Legal
Terms of Service Privacy Policy Data Processing Addendum Sub-processors E-signature consent
On this page
1. Scope, incorporation and execution 2. Definitions 3. Roles of the parties 4. Processing of Customer Personal Data 5. Confidentiality and personnel 6. Security 7. Sub-processors 8. International transfers 9. Assistance to Customer 10. Security Incidents 11. Audits and compliance evidence 12. Deletion and return 13. Liability 14. General Schedule 1 — Signer erasure procedure Annex I — Description of the processing A. List of parties B. Description of the transfer C. Competent supervisory authority Annex II — Technical and organisational measures Annex III — Sub-processors Annex IV — UK International Data Transfer Addendum Signature (optional — see Section 1.5)

Usign Data Processing Addendum

Under legal review. Effective 8 September 2026; not yet countersigned by counsel. Please confirm the current version with legal@usign.co before relying on it.

Version 1.0
Effective date: 8 September 2026

1. Scope, incorporation and execution

1.1 Parties. This Data Processing Addendum (the "DPA") is entered into between Upfluence Inc., a corporation with its principal place of business at 214 Sullivan Street, Suite 3A, New York, NY 10012, United States, operating the Usign service ("Usign"), and the customer identified in the Agreement ("Customer"). Each is a "party" and together the "parties".

1.2 Incorporation. This DPA supplements and forms part of the Usign Terms of Service or other written agreement between the parties governing Customer's use of the Service (the "Agreement"). Capitalised terms not defined here have the meaning given in the Agreement.

1.3 Application. This DPA applies where, and to the extent that, Usign processes Customer Personal Data on Customer's behalf in connection with the Service, and Data Protection Laws apply to that processing.

1.4 Execution — no signature required. This DPA is incorporated into the Agreement by reference under Section 11.2 of the Terms of Service and takes effect automatically, without signature, when Customer accepts the Agreement or first uses the Service, whichever is earlier. This is deliberate: Article 28(3) GDPR requires the processing contract to be in place before processing begins, and a DPA that waits for countersignature leaves customers unprotected in the meantime.

1.5 Optional countersignature. A Customer that requires an executed copy may request one at legal@usign.co. Usign will send this DPA for signature through the Usign service; the countersigned version has the same terms as the published version in force on the date of signature, and where the two differ the countersigned version prevails between those parties.

1.6 Order of precedence. In the event of conflict: (a) the Standard Contractual Clauses (Section 8 and Annex IV) prevail over this DPA; (b) this DPA prevails over the Agreement in respect of the processing of Customer Personal Data; (c) the Agreement prevails in all other respects. Nothing in this DPA reduces a party's obligations under Data Protection Laws.

1.7 Changes. Usign may update this DPA where necessary to reflect a change in Data Protection Laws, a decision of a supervisory authority or court, the adoption of new standard clauses, or a change in the Service. Usign will publish the updated version and give Customer at least 30 days' notice of a material change by email to the Customer's administrative contacts or by notice in the Service. No update will materially reduce Usign's obligations or Customer's rights; where an update would, it applies only on Customer's acceptance or renewal.

2. Definitions

"Agreement" has the meaning in Section 1.2.

"CCPA" means the California Consumer Privacy Act of 2018 as amended by the California Privacy Rights Act, and its implementing regulations.

"Controller", "Processor", "Data Subject", "Personal Data", "Personal Data Breach", "Processing" and "Supervisory Authority" have the meanings given in the GDPR; "Business", "Service Provider", "Sell", "Share" and "Consumer" have the meanings given in the CCPA.

"Customer Personal Data" means Personal Data contained within Customer Data — including document content, Signer names and email addresses, field values, signature images and Audit Trail entries — that Usign processes on Customer's behalf under the Agreement.

"Data Protection Laws" means all laws applicable to the processing of Customer Personal Data under this DPA, including the GDPR, the UK GDPR and the UK Data Protection Act 2018, the Swiss Federal Act on Data Protection ("FADP"), the CCPA and other U.S. state privacy laws, in each case as amended or replaced.

"EEA" means the European Economic Area.

"GDPR" means Regulation (EU) 2016/679.

"Restricted Transfer" means a transfer of Customer Personal Data from the EEA, the United Kingdom or Switzerland to a country that is not the subject of an adequacy decision applicable to that transfer.

"SCCs" means the standard contractual clauses annexed to European Commission Implementing Decision (EU) 2021/914 of 4 June 2021, as completed in Section 8 and Annex IV.

"Security Incident" means a Personal Data Breach affecting Customer Personal Data.

"Sub-processor" means a third party engaged by Usign to process Customer Personal Data.

"UK Addendum" means the International Data Transfer Addendum to the EU Commission Standard Contractual Clauses issued by the UK Information Commissioner under section 119A of the Data Protection Act 2018, version B1.0.

"UK GDPR" has the meaning given in the Data Protection Act 2018.

3. Roles of the parties

3.1 Allocation. With respect to Customer Personal Data:

(a) where Customer is a Controller, Customer is the Controller and Usign is the Processor;

(b) where Customer is itself a Processor acting on behalf of a third-party controller — which is the ordinary position for an integrator embedding Usign in its own product, including under Section 4 of the Terms of Service — Customer is the Processor and Usign is the Sub-processor; and

(c) for the purposes of the CCPA and comparable U.S. state laws, Customer is the Business (or a Service Provider) and Usign is a Service Provider (or, as applicable, a sub-contracted Service Provider).

3.2 Usign as Controller. Usign is an independent Controller of account, billing, support, security-log and website data described in its Privacy Policy. That processing is governed by the Privacy Policy and applicable law, not by this DPA, and Usign does not act on Customer's instructions in respect of it.

3.3 Customer's authority. Where Section 3.1(b) applies, Customer warrants that it has the third-party controller's authority to enter into this DPA on that controller's behalf, to give the instructions in Section 4, and to appoint Usign and its Sub-processors. Customer will make this DPA available to that controller on request.

4. Processing of Customer Personal Data

4.1 Instructions. Usign will process Customer Personal Data only on Customer's documented instructions, including with regard to transfers, unless required to do otherwise by law to which Usign is subject. In that case, Usign will inform Customer of that legal requirement before processing, unless the law prohibits it on important grounds of public interest.

4.2 What constitutes an instruction. The following are Customer's complete and documented instructions: (a) this DPA and the Agreement; (b) Customer's use and configuration of the features of the Service, including creating and sending Contracts, adding Signers, configuring templates, allow-listing iframe origins, connecting integrations and authorising AI agents; (c) instructions given through the API or the MCP endpoint using Customer's credentials; and (d) any further written instruction the parties agree. Usign may charge for, or decline, an instruction that requires material work outside the Service as documented.

4.3 Unlawful instructions. Usign will notify Customer without undue delay if, in its reasonable opinion, an instruction infringes Data Protection Laws, and may suspend performance of that instruction until it is confirmed, withdrawn or amended. Usign is not obliged to conduct a legal review of Customer's instructions.

4.4 Details of processing. The subject matter, duration, nature and purpose of the processing, the types of Personal Data and the categories of Data Subjects are set out in Annex I.

4.5 Customer's obligations. Customer warrants and undertakes that:

(a) it has, and will maintain throughout the term, a lawful basis for the processing of Customer Personal Data, including its disclosure to Usign and its Sub-processors and its transfer to the United States;

(b) it has provided all notices and obtained all consents required under Data Protection Laws, including to the Signers it designates;

(c) the Signer names and email addresses it supplies are accurate, and it will not send a Contract to a person who has no connection to the transaction;

(d) it will not include in Customer Data any special categories of Personal Data under Article 9 GDPR, criminal-offence data under Article 10 GDPR, government identifier numbers, payment card data subject to PCI DSS, protected health information subject to HIPAA, or Personal Data of children under 16, unless the parties have agreed in writing in advance on additional safeguards; and

(e) it is responsible for the accuracy, quality and legality of Customer Personal Data and for the means by which it acquired it.

4.6 Prohibited processing (CCPA and U.S. state laws). Usign will not: (i) Sell or Share Customer Personal Data; (ii) retain, use or disclose it for any purpose other than performing the Service and the business purposes specified in this DPA and the Agreement, including not for its own commercial purposes; (iii) retain, use or disclose it outside the direct business relationship between the parties; or (iv) combine it with Personal Data received from or on behalf of another person, except as permitted by the CCPA for a Service Provider. Usign certifies that it understands these restrictions and will comply with them. Usign does not use Customer Personal Data to train, fine-tune or improve machine-learning models, and does not permit its Sub-processors to do so on its behalf. Usign will notify Customer if it determines it can no longer meet its obligations as a Service Provider.

4.7 Aggregated and de-identified data. Usign may generate aggregated or de-identified data from the operation of the Service, and will not attempt to re-identify it, will maintain it in de-identified form, and will contractually oblige any recipient to the same. Such data is not Customer Personal Data.

5. Confidentiality and personnel

5.1 Usign will ensure that persons authorised to process Customer Personal Data are subject to an appropriate obligation of confidentiality, whether contractual or statutory, that survives the end of their engagement.

5.2 Usign will limit access to Customer Personal Data to personnel who need it to provide, secure or support the Service, will apply least-privilege access, and will revoke access promptly on role change or departure.

5.3 Usign will ensure that such personnel receive appropriate training on their data-protection and security responsibilities.

6. Security

6.1 Measures. Usign will implement and maintain the technical and organisational measures set out in Annex II, taking into account the state of the art, the costs of implementation, the nature, scope, context and purposes of processing, and the risk to Data Subjects, as required by Article 32 GDPR.

6.2 Changes to measures. Usign may update the measures in Annex II provided it does not materially reduce the overall level of security. Material changes are published with the sub-processor and security documentation.

6.3 Customer's own measures. Customer is responsible for its own security configuration and use of the Service, including credential and API-key hygiene, key rotation, allow-listed iframe origins, permissions granted to integrations and AI agents, and prompt removal of Authorized Users who leave. Customer will assess whether the measures in Annex II meet its requirements, including its obligations under Article 32 GDPR.

6.4 Current limitations. Usign discloses, so that Customer may take it into account in its own risk assessment, that as at the effective date of this DPA Usign does not hold a SOC 2 or ISO/IEC 27001 attestation, does not offer multi-factor authentication for Authorized Users, and signs documents using a self-signed certificate with signing key material held in its hosting provider's encrypted environment-variable store.

7. Sub-processors

7.1 General authorisation. Customer gives Usign general written authorisation to engage Sub-processors, subject to this Section. The current list of Sub-processors, including each one's role, processing location and transfer mechanism, is published at https://usign.co/legal/subprocessors and reproduced at Annex III.

7.2 Notice of changes. Usign will give at least 30 days' notice before adding or replacing a Sub-processor, by updating that page and by email to Customers who have subscribed to notices at legal@usign.co. Customer is responsible for subscribing and for keeping its notification address current.

7.3 Objection. Customer may object to a new Sub-processor within 30 days of notice, on reasonable and documented data-protection grounds. The parties will discuss the objection in good faith, and Usign will use reasonable efforts to make available a change in the Service, or to recommend a commercially reasonable alternative, that avoids the objected-to processing. If no such option is available within 30 days, Customer may terminate the affected part of the Service on written notice, without penalty, and receive a pro-rata refund of prepaid, unused fees for the terminated portion. Termination on this basis is Customer's sole remedy.

7.4 Emergency engagement. Usign may engage a new Sub-processor without advance notice where necessary to address a security or availability emergency, and will notify affected Customers promptly afterwards, with the reason.

7.5 Flow-down and responsibility. Usign will impose on each Sub-processor, by written contract, data-protection obligations no less protective than those in this DPA, including the obligations in Sections 4 to 6 and the transfer obligations in Section 8. Usign remains fully liable to Customer for the performance of each Sub-processor's obligations.

7.6 Not Sub-processors. The following are not Sub-processors of Usign, and Usign is not responsible for their processing: (a) an AI assistant, agent or model provider that Customer authorises to access its Workspaces, including through the MCP endpoint — Customer directs that disclosure and is responsible for its own agreement with that provider; (b) endpoints and systems to which Customer directs data, including webhook receivers; and (c) other third-party services Customer connects.

8. International transfers

8.1 Transfer mechanism. Where a Restricted Transfer occurs under this DPA, the parties agree that:

(a) the SCCs apply, incorporated into this DPA and completed as set out in Section 8.2 and Annexes I to III;

(b) for transfers subject to the UK GDPR, the SCCs apply as varied by the UK Addendum, completed as set out in Annex IV; and

(c) for transfers subject to the FADP, the SCCs apply with the adaptations in Section 8.4.

8.2 SCC module selection and options. The SCCs are completed as follows:

SCC provisionElection
ModuleModule Two (Controller to Processor) where Customer is a Controller. Module Three (Processor to Processor) where Customer is a Processor acting for a third-party controller. Modules One and Four do not apply.
Clause 7 (docking clause)Included.
Clause 9 (use of sub-processors)Option 2 — General written authorisation. The notice period for changes is 30 days, as set out in Section 7.2.
Clause 11(a) (independent dispute resolution body)The optional language is not included.
Clause 13 (supervisory authority)As specified in Annex I.C.
Clause 17 (governing law)Option 1 — the law of France.
Clause 18(b) (choice of forum)The courts of France.
Annex I, II and III of the SCCsAnnexes I, II and III of this DPA respectively.

The data exporter is Customer; the data importer is Usign. For Module Three, the third-party controller's instructions reach Usign through Customer, and Customer's warranty in Section 3.3 applies.

8.3 Signature of the SCCs. By entering into this DPA, each party is deemed to have signed the SCCs, including their Annexes, as of the effective date of this DPA. Where a countersigned copy is executed under Section 1.5, that execution constitutes signature of the SCCs.

8.4 Swiss adaptations. For transfers subject to the FADP: references to the GDPR are to be understood as references to the FADP; the competent supervisory authority is the Swiss Federal Data Protection and Information Commissioner; the term "Member State" must not be interpreted to exclude Data Subjects in Switzerland from suing for their rights in their place of habitual residence; and references to EU Member State law are to be understood as references to Swiss law where the FADP applies.

8.5 Data Privacy Framework. Where Usign or a Sub-processor is certified under the EU–US Data Privacy Framework, the UK Extension or the Swiss–US Data Privacy Framework, and the transfer falls within the scope of that certification, the parties may rely on it as the transfer mechanism, in which case the SCCs apply only to transfers not covered.

8.6 Government access requests. Usign will, unless legally prohibited: notify Customer of any legally binding request from a public authority for disclosure of Customer Personal Data; challenge a request that appears unlawful or overbroad, including by seeking interim measures; disclose only the minimum amount of data lawfully required; and document its assessment. Where Usign is prohibited from notifying Customer, it will use reasonable efforts to obtain a waiver and will publish transparency information to the extent lawful. Usign confirms that it has no reason to believe that laws applicable to it prevent it from fulfilling its obligations under the SCCs.

8.7 EU and UK representatives. Usign has appointed a representative under Article 27 GDPR, identified in Annex I.A. Usign has not appointed a representative under Article 27 UK GDPR: it does not offer the Service to UK-established customers. A Signer in the United Kingdom may nonetheless be sent a document at Customer's direction, in which case Usign processes that Signer's personal data as Customer's Processor and on Customer's instructions; the UK Addendum at Annex IV is completed so that a transfer subject to the UK GDPR has a mechanism if one arises.

9. Assistance to Customer

9.1 Data Subject requests. Taking into account the nature of the processing, Usign will assist Customer by appropriate technical and organisational measures, insofar as possible, to respond to requests to exercise Data Subject rights. The Service provides Customer's administrators with direct access to Customer Personal Data in its Workspaces, which Customer will use in the first instance.

9.2 Requests received by Usign. If Usign receives a request from a Data Subject relating to Customer Personal Data, it will not respond substantively except to acknowledge the request and to direct the Data Subject to Customer, and will notify Customer without undue delay, unless prohibited by law or unless Customer has authorised Usign to respond.

9.3 Signer erasure. Because an executed instrument cannot be rewritten without destroying its evidentiary value, Usign operates the specific erasure procedure in Schedule 1. Customer, as Controller, remains responsible for determining the lawful basis on which a Signed Document is retained after an erasure request, and for responding to the Data Subject.

9.4 Other assistance. Taking into account the nature of processing and the information available to it, Usign will provide reasonable assistance to Customer with: security of processing (Article 32); notification of Personal Data Breaches to supervisory authorities and Data Subjects (Articles 33 and 34); data protection impact assessments (Article 35); and prior consultation with a supervisory authority (Article 36). Usign will make available the information necessary to demonstrate compliance with Article 28.

9.5 Costs. Assistance under this Section is provided at no charge where the request is reasonable in scope and frequency. Usign may charge a reasonable fee, notified in advance, for assistance that is materially beyond that — including bespoke engineering work, repeated bulk exports, or support for a Data Subject request volume that is disproportionate to Customer's use of the Service.

10. Security Incidents

10.1 Notification. Usign will notify Customer without undue delay, and in any event within 48 hours, after becoming aware of a Security Incident affecting Customer Personal Data. Notice will be sent to Customer's administrative contacts and, where Customer has provided one, its designated security contact.

10.2 Content. The notification will describe, to the extent known and as it becomes known: the nature of the incident and the categories and approximate number of Data Subjects and records affected; the likely consequences; the measures taken or proposed to address it and mitigate its effects; and a contact point. Usign will provide updates as the investigation progresses.

10.3 Cooperation. Usign will take reasonable steps to contain, investigate and remediate the incident, will preserve relevant evidence, and will cooperate with Customer's own notification obligations to supervisory authorities and Data Subjects.

10.4 No admission. Notification is not, and will not be construed as, an acknowledgement of fault or liability.

10.5 Customer notification obligations. Customer is responsible for determining whether an incident requires notification to a supervisory authority or Data Subjects, and for making that notification. Usign will not notify Customer's Data Subjects or a supervisory authority on Customer's behalf without Customer's prior written agreement, unless required by law.

10.6 Reporting to Usign. Customer will report a suspected incident affecting the Service to security@usign.co without undue delay.

11. Audits and compliance evidence

11.1 Documentation. On written request, and no more than once in any 12-month period (unless required by a supervisory authority or following a confirmed Security Incident affecting Customer Personal Data), Usign will provide: its then-current security documentation; a completed security questionnaire, using Usign's standard responses where the questions are equivalent; the information necessary to demonstrate compliance with Article 28 GDPR; and, once available, any third-party attestation or certification report it holds.

11.2 Audits. Where the documentation under Section 11.1 does not reasonably satisfy Customer's obligations under Data Protection Laws, or where a supervisory authority requires it, or following a confirmed Security Incident affecting Customer Personal Data, Customer or an independent auditor mandated by Customer may conduct an audit of Usign's processing, subject to: at least 30 days' written notice; the auditor being bound by confidentiality obligations and not being a competitor of Usign; the audit being conducted during normal business hours, at Customer's cost, without unreasonable disruption to Usign's business; a scope limited to systems and documentation relevant to the processing of that Customer's Personal Data; and no access to another customer's data, to Usign's premises where that would risk the confidentiality of another customer, or to source code, cryptographic key material or secret stores.

11.3 Findings. Audit findings are the Confidential Information of both parties. Usign will remediate confirmed material findings within a reasonable period, and the parties will agree a remediation plan.

11.4 SCC Clause 8.9. This Section 11 sets out the parties' agreed arrangements for the purposes of Clause 8.9 of the SCCs, and satisfies Usign's obligations under it.

12. Deletion and return

12.1 On termination. Following termination or expiry of the Agreement, Usign will, at Customer's election, delete or return Customer Personal Data in accordance with Section 12 of the Terms of Service: Customer may request an export for 30 days after termination, after which Usign will delete or de-identify Customer Personal Data within a further 90 days. Customer's election must be made within the 30-day export window; absent an election, Usign will delete.

12.2 Exceptions. Usign may retain Customer Personal Data to the extent, and for as long as: (a) required by applicable law, in which case Usign will isolate it, protect it and process it no further; (b) it is contained in backups, which purge on their own cycle as described in the Privacy Policy (currently 7 days for database point-in-time recovery and 30 days for storage object versions); or (c) it is contained in Audit Trail entries, which are append-only, are retained after the deletion of the related Contract or Workspace, and are redacted rather than deleted on a valid erasure request, as described in Schedule 1. Customer acknowledges and instructs this retention as necessary for the establishment, exercise and defence of legal claims and for the integrity of the electronic signature records the Service produces.

12.3 Certification. Usign will confirm deletion in writing on request.

13. Liability

13.1 Cap. Each party's liability arising out of or relating to this DPA, whether in contract, tort or under any other theory, is subject to the exclusions and limitation of liability in Section 14 of the Terms of Service. Liability under this DPA and under the Agreement is aggregated, and a single cap applies across both — there is no separate or additional cap for claims under this DPA.

13.2 No double recovery. Neither party may recover twice for the same loss under this DPA, the SCCs and the Agreement.

13.3 SCCs preserved. Nothing in this Section limits a Data Subject's rights as a third-party beneficiary under the SCCs, or either party's liability to a Data Subject or a supervisory authority under Data Protection Laws, where that liability cannot be limited by agreement.

14. General

14.1 Term. This DPA takes effect as set out in Section 1.4 and continues until Usign has ceased all processing of Customer Personal Data. Sections that by their nature should survive do so.

14.2 Governing law. This DPA is governed by the law stated in Section 16 of the Terms of Service (the State of New York), except that the SCCs are governed by the law of France as elected in Section 8.2, and except where Data Protection Laws require otherwise.

14.3 Severability. If a provision of this DPA is held invalid or unenforceable, the remainder continues in effect, and the parties will replace the affected provision with a valid one that most closely achieves its intent.

14.4 Notices. Notices under this DPA are sent to legal@usign.co (for Usign) and to Customer's administrative contacts in the Service (for Customer). Data Subject enquiries: privacy@usign.co. Security incidents: security@usign.co.

Schedule 1 — Signer erasure procedure

This Schedule describes how Usign gives effect to an erasure request concerning a Signer, and is provided so that Customer can answer a Data Subject accurately. It reflects the actual behaviour of the Service.

What is erased. On Customer's documented instruction, Usign:

  • sets the Signer's email address to null;
  • replaces the Signer's display name with "Redacted Signer";
  • deletes the IP address, user agent and approximate geographic location recorded against the Signer;
  • deletes any decline reason recorded;
  • deletes the corresponding IP address, user agent and geolocation fields in the related Audit Trail entries;
  • records the erasure timestamp; and
  • withholds the erased Signer's signature from the live signing page, so that a counterparty loading the page can no longer see it.

What is retained, and why.

  • The Signed Document (PDF) is not modified. It remains the immutable record of an executed agreement and continues to show the name and signature as at the time of signing. Altering it would destroy the evidentiary value the document exists to provide, and would break the content hash that allows its integrity to be verified.
  • Field values entered by the Signer remain, because they are agreed terms of the contract rather than incidental identifiers.
  • The Audit Trail entry recording that events occurred remains, with the personal data within it redacted as above. The record of what happened survives; the record of who, from where, on what device does not.
  • An audit entry recording the erasure itself is written, identifying the operator and the timestamp.

Roles. Usign performs this procedure as Processor, on Customer's instruction. Customer, as Controller, decides whether the request is valid, whether an exemption applies, and on what lawful basis the Signed Document is retained — ordinarily Article 17(3)(e) GDPR (establishment, exercise or defence of legal claims) or a legal retention obligation. Usign will notify the Signer that the erasure is complete where Customer asks it to.

Timing. Usign will action a valid documented instruction within 10 business days, so that Customer can meet its own one-month deadline under Article 12(3) GDPR. As at the effective date of this DPA the procedure is executed manually by a Usign operator; a self-service flow is planned.

Annex I — Description of the processing

A. List of parties

Data exporter

NameThe Customer, as identified in the Agreement (name, address and contact details as recorded in Customer's Usign account)
ContactThe administrative contact(s) designated in Customer's Usign account
Activities relevant to the transferUse of the Usign electronic signature platform to create, send, execute, store and administer documents
RoleController (Module Two) or Processor (Module Three), as set out in Section 3.1
Signature and dateDeemed signed on acceptance of the Agreement (Section 8.3)

Data importer

NameUpfluence Inc., operating the Usign service
Address214 Sullivan Street, Suite 3A, New York, NY 10012, United States
Contactlegal@usign.co (contractual); privacy@usign.co (data protection); security@usign.co (security)
EU representative (Art. 27 GDPR)Upfluence SAS, 33 quai Arloing, 69009 Lyon, France. Contact: privacy@usign.co
UK representative (Art. 27 UK GDPR)None appointed. Usign does not offer the Service to UK-established customers — see Section 8.7
Activities relevant to the transferProvision of the Usign electronic signature platform: document rendering and storage, delivery of signing requests, identity verification of Signers by email and one-time passcode, PDF generation and cryptographic signing, audit logging, webhooks and API access
RoleProcessor (Module Two) or Sub-processor (Module Three)
Signature and dateDeemed signed on acceptance of the Agreement (Section 8.3)

B. Description of the transfer

Categories of Data Subjects

  • Customer's Authorized Users — employees, contractors and personnel of Customer and its affiliates who hold accounts in Customer's Organization.
  • Signers — individuals invited by Customer to review, complete, sign or decline a document, who do not hold accounts. In Usign's typical deployment these include creators, freelancers, contractors, brand and agency counterparties.
  • Individuals whose personal data appears in the content of a document — for example a named beneficiary, signatory of a counterparty, or contact person — determined solely by Customer.
  • Customer's billing and administrative contacts.

Categories of Personal Data

CategoryDetail
Identity dataName, display name, email address; job title or role where Customer includes it
Account data (Authorized Users)Email address, hashed password, profile image where uploaded, workspace membership and role, authentication method, account event timestamps
Document contentAny personal data Customer places in a template, contract or merge field, and any value a Signer enters in a fillable field
Signature dataDrawn, typed or uploaded signature images; initials; signatures held on file for reuse within a Workspace
Signing and audit dataEvent type and timestamp for each event (sent, opened, viewed, one-time passcode requested and verified, email re-affirmed, signed, declined, voided, expired, downloaded); IP address; browser user agent; approximate geographic location (country and region) derived from IP address; document content hash
Integration dataExternal references supplied by Customer, API key and agent identifiers, webhook delivery metadata
Billing dataBilling contact and email, plan and usage records, payment status, card brand and last four digits (full card data is held by Stripe, not Usign)

Special categories of data. None are intended or required. Customer undertakes not to include them without prior written agreement (Section 4.5(d)). Where Customer does so notwithstanding that undertaking, the restrictions and safeguards in Annex II apply to that data as they do to all Customer Personal Data.

Frequency of the transfer. Continuous, for the duration of the Agreement.

Nature and purpose of the processing. Hosting, storage, rendering, transmission, cryptographic hashing and signing, email delivery, identity verification of Signers, audit logging, backup, support and security operations — in each case for the purpose of providing the Service to Customer.

Duration of the processing. For the term of the Agreement plus the retention and deletion periods in Section 12 and in the Privacy Policy. Audit Trail entries are retained beyond that period as set out in Section 12.2(c).

Transfers to Sub-processors. Subject matter, nature and duration as set out in Annex III.

C. Competent supervisory authority

For the purposes of Clause 13 of the SCCs, the competent supervisory authority is:

(a) where the data exporter is established in an EEA Member State — the supervisory authority of that Member State;

(b) where the data exporter is not established in an EEA Member State but falls within the territorial scope of the GDPR under Article 3(2) and has appointed a representative under Article 27 — the supervisory authority of the Member State in which that representative is established;

(c) where the data exporter is not established in an EEA Member State and has not appointed a representative under Article 27 — the supervisory authority of the Member State in which the Data Subjects whose personal data is transferred are located.

For transfers subject to the UK GDPR, the competent authority is the Information Commissioner's Office. For transfers subject to the FADP, it is the Federal Data Protection and Information Commissioner.

Annex II — Technical and organisational measures

These are the measures referred to in Clause 8.5 of the SCCs and Article 32 GDPR, described so that a reviewer can verify them rather than take them on faith.

Pseudonymisation and encryption of personal data

  • All data in transit is encrypted: HTTPS only, TLS 1.2 or higher, plain HTTP rejected at the edge, HSTS on all responses.
  • All data at rest is encrypted, including the PostgreSQL database, stored PDF artifacts and signature images, and backups.
  • Passwords are stored only as bcrypt hashes. API keys are stored only as SHA-256 hashes and compared in constant time.
  • Personal data in Audit Trail entries can be redacted in place without destroying the underlying record (Schedule 1).

Confidentiality, integrity, availability and resilience of processing systems

  • Tenant isolation is enforced at the database layer by row-level security policies, in addition to application-level authorisation. Every policy combines an authenticated-user check with a workspace-membership check; neither alone is sufficient. Cross-tenant denial is covered by automated regression tests for every tenant-scoped table.
  • Three redundant authorisation layers: route-level authentication, application-level permission checks, and database row-level security — so that a defect in one is caught by another.
  • Role-based access control within Organizations and Workspaces; least-privilege operator access to production.
  • Session cookies are HttpOnly, Secure, SameSite=Lax; session tokens are short-lived and refreshed on use.
  • Signing tokens are signed JWTs, validated against a server-held secret with a token identifier cross-checked against the signer record.
  • Strict content security policy on signing pages, with no inline scripts; iframe embedding permitted only from origins a Workspace has explicitly allow-listed, and denied by both X-Frame-Options and CSP frame-ancestors otherwise.
  • All API input validated against schemas; uploads verified by magic bytes, content type and size; parameterised queries throughout.
  • Rate limiting per API key, per user session, per Workspace, and a separate limit on one-time passcode requests per Signer.
  • Append-only Audit Trail: no update or delete path exists, and entries are written only through a privileged server-side helper, so that events cannot be forged or removed by a user or by application code.
  • Document integrity: a SHA-256 content hash is embedded in every Signed Document; signing is performed server-side only; a Signed Document can be regenerated deterministically from stored data and its hash compared.

Availability and restoration

  • Managed PostgreSQL with encrypted daily backups and point-in-time recovery (currently 7 days); storage object version history (currently 30 days).
  • A Signed Document can be regenerated from the database if a stored artifact is lost.
  • Restore drills are performed periodically.

Testing, assessment and evaluation of effectiveness

  • Automated test suite gating every change, including cross-tenant denial tests for tenant-scoped tables and integration tests requiring an authorisation-failure case for each API route.
  • Application error monitoring and alerting; authentication event logs; request logs correlated by request identifier.
  • Code review before merge; migrations promoted through development and staging before production; no untested change applied to the production database.
  • Documented incident-response runbooks covering suspected data breach, signing-key compromise, abuse, and loss of a critical infrastructure provider, including a customer-communication template.

User identification and authorisation

  • Email-and-password or Google sign-in for Authorized Users; per-workspace API keys with scopes; OAuth authorisation for AI agents, revocable by Customer at any time.
  • Signers are identified by control of an email address, verified by re-affirmation on hosted signing pages or by a one-time passcode in embedded contexts.
  • Multi-factor authentication for Authorized Users is not currently available (Section 6.4).

Data minimisation, quality and retention

  • A Signer's identity is scoped to a single Workspace: the same email address signing for two customers produces two unlinked records, and no cross-customer profile is built.
  • Secrets are never written to logs; document content and personal data are excluded from application logging by policy.
  • Retention periods are published in the Privacy Policy and implemented as described in Section 12.

Accountability and governance

  • Production secrets held in a restricted secret store with documented rotation procedures and defined rotation triggers.
  • Written agreements with all Sub-processors, including data-protection terms and transfer mechanisms.
  • Personnel bound by confidentiality obligations.
  • No SOC 2 or ISO/IEC 27001 attestation is held at the effective date of this DPA (Section 6.4).

Measures applying to Sub-processors. Usign selects Sub-processors that offer sufficient guarantees under Article 28(1) GDPR, imposes the obligations in Section 7.5 by written contract, and reviews their security documentation and attestations before engagement and on material change.

Annex III — Sub-processors

The authoritative, current list is published at https://usign.co/legal/subprocessors. As at the effective date of this DPA:

Sub-processorRolePersonal data processedLocationTransfer mechanism
Supabase, Inc. (USA)Managed PostgreSQL database, authentication, object storage for signed PDFs and signature images, encrypted backupsAll Customer Personal Data: document content, Signer identity and field values, signature images, Audit Trail, account dataUnited States (us-east-1)SCCs / DPF as applicable
Vercel, Inc. (USA)Application hosting, edge network, serverless compute, request loggingAll data passing through the application; technical logs including IP addressesUnited States (iad1)SCCs / DPF as applicable
Resend — Plus Five Five, Inc. (USA)Transactional email: invitations, signing requests, one-time passcodes, completed-document notifications, authentication emailsRecipient name and email address, message content, delivery metadataUnited StatesSCCs
Stripe, Inc. (USA)Payment processing, card vaulting, metered billingBilling contact details, transaction and usage records (full card data held by Stripe)United States and Stripe's global infrastructureSCCs / DPF as applicable
Functional Software, Inc. (Sentry) (USA)Application error monitoring and diagnosticsTechnical and diagnostic data; identifiers incidentally present in an error contextUnited StatesSCCs / DPF as applicable
Google LLC (USA)Google sign-in for Authorized Users who choose itName, email address, Google account identifierUnited States and Google's global infrastructureSCCs / DPF as applicable

Nature, subject matter and duration of each Sub-processor's processing: as necessary to provide the function described above, for the term of Usign's engagement of that Sub-processor.

Annex IV — UK International Data Transfer Addendum

This Annex completes the UK Addendum (version B1.0) for transfers subject to the UK GDPR. The SCCs, as completed in this DPA, apply as varied by the UK Addendum.

Table 1 — Parties

ExporterImporter
Start dateThe effective date of this DPAThe effective date of this DPA
Parties' detailsCustomer, as identified in the Agreement and Annex I.AUpfluence Inc., 214 Sullivan Street, Suite 3A, New York, NY 10012, United States
Key contactCustomer's administrative contact(s) in the Servicelegal@usign.co / privacy@usign.co

Table 2 — Selected SCCs, Modules and Selected Clauses

The version of the Approved EU SCCs to which this Addendum is appended is the SCCs incorporated at Section 8, including the Module and clause options selected in Section 8.2 (Module Two or Module Three as applicable; Clause 7 included; Clause 9 Option 2 with a 30-day notice period; Clause 11(a) optional language not used; Clause 17 Option 1, law of France; Clause 18(b) courts of France — read, for UK transfers, as varied by Section 15 of the UK Addendum).

Table 3 — Appendix Information

Appendix itemLocation
Annex 1A: List of partiesAnnex I.A of this DPA
Annex 1B: Description of transferAnnex I.B of this DPA
Annex II: Technical and organisational measuresAnnex II of this DPA
Annex III: List of sub-processorsAnnex III of this DPA

Table 4 — Ending this Addendum when the Approved Addendum changes

Either party may end this Addendum as set out in Section 19 of the UK Addendum: Importer and Exporter.

Signature (optional — see Section 1.5)

This DPA applies without signature under Section 1.4. Where a countersigned copy is required, the parties execute below, and by doing so also execute the SCCs and the UK Addendum, including their Annexes.

Upfluence Inc. (Usign)

Name: ____________________ Title: ____________________
Signature: ____________________ Date: ____________________

Customer

Entity name: ____________________
Name: ____________________ Title: ____________________
Signature: ____________________ Date: ____________________