clauses. Region-pinned storage is on the roadmap for Enterprise and is not offered today.