GDPR Data Processing Agreement
This Data Processing Agreement (“DPA”) forms part of the agreement between the subscribing organization (“Customer”) and Envisage Companies, LLC (“FileButler,” “we,” “us,” or “our”) for the provision of FileButler client-portal software and related services (the “Services”). It applies where and to the extent FileButler processes Personal Data on Customer's behalf as a processor under the EU General Data Protection Regulation (“GDPR”) or materially similar data-protection law.
1. Roles and relationship
For Customer Content processed through the Services on Customer's instructions, Customer is generally the controller and FileButler is the processor. Where Customer is itself a processor, FileButler may act as a subprocessor to the extent the parties' documented roles require. For FileButler's own account administration, billing, security, fraud prevention and service operations, FileButler may act as an independent controller for the information it needs to perform those functions.
2. Subject matter, duration and nature of processing
The subject matter of processing is the provision of the Services, including secure client folders, document upload and storage, document templates and merge fields, electronic signatures, internal messaging, portal email, reminders, status tracking, user administration, support and related security functions.
Processing continues for the term of the Customer's subscription and for the limited period necessary after termination to complete requested export, deletion, security, legal or other post-termination obligations, in accordance with the applicable FileButler Data Retention Policy and Customer's documented instructions.
3. Types of Personal Data and data subjects
Depending on how Customer uses FileButler, Personal Data may include names, contact information, organization and account information, user identifiers, client and transaction information, documents and their contents, messages, signatures, status and workflow information, audit records, authentication and security information, and technical information associated with use of the Services.
Data subjects may include Customer personnel, clients, customers, vendors, contractors, counterparties, transaction participants and other individuals whose information Customer chooses to place in the Services.
Customer Content may contain special categories of Personal Data or other sensitive information depending on Customer's use. Customer is responsible for determining whether such information may lawfully be processed through the Services and for obtaining any required notices, consents, authorizations or agreements.
4. Documented instructions
FileButler will process Personal Data only on Customer's documented instructions, including instructions arising from Customer's use of the Services, this DPA, the applicable Terms of Service and other written instructions accepted by FileButler, unless processing is required by applicable law. Where law requires processing beyond Customer's instructions, FileButler will inform Customer before processing unless the law prohibits that notice.
5. Confidentiality
Persons authorized by FileButler to process Customer Personal Data will be bound by confidentiality obligations appropriate to their role.
6. Security of processing
FileButler will maintain appropriate technical and organizational measures designed to protect Personal Data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure or unauthorized access. Measures may include encrypted transmission, access controls, role-based permissions, two-step verification, audit logging, restricted administrative access, secure hosting practices, backup and disaster-recovery controls, and personnel confidentiality requirements.
FileButler does not guarantee that any electronic system is completely secure. Customer remains responsible for configuring users, permissions and portal workflows appropriately and for maintaining the security of credentials and devices under its control.
7. Subprocessors
Customer authorizes FileButler to use the subprocessors identified in Annex 1, and any additional subprocessors added in accordance with the notice and objection procedures in this DPA, subject to applicable GDPR requirements. FileButler will impose data-protection obligations on subprocessors that are materially consistent with the obligations applicable to FileButler for the relevant processing.
FileButler may engage additional subprocessors where necessary. Where required by applicable law, FileButler will provide notice of material changes and an opportunity for Customer to object on reasonable data-protection grounds. The current subprocessors listed in Annex 1 are the providers presently used for the processing functions identified there.
Annex 1 – Current subprocessors
| Provider | Function | Processing context |
|---|---|---|
| Backblaze, Inc. | Cloud file storage | Storage of Customer Content and related file data. |
| Stripe, Inc. | Subscription payment processing | Checkout, billing and payment-related information. FileButler does not store full payment card numbers. |
The current FileButler production architecture identifies Backblaze, Inc. and Stripe, Inc. as the subprocessors covered by this Annex. Hostinger provides hosting infrastructure but, as configured for FileButler, does not store Customer Personal Data and is not listed as a subprocessor for Customer Personal Data under this DPA.
8. Assistance with data-subject rights
Taking into account the nature of processing, FileButler will provide reasonable assistance to Customer, where feasible, for requests from data subjects to exercise rights under applicable data-protection law. Customer remains responsible for receiving, verifying and responding to data-subject requests as the controller unless the parties' roles require otherwise.
9. Assistance with security, DPIAs and regulatory obligations
FileButler will provide reasonable cooperation, information and assistance needed for Customer to meet its obligations concerning security, data protection impact assessments and consultations with supervisory authorities, taking into account the nature of processing and information available to FileButler. Assistance that requires substantial bespoke work may be subject to reasonable charges unless the law requires otherwise.
10. Personal data breaches
FileButler will notify Customer without undue delay after becoming aware of a Personal Data breach affecting Customer Personal Data and will provide information reasonably available to FileButler that is necessary for Customer to meet applicable notification obligations. The notice may include, where known, the nature of the incident, affected systems or data, likely consequences, mitigation steps and information about ongoing remediation.
11. International transfers
Customer authorizes international transfers of Personal Data where necessary to provide the Services and where permitted by applicable law. Where a transfer from the EEA to a country not recognized as providing an adequate level of protection requires an appropriate transfer mechanism, the parties will use the mechanism required by applicable law.
For transfers governed by GDPR Article 46, the parties intend to use the European Commission's 2021 Standard Contractual Clauses (“EU SCCs”) where applicable. The relevant module will be selected according to the parties' actual roles, typically Module Two where an EEA controller transfers Personal Data to FileButler as processor, and Module Three where an EEA processor transfers Personal Data to FileButler as subprocessor. The EU SCCs will not be modified except as permitted by their terms.
Where a recipient is covered by a current European Commission adequacy decision, including the EU-U.S. Data Privacy Framework for U.S. organizations that validly participate in that framework and whose participation covers the relevant data, the parties may rely on that adequacy decision for the applicable transfer. FileButler does not represent in this DPA that it or any named vendor participates in the EU-U.S. Data Privacy Framework unless its participation is separately verified.
Where SCCs are used, the parties will complete the applicable annexes, identify the data-exporter and data-importer information, document the applicable processing details and security measures, and implement any supplementary measures required by applicable law following the circumstances of the transfer.
Annex 2 – International transfer framework
| Item | FileButler position |
|---|---|
| Primary transfer mechanism | EU SCCs under Commission Implementing Decision (EU) 2021/914 where a transfer mechanism is required and no adequacy decision applies. |
| Adequacy | Where applicable, an adequacy decision may be used instead of SCCs. The EU-U.S. Data Privacy Framework applies only to U.S. organizations actually participating in the framework for the relevant data. |
| Supplementary measures | Contractual confidentiality, access controls, encryption, least-privilege administration, audit logging, incident response and other measures appropriate to the processing and transfer risk. |
| Government access | FileButler will assess requests from public authorities under applicable law and will use legally available procedures to protect Customer Personal Data. Where legally permitted, FileButler will notify Customer of compelled disclosure. |
| Transfer review | Transfer mechanisms and vendor locations should be reviewed when subprocessors, hosting locations or applicable law changes. |
12. Return and deletion
At Customer's request, FileButler will provide reasonable assistance to return or make available Customer Personal Data in the form supported by the Services. After the end of the applicable retention period, FileButler will delete or anonymize Customer Personal Data unless retention is required by law or necessary for a legitimate legal, security, accounting or dispute-related purpose.
13. Audits and information
FileButler will make available information reasonably necessary to demonstrate compliance with the processor obligations applicable to the Services. Where required by GDPR and subject to reasonable confidentiality, security and operational safeguards, FileButler will permit audits or inspections by Customer or an auditor mandated by Customer. Customer will give reasonable notice and avoid unnecessary disruption to other customers or the Services.
14. Order of precedence
If there is a conflict between this DPA and another FileButler agreement concerning data processing governed by applicable data-protection law, this DPA controls to the extent of the conflict for that processing. The EU SCCs control to the extent required by their own terms when they are incorporated for an international transfer.
15. Changes
FileButler may update this DPA when necessary to reflect changes in the Services, applicable law, regulatory guidance or subprocessors. Material changes will be handled in accordance with the notice and amendment provisions of the parties' agreement.
16. Contact
Data protection inquiries may be sent to info@filebutler.io.