version 1.0
This Cloud Data Processing Agreement (CDPA) governs the processing of personal data by LogicalDOC on behalf of the Controller in connection with the provision of LogicalDOC Cloud, a document management and workflow automation platform.
ROLES AND RESPONSIBILITIES
-
The Controller determines the purposes and means of processing personal data.
-
LogicalDOC acts solely as Processor, processing personal data only on documented instructions from the Controller.
CATEGORIES OF PERSONAL DATA
LogicalDOC Cloud may process the following categories of personal data:
-
Identification data (name, surname, email, phone number)
-
Personal data contained within documents uploaded by the Controller
-
Metadata (tags, categories, versions, workflow states)
-
System logs (access logs, audit trails, IP addresses, timestamps)
-
Technical data required for service operation
The Controller is responsible for ensuring that no special categories of data (Art. 9 GDPR) are uploaded unless lawfully permitted.
DURATION OF PROCESSING
Processing shall continue for the duration of the Controller’s subscription to LogicalDOC Cloud. Upon termination, data shall be handled according to the article "Return or Deletion of Data" of this agreement.
DOCUMENTED INSTRUCTIONS
LogicalDOC shall process personal data exclusively:
-
to provide, maintain, and improve LogicalDOC Cloud
-
to ensure security, backup, and continuity
-
to provide technical support
-
according to written instructions from the Controller
LogicalDOC shall immediately inform the Controller if an instruction violates GDPR.
TECHNICAL AND ORGANIZATIONAL MEASURES (ART. 32 GDPR)
LogicalDOC implements appropriate security measures, including:
-
Encryption in transit (TLS 1.2+) and at rest (AES‑256)
-
Strong authentication and password policies
-
Optional multi‑factor authentication (MFA)
-
Tenant isolation and data segregation
-
Daily backups with configurable retention
-
Continuous monitoring and logging
-
Regular patching and system hardening
-
Disaster recovery and business continuity plans
-
Access restricted to authorized personnel only
SUB‑PROCESSORS
LogicalDOC may engage sub‑processors for:
-
Cloud hosting and infrastructure
-
Backup and storage
-
Monitoring and security services
LogicalDOC shall:
-
maintain an updated list of sub‑processors
-
ensure each sub‑processor is bound by a GDPR‑compliant contract
-
notify the Controller of any intended changes
INTERNATIONAL DATA TRANSFERS
If personal data is transferred outside the European Economic Area (EEA), LogicalDOC shall ensure compliance through:
-
adequacy decisions, or
-
Standard Contractual Clauses (SCCs), or
-
supplementary technical measures (e.g., encryption)
CONFIDENTIALITY
LogicalDOC ensures that:
-
personnel authorized to process data are bound by confidentiality obligations
-
access is granted strictly on a need‑to‑know basis
-
confidentiality is maintained even after termination of employment
ASSISTANCE TO THE CONTROLLER
LogicalDOC shall assist the Controller in:
-
responding to data subject requests (Art. 15–22 GDPR)
-
conducting Data Protection Impact Assessments (DPIA)
-
ensuring compliance with security obligations
-
managing data breaches
Personal Data Breach Notification
In the event of a personal data breach:
-
LogicalDOC shall notify the Controller without undue delay
-
provide all relevant information required under Articles 33–34 GDPR
-
cooperate to mitigate adverse effects
AUDITS AND INSPECTIONS
The Controller may conduct audits or request security documentation. Audits must:
-
be scheduled with reasonable notice
-
not disrupt LogicalDOC’s operations
-
respect the security of other customers
LIABILITY
LogicalDOC is liable for damages caused by processing activities that violate GDPR or the Controller’s instructions. The Controller is responsible for the lawfulness of the data and the purposes of processing.
DATA RETENTION
Personal data is retained for the duration of the service. Backup retention periods may vary based on technical requirements.
RETURN OR DELETION OF DATA
Upon termination:
-
the Controller may request full data export
-
LogicalDOC shall delete all personal data within 30 days, unless legal obligations require retention
-
backups will be deleted
AMENDMENTS
LogicalDOC may update this DPA to reflect legal or technical changes. Updates will be communicated to the Controller.
GOVERNING LAW AND JURISDICTION
This Agreement is governed by the laws of Italy. The competent court is Modena, unless otherwise agreed.
This document is published at the "Cloud Data Processing Agreement " section of this site and is subject to updating.