Data Processing Agreement
Applicable from July 25th, 2020
Version: 2.0
Date: July 25th, 2020
Table of contents:
1. Introduction
2. Grounds
3. Parties
4. Validity of this agreement
5. Data
6. Sub-processors
7. Hosting & storage
8. Security
9. Audits
10. Data breaches
11. Responsibilities and accountabilities
12. Contact details
1. Introduction
By uploading information to Doxis, you are very likely to be processing sensitive personal data from your customers, partners, suppliers and/or employees. Based on GDPR legislation, you are responsible for this personal data and are using Doxis as a partner for digitization. In this agreement, you and Doxis agree on the terms of this collaboration. With this agreement, you give Doxis the explicit consent to process the data on your behalf and accept all responsibility and potential risks associated with working with Doxis. The Dutch version of GDPR legislation will be used as the base for this agreement. Any articles referred to are articles in the ‘AVG’.
2. Grounds
Within this agreement, you, as a user or customer of Doxis, are pointed out as the responsible party for all personal data. Doxis is the processing partner helping you handle this data by using digital applications.
3. Parties
In this agreement, we are referring to the parties. With parties, we mean Doxis AI Solutions B.V. and you as a user or licensee of Doxis. Doxis AI Solutions B.V. can be named Doxis, we or us and you will be named user, licensee, customer or you.
4. Validity of this agreement
From the moment this agreement is accepted until the account has been deleted, this agreement is valid. Starting this agreement is done by registering a new account or by accepting this agreement in your account settings. It is not possible to terminate this agreement without deleting your complete Doxis account.
5. Data
As a user or customer of Doxis, you are responsible for the data that you process using Doxis. This data is processed by you using Doxis with goals in the areas of expense management, invoice processing and processing of credit card transactions.
6. Sub-processors
In some cases, Doxis will use sub-processors to perform tasks that enable Doxis to provide you with the best services. We try our very best to select sub-processors that we deem reliable partners and have selected the following to provide our services:
– Microsoft Azure: Doxis makes use of Microsoft servers for the processing power in our web services and safe, high-volume data storage. The cloud follows worldwide security standards SOC 1,2,3, ISO:27001,27017, 27018 and is PCI-DSS compliant. We chose Amsterdam as our processing location to minimize latency for our users and make sure that the data center security is in compliance with Dutch laws and regulations.
– Google Cloud Services: Doxis uses Google G Suite for internet services, such as e-mail, creation and storage of internal spreadsheets, presentations and text files, and Google Vision as an integral part of our Optical Character Recognition framework. Google Vision is part of the Google Cloud and is ISO:27001, 27017, 27018-certified and SOC 1, 2, 3 compliant.
– MongoDB Inc.: To make sure not to lose valuable information, MongoDB helps us to make continuous backups. MongoDB Inc. is ISO:27001-certified and SOC 2 compliant.
– Sendgrid Inc.: Sending of emails for account activation, password updates and activity reminding is performed by Sendgrid. SendGrid is ISO 27001-certified and SOC 2 compliant.
– Steldia Services Limited: Doxis can make use of Steldia’s manual data processing services in case you have selected the ‘reliable OCR mode’ in our software. Steldia is ISO:9001 certified.
– Contractbook ApS.: To create, communicate about, sign and store our legal contracts, we use Contractbook. Information that relates to the agreement(s) may be stored in Contractbook.
– Informer Online Nederland B.V.: All invoice-related information is stored in our accounting software, Informer. Informer stores company information to perform (recurring) invoicing.
– Pipedrive OÜ: To best serve our clients, we try to log all human-to-human communication that we have with our clients. Pipedrive helps us to save these notes, together with all client-related factual information, such as phone numbers and email addresses.
– Crisp: We use Crisp as a communication tool to provide a personal chat function on our website. Crisp is also used to handle support tickets and provide a knowledge base.
Doxis has appropriate data processing agreements in place with these sub-processors. These agreements are reviewed at least annually by management. By engaging in services with Doxis, you agree on the fact that Doxis uses sub-processors.
7. Hosting & storage
Doxis processes the data within the EU. We are using servers from Microsoft Azure in the Netherlands.
8. Security
Preserving the confidentiality and integrity of your information is one of Doxis’ highest priorities. We have technical and organizational measures in place to ensure a level of security appropriate to the risk, including in the Doxis Security Policy. A summary of the measures is included below:
– Data Center Security: Doxis makes use of off-site data centers, provided by Microsoft, further detailed in article 5.
– Secure Connections: We make use of SSL. All traffic to and from the API is HTTPS-secured. Any attempt to connect over HTTP is redirected to HTTPS.Firewall: Our servers are protected by a firewall at the provider network layer. Bad traffic will not reach the servers.
– Separation Application and Data: The architecture of Doxis is built around a REST API. Doxis’ application servers are physically and logically separated from servers that store customer data. Hardened Operating System: Doxis runs on hardened Linux servers. Externally exposed critical patches are addressed within 24 hours.
– OWASP 2017 Top 10: We have validated our security measures against the top ten vulnerabilities on web applications by the Open Web Application Security Project. By means of this procedure, we confirmed the robustness of our framework.
– Security Audits: Comsec performs independent audits on our security measures. The National Cyber Security Centre (NCSC) of the Dutch government recommends a regular black-box scan. We followed up on this recommendation and requested multiple third parties to perform grey-box scans.
9. Audits
When you have agreed to this agreement, you have the right to perform an audit to check if Doxis is in compliance with this agreement. If you want to have an audit performed, you have to let Doxis know at least 30 days beforehand. Any audit will always be performed at a day and time that is favorable to Doxis. Audits can only take place by an independent auditor who is a member of NOREA. Both you and your auditor are bound by a full non-disclosure agreement on the process and outcome of the audit. Any cost, directly or indirectly, associated with an audit is to be paid by you.
10. Data breaches
Even though we and our sub-processors adhere to the high-quality standards, there is never a 100% safety guarantee on digital systems. In the case that Doxis encounters a data breach in its systems, which impacts your data security, Doxis will inform you, when practically possible, within 5 working days. In this communication, we will inform you about the cause of the leak, what the potential risks are and how we are going to solve this. After we have informed you, it is up to you to determine whether or not you have to inform your customers, partners and suppliers. It is also up to you to inform the appropriate authorities if you think this is necessary.
11. Responsibilities and accountabilities
As a processor of personal data, you are responsible and accountable for the data you are processing using Doxis software. As a processor, you have the obligation to check whether you have the right to process certain personal data. You also have to make sure you have solid protection for the data. Doxis is not responsible for any claims based on the data you process as a result of using Doxis. In case Doxis gets into any legal problems relating to illegal data you processed using Doxis, you are obligated to compensate Doxis fully for any damages and legal fees.
12. Contact details
If you have any questions, complaints or comments after reading this Data Processing Agreement, please do not hesitate to contact us by email at [email protected].
Doxis AI Solutions B.V. in Groningen, the Netherlands.