Security and privacy

Your agreements, protected

Agreements carry personal data and business secrets. This page explains, in plain language, how NextSigner stores, protects and processes them β€” and what that means for your GDPR obligations.

Encryption

All traffic is encrypted with TLS. Documents are stored encrypted at rest (AES-256), and encryption keys are managed separately from the data.

Stored in the EU

Documents and data are stored in the EU/EEA. Nothing is moved outside the region for storage, and access is limited to what the service needs to run.

Tamper-evident signatures

Every signature is tied to a SHA-256 checksum of the exact document signed, a timestamp, the signer's email verified with a one-time code, and a full event log: sent, opened, signed. Change one byte of the document and the checksum reveals it.

Access control

Workspaces are strictly separated. Roles and permissions control what each user can do, API keys are scoped and revocable, and signing links are personal and verified with one-time codes.

GDPR

Built for your GDPR obligations

When you send an agreement, you are the data controller for your counterparties' personal data β€” NextSigner is your data processor. We only process data on your instructions, and the obligations are set out in our data processing agreement.

Deleting a document deletes it from storage, not just from view. When you close your account, your workspace data is deleted after a documented retention window.

What you get as a customer
  • βœ“ Data processing agreement (DPA) as part of the terms β€” read it here
  • βœ“ Storage and processing in the EU/EEA
  • βœ“ Real deletion of documents and accounts
  • βœ“ Signature evidence you can present in a dispute
  • βœ“ A public list of sub-processors, with notice before changes
  • βœ“ Export of your own data
Sub-processors

Who processes data on our behalf

We use a small number of carefully chosen suppliers. Each one is bound by a data processing agreement, and we notify customers before adding or replacing a sub-processor.

Supplier Purpose Region
Amazon Web Services Document storage and infrastructure EU (Stockholm)
Anthropic AI features: template import and drafting. Document content is sent only when you use an AI feature, and is not used to train models. USA (with EU standard contractual clauses)
Email provider Delivery of signing links, one-time codes and notifications EU
AI, transparently

What the AI sees β€” and what it never sees

AI is used for one thing: turning your documents into reusable templates and drafting contract text. The content of a template is sent to the AI supplier only when you press an AI button β€” never automatically. Signed documents, your party register and your archive are never sent to the AI. API traffic to the AI supplier is not used for model training.

Questions about security or a DPA?

We answer security questionnaires and sign data processing agreements for customers who need their own. Get in touch.