Data Processing Addendum
Effective July 14, 2026
This Data Processing Addendum (“DPA”) supplements the SignedBy Terms of Service between the Customer and SPRK10 B.V., a company incorporated in the Netherlands (“SignedBy”), and applies where SignedBy processes personal data on behalf of a customer (“Customer”) in the course of providing the service — for example, the names and email addresses of Signers a Customer invites to sign a document.
Because SignedBy is established in the Netherlands, this DPA is intended to meet the requirements of Article 28 of the GDPR.
1. Roles of the parties
For personal data submitted to SignedBy by or through a Customer's use of the service (including data about that Customer's Signers), the Customer is the controller and SignedBy is the processor within the meaning of the GDPR (or “business” and “service provider,” respectively, under other applicable law). SignedBy processes such data only on the Customer's documented instructions, as reflected in this DPA and the Customer's configuration and use of the service.
Notwithstanding the foregoing, to the extent SignedBy retains audit-trail records after closure of the Customer's account for its own legal-defensibility, evidentiary, and compliance purposes, SignedBy acts as an independent controller with respect to those retained records and processes them under its own responsibility in accordance with applicable law.
As controller of its recipients' personal data, the Customer is responsible for complying with applicable data protection law in respect of the documents it sends, including providing recipients with any required privacy information and informing them, where required, about the audit-trail and engagement tracking involved in the signing process (such as open notifications and, on paid plans, per-page engagement data).
2. Scope and nature of processing
SignedBy processes personal data to: render and store uploaded documents; capture field values and signatures entered by Signers; route signing requests by email; record the audit trail (timestamps, IP addresses, user agent strings, and document hashes) needed for a legally defensible electronic signature; generate the final signed PDF and certificate of completion; and, for Customers using optional AI-assisted features, send relevant document text to an AI sub-processor for field-suggestion, drafting, or summarization — Mistral AI. Processing lasts for the duration of the Customer's use of the service and any applicable retention period described in our Privacy Policy.
3. Sub-processors
SignedBy uses the following sub-processors to provide the service:
- Supabase — database hosting and authentication
- Cloudflare, Inc. (R2) — document file storage
- Resend — transactional email delivery
- Mistral AI — AI processing for optional field-suggestion, document-drafting, and summary features
- Stripe, Inc. — payment processing for subscriptions
- Vercel Inc. — application hosting
We will provide reasonable advance notice before adding or replacing a sub-processor that processes personal data covered by this DPA, so the Customer can object on reasonable grounds. Each sub-processor is bound by confidentiality and data-protection obligations at least as protective as this DPA. Where a sub-processor is located outside the European Economic Area, SignedBy relies on appropriate transfer safeguards recognized under GDPR, such as the European Commission's Standard Contractual Clauses.
Where personal data covered by this DPA is transferred to, or accessible by, a sub-processor incorporated in the United States (including Supabase, Cloudflare, Resend, Stripe, and Vercel), the Standard Contractual Clauses adopted by the European Commission in Commission Implementing Decision (EU) 2021/914 of 4 June 2021 (the “2021 SCCs”), including the module applicable to the relevant controller-to-processor or processor-to-processor transfer, are hereby incorporated into this DPA by reference and apply as if set out in full. In the event of any conflict between the 2021 SCCs and the other terms of this DPA or the Terms of Service, the 2021 SCCs will prevail with respect to the transfers they govern.
4. SignedBy's obligations
SignedBy will:
- Process personal data only on the Customer's documented instructions;
- Ensure personnel with access to personal data are subject to confidentiality obligations;
- Implement appropriate technical and organizational security measures, including encryption in transit and at rest;
- Assist the Customer, to the extent reasonably possible, in responding to data subject requests (access, correction, deletion) relating to data the Customer controls, and, where SignedBy receives such a request directly from a data subject, promptly notify the Customer and not respond to the request itself except on the Customer's documented instructions; and
- Notify the Customer of any personal data breach affecting the Customer's data without undue delay, and in any event no later than 48 hours after becoming aware of it, providing at least the nature of the breach, the categories and approximate number of data subjects and records affected, the likely consequences of the breach, the measures taken or proposed to address it, and a contact point from whom further information can be obtained.
5. Deletion or return of data
On termination of the Customer's account, SignedBy will, at the Customer's election (made in writing on or before termination), delete or return the personal data processed on the Customer's behalf, and will do so within a reasonable period not exceeding ninety (90) days after termination, except to the extent SignedBy is required by law to retain it. Audit-trail records tied to a completed electronic signature that must remain reproducible are expressly carved out from this deletion or return obligation and will be retained by SignedBy, and any such retained records will continue to be held subject to the confidentiality and security obligations of this DPA.
6. Audits
SignedBy will make available information reasonably necessary to demonstrate compliance with this DPA and will allow for, and contribute to, audits conducted by the Customer or an auditor mandated by the Customer, subject to reasonable advance notice and confidentiality.
7. Liability
Liability under this DPA is subject to, and does not increase, the limitation of liability and exclusions of liability set out in the SignedBy Terms of Service. Those limitations, caps, and exclusions apply to and flow through to all claims arising under or in connection with this DPA, whether in contract, tort, or otherwise, and nothing in this DPA increases or expands either party's aggregate liability beyond what is provided in the Terms of Service.
8. Contact
Questions about this DPA can be sent to privacy@signedby.ai.
Annex A — Details of Processing
This Annex A sets out the details of the processing carried out by SignedBy on behalf of the Customer, as required by Article 28(3) of the GDPR.
Subject matter of the processing:SignedBy's processing of personal data on behalf of the Customer in connection with providing the SignedBy electronic-signature and document-workflow service under the Terms of Service and this DPA.
Duration of the processing:For the duration of the Customer's use of the service and any applicable retention period described in the Privacy Policy, subject to the deletion and return provisions of this DPA and any legally required retention (including audit-trail records tied to a completed electronic signature).
Categories of data subjects:Senders (the Customer's account holders and authorized users) and Signers (individuals the Customer invites to view or sign a document).
Types of personal data: names; email addresses; document content uploaded by or on behalf of the Customer; field values and typed or drawn signature images entered by Signers; and audit-trail data (including timestamps, IP addresses, browser/user-agent strings, and cryptographic document hashes).
Special categories of data: SignedBy does not intentionally collect or request special categories of personal data (as defined in Article 9 of the GDPR). Uploaded documents may contain any content the Customer chooses to include; as controller, the Customer is solely responsible for determining the content of documents, for the presence of any special-category or other sensitive data within them, and for ensuring an appropriate lawful basis for its processing.
Nature and purpose of the processing: to render and store uploaded documents; capture field values and signatures entered by Signers; route signing requests by email; record the audit trail needed for a legally defensible electronic signature; generate the final signed PDF and certificate of completion; provide optional AI-assisted features (field-suggestion, drafting, and summarization); process billing; secure the service and prevent abuse; and comply with legal obligations.