Last updated: May 6, 2026 · Compliant with GDPR Article 28
Who this applies to
This Data Processing Agreement (DPA) applies to customers who process personal data of EU/EEA residents using Credible Documents. By using the Service, you (the "Controller") agree to this DPA with Blakiston Peak LLC (the "Processor"), as required by GDPR Article 28.
| Category | Details |
|---|---|
| Subject matter | Document management, authentication, electronic signing, and verification services |
| Duration | For the term of the Service agreement |
| Nature | Storage, retrieval, transmission, hashing, and blockchain recording of documents |
| Purpose | Providing document authentication and signing services as instructed by the Controller |
| Data types | Names, email addresses, IP addresses, document contents, signing timestamps |
| Data subjects | Controller's customers, employees, contractors, and document signers |
Blakiston Peak LLC (Processor) agrees to:
The Controller agrees to:
| Sub-Processor | Purpose | Location |
|---|---|---|
| Stripe Inc. | Payment processing | United States |
| Hostinger | Email delivery (SMTP) | United States / EU |
The Controller consents to the use of the above sub-processors. The Processor will notify the Controller of any intended changes to sub-processors, giving the Controller the opportunity to object.
Personal data is currently processed and stored in the United States. Transfers from the EU/EEA to the US are made on the basis of Standard Contractual Clauses (SCCs) as adopted by the European Commission. By accepting this DPA, you agree to these transfer mechanisms.
We are working toward EU data residency as a future product milestone, which will allow EU customers to keep their data within the EU.
In the event of a personal data breach, the Processor will notify the Controller without undue delay and no later than 72 hours after becoming aware of the breach, consistent with GDPR Article 33 requirements. Notification will include: nature of the breach, categories and approximate number of data subjects affected, likely consequences, and measures taken or proposed.
The Processor will assist the Controller in responding to data subject rights requests including: access, rectification, erasure, portability, restriction, and objection. Submit requests to [email protected]. We will respond within 5 business days.
The Controller has the right to audit the Processor's compliance with this DPA, subject to reasonable notice (minimum 30 days) and confidentiality obligations. Audits may be conducted by the Controller or a qualified third-party auditor appointed by the Controller.
This DPA remains in effect for the duration of the Service agreement. Upon termination, the Processor will delete or return all personal data within 30 days, except where retention is required by law (e.g., signed document audit trails — 7 years).
This DPA is governed by the laws of the State of Florida, United States, without prejudice to the rights of EU data subjects under GDPR.
For enterprise customers requiring a countersigned DPA document, please contact us. We can provide a signed PDF within 2 business days.
Request Signed DPA →Blakiston Peak LLC — Data Controller & Processor
13459 Romford Ave, Port Charlotte, FL 33981, United States
[email protected]