Data processing agreement (DPA)

Version 1.1 · in force on 1er octobre 2026

Translation for information only. In case of discrepancy between language versions, the French version prevails.

1. Parties and purpose

This agreement (art. 28 GDPR) is entered into between the client company that created a WeDoc space (the « Controller ») and BKH Tech BV (Belgique, VAT BE 0792.957.182) (the « Processor »). It is accepted by the space administrator on behalf of their company at sign-up and supplements the Terms. It governs WeDoc's processing of the personal data the Controller records in its space (« Client Data »).

2. Nature of the processing

  • Purpose: hosting and provision of the WeDoc platform.
  • Duration: the term of the subscription, plus 30 days for return of data.
  • Nature: storage, display, backup, sending of transactional emails.
  • Data concerned: whatever the Controller chooses to record — typically identities and contact details of its clients and contacts, document content, tasks and files.
  • AI assistant (optional): if the Controller enables it, the questions asked by its users and the Client Data excerpts needed to answer them are sent to a self-hosted search-and-generation module run by the Processor — no transfer to a third-party service. Exchanges are kept for 90 days then deleted.
  • Data subjects: clients, prospects, staff and contacts of the Controller.

3. Obligations of the Processor

  • Process Client Data only on documented instructions from the Controller (use of the service constitutes instruction);
  • Ensure confidentiality — authorised personnel are bound by a confidentiality obligation;
  • Implement the technical and organisational measures of art. 32 (TLS encryption, separation per space, access control by roles and licences, backups, logging);
  • Assist the Controller with data subject requests and reasonably requested impact assessments;
  • Notify the Controller of any Client Data breach as soon as possible, and no later than 48 hours after becoming aware of it;
  • At the end of the contract: return the Client Data (export) then delete it within 30 days, save for legal retention obligations.

4. Sub-processors

The Controller gives general authorisation for the following sub-processors, bound by equivalent obligations:

  • OVH (EU) — hosting, emails.
  • Stripe — payments (billing data only).
  • Google / Microsoft — OAuth authentication, if enabled by users.

Any change to this list will be notified (email to administrators) at least 30 days in advance; absent a reasoned objection, the change is deemed accepted.

5. Location and transfers

Client Data is hosted in the European Union. Any transfer outside the EU relies on the safeguards of chapter V of the GDPR (standard contractual clauses of the providers concerned).

6. Audit

Upon reasonable written request (at most once a year), WeDoc makes available the information necessary to demonstrate compliance with this agreement.

7. Contact

Any question about this DPA: privacy@wedoc.io.