Data Processing Agreement (DPA)

An appendix to Contractsign's terms and conditions. It governs the processing of personal data on behalf of the Customer under GDPR Article 28.

Data Processing Agreement (DPA)

Appendix to Contractsign's terms and conditions

Last updated: August 1, 2026

This Data Processing Agreement ("DPA") governs Contractsign's processing of personal data on behalf of the Customer under Article 28 of Regulation (EU) 2016/679 of the European Parliament and of the Council ("GDPR").

1. Parties and roles

This DPA is entered into between:

The Customer (data controller)

and

Contractsign (data processor)

Contractsign processes personal data solely on behalf of the Customer in connection with providing the Contractsign platform.

2. Nature and purpose of the processing

2.1 Purpose

Processing is carried out for the purposes of:

  • Uploading, storing and managing documents
  • Electronic signing
  • Logging and documenting signing processes
  • Technical operation and security

2.2 Nature of the processing

Processing may include:

  • Collection
  • Recording
  • Structuring
  • Storage
  • Adaptation
  • Transfer
  • Erasure

3. Categories of data subjects

The processing may cover the following categories:

  • The Customer's employees
  • Signers
  • Contracting parties
  • Representatives
  • Other people named in documents

4. Categories of personal data

The processing may cover:

  • Name
  • Email
  • Phone number
  • Job title/company
  • IP address
  • Signature metadata
  • Document content uploaded by the Customer

Contractsign has no control over the content of the documents the Customer uploads.

5. The Customer's obligations

The Customer represents and warrants that:

  • The Customer has a lawful basis for processing
  • The Customer meets its information obligations
  • The processing is lawful
  • Instructions to Contractsign comply with GDPR
  • The Customer is solely responsible for document content.

6. Contractsign's obligations

Contractsign undertakes to:

  • Process personal data only on documented instructions
  • Ensure confidentiality
  • Implement appropriate technical and organisational measures
  • Assist the Customer with data subject requests
  • Notify the Customer of personal data breaches without undue delay

7. Technical and organisational security measures

Contractsign has implemented:

  • Encryption in transit (TLS)
  • Encrypted hosting infrastructure
  • Access restrictions
  • Role-based access
  • Logging
  • Backup and redundancy
  • Security monitoring

8. Sub-processors

The Customer gives general prior authorisation for Contractsign to use sub-processors.

Contractsign uses, among others:

  • Cloudflare R2 (EU) — file and document storage
  • Laravel Cloud / Amazon Web Services (EU) — hosting and operations
  • Amazon Web Services Textract (EU) — text recognition (OCR)
  • OpenAI — AI analysis of documents
  • Aspose Words Cloud — document generation and conversion
  • Mailgun (EU) — email delivery
  • sms.dk — SMS delivery
  • Cloudflare — CDN, security and PDF generation
  • Sentry — technical error monitoring

Contractsign ensures that sub-processors are bound by equivalent data protection obligations.

The list in force at any given time is set out in the privacy policy at contractsign.io/privacy. Changes to the list are announced at least 30 days in advance by email or via the platform, after which the Customer may object to the change.

9. Transfers to third countries

If personal data is transferred outside the EU/EEA, Contractsign ensures an adequate level of protection through:

  • The European Commission's Standard Contractual Clauses (SCCs)
  • The EU-US Data Privacy Framework (where relevant)
  • Supplementary security measures

10. Security breaches

In the event of a personal data breach:

  • Contractsign notifies the Customer without undue delay
  • Provides the information relevant to assessing the risk
  • Assists with documentation

11. Assistance to the Customer

Contractsign provides reasonable assistance to the Customer with:

  • Subject access requests
  • Erasure
  • Data portability
  • Data protection impact assessments (DPIAs)
  • Liaising with supervisory authorities

Assistance may be invoiced on a time-spent basis.

12. Termination and erasure

On termination of the agreement:

  • Contractsign deletes or returns personal data at the Customer's choice
  • May retain backups for a limited period
  • Retains data where required by law

13. Review and audit

The Customer may request documentation of security measures.

Any audit:

  • Must be announced with reasonable notice
  • Must not disrupt operations
  • Is carried out at the Customer's expense

14. Limitation of liability

Contractsign's liability under this DPA is subject to the limitation of liability in the terms and conditions.

Contractsign is not liable for:

  • Unlawful instructions
  • Document content
  • The Customer's failure to comply with GDPR

15. Duration

This DPA applies for as long as Contractsign processes personal data on behalf of the Customer.