Legal
Effective 19 June 2026

Data Processing Addendum

For OwnSigner Cloud customers subject to GDPR, KSA PDPL, UAE PDPL, or other equivalent data protection law.

هذا المستند القانوني متاح حاليًا باللغة الإنجليزية. النسخة الإنجليزية هي المرجع الرسمي. سيتم نشر ترجمة عربية معتمدة قانونيًا قريبًا.

Last updated: 19 June 2026 · Version 1.0

This DPA applies to OwnSigner Cloud only. For self-hosted OwnSigner deployments, the Customer is solely the Controller and Processor for all data; OwnSigner is neither. No DPA is required for self-hosted use.

1. Roles & subject matter

This Data Processing Addendum forms part of the OwnSigner Terms of Service between the Customer (the "Controller") and OwnSigner (the "Processor"). For all Personal Data processed by OwnSigner Cloud on behalf of the Controller, OwnSigner acts as Processor and processes Personal Data only on the Controller's documented instructions.

2. Duration

This DPA applies for the duration of the OwnSigner Cloud subscription and for any post-termination period required for data return or deletion.

3. Categories of Personal Data

CategoryExamples
Identification & contactNames, email addresses, phone numbers of Users and Signers
AuthenticationHashed passwords, MFA secrets, IP addresses, user agents
ContentDocuments uploaded by the Controller and any personal data contained within them
SignaturesDrawn signature images, typed names, timestamps, IP addresses of Signers
Audit dataEvery action taken on each document: who viewed, signed, declined; from which IP and time

4. Categories of Data Subjects

5. Sub-processors

The Controller authorizes OwnSigner to engage the following Sub-processors:

Sub-processorPurposeLocation
Oracle Cloud InfrastructureCompute & storageCustomer's chosen region (EU / US / KSA)
Amazon Web ServicesObject storage & backup (when selected)Customer's chosen region
Mailjet (Sinch)Transactional email deliveryEU (France)
CloudflareDDoS protection, TLS terminationGlobal edge (no document content transits Cloudflare; only TLS metadata)

OwnSigner will provide 30 days' prior notice of any addition or replacement of a Sub-processor. If the Controller objects on reasonable data-protection grounds, the Controller may terminate the affected portion of the Service without penalty for the period covered by pre-paid fees.

6. International transfers

OwnSigner stores Personal Data in the region the Controller selects at onboarding. OwnSigner does NOT transfer Personal Data outside that region for processing purposes.

For incidental support transfers (e.g. a Controller raising a support ticket from a different country), where required by applicable law, transfers are made under EU Standard Contractual Clauses (Commission Decision 2021/914) or equivalent approved transfer mechanisms.

7. Security measures

OwnSigner implements technical and organisational measures including:

8. Personnel

OwnSigner ensures that any personnel authorised to process Personal Data:

9. Data subject rights

OwnSigner will assist the Controller in responding to data subject requests (access, rectification, erasure, portability, restriction, objection) by providing tools within the OwnSigner admin interface and, where necessary, by responding to written requests from the Controller within 10 business days.

10. Data breach notification

OwnSigner will notify the Controller without undue delay, and in any event within 72 hours, of becoming aware of a Personal Data breach involving the Controller's data. The notification will include:

11. Audits

OwnSigner makes available to the Controller all information necessary to demonstrate compliance with this DPA. The Controller may conduct an audit no more than once per 12 months, on at least 30 days' prior written notice, during business hours, and at the Controller's expense. OwnSigner may satisfy this obligation by providing recent third-party audit reports (e.g. SOC 2 Type II, ISO 27001) where available.

12. Deletion or return of data

On termination of the Service, OwnSigner will:

OwnSigner will provide written confirmation of deletion on request.

13. Liability

Liability arising out of this DPA is subject to the limitations in the Terms of Service.

14. Conflict

In the event of a conflict between this DPA and the Terms of Service or any Order Form, this DPA prevails with respect to the processing of Personal Data.

15. Contact

Privacy Officer
OwnSigner
Email: [email protected]

Template notice. This DPA is a working template aligned with GDPR Article 28 and similar data protection regimes. Before signing with customers, have it reviewed by qualified counsel — specifically for jurisdictional carve-outs (e.g. KSA PDPL, UAE PDPL, HIPAA BAA), Standard Contractual Clauses references, and any industry-specific addenda required by your customers.