Data Processing Agreement (DPA)

Written by Анатолій
Updated 5 days ago

LLC "CENTREDO", Ukraine
Date: July 8, 2026


     
    The article is divided into different sections,
    so you can go straight to the one you need:
  1. Parties and Roles
  2. Definitions
  3. Subject Matter, Nature, Purpose and Duration of Processing
  4. Customer Obligations as Data Controller
  5. Obligations of LLC "CENTREDO" as Data Processor
  6. Subprocessors
  7. International Data Transfers
  8. Security of Processing
  9. Data Subject Requests
  10. Personal Data Security Incidents
  11. Assistance with DPIAs, Consultations and Compliance
  12. Audit and Demonstration of Compliance
  13. Data Return, Deletion and Retention
  14. Artificial Intelligence and Automated Processing
  15. Confidentiality
  16. Term and Termination
  17. Priority of Documents and Amendments
  18. Official contact details of LLC "CENTREDO"

This Data Processing Agreement ("DPA") forms part of the Agreement, Public Offer, Terms of Use, Order, or other document pursuant to which LLC "CENTREDO" provides the Customer with access to the WhiteDoc cloud platform (the "Main Agreement").

This DPA governs the processing of personal data that the Customer or its users upload, create, transmit, or otherwise process within the WhiteDoc Platform where LLC "CENTREDO" acts as a Data Processor on behalf of the Customer.

If any inconsistency arises between the provisions of this DPA and the Main Agreement with respect to the processing of User Data, the provisions of this DPA shall prevail unless otherwise expressly agreed by the Parties in writing.


1. Parties and Roles

🔍 Return to content

1.1. "Customer" means a legal entity or an individual using the WhiteDoc Platform pursuant to the Main Agreement and determining the purposes and means of processing User Data.

1.2. "Processor" means LLC "CENTREDO" (EDRPOU Code 43617469, Ukraine), which processes User Data on behalf of the Customer in accordance with the Customer's documented instructions, the Main Agreement, and this DPA.
1.3. With respect to User Data, the Customer acts as the Data Controller, and LLC "CENTREDO" acts as the Data Processor.

With respect to certain categories of data, including user registration data, billing information, technical security logs, support data, and marketing communications, LLC "CENTREDO" may act as an independent Data Controller in accordance with the WhiteDoc Privacy Policy.

1.4. The Parties agree that this DPA does not alter the status of independent controllers, including Qualified Trust Service Providers, the services of the State Enterprise "Diia", and other integrated providers that independently determine the purposes and means of their own processing of personal data.


2. Definitions

🔍 Return to content

2.1. The terms "personal data", "processing", "controller", "processor", "data subject", "personal data breach" and other data protection terms shall have the meanings assigned to them under applicable law, including the GDPR and the Law of Ukraine "On Personal Data Protection".

2.2. "User Data" means documents, attachments, structured data, metadata, comments, document fields, Envelope data, workflow participant information, and any other information that the Customer or Platform users upload, create, send, receive, or otherwise process using WhiteDoc.

2.3. "Documented Instructions" means the Customer's instructions regarding the processing of User Data as set out in the Main Agreement, this DPA, Platform settings, WhiteDoc technical documentation, including the Wiki, written orders, API requests, support requests, or any other forms of interaction agreed by the Parties.

Platform settings, user actions performed within the Platform, and API requests made on behalf of the Customer shall be deemed the Customer's documented instructions within the scope of the relevant functionality of the Platform.

2.4. "Subprocessor" means a third party engaged by LLC "CENTREDO" to process User Data on behalf of the Customer for the purposes of providing, supporting, securing, or developing the Platform.


3. Subject Matter, Nature, Purpose and Duration of Processing

🔍 Return to content

3.1. The subject matter of this DPA is the processing of User Data by LLC "CENTREDO" on behalf of the Customer in connection with providing access to the WhiteDoc Platform and related services.

3.2. The nature of the processing includes, without limitation, collection, recording, structuring, storage, display, transmission, routing, indexing, backup, activity logging, support for electronic signing, approval workflows, data exchange, deletion, and other operations necessary for the operation of the Platform.

3.3. The purpose of the processing is to provide electronic document management, data exchange, approval workflows, electronic signing, storage, routing, audit logging, integrations, and other Platform functions used by the Customer pursuant to the Main Agreement.

3.4. The duration of the processing shall correspond to the term of the Main Agreement and any additional period required to complete deletion, return of data, backup retention, compliance with legal obligations, or the defense of legal claims, unless otherwise provided by the Main Agreement or applicable law.

3.5. The processing details, including categories of data, categories of data subjects, processing operations, and retention periods, are set out in Table 1 to this DPA.

Table 1. User Data Processing Details

Parameter Description
Subject Matter of Processing Provision of access to the WhiteDoc Platform and related functionality for electronic document management, data exchange, approval workflows, electronic signing, routing, storage, and integrations.
Nature of Processing Collection, recording, structuring, storage, display, transmission, routing, indexing, backup, logging, deletion, anonymization, and other operations necessary for the operation of the Platform.
Purpose of Processing Provision, support, security, administration, and development of the Platform in accordance with the Main Agreement and the Customer's documented instructions.
Duration of Processing For the duration of the Main Agreement and any additional period necessary for deletion, return of data, backup retention, compliance with legal obligations, or the defense of legal claims.
Categories of Data Subjects Platform users, Customer employees, Customer representatives, contractors, suppliers, customers, signatories, document recipients, approval participants, administrators, contact persons, and individuals whose personal data are contained in documents or attachments.
Categories of Personal Data First name, last name, email address, telephone number, job title, company, workflow role, user/account identifiers, IP address, activity logs, signature or certificate data, document metadata, comments, document fields, attachments, structured data, Envelope data, and other data uploaded or created by the Customer or Platform users.
Special Categories of Personal Data The Platform is not specifically designed for processing special categories of personal data. Where the Customer uploads such data within documents or attachments, the Customer is responsible for ensuring the existence of appropriate legal grounds and safeguards.
Children's Data The Platform is not intended for independent use by children. Where the Customer uploads personal data relating to minors within its own business processes, the Customer is responsible for the lawfulness of such processing and for obtaining the necessary consents or other legal grounds.
Processing Frequency Continuous throughout the Customer's and Platform users' use of the Platform.
Location of Primary Infrastructure AWS Europe, Germany, unless otherwise agreed by the Parties.

4. Customer Obligations as Data Controller

🔍 Return to content

4.1. The Customer shall independently determine the purposes and means of processing User Data and shall be solely responsible for the lawfulness of such processing.

4.2. The Customer shall ensure that appropriate legal grounds exist for the collection, transfer, and processing of User Data within the Platform, including consent, performance of a contract, legitimate interests, compliance with a legal obligation, or any other applicable legal basis.

4.3. The Customer shall be responsible for providing data subjects with appropriate privacy notices, complying with transparency requirements, determining retention periods, ensuring the accuracy of personal data, and facilitating the exercise of data subject rights.

4.4. The Customer shall not upload to the Platform personal data whose processing is unlawful, excessive, or incompatible with the stated purpose, nor special categories of personal data where appropriate legal grounds and safeguards are absent.

4.5. The Customer shall be responsible for configuring access rights, user roles, permissions, processing workflows, templates, integrations, and other Platform settings that determine the scope and manner of processing User Data.

4.6. The Customer shall bear sole responsibility for the content of User Data, documents, attachments, messages, payment details, invoices, instructions, approval workflows, recipients, and any other actions performed by the Customer or its users within the Platform.

The Customer represents and warrants that such data, documents, and activities are lawful, accurate, do not mislead third parties, are not used for fraud, phishing, unlawful obtaining of funds, distribution of malicious, offensive, discriminatory, or otherwise unlawful content, and do not infringe the rights of any third party.


5. Obligations of LLC "CENTREDO" as Data Processor

🔍 Return to content

5.1. LLC "CENTREDO" shall process User Data solely on behalf of the Customer and in accordance with the Customer's documented instructions unless otherwise required by applicable law.

5.2. Where LLC "CENTREDO" considers that an instruction from the Customer infringes applicable personal data protection legislation, the Company shall inform the Customer accordingly, unless such notification is prohibited by law.

5.3. LLC "CENTREDO" shall ensure that all persons authorized to process User Data are bound by confidentiality obligations or are subject to an appropriate statutory duty of confidentiality.

5.4. LLC "CENTREDO" shall implement and maintain appropriate technical and organizational security measures as described in Table 2 of this DPA.

Table 2. Technical and Organizational Security Measures

Area Measures
Information Security Management System The Information Security Management System (ISMS) of LLC "CENTREDO" is certified in accordance with ISO/IEC 27001:2022. Internal security policies, access controls, risk management procedures, and incident response processes have been implemented.
Encryption Data in transit is protected using TLS 1.2/1.3.
Access Control AWS IAM, least privilege principle, role-based access control, restrictions on access to documents, account settings, and the production environment.
Authentication Email address and password, password policy, Multi-Factor Authentication (MFA), Single Sign-On (SSO), OAuth (Google, Microsoft, Apple), and additional verification when SSO is used.
Engineer Access Direct developer access to the production environment is restricted. Access is granted only where required for critical operational purposes through secure channels, VPN, SSH keys, and comprehensive logging
Logging Actions relating to Envelopes and Accounts are recorded in system logs together with timestamps, IP addresses, and Platform identifiers. Infrastructure activities are logged through AWS CloudTrail.
Backup System backup procedures are implemented. Backup copies are retained for 30 days, unless otherwise agreed or required by law.
Data Segregation Customer data is logically segregated through accounts, roles, access permissions, and system identifiers.
Monitoring and Incident Response Security event monitoring, incident analysis, incident containment, Customer notification, and service recovery are performed in accordance with internal procedures.
Subprocessors Engagement of Subprocessors is governed by contractual agreements, confidentiality obligations, security requirements, and prior Customer notification procedures.
Physical Security Physical security of the primary cloud infrastructure is provided by AWS within its respective data centers.
Deletion Deletion and anonymization of data are carried out in accordance with the Customer's instructions, the Platform's functionality, the Main Agreement, and applicable law.

5.5. Taking into account the nature of the processing, LLC "CENTREDO" shall provide reasonable assistance to the Customer in fulfilling obligations relating to data subject requests, security of processing, personal data breach notifications, data protection impact assessments, and consultations with supervisory authorities.

5.6. LLC "CENTREDO" shall not use User Data for its own marketing purposes, sell User Data to third parties, or use User Data for training public artificial intelligence models.

5.7. Upon termination of the Services, LLC "CENTREDO" shall delete or return User Data in accordance with the Main Agreement, the Customer's instructions, the technical capabilities of the Platform, and applicable law.

5.8. LLC "CENTREDO" does not perform prior legal, financial, accounting, or substantive review of documents, invoices, files, messages, payment details, or any other User Data created, uploaded, or transmitted by the Customer or its users through the Platform.

LLC "CENTREDO" is not a party to transactions, settlements, deliveries, payments, or any other legal relationships between the Customer, its users, counterparties, or third parties, unless otherwise expressly provided under a separate agreement.


6. Subprocessors

🔍 Return to content

6.1. The Customer grants LLC "CENTREDO" a general authorization to engage Subprocessors necessary for the provision, support, security, integration, and development of the Platform, provided that the requirements of this DPA are complied with.

6.2. LLC "CENTREDO" shall maintain an up-to-date list of Subprocessors. The initial list is set out in Table 3 to this DPA.

Table 3. Initial List of Subprocessors

Provider Function Categories of Data Location
Amazon Web Services EMEA SARL Primary cloud infrastructure, hosting, databases, content storage, backups User Data, metadata, system data EU: Germany (Frankfurt Region, AWS Europe). Processing and storage are performed exclusively within the European Union.
SendPulse OÜ / SendPulse Inc. Transactional Platform notifications Email addresses, names, system event metadata EU / USA, depending on the service configuration
Google Ireland Limited Google Gemini API / Vertex AI for AI functionality; Google Places / Maps API for address validation Documents, metadata, prompts processed within AI requests; address data for validation EU: Germany / Ireland. Vertex AI processing is performed within Google's dedicated European cloud environment.
Zoho Corporation B.V. Help desk and support request processing Contact details, support request descriptions, technical support data EU: Netherlands / Ireland
HelpCrunch Corporation Online support chat and feedback widgets Contact details, support messages, technical metadata EU / USA
AnyDesk Software GmbH Secure remote technical support sessions where required Technical session data and, where applicable, data visible during the agreed support session EU: Germany
LLC "STREAM TELECOM" Corporate IP telephony for customer support Contact telephone numbers, call recordings or call metadata, where applicable Ukraine
Worksection Internal task management for the technical team, bug tracking, task management Technical task descriptions and limited information where required for issue resolution EU: Germany (Hetzner)
Google Analytics 4 / Google Tag Manager Product analytics, web analytics, tag management De-identified or technical metrics, cookie identifiers according to consent settings EU / Google's global infrastructure
Meta Platforms Ireland Limited / Meta Platforms, Inc. Advertising analytics, Facebook Pixel / Conversions API, where applicable Marketing and conversion metadata according to consent settings EU / Meta's global infrastructure
Uspacy Cloud data center infrastructure Cloud CRM system for customer relationship management, contact database maintenance, lead generation, sales automation, and recording service interaction history Ukraine

Note:
Integrated Qualified Trust Service Providers of Ukraine and European Trust Service Providers included in the eIDAS Trusted List act as independent Data Controllers in accordance with Clause 1.4 of this Agreement and are not Subprocessors of LLC "CENTREDO."

6.3. LLC "CENTREDO" shall notify Customers of the engagement of a new Subprocessor at least 30 calendar days in advance through the website, the Platform interface, email, or another available notification channel.

6.4. The Customer shall have the right to submit a reasoned objection based on security or personal data protection concerns within 14 calendar days after receiving such notification.

6.5. Upon receipt of a justified objection, LLC "CENTREDO" shall consider it in good faith and may provide additional information, propose alternative safeguards, or, where the identified risk cannot reasonably be mitigated, agree to terminate the relevant part of the Services in accordance with the Main Agreement.

6.6. LLC "CENTREDO" shall enter into agreements with its Subprocessors imposing data protection obligations that are no less protective than those applicable to LLC "CENTREDO" under this DPA, taking into account the nature of the Subprocessor's services.

6.7. LLC "CENTREDO" shall remain responsible to the Customer for the performance of its Subprocessors' obligations to the extent provided by applicable law and the Main Agreement.


7. International Data Transfers

🔍 Return to content

7.1. Unless otherwise agreed by the Parties, the primary infrastructure of the Platform is hosted within the AWS Europe Region (Germany).

7.2. Where the processing of User Data involves the transfer of personal data outside the European Economic Area (EEA), Ukraine, or any other jurisdiction that restricts international data transfers, LLC "CENTREDO" shall implement appropriate safeguards.

Table 4. International Data Transfer Safeguards

Element Description
Primary Location The primary Platform infrastructure is hosted in AWS Europe, Germany.
Transfer Mechanisms Standard Contractual Clauses (SCCs), adequacy decisions, DPAs with Subprocessors, contractual restrictions, where applicable.
Transfer Impact Assessment (TIA) Assessment of the destination country's legal framework, risks of access by public authorities, the nature of the data, categories of data subjects, purposes of the transfer, and available technical safeguards.
Additional Safeguards Encryption, access controls, logging, pseudonymization or data minimization, Subprocessor access restrictions, technical and contractual safeguards.
Onward Transfers Subprocessors may further transfer data only in accordance with applicable agreements, DPAs, and international data transfer mechanisms.
Customer Notification Changes relating to Subprocessors or material changes in processing locations shall be communicated in accordance with the procedure established by this DPA.

7.3. Such safeguards may include adequacy decisions, the European Commission Standard Contractual Clauses (SCCs), Transfer Impact Assessments (TIAs), additional technical and organizational measures, encryption, access controls, contractual restrictions, and Subprocessor governance.

7.4. Where SCCs are required for transfers of personal data from the Customer within the EEA to LLC "CENTREDO" or its Subprocessors, the applicable SCC modules shall apply by incorporation by reference or through execution of a separate document, unless otherwise agreed by the Parties.


8. Security of Processing

🔍 Return to content

8.1. LLC "CENTREDO" shall implement appropriate technical and organizational measures, taking into account the state of the art, implementation costs, the nature, scope, context, and purposes of processing, and the risks to the rights and freedoms of natural persons.

8.2. Such measures shall include, without limitation, encryption of data in transit and at rest, access controls, the principle of least privilege, activity logging, backup procedures, security monitoring, incident management, environment segregation, and Subprocessor management.

8.3. A detailed description of the technical and organizational measures is provided in Table 2 of this DPA.

8.4. The Customer shall be responsible for the secure use of the Platform on its side, including management of users, roles, permissions, passwords, Single Sign-On (SSO), Multi-Factor Authentication (MFA), API keys, integrations, and internal access control policies.


9. Data Subject Requests

🔍 Return to content

9.1. Where a data subject submits a request directly to LLC "CENTREDO" concerning User Data for which LLC "CENTREDO" acts as the Data Processor, the Company may forward such request to the Customer or act in accordance with the Customer's documented instructions, unless otherwise required by law.

9.2. LLC "CENTREDO" shall provide the Customer with reasonable assistance in facilitating the exercise of data subject rights, taking into account the nature of the processing and the information available to the Company.

9.3. The Customer shall remain responsible for deciding whether to grant, reject, or restrict data subject requests, unless otherwise required by applicable law.


10. Personal Data Security Incidents

🔍 Return to content

10.1. In the event of a confirmed security incident that may result in a breach of the confidentiality, integrity, or availability of User Data, LLC "CENTREDO" shall take appropriate measures to contain, assess, and remediate the consequences of such incident.

10.2. Where LLC "CENTREDO" acts as the Data Processor, the Company shall notify the relevant Customer acting as the Data Controller without undue delay after becoming aware of a confirmed personal data incident.

10.3. The incident notification shall include the information available to LLC "CENTREDO" at the time of notification, including, where available, a description of the nature of the incident, the categories and approximate number of affected data subjects or records, the likely consequences, and the measures taken or proposed.

10.4. LLC "CENTREDO" may provide information in phases where complete information about the incident is not available at the time of the initial notification.

10.5. The Customer shall remain responsible for fulfilling its own obligations to notify competent supervisory authorities and/or data subjects where such obligations apply to the Customer in its capacity as the Data Controller.


11. Assistance with DPIAs, Consultations and Compliance

🔍 Return to content

11.1. LLC "CENTREDO" shall provide the Customer with reasonable assistance in fulfilling obligations relating to Data Protection Impact Assessments (DPIAs), prior consultations with supervisory authorities, and risk assessments where such assistance relates to the processing of User Data within the Platform.

11.2. Such assistance may include providing descriptions of technical and organizational measures, information regarding Subprocessors, processing locations, security standards, and other information available to LLC "CENTREDO".

11.3. Where the Customer's request requires substantial additional work, the Parties may agree separately on the applicable scope, timelines, and fees for such work in accordance with the Main Agreement.


12. Audit and Demonstration of Compliance

🔍 Return to content

12.1. LLC "CENTREDO" shall provide the Customer with the information necessary to demonstrate compliance with the Processor's obligations under this DPA, taking into account confidentiality, security, the rights of other customers, and the protection of trade secrets.

12.2. As the primary means of demonstrating compliance, LLC "CENTREDO" may provide certificates, policies, a Security Overview, independent audit reports, descriptions of technical and organizational measures, extracts from documentation, or responses to information security questionnaires (Security Questionnaires).

12.3. Where the Customer reasonably requires an additional audit, such audit shall be conducted only upon the Parties' prior written agreement, no more than once per calendar year, during normal business hours, without disrupting the operation of the Platform, without access to other customers' data, and subject to appropriate confidentiality obligations.

12.4. The Customer shall not conduct penetration testing, vulnerability scanning, load testing, or any other technical testing of the Platform without the prior written consent of LLC "CENTREDO".


13. Data Return, Deletion and Retention

🔍 Return to content

13.1. Upon termination of the Services, the Customer may export or delete User Data using the functionality of the Platform or in accordance with the agreed procedures.

13.2. LLC "CENTREDO" shall delete or anonymize User Data in accordance with the Customer's instructions, the Main Agreement, the technical capabilities of the Platform, and applicable law.

13.3. Where an Envelope containing documents is associated with multiple participants from different accounts, deletion by one participant shall not result in deletion of the object for the remaining parties where continued retention is necessary for the performance of a contract, compliance with a legal obligation, the establishment, exercise or defense of legal claims, or the legitimate interests of other participants in the document workflow.

13.4. Backup copies may be retained for the duration of the backup retention cycle specified in the Privacy Policy or the Main Agreement without active use, except where required for restoration, security, incident investigation, or compliance with a legal obligation.

13.5. LLC "CENTREDO" may retain certain data for a longer period where necessary to comply with a legal obligation, establish, exercise or defend legal claims, conduct audits, ensure security, prevent fraud, or comply with applicable law.


14. Artificial Intelligence and Automated Processing

🔍 Return to content

14.1. Where the Customer or Platform users utilize WhiteDoc AI functionality, User Data shall be processed solely at the initiative of the user and only within the relevant Envelope or other Platform object.

14.2. Documents, metadata, and requests processed through AI functionality shall not be used by LLC "CENTREDO" for training public or foundation artificial intelligence models.

14.3. AI-generated output may be inaccurate or incomplete and does not constitute legal, financial, HR, tax, or any other professional advice. The Customer and Platform users are responsible for independently verifying all AI-generated results before using them in legally significant or other important processes.

14.4. The use of AI functionality may be restricted or disabled at the account level where such functionality is available within the Platform or otherwise agreed by the Parties.


15. Confidentiality

🔍 Return to content

15.1. Each Party shall keep confidential all information received from the other Party in connection with this DPA, including technical, commercial, organizational, and other non-public information.

15.2. LLC "CENTREDO" shall ensure that its employees, contractors, and other authorized persons having access to User Data are bound by confidentiality obligations.

15.3. The obligation of confidentiality shall not apply to information that:

  • is publicly available;
  • was lawfully obtained from a third party without restriction;
  • was independently developed by the receiving Party; or
  • is required to be disclosed pursuant to applicable law.

16. Term and Termination

🔍 Return to content

16.1. This DPA shall become effective on the effective date of the Main Agreement or on the date LLC "CENTREDO" first begins processing User Data on behalf of the Customer, whichever occurs first.

16.2. This DPA shall remain in effect throughout the term of the Main Agreement and until completion of all operations relating to the return, deletion, anonymization, or lawful retention of User Data.

16.3. Termination of the Main Agreement shall not relieve either Party of obligations that, by their nature, are intended to survive termination, including obligations relating to confidentiality, security, deletion or return of data, audits, and the establishment, exercise or defense of legal claims.


17. Priority of Documents and Amendments

🔍 Return to content

17.1. In the event of any inconsistency between this DPA and the Privacy Policy with respect to the processing of User Data, this DPA shall prevail.

17.2. In the event of any inconsistency between this DPA and the Main Agreement concerning purely commercial terms, liability, payment, service periods, or termination procedures, the provisions of the Main Agreement shall apply, provided that they do not conflict with mandatory requirements of applicable personal data protection legislation.

17.3. LLC "CENTREDO" may update this DPA due to changes in applicable law, Platform functionality, Subprocessors, or technical security measures.

Material changes affecting the Customer's rights or obligations shall be communicated to the Customer in advance in the manner provided for in the Main Agreement or through the Platform.


18. Official contact details of LLC "CENTREDO"

🔍 Return to content

Legal Entity Name: LLC "CENTREDO"

EDRPOU Code: 43617469

Tax Identification Number (TIN): 436174626585

D-U-N-S Number: 537809077

Registered Address: 7A Mykoly Vasylenka Street, Kyiv, 03124, Ukraine

Email for Personal Data Requests: privacy@whitedoc.ua

Customer Support: help@whitedoc.ua

Did this answer your question?