DullDocs Customer Data Processing Agreement =========================================== This agreement contains the mandatory processor terms for personal data that DullDocs handles on a customer's behalf. Owner: RJS & Partners LLP, trading as DullDocs Version: 2026-09-24 Effective date: 24 September 2026 Audience: Customer controllers, DullDocs and customer privacy advisers Permanent link: https://app.dulldocs.com/legal/dpa/versions/2026-09-24 SHA-256 of the published source: a1e77f4e6d2b35a77520c14f42f043969fe2f67a8086337d14293649a0a3dba6 1 Scope and precedence ---------------------- This Data Processing Agreement forms part of the DullDocs Terms of Service or applicable order form between the Customer as controller and RJS & Partners LLP trading as DullDocs as processor. It applies whenever DullDocs processes Customer Personal Data on the Customer's behalf. If this DPA conflicts with the main agreement on personal-data processing, this DPA prevails. 2 Definitions ------------- Applicable Data Protection Law means the UK GDPR, Data Protection Act 2018, Privacy and Electronic Communications Regulations 2003 where applicable, and binding replacement or amending legislation. Customer Personal Data means personal data processed by DullDocs on behalf of the Customer. Data Subject, controller, processor, personal data breach, processing and subprocessor have the meanings in Applicable Data Protection Law. Restricted Transfer means a transfer governed by the UK GDPR international-transfer rules. 3 Processing details -------------------- Subject matter: Delivery, security, support and termination of the DullDocs evidence-management service Duration: Subscription term plus the export, deletion and backup-expiry periods Nature: Collection, upload, receipt, access, storage, organisation, extraction, classification, comparison, display, communication, reporting, restriction, export and deletion Purposes: Evidence management, expiry and completeness checks, staff and setting records, reminders, customer-requested reports, secure sharing, support, security and lawful service operation Data subjects: Customer users; nursery staff, applicants, volunteers and contractors; referees; acknowledgment and declaration recipients; and people incidentally named in uploaded evidence, potentially including children and parents Personal data: Identity and contact details; employment and role information; training, qualification, right-to-work and reference evidence; dates and document metadata; photographs; usage and audit information; email content; free text; original documents and extracted text Sensitive data: Information that may reveal health, disability, ethnicity, religion, trade-union membership or safeguarding matters; DBS, vetting and other criminal-offence-related data; incidental child information Frequency: Continuous while the Customer uses the relevant features 4 Documented instructions ------------------------- DullDocs will process Customer Personal Data only on documented instructions from the Customer, including the instructions in the agreement, configured features, authorised user actions and support requests. Those instructions include using the subprocessors and Restricted Transfers identified in the current Subprocessor and Transfers Notice, but only where DullDocs has put the required contractual and transfer safeguards in place. If DullDocs believes an instruction breaches Applicable Data Protection Law, it will inform the Customer unless prohibited and may pause the affected processing. If law requires processing outside the Customer's instructions, DullDocs will tell the Customer before processing unless the law prohibits notice. DullDocs will not sell Customer Personal Data, use document content for advertising, or use Customer Personal Data to train its own general-purpose model. 5 Confidentiality ----------------- DullDocs will ensure that personnel authorised to process Customer Personal Data are subject to confidentiality obligations, receive appropriate privacy and security instruction, and access data only where necessary for their role. 6 Security ---------- DullDocs will implement and maintain appropriate technical and organisational measures taking account of the state of the art, implementation costs, the nature and purpose of processing, and risk to individuals. The current measures are set out in the Technical and Organisational Measures document. DullDocs may improve or replace measures provided the overall protection is not materially reduced. 7 Subprocessors --------------- The Customer gives general written authorisation for the subprocessors listed in the current Subprocessor and Transfers Notice. DullDocs will: - conduct proportionate due diligence; - impose written data-protection terms providing protection equivalent in substance to this DPA; - remain responsible to the Customer for the subprocessor's performance of those obligations; - provide at least 14 days' advance notice of a new subprocessor that will process Customer Personal Data, except where urgent replacement is necessary for security or service continuity; and - provide a reasonable opportunity to object on genuine data-protection grounds. If the parties cannot resolve an objection, DullDocs may offer a reasonable alternative. If none is reasonably available, the Customer may stop using the affected feature or terminate it without penalty. 8 International transfers ------------------------- DullDocs will not make a Restricted Transfer unless it has a lawful transfer route. This may include UK adequacy regulations, the UK Extension to an approved data-privacy framework where the recipient and data are covered, the ICO International Data Transfer Agreement, or the UK Addendum to approved standard contractual clauses, together with the required data protection test and supplementary measures. DullDocs will record the applicable recipient, country, mechanism and assessment in its International Transfer Register and make relevant safeguard information available to the Customer on request, subject to confidentiality restrictions. 9 Assistance with individual rights ----------------------------------- Taking account of the nature of processing, DullDocs will provide reasonable technical and organisational assistance so the Customer can respond to requests for access, rectification, erasure, restriction, objection and portability. If DullDocs receives a request relating to Customer Personal Data directly, it will forward it promptly and will not respond substantively unless authorised or legally required. 10 Security and personal data breaches -------------------------------------- DullDocs will notify the Customer without undue delay after becoming aware of a personal data breach affecting Customer Personal Data. Where reasonably possible, initial notice will be provided within 24 hours of confirmation and will include known information about the nature of the breach, affected people and data, likely consequences, containment and contact point. Information may be provided in phases. DullDocs will take reasonable steps to contain, investigate and remediate the breach and will assist the Customer with its assessment and notifications. DullDocs will not notify an authority or affected person on the Customer's behalf unless authorised or legally required. 11 DPIAs consultations and compliance assistance ------------------------------------------------ Taking account of the nature of processing and information available, DullDocs will assist the Customer with security obligations, breach notification, DPIAs and prior consultation. DullDocs will provide its service-level DPIA, security measures and data-flow information where appropriate. The Customer remains responsible for its own lawful bases, conditions and DPIA decisions as controller. 12 Demonstrating compliance and audits -------------------------------------- DullDocs will make information reasonably necessary to demonstrate compliance with Article 28 available to the Customer. Evidence may include policies, test reports, architecture information, provider evidence and independent assessments. No more than once annually, or following a material incident, the Customer may request a reasonable audit. Audits must protect other customers, security information and confidentiality, avoid unnecessary disruption and use existing evidence first. On-site access is available only where documentary evidence is insufficient and subject to reasonable notice and safeguards. 13 Return and deletion ---------------------- At the Customer's choice and subject to product capability, DullDocs will return or make Customer Personal Data available for export. After termination, DullDocs will delete Customer Personal Data from live systems. DullDocs may retain data where UK law requires it, provided it isolates the data, processes it only for that legal purpose and deletes it when the obligation ends. Anonymous aggregate information that cannot identify a person or Customer is not Customer Personal Data. 14 Customer obligations ----------------------- The Customer is responsible for the lawfulness, accuracy and relevance of Customer Personal Data and its instructions. The Customer must: - provide privacy information to data subjects; - identify an Article 6 basis and, where applicable, Article 9 and Article 10 or Schedule 1 conditions; - maintain any required Appropriate Policy Document; - limit uploads to information necessary for nursery operations and evidence; - review AI-derived or inferred information before using it for significant decisions; and - notify DullDocs promptly if data should be corrected, restricted or deleted. 15 Liability and duration ------------------------- Each party is responsible for its obligations under Applicable Data Protection Law. Contractual liability is governed by the main agreement except where law requires otherwise. This DPA remains effective while DullDocs processes Customer Personal Data. Schedule 1 Security measures ---------------------------- The Technical and Organisational Measures document is incorporated into this DPA. DullDocs Technical and Organisational Measures This schedule describes the baseline controls used to protect Customer Personal Data and supports the customer Data Processing Agreement. 2 Identity and access - Role-based and organisation-scoped access. - Site restrictions combined with organisation scope. - Privileged support access restricted by allowlist, separate multi-factor authentication and audit events. - Short-lived authentication codes, hashed session tokens, rate limiting and production-secret validation. 3 Tenant isolation - Organisation scope applied at route and query layers. - Automated guards identify unscoped customer-data access. - Negative cross-tenant tests cover representative read, create, search, update, delete and export paths and fail closed when the test database is unavailable. - Signed-token features treat the scoped token as authorisation and are separately rate limited and audited. 4 Encryption and secrets - TLS for data in transit. - Private object storage for customer documents and extracted text. - Field-level AES-256-GCM encryption for selected DBS identity fields, multi-factor secrets and OAuth credentials. - One-way hashing for session, share and acknowledgement tokens and non-reversible storage references in logs. - Secrets stored in managed environment configuration and excluded from source control and reports. 5 Upload controls - File type and magic-byte validation, size limits and safe attachment delivery. - Durable jobs use leases, retry limits, backoff and recorded outcomes. 6 AI processing controls - Complete-document analysis applies only to a Customer that has accepted the DullDocs Terms of Service and Customer Data Processing Agreement dated 24 September 2026, and only once DullDocs switches it on for that Customer; where it applies, it preserves page provenance and identifies restrictions, absent dates and integrity issues. - Model output is treated as an untrusted claim; deterministic application code validates source grounding and produces the user-visible decision. - Prompt-injection tests, derived canaries and merge-integrity tests are maintained. 7 Logging and monitoring - Security and audit events record actor, action, organisation, time and appropriate network/device context. - Document content, provider response bodies, secrets and signed URLs are excluded from routine logs. - Alerts cover high-risk failures and unexpected AI tier fallback. 8 Resilience and recovery - Rollback procedures exist for feature flags. 9 Secure development - No production customer data is used in synthetic test corpora. - Security findings are tracked to closure or documented acceptance. 10 Data lifecycle - Customer export and organisation-level verified deletion. - Person-level search and export with organisation isolation and review before release. 11 Incident response - Processor notification to affected customers without undue delay. Schedule 2 Approved subprocessors --------------------------------- The current Subprocessor and Transfers Notice (https://app.dulldocs.com/legal/subprocessors) is incorporated into this DPA and is available through the DullDocs Trust Centre (https://app.dulldocs.com/trust).