Data Processing Agreement
Effective Date: June 30, 2026 | Last Updated: July 4, 2026
For Business Customers
This Data Processing Agreement (“DPA”) is entered into by Skillhanger Limited (RC 1711272, registered in Nigeria), trading as Middledoc, and any business customer (“Customer”) who accepts the Middledoc Terms of Service and uses the Service to process personal data of their own clients or employees. This DPA forms part of the agreement between Middledoc and Customer and is effective upon Customer's acceptance of the Terms of Service. If you require a countersigned DPA with your company name, contact [email protected].
Download PDF1. Definitions
As used in this DPA:
- “Controller” means the natural or legal person who determines the purposes and means of processing personal data. Customer is the Controller of End-User Personal Data.
- “Processor” means the entity that processes personal data on behalf of the Controller. Skillhanger Limited (trading as Middledoc) is the Processor.
- “End-User Personal Data” means personal data that Customer's clients or employees upload to or through the Service.
- “GDPR” means Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 and, where applicable, the equivalent UK GDPR.
- “Sub-Processor” means any third party appointed by Middledoc to process personal data in connection with the Service.
- “Data Subject” means the individual to whom personal data relates.
- “Security Incident” means a confirmed breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, personal data.
- “SCCs” means the Standard Contractual Clauses for the transfer of personal data to third countries pursuant to GDPR, as issued by the European Commission in June 2021.
- All other defined terms have the meanings given in the Middledoc Terms of Service or the GDPR.
2. Roles of the Parties
2.1 Customer is the Controller in respect of End-User Personal Data processed through the Service. Customer determines the purposes for which personal data is collected from its clients (e.g., collecting tax documents, HR records, legal documents) and instructs Middledoc on how to process that data through its configuration of the Service.
2.2Middledoc is the Processor of End-User Personal Data. Middledoc processes such data only in accordance with Customer's documented instructions, as set out in this DPA and the Terms of Service, except where applicable law requires otherwise.
2.3Middledoc is the Controller of account registration data (name, email, billing information) of Customer's authorized users. This data is processed pursuant to Middledoc's Privacy Policy.
3. Details of Processing
3.1 Subject Matter
The processing of personal data by Middledoc on behalf of Customer in connection with the provision of the document collection, AI classification, and e-signature platform.
3.2 Duration
The term of the agreement between Middledoc and Customer (including any renewal periods) plus any post-termination period during which Middledoc retains data subject to the retention provisions of this DPA.
3.3 Nature and Purpose of Processing
- Storing uploaded documents on behalf of Customer
- Transmitting uploaded documents to AI classification services (OpenAI/Anthropic) when the feature is enabled by Customer
- Generating and embedding electronic signature audit trails in PDF documents
- Sending email notifications and reminders to Client's clients on Customer's behalf via SendGrid
- Providing Customer with document management, organization, and search functionality
- Maintaining logs and audit trails for compliance purposes
3.4 Types of Personal Data
- Names and email addresses of Customer's clients (end users of the portal)
- Content of documents uploaded by Customer's clients (which may include identity documents, financial records, health records, legal documents, and other personal data depending on Customer's use case)
- Electronic signature data: signer name, email address, IP address, timestamp
- IP addresses and access logs generated when Customer's clients access the portal
3.5 Categories of Data Subjects
- Customer's clients who upload documents via the Middledoc portal
- Individuals referenced in documents uploaded to the Service
- Individuals who sign documents via the e-signature feature
4. Customer Obligations
Customer represents and warrants that:
- Customer has a valid legal basis under applicable data protection law for collecting and processing End-User Personal Data and for instructing Middledoc to process it
- Customer has provided all required notices to, and obtained all required consents from, Data Subjects whose personal data will be processed through the Service
- Customer's instructions to Middledoc comply with applicable law
- Customer will promptly inform Middledoc if Customer believes any Middledoc instruction or action would violate applicable data protection law
5. Middledoc's Obligations as Processor
Middledoc agrees to:
- Process only on instruction:Process End-User Personal Data only in accordance with Customer's documented instructions (as reflected in these Terms and DPA) and not for any other purpose, except where required by applicable law.
- Confidentiality: Ensure that persons authorized to process End-User Personal Data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality.
- Security: Implement and maintain the technical and organizational security measures described in Section 7 of this DPA.
- Sub-Processor management: Engage Sub-Processors only as described in Section 6 and impose equivalent data protection obligations on them.
- Data Subject rights assistance: Assist Customer in fulfilling its obligations to respond to Data Subject requests as described in Section 9.
- Breach notification: Notify Customer of Security Incidents as described in Section 8.
- DPIA assistance: Assist Customer in ensuring compliance with obligations regarding data protection impact assessments (DPIAs) and prior consultation, taking into account the nature of processing and information available to Middledoc.
- Deletion or return:At Customer's option, delete or return all End-User Personal Data upon termination of the agreement, subject to Section 11.
- Audit cooperation: Make available to Customer all information necessary to demonstrate compliance with GDPR Article 28 obligations and allow for and contribute to audits as described in Section 10.
- Notification of unlawful instructions:Inform Customer promptly if, in Middledoc's reasonable opinion, any instruction from Customer infringes GDPR or applicable data protection law.
6. Sub-Processors
6.1 Authorization
Customer grants Middledoc general written authorization to engage the Sub-Processors listed in the table below. Middledoc will impose data protection obligations on each Sub-Processor equivalent to those imposed on Middledoc by this DPA.
6.2 Approved Sub-Processors
| Sub-Processor | Processing Activity | Data Location |
|---|---|---|
| Cloudflare, Inc. | CDN, DNS, DDoS protection; document object storage (R2) | USA (global edge network); EU (R2 document storage) |
| Render Services, Inc. | Application server hosting, background job processing | USA |
| OpenAI, L.L.C. | AI document classification (when feature is enabled) | USA |
| Anthropic, PBC | AI document classification — alternative provider (when feature is enabled) | USA |
| Twilio Inc. (SendGrid) | Transactional email delivery | USA |
| Paddle.com Market Ltd | Merchant of record — subscription billing (US/international customers) | United Kingdom |
| Paystack | Payment processing (African market customers) | Nigeria |
| Render Services, Inc. (Managed PostgreSQL) | Relational database hosting (structured account and metadata storage) | USA (Ohio) |
6.3 Changes to Sub-Processors
Middledoc will provide Customer with at least 30 days' prior written notice (via email to the Customer's account email or via notification in the platform) before adding or replacing any Sub-Processor. Customer may object to a new Sub-Processor within 14 days of notice on reasonable data protection grounds by emailing [email protected]. If Middledoc cannot accommodate the objection without materially affecting the Service, either party may terminate the agreement with 30 days' written notice without penalty.
7. Security Measures
Middledoc implements and maintains the following technical and organizational security measures to protect End-User Personal Data:
7.1 Encryption
- All data in transit is encrypted using TLS 1.3 or higher
- Documents stored at rest are encrypted using AES-256 on Cloudflare R2
- Database connections use encrypted channels
7.2 Access Controls
- Role-based access control (RBAC) is enforced at both application and API levels
- Access to production systems is restricted to authorized personnel
- Multi-factor authentication is required for production infrastructure access
- Principle of least privilege is applied to all system and employee access
7.3 Data Isolation
- Customer data is logically isolated from other customers' data at the application layer
- All API endpoints enforce ownership checks ensuring users can only access their own organization's data
- Group-based access controls limit team member visibility to assigned clients only
7.4 Infrastructure Security
- Cloudflare WAF (Web Application Firewall) protects against common web vulnerabilities
- DDoS protection is provided at the network edge by Cloudflare
- Regular security audits are performed; findings are remediated according to risk severity
- Software dependencies are monitored for known vulnerabilities
7.5 Organizational Measures
- Personnel with access to personal data are trained on data protection obligations
- Data protection considerations are incorporated into product development processes
- An incident response plan is maintained and tested regularly
8. Security Incident (Data Breach) Notification
8.1 Middledoc will notify Customer without undue delay and in any event within 72 hoursof becoming aware of a Security Incident affecting End-User Personal Data. Notification will be sent to the email address associated with Customer's Middledoc account.
8.2 The notification will include, to the extent then known:
- A description of the nature of the Security Incident including categories and approximate number of Data Subjects and records concerned
- The name and contact details of Middledoc's data protection contact
- The likely consequences of the Security Incident
- Measures taken or proposed to address the Security Incident
8.3 Middledoc may provide initial notification with information available at the time and supplement it as additional information becomes available.
8.4 Customer is responsible for notifying Data Subjects and relevant supervisory authorities as required by applicable law. Middledoc will cooperate reasonably with Customer in connection with such notifications.
9. Data Subject Rights Assistance
9.1 Middledoc provides Customer with the following tools to assist in responding to Data Subject requests:
- Account holders can export all their data (including client data and documents) via Settings > Account > Export Data
- Account holders can delete their accounts and associated data via Settings > Account > Delete Account
- Individual documents can be deleted from the document browser
9.2To the extent Customer cannot fulfill a Data Subject request using the tools above, Customer may request Middledoc's assistance by emailing [email protected]. Middledoc will provide assistance within a commercially reasonable time. Middledoc may charge a fee for assistance beyond the standard tooling where permitted by applicable law.
9.3 Customer is the primary point of contact for Data Subjects whose personal data is processed through the Service. Middledoc will, where it receives a direct Data Subject request, redirect the Data Subject to Customer unless Middledoc is legally required to respond directly.
10. Audit Rights
10.1Middledoc will make available to Customer, upon written request, all information reasonably necessary to demonstrate Middledoc's compliance with its obligations under this DPA, including this DPA itself, Middledoc's security policies, and any relevant third-party certifications or audit reports (under appropriate confidentiality obligations).
10.2Customer may, no more than once per calendar year and with at least 60 days' prior written notice, request an audit of Middledoc's data processing practices relevant to this DPA, conducted by Customer or a mutually agreed third-party auditor under confidentiality obligations. Such audits must be conducted during normal business hours and in a manner that minimizes disruption to Middledoc's operations. Customer bears the costs of such audits unless the audit reveals material non-compliance by Middledoc.
10.3Middledoc may satisfy audit requests by providing relevant third-party audit reports (e.g., SOC 2 Type II reports when available) in lieu of direct site audits where this adequately addresses Customer's concerns.
11. Data Deletion and Return Upon Termination
11.1Upon termination of the agreement between Middledoc and Customer for any reason, Middledoc will, at Customer's election:
- Delete all End-User Personal Data within 30 days of termination, or
- Return End-User Personal Data to Customer in a machine-readable format (JSON and PDF) within 30 days
11.2 Customer must make its election within 30 days of termination by emailing [email protected]. If no election is made within 30 days, Middledoc will delete all End-User Personal Data.
11.3 Notwithstanding the above, Middledoc may retain:
- E-signature audit trail records for 7 years as required for legal enforceability
- Billing and payment records for 7 years as required by accounting and tax law
- Aggregated and anonymized analytics data that does not identify any individual
- Any data Middledoc is required to retain by applicable law
11.4 Middledoc will provide Customer with written confirmation of deletion upon request.
12. International Data Transfers
12.1Middledoc's infrastructure is primarily located in the United States. Processing of End-User Personal Data by Middledoc and its Sub-Processors may involve transfer of personal data from the EEA, UK, or Switzerland to the United States or other countries that may not provide an equivalent level of data protection.
12.2 For such transfers, Middledoc relies on:
- Standard Contractual Clauses (SCCs): This DPA incorporates the Module Two SCCs (controller to processor) as issued by the European Commission on 4 June 2021 (Decision 2021/914/EU), which are hereby incorporated into and form part of this DPA. The SCCs are completed as follows:
- Clause 7 (Docking clause): Not applicable
- Clause 9 (Use of sub-processors): Option 2 — General written authorization
- Clause 11 (Redress): The optional language is not included
- Clause 17 (Governing law): The law of Ireland
- Clause 18 (Choice of forum): The courts of Ireland
- Annex I.A: Customer as data exporter; Skillhanger Limited (trading as Middledoc) as data importer
- Annex I.B: The processing details set out in Section 3 of this DPA
- Annex I.C: The competent supervisory authority for the Customer
- Annex II: The technical and organizational measures set out in Section 7 of this DPA
- UK IDTA: For transfers involving UK personal data, Middledoc will provide a UK International Data Transfer Agreement (IDTA) or addendum upon request.
12.3 Middledoc will ensure that Sub-Processors engaged to process EEA, UK, or Swiss personal data provide equivalent transfer safeguards.
13. Governing Law and Dispute Resolution
This DPA is governed by the law specified in the Middledoc Terms of Service, except that the SCCs incorporated under Section 12 are governed by the law of Ireland as specified therein. Disputes relating to this DPA will be resolved pursuant to the dispute resolution provisions of the Terms of Service.
14. Order of Precedence
In the event of a conflict between this DPA and the Terms of Service with respect to the processing of personal data subject to applicable data protection law, this DPA will prevail. In all other respects, the Terms of Service prevail.
15. Contact
For DPA-related inquiries, countersigned DPA requests, or Sub-Processor objections:
Skillhanger Limited (trading as Middledoc)48a Ogudu, Lagos, Nigeria
RC 1711272
Email: [email protected]