This Data Processing Addendum forms part of the Sunset Docs Terms of service between the customer and Esteve Castells Calpe, Barcelona, Spain. It applies automatically whenever Sunset Docs processes Customer Personal Data on the customer's behalf. A separately signed DPA prevails where it expressly conflicts with this document.
1. Definitions
GDPR means Regulation (EU) 2016/679. Controller, processor, personal data, processing, data subject, and personal data breach have the meanings given in the GDPR. Customer Personal Data means personal data submitted to or generated within a customer workspace that Sunset Docs processes on the customer's behalf.
Data Protection Law means the GDPR and any other privacy or data-protection law applicable to processing under this DPA. The Service and Customer have the meanings given in the Terms.
2. Roles and scope
The customer is the controller or a processor acting for another controller. Sunset Docs is the processor or subprocessor. Each party will meet its own obligations under Data Protection Law.
Where the customer acts as a processor, it confirms that the relevant controller has authorised its instructions and Sunset Docs' engagement. Annex 1 describes the processing covered by this DPA.
3. Documented instructions
Sunset Docs processes Customer Personal Data only on documented instructions contained in the Terms, this DPA, the customer's service configuration, and authorised use of features. If EU or Member State law requires other processing, we will inform the customer before processing unless law prohibits notice.
We will inform the customer if we believe an instruction infringes Data Protection Law and may pause the affected processing while the parties resolve it.
4. Confidentiality
Every person authorised by Sunset Docs to process Customer Personal Data is bound by contractual or statutory confidentiality obligations and receives access only where needed for that person's role.
5. Security
Sunset Docs maintains technical and organisational measures appropriate to the processing risks, taking account of the state of the art, implementation costs, and the nature, scope, context, and purposes of processing. Current measures are described in Annex 2.
We may update the measures as the service changes, provided the update does not materially reduce the overall protection of Customer Personal Data.
6. Subprocessors
The customer gives general written authorisation for the subprocessors identified on the Subprocessors page. We will give at least 30 days' notice before adding or replacing a subprocessor that will process Customer Personal Data. The customer may object within that period on reasonable data-protection grounds.
We impose data-protection obligations on each subprocessor that provide materially equivalent protection for the relevant processing. We remain responsible to the customer for the subprocessor's performance as required by law. If no reasonable alternative is available after a valid objection, the customer may terminate the affected service and receive a pro-rata refund of prepaid fees for the unused period.
7. Data-subject requests
Taking into account the nature of processing, we will provide reasonable technical and organisational assistance with requests to exercise data-subject rights. If a data subject contacts us directly about Customer Personal Data, we will forward the request to the customer without undue delay and will not respond on the merits unless authorised or legally required.
8. Personal data breaches
We will notify the customer without undue delay after becoming aware of a personal data breach affecting Customer Personal Data. We will provide the information reasonably available about the nature of the breach, affected categories and approximate numbers, likely consequences, and measures taken or proposed.
Information may be supplied in phases. We will not delay an initial notice only because every detail is not yet known, and we will provide reasonable assistance with the customer's notification and communication obligations.
9. Other assistance
Taking into account the nature of processing and information available to us, we will provide reasonable assistance with security obligations, data-protection impact assessments, and prior consultations with supervisory authorities where they relate to the Service.
10. International transfers
A restricted transfer will occur only under a mechanism permitted by Chapter V GDPR. Depending on the recipient, this may include an adequacy decision, the EU-US Data Privacy Framework where the recipient is certified, or European Commission Standard Contractual Clauses with supplementary measures where required. Provider details are published on the Subprocessors page.
11. Information and audits
We will provide information reasonably necessary to demonstrate compliance with Article 28 GDPR, including responses to proportionate written security questions. The customer may audit compliance no more than once every 12 months, on at least 30 days' notice, during business hours, at its cost and under confidentiality, without disrupting the service or accessing another customer's data.
The frequency and notice limits do not apply after a suspected breach, credible evidence of material non-compliance, or a supervisory-authority request. Documentation review should be used before an on-site audit where it can reasonably satisfy the request.
12. Return and deletion
The configured deletion schedule is a continuing documented instruction and is not extended by subscription cancellation. The customer may delete data earlier. Before processing ends, the customer can retrieve originals for which the owner has enabled download or request a reasonable service-level export of active Customer Personal Data.
When processing ends, the customer may instruct us to return and delete active Customer Personal Data or delete it without return, unless EU or Member State law requires storage. If the customer gives no different instruction, existing deletion schedules continue. Encrypted database backup residuals expire within 30 days and remain protected until deletion.
Minimal non-content deletion and audit records may remain for 12 months for security and accountability. On written request, we will confirm completion of the applicable deletion process.
13. Liability
The liability terms in the Terms apply to this DPA. They do not limit data-subject rights, supervisory-authority powers, or liability that Data Protection Law does not permit the parties to exclude or limit.
14. Term and precedence
This DPA applies for as long as Sunset Docs processes Customer Personal Data. It prevails over the Terms for data-protection subject matter. Changes to the DPA follow the change process in the Terms, except that a change required by law may take effect sooner with notice.
Annex 1: Details of processing
Subject matter: provision and support of the Sunset Docs document-intake service. Duration: the contract term plus each configured deletion period, any agreed export period, and the protected backup cycle.
Nature and purposes: receiving, validating, malware scanning, encrypting, storing, previewing, displaying, notifying, printing where enabled, allowing owner-authorised original downloads, auditing, and deleting temporary documents.
Data subjects: document senders, customer users and personnel, clients, contractors, suppliers, and other people whose information appears in submitted documents. Personal data can include names, contact information, identification, business, professional and financial information, document contents, filenames, sender email, metadata, IP-derived security data, and access activity.
Special categories and high-risk data are not intended or authorised unless separately agreed in writing. The customer must not submit children's data, criminal-conviction data, full payment-card data, credentials, secrets, or data it is not legally entitled to process.
Annex 2: Technical and organisational measures
Measures include application-level AES-256-GCM encryption of document objects; separately wrapped per-document keys; TLS in transit; private infrastructure; a private encrypted R2 mirror; workspace access checks; optional TOTP two-step verification; Argon2id password hashing; secure sessions and CSRF protection; quarantine, content validation, and malware scanning.
Measures also include short-lived viewer authorisation; restrictive cache controls; non-public object paths; logging of material document actions; defined backup retention; scheduled and manual deletion; restricted production access; confidentiality obligations; provider review; and incident-response procedures.
Annex 3: Subprocessors
The current subprocessors, their purposes, data categories, processing regions, and transfer safeguards are published at sunsetdocs.com/subprocessors. Only providers identified there as subprocessors form part of this Annex for Customer Personal Data.
15. Contact
Questions, objections, deletion confirmations, and signed copies can be requested at [email protected].