Legal
Data Processing Agreement
This agreement governs how we process personal data on your behalf when you use the Service. It applies automatically to every customer — you do not have to request or sign anything separately, though we will sign a copy if your procurement process needs one. Write to privacy@dynamicdocumentapi.com.
1. Scope and precedence
This agreement forms part of the Terms of Service between you (the controller) and N.M.M. Noble Minds Media Ltd (the processor). It applies whenever we process personal data on your behalf in providing the Service. On data protection matters it takes precedence over the Terms of Service. Where you are yourself a processor for someone else, this agreement operates as a processor-to-processor arrangement and your own controller’s instructions flow through you to us.
2. Definitions
Controller, processor, personal data, processing, data subject, personal data breach and supervisory authority have the meaning given in the GDPR. Customer Personal Data means personal data contained in Customer Content and Output as defined in the Terms of Service. Data Protection Law means the GDPR, the UK GDPR, the Swiss FADP and any other data protection law that applies to the processing.
3. Roles and subject matter
You decide why and how Customer Personal Data is processed. We process it only to provide, secure and support the Service, as set out in Annex 1. We remain the controller for the account, billing, support and security data described in our Privacy Policy; that data is outside this agreement.
You are responsible for having a legal basis for the processing, for informing data subjects, and for the lawfulness of the content you send us — including whether you may capture a third-party web page.
4. Your instructions
We process Customer Personal Data only on your documented instructions. The Terms of Service, this agreement, the settings you choose in the workspace and each API request you send are your instructions. Additional instructions must be agreed in writing; if they require work beyond the Service as documented, we may charge for it.
We will tell you if, in our view, an instruction breaches Data Protection Law, and may suspend that instruction until it is resolved. We will not process Customer Personal Data for our own purposes, and we will not use it to train machine-learning models.
5. Confidentiality
Everyone we allow to process Customer Personal Data is bound by confidentiality obligations that survive the end of their engagement, and receives access only to the extent their work requires.
6. Security of processing
We implement the technical and organisational measures in Annex 2 and keep them under review. Measures may change as technology moves on, but the overall level of protection will not fall below what Annex 2 describes. You are responsible for the security of your own systems and for how you configure the workspace — in particular how long files and request logs are kept, who has access and how API keys are handled.
7. Sub-processors
You give us general authorisation to engage sub-processors. The current list, with purpose and location, is at dynamicdocumentapi.com/subprocessors.
Before a new sub-processor starts processing Customer Personal Data, we announce it there and notify subscribers at least 30 days in advance; how to subscribe is explained on that page. You may object on reasonable data protection grounds within that period. If we cannot resolve your objection, you may terminate the affected part of the Service and receive a pro-rata refund of prepaid fees for the unused period.
We impose on every sub-processor data protection obligations no less protective than those in this agreement, and we remain fully liable to you for their performance.
8. Data subject requests
Through the dashboard and the API you can view, download, change and delete templates and generated files yourself, which will answer most requests. Where it does not, we assist you with appropriate technical and organisational measures, as far as is reasonably possible, and at your cost where the effort goes beyond the Service as documented.
If a data subject contacts us directly about Customer Personal Data, we will not respond on the substance. We will forward the request to you without undue delay, and tell the data subject that we did.
9. Assistance with your obligations
Taking into account the nature of the processing and the information available to us, we assist you with your obligations under Articles 32 to 36 GDPR: security of processing, breach notification, data protection impact assessments and prior consultation.
10. Personal data breaches
If we become aware of a personal data breach affecting Customer Personal Data, we notify you without undue delay and in any event within 48 hours of becoming aware. The notification describes what happened, which categories and approximate numbers of data subjects and records are affected, the likely consequences, the measures taken and a contact point. Where we cannot provide all of it at once, we provide it in phases without undue further delay.
We will not notify supervisory authorities or data subjects on your behalf unless you instruct us to, and we will not name you publicly without your agreement unless the law requires it.
11. Deletion and return
Customer Personal Data is deleted when its retention window under section 11 of the Terms of Service and your workspace settings ends, or earlier when you delete it. Ending a paid subscription does not delete it; the workspace continues on the free plan. When you delete a workspace or your account, its Customer Personal Data can be restored for 7 days and is then deleted; backups roll off within a further 35 days. Before deleting, you can download your files and templates through the dashboard or the API; that is how data is returned. Where the law requires us to keep data, we keep it only for that purpose and continue to protect it under this agreement.
We confirm deletion in writing on request.
12. Audits and evidence
We make available the information needed to demonstrate compliance with Article 28 GDPR. In practice, in this order:
- this agreement, Annex 2 and the security page;
- our answers to your written security questionnaire, once per year and free of charge;
- an on-site audit, where the above genuinely does not suffice: with 30 days’ notice, during business hours, no more than once a year unless a supervisory authority or a breach requires otherwise, by you or an independent auditor who is not our competitor and who signs a confidentiality undertaking, at your cost, and without access to other customers’ data.
13. International transfers
Customer Personal Data is stored and rendered in the European Union. If it is nevertheless transferred out of the EEA, the transfer is based on the Standard Contractual Clauses (Commission Implementing Decision (EU) 2021/914), which are incorporated into this agreement by reference:
- Module Two (controller to processor) where you are a controller, and Module Three (processor to processor) where you are a processor;
- Clause 7 (docking) applies; Clause 9 option 2 (general written authorisation) with the notice period in section 7; Clause 11 without the independent dispute resolution option; Clause 17 option 1 with the law of Cyprus; Clause 18(b) the courts of Cyprus;
- Annexes I, II and III of the Clauses are Annexes 1, 2 and 3 of this agreement;
- for the United Kingdom, the ICO International Data Transfer Addendum applies; for Switzerland, the Clauses are read with the amendments required by the FADP.
Before such a transfer we assess the law of the destination country and apply supplementary measures where needed, in particular encryption in transit, access control and the commitment in section 14. We make that assessment available to you on request.
14. Government access requests
If an authority requests access to Customer Personal Data, we notify you before disclosing anything, unless we are legally barred from doing so — in which case we use the legal remedies available to challenge the prohibition where there are grounds to do so, and disclose only the minimum legally required. We do not give any authority direct or unrestricted access to Customer Personal Data, and we do not hold decryption keys for any authority.
15. United States: service provider terms
Where the California Consumer Privacy Act or a comparable US state law applies, we act as a service provider or processor. We process personal information only to perform the Service, do not sell or share it, do not retain, use or disclose it outside the direct business relationship, and do not combine it with personal information from other sources except as permitted. We will notify you if we can no longer meet these obligations.
16. Liability, term and law
The liability provisions of the Terms of Service apply to this agreement, subject to any mandatory rule of Data Protection Law and to the Standard Contractual Clauses, which prevail in the event of conflict. This agreement lasts as long as we process Customer Personal Data. It is governed by the law stated in the Terms of Service, save that the Clauses are governed by the law named in section 13.
Annex 1 — Description of the processing
A. Parties
Data exporter: you, as identified in your workspace. Data importer: N.M.M. Noble Minds Media Ltd, registration number HE 453611, Grigori Afxentiou 7, 6023 Larnaca, Cyprus, contact privacy@dynamicdocumentapi.com.
B. Description
| Categories of data subjects | Whoever you put into your documents: your customers, employees, suppliers, members, recipients of invoices, certificates or messages. |
|---|---|
| Categories of personal data | Whatever your templates and payloads contain — typically names, addresses, contact details, customer and order numbers, amounts, dates, usage data, and images. Also the metadata of your API requests. |
| Special categories | Not permitted without a separate written agreement (Terms of Service, section 9). We do not knowingly process them. |
| Frequency | Continuous, for as long as you use the Service. |
| Nature and purpose | Receiving, rendering, storing and delivering documents and images; operating, securing and supporting the platform. |
| Retention | As set out in the Terms of Service, section 11, and your workspace settings. |
| Sub-processors | See Annex 3. |
C. Competent supervisory authority
For Module Two and Three transfers: the supervisory authority of the member state where you are established, or where you have designated an Article 27 representative. Ours is the Office of the Commissioner for Personal Data Protection of the Republic of Cyprus.
Annex 2 — Technical and organisational measures
The measures below apply to the production platform. We may replace a measure with one that protects at least as well (section 6).
| Physical security | Servers in the data centres of our hosting providers in the EU, as listed on the sub-processor page |
|---|---|
| Encryption | TLS 1.2 or higher between you and the Service, with HSTS; database volumes encrypted with AES-256; backups encrypted before they leave the server; generated files delivered through signed URLs that expire after 1 hour by default and at most 7 days |
| Staff access | Individual accounts, multi-factor authentication, access only as far as the task requires, administrative access logged |
| Customer accounts and API keys | Passwords hashed with Argon2 and checked against known breaches; multi-factor authentication and passkeys; API keys stored only as hashes, with scopes, template and IP allowlists, expiry and rotation |
| Tenant separation | Every query is scoped to its workspace in the data layer, backed by row-level security in the database and covered by automated tests |
| Rendering isolation | Renderers run without root rights on a read-only file system, with a seccomp profile and the browser’s own sandbox, and keep no browser profile between renders; outbound requests go only through an egress proxy that blocks private, loopback, link-local and other internal addresses; renderers hold no storage credentials |
| Logging | Security-relevant events and administrative actions are logged; workspaces on Growth and above see their own audit log |
| Backups and restore | Databases: continuous archiving with about one minute’s delay plus a nightly full backup, encrypted, kept for 35 days; restore tested at least quarterly |
| Secure development | Code review; dependency and secret scanning in continuous integration; development and staging separated from production; no production data used for development |
| Incident handling | Security incidents are assessed, contained and documented; the notification duty in section 10 applies |
| Deletion | Automatic deletion at the end of the retention window; deleted workspaces and accounts purged after 7 days; backups roll off within 35 days |
| Confidentiality | Everyone with access is bound to confidentiality; access is removed when someone leaves |
| Sub-processor management | Checked before engagement, bound by a data processing agreement, listed publicly |
Annex 3 — Sub-processors
The current list, including purpose, data categories and location, is published at dynamicdocumentapi.com/subprocessors and forms part of this agreement. Changes follow section 7.
Change history
| Version | Date | Change |
|---|---|---|
| 0.1 | 23 September 2026 | First draft, pending legal review |
| 1.0 | 4 October 2026 | In force. Section 7: 30 days’ notice of new sub-processors. Section 10: breach notice within 48 hours. Section 11: deletion and return as the platform handles them. Section 12: no third-party audit reports. Section 13: Customer Personal Data stays in the EU; courts of Cyprus. Annex 2: measures as implemented |