Data Processing Addendum
Last updated: 10 July 2026
This Data Processing Addendum (DPA) applies where DotMD processes personal data on your behalf and data-protection law such as the GDPR or UK GDPR applies. It forms part of our Terms.
1. Roles and scope
For personal data contained in the content you create on DotMD, you act as the “controller” and DotMD acts as your “processor”, as those terms are used in applicable data-protection law. DotMD processes that personal data only to provide and support the Service. The subject matter is your use of the Service; the duration is the term of your account; the categories of data subjects and personal data are those you choose to include in your content and account (summarised in Annex I, section 13).
2. Processing on your instructions
DotMD processes personal data only on your documented instructions — including the instructions inherent in your use of the Service — unless the law requires otherwise, in which case we will tell you (where permitted).
3. Confidentiality and security
Personnel authorised to process personal data are bound by confidentiality. We maintain appropriate technical and organisational security measures, including encryption of data in transit and at rest, access controls, and key-management for secrets, taking account of the nature of the data and the risks involved.
4. Sub-processors
You give general authorisation for the sub-processors listed on our Sub-processors page. We impose data-protection obligations on them consistent with this DPA, and we will give at least 30 days’ notice before adding or replacing a sub-processor so you can object on reasonable data-protection grounds.
5. Assisting you with data-subject rights
Taking account of the nature of the processing, we assist you in responding to requests from data subjects to exercise their rights (such as access, rectification, erasure, and portability), including through the Service’s export and deletion features and reasonable support.
6. International transfers
Personal data is processed in the United States. For transfers from the EEA, the UK, or Switzerland, we rely on appropriate safeguards, such as the European Commission’s Standard Contractual Clauses (and the UK Addendum where relevant), which are incorporated by reference where they apply.
7. Personal-data breaches
We will notify you without undue delay after becoming aware of a personal-data breach affecting personal data we process for you, and we will provide the information you reasonably need to meet your own breach-notification obligations.
8. Return and deletion
On termination, we delete or return the personal data we process for you, as described in our Privacy Policy (deletion of your documents without undue delay, with residual copies removed as backups expire), unless the law requires us to retain it.
9. Information and audits
We make available the information reasonably necessary to demonstrate compliance with this DPA and will allow for and contribute to reasonable audits — no more than once per year, on reasonable notice, at your cost, and without disrupting the Service. To request this DPA as a counter-signed agreement, contact us at
support@dotmd.co.
10. Impact assessments and prior consultation
Taking account of the nature of the processing and the information available to us, we provide reasonable assistance with your data-protection impact assessments and any prior consultation with a supervisory authority, where applicable data-protection law (such as Articles 35 and 36 of the GDPR) requires it.
11. US state privacy (service-provider terms)
Where the California Consumer Privacy Act (as amended) or a similar US state law applies, DotMD acts as your “service provider” or “processor”: we process personal information only to provide the Service and for the limited purposes set out in this DPA, and we do not “sell” or “share” it, or retain, use, or disclose it for any other purpose. We delete or return personal information on your request, subject to any retention the law requires.
12. Term, liability, definitions and precedence
This DPA takes effect when you accept the Terms and continues for as long as we process personal data for you. Each party’s liability under this DPA is subject to the limitations and exclusions of liability in the Terms.
Terms such as “controller”, “processor”, “personal data”, “processing”, and “data subject” have the meanings given in applicable data-protection law. If there is a conflict, this DPA prevails over the Terms on data-protection matters, and any executed Standard Contractual Clauses prevail over this DPA to the extent of the conflict.
13. Annexes
The details required by the Standard Contractual Clauses are set out in the annexes below:
- Annex I — the parties and processing: you (the customer) are the controller/data exporter and DotMD LLC is the processor/data importer. Data subjects are your account users and the individuals whose information you include in your content; the personal data is your account data and any personal data contained in the documents you create (the Service requires no special categories); the processing is hosting, storage, syncing, backup, and display to provide the Service, for the duration of your account.
- Annex II — technical and organisational measures: encryption in transit (TLS) and at rest, KMS-managed keys and secrets, least-privilege access controls, single-region storage (AWS us-west-2), operational logging that excludes document content, and periodic review — as summarised in section 3.
- Annex III — the list of sub-processors, published and kept current on our Sub-processors page (/subprocessors).