Data Processing Agreement
Last updated 2 September 2026
1. Parties and roles
This agreement applies between DocuScore AI ("Processor") and any customer that uploads personal data belonging to third parties — typically an agency or consultancy acting for applicants ("Controller"). It takes effect automatically when the Controller creates an agency workspace, and supplements our Terms of Service and Privacy Policy.
The Controller determines why applicant data is processed. DocuScore AI processes it only on the Controller's documented instructions, which are given through use of the product.
2. Subject matter and duration
The subject matter is automated readiness analysis of visa application documents. Processing lasts for as long as the Controller maintains an account, plus the retention window below.
3. Categories of data and data subjects
- Data subjects: visa applicants and their dependants, and the Controller's own staff users.
- Identity data: names, dates of birth, nationality, passport and identity document numbers.
- Document data: passports, photographs, financial statements, letters, and other files the Controller uploads.
- Account data: staff email addresses, roles, workspace activity, and case notes.
4. Processor obligations
- Process personal data only on the Controller's instructions, and not for our own purposes.
- Keep personnel with access bound by confidentiality obligations.
- Implement the technical and organisational measures described in section 6.
- Assist the Controller with data subject requests, impact assessments and regulator enquiries.
- Notify the Controller without undue delay after becoming aware of a personal data breach.
- Delete or return personal data at the end of the engagement, subject to legal retention duties.
5. Subprocessors
The Controller authorises the following subprocessors. We will give notice before adding or replacing a subprocessor, and the Controller may object on reasonable data-protection grounds.
- Supabase — database, authentication and encrypted document storage.
- Cloudflare — content delivery, application hosting and network security.
- Paddle — payment processing and merchant of record (billing data only; no applicant documents).
- Resend — transactional and lifecycle email delivery (email addresses and message content only).
- Google Gemini via the Lovable AI Gateway — text analysis of extracted document fields.
6. Security measures
- Document text extraction, optical character recognition and image inspection run in the browser on the user's own device wherever technically possible.
- Stored documents are held in a private bucket, are never publicly listable, and are served only through short-lived signed URLs.
- Row-level security policies isolate every workspace; a user can only reach rows their account or organisation owns.
- Encryption in transit (TLS) and at rest for all stored data.
- Role-based access inside agency workspaces, with an immutable per-case activity log.
- Least-privilege administrative access, reviewed when staffing changes.
7. International transfers
Data may be processed outside the country of origin, including in the European Union and the United States. Transfers out of the EEA or UK rely on the European Commission's Standard Contractual Clauses and the UK Addendum, incorporated into this agreement by reference.
8. Retention and deletion
Uploaded documents can be deleted by the Controller at any time from the case screen, and deletion removes the stored file. Cases and reports are retained while the account is active. On account closure, applicant documents are deleted within 30 days; anonymised aggregate statistics that cannot identify a person may be retained.
9. Audits
On reasonable written request, and no more than once a year unless required by a regulator, we will provide the information needed to demonstrate compliance with this agreement.
10. Contact
Data protection enquiries and signed-copy requests: privacy@getdocuscore.com. We countersign this agreement on request for agency customers.