GDPR
Full compliance with the EU General Data Protection Regulation
- Data processing in the EU
- Right to deletion
- Transparent processing
DPA, TOMs, sub-processors and certifications — documented, not merely claimed.
Trusted by leading companies worldwide
Proof
Processing on own hardware in the EU Datacenter Spain. The generator produces the DPA and the TOMs — from company data, as a PDF.
All relevant compliance requirements met. SOC 2 Type II and ISO 27001 are active.
Full compliance with the EU General Data Protection Regulation
International standard for Information Security Management
AICPA Service Organization Control for Trust Services Criteria
US standard for health data protection
Payment Card Industry Data Security Standard
German principles for proper record keeping
ISO 27001 and SOC 2 Type II are active. Reports available on request under NDA.
Every document is encrypted at rest and in transit. Key management uses HSMs.
All stored data fully encrypted
TLS 1.3 for all connections
HSM-based key management
Decryption only for authorized processing – with audit trail
Every request is authenticated. Every access is logged. No exceptions.
Multi-factor authentication, SSO, biometric options for every access.
Minimal permissions. Only access to what's really needed.
Permanent verification. No "trusted zones". Every session is validated.
Complete logging of all access. Immutable audit logs.
Isolated network segments. Breach in one area stays isolated.
AI-based anomaly detection. Threats detected in real-time.
The generator in the app produces the DPA and the TOMs — from company data, as a PDF.
The data processing agreement is created in the app — pre-filled with the company data, as a PDF on PaperOffice letterhead.
Technical and organisational measures for exactly the services used in the account.
All devices and sessions of the account at a glance — who accesses what, when and from where.
Per device, the countries from which access is permitted are defined. Regions not approved are blocked.
PaperOffice operates its own EU infrastructure. Only the sub-processors listed below are used externally – fully documented in the DPA sub-processor directory.
DDoS Protection & CDN
Databases, storage, AI models, email servers and backup systems run on our own hardware in the EU Datacenter Spain.
Whitepaper, penetration-test report and certificates are available on request from the Enterprise plan.
DPA, TOMs and the sub-processor register are available in PaperOffice.