d.digitizerGo to dashboard →
Legal & privacy

Data processing agreement

The terms that apply when Digitizer processes personal data in your documents on your behalf.

Effective 22 September 2026Codester OÜ

On this page

1. Parties and scope2. Processing details3. Instructions and confidentiality4. Technical and organisational measures5. Subprocessors and location6. Assistance, incidents, and audit7. Return and deletion
Pricing guide →

1. Parties and scope

This Data Processing Agreement (DPA) forms part of the Digitizer Terms of Service between the customer identified in the workspace and Codester OÜ, registry code 16353798, at Paekivi tn 8, Vasalemma alevik, Lääne-Harju vald, 76101 Harju maakond, Estonia. The customer is the controller and Codester OÜ is the processor for customer content. If the customer itself acts as processor, it warrants that its controller has authorised this engagement; Codester OÜ acts as subprocessor for that content.

This DPA governs customer-content processing under Article 28 GDPR. It takes precedence over conflicting general terms on that subject. Codester OÜ's separate controller activities for accounts, billing, and security are described in the Privacy Policy.

2. Processing details

ItemDescription
Subject and purposeReceiving, recognising, extracting, organising, reviewing, and delivering business-document data as instructed by the customer.
DurationWhile the service is used and for the agreed return/deletion period after it ends; legally required retention is separately restricted.
OperationsCollection, transmission, OCR/extraction, structuring, duplicate comparison, storage, retrieval, export, correction, and deletion.
IndividualsCustomer staff, customers, suppliers, contractors, senders, recipients, and other people appearing in submitted business records.
Data categoriesNames, contacts, addresses, identifiers, invoice and receipt details, bank/payment information, business communications, file metadata, and customer-selected document content.
Sensitive dataIntentional special-category or criminal-offence processing requires a separate agreement and suitable safeguards.

3. Instructions and confidentiality

We process customer personal data only on documented instructions, including the customer's use of authorised dashboard, API, email, and callback settings. The customer is responsible for lawful instructions, required notices, and authorising its users. Additional instructions may be submitted to [email protected].

We inform the customer if an instruction appears to infringe applicable data-protection law. If law requires processing outside the instructions, we inform the customer before doing so unless that law prohibits notice. We do not use customer content for our own advertising or general-purpose model training.

Personnel with access must be authorised, bound by confidentiality, and limited to access needed for their responsibilities. These duties survive the end of their access or employment.

4. Technical and organisational measures

We provide relevant details of the measures on request. We may update technical measures while maintaining protection appropriate to the risk; we will not materially reduce agreed protection without addressing the effect with the customer.

  • Restrict access by authenticated identity, workspace, business, and role; protect secrets and revoke credentials when access ends.
  • Use encrypted transport for production transfers and appropriate protection for stored customer data and backups; keep document-processing and storage infrastructure in EU data centres.
  • Maintain controlled administrative access, security logging, patching, incident handling, recovery procedures, and regular assessment of safeguards.
  • Keep customer workloads and data access logically separated; verify authority for export and erasure requests.
  • Maintain documented deletion and recovery procedures, including removal of deleted content from backups within 30 days and reapplication of deletions after restore.

5. Subprocessors and location

Before personal-data processing starts, we provide the customer with the applicable subprocessor list, including legal identities, services, and processing locations. The customer gives general authorisation only for subprocessors on that disclosed list. We give at least 30 days' notice of intended additions or replacements so the customer can raise a reasonable data-protection objection before the change takes effect.

We work to resolve an objection, including an alternative arrangement where feasible. If no reasonable resolution is available, the customer may end the affected service before the new subprocessor processes its data. We impose equivalent data-protection obligations by written contract and remain responsible for subprocessor performance under this DPA.

Production customer-document storage, extraction, and backups remain in the EU. Remote access from outside the EEA or a transfer arranged by us outside the EEA requires an appropriate legal mechanism and the customer's documented instruction. Customer-configured outbound destinations are the customer's instructions; the customer remains responsible for its recipient arrangements.

6. Assistance, incidents, and audit

Taking account of the processing and information available to us, we assist the customer with data-subject requests, security duties, breach assessment and notification, impact assessments, and consultation with supervisory authorities. We forward requests concerning customer content to the customer unless prohibited by law, and do not independently decide the customer's response.

We notify the customer without undue delay after becoming aware of a personal-data breach affecting its content. We provide available information about the incident, affected data and individuals, likely consequences, mitigation, and a contact for follow-up, supplementing it as the investigation progresses. We cooperate with the customer's response and preserve relevant evidence without unnecessary disclosure.

We make information necessary to demonstrate compliance available to the customer and allow and contribute to reasonable audits, including inspections, by it or an auditor it appoints. Parties coordinate timing and confidentiality to protect other customers and service security; these arrangements do not remove statutory audit rights. We notify the customer of an instruction that in our opinion infringes data-protection law.

7. Return and deletion

At the customer's choice, we return or delete customer personal data when processing services end, and delete remaining copies unless Union or Member State law requires retention. The customer can export records using the service and contact [email protected] to arrange a complete return or workspace erasure. We agree the export method and verify the requester's authority.

Customer documents are otherwise retained until deletion or workspace closure. Source email and downstream recipient copies are separate from the processed document record; a complete erasure request must cover source records and any retained delivery copies. We complete active-data deletion without undue delay, and remove deleted content from backups within 30 days. Retained legal records are restricted to the legally required purpose. On request we confirm completion and any lawful exception.

Questions?

Contact Codester OÜ at [email protected].

Codester OÜ · Registry code 16353798
Terms of servicePrivacy policyData processing agreementCookies