Data Processing Agreement
This DPA sets out the processing terms for customer-controlled personal data handled by DocMind on behalf of an organization.
1. Definitions and roles
This Data Processing Agreement forms part of the DocMind Terms of Service. The customer is the controller of personal data submitted to DocMind. Wistfare, as operator of DocMind, acts as processor when it processes that personal data on the customer's documented instructions.
2. Scope of processing
Processing covers hosting, receiving, parsing, extracting, storing, transmitting, securing and deleting documents, templates, extraction outputs, logs and account metadata necessary to provide DocMind. Categories of data depend on customer uploads and may include commercial, financial, identification, contact and transactional records.
3. Processing instructions
Wistfare processes personal data only to provide DocMind, follow customer configuration, comply with the terms, respond to support requests, protect the platform and meet legal obligations. If Wistfare believes an instruction violates applicable law, it will notify the customer where legally permitted.
4. Confidentiality
Personnel and contractors with access to customer data are bound by confidentiality obligations and receive access only where needed for operation, security, support or compliance. Production access is restricted and auditable.
5. Security measures
- TLS-protected transport for web and API traffic.
- Logical tenant isolation across organizations.
- Role-based access controls and organization-scoped API keys.
- Audit trails for key administrative and API activities.
- Restricted production access and credential rotation practices.
- Backups, monitoring and incident response procedures appropriate to the service.
6. Sub-processors
Wistfare may engage sub-processors for hosting, databases, email, payments, monitoring and AI processing. Wistfare remains responsible for sub-processor performance and will use contractual safeguards that require appropriate confidentiality, security and data-protection commitments.
7. Data subject requests
When a data subject contacts Wistfare about customer-controlled data, Wistfare will direct the person to the customer where appropriate. Wistfare will reasonably assist customers with access, deletion, correction or export requests using the dashboard, API or support workflow.
8. Personal data breaches
Wistfare will investigate confirmed or reasonably suspected personal data breaches affecting customer data and notify impacted customers without undue delay, including available information about the nature of the event, affected data and mitigation steps.
9. International transfers
Where personal data is transferred internationally, Wistfare will use appropriate transfer mechanisms and operational safeguards. Customers are responsible for confirming that their use of DocMind is lawful for the data categories and jurisdictions involved.
10. Audits
Wistfare will provide reasonable information about security controls, sub-processors and status history. Formal audits must be requested in writing, scoped to the customer's data, scheduled to avoid operational disruption and subject to confidentiality.
11. Return and deletion
Customers may export extraction data through product features or API access. On termination or written request, Wistfare will delete customer data according to retention settings and legal obligations. Backup copies expire through normal backup rotation.
12. Annexes
Annex A: subject matter is document extraction and related account operations. Annex B: duration is the active subscription plus retention and backup periods. Annex C: data subjects may include customer personnel, customer end users, vendors, buyers, employees or individuals appearing in uploaded documents.
Annex D: technical and organizational measures are summarized in the security measures section above and may be updated as DocMind's infrastructure evolves.