Data Processing Addendum
Effective date: July 18, 2026 · Version 1.0
This Data Processing Addendum ("DPA") forms part of the End User License Agreement(or other written order) between OwnSig Inc. ("OwnSig", "Processor") and the customer organisation ("Customer", "Controller") that uses the OwnSig service. It governs OwnSig's processing of Customer Personal Data.
This public DPA is the standard form offered for self-serve and enterprise agreements. Countersigned copies, custom schedules, and UK/EU representative details are available on request via Contact or privacy@ownsig.com.
1. Roles and scope
For employee directory attributes, signature content, organisational settings, and related account data that Customer uploads or syncs into the service, Customer is the Controller and OwnSig is the Processor. OwnSig processes such data only on Customer's documented instructions (including configuration in the product) and as described in the Privacy Policy.
For OwnSig's own account, billing, and website data, OwnSig acts as an independent Controller as described in the Privacy Policy — that processing is outside this DPA.
2. Categories of data and data subjects
- Data subjects:Customer's employees, contractors, and other workspace users; optionally recipients of Customer's own emails when Customer enables the organisation-controlled message log.
- Personal data: names, work email addresses, titles, departments, phone numbers, photos, office locations, manager relationships, leave/OOO metadata, signature HTML and related assets, authentication identifiers, and audit/security logs tied to those users.
- Special categories: not intentionally collected. Customer must not instruct OwnSig to process special-category data unless a separate written addendum applies.
3. Processing purposes and duration
OwnSig processes Customer Personal Data to provide, secure, support, and improve the service as configured by Customer (signature management, analytics, integrations, AI features Customer enables, residency/isolation options). Processing continues for the term of the subscription and the retention periods in the Privacy Policy and product (including post-termination export/deletion windows).
4. Customer instructions
Customer instructs OwnSig to process Customer Personal Data to deliver the subscribed features, including syncing from Customer-connected HRIS/IdP/mail platforms, storing data in the residency region(s) Customer selects (where contracted), and disclosing data to subprocessors listed at /legal/subprocessorsas needed to operate the service. Additional written instructions require mutual agreement if they fall outside the product's documented capabilities.
5. Confidentiality and personnel
OwnSig ensures persons authorised to process Customer Personal Data are bound by confidentiality and receive security awareness appropriate to their role. Staff access to customer tenants is gated by role, logged, and subject to periodic access review (see Security & compliance).
6. Security measures
OwnSig implements technical and organisational measures appropriate to the risk, including encryption in transit (TLS 1.2+) and at rest (AES-256 / CMEK where deployed), AES-256-GCM for tenant secrets, logical tenant isolation (and dedicated cells where contracted), RBAC, optional SSO/SCIM and MFA, audit logging, vulnerability management in CI, backups with restore drills, and documented incident response. Measures are described further on the Security page and may evolve without reducing the overall level of protection.
7. Subprocessors
Customer authorises OwnSig to engage subprocessors. The current list is published at /legal/subprocessors. OwnSig will provide notice of material additions (via the page changelog and, for Enterprise contacts on file, email) and remain liable for subprocessor performance as required by applicable law. Objection rights for Enterprise customers follow the order form or a separately executed schedule.
8. International transfers
Where Customer Personal Data is transferred from the EEA, UK, or Switzerland to a country without an adequacy decision, OwnSig relies on the European Commission's Standard Contractual Clauses (Module 2 Controller→Processor) and the UK International Data Transfer Addendum (as applicable), completed with OwnSig's details and the technical measures in §6. On Enterprise Sovereign, Customer may select regional cells to keep primary processing in-region.
9. Assistance with data-subject rights and DPIAs
OwnSig provides product tooling (DSAR export, erasure workflows) and reasonable assistance so Customer can respond to data-subject requests and conduct DPIAs / transfer assessments. Customer remains responsible for verifying the requester and for its own legal bases and notices to employees.
10. Breach notification
OwnSig will notify Customer without undue delay and, where feasible, within 72 hours after becoming aware of a personal-data breach affecting Customer Personal Data, with information reasonably available to help Customer meet its own notification duties. Further detail is in the incident & disclosure policy.
11. Audits and evidence
Upon written request (not more than once annually, unless a regulator requires otherwise), OwnSig will make available information reasonably necessary to demonstrate compliance with this DPA, including summaries of relevant controls and, when available, third-party audit reports under NDA. On-site audits require reasonable notice and are limited to facilities and systems processing Customer Personal Data.
OwnSig builds its ISMS and product controls to SOC 2 Trust Services Criteria and ISO/IEC 27001 Annex A standards; formal certification audits are on the public roadmap and are not represented here as completed certifications.
12. Return and deletion
On termination, Customer may export data via product tools (where available) during the documented retention window. Thereafter OwnSig deletes or anonymises Customer Personal Data from active systems within the periods stated in the Privacy Policy, except data OwnSig must retain under law (kept isolated and no longer used for the service).
13. Precedence
If this DPA conflicts with the EULA or an order form on data-protection matters, this DPA controls. Governing law and venue follow the EULA unless mandatory privacy law requires otherwise.