Legal document
Data Processing Agreement
Terms governing ParseForMe as a data processor on behalf of business customers.
Last updated 1 August 2026
1. Roles of the parties
Where you use ParseForMe to process personal data contained in documents you upload, you are the data controller and ParseForMe is the data processor acting on your instructions. This DPA forms part of the Terms of Service.
2. Scope and purpose of processing
We process the personal data in your uploaded documents only to provide the Service — to extract, let you review, and export structured data — and for no other purpose. The subject matter is the documents you choose to upload; the duration is the term of your use plus the retention period below.
3. Sub-processors
We use Mistral AI (document parsing), Paddle (Merchant-of-Record billing), Hetzner (EU hosting), Cloudflare (network layer), and Namecheap (email hosting) as sub-processors. Of these, only Mistral receives document contents; Namecheap sees only the recipient email address needed to deliver an account notification.
Where you connect your own Google account, we transmit extracted rows to the Google Sheet you nominate. This happens only on your instruction, for exports you start, and Google acts under your own relationship with them rather than as our sub-processor.
We impose data-protection obligations on each sub-processor and give reasonable notice before adding a new one.
4. Security measures
We apply database-level tenant isolation (row-level security), a credential-less document processor, encryption in transit and at rest, and restricted, logged access. Raw uploads are deleted at ingest.
5. Data subject requests
We assist you in responding to data subject access, correction, and deletion requests through the app’s export and deletion features, and by acting on your documented instructions where the app does not directly provide for a request.
6. International transfers
Processing and storage take place in the EU. The processor is established in Pakistan and administers the Service from there, so personal data is accessible from outside the EEA; the data itself is not moved out of the EU, and no sub-processor outside the EEA receives document contents.
Any transfer outside the EEA to a separate recipient (for example, payment data handled by Paddle) is covered by an appropriate safeguard such as Standard Contractual Clauses or an adequacy decision.
7. Term and termination
This DPA lasts as long as we process personal data on your behalf. On termination, or on your request, we delete the personal data in your workspace in the ordinary course (extracted data and exports after 90 days, or sooner on deletion; raw uploads are already deleted at ingest).