# Data Processing Agreement

Source: https://contracko.com/legal/dpa

# Data Processing Agreement

Version 1.0. Last updated: 26 July 2026. Contracko contact: [security@contracko.com](mailto:security@contracko.com).

## 1. Parties, roles, and relationship to the main agreement

This Data Processing Agreement ("DPA") forms part of and is incorporated into the agreement between the Customer ("Controller" or "Customer") and Velocity Ventures B.V., Van Imhoffplein 19, 2595 SK Den Haag, Netherlands (KvK 87321432) ("Processor" or "Contracko"), under which Contracko provides the Contracko service ("Service") - namely the Common Paper Cloud Service Agreement (Standard Terms v2.1) as accepted by the Customer or as set out in a signed Cover Page (the "Agreement").

For personal data that Contracko processes on the Customer's behalf in providing the Service, the Customer is the controller and Contracko is the processor. Where Contracko processes data for its own purposes (for example account administration, billing, and security), it acts as an independent controller for that limited processing, governed by Contracko's privacy policy.

In case of conflict, the order of precedence is: (1) the Standard Contractual Clauses in Annex 3 (to the extent they apply to a restricted transfer), (2) this DPA, (3) the Agreement.

## 2. Definitions

"personal data", "processing", "data subject", "controller", "processor", "sub-processor", and "supervisory authority" have the meanings given in the EU General Data Protection Regulation (Regulation (EU) 2016/679, "GDPR"). "Applicable Data Protection Law" means the GDPR together with the Dutch implementing law (UAVG) and, where applicable, the UK GDPR and the Swiss FADP. "Restricted Transfer" means a transfer of personal data to a country outside the EEA that is not covered by an adequacy decision.

## 3. Subject matter, duration, nature and purpose (Art. 28(3))

- Subject matter: processing of personal data contained in or related to the contracts, documents, and account data the Customer submits to the Service.
- Duration: the term of the Agreement, plus the deletion/return period in Section 11.
- Nature and purpose: storage, organisation, parsing, AI-assisted analysis and extraction, retrieval, electronic signature, and management of the Customer's contract data, solely to provide the Service.
- Full processing particulars are set out in Annex 1.

## 4. Types of personal data and categories of data subjects

- Types (illustrative, Customer-determined): names, contact details, signatures, financial and commercial terms, employment-related details, and any other personal data the Customer includes in uploaded documents and account data.
- Categories of data subjects: the Customer's employees, customers, suppliers, counterparties, and other individuals named in the Customer's documents.

The Customer is responsible for ensuring it has a lawful basis for the personal data it submits and for the instructions it gives. The Customer must not submit special-category data except as incidental to contract content, and is responsible for any such data it chooses to submit.

## 5. Processor obligations (Art. 28(3)(a)–(h))

Contracko shall:

1. process personal data only on the Customer's documented instructions (including for transfers), which comprise this DPA, the Agreement, and the Customer's configured use of the Service, unless required by law - in which case Contracko informs the Customer first, unless the law prohibits it;
2. ensure persons authorised to process personal data are bound by confidentiality;
3. implement the technical and organisational measures in Annex 2 (TOMs) (Art. 32);
4. respect the conditions in Section 6 for engaging sub-processors;
5. assist the Customer, by appropriate technical and organisational measures and insofar as possible, with data-subject requests (Section 7);
6. assist the Customer with security, personal-data-breach notification, data protection impact assessments, and prior consultation (Sections 8–9), taking into account the nature of processing and the information available to Contracko;
7. at the Customer's choice, delete or return personal data at the end of the Service (Section 11);
8. make available information necessary to demonstrate compliance and allow for audits (Section 10); and
9. not use the Customer's personal data to train any AI model, and engage AI sub-processors only on terms that exclude training on Customer data and, where offered, apply zero data retention.

Unlawful instructions. Contracko will inform the Customer without undue delay if, in its opinion, an instruction infringes Applicable Data Protection Law. The Customer will then have a reasonable period (at least 30 days) to issue a revised, lawful instruction. Pending resolution Contracko may suspend the affected processing, and if the Customer does not provide a lawful instruction within that period Contracko may terminate the affected part of the Service without liability.

## 6. Sub-processors (Art. 28(2) and (4))

General authorisation. The Customer provides general written authorisation for Contracko to engage sub-processors to process personal data in providing the Service, in categories including hosting and storage, database, AI-assisted analysis, electronic signature, email delivery, analytics, and payments. The current, specifically-named sub-processor list is set out in Annex 1.

Notice of changes. Contracko maintains a current, specifically-named sub-processor list. At least fourteen (14) days before authorising a new sub-processor to process personal data, Contracko will update the list and actively notify the Customer by email.

Objection. The Customer may object to a new sub-processor on reasonable grounds relating to data protection by written notice within seven (7) days of the notification. If the Customer does not object within that period, the sub-processor is deemed accepted. The new sub-processor will not process the Customer's personal data before the fourteen (14) day notice period expires. If the Customer objects and Contracko cannot make a commercially reasonable alternative available within a reasonable time, the Customer's sole remedy is to terminate the affected part of the Service on reasonable prior written notice.

Flow-down and liability. Contracko imposes on each sub-processor, by written contract, data-protection obligations no less protective than those in this DPA (in particular Art. 32 measures), and remains fully liable to the Customer for each sub-processor's performance of its obligations.

## 7. Data subject rights (Art. 28(3)(e))

Taking into account the nature of the processing, Contracko shall assist the Customer by appropriate technical and organisational measures, insofar as possible, in fulfilling the Customer's obligation to respond to requests to exercise data-subject rights (access, rectification, erasure, restriction, portability, objection), including through the Service's self-service export and deletion functions. If a data subject contacts Contracko directly, Contracko will refer them to the Customer.

## 8. Personal data breach (Art. 33)

Contracko shall notify the Customer without undue delay after becoming aware of a personal data breach affecting the Customer's personal data, and provide the information reasonably available to assist the Customer's own notification obligations, including, where available, the nature of the breach, the categories and approximate number of data subjects and records affected, the likely consequences, and the measures taken or proposed. Where the information cannot be provided at once, it may be given in phases without undue further delay. As processor, Contracko does not notify the supervisory authority or data subjects; that obligation rests with the Customer as controller.

## 9. Security, DPIAs, and prior consultation (Art. 32, 35–36)

Contracko implements and maintains the measures in Annex 2, taking into account the state of the art, the costs of implementation, and the nature, scope, context and risk of the processing. Contracko does not warrant that these measures are effective under all circumstances; consistent with Article 82(2) GDPR, Contracko is liable only where damage results from Contracko's failure to comply with obligations specifically directed to processors under Applicable Data Protection Law, or with the Customer's lawful instructions. Contracko assists the Customer, taking into account the nature of processing and the information available to it, with data protection impact assessments and prior consultation with the supervisory authority where required. Contracko may charge a reasonable fee for assistance under Sections 7 to 9 that materially exceeds the ordinary functionality of the Service, except where the assistance is required due to Contracko's breach of this DPA.

## 10. Audits (Art. 28(3)(h))

Contracko shall make available to the Customer the information necessary to demonstrate compliance with this DPA. Contracko may satisfy audit requests by providing its available third-party audit reports, certifications or self-assessments (such as ISO 27001, SOC 2, or CSA STAR, to the extent Contracko holds them), and its TOMs, which the Customer accepts as satisfying the audit right where they reasonably address the request. Where those are not reasonably sufficient, the Customer (or a mandated auditor bound by confidentiality, and not a Contracko competitor) may conduct an inspection no more than once per year, on at least 30 days' prior written notice, during business hours, without unreasonable disruption, and at the Customer's cost.

## 11. Return and deletion (Art. 28(3)(g))

On termination of the Service, Contracko shall, at the Customer's choice, delete or return all personal data and delete existing copies, unless retention is required by law. Contracko completes deletion without undue delay and in any event within 90 days of termination or of a verified deletion request; residual copies in backups are purged on the normal backup cycle.

## 12. International transfers (GDPR Chapter V)

Contracko's hosting and primary storage are in the EU. The Customer-to-Contracko relationship is intra-EEA and does not itself involve a restricted transfer. Where providing the Service involves a Restricted Transfer to a sub-processor outside the EEA, that transfer is made under an appropriate transfer mechanism, applied in the following order: (a) an adequacy decision or, where the recipient is certified, the EU-US Data Privacy Framework; otherwise (b) the EU Standard Contractual Clauses (Commission Implementing Decision (EU) 2021/914), Module Three for onward Processor-to-Sub-processor transfers (and Module Two where the Customer is the data exporter), together with the UK International Data Transfer Addendum and Swiss adaptations where relevant, and any supplementary measures required following a transfer impact assessment. Each sub-processor's location is recorded in the sub-processor list (Annex 1). The SCCs are incorporated by reference and, where they apply, prevail over this DPA (Annex 3 records the elected modules and completed appendices).

## 13. Liability and governing law

Each party's liability under this DPA is subject to the limitations and exclusions of liability in the Agreement (Common Paper CSA Standard Terms v2.1), which apply to this DPA. The Customer will indemnify Contracko against third-party claims and losses to the extent they arise from the Customer's unlawful processing instructions, unlawful Customer content, or the Customer's breach of this DPA or Applicable Data Protection Law. This DPA is governed by the laws of the Netherlands, and the courts of The Hague or Amsterdam have jurisdiction, consistent with the Agreement, without prejudice to mandatory data-subject protections and to any governing-law/forum required by the SCCs.

## 14. Language

This DPA may be provided in translation for convenience. In case of any conflict or inconsistency between the English version and a translation, the English version prevails, except where the Standard Contractual Clauses require otherwise.

## Annexes

- Annex 1 - Processing particulars and sub-processor list: the processing particulars in Sections 3 and 4, together with the sub-processor list set out below.
- Annex 2 - Technical and Organisational Measures (TOMs): Contracko's current technical and organisational security measures, made available to the Customer on request.
- Annex 3 - Standard Contractual Clauses: where a Restricted Transfer relies on the SCCs, the EU Standard Contractual Clauses (Commission Implementing Decision (EU) 2021/914) apply, with Modules Two and Three elected as applicable, the competent supervisory authority being the Autoriteit Persoonsgegevens where Contracko is the data exporter (Module Three) and the Customer's competent supervisory authority where the Customer is the data exporter (Module Two), and the Annex 2 measures serving as the technical and organisational measures appendix.
- Annex 4 - Security and processing disclosure: a structured disclosure of Contracko's security standard, certifications, sub-processors, and retention and deletion practices, made available to the Customer on request.

### Annex 1 - Sub-processor list

The sub-processors Contracko engages to process personal data in providing the Service. Changes are notified in accordance with Section 6.

| Sub-processor | Purpose | Location |
| --- | --- | --- |
| Hetzner Cloud | Application hosting and job queue | Germany (EU) |
| PlanetScale | Managed application database | EU |
| Cloudflare | Document storage, DNS, CDN and security | EU |
| Google (Gemini API) | AI contract analysis and extraction | United States |
| Mistral AI | AI analysis (zero data retention) | France (EU) |
| OpenAI | Fallback AI analysis (zero data retention) | United States |
| xAI (Grok) | AI analysis (zero data retention) | United States |
| LlamaIndex (LlamaParse) | Document parsing and text extraction | EU |
| DocuSeal | Electronic signature requests and execution | EU |
| Mailgun | Inbound email import | EU |
| Bento | Transactional and lifecycle email, and support chat | Australia |
| Stripe | Payments and billing | EU and United States |
| PostHog | Product and website analytics | EU |

## Attribution

This Data Processing Agreement is adapted, with modifications, by Velocity Ventures B.V. from the [Common Paper Data Processing Agreement](https://commonpaper.com/standards/), © Common Paper, licensed under [CC BY 4.0](https://creativecommons.org/licenses/by/4.0/).
