SignIQ Data Processing Addendum
Last updated: July 29, 2026 · Effective: August 1, 2026
This Data Processing Addendum (this "DPA") is entered into by and between [Sign IQ legal entity] ("Provider") and [Customer legal entity] ("Customer") and forms part of the SaaS Subscription Agreement or other written agreement between Provider and Customer governing Customer's use of the Services (the "Agreement").
Capitalized terms not defined in this DPA have the meanings given to them in the Agreement. In the event of conflict between this DPA and the Agreement regarding the processing of Customer Personal Data, this DPA controls. This DPA is intended to address U.S. privacy law obligations, including CCPA/CPRA and other U.S. state privacy laws, while preserving appropriate transfer and non-U.S. privacy provisions where applicable. GDPR, UK GDPR, Swiss, and other non-U.S. transfer provisions apply only to the extent those laws are applicable to the relevant Customer Personal Data.
1. Definitions
"Applicable Data Protection Laws" means all privacy, data protection, data security, consumer privacy, electronic communications, and breach notification laws applicable to the processing of Customer Personal Data under the Agreement, including, to the extent applicable, U.S. state consumer privacy laws, the California Consumer Privacy Act as amended by the California Privacy Rights Act and its implementing regulations (collectively, "CCPA"), and other U.S. federal, state, and local privacy and security laws. Applicable Data Protection Laws also include the GDPR, UK GDPR, Swiss Federal Act on Data Protection, and similar non-U.S. laws only to the extent applicable to the relevant Customer Personal Data.
"Business, Controller, Consumer, Contractor, Personal Data, Personal Information, Process, Processor, Sell, Sale, Share, Service Provider, Targeted Advertising, and Cross-Context Behavioral Advertising" have the meanings given to those or substantially similar terms under Applicable Data Protection Laws. Where a term is defined differently under different laws, the meaning applicable to the relevant law and processing activity applies.
"Customer Personal Data" means Personal Data or Personal Information contained in Customer Content or otherwise processed by Provider on behalf of Customer in providing the Services.
"Data Subject Request or Consumer Request" means a request by or on behalf of an individual to exercise privacy rights under Applicable Data Protection Laws, including rights to know, access, delete, correct, obtain a copy of, opt out of certain processing, restrict, or appeal.
"De-identified Data" means information that cannot reasonably be used to infer information about, or otherwise be linked to, an identified or identifiable individual, household, device, or Consumer, provided Provider maintains the information in de-identified form and does not attempt to re-identify it except as permitted by Applicable Data Protection Laws.
"Security Incident" means a confirmed breach of security leading to unauthorized access to, acquisition of, disclosure of, loss of, or Processing of Customer Personal Data in Provider's possession or control. Unsuccessful access attempts, pings, port scans, denial-of-service attacks, and similar events that do not compromise Customer Personal Data are not Security Incidents.
"Sensitive Data" means sensitive personal information,
special categories of personal data, or similarly regulated data under Applicable Data Protection Laws, including precise geolocation, government identifiers, biometric information, racial or ethnic origin, religious or philosophical beliefs, health information, financial account information, children's data, account credentials, and similar data.
"Standard Contractual Clauses or SCCs" means the standard contractual clauses approved by the European Commission for transfers of personal data to third countries, as updated or replaced from time to time, including any UK or Swiss addendum or supplement where applicable.
"Subprocessor" means a third party engaged by Provider to Process Customer Personal Data on behalf of Customer in connection with the Services.
"U.S. State Privacy Laws" means comprehensive U.S. state consumer privacy laws applicable to the Processing of Customer Personal Data, including the CCPA and other similar state laws that impose Controller/Processor, Business/Service Provider, Contractor, Consumer rights, data protection assessment, sale, sharing, targeted advertising, or sensitive data obligations.
2. Roles of the Parties
For Customer Personal Data, Customer is the Business or Controller and Provider is the Service Provider, Contractor, Processor, or similar role under Applicable Data Protection Laws, except where the parties expressly agree otherwise in writing or where Provider processes data for its own independent business purposes outside the scope of this DPA.
Customer is responsible for determining the purposes and means of processing Customer Personal Data, providing required notices, obtaining required consents or authorizations, establishing an applicable legal basis for processing, responding to Consumer Requests, and ensuring Customer's use of the Services complies with Applicable Data Protection Laws.
Provider will process Customer Personal Data only on behalf of Customer and in accordance with Customer's documented instructions, including the Agreement, this DPA, applicable Order Forms, Customer's configurations and settings, use of the Services, and other written instructions accepted by Provider.
Provider may process limited account, billing, usage, security, and business contact information as an independent Business or Controller for its own compliance, billing, account administration, fraud prevention, security, legal, and business operations purposes, as described in Provider's privacy policy. Such independent processing is not Customer Personal Data processed on behalf of Customer under this DPA.
3. Details of Processing
The subject matter, duration, nature, purpose, categories of Personal Data, categories of Data Subjects or Consumers, and processing activities are described in Schedule 1. Customer remains responsible for ensuring that Schedule 1 accurately reflects Customer's intended use of the Services and the categories of Customer Personal Data submitted to the Services.
Provider may process Customer Personal Data to provide, operate, maintain, secure, support, troubleshoot, and improve the Services; authenticate users and Signers; route, transmit, store, and display documents; maintain transaction records and audit trails; prevent fraud, abuse, and security incidents; comply with legal obligations; and perform the processing activities described in the Agreement, this DPA, and applicable Order Forms.
Provider will not materially change the nature or purpose of processing Customer Personal Data in a manner that is inconsistent with this DPA unless permitted by Applicable Data Protection Laws and the Agreement, or unless Customer provides additional documented instructions.
4. Customer Instructions
Provider will comply with Customer's documented instructions unless Provider is required by applicable law to process Customer Personal Data differently. If Provider is required by law to process Customer Personal Data other than in accordance with Customer's instructions, Provider will notify Customer before doing so unless legally prohibited.
Provider will promptly inform Customer if, in Provider's reasonable opinion, an instruction infringes Applicable Data Protection Laws. Customer acknowledges that Provider is not responsible for determining whether Customer's instructions, configurations, documents, retention choices, signer workflows, legal notices, consent language, or use cases comply with Applicable Data Protection Laws.
If Provider reasonably determines that it can no longer meet its obligations under Applicable Data Protection Laws with respect to Customer Personal Data, Provider will notify Customer and will use commercially reasonable efforts to remediate the issue. Customer may take reasonable and appropriate steps to stop and remediate unauthorized processing, including by suspending affected processing or terminating the affected Order Form if the issue cannot be remediated.
5. Confidentiality and Personnel
Provider will ensure that personnel authorized to process Customer Personal Data are subject to appropriate confidentiality obligations and receive training or instructions appropriate to their role and access to Customer Personal Data.
Provider will limit access to Customer Personal Data to personnel who need access to provide, secure, support, maintain, or improve the Services, or to comply with the Agreement, this DPA, or applicable law. Provider will take reasonable steps to ensure that such personnel process Customer Personal Data only in accordance with this DPA and Customer's documented instructions.
6. Security Measures
Provider will implement and maintain appropriate technical, administrative, and organizational measures designed to protect Customer Personal Data against Security Incidents and to preserve the confidentiality, integrity, availability, and resilience of the Services. The measures are further described in Schedule 2 and the Security Exhibit.
The parties acknowledge that the Services are a configurable SaaS platform and that Customer is responsible for configuring the Services appropriately, managing user access and roles, selecting authentication and signer-verification methods, maintaining secure credentials, controlling integrations, and determining retention, export, and deletion settings available through the Services.
Provider may update security measures from time to time, provided that updates do not materially reduce the overall security of the Services during an active Subscription Term. Provider's security measures are intended to satisfy U.S. privacy law requirements for reasonable and appropriate administrative, technical, and physical safeguards, as applicable to the nature of the processing and the Services.
7. Security Incident Notification
Provider will notify Customer without undue delay after confirming a Security Incident involving Customer Personal Data. Notice will be provided to the contact designated by Customer in the Agreement, Order Form or other agreed channel.
Provider's notice will include, to the extent known and legally permitted: a description of the Security Incident, the categories of Customer Personal Data affected, the approximate number of affected individuals where known, the likely consequences of the Security Incident, measures taken or proposed to address the Security Incident, and a contact point for further information.
Provider will take reasonable steps to contain, investigate, and remediate the Security Incident. Provider will reasonably cooperate with Customer in connection with Customer's breach notification obligations under Applicable Data Protection Laws, taking into account the nature of the processing and information available to Provider. Provider's notification of or response to a Security Incident is not an admission of fault, liability, or violation of law.
8. Subprocessors
Customer authorizes Provider to use Subprocessors to process Customer Personal Data in connection with the Services. Provider will impose written data protection obligations on Subprocessors that are no less protective in substance than the obligations imposed on Provider under this DPA, including obligations relating to confidentiality, security, permitted processing, deletion or return, and restrictions required by Applicable Data Protection Laws.
Provider remains responsible for its Subprocessors' processing of Customer Personal Data to the same extent Provider would be responsible if performing the processing directly, except to the extent a Subprocessor's acts or omissions are caused by Customer's instructions or Customer's use of third-party services.
Provider will maintain a list of Subprocessors used for the Services as set forth in Schedule 3 or at a designated online location. Provider will provide notice of new Subprocessors as required by the Agreement or as otherwise reasonably determined by Provider. Customer may object to a new Subprocessor on reasonable data protection grounds within the stated notice period. If the parties cannot resolve the objection, Customer may terminate the affected Services as provided in the Agreement or applicable Order Form.
Provider will require each Subprocessor that processes Customer Personal Data subject to U.S. State Privacy Laws to comply with applicable Service Provider, Contractor, Processor, and similar restrictions, including restrictions on Sale, Sharing, retention, use, disclosure, combination, and targeted advertising to the extent applicable.
9. International Transfers
Customer authorizes Provider and its Subprocessors to process Customer Personal Data in the United States and other jurisdictions where Provider or its Subprocessors maintain facilities, personnel, support operations, or infrastructure, subject to the Agreement, this DPA, and the Security Exhibit.
The parties intend this DPA to operate primarily as a U.S.-focused Service Provider/Processor addendum. However, if Customer Personal Data is subject to restrictions on cross-border transfers under GDPR, UK GDPR, Swiss law, or similar non-U.S. laws, the parties will use an appropriate transfer mechanism required by Applicable Data Protection Laws, including the SCCs or other lawful transfer mechanism where applicable.
To the extent the SCCs apply, the parties agree that Module Two applies where Customer is a Controller and Provider is a Processor, and Module Three applies where Customer is a Processor and Provider is a Subprocessor. The optional docking clause does not apply unless the parties agree otherwise. The competent supervisory authority, governing law, and forum will be determined as required by the SCCs. This Section is included to preserve transfer compliance where required and is not intended to make this DPA an EU-only agreement.
10. Data Subject and Consumer Requests
Customer is responsible for receiving, verifying, and responding to Data Subject Requests, Consumer Requests, and similar privacy rights requests relating to Customer Personal Data, including requests to know, access, correct, delete, obtain a copy, opt out, restrict processing, or appeal, to the extent required by Applicable Data Protection Laws.
Provider will, taking into account the nature of the processing, provide reasonable assistance to Customer through appropriate technical and organizational measures, insofar as possible, to enable Customer to respond to such requests. Provider may satisfy this obligation by making functionality available through the Services, providing standard documentation, or offering reasonable support.
If Provider receives a request directly from a Data Subject or Consumer relating to Customer Personal Data, Provider will not respond to the substance of the request except to direct the individual to Customer or as legally required. Provider will notify Customer of the request where legally permitted and reasonably practicable.
11. Assistance with Compliance
Taking into account the nature of processing and information available to Provider, Provider will provide reasonable assistance to Customer as required by Applicable Data Protection Laws in connection with security obligations, breach notifications, Consumer Requests, data protection assessments, privacy impact assessments, risk assessments, regulator consultations, and similar obligations applicable to Customer's use of the Services.
Provider may charge reasonable fees for assistance that is outside the ordinary functionality or standard support for the Services, unless the assistance is required due to Provider's breach of this DPA. Customer is responsible for determining whether a data protection assessment or similar assessment is required for Customer's use of the Services and for preparing and maintaining such assessment unless otherwise agreed in writing.
12. Deletion and Return
Upon expiration or termination of the Services, Provider will make Customer Personal Data available for export for the period stated in the Agreement, Order Form, documentation, or administrative console. After that period, Provider may delete or anonymize Customer Personal Data in accordance with the Agreement, this DPA, and Provider's standard retention practices.
Provider may retain Customer Personal Data in backups, archives, logs, and legal or compliance records for a limited period, provided that retained data remains subject to this DPA and is not processed for any purpose other than backup, security, legal, compliance, dispute resolution, or as otherwise required or permitted by applicable law.
Customer is responsible for exporting and preserving documents, audit trails, certificates, transaction records, and other records needed for Customer's legal, regulatory, evidentiary, or business purposes before termination or expiration of the applicable Services.
13. Audits and Information
Provider will make available information reasonably necessary to demonstrate compliance with this DPA, which may include summaries of security measures, third-party audit reports, certifications, policies, questionnaires, or other documentation made available by Provider.
If the information provided is insufficient to satisfy Customer's legally required audit or assessment rights under Applicable Data Protection Laws, Customer may request an audit no more than once annually, unless required more frequently by Applicable Data Protection Laws or following a Security Incident. Audits must be conducted during normal business hours, on reasonable prior notice, and in a manner designed to minimize disruption to Provider's business and the Services.
Provider may require that audits be conducted by an independent third-party auditor subject to confidentiality obligations. Audits may not include penetration testing, vulnerability scanning, access to other customers' data, access to Provider source code, or access to information that would compromise the security, confidentiality, or integrity of Provider systems or third-party systems.
Where U.S. State Privacy Laws require Customer to take reasonable and appropriate steps to ensure Provider's processing is consistent with Customer's obligations, the information and audit rights in this Section are intended to satisfy those requirements.
14. U.S. State Privacy Laws
To the extent U.S. State Privacy Laws apply, and Customer discloses or makes available Personal Information to Provider as a Service Provider, Contractor, Processor, or similar role, Provider will process Customer Personal Data solely for the limited and specified business purposes described in the Agreement, this DPA, applicable Order Forms, and Customer's documented instructions.
Provider will not Sell or Share Customer Personal Data. Provider will not retain, use, or disclose Customer Personal Data for any purpose other than the business purposes specified in the Agreement, this DPA, or Customer's documented instructions, except as permitted by Applicable Data Protection Laws. Provider will not retain, use, or disclose Customer Personal Data outside the direct business relationship between Provider and Customer except as permitted by Applicable Data Protection Laws.
Provider will not combine Customer Personal Data with Personal Information received from or on behalf of another person, collected from Provider's own interactions with individuals, or collected from other sources, except as permitted by Applicable Data Protection Laws, including for security, fraud prevention, debugging, analytics, internal operations, or other purposes permitted for Service Providers, Contractors, or Processors.
Provider will not use Customer Personal Data for Cross-Context Behavioral Advertising, Targeted Advertising, profiling in furtherance of decisions that produce legal or similarly significant effects, or to train or improve artificial intelligence or machine learning models for the benefit of third parties, except to the extent expressly permitted by Customer in writing and by Applicable Data Protection Laws.
Provider will comply with applicable obligations imposed on Service Providers, Contractors, Processors, and similar roles under U.S. State Privacy Laws, including providing the same level of privacy protection required by such laws, notifying Customer if Provider determines it can no longer meet its obligations, and allowing Customer to take reasonable and appropriate steps to stop and remediate unauthorized processing.
15. Sensitive Data and Restricted Data
Customer will not submit Sensitive Data, protected health information, payment card data, government classified information, children's data, biometric data, or other regulated data to the Services.
Customer is responsible for determining whether any Customer Personal Data is subject to sector-specific privacy or security laws, including HIPAA, GLBA, FCRA, FERPA, COPPA, payment card rules, employment privacy laws, biometric privacy laws, or similar laws, and whether the Services are appropriate for such data. Provider is not responsible for Customer's decision to submit regulated or sensitive data to the Services except as expressly set forth in the Agreement, this DPA, or a signed Order Form.
If Customer Personal Data includes Sensitive Data permitted under the Agreement, Provider will process such Sensitive Data only as necessary to provide the Services, comply with Customer's documented instructions, maintain security, prevent fraud or abuse, and comply with applicable law.
16. Government and Law Enforcement Requests
If Provider receives a governmental, law enforcement, court, or regulatory request for Customer Personal Data, Provider will, to the extent legally permitted, notify Customer and provide Customer with reasonable information necessary to respond to the request.
If Provider is legally required to disclose Customer Personal Data, Provider will disclose only the portion legally required and will use reasonable efforts to preserve confidentiality where legally available. Nothing in this DPA requires Provider to violate applicable law or a binding legal order.
17. De-identified and Aggregated Data
Provider may process aggregated or De-identified Data derived from the Services for analytics, benchmarking, security, product improvement, operational, and business purposes, provided such data does not identify Customer, Authorized Users, Signers, Consumers, Data Subjects, or any individual.
Provider will maintain and use De-identified Data in de-identified form and will not attempt to re-identify De-identified Data except to test and maintain de-identification safeguards or as otherwise permitted by Applicable Data Protection Laws.
18. Order of Precedence; Liability; Term
If there is a conflict between this DPA and the Agreement regarding the processing of Customer Personal Data, this DPA controls. If there is a conflict between this DPA and an applicable Order Form that expressly addresses data protection or privacy requirements for particular Customer Personal Data, the Order Form controls solely for that Customer Personal Data and only to the extent of the conflict.
The liability of each party under this DPA is subject to the limitations and exclusions of liability in the Agreement, unless prohibited by Applicable Data Protection Laws. Nothing in this DPA limits either party's liability to the extent such limitation is prohibited by applicable law.
This DPA will remain in effect for as long as Provider processes Customer Personal Data on behalf of Customer. Sections that by their nature should survive, including confidentiality, deletion and return, de-identified data, audit rights, U.S. State Privacy Law restrictions, liability, and transfer provisions, will survive expiration or termination to the extent applicable.
19. Signature
This DPA is incorporated into the Agreement and is effective as of the Effective Date of the Agreement or the date the parties otherwise agree to this DPA.
|
Provider |
Customer |
|
[Sign IQ legal entity] |
[Customer legal entity] |
|
By: _________________________ |
By: _________________________ |
|
Name: _______________________ |
Name: _______________________ |
|
Title: ______________________ |
Title: ______________________ |
|
Date: _______________________ |
Date: _______________________ |
Schedule 1. Details of Processing
|
Item |
Description |
|
Subject Matter |
Provider's processing of Customer Personal Data to provide the Services under the Agreement. |
|
Duration |
For the Subscription Term and any post-termination period during which Provider processes Customer Personal Data as described in the Agreement, this DPA, or applicable law. |
|
Nature and Purpose |
Hosting, storage, transmission, display, routing, electronic signature workflows, audit trails, account administration, authentication, support, security, troubleshooting, service improvement, compliance, and related processing activities. |
|
Categories of Data Subjects / Consumers |
Customer personnel, Authorized Users, Signers, recipients, counterparties, administrators, support contacts, and other individuals whose information is included in Customer Content or processed through the Services. |
|
Categories of Personal Data |
Names, email addresses, phone numbers, account identifiers, IP addresses, device and browser data, authentication data, signature data, audit trail data, transaction metadata, document content, templates, messages, and other information submitted to or generated through the Services. |
|
Sensitive Data |
Not intended |
|
Frequency of Transfer |
Continuous or as initiated by Customer, Authorized Users, Signers, or the Services. |
|
Retention |
As configured by Customer, set forth in the Agreement or Order Form, or maintained under Provider's standard retention, backup, logging, legal, and compliance practices. |
Schedule 2. Technical and Organizational Measures
- Access controls designed to limit access to Customer Personal Data to authorized personnel with a business need to know.
- Authentication controls, password policies, session management, role-based access, and support for administrative configuration of user permissions.
- Encryption of Customer Personal Data in transit using industry-standard transport encryption and encryption at rest where supported by Provider systems.
- Logging and monitoring of relevant system, security, authentication, and administrative events.
- Vulnerability management, patching, secure development practices, code review, and security testing appropriate to the Services.
- Network and infrastructure safeguards, including firewalls, segmentation, intrusion detection or prevention tools, and hardened configurations where appropriate.
- Personnel security measures, including confidentiality obligations.
- Incident response procedures designed to identify, investigate, contain, remediate, and notify regarding Security Incidents.
- Business continuity and disaster recovery measures designed to support availability and resilience of the Services.
- Vendor and Subprocessor management processes, including due diligence and contractual data protection obligations.
- Data minimization, retention, deletion, and backup practices appropriate to the nature of the Services and Customer configurations.
- Administrative controls and policies designed to support compliance with applicable U.S. privacy and security obligations for Service Providers, Contractors, and Processors.