Effective 7 September 2026 · version 2026-09-07
Data processing agreement
Our processor commitments to customers under the GDPR and UK GDPR.
This agreement is part of the terms of service between the customer ("you", the controller) and ShareSign, Inc., 169 Madison Ave STE 15132, New York, NY 10016, USA ("ShareSign", the processor) and applies whenever ShareSign processes personal data on your behalf. Capitalised terms have the meaning given in the GDPR.
1. Subject matter and duration
ShareSign processes personal data in documents you upload and about the people you send them to, for as long as you use the service and until the data is deleted under section 8.
2. Nature and purpose
Storage, transmission, display, signature capture, audit recording, and delivery of documents for electronic signature, at your instruction through the product.
3. Types of data and data subjects
Names, email addresses, signature images, network addresses, device information, timestamps, and any personal data contained in documents. Data subjects are your staff, your customers, your counterparties, and anyone you send documents to.
4. Your instructions
ShareSign processes personal data only on your documented instructions, which are given through the product. If ShareSign believes an instruction breaks data protection law, it will tell you.
5. Confidentiality and security
People with access to personal data are bound by confidentiality. ShareSign implements the measures on the security page, including encryption in transit and at rest, short-lived file access links, an append-only hash-chained audit trail, access control by workspace and role, and regional data storage. ShareSign will not reduce these measures during the agreement.
6. Sub-processors
You authorise the sub-processors listed on the sub-processor page. ShareSign will announce changes at least 30 days before they take effect by updating that page and notifying workspace owners by email. You may object on reasonable grounds; if no solution is found, you may end the affected service and receive a refund for the unused period.
7. International transfers
Where a sub-processor is outside the EEA or the UK, transfers rely on adequacy decisions or the European Commission's standard contractual clauses (and the UK addendum), which ShareSign has in place with each such sub-processor. European workspaces keep documents and signatures in the EU.
8. Deletion and return
You can export all workspace data as a machine-readable archive and delete it at any time from settings. On termination, ShareSign deletes your personal data within 30 days unless the law requires retention, in which case it is kept only for that purpose.
9. Assistance
ShareSign helps you meet data subject requests, security obligations, breach notifications, and impact assessments, using the tools in the product where possible and otherwise on request.
10. Breach notification
ShareSign will notify you without undue delay, and in any case within 48 hours, after becoming aware of a personal data breach affecting your data, with the information you need to meet your own obligations.
11. Audit
ShareSign provides the information needed to demonstrate compliance, including third-party assessments when available, and allows audits by you or an auditor you mandate on reasonable notice, at most once a year unless a breach or a regulator requires more.
12. Liability and precedence
Liability is as set in the terms of service. If this agreement conflicts with the terms, this agreement prevails for data protection matters.
Signed copies of this agreement, with your company details filled in, are available on request through the support form.