Legal

Data Processing Addendum

Last updated: July 29, 2026

This is the addendum zendoc signs. It is published rather than sent on request so your privacy counsel can read it before you book a call, and it is written to be read in five minutes.

1. Parties and role

  • This Data Processing Addendum forms part of the Terms of Service between Mavdotso LLC, which operates zendoc ("zendoc"), and the firm that subscribes to the Service ("Customer"). It applies whenever zendoc processes personal data on the Customer's behalf.
  • The Customer is the controller of that data and zendoc is the processor. Where the Customer is itself a processor acting for its own clients, zendoc is a subprocessor and the same obligations apply.
  • The Customer decides what it asks its clients for. zendoc does not choose the checklist, and so does not choose the categories of data it ends up processing.

2. Subject matter, duration, nature and purpose

  • zendoc processes personal data for one purpose: providing the Service — client onboarding, document collection, e-signature, and messaging between a firm and its clients.
  • Processing runs for the term of the subscription, plus the deletion window in section 7.

3. Categories of data subjects and personal data

  • Data subjects: the Customer's clients and their signatories, and the Customer's own staff.
  • Personal data: identity and contact details (name, email address, phone number); the documents a firm's clients upload, which routinely include identity documents and financial records and may include whatever else the Customer's checklist asks for; e-signature evidence (timestamp, browser and device, and per-field view, fill and sign events); and the content of messages sent through the Service.

4. zendoc's obligations as processor

  • Process personal data only on the Customer's documented instructions — the Terms of Service, this addendum, and the Customer's own use of the Service. If a law compels processing beyond them, zendoc tells the Customer first unless that law forbids it.
  • Keep every person with access bound by confidentiality.
  • Implement and maintain the technical and organisational measures described at zendoc.ai/security. That page is part of this addendum, including what it says zendoc does not claim: zendoc is not SOC 2 certified, and nothing here says otherwise.
  • Engage no subprocessor other than those listed at zendoc.ai/subprocessors, post a change on that page before a new one starts processing customer data, and contract with each on terms that carry these obligations down. zendoc stays responsible for its subprocessors' performance.

5. Assistance

  • Data-subject requests: the Service is built so the Customer can answer most of them itself — Settings → General → Export workspace data returns the workspace's records, and deleting a client or a file starts the erasure in section 7. Where a request needs zendoc, we help in time for the Customer to meet its own statutory deadline.
  • Security incidents: zendoc notifies the Customer without undue delay after becoming aware of a personal-data breach affecting its data, with what is known at the time and what is being done about it, and follows up as more is known.
  • Impact assessments: zendoc provides the information it holds to support a DPIA or a prior consultation, on request.

6. International transfers

  • zendoc is a United States company and processes personal data in the United States and wherever the subprocessors listed at zendoc.ai/subprocessors operate. zendoc does not offer a region-pinned deployment or a data-residency guarantee, and this addendum does not pretend otherwise.
  • Where a Customer's transfer of personal data out of the EEA, the UK or Switzerland relies on the EU Standard Contractual Clauses, zendoc will execute them as part of this addendum on request. zendoc claims no adequacy decision and no certification scheme.

7. Deletion and return

  • The Customer can export its data at any time during the subscription — Settings → General → Export workspace data — and should do so before ending it.
  • When the Customer deletes a workspace, a client record or a file, zendoc erases it, including the copy in file storage, 30 days later. Deletion is not reversible from within the Service.
  • Two things deliberately survive that erasure: documents that were electronically signed, and the audit trail recording who signed them and when. They are evidence other parties rely on, and zendoc retains them on that legal basis. Everything else goes.

8. Audit

  • zendoc answers security questionnaires and provides the information reasonably necessary to demonstrate compliance with this addendum, including the measures at zendoc.ai/security and the current subprocessor list.
  • An on-site or third-party audit is by arrangement, once a year, at the Customer's cost — sooner and at zendoc's cost if a regulator requires it or a breach affecting the Customer's data has occurred.

9. How to execute

  • Email security@zendoc.ai with your firm's legal entity name and an address for notices. We countersign and send a copy back.
  • No negotiation is needed to start a pilot: this text is the standing offer, and zendoc is bound by it from the date it countersigns.

Read these alongside it

zendoc.ai/security for the measures section 4 commits to, zendoc.ai/subprocessors for the list section 4 limits us to, and the privacy policy for what zendoc does with data of its own.