Skip to main content
Legal

Data Processing Agreement (DPA)

Effective: Jun 14, 2026 Updated: Jun 14, 2026

1. Overview

This Data Processing Agreement (“DPA”) is entered into between ChromaParse (the “Processor”) and the enterprise customer (the “Controller”) to ensure compliance with GDPR, PIPL, and other applicable data protection laws.

This DPA supplements the Terms of Service and applies to enterprise customers, Team plan customers, and on-premise customers. If this DPA conflicts with the Terms, this DPA prevails.

2. Scope and purpose

The Processor processes the following personal data on the Controller’s instructions:

  • Controller user account information (name, email, organization)
  • Personal data potentially contained in PDF files uploaded by Controller users
  • Usage logs of Controller users

Purpose: solely to provide ChromaParse services to the Controller, including PDF data extraction, user management, credit billing, and security monitoring.

Duration: ongoing during the contract term. After termination, data is deleted or returned per the Controller’s instruction, except where retention is legally required.

3. Processor obligations

  • Process personal data only on the Controller’s written instructions
  • Ensure personnel authorized to process personal data are committed to confidentiality
  • Implement appropriate technical and organizational measures to ensure data security
  • Assist the Controller in fulfilling its obligations under GDPR/PIPL, including data subject rights requests
  • On contract termination, delete or return data per the Controller’s instructions

4. Security measures

Technical: TLS 1.3 in transit, AES-256 at rest, auto-deletion (7-day default), per-tenant key isolation, role-based access control (RBAC), audit logs for all data access, container-sandboxed processing workers, network segmentation, quarterly third-party penetration testing.

Organizational: employee data protection training, principle of least privilege, periodic security reviews, designated data protection responsible person.

5. Subprocessors

The Processor uses the following subprocessors:

SubprocessorPurposeLocation
AliyunServer hosting and data storageChina (cn-shanghai)
AWSInternational customer servers (optional)Singapore (ap-southeast-1)
SendGridEmail notificationsUnited States
SentryError monitoring (excludes uploaded file content)United States
WeChat Pay / AlipayPaid transaction processingChina

The Processor will give the Controller 30 days advance notice of replacement or addition of subprocessors, with a reasonable opportunity to object.

6. Cross-border data transfer

Where cross-border transfer is involved:

  • Within China: complies with the Data Security Law and Personal Information Protection Law
  • Cross-border: uses EU Standard Contractual Clauses (SCCs) or explicit Controller consent

7. Data subject rights

The Processor will assist the Controller in responding to data subject rights requests, including: access, rectification, deletion, restriction of processing, data portability, and objection to processing. Response timelines meet GDPR (30 days) and PIPL (15 business days).

8. Breach notification

In the event of a data breach:

  • The Processor will notify the Controller within 24 hours of discovery
  • Provide details of the nature of the incident, types of data involved, potential consequences, and measures taken
  • Assist the Controller in notifying data subjects and supervisory authorities

9. Audit rights

The Controller has the right to:

  • Conduct one written audit per year
  • Conduct additional audits after material changes or security incidents
  • Obtain the latest security certification reports (where applicable)

Audits require 30 days advance notice, occur during business hours, and must not unreasonably impact the Processor’s operations.

10. Termination and data deletion

After contract termination:

  • The Controller may export all data within 30 days
  • After 30 days, the Processor will permanently delete all customer data, except where retention is legally required
  • After deletion, the Processor will provide written confirmation to the Controller

11. Governing law and disputes

This DPA is governed by the laws of the People’s Republic of China. Where EU data subjects are involved, GDPR applies. Disputes are resolved through friendly negotiation; failing that, by the court with jurisdiction.

12. Contact

DPA requests and execution: [email protected] Data Protection Officer (DPO): [email protected]


This DPA is a template. The version actually executed may be adjusted based on negotiation. Enterprise customers may request custom terms.