This Data Processing Agreement (“DPA”) forms part of, and is incorporated into, the Filecheck Terms of Service or other written or electronic agreement between the Customer and Print.App ApS governing the Customer’s use of Filecheck (the “Agreement”).
This DPA reflects the parties’ agreement on the processing of Personal Data in connection with the General Data Protection Regulation (Regulation (EU) 2016/679, “GDPR”) and other applicable data protection laws.
In this DPA, Print.App ApS (“Print.App”, “we”, “us”, or “our”), a company registered in the Kingdom of Denmark (CVR: 45469808) with its registered office in Copenhagen, Denmark, is the parent company and owner of Filecheck (“Filecheck”, “filecheck.io”) and acts as the Data Processor. The Customer — the person or company that uses Filecheck or installs one of our products on its store, website, or application — acts as the Data Controller.
Where the Customer is itself acting as a processor on behalf of a third-party controller, the Customer warrants that it is authorized to instruct Print.App as a sub-processor on that controller’s behalf, and references to the Data Controller in this DPA apply accordingly.
Capitalized terms not defined in this DPA have the meaning given to them in the Agreement or in the GDPR. “Personal Data”, “processing”, “data subject”, “controller”, “processor”, and “supervisory authority” have the meanings given to them in the GDPR.
If there is a conflict between this DPA and the Agreement regarding the processing of Personal Data, this DPA prevails.
This DPA defines the terms, conditions, and obligations regarding the processing of personal data (“Personal Data”) that Print.App processes on behalf of the Customer when providing the Filecheck services (the “Services”).
Nature: Print.App will collect, store, and otherwise process Personal Data electronically in order to provide the Services. Filecheck operates as a preflight, validation, and policy layer for file uploads: files submitted through the Customer’s website or application are inspected in real time, optionally repaired or optimized according to the Customer’s configured rules, and delivered onward according to the Customer’s configuration, after which transient processing data is purged.
Purpose: To offer and maintain file inspection, preflight, validation, remediation, and soft-proofing services; to generate the metadata reports and job records that populate the Customer’s dashboard and support usage-based billing; to troubleshoot issues; and to provide related customer support.
Duration: Processing lasts for the duration of the Agreement and for as long as Print.App provides the Services to the Customer, unless otherwise agreed in writing or required by applicable law. Transient file content is processed only for the time required to complete a job (see Section 9).
Types of Personal Data: (a) Customer account and billing data, such as the name, email address, and company name of the Customer’s authorized users, and billing details processed via our payment provider; and (b) any Personal Data contained within the files, designs, documents, images, PDFs, webhook payloads, or other content that the Customer or its Users submit to the Services for inspection or processing. Because the Customer controls what content is uploaded, such content may include names, contact details, images depicting individuals, identity or compliance documents, and other Personal Data determined by the Customer’s own use case.
Categories of Data Subjects: The Customer’s authorized personnel and account users; and the Customer’s own end users, customers, or any other individuals (“Users”) whose Personal Data the Customer or its Users submit through the Services.
The details of the processing are further described in Annex 1.
Print.App processes Personal Data strictly to provide the Services and will follow the Customer’s documented instructions, including with regard to transfers of Personal Data, unless required to do otherwise by Union or Member State law to which Print.App is subject. The Agreement, this DPA, and the Customer’s configuration and use of the Services (including the rules, widgets, API calls, and webhooks the Customer configures) constitute the Customer’s complete and documented instructions to Print.App. If Print.App is required by law to process Personal Data beyond these instructions, it will inform the Customer of that legal requirement before processing, unless the law prohibits such notice on important grounds of public interest.
Print.App may process Personal Data as necessary to offer and maintain the Services, troubleshoot issues, and provide customer support. Print.App will not process Personal Data for its own purposes, and will not sell Personal Data or use the Personal Data it processes on behalf of the Customer to independently contact or market to the Customer’s Users.
Taking into account the nature of processing and the information available to it, Print.App shall provide reasonable assistance to the Customer in carrying out Data Protection Impact Assessments (DPIAs) and any related prior consultations with supervisory authorities, where required under Articles 35 and 36 of the GDPR.
Print.App implements and maintains appropriate technical and organizational measures to protect Personal Data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to Personal Data, taking into account the state of the art, the costs of implementation, and the nature, scope, context, and purposes of processing, as well as the risk to the rights and freedoms of natural persons. A summary of these measures is set out in Annex 2.
Print.App ensures that all persons authorized to process Personal Data have committed themselves to confidentiality (for example, through employment contracts or separate confidentiality agreements) or are under an appropriate statutory obligation of confidentiality, and that access to Personal Data is limited to personnel who need it to provide the Services.
Print.App continually assesses the risks to Personal Data, updates its security measures, and regularly reviews its security controls to ensure a level of security appropriate to the risk.
The Customer grants Print.App a general written authorization to engage other processors (“Sub-processors”) to support the provision of the Services. A current list of Sub-processors is set out in Annex 3. Print.App shall not engage a Sub-processor to process Personal Data on behalf of the Customer other than in accordance with this Section.
Print.App will provide the Customer with reasonable prior notice of the intended addition or replacement of any Sub-processor, giving the Customer the opportunity to object.
If the Customer has a legitimate, data-protection-related objection to a new Sub-processor, the parties will discuss the objection in good faith with a view to resolving it. If the parties cannot reach a resolution, the Customer may, as its sole remedy, terminate the affected Services.
Where Print.App engages a Sub-processor, it will do so by way of a written contract that imposes data protection obligations that are substantially equivalent to those set out in this DPA. Print.App remains fully liable to the Customer for the performance of each Sub-processor’s obligations.
Taking into account the nature of the processing, Print.App will assist the Customer by appropriate technical and organizational measures, insofar as this is possible, in fulfilling the Customer’s obligation to respond to requests from data subjects exercising their rights under Chapter III of the GDPR (including rights of access, rectification, erasure, restriction, portability, and objection). If Print.App receives a request directly from a data subject relating to the Customer’s Personal Data, it will, unless legally prohibited, promptly notify the Customer and will not respond to the request itself except on the Customer’s documented instructions.
Print.App shall notify the Customer without undue delay after becoming aware of a personal data breach affecting Personal Data processed under this DPA, in accordance with Article 33 of the GDPR. The notification will include, to the extent available, the nature of the breach, the categories and approximate number of data subjects and records concerned, the likely consequences, and the measures taken or proposed to address the breach.
Print.App shall cooperate with the Customer and take such reasonable steps as are directed by the Customer to assist in the investigation, mitigation, and remediation of the breach.
Print.App will maintain records of its processing activities and data protection practices sufficient to demonstrate compliance with its obligations under this DPA and Article 28 of the GDPR, and will make such information available to the Customer upon reasonable request.
Upon reasonable prior written notice, and no more than once per year (unless required by a supervisory authority or following a personal data breach), the Customer or an independent auditor appointed by the Customer may conduct an audit, during regular business hours and subject to appropriate confidentiality obligations, to verify Print.App’s compliance with this DPA. Print.App may satisfy an audit request by providing relevant certifications, third-party audit reports, or written responses to a reasonable security questionnaire where these adequately demonstrate compliance.
Print.App’s production infrastructure for the Services is hosted on Amazon Web Services (AWS) within the European Union, with primary processing in the AWS Europe (Frankfurt, Germany) region and backups in the AWS Europe (Stockholm, Sweden) region. In the ordinary course of providing the Services, Customer file content and report data are processed and stored within the EU/EEA.
Where the provision of the Services requires the transfer of Personal Data to a Sub-processor or other recipient outside the European Economic Area (EEA) — for example, in connection with payment processing — Print.App will ensure that such transfers are subject to appropriate safeguards in accordance with Chapter V of the GDPR, such as an adequacy decision, the European Commission’s Standard Contractual Clauses, or another legally recognized transfer mechanism.
Print.App will keep records of such transfers and, upon reasonable request, make them available to the Customer.
Filecheck is designed to minimize retention. File content submitted for inspection is processed transiently: once a job is completed, temporary scratch files and transient processing data created during inspection, extraction, conversion, or rendering are purged from Print.App’s processing environment. Print.App generally retains only the structural metadata reports (such as page count, file size, DPI, and pass/fail status) and job records required to populate the Customer’s dashboard and support billing, together with any webhook payloads the Customer has configured to be stored.
Following termination or expiry of the Services, or upon the Customer’s earlier written request, Print.App will, at the Customer’s choice, either return or securely delete all remaining Personal Data processed on the Customer’s behalf within thirty (30) days, unless applicable law requires continued retention.
Where Print.App is required by Union or Member State law to retain Personal Data, it will store such data only to the extent and for the period required by that law, and will keep it protected in accordance with this DPA.
Each party’s liability arising out of or related to this DPA is subject to the limitations and exclusions of liability set out in the Agreement.
Except as amended by this DPA, the Agreement remains in full force and effect. In the event of any conflict between this DPA and the Agreement in relation to the processing of Personal Data, this DPA prevails.
This DPA shall be governed by and construed in accordance with the laws of the Kingdom of Denmark, without regard to its conflict of law principles, consistent with the Filecheck Terms of Service. Any dispute arising out of or in connection with this DPA shall be subject to the exclusive jurisdiction of the courts of the Kingdom of Denmark, without prejudice to any mandatory rights a data subject or supervisory authority may have under the GDPR.
Questions about this DPA, requests to execute a countersigned copy, and data protection enquiries may be sent to Print.App ApS at filecheck@print.app.
Data Exporter / Data Controller: The Customer, as identified in the Agreement.
Data Importer / Data Processor: Print.App ApS (CVR: 45469808), Copenhagen, Denmark, owner and operator of Filecheck.
Subject matter of the processing: Provision of the Filecheck file preflight, validation, remediation, and soft-proofing Services.
Nature and purpose of the processing: Real-time inspection, validation, optional remediation/optimization, packaging, and soft-proofing of files submitted through the Services; generation of metadata reports and job records; provision of the dashboard, API, and webhooks; support and billing.
Duration of the processing: For the term of the Agreement, plus the retention and deletion periods described in Section 9.
Categories of data subjects:
Categories of Personal Data:
Special categories of data: Print.App does not require or request special-category data. The Customer is responsible for determining whether its use case (for example, identity or compliance document workflows) involves special categories of Personal Data and, if so, for ensuring an appropriate legal basis and any additional safeguards. Any such data is processed transiently as described in Section 9.
Frequency of the transfer/processing: Continuous, for the duration of the Agreement, on the basis of files and requests submitted by the Customer and its Users.
Print.App maintains technical and organizational measures including, without limitation:
Print.App engages the following Sub-processors to process Personal Data in connection with the Services:
| Sub-processor | Purpose | Location |
|---|---|---|
| Amazon Web Services EMEA SARL (AWS) | Cloud hosting, serverless compute, storage, CDN, and backups | EU (Frankfurt, Germany; Stockholm, Sweden) |
| Stripe, Inc. / Stripe Payments Europe, Ltd. | Subscription and credit billing, payment processing, and fraud prevention | EU / United States (transfers subject to Standard Contractual Clauses) |
Print.App will maintain an up-to-date list of Sub-processors and provide reasonable prior notice of any intended additions or replacements in accordance with Section 4.