BridgeDox
Data Processing Agreement (DPA)
Last updated: June 14, 2026 · Operator: MCD United Grup SRL
This Data Processing Agreement applies when you use BridgeDox to process personal data of third parties (your clients, signers or employees). In this context you act as Data Controller and MCD United Grup SRL acts as Data Processor.
1. Subject matter and duration
The Processor processes personal data solely for the purpose of providing the Service under the Terms & Conditions. Processing duration matches the contract duration plus the 30-day export retention period.
2. Nature and purpose of processing
Storage, organization, structuring, consultation, transmission, deletion of documents, client data, electronic signatures and audit logs uploaded or generated by the Controller in the platform.
3. Categories of data and data subjects
Identification data (name, email, phone), contract data (role, company), signature data (IP, timestamp, image), document content. Data subjects: clients, partners, employees and signers designated by the Controller.
4. Processor obligations
Process data only on the Controller's documented instructions.
Ensure confidentiality of authorized personnel.
Implement appropriate technical and organizational measures (Art. 32 GDPR): encryption, access control, RLS, backups, monitoring.
Assist the Controller in responding to data subject requests.
Notify the Controller without undue delay of any security breach (within 48 hours).
On contract termination, delete or return data per the Controller's choice.
5. Sub-processors
The Controller authorizes the following sub-processors: Supabase / Lovable Cloud (hosting, auth, storage), Lovable AI Gateway (AI processing), transactional email providers.
The Processor will give the Controller at least 30 days' notice before adding or replacing a sub-processor, allowing reasonable objection.
6. International transfers
Any transfers outside the EEA rely on the European Commission's Standard Contractual Clauses or other GDPR-compliant mechanisms.
7. Audit
Upon reasonable request and once per year, the Processor will provide the Controller with information necessary to demonstrate compliance with its GDPR obligations.
8. Liability
Liability is governed by the Terms & Conditions and the mandatory provisions of GDPR.
9. Contact
MCD United Grup SRL · [contact@TBD] · DPO: [DPO: TBD]