Data Processing Agreement
Version 1.0.0 · Effective 2026-07-07
1. Parties
This Data Processing Agreement ("DPA") forms part of the SIGNFILE Terms of Service between Ilxonwat ("Processor", "we", "us") and the workspace owner ("Controller", "you"). By accepting the Terms of Service, the Controller also accepts this DPA on behalf of itself and any underlying data subjects whose personal data it submits to the Service.
2. Subject matter and duration
The Processor shall process personal data on behalf of the Controller for the purpose of providing the SIGNFILE e-signature service (creating, sending, signing, storing, and auditing electronic signature workflows). The processing begins when the Controller submits a document or signer data to the Service and ends when the Controller (a) deletes the relevant document or workspace, (b) terminates the SIGNFILE account, or (c) requests return or deletion of personal data under Section 11.
3. Nature and purpose of processing
The Processor shall: (a) receive PDF documents and signer contact details submitted by the Controller; (b) embed signature fields; (c) send signing invitation emails to signers; (d) capture each signer's typed signature, drawn signature, IP address, user agent, and timestamps; (e) produce an immutable SHA-256 hash of the signed document; (f) stamp the signed PDF with the cryptographic signature and the SHA-256 hash; and (g) maintain an audit trail of every signing event.
4. Categories of personal data
The Processor processes the following categories of data:
- Account data: the Controller's name, email address, optional company name, hashed password.
- Signer data: each signer's name, email address, IP address, user agent string, typed signature image, and signing timestamps.
- Document content: the PDFs submitted by the Controller, including any personal data those PDFs contain. The Processor does not inspect, scan, or train any model on document content.
- Audit metadata: workspace ID, document ID, signer ID, event name, event timestamp.
5. Categories of data subjects
Data subjects are (a) the Controller and the Controller's authorized users (members of the workspace), and (b) the individuals named as signers on documents submitted by the Controller. The Controller is responsible for ensuring it has a lawful basis under GDPR Art. 6 to submit each signer's data to the Service.
6. Sub-processors
The Controller authorizes the Processor to engage the sub-processors listed on the Sub-processors page. The Processor shall notify the Controller at least 30 days before adding a new sub-processor. The Controller may object on reasonable data-protection grounds; if the parties cannot resolve the objection, the Controller may terminate the affected workspace and receive a pro-rated refund.
The Processor enters a written contract with each sub-processor that imposes data-protection obligations no less protective than those in this DPA. The Processor remains fully liable to the Controller for the performance of each sub-processor's obligations.
7. Security of processing
The Processor implements the technical and organizational measures listed on the How We Audit Signatures page, including TLS 1.2+ in transit, AES-256 at rest in the Appwrite Cloud storage bucket (Frankfurt region), SHA-256 cryptographic verification of signed documents, role-based access control, and least-privilege administrative access. The Processor reviews these measures at least annually and updates them as the threat landscape evolves.
8. Audit rights
The Processor shall make available to the Controller all information necessary to demonstrate compliance with this DPA, by providing: (a) the security measures listed on the public Security page; (b) the most recent SOC 2 Type II report or equivalent independent assessment, when available; and (c) prompt responses to reasonable written audit requests, no more than once per calendar year, at the Controller's cost. Audit requests should be sent to support@signfile.io.
9. Breach notification
The Processor shall notify the Controller without undue delay, and in any case within 72 hours, after becoming aware of a Personal Data Breach affecting the Controller's data. The notification shall describe the nature of the breach, the categories and approximate number of data subjects affected, the likely consequences, and the measures taken or proposed to address the breach. The Processor shall reasonably cooperate with the Controller in fulfilling its own notification obligations under GDPR Art. 33 and Art. 34.
10. Data subject rights
The Processor shall assist the Controller, by appropriate technical and organizational measures, in fulfilling its obligation to respond to data-subject requests under GDPR Art. 15–22. The Service exposes self-service endpoints for data export (/api/me/export) and account deletion (/api/account/deletion/request) that allow the Controller (or, where the Controller is itself the data subject, the signer) to exercise these rights directly.
11. Return and deletion
On termination of the SIGNFILE account, the Processor shall, at the Controller's written request, return a copy of all personal data processed under this DPA in a structured, commonly used, machine-readable format, and shall delete all such personal data within 30 days. Signed documents and the cryptographic SHA-256 hash of each signed document are retained for 7 years per the ESIGN Act recordkeeping guidance (15 U.S.C. § 7001 et seq.); this retention is necessary for the legal validity of the signature and is disclosed in the Privacy Policy.
12. International transfers
The Processor is hosted in the European Union (Appwrite Cloud, Frankfurt region). The Processor does not transfer personal data outside the EU/EEA except where required to deliver the Service (e.g. transactional email delivery via a sub-processor listed on the Sub-processors page). Where a transfer occurs, the Processor relies on Standard Contractual Clauses (Commission Decision 2021/914) or another lawful transfer mechanism.
13. Governing law
This DPA is governed by the laws of the European Union (GDPR) and, for any non-GDPR matters, the law of the Processor's registered seat. Disputes shall be resolved in the courts of that seat unless mandatory law (e.g. consumer-protection statute) provides otherwise.
14. Acceptance
This DPA is accepted by checking the "I agree to the Terms of Service and Data Processing Agreement" box at signup, or by continuing to use the Service under a pre-existing account. Enterprise customers may execute a paper-signed version of this DPA by emailing support@signfile.io; a signed paper copy supersedes the click-through version.