Legal
Terms of Service Privacy Policy Data Processing Addendum Sub-processors E-signature consent
On this page
1. Current sub-processors 2. Notice of changes 3. Sub-processor obligations

Usign Sub-processors

Under legal review. Effective 8 September 2026; not yet countersigned by counsel. Please confirm the current version with legal@usign.co before relying on it.

Version 1.0 — Effective 8 September 2026 — Last updated 8 September 2026

This page lists the third parties Usign (Upfluence Inc.) engages to process personal data on behalf of its customers, as required by Article 28(2) GDPR and by the Usign Data Processing Addendum ("DPA"). It is referenced by the Privacy Policy and by the DPA, and it is the authoritative list.

Why this page exists as a public URL. Enterprise security reviews and DPAs both require a durable, dated location where the list can be checked and changes tracked. Keep it at a stable URL and keep the "Last updated" date honest — a stale sub-processor page is a finding in every security questionnaire.

1. Current sub-processors

Sub-processorRole in the ServicePersonal data processedProcessing locationTransfer mechanism
Supabase, Inc. (USA)Managed PostgreSQL database, authentication, object storage for signed PDFs and signature images, encrypted backupsAll Customer Data: document content, signer name/email/field values, signature images, audit trail, account dataUnited States (us-east-1)SCCs / DPF as applicable
Vercel, Inc. (USA)Application hosting, edge network, serverless compute, request loggingAll data passing through the application; technical logs including IP addressesUnited States (iad1)SCCs / DPF as applicable
Resend — Plus Five Five, Inc. (USA)Transactional email: invitations, signing requests, one-time passcodes, completed-document copies, auth emailsRecipient name and email address, message content, PDF attachments, delivery metadataUnited StatesSCCs
Stripe, Inc. (USA)Payment processing, card vaulting, metered billingBilling contact details, payment card data (held by Stripe, not Usign), transaction and usage recordsUnited States and Stripe's global infrastructureSCCs / DPF as applicable
Functional Software, Inc. (Sentry) (USA)Application error monitoring and diagnosticsTechnical and diagnostic data; identifiers incidentally present in an error contextUnited StatesSCCs / DPF as applicable
Google LLC (USA)Google sign-in for Authorized Users who choose itName, email address, Google account identifierUnited States and Google's global infrastructureSCCs / DPF as applicable

Not sub-processors.

  • AI assistants and agents a customer connects (for example through Usign's MCP endpoint). Where a customer authorizes an AI assistant to act in its Workspaces, that customer directs the disclosure to a provider it selected. The provider is the customer's own vendor and is governed by the customer's agreement with it, not by Usign's DPA. Usign discloses no Workspace data to any AI provider on its own initiative.
  • A customer's own webhook endpoints and systems, which receive data at the customer's direction.
  • Vendors that do not process customer personal data, such as Usign's internal password manager and source-code hosting.


2. Notice of changes

Usign will give customers who have entered into the DPA at least 30 days' advance notice before adding a new sub-processor or replacing an existing one, by updating this page and by email to the customer's designated contact where the customer has subscribed to notifications.

A customer may object to a new sub-processor on reasonable, documented data-protection grounds within 30 days of notice. Usign will work in good faith to provide an alternative or a mitigating measure. If none can be agreed, the customer may terminate the affected part of the Service, without penalty, on written notice — and receive a pro-rata refund of prepaid, unused fees for the terminated portion.

Usign may engage a new sub-processor without advance notice where necessary to address a security or availability emergency, and will notify affected customers promptly afterwards.

To subscribe to sub-processor change notices: email legal@usign.co with the address that should receive them.

3. Sub-processor obligations

Each sub-processor is engaged under a written agreement that imposes data-protection obligations no less protective than those in the Usign DPA, including: processing only on Usign's instructions and only for the purpose of providing its service; confidentiality; appropriate technical and organizational security measures; assistance with data subject requests and incidents; restrictions on onward transfer; and deletion or return of data at the end of the engagement. Usign remains responsible to its customers for its sub-processors' performance.