Last updated: January 6, 2026
This Data Processing Agreement ("DPA") forms part of the Terms of Service between Zignt ("Processor," "we," "us") and the Customer ("Controller," "you") who uses our Service to process personal data. This DPA applies to the processing of personal data on behalf of the Controller pursuant to GDPR, UK GDPR, CCPA, and other applicable data protection laws.
For the purposes of this DPA, the following definitions apply:
This DPA applies to the processing of Personal Data by Zignt in connection with the provision of the electronic signature Service as described in the Terms of Service.
Zignt processes Personal Data for the following purposes:
The following categories of Personal Data may be processed:
Personal Data relates to the following categories of Data Subjects:
Processing will continue for the duration of the Service agreement and for such additional period as required for legal compliance, backup, and audit purposes.
As the Processor, Zignt agrees to:
Process Personal Data only on documented instructions from the Controller, unless required by applicable law. The Terms of Service and this DPA constitute documented instructions for processing.
Ensure that persons authorized to process Personal Data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality.
Implement appropriate technical and organizational measures to ensure a level of security appropriate to the risk, including:
Not engage another processor (Sub-processor) without prior written authorization from the Controller. The Controller hereby provides general authorization for Zignt to engage Sub-processors listed in Section 6, subject to notification of changes.
Assist the Controller in responding to requests from Data Subjects to exercise their rights under applicable data protection laws, taking into account the nature of processing.
Notify the Controller without undue delay (and in any event within 72 hours) upon becoming aware of a Personal Data breach, and provide reasonable assistance in investigating and mitigating the breach.
At the Controller's choice, delete or return all Personal Data upon termination of the Service, unless retention is required by applicable law.
Make available to the Controller information necessary to demonstrate compliance with this DPA and allow for audits, including inspections, by the Controller or an auditor mandated by the Controller.
As the Controller, you agree to:
Personal Data may be transferred to and processed in countries outside the European Economic Area (EEA), United Kingdom, or Switzerland. Where such transfers occur, Zignt ensures appropriate safeguards are in place:
For transfers of Personal Data from the EEA to countries without an adequacy decision, the parties agree that the Standard Contractual Clauses (Module 2: Controller to Processor) are incorporated by reference and form part of this DPA.
For transfers from the UK, the International Data Transfer Addendum to the EU Commission Standard Contractual Clauses applies.
The Controller authorizes Zignt to engage the following Sub-processors:
| Sub-processor | Purpose | Location |
|---|---|---|
| Cloudinary | Document and image storage | USA / EU |
| Neon | Database hosting (PostgreSQL) | USA |
| Resend | Transactional email delivery | USA |
| Stripe | Payment processing | USA |
| Vercel | Application hosting and CDN | USA / Global |
| Google Cloud | Google Drive integration (when enabled) | USA / Global |
| OpenAI | AI-powered contract date extraction | USA |
Zignt will notify the Controller at least 14 days before adding or replacing a Sub-processor by updating this page and, where the Controller has subscribed to notifications, by email. The Controller may object to such changes within 14 days of notification.
Zignt ensures that each Sub-processor is bound by data protection obligations at least as protective as those set out in this DPA.
Zignt implements the following technical and organizational security measures:
In the event of a Personal Data breach affecting the Controller's data, Zignt will:
Zignt will provide reasonable assistance to the Controller in complying with its breach notification obligations under applicable law.
Zignt will assist the Controller in responding to Data Subject requests to exercise their rights under applicable law, including:
If Zignt receives a Data Subject request directly, Zignt will promptly notify the Controller unless prohibited by law.
Upon reasonable request, Zignt will make available to the Controller information necessary to demonstrate compliance with this DPA. The Controller may conduct an audit (or appoint a third-party auditor) with reasonable advance notice, during normal business hours, and subject to confidentiality obligations.
Where available, Zignt may provide third-party certifications or audit reports (such as SOC 2 reports) as evidence of compliance in lieu of a direct audit.
This DPA remains in effect for as long as Zignt processes Personal Data on behalf of the Controller.
Upon termination of the Service, the Controller may request the return or deletion of Personal Data. Zignt will comply with such request within 30 days, except where retention is required by applicable law.
Each party's liability under this DPA is subject to the limitations of liability set forth in the Terms of Service, except that such limitations do not apply to data protection fines or penalties imposed by a supervisory authority as a result of a party's breach of applicable data protection laws.
For questions about this DPA or data protection matters, please contact: