Legal
Data Processing Agreement
The terms on which Larcade Labs Ltd processes personal data on your behalf when you use doconvoy. This agreement forms part of our Terms of Service.
Last updated: September 2026
This Data Processing Agreement ("DPA") forms part of, and is incorporated into, the Terms of Service between you ("Customer") and Larcade Labs Ltd ("Larcade Labs", "we", "us"), which operates doconvoy. It applies whenever you use doconvoy to process personal data of other people. By using the service you agree to this DPA; no separate signature is required. Where this DPA conflicts with the Terms of Service on the processing of personal data, this DPA prevails.
1. Definitions
"Controller", "processor", "data subject", "personal data", "processing", "sub-processor" and "personal data breach" have the meanings given in the EU General Data Protection Regulation (GDPR) and the UK GDPR ("Data Protection Law"). "Customer Personal Data" means personal data that we process on your behalf through doconvoy.
2. Roles and scope
You are the controller of the Customer Personal Data you collect and share through doconvoy, and we are your processor. You determine the purposes and means of the processing; we process the data only to provide the service and only on your documented instructions. Using the product's features constitutes your instructions.
- Subject-matter and duration — we process Customer Personal Data for as long as your account or subscription is active, and until the data expires or you delete it.
- Nature and purpose — storing, transmitting, encrypting, tokenising, displaying data to the people you authorise, sending the transactional emails the service requires, and erasing data on your instruction.
- Categories of data subjects — your team members, and your end users: the people who view, submit to, or receive your shares and requests.
- Categories of personal data — the content and files you share or collect (encrypted), the email addresses of those end users, and any access metadata you choose to enable.
3. Our obligations as processor
- We process Customer Personal Data only on your documented instructions, including for international transfers, unless required otherwise by law — in which case we will tell you first, where the law permits.
- Our personnel who access Customer Personal Data are bound by confidentiality.
- We implement and maintain the technical and organisational measures in Section 4.
- We assist you, as set out below, in meeting your own obligations under Data Protection Law.
4. Technical and organisational measures
We maintain appropriate technical and organisational measures for the security of Customer Personal Data, including:
- Tenant isolation — each workspace's data is kept separate.
- Client-side end-to-end encryption — content is encrypted in the browser with XChaCha20-Poly1305 before it reaches us; we store only ciphertext and do not hold the keys.
- Crypto-shredding erasure — we erase data by destroying the keys that decrypt it, at the level of a single item, a single person (effective immediately), or an entire workspace.
- Mandatory expiry — every share and request has a required expiry (default 3 months, maximum 1 year); there is no "never expires".
- Role-based access control with least-privilege access for workspace members.
- Data minimisation — inside the application, optional device, location, and IP metadata is off by default; email addresses are encrypted and kept in a separate store, represented elsewhere by a stand-in token, so they can be erased by destroying their key.
- Immutable audit logging of access and key-lifecycle events, exportable by the Customer.
- Encryption in transit over TLS 1.2 or higher.
- EU hosting — application data is hosted with AWS in the EU.
5. Sub-processors
You authorise us to engage the sub-processors listed on our Sub-processors page to process Customer Personal Data. We impose data-protection obligations on each sub-processor no less protective than those in this DPA, and we remain responsible for their performance. We will give you notice before adding or replacing a sub-processor that handles Customer Personal Data, and you may object on reasonable data-protection grounds.
6. Assisting with data-subject requests
Taking into account the nature of the processing, we assist you in responding to data-subject requests. From within the product you can list who accessed what, erase an identified viewer or submitter (effective immediately), and export data for an access or portability request.
Some scope limits apply, and we state them plainly: one-click "forget" covers identified viewers and submitters, not the email recipients of a delivery; it does not reach allow/deny lists, search-index traces, already-stored audit IPs, or already-sent emails. A few email addresses (such as a pending invitation or your billing contact) are stored in readable form because the service needs them to function. These limits are described further in our Privacy Policy.
7. Personal data breach
If we become aware of a personal data breach affecting Customer Personal Data, we will notify you without undue delay and provide the information you reasonably need to meet your own notification obligations under Articles 33 and 34 of the GDPR.
8. Deletion and return
When you delete a share or request, its content is crypto-shredded. When you delete a workspace, then after a short recovery window we crypto-erase every key for that workspace, so its data becomes permanently unrecoverable; we retain only the billing record and the empty workspace shell. On termination of the service, the same deletion mechanisms apply to Customer Personal Data.
9. International transfers
We host application data with AWS in the EU. Where we or a sub-processor transfers Customer Personal Data outside the EU or UK, we rely on an appropriate transfer mechanism under Data Protection Law, such as the European Commission's Standard Contractual Clauses.
10. Audit and information
We make available to you the information reasonably necessary to demonstrate compliance with Article 28 of the GDPR, and allow for and contribute to audits, including inspections, conducted by you or an auditor you mandate, on reasonable prior notice and subject to confidentiality.
11. Contact
For any question about this DPA or to exercise rights in respect of Customer Personal Data, contact privacy@doconvoy.com.