BridgeDox

Data Processing Agreement (DPA)

Last updated: June 14, 2026 · Operator: MCD United Grup SRL

This Data Processing Agreement applies when you use BridgeDox to process personal data of third parties (your clients, signers or employees). In this context you act as Data Controller and MCD United Grup SRL acts as Data Processor.

1. Subject matter and duration

The Processor processes personal data solely for the purpose of providing the Service under the Terms & Conditions. Processing duration matches the contract duration plus the 30-day export retention period.

2. Nature and purpose of processing

Storage, organization, structuring, consultation, transmission, deletion of documents, client data, electronic signatures and audit logs uploaded or generated by the Controller in the platform.

3. Categories of data and data subjects

Identification data (name, email, phone), contract data (role, company), signature data (IP, timestamp, image), document content. Data subjects: clients, partners, employees and signers designated by the Controller.

4. Processor obligations

Process data only on the Controller's documented instructions.

Ensure confidentiality of authorized personnel.

Implement appropriate technical and organizational measures (Art. 32 GDPR): encryption, access control, RLS, backups, monitoring.

Assist the Controller in responding to data subject requests.

Notify the Controller without undue delay of any security breach (within 48 hours).

On contract termination, delete or return data per the Controller's choice.

5. Sub-processors

The Controller authorizes the following sub-processors: Supabase / Lovable Cloud (hosting, auth, storage), Lovable AI Gateway (AI processing), transactional email providers.

The Processor will give the Controller at least 30 days' notice before adding or replacing a sub-processor, allowing reasonable objection.

6. International transfers

Any transfers outside the EEA rely on the European Commission's Standard Contractual Clauses or other GDPR-compliant mechanisms.

7. Audit

Upon reasonable request and once per year, the Processor will provide the Controller with information necessary to demonstrate compliance with its GDPR obligations.

8. Liability

Liability is governed by the Terms & Conditions and the mandatory provisions of GDPR.

9. Contact

MCD United Grup SRL · [contact@TBD] · DPO: [DPO: TBD]