Data Processing Agreement
Last updated: July 2026
This Data Processing Agreement ("DPA") forms part of, and is incorporated into, the agreement between the customer using Structurify.ai ("Controller") and Discovery AI Limited, a company registered in England and Wales (Company No. 17032815), registered office 167-169 Great Portland Street, London, England, W1W 5PF, operating together with its Indian affiliate Redscvry Technology Private Limited ("Processor", "DscvryAI", "we", "us"). It governs the processing of personal data by the Processor on behalf of the Controller in connection with the Structurify.ai service, and reflects the requirements of Article 28 of the GDPR.
Customers may request a countersigned copy of this DPA for their organization by contacting privacy@dscvryai.com. Where this DPA is incorporated by reference into a signed master service agreement or statement of work, the terms of that agreement govern precedence.
1. Subject Matter and Duration
This DPA applies to the processing of personal data carried out by the Processor on behalf of the Controller for the duration of the underlying service agreement, plus any statutory retention period thereafter.
2. Nature and Purpose of Processing
The Processor provides AI-assisted document data extraction services as described in the service agreement. Personal data is processed solely to provide, maintain, and support the Structurify.ai service, and for no other purpose.
3. Categories of Data Subjects and Personal Data
- Data subjects: the Controller's employees, customers, vendors, or other individuals whose personal data the Controller submits to the service.
- Categories of personal data: as specified by the Controller in the service agreement; may include names, contact details, identification numbers, and other personal data contained within documents submitted to the service.
4. Processor Obligations
The Processor shall:
- Process personal data only on documented instructions from the Controller, including with regard to transfers of personal data to a third country, unless required to do otherwise by applicable law.
- Ensure that persons authorized to process personal data are subject to appropriate confidentiality obligations.
- Implement appropriate technical and organizational measures to ensure a level of security appropriate to the risk (see Section 6).
- Respect the conditions for engaging sub-processors set out in Section 5, and flow down equivalent data protection obligations to any sub-processor.
- Taking into account the nature of the processing, assist the Controller by appropriate technical and organizational measures for the fulfilment of the Controller's obligations to respond to data subject rights requests (GDPR Articles 12-22).
- Assist the Controller in ensuring compliance with security, breach notification, data protection impact assessment, and prior consultation obligations, taking into account the nature of processing and information available to the Processor.
- At the Controller's choice, delete or return all personal data to the Controller after the end of the provision of services, and delete existing copies unless applicable law requires storage.
- Make available to the Controller all information necessary to demonstrate compliance with Article 28 obligations, and allow for and contribute to audits, including inspections, conducted by the Controller or an auditor mandated by the Controller.
5. Sub-processors
The Controller provides general authorization for the Processor to engage sub-processors to support delivery of the service. The Processor will notify the Controller of any intended changes concerning the addition or replacement of sub-processors, giving the Controller the opportunity to object on reasonable data protection grounds.
| Sub-processor | Location | Purpose | Transfer safeguard |
|---|---|---|---|
| Microsoft Azure / Microsoft 365 | United States / EU | Cloud infrastructure, email, productivity | Standard Contractual Clauses + Microsoft DPA |
| Cloudflare | United States | Web proxy, CDN, DDoS protection | Standard Contractual Clauses |
| Stripe / PayPal | United States | Payment processing | Standard Contractual Clauses |
An up-to-date sub-processor list is maintained internally and available on request at privacy@dscvryai.com.
6. Security Measures
Taking into account the state of the art, costs of implementation, and the nature, scope, context, and purposes of processing, as well as the risk to data subjects, the Processor implements measures including:
- Encryption of personal data in transit (TLS 1.3) and at rest (AES-256)
- Processing of documents in isolated environments
- Access controls and logging restricting access to personal data on a need-to-know basis
- Regular testing, assessment, and evaluation of the effectiveness of technical and organizational security measures
- A documented incident response and breach notification process
7. International Transfers
Where the Processor or a sub-processor transfers personal data outside the EEA or UK, such transfers are made subject to appropriate safeguards, including the Standard Contractual Clauses approved by the European Commission (Decision 2021/914) and, where applicable, the UK International Data Transfer Addendum, or reliance on an applicable adequacy decision.
8. Personal Data Breach Notification
The Processor shall notify the Controller without undue delay after becoming aware of a personal data breach affecting the Controller's personal data, and shall provide reasonable assistance to the Controller in meeting its own breach notification obligations under GDPR Articles 33 and 34.
9. Audits
The Processor shall make available to the Controller all information reasonably necessary to demonstrate compliance with this DPA, and shall allow for and contribute to audits and inspections conducted by the Controller or an auditor mandated by the Controller, subject to reasonable notice and confidentiality safeguards.
10. Return or Deletion of Data
Upon termination of the underlying service agreement, the Processor shall, at the Controller's choice, delete or return all personal data processed on the Controller's behalf, and delete existing copies, unless applicable law requires the Processor to retain the personal data.
11. Contact
- Email: privacy@dscvryai.com
- EU Representative: James Stevenson, james.stevenson@dscvryai.com
- Registered address (UK): Discovery AI Limited, 167-169 Great Portland Street, London, England, W1W 5PF
- Operational site (India): Redscvry Technology Private Limited, WeWork Krishe Emerald, Kondapur Main Road, Laxmi Cyber City, Hyderabad, Telangana 500081
12. Updates
We may update this DPA from time to time to reflect changes in our processing activities, sub-processors, or applicable law. Material changes will be notified to customers via email or through the service. See also our Privacy Policy and Cookie Policy.