Usign Sub-processors
Under legal review. Effective 8 September 2026; not yet countersigned by counsel. Please confirm the current version with legal@usign.co before relying on it.
This page lists the third parties Usign (Upfluence Inc.) engages to process personal data on behalf of its customers, as required by Article 28(2) GDPR and by the Usign Data Processing Addendum ("DPA"). It is referenced by the Privacy Policy and by the DPA, and it is the authoritative list.
Why this page exists as a public URL. Enterprise security reviews and DPAs both require a durable, dated location where the list can be checked and changes tracked. Keep it at a stable URL and keep the "Last updated" date honest — a stale sub-processor page is a finding in every security questionnaire.
1. Current sub-processors
| Sub-processor | Role in the Service | Personal data processed | Processing location | Transfer mechanism |
|---|---|---|---|---|
| Supabase, Inc. (USA) | Managed PostgreSQL database, authentication, object storage for signed PDFs and signature images, encrypted backups | All Customer Data: document content, signer name/email/field values, signature images, audit trail, account data | United States (us-east-1) | SCCs / DPF as applicable |
| Vercel, Inc. (USA) | Application hosting, edge network, serverless compute, request logging | All data passing through the application; technical logs including IP addresses | United States (iad1) | SCCs / DPF as applicable |
| Resend — Plus Five Five, Inc. (USA) | Transactional email: invitations, signing requests, one-time passcodes, completed-document copies, auth emails | Recipient name and email address, message content, PDF attachments, delivery metadata | United States | SCCs |
| Stripe, Inc. (USA) | Payment processing, card vaulting, metered billing | Billing contact details, payment card data (held by Stripe, not Usign), transaction and usage records | United States and Stripe's global infrastructure | SCCs / DPF as applicable |
| Functional Software, Inc. (Sentry) (USA) | Application error monitoring and diagnostics | Technical and diagnostic data; identifiers incidentally present in an error context | United States | SCCs / DPF as applicable |
| Google LLC (USA) | Google sign-in for Authorized Users who choose it | Name, email address, Google account identifier | United States and Google's global infrastructure | SCCs / DPF as applicable |
Not sub-processors.
- AI assistants and agents a customer connects (for example through Usign's MCP endpoint). Where a customer authorizes an AI assistant to act in its Workspaces, that customer directs the disclosure to a provider it selected. The provider is the customer's own vendor and is governed by the customer's agreement with it, not by Usign's DPA. Usign discloses no Workspace data to any AI provider on its own initiative.
- A customer's own webhook endpoints and systems, which receive data at the customer's direction.
- Vendors that do not process customer personal data, such as Usign's internal password manager and source-code hosting.
2. Notice of changes
Usign will give customers who have entered into the DPA at least 30 days' advance notice before adding a new sub-processor or replacing an existing one, by updating this page and by email to the customer's designated contact where the customer has subscribed to notifications.
A customer may object to a new sub-processor on reasonable, documented data-protection grounds within 30 days of notice. Usign will work in good faith to provide an alternative or a mitigating measure. If none can be agreed, the customer may terminate the affected part of the Service, without penalty, on written notice — and receive a pro-rata refund of prepaid, unused fees for the terminated portion.
Usign may engage a new sub-processor without advance notice where necessary to address a security or availability emergency, and will notify affected customers promptly afterwards.
To subscribe to sub-processor change notices: email legal@usign.co with the address that should receive them.
3. Sub-processor obligations
Each sub-processor is engaged under a written agreement that imposes data-protection obligations no less protective than those in the Usign DPA, including: processing only on Usign's instructions and only for the purpose of providing its service; confidentiality; appropriate technical and organizational security measures; assistance with data subject requests and incidents; restrictions on onward transfer; and deletion or return of data at the end of the engagement. Usign remains responsible to its customers for its sub-processors' performance.