Data Processing Agreement
Under Art. 28 GDPR • Accepted upon account creation • Effective date: September 24, 2026
ACCEPTANCE AND PARTIES
This Data Processing Agreement (the "Agreement") is concluded between 2 Create Ltd, UIC 200659554, with its registered seat and address at 8 Neptun Street, Varna 9000, Bulgaria (the "Processor" or "2 Create"), and the natural or legal person that creates an account for and uses the DocuMocu platform (the "Controller" or the "Customer"). Together they are referred to as the "Parties".
Acceptance: The Agreement is accepted electronically — by creating an account (completing the sign-up form, which states that by continuing you agree to the Terms of Service and this Agreement) and/or by using the service. The person accepting the Agreement confirms that they have authority to bind the Customer. The Agreement is an integral part of the Terms of Service and does not require a handwritten signature.
Identification of the Controller: the data identifying the Controller (name, identifier, address and contact person) are those provided upon account registration and in the account settings.
RECITALS
(A) The Parties are bound by the Terms of Service for the DocuMocu platform (the "Main Agreement"), accepted electronically upon registration.
(B) In providing the services, the Processor processes personal data on behalf of and on the instructions of the Controller.
(C) This Agreement sets out the terms of such processing in accordance with Art. 28 of Regulation (EU) 2016/679 ("GDPR") and forms an integral part of the Main Agreement.
1. Subject matter, definitions and interpretation
1.1. This Agreement governs the processing of Customer Personal Data by the Processor in its capacity as a processor for the Controller.
1.2. Terms have the meaning given in the GDPR. "Customer Personal Data" means personal data processed by the Processor on behalf of the Controller within the services under the Main Agreement. "Sub-processor" means another processor engaged by the Processor. "Applicable Data Protection Law" means the GDPR, the Bulgarian Personal Data Protection Act and other applicable law in the field.
1.3. In the event of conflict between this Agreement and the Main Agreement on data protection matters, this Agreement prevails. Where standard contractual clauses apply, they prevail.
2. Roles and scope
2.1. In respect of the Customer Personal Data, the Controller is the controller and the Processor is the processor.
2.2. The subject matter, duration, nature and purpose of the processing, the types of personal data and the categories of data subjects are described in Annex 1.
2.3. Scope: this Agreement does not cover data that the Processor processes as a controller in its own right (e.g., the Customer’s registration, account administration and billing data); such processing is governed by the Processor’s Privacy Policy.
3. Controller obligations
3.1. The Controller warrants that it has a valid legal basis for the processing of the Customer Personal Data and for instructing the Processor.
3.2. The Controller is responsible for the accuracy, quality and lawfulness of the Customer Personal Data and the means by which it acquired them.
3.3. The Controller has provided data subjects with the information required under Arts. 13 and 14 GDPR and, where applicable, has obtained consent.
3.4. The Controller’s instructions comply with Applicable Data Protection Law; the Controller determines whether a data protection impact assessment (DPIA) is required.
4. Processing on instructions (Art. 28(3)(a))
4.1. The Processor processes the Customer Personal Data only on documented instructions from the Controller, including with regard to transfers of data to a third country, unless EU or Member State law requires otherwise; in that case, the Processor informs the Controller before processing, unless the law prohibits this.
4.2. The Main Agreement, this Agreement and the Controller’s use of the platform features constitute the initial documented instructions. Additional or changed instructions are given in writing.
4.3. The Processor informs the Controller without delay if, in its opinion, an instruction infringes Applicable Data Protection Law, without thereby assuming an obligation to verify the lawfulness of the instructions.
5. Confidentiality (Art. 28(3)(b))
5.1. The Processor ensures that persons authorised to process the Customer Personal Data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality.
5.2. Access to the Customer Personal Data is limited to employees and Sub-processors who need it to provide the services (need-to-know principle).
6. Security of processing (Art. 32)
6.1. The Processor implements appropriate technical and organisational measures to ensure a level of security appropriate to the risk. The measures are described in Annex 2.
6.2. The measures take into account the state of the art, the costs of implementation, the nature, scope, context and purposes of the processing, and the risks to the rights and freedoms of natural persons.
6.3. The Processor may update the measures over time, provided that the level of security is not reduced.
7. Sub-processors (Art. 28(2) and (4))
7.1. The Controller gives the Processor general written authorisation to engage Sub-processors to process the Customer Personal Data. The current list is in Annex 3.
7.2. Where the Processor intends to add or replace a Sub-processor, it informs the Controller in advance, at least 30 days before the change (e.g., by e-mail or via the platform), giving an opportunity to object. In urgent cases (e.g. security incident or sudden unavailability of a Sub-processor), the Processor may replace a Sub-processor immediately and inform the Controller without undue delay.
7.3. If the Controller objects on reasonable data-protection grounds, the Parties seek a solution in good faith; if none is found, the Controller may terminate the relevant service.
7.4. The Processor imposes on each Sub-processor, by contract, the same data protection obligations as set out in this Agreement, and remains fully liable to the Controller for the Sub-processor’s performance.
8. Assistance with data subject rights (Art. 28(3)(e))
8.1. Insofar as possible, the Processor assists the Controller by appropriate technical and organisational measures in fulfilling its obligation to respond to requests to exercise data subject rights under Chapter III GDPR.
8.2. If the Processor receives a request directly from a data subject, it does not respond on the merits but forwards the request to the Controller without undue delay.
9. Assistance with security, breaches and impact assessments (Art. 28(3)(f); Arts. 32–36)
9.1. The Processor assists the Controller in complying with its obligations under Arts. 32–36 GDPR, taking into account the nature of the processing and the information available to it.
9.2. Breach notification (Art. 33(2)): upon becoming aware of a personal data breach affecting the Customer Personal Data, the Processor notifies the Controller without undue delay and no later than 48 hours, providing the information available at that time. To the extent not available initially, the Processor provides the following information in phases, without undue delay, as it becomes available: the nature of the breach, the categories and approximate number of data subjects and records affected, the likely consequences, and the measures taken or proposed to address the breach and mitigate its possible effects.
9.3. The Processor does not notify the supervisory authority (CPDP) or the data subjects in its own name in respect of the Customer Personal Data, unless instructed to do so in writing by the Controller.
9.4. On request, the Processor assists the Controller in carrying out data protection impact assessments (DPIAs) and prior consultations with the supervisory authority.
10. International transfers (Chapter V GDPR)
10.1. The Processor does not transfer Customer Personal Data outside the European Economic Area (EEA) unless appropriate safeguards under Chapter V GDPR are in place (an adequacy decision, standard contractual clauses or another recognised mechanism) or an applicable derogation under Art. 49 applies.
10.2. Where a transfer to a Sub-processor outside the EEA takes place, the Processor ensures an appropriate mechanism. In the absence or invalidation of an adequacy decision, the European Commission’s Standard Contractual Clauses apply as a fallback mechanism. (The validity of the EU–US Data Privacy Framework is subject to judicial review, which is why a fallback mechanism is expressly provided.)
10.3. On request, the Processor provides the Controller with information on the applicable transfer mechanism for a specific Sub-processor.
10.4. By accepting this Agreement and the general authorisation for Sub-processors under Section 7, the Controller authorises the Processor to conclude, accede to or rely on Standard Contractual Clauses and other Chapter V GDPR mechanisms with non-EEA Sub-processors on the Controller’s behalf. Where a Sub-processor provides its own data processing agreement incorporating Standard Contractual Clauses, the Processor may rely on it; the Processor retains a copy of the applicable mechanism and provides it on request.
11. Deletion or return of data (Art. 28(3)(g))
11.1. After the end of the provision of the services, the Processor, at the Controller’s choice, deletes or returns all Customer Personal Data and deletes existing copies, unless EU or Member State law requires storage.
11.2. The Controller exercises its choice within 30 days of termination. In the absence of an express choice, the Processor deletes the data after a reasonable period, save where there is a legal obligation to retain it.
12. Audit and information (Art. 28(3)(h))
12.1. The Processor makes available to the Controller all information necessary to demonstrate compliance with Art. 28 GDPR, and allows for and contributes to audits, including inspections, conducted by the Controller or an auditor mandated by it.
12.2. Audits are carried out after prior written notice within a reasonable period, during business hours, without unreasonable disruption to operations and subject to confidentiality. The cost of the audit is borne by the Controller, unless the audit reveals material non-compliance by the Processor.
12.3. The Processor may contribute to demonstrating compliance by providing up-to-date certifications or audit reports (e.g., ISO 27001, SOC 2); this does not limit the Controller’s right to audit under this Section.
12.4. The Processor maintains records of processing activities carried out on behalf of the Controller in accordance with Art. 30(2) GDPR.
13. Liability
13.1. The liability of each Party is governed by Art. 82 GDPR and by the Main Agreement. The limitations of liability set out in the Main Agreement also apply to this Agreement, to the extent permitted by applicable law.
13.2. Each Party is liable for the damage caused by its non-compliance with its obligations under Applicable Data Protection Law.
14. Term and termination
14.1. This Agreement takes effect upon its acceptance (account creation) and remains in force for as long as the Processor processes Customer Personal Data.
14.2. Provisions which by their nature should survive (confidentiality, deletion or return of data, audit and liability) remain in force after termination.
15. Final provisions
15.1. The Processor may update this Agreement to reflect changes in applicable law or in the Service by publishing the updated version and notifying the Controller by appropriate means (e.g., by e-mail or via the platform). If a change is material and the Controller does not accept it, the Controller may terminate the relevant service before it takes effect; continued use after it takes effect constitutes acceptance.
15.2. This Agreement is governed by the law of the Republic of Bulgaria. The competent courts are those specified in the Main Agreement.
15.3. This Agreement is drawn up in Bulgarian and English. In the event of any discrepancy between the two versions, the Bulgarian text prevails.
15.4. Annexes 1, 2 and 3 form an integral part of this Agreement.
15.5. This Agreement is accepted and concluded electronically and is valid without a handwritten signature. The Processor retains the accepted version and an electronic record of acceptance.
Annex 1 — Description of the processing
Subject matter: provision of the DocuMocu platform and related services.
Duration: for the term of the Main Agreement and until deletion or return of the data under Section 11.
Nature and purpose: creation, sending, signing, tracking and storage of electronically signed documents on the Controller’s instructions, including building and maintaining an audit trail of the signing process.
Types of personal data: identification and contact data (names, e-mail addresses); user accounts and identifiers; signatory data; electronic signature metadata (date and time, IP address, location (derived from IP address), audit trail); document content, which may contain personal data of third parties. The specific types are determined by the Controller.
Categories of data subjects: signatories and senders; employees, customers and counterparties of the Controller; other persons whose data are contained in the documents that the Controller processes via the platform.
Special categories: as a rule, none are envisaged. If the Controller enters such data, it is responsible for the existence of a legal basis and for informing the Processor.
Annex 2 — Technical and organisational measures (Art. 32)
- Access control: individual accounts, authentication, and role and permission management on a least-privilege basis.
- Encryption: encryption of data in transit (TLS); measures to protect data at rest (including pseudonymisation and/or encryption, where applicable).
- Confidentiality, integrity, availability and resilience of processing systems and services.
- Backups and the ability to restore availability and access in a timely manner in the event of an incident.
- Logging and monitoring of access and events in the systems.
- Vulnerability management and regular updates; separation of production and staging environments.
- Organisational measures: internal policies, staff training, confidentiality commitments and a breach procedure.
- Regular testing, assessing and evaluating the effectiveness of the measures.
The specific measures reflect those actually implemented by the Processor and may be updated, provided the level of security is not reduced.
Annex 3 — List of Sub-processors
| Sub-processor | Service | Location | Transfer mechanism |
|---|---|---|---|
| DigitalOcean | Hosting & infrastructure | EU (Germany) | EU residency |
| Cloudflare (R2) | Object storage & CDN | EU / Global | SCC |
| AWS (SES) | Transactional emails | USA | DPF + SCC (fallback) |
| AWS (S3) | Inbound email file storage | USA | DPF + SCC |
| Postmark | Transactional emails | USA | SCC |
| Firebase | Push notifications | USA | DPF + SCC (fallback) |
| Sentry | Error tracking | USA | DPF + SCC (fallback) |
| Laravel Nightwatch | Performance monitoring | USA | SCC |
| Stripe | Payment processing | USA (+ EU infrastructure) | DPF (active) + SCC |
| Intercom | Customer support chat | USA | DPF + SCC (fallback) |
| Filepreviews | File preview & metadata generation | USA (AWS S3) | SCC |