Data Processing Addendum
For OwnSigner Cloud customers subject to GDPR, KSA PDPL, UAE PDPL, or other equivalent data protection law.
1. Roles & subject matter
This Data Processing Addendum forms part of the OwnSigner Terms of Service between the Customer (the "Controller") and OwnSigner (the "Processor"). For all Personal Data processed by OwnSigner Cloud on behalf of the Controller, OwnSigner acts as Processor and processes Personal Data only on the Controller's documented instructions.
2. Duration
This DPA applies for the duration of the OwnSigner Cloud subscription and for any post-termination period required for data return or deletion.
3. Categories of Personal Data
| Category | Examples |
|---|---|
| Identification & contact | Names, email addresses, phone numbers of Users and Signers |
| Authentication | Hashed passwords, MFA secrets, IP addresses, user agents |
| Content | Documents uploaded by the Controller and any personal data contained within them |
| Signatures | Drawn signature images, typed names, timestamps, IP addresses of Signers |
| Audit data | Every action taken on each document: who viewed, signed, declined; from which IP and time |
4. Categories of Data Subjects
- The Controller's employees, contractors, and authorized Users
- Signers invited to sign documents
- Other natural persons whose Personal Data the Controller chooses to include in documents
5. Sub-processors
The Controller authorizes OwnSigner to engage the following Sub-processors:
| Sub-processor | Purpose | Location |
|---|---|---|
| Oracle Cloud Infrastructure | Compute & storage | Customer's chosen region (EU / US / KSA) |
| Amazon Web Services | Object storage & backup (when selected) | Customer's chosen region |
| Mailjet (Sinch) | Transactional email delivery | EU (France) |
| Cloudflare | DDoS protection, TLS termination | Global edge (no document content transits Cloudflare; only TLS metadata) |
OwnSigner will provide 30 days' prior notice of any addition or replacement of a Sub-processor. If the Controller objects on reasonable data-protection grounds, the Controller may terminate the affected portion of the Service without penalty for the period covered by pre-paid fees.
6. International transfers
OwnSigner stores Personal Data in the region the Controller selects at onboarding. OwnSigner does NOT transfer Personal Data outside that region for processing purposes.
For incidental support transfers (e.g. a Controller raising a support ticket from a different country), where required by applicable law, transfers are made under EU Standard Contractual Clauses (Commission Decision 2021/914) or equivalent approved transfer mechanisms.
7. Security measures
OwnSigner implements technical and organisational measures including:
- Encryption at rest — AES-256 for stored documents
- Encryption in transit — TLS 1.3 for all traffic
- Per-tenant key separation with optional Customer-Managed Keys (CMK)
- Bcrypt-hashed passwords with a high work factor
- MFA (TOTP and email OTP) for OwnSigner administrators
- Network segmentation between tenants and between environments
- Detailed audit logs retained for at least 365 days
- Daily encrypted backups with 30-day retention
- SOC 2-aligned operational controls (vendor management, change management, incident response)
- Annual penetration testing by an independent firm
- Mandatory security training for all OwnSigner personnel with access to production systems
8. Personnel
OwnSigner ensures that any personnel authorised to process Personal Data:
- Are bound by confidentiality obligations
- Have completed mandatory data-protection training
- Access Personal Data only on a need-to-know basis with role-based controls
9. Data subject rights
OwnSigner will assist the Controller in responding to data subject requests (access, rectification, erasure, portability, restriction, objection) by providing tools within the OwnSigner admin interface and, where necessary, by responding to written requests from the Controller within 10 business days.
10. Data breach notification
OwnSigner will notify the Controller without undue delay, and in any event within 72 hours, of becoming aware of a Personal Data breach involving the Controller's data. The notification will include:
- Nature of the breach and categories of data subjects and records affected (approximate)
- Likely consequences of the breach
- Measures taken or proposed to address the breach and mitigate its effects
- Contact point for further information
11. Audits
OwnSigner makes available to the Controller all information necessary to demonstrate compliance with this DPA. The Controller may conduct an audit no more than once per 12 months, on at least 30 days' prior written notice, during business hours, and at the Controller's expense. OwnSigner may satisfy this obligation by providing recent third-party audit reports (e.g. SOC 2 Type II, ISO 27001) where available.
12. Deletion or return of data
On termination of the Service, OwnSigner will:
- For 30 days, retain Customer data and provide export tools
- After 30 days, delete Personal Data from active systems
- Within 90 days, delete Personal Data from backups (subject to backup rotation)
OwnSigner will provide written confirmation of deletion on request.
13. Liability
Liability arising out of this DPA is subject to the limitations in the Terms of Service.
14. Conflict
In the event of a conflict between this DPA and the Terms of Service or any Order Form, this DPA prevails with respect to the processing of Personal Data.
15. Contact
Privacy Officer
OwnSigner
Email: [email protected]