Data Processing Agreement
Annex to the Terms of Service · pursuant to Article 28(3) of Regulation (EU) 2016/679 (the “GDPR”) · version 0.1
1. Parties and background
This Data Processing Agreement (the “Agreement”) is entered into between:
- Controller: the customer that has created a workspace in NextSigner (the “Customer”), as identified in the Customer's account details.
- Processor: NextSigner (“we”, “us”), the operator of https://netxsigner.com.
NextSigner provides a service for filling in, sending, electronically signing and archiving agreements and quotes (the “Service”). In providing the Service we process personal data on behalf of the Customer. This Agreement governs that processing and prevails over the Terms of Service in matters concerning the processing of personal data.
2. Nature, purpose and duration of the processing
We process personal data solely to provide the Service to the Customer: storing and rendering documents, sending signing requests and notifications by email, verifying signers with one-time codes, keeping event and evidence logs, archiving signed documents with expiry reminders, and — only when the Customer actively uses an AI feature — generating templates and drafts from document content. The processing lasts for as long as the Customer holds an account, and thereafter until deletion under section 9. The categories of data subjects and personal data are set out in Annex A.
3. The Customer's responsibilities and instructions
- The Customer is the controller and warrants that the processing has a valid legal basis and that data subjects have received the information required by Articles 13 and 14 of the GDPR.
- The Customer's documented instructions consist of this Agreement, the Terms of Service and the choices the Customer makes in the Service (which parties and contacts are entered, which documents are sent, when AI features are used, and so on).
- We will inform the Customer if, in our opinion, an instruction infringes the GDPR or other data protection law.
4. Our obligations as processor
- Process personal data only on documented instructions from the Customer, including with regard to transfers to third countries, unless required to do so by law to which we are subject; in that case we will inform the Customer before processing, unless the law prohibits it.
- Ensure that persons authorised to process the personal data are bound by confidentiality.
- Implement the technical and organisational measures required by Article 32 of the GDPR, at minimum those in Annex C.
- Assist the Customer, insofar as possible and taking the nature of the processing into account, in responding to requests from data subjects (access, rectification, erasure, portability and others). Requests received directly by us are forwarded to the Customer without undue delay.
- Assist the Customer in complying with Articles 32–36 of the GDPR (security, breach notification, impact assessments), taking into account the nature of the processing and the information available to us.
- Make available the information necessary to demonstrate compliance with Article 28 and allow for and contribute to audits under section 8.
5. Sub-processors
- The Customer grants a general prior authorisation for our use of sub-processors. The current list is set out in Annex B and kept up to date on our website.
- We give the Customer at least 30 days' notice before adding or replacing a sub-processor. The Customer may object on reasonable grounds within that period; if no agreement is reached, the Customer may terminate the Service with effect from the change.
- We impose on every sub-processor the same data protection obligations as in this Agreement and remain fully liable to the Customer for the sub-processor's performance.
6. Transfers to third countries
Personal data is stored and processed in the EU/EEA as the main rule. Where a sub-processor processes personal data outside the EU/EEA (see Annex B), the transfer is based on the European Commission's Standard Contractual Clauses or another valid transfer mechanism under Chapter V of the GDPR, with supplementary measures where necessary.
7. Personal data breaches
We notify the Customer without undue delay, and no later than 48 hours, after becoming aware of a personal data breach affecting the Customer's data. As far as possible, the notification contains the information the Customer needs to meet its obligations under Articles 33 and 34 of the GDPR: the nature of the breach, the categories and approximate number of data subjects concerned, the likely consequences, and the measures taken or proposed.
8. Audits
Once per year, on reasonable notice, the Customer may request documentation of our compliance with this Agreement, including completion of security questionnaires. On-site audits may be carried out by the Customer or an independent third party that is not our competitor, against coverage of our reasonable costs, and conducted so as not to disproportionately affect operations or the security of other customers.
9. Deletion and return
- The Customer may delete individual documents and data in the Service at any time. Deletion removes the data from active storage; copies in backups are rotated out within 35 days.
- Upon termination of the customer relationship we delete all personal data processed on behalf of the Customer within 90 days, unless retention is required by law. Before that deadline the Customer may export its documents and data from the Service.
- Evidence logs tied to signed documents are deleted together with the document they concern.
10. Liability, term and governing law
- The limitations of liability in the Terms of Service also apply to this Agreement, subject to mandatory law.
- This Agreement applies for as long as we process personal data on behalf of the Customer.
- This Agreement is governed by Norwegian law. Venue follows the Terms of Service.
Annex A — Subject matter of the processing
Categories of data subjects
- The Customer's users (employees and others with access to the workspace)
- The Customer's counterparties and their contact persons (signers, customers, suppliers, employees)
Categories of personal data
- Identity and contact details: name, email address, phone number, address, date of birth, job title
- The content of documents and quotes the Customer creates, sends or archives — which may include further personal data the Customer enters (for example salary and employment terms)
- Signature evidence: timestamps, verified email address, IP address, browser information and the document checksum
- Usage and event logs tied to the documents (sent, opened, signed, reminded)
Special categories: the Service is not intended for special categories of personal data (Article 9 GDPR). The Customer is responsible for the content of its own documents.
Annex B — Sub-processors
| Supplier |
Processing |
Region / transfer mechanism |
| Amazon Web Services EMEA SARL |
Document storage and infrastructure |
EU (Stockholm, eu-north-1) |
| Anthropic PBC |
AI generation of templates and contract drafts. Document content is sent only when the Customer actively uses an AI feature; API data is not used for model training. |
USA · SCC |
| Email provider |
Delivery of signing links, one-time codes and notifications |
EU |
| Twilio Inc. (only when SMS features are used) |
SMS delivery |
USA · SCC |
Annex C — Technical and organisational measures
- Encryption: TLS 1.2+ for all traffic; documents encrypted at rest (AES-256) with keys managed separately from the data (KMS).
- Access control: strictly separated workspaces (tenant isolation in the application layer), role-based access, personal signing links verified with one-time codes, scoped and revocable API keys.
- Integrity: SHA-256 checksum of every signed document, a complete per-document event log, versioned storage protected against overwriting.
- Infrastructure: private storage with no public access, least-privilege service accounts, access logging at the storage layer.
- Organisational: confidentiality obligations for personnel, access on a need-to-know basis, documented incident-response and deletion routines.
- Resilience: backups with defined recovery capability; backup copies rotated out within 35 days.
Questions about this Agreement can be sent to support@saasykit.com.