Data Processing Agreement

Last updated: May 6, 2026 · Compliant with GDPR Article 28

Who this applies to

This Data Processing Agreement (DPA) applies to customers who process personal data of EU/EEA residents using Credible Documents. By using the Service, you (the "Controller") agree to this DPA with Blakiston Peak LLC (the "Processor"), as required by GDPR Article 28.

1. Definitions

2. Subject Matter and Nature of Processing

CategoryDetails
Subject matterDocument management, authentication, electronic signing, and verification services
DurationFor the term of the Service agreement
NatureStorage, retrieval, transmission, hashing, and blockchain recording of documents
PurposeProviding document authentication and signing services as instructed by the Controller
Data typesNames, email addresses, IP addresses, document contents, signing timestamps
Data subjectsController's customers, employees, contractors, and document signers

3. Processor Obligations

Blakiston Peak LLC (Processor) agrees to:

4. Controller Obligations

The Controller agrees to:

5. Technical and Organizational Security Measures

Implemented Safeguards

6. Sub-Processors

Sub-ProcessorPurposeLocation
Stripe Inc.Payment processingUnited States
HostingerEmail delivery (SMTP)United States / EU

The Controller consents to the use of the above sub-processors. The Processor will notify the Controller of any intended changes to sub-processors, giving the Controller the opportunity to object.

7. International Data Transfers

Personal data is currently processed and stored in the United States. Transfers from the EU/EEA to the US are made on the basis of Standard Contractual Clauses (SCCs) as adopted by the European Commission. By accepting this DPA, you agree to these transfer mechanisms.

We are working toward EU data residency as a future product milestone, which will allow EU customers to keep their data within the EU.

8. Data Breach Notification

In the event of a personal data breach, the Processor will notify the Controller without undue delay and no later than 72 hours after becoming aware of the breach, consistent with GDPR Article 33 requirements. Notification will include: nature of the breach, categories and approximate number of data subjects affected, likely consequences, and measures taken or proposed.

9. Data Subject Rights

The Processor will assist the Controller in responding to data subject rights requests including: access, rectification, erasure, portability, restriction, and objection. Submit requests to [email protected]. We will respond within 5 business days.

10. Audit Rights

The Controller has the right to audit the Processor's compliance with this DPA, subject to reasonable notice (minimum 30 days) and confidentiality obligations. Audits may be conducted by the Controller or a qualified third-party auditor appointed by the Controller.

11. Term and Termination

This DPA remains in effect for the duration of the Service agreement. Upon termination, the Processor will delete or return all personal data within 30 days, except where retention is required by law (e.g., signed document audit trails — 7 years).

12. Governing Law

This DPA is governed by the laws of the State of Florida, United States, without prejudice to the rights of EU data subjects under GDPR.

Need a signed DPA?

For enterprise customers requiring a countersigned DPA document, please contact us. We can provide a signed PDF within 2 business days.

Request Signed DPA →

13. Contact

Blakiston Peak LLC — Data Controller & Processor
13459 Romford Ave, Port Charlotte, FL 33981, United States
[email protected]