Data Processing Agreement
This agreement is part of our Terms of Service. It applies when you use SignEdge to handle documents that contain other people’s personal data.
SignEdge is provided by AurumCodeWorks. Who we are, our address and contact details: Legal information.
What this covers
It covers the personal data in the documents you upload and send, in the field values signers enter, and in the signer details you provide, together “customer data”. It doesn’t cover our own account, billing and security data, which our Privacy Policy explains. The words “controller”, “processor” and “personal data” mean what they mean in the UK GDPR.
Who does what
For customer data you (or your organisation) are the controller and we are your processor. You decide why and how the data is used. We only process it on your documented instructions, which are these terms and your use of the service. If you use SignEdge purely for personal or household purposes, the UK GDPR may not apply to you, but we handle the data the same way.
The processing
- Subject matter and purpose: storing documents, collecting signatures and sending the emails needed to do that.
- Duration: until you delete the document or close your account (see the retention section of the Privacy Policy).
- Data subjects: you, your team, your signers, and anyone named in your documents.
- Types of data: names, email addresses, signatures and typed entries, document content, and the times documents were opened and signed. You decide what the documents contain, so they may include other categories of data.
Our commitments
- We process customer data only on your instructions, unless the law requires otherwise, in which case we’ll tell you first where we’re allowed to.
- Everyone with access to it is bound by confidentiality.
- We apply appropriate security: encryption in transit, hashed credentials, access limited to the person who runs SignEdge, and optional two-step verification for accounts.
- We’ll help you respond to requests from people exercising their data rights, and with security, breach notification and impact assessments, taking into account what we can see. Much of this you can do yourself in your account.
- We’ll let you check we’re complying by giving you the information you reasonably need.
- We’ll tell you if we think an instruction of yours breaks data protection law.
- You are responsible for making sure you may lawfully upload each document and for telling the people in it.
Sub-processors
You agree that we may use sub-processors to run the service. They are our hosting and storage provider, and our email delivery provider. Each is bound by terms that give the same protection as this agreement. We keep a list of them and will email you at least 30 days before adding or replacing one. If you object on reasonable data protection grounds you can close your account and we’ll delete your data.
International transfers
Our sub-processors may process data outside the UK. We only use them where the UK recognises the destination as adequate or where approved safeguards, such as the ICO’s International Data Transfer Agreement or Addendum, are in place.
Personal data breaches
If we become aware of a breach affecting customer data we’ll tell you without undue delay, and aim to do so within 48 hours, with what we know about what happened, what data is involved and what we’re doing about it.
When your account ends
When you close your account we delete customer data straight away; our backups roll off within 30 days. Before you do, download anything you need to keep. If the law requires us to keep any of it we’ll protect it and only use it for that purpose.