# Data Processing Addendum

The Data Processing Addendum governing how Modern Paper, Inc. processes personal data on behalf of PDF Blocks customers, including EU Standard Contractual Clauses and CCPA terms.

## 1. Introduction and Incorporation

This Data Processing Addendum ("DPA") forms part of the [Terms &
Conditions](/docs/trust/terms) or other written agreement between you ("Customer") and
Modern Paper, Inc. ("Modern Paper", "we", "us", or "our") governing your use of
PDF Blocks (the "Agreement"). It reflects the parties' agreement on the
processing of Personal Data in connection with the Service.

This DPA is provided at no charge and does not depend on any third-party
platform. It applies automatically and is incorporated into the Agreement when
Customer uses the Service to process Personal Data that is subject to Data
Protection Laws. No signature is required for this DPA to be effective; by
accepting the Agreement or using the Service, you agree to this DPA. If you
require a countersigned copy, contact
[privacy@pdfblocks.com](mailto:privacy@pdfblocks.com).

In the event of a conflict between this DPA and the rest of the Agreement in
relation to the processing of Personal Data, this DPA prevails. In the event of
a conflict between this DPA and the Standard Contractual Clauses, the Standard
Contractual Clauses prevail.

## 2. Definitions

- **"Data Protection Laws"** means all laws applicable to the processing of
  Personal Data under the Agreement, including, where applicable, the GDPR, the
  UK GDPR, the Swiss FADP, and the CCPA.
- **"GDPR"** means Regulation (EU) 2016/679. **"UK GDPR"** means the GDPR as
  incorporated into United Kingdom law. **"Swiss FADP"** means the Swiss Federal
  Act on Data Protection.
- **"CCPA"** means the California Consumer Privacy Act of 2018, as amended by
  the California Privacy Rights Act (CPRA), and its regulations.
- **"Customer Personal Data"** means Personal Data contained in the documents,
  files, and data that Customer submits to the API for processing and that
  Modern Paper processes solely on Customer's behalf under the Agreement. It
  does not include the account, billing, or website data that Modern Paper
  processes as a Controller for its own purposes, which is addressed in the
  [Privacy Policy](/docs/trust/privacy) and is outside the scope of this DPA.
- **"Controller"**, **"Processor"**, **"Data Subject"**, **"Personal Data"**,
  **"processing"**, and **"Supervisory Authority"** have the meanings given in
  the GDPR. **"Business"**, **"Service Provider"**, **"Personal Information"**,
  **"Sell"**, and **"Share"** have the meanings given in the CCPA.
- **"Personal Data Breach"** means a breach of security leading to the
  accidental or unlawful destruction, loss, alteration, unauthorised disclosure
  of, or access to, Customer Personal Data.
- **"Standard Contractual Clauses"** or **"SCCs"** means the clauses in the
  Annex to Commission Implementing Decision (EU) 2021/914 of 4 June 2021,
  available at
  [eur-lex.europa.eu](https://eur-lex.europa.eu/eli/dec_impl/2021/914/oj).
- **"Subprocessor"** means any Processor engaged by Modern Paper to process
  Customer Personal Data.

## 3. Roles of the Parties

This DPA governs only Modern Paper's processing of Customer Personal Data as a
Processor on Customer's behalf. In respect of that processing, Customer is the
Controller (or a Processor acting on behalf of a third-party Controller) and
Modern Paper is the Processor (or Subprocessor).

Modern Paper's separate processing of account, billing, and website data as a
Controller for its own purposes is outside the scope of this DPA and is
described in our [Privacy Policy](/docs/trust/privacy). Each party will comply with its
obligations under Data Protection Laws.

## 4. Scope and Instructions for Processing

Modern Paper will process Customer Personal Data only on documented instructions
from Customer, including as set out in the Agreement, this DPA, and Customer's
configuration and use of the Service, and as required to provide the Service and
comply with applicable law. If Modern Paper is required by law to process
Customer Personal Data beyond these instructions, it will inform Customer of
that requirement before processing, unless the law prohibits such notice on
important grounds of public interest.

Modern Paper will notify Customer if, in its opinion, an instruction infringes
Data Protection Laws. The subject matter, duration, nature, and purpose of the
processing, and the types of Personal Data and categories of Data Subjects, are
described in **Annex I**.

Customer submits documents to, and receives results from, Modern Paper solely
through the API. Modern Paper does not receive or transmit Customer documents by
email or any other channel. Documents submitted to the API are processed
transiently, in memory, to perform the requested operation and are not retained
after the response is returned, as further described in our Privacy Policy.

## 5. Customer Obligations

Customer is responsible for the accuracy and lawfulness of Customer Personal
Data and for having an appropriate legal basis to submit it to the Service and
to authorise its processing under this DPA. Customer will provide any notices
and obtain any consents required from Data Subjects. Customer will not submit
special categories of Personal Data, or data subject to heightened regulatory
regimes (such as protected health information under HIPAA), except as permitted
by the Agreement's Acceptable Use section or as separately agreed in writing.

## 6. Confidentiality

Modern Paper will ensure that persons authorised to process Customer Personal
Data are bound by an appropriate obligation of confidentiality and process that
data only as instructed.

## 7. Security Measures

Modern Paper will implement and maintain appropriate technical and
organisational measures to protect Customer Personal Data against a Personal
Data Breach, taking into account the state of the art, the costs of
implementation, and the nature, scope, context, and purposes of processing.
Those measures are described in **Annex II** and may be updated from time to
time provided the level of protection is not materially reduced.

## 8. Personal Data Breaches

Modern Paper will notify Customer without undue delay after becoming aware of a
Personal Data Breach affecting Customer Personal Data, and will provide
information reasonably available to it to help Customer meet its own breach
obligations. Modern Paper will take reasonable steps to mitigate and remedy the
breach.

## 9. Subprocessors

Customer provides general authorisation for Modern Paper to engage Subprocessors
to process Customer Personal Data. The current Subprocessors are listed in
**Annex III**. Modern Paper will impose data-protection obligations on each
Subprocessor that are no less protective than those in this DPA and remains
responsible for its Subprocessors' performance.

Modern Paper will give Customer at least 30 days' notice before adding or
replacing a Subprocessor, by updating Annex III and, where Customer has
subscribed to notifications, by email. Customer may object on reasonable
data-protection grounds within that period; the parties will work in good faith
to resolve the objection, and if they cannot, Customer may terminate the
affected part of the Service.

## 10. Data Subject Requests

Taking into account the nature of the processing, Modern Paper will assist
Customer, by appropriate technical and organisational measures and insofar as
possible, to respond to requests from Data Subjects to exercise their rights. If
Modern Paper receives a request directly from a Data Subject relating to
Customer Personal Data, it will not respond except on Customer's instructions or
as required by law, and will promptly forward the request to Customer.

## 11. Assistance to the Customer

Taking into account the nature of the processing and the information available
to it, Modern Paper will assist Customer in ensuring compliance with its
obligations regarding security, breach notification, data protection impact
assessments, and prior consultation with a Supervisory Authority.

## 12. Deletion and Return of Personal Data

Documents submitted to the API are not retained after processing. Because Modern
Paper does not retain Customer Personal Data in its role as Processor, no
separate deletion or return step is required on termination. Modern Paper's
handling of the account and usage data that it processes as a Controller is
governed by the Privacy Policy and is outside the scope of this DPA.

## 13. Audits and Records

Modern Paper will make available to Customer information reasonably necessary to
demonstrate compliance with this DPA and will allow for and contribute to
audits, including inspections, conducted by Customer or an auditor it mandates.
The parties agree that audits will ordinarily be satisfied by Modern Paper
providing relevant documentation, security summaries, and responses to
reasonable questionnaires. On-site audits will be limited to once per year
(absent a Personal Data Breach or Supervisory Authority requirement), on
reasonable prior notice, during business hours, and subject to confidentiality.

## 14. International Data Transfers

Where Modern Paper processes Customer Personal Data that is transferred out of
the European Economic Area (EEA), the United Kingdom, or Switzerland to a
country that does not ensure an adequate level of protection, the following
transfer mechanisms apply.

### 14.1 EU Standard Contractual Clauses

The SCCs are incorporated into this DPA by reference and completed as follows:

- **Module Two** (Controller to Processor) applies where Customer is a
  Controller; **Module Three** (Processor to Processor) applies where Customer
  is itself a Processor acting for a third-party Controller.
- Clause 7 (Docking clause) applies.
- Clause 9(a): Option 2 (general written authorisation) applies, with the
  minimum notice period stated in Section 9 of this DPA.
- Clause 11(a): the optional independent dispute-resolution option does not
  apply.
- Clause 17 (Governing law): Option 1 applies, and the SCCs are governed by the
  law of Ireland.
- Clause 18(b) (Choice of forum): the courts of Ireland.
- Annexes I, II, and III of the SCCs are populated by Annexes I, II, and III of
  this DPA. The data exporter is Customer; the data importer is Modern Paper.

### 14.2 United Kingdom

For transfers subject to the UK GDPR, the SCCs as incorporated above are
supplemented by the International Data Transfer Addendum issued by the UK
Information Commissioner ("UK Addendum"), which is incorporated by reference.
Table 1 is completed with the parties' details in Annex I.A; Tables 2 and 3 with
the SCCs and Annexes as incorporated above; and for Table 4, neither party may
end the UK Addendum when the approved Addendum changes, save as set out in its
terms. The UK Addendum's Mandatory Clauses apply.

### 14.3 Switzerland

For transfers subject to the Swiss FADP, the SCCs apply with these amendments:
references to the GDPR are to the FADP; the competent authority is the Swiss
Federal Data Protection and Information Commissioner; the SCCs also protect the
Personal Data of legal entities until the FADP no longer requires it; and Swiss
Data Subjects may enforce their rights in Switzerland.

### 14.4 Alternative Transfer Mechanism

If Modern Paper adopts an alternative lawful transfer mechanism, that mechanism
applies to the relevant transfers instead of the SCCs to the extent it is
superseded.

## 15. California Consumer Privacy Act

Where Modern Paper processes Personal Information of California residents on
Customer's behalf, Modern Paper acts as a Service Provider and the terms in
**Annex IV** apply.

## 16. Liability

Each party's liability arising out of or related to this DPA and the SCCs,
whether in contract, tort, or under any other theory of liability, is subject to
the limitations and exclusions of liability set out in the Agreement.

## 17. Term

This DPA takes effect on the earlier of Customer's acceptance of the Agreement
or first use of the Service to process Personal Data, and remains in effect
until the Agreement terminates and Modern Paper has ceased processing Customer
Personal Data.

## Annex I — Description of Processing

### A. List of Parties

**Data exporter:** the Customer identified in the Agreement, acting as
Controller (or Processor) of Customer Personal Data. Contact: the account
owner's contact details in the Customer's account.

**Data importer:** Modern Paper, Inc., a Delaware corporation, acting as
Processor. Contact: [privacy@pdfblocks.com](mailto:privacy@pdfblocks.com).

### B. Description of the Transfer

- **Categories of Data Subjects:** determined by Customer; typically Customer's
  employees, contractors, customers, and other individuals whose Personal Data
  appears in the documents or data Customer submits to the API.
- **Categories of Personal Data:** determined by Customer; any Personal Data
  contained in the documents and data Customer submits to the API. Customer
  controls what it submits.
- **Special categories of data:** not intended to be processed; Customer must
  not submit special-category or regulated data except as separately agreed (see
  Section 5).
- **Frequency of the transfer:** continuous, on Customer's use of the Service.
- **Nature and purpose of processing:** performing PDF processing operations
  (such as merging, splitting, password protection, watermarking, stamping, and
  page manipulation) on the documents Customer submits through the API.
- **Duration:** document content is processed transiently and is not retained
  after the response is returned.
- **Subprocessors:** as listed in Annex III, processing for the duration of
  their engagement.

### C. Competent Supervisory Authority

Where Customer is established in an EEA member state, the Supervisory Authority
of that member state. Where Customer is not established in the EEA but has
appointed a representative under Article 27 GDPR, the Supervisory Authority of
the representative's member state. In all other cases, the Irish Data Protection
Commission acts as the competent Supervisory Authority for the SCCs.

## Annex II — Technical and Organisational Measures

Modern Paper maintains, at a minimum, the following measures:

- **Encryption:** TLS for data in transit on every API call; AES encryption
  applied to password-protected document output.
- **Ephemeral processing:** submitted documents are processed in memory and are
  not written to durable storage; any temporary buffering required for a single
  request is deleted when the request completes.
- **Pseudonymisation of credentials:** account passwords are stored only as
  salted hashes, and API keys are stored only as one-way digests; document
  contents are not logged.
- **Access control:** role-based, least-privilege access to production systems,
  with multi-factor authentication for administrative access.
- **Network security:** segmented cloud networks, firewalls, a web application
  firewall, and TLS-terminating load balancers.
- **Physical security:** hosting in cloud data centres that maintain recognised
  security certifications (see Annex III).
- **Logging and monitoring:** security-event logging and request-metadata
  monitoring, configured to avoid capturing document content.
- **Resilience:** auto-scaling and multi-availability-zone deployment across the
  hosting providers listed in Annex III.
- **Vulnerability management:** a secure development lifecycle, dependency
  management, and remediation of identified vulnerabilities.
- **Personnel:** confidentiality obligations and security awareness for staff
  with access to Customer Personal Data.
- **Incident response:** a documented process for detecting, responding to, and
  notifying Personal Data Breaches.

## Annex III — List of Subprocessors

Modern Paper engages the following Subprocessors to host and operate the Service
and to carry out the transient processing of documents Customer submits through
the API. These are the only Subprocessors that process Customer Personal Data:

- **Amazon Web Services, Inc.** — cloud hosting and compute. Locations: the
  regions in which the Service operates — United States, European Union, United
  Kingdom, Canada, Australia, Japan, India, and Brazil.
- **Microsoft Corporation (Microsoft Azure)** — cloud hosting and compute.
  Locations: the regions in which the Service operates — United States, European
  Union, United Kingdom, Canada, Australia, Japan, India, and Brazil.

Modern Paper will give notice of any addition or change to this list as provided
in Section 9.

## Annex IV — California Consumer Privacy Act (Service Provider Terms)

These terms apply to the extent Modern Paper processes Personal Information of
California residents on Customer's behalf. Customer is the Business and Modern
Paper is a Service Provider. Modern Paper will:

- process Personal Information only to perform the Service and for the business
  purposes specified in the Agreement and this DPA, and not for any other
  purpose;
- not Sell or Share Personal Information;
- not retain, use, or disclose Personal Information outside the direct business
  relationship with Customer, or for any commercial purpose other than the
  specified services, except as permitted by the CCPA;
- not combine Personal Information received under the Agreement with personal
  information from other sources, except as permitted by the CCPA;
- provide the same level of privacy protection as required of a Business under
  the CCPA, and comply with its applicable obligations;
- assist Customer in responding to verifiable consumer requests to know, access,
  correct, delete, and opt out; and
- notify Customer if it determines that it can no longer meet its obligations
  under the CCPA.

Modern Paper certifies that it understands and will comply with these
restrictions. Neither party will attempt to reidentify any deidentified data it
receives.

## Contact

Questions about this DPA, or requests for a countersigned copy, may be sent to
[privacy@pdfblocks.com](mailto:privacy@pdfblocks.com).
