Data Processing Agreement (DPA)
An appendix to Contractsign's terms and conditions. It governs the processing of personal data on behalf of the Customer under GDPR Article 28.
Data Processing Agreement (DPA)
Appendix to Contractsign's terms and conditions
Last updated: August 1, 2026
This Data Processing Agreement ("DPA") governs Contractsign's processing of personal data on behalf of the Customer under Article 28 of Regulation (EU) 2016/679 of the European Parliament and of the Council ("GDPR").
1. Parties and roles
This DPA is entered into between:
The Customer (data controller)
and
Contractsign (data processor)
Contractsign processes personal data solely on behalf of the Customer in connection with providing the Contractsign platform.
2. Nature and purpose of the processing
2.1 Purpose
Processing is carried out for the purposes of:
- Uploading, storing and managing documents
- Electronic signing
- Logging and documenting signing processes
- Technical operation and security
2.2 Nature of the processing
Processing may include:
- Collection
- Recording
- Structuring
- Storage
- Adaptation
- Transfer
- Erasure
3. Categories of data subjects
The processing may cover the following categories:
- The Customer's employees
- Signers
- Contracting parties
- Representatives
- Other people named in documents
4. Categories of personal data
The processing may cover:
- Name
- Phone number
- Job title/company
- IP address
- Signature metadata
- Document content uploaded by the Customer
Contractsign has no control over the content of the documents the Customer uploads.
5. The Customer's obligations
The Customer represents and warrants that:
- The Customer has a lawful basis for processing
- The Customer meets its information obligations
- The processing is lawful
- Instructions to Contractsign comply with GDPR
- The Customer is solely responsible for document content.
6. Contractsign's obligations
Contractsign undertakes to:
- Process personal data only on documented instructions
- Ensure confidentiality
- Implement appropriate technical and organisational measures
- Assist the Customer with data subject requests
- Notify the Customer of personal data breaches without undue delay
7. Technical and organisational security measures
Contractsign has implemented:
- Encryption in transit (TLS)
- Encrypted hosting infrastructure
- Access restrictions
- Role-based access
- Logging
- Backup and redundancy
- Security monitoring
8. Sub-processors
The Customer gives general prior authorisation for Contractsign to use sub-processors.
Contractsign uses, among others:
- Cloudflare R2 (EU) — file and document storage
- Laravel Cloud / Amazon Web Services (EU) — hosting and operations
- Amazon Web Services Textract (EU) — text recognition (OCR)
- OpenAI — AI analysis of documents
- Aspose Words Cloud — document generation and conversion
- Mailgun (EU) — email delivery
- sms.dk — SMS delivery
- Cloudflare — CDN, security and PDF generation
- Sentry — technical error monitoring
Contractsign ensures that sub-processors are bound by equivalent data protection obligations.
The list in force at any given time is set out in the privacy policy at contractsign.io/privacy. Changes to the list are announced at least 30 days in advance by email or via the platform, after which the Customer may object to the change.
9. Transfers to third countries
If personal data is transferred outside the EU/EEA, Contractsign ensures an adequate level of protection through:
- The European Commission's Standard Contractual Clauses (SCCs)
- The EU-US Data Privacy Framework (where relevant)
- Supplementary security measures
10. Security breaches
In the event of a personal data breach:
- Contractsign notifies the Customer without undue delay
- Provides the information relevant to assessing the risk
- Assists with documentation
11. Assistance to the Customer
Contractsign provides reasonable assistance to the Customer with:
- Subject access requests
- Erasure
- Data portability
- Data protection impact assessments (DPIAs)
- Liaising with supervisory authorities
Assistance may be invoiced on a time-spent basis.
12. Termination and erasure
On termination of the agreement:
- Contractsign deletes or returns personal data at the Customer's choice
- May retain backups for a limited period
- Retains data where required by law
13. Review and audit
The Customer may request documentation of security measures.
Any audit:
- Must be announced with reasonable notice
- Must not disrupt operations
- Is carried out at the Customer's expense
14. Limitation of liability
Contractsign's liability under this DPA is subject to the limitation of liability in the terms and conditions.
Contractsign is not liable for:
- Unlawful instructions
- Document content
- The Customer's failure to comply with GDPR
15. Duration
This DPA applies for as long as Contractsign processes personal data on behalf of the Customer.
