Legal
Data Processing Agreement
Draft — not yet in force. This text is a working draft awaiting review by qualified counsel. Passages marked like this depend on facts that are not yet fixed. The technical measures in Annex 2 must match what the platform actually does before this is offered to anyone.
This agreement governs how we process personal data on your behalf when you use the Service. It applies automatically to every customer — you do not have to request or sign anything separately, though we will sign a copy if your procurement process needs one. Write to privacy@dynamicdocumentapi.com.
1. Scope and precedence
This agreement forms part of the Terms of Service between you (the controller) and N.M.M. Noble Minds Media Ltd (the processor). It applies whenever we process personal data on your behalf in providing the Service. On data protection matters it takes precedence over the Terms of Service. Where you are yourself a processor for someone else, this agreement operates as a processor-to-processor arrangement and your own controller’s instructions flow through you to us.
2. Definitions
Controller, processor, personal data, processing, data subject, personal data breach and supervisory authority have the meaning given in the GDPR. Customer Personal Data means personal data contained in Customer Content and Output as defined in the Terms of Service. Data Protection Law means the GDPR, the UK GDPR, the Swiss FADP and any other data protection law that applies to the processing.
3. Roles and subject matter
You decide why and how Customer Personal Data is processed. We process it only to provide, secure and support the Service, as set out in Annex 1. We remain the controller for the account, billing, support and security data described in our Privacy Policy; that data is outside this agreement.
You are responsible for having a legal basis for the processing, for informing data subjects, and for the lawfulness of the content you send us — including whether you may capture a third-party web page.
4. Your instructions
We process Customer Personal Data only on your documented instructions. The Terms of Service, this agreement, the settings you choose in the workspace and each API request you send are your instructions. Additional instructions must be agreed in writing; if they require work beyond the Service as documented, we may charge for it.
We will tell you if, in our view, an instruction breaches Data Protection Law, and may suspend that instruction until it is resolved. We will not process Customer Personal Data for our own purposes, and we will not use it to train machine-learning models.
5. Confidentiality
Everyone we allow to process Customer Personal Data is bound by confidentiality obligations that survive the end of their engagement, and receives access only to the extent their work requires.
6. Security of processing
We implement the technical and organisational measures in Annex 2 and keep them under review. Measures may change as technology moves on, but the overall level of protection will not fall below what Annex 2 describes. You are responsible for the security of your own systems and for how you configure the workspace — in particular retention windows, whether payload logging is enabled, who has access and how API keys are handled.
7. Sub-processors
You give us general authorisation to engage sub-processors. The current list, with purpose and location, is at dynamicdocumentapi.com/subprocessors.
Before a new sub-processor starts processing Customer Personal Data, we announce it there and notify subscribers at least [TO CONFIRM: 30] days in advance. You may object on reasonable data protection grounds within that period. If we cannot resolve your objection, you may terminate the affected part of the Service and receive a pro-rata refund of prepaid fees for the unused period.
We impose on every sub-processor data protection obligations no less protective than those in this agreement, and we remain fully liable to you for their performance.
8. Data subject requests
The workspace lets you access, export, correct and delete Customer Personal Data yourself, which will answer most requests. Where it does not, we assist you with appropriate technical and organisational measures, as far as is reasonably possible, and at your cost where the effort goes beyond the Service as documented.
If a data subject contacts us directly about Customer Personal Data, we will not respond on the substance. We will forward the request to you without undue delay, and tell the data subject that we did.
9. Assistance with your obligations
Taking into account the nature of the processing and the information available to us, we assist you with your obligations under Articles 32 to 36 GDPR: security of processing, breach notification, data protection impact assessments and prior consultation.
10. Personal data breaches
If we become aware of a personal data breach affecting Customer Personal Data, we notify you without undue delay and in any event within [TO CONFIRM: 48] hours of becoming aware. The notification describes what happened, which categories and approximate numbers of data subjects and records are affected, the likely consequences, the measures taken and a contact point. Where we cannot provide all of it at once, we provide it in phases without undue further delay.
We will not notify supervisory authorities or data subjects on your behalf unless you instruct us to, and we will not name you publicly without your agreement unless the law requires it.
11. Deletion and return
During the term, deletion follows the retention windows in the Terms of Service and your workspace settings. On termination you may export Customer Personal Data for 30 days. After that we delete it, including from backups as they roll off within [TO CONFIRM: 35] days, unless the law requires us to keep it — in which case we keep it only for that purpose and continue to protect it under this agreement.
We confirm deletion in writing on request.
12. Audits and evidence
We make available the information needed to demonstrate compliance with Article 28 GDPR. In practice, in this order:
- this agreement, Annex 2 and the security page;
- our answers to your written security questionnaire, once per year and free of charge;
- [TO CONFIRM: third-party audit reports once they exist — do not promise SOC 2 or ISO 27001 before it is certified];
- an on-site audit, where the above genuinely does not suffice: with 30 days’ notice, during business hours, no more than once a year unless a supervisory authority or a breach requires otherwise, by you or an independent auditor who is not our competitor and who signs a confidentiality undertaking, at your cost, and without access to other customers’ data.
13. International transfers
You choose the processing region for your workspace. If Customer Personal Data is transferred out of the EEA, the transfer is based on the Standard Contractual Clauses (Commission Implementing Decision (EU) 2021/914), which are incorporated into this agreement by reference:
- Module Two (controller to processor) where you are a controller, and Module Three (processor to processor) where you are a processor;
- Clause 7 (docking) applies; Clause 9 option 2 (general written authorisation) with the notice period in section 7; Clause 11 without the independent dispute resolution option; Clause 17 option 1 with the law of Cyprus; Clause 18(b) the courts of [TO CONFIRM: Cyprus];
- Annexes I, II and III of the Clauses are Annexes 1, 2 and 3 of this agreement;
- for the United Kingdom, the ICO International Data Transfer Addendum applies; for Switzerland, the Clauses are read with the amendments required by the FADP.
We have assessed the law of the destination countries and apply supplementary measures, in particular encryption in transit and at rest, access control and the commitment in section 14. We provide our transfer impact assessment on request.
14. Government access requests
If an authority requests access to Customer Personal Data, we notify you before disclosing anything, unless we are legally barred from doing so — in which case we challenge the prohibition and disclose only the minimum legally required. We do not give any authority direct or unrestricted access to Customer Personal Data, and we do not hold decryption keys for any authority. We publish the number of such requests [TO CONFIRM: transparency report planned? Only promise it if it will exist.]
15. United States: service provider terms
Where the California Consumer Privacy Act or a comparable US state law applies, we act as a service provider or processor. We process personal information only to perform the Service, do not sell or share it, do not retain, use or disclose it outside the direct business relationship, and do not combine it with personal information from other sources except as permitted. We will notify you if we can no longer meet these obligations.
16. Liability, term and law
The liability provisions of the Terms of Service apply to this agreement, subject to any mandatory rule of Data Protection Law and to the Standard Contractual Clauses, which prevail in the event of conflict. This agreement lasts as long as we process Customer Personal Data. It is governed by the law stated in the Terms of Service, save that the Clauses are governed by the law named in section 13.
Annex 1 — Description of the processing
A. Parties
Data exporter: you, as identified in your workspace. Data importer: N.M.M. Noble Minds Media Ltd, registration number HE 453611, Grigori Afxentiou 7, 6023 Larnaca, Cyprus, contact privacy@dynamicdocumentapi.com.
B. Description
| Categories of data subjects | Whoever you put into your documents: your customers, employees, suppliers, members, recipients of invoices, certificates or messages. |
|---|---|
| Categories of personal data | Whatever your templates and payloads contain — typically names, addresses, contact details, customer and order numbers, amounts, dates, usage data, and images. Also the metadata of your API requests. |
| Special categories | Not permitted without a separate written agreement (Terms of Service, section 9). We do not knowingly process them. |
| Frequency | Continuous, for as long as you use the Service. |
| Nature and purpose | Receiving, rendering, storing and delivering documents and images; operating, securing and supporting the platform. |
| Retention | As set out in the Terms of Service, section 11, and your workspace settings. |
| Sub-processors | See Annex 3. |
C. Competent supervisory authority
For Module Two and Three transfers: the supervisory authority of the member state where you are established, or where you have designated an Article 27 representative. Ours is the Office of the Commissioner for Personal Data Protection of the Republic of Cyprus.
Annex 2 — Technical and organisational measures
[TO CONFIRM: every line against the running platform. A measure listed here that is not implemented is a misrepresentation with contractual effect.]
| Encryption | TLS 1.2 or higher in transit; encryption at rest for stored files, databases and backups; signed, expiring URLs for file delivery |
|---|---|
| Access control | Least privilege, multi-factor authentication for staff, individual accounts, access reviews, logged administrative access |
| Tenant separation | Logical separation of workspaces enforced in the data layer, with automated tests |
| Rendering isolation | Each render runs in a sandbox without access to other customers’ data, with restricted outbound network access |
| Key management | API keys stored as hashes; secrets in a managed key store; rotation supported |
| Logging and monitoring | Security-relevant events logged and monitored; alerting on anomalies; audit log available to customers |
| Backups and restore | Regular encrypted backups, restore tested [TO CONFIRM: how often] |
| Secure development | Code review, dependency and secret scanning in CI, separate environments, no production data in development |
| Incident response | Documented process with defined roles and the notification duty in section 10 |
| Deletion | Automatic deletion at the end of the retention window; purge after workspace deletion; backups roll off |
| Staff | Confidentiality undertakings, security training, offboarding checklist |
| Sub-processor management | Due diligence before engagement, contractual obligations, published list |
Annex 3 — Sub-processors
The current list, including purpose, data categories and location, is published at dynamicdocumentapi.com/subprocessors and forms part of this agreement. Changes follow section 7.
Change history
| Version | Date | Change |
|---|---|---|
| 0.1 | 23 September 2026 | First draft, pending legal review |