Pricing Features Resources
Login Register
Pricing Features Resources
Login Register
Back to Legal Hub
100% IN-COUNTRY DB • EU R2 ENCRYPTED BLOBS

Sub-processors Directory

Doccu Statutory Policy • Last Updated: September 2026 • Jurisdiction: Republic of South Africa

Table of Contents

1. Architecture & Residency Overview 2. Approved Sub-processors Table 3. Statutory Security Safeguards 4. Sub-processor Update Notifications

1. Architecture & Data Residency Overview

To deliver a resilient, high-speed, and secure document signing platform, Doccu engages trusted infrastructure sub-processors. All primary customer databases, credentials, and business metadata reside 100% in-country within the Republic of South Africa. Encrypted document binaries are stored within tier-1 enterprise facilities subject to strict adequacy safeguards under POPIA Section 72.

2. Approved Sub-processors Directory

Sub-processor Location Role & Activity Data Transferred Compliance Standard
xneelo (Pty) Ltd South Africa (CPT / JHB) Primary production compute, application servers, and relational PostgreSQL databases. All primary application data and user records. 100% In-Country Residency
Cloudflare, Inc. (Cloudflare R2) European Union Object storage for encrypted PDF document binaries and signed artifacts. Encrypted PDF documents and evidence attachments. POPIA s72(1)(a) Adequacy
PayFast (Pty) Ltd (Network International) South Africa Payment processing gateway, card tokenization, and instant EFT handling. Billing details, transaction IDs, payer names. PCI-DSS Level 1
Resend, Inc. United States / EU Transactional email delivery for signing invitations and completion notices. Signer email addresses, names, and invitation links. SOC 2 Type II / TLS 1.3
Functional Software, Inc. (Sentry) United States Real-time application crash telemetry and error reporting. Application trace errors (sanitized by automated PII scrubber middleware). PII Scrubbing Enforced
Aikido Security BV European Union Automated SAST/DAST application security and vulnerability assessments. Code metadata and security scan telemetry (no customer PII transferred). ISO 27001 / GDPR

3. Statutory Security Safeguards

Doccu conducts thorough security diligence prior to engaging any sub-processor. All data transferred is encrypted using industry-standard protocols (TLS 1.3 in transit and AES-256 at rest), with minimal data sharing principles strictly enforced.

4. Sub-processor Update Notifications

Doccu provides at least thirty (30) days advance written notice to account administrators prior to authorizing any new infrastructure sub-processor to process customer personal information. Customers may object to proposed changes on reasonable data protection grounds by contacting our Information Officer at legal@doccu.co.za.

Legal Hub Terms of Service Privacy Policy Data Processing Agreement Sub-processors
© 2026 Doccu • Republic of South Africa