Data Processing Agreement
This Data Processing Agreement (“DPA”) forms part of the Terms of Service between you (“Customer,” acting as data controller for the personal data you route through the Service) and DMiller Tech LLC d/b/a DocBurst(“Processor”), and applies whenever Customer's use of the Service involves the processing of personal data subject to GDPR, UK GDPR, CCPA/CPRA, or equivalent data-protection law.
1. Roles
Customer is the controller (or “business,” under CCPA) of any personal data contained in documents it uploads and recipient addresses it configures. DocBurst is the processor (or “service provider”), acting only on Customer's documented instructions as expressed through the Service's routing rules and dispatch actions.
2. Subject Matter and Duration
Subject matter: splitting and routing Customer-uploaded documents to recipients Customer specifies. Duration: for as long as Customer maintains an active account, plus any period required to retain audit records under Customer's instructions or applicable law.
3. Nature and Purpose of Processing
DocBurst processes document content in memory to (a) split multi-page PDFs, (b) extract recipient information per Customer's configured routing rules, (c) assemble per-recipient output files, and (d) dispatch them by email or make them available as a download. Document content is never written to persistent storage; only routing metadata and delivery outcomes (page counts, recipient addresses actually used, timestamps, success/failure status) are retained, for audit purposes.
4. Categories of Data Subjects and Data
- Data subjects: Customer's own end customers, employees, vendors, or other recipients named in uploaded documents.
- Data categories: names, email addresses, and whatever content Customer's uploaded documents contain (e.g. invoice, paystub, or statement data) - determined entirely by Customer, not DocBurst.
DocBurst does not determine what categories of personal data Customer includes in its documents and has no visibility into document content beyond what is needed to execute Customer's own routing rules in real time.
5. Sub-processors
Current sub-processors, each processing data only as needed to provide their respective function:
- Firebase / Google Cloud - authentication (identity only; no document content).
- Postgres database host (e.g. Railway) - settings, usage, and audit metadata storage.
- Resend - platform default email delivery, used only for accounts that have not connected their own SMTP mailbox.
DocBurst will notify Customer of any intended change concerning the addition or replacement of sub-processors, giving Customer the opportunity to object on reasonable data-protection grounds.
6. Security Measures
- Encryption in transit (TLS) for all traffic to the Service.
- Encryption at rest (AES-256-GCM) for saved sender credentials and directory-database connection secrets.
- In-memory-only document processing - uploaded content is never written to disk or a database.
- Per-account access scoping on every database query; the browser never has direct database access.
- Server-side verification of every authenticated request against the caller's actual identity and role.
7. Data Subject Requests
If DocBurst receives a request from a data subject relating to Customer's data, DocBurst will promptly forward it to Customer and will not respond directly except as required by law. Customer is responsible for responding to such requests.
8. International Transfers
Where personal data is transferred outside the data subject's jurisdiction, DocBurst relies on the transfer mechanisms offered by its sub-processors (e.g. Standard Contractual Clauses), consistent with each sub-processor's own compliance documentation.
9. Breach Notification
DocBurst will notify Customer without undue delay after becoming aware of a personal data breach affecting Customer's data, providing information reasonably available to help Customer meet its own notification obligations.
10. Deletion on Termination
On termination of Customer's account, DocBurst will delete or anonymize Customer's stored configuration and audit data within a commercially reasonable period, except where retention is required by law.