Data processing addendum
The Article 28 contract that applies when DropTheDoc processes personal data on your behalf, including the Standard Contractual Clauses and the annexes they require.
- Effective
- 26 July 2026
- Version
- 1.0
This addendum forms part of the terms of service between [your registered company name] ("we", the processor) and the account holder ("you", the controller). It applies automatically whenever we process personal data on your behalf, and no signature is needed for it to take effect. If your organisation requires a countersigned copy, see clause 15.
Which parts of your data this covers
This addendum covers the personal data inside the documents you send and the recipient details you supply, where you are the controller and we act on your instructions. It does not cover your own account data, where we are the controller in our own right, or the audit trail, where we are an independent controller because we keep it to meet our own legal and evidentiary obligations. Clause 2 of the privacy policy sets out the full split.
1.Definitions
Data Protection Law means every law applicable to the processing under this addendum, including Regulation (EU) 2016/679 (GDPR), the UK GDPR and the Data Protection Act 2018, the Swiss Federal Act on Data Protection, the Digital Personal Data Protection Act, 2023 and the rules under it, the Information Technology Act, 2000 and the SPDI Rules, 2011, and the California Consumer Privacy Act as amended.
Controller, processor, subprocessor, data subject, personal data, processing and personal data breach have the meanings given in the GDPR. Data Fiduciary, Data Processor and Data Principal have the meanings given in the DPDP Act, and correspond to controller, processor and data subject respectively.
SCCs means the Standard Contractual Clauses annexed to Commission Implementing Decision (EU) 2021/914 of 4 June 2021.
Customer Personal Data means personal data contained in customer content that we process on your behalf.
2.Roles of the parties
You are the controller of Customer Personal Data and we are your processor. Where you are yourself a processor for another controller, we are a subprocessor and this addendum applies as though references to controller were to that other controller, with you responsible for having the authority to appoint us.
You warrant that you have a lawful basis for the processing you instruct, that you have given every required notice and obtained every required consent, and that your instructions comply with Data Protection Law. You are responsible for the accuracy, quality and legality of Customer Personal Data and for how you obtained it.
3.Processing on documented instructions (Article 28(3)(a))
We will process Customer Personal Data only on your documented instructions, including on transfers to a third country, unless required to do otherwise by law to which we are subject, in which case we will tell you of that requirement before processing unless the law prohibits it on important grounds of public interest.
Your instructions are: the terms of service, this addendum, and the configuration choices and actions you take in the product. Providing the service in accordance with them is the full scope of processing you have authorised.
We will tell you if, in our opinion, an instruction infringes Data Protection Law. We may suspend the affected processing until the instruction is corrected or withdrawn, and doing so is not a breach of the terms.
We do not sell Customer Personal Data, do not share it for cross-context behavioural advertising, do not use it for our own purposes, and do not use it to train machine learning models.
4.Confidentiality of personnel (Article 28(3)(b))
We limit access to Customer Personal Data to personnel who need it to provide the service or to comply with the law. Everyone with access is bound by a written confidentiality obligation that survives the end of their engagement, and is trained on their obligations. Access is logged and reviewed, and is revoked when no longer required.
5.Security of processing (Article 28(3)(c) and Article 32)
We implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk, having regard to the state of the art, the costs of implementation, and the nature, scope, context and purposes of processing. Those measures are set out in Annex II at clause 17, and described in operational detail on the security page.
We may update the measures as technology develops, provided the updates do not materially reduce the overall level of protection.
6.Subprocessors (Article 28(3)(d) and Article 28(2))
You give us general written authorisation to appoint subprocessors, subject to the conditions in this clause. The current list is at subprocessors.
- We will give you at least 30 days' notice of any intended addition or replacement, by email to workspace owners and by updating the subprocessor page.
- You may object on reasonable data protection grounds within that period. We will work with you in good faith to address the objection.
- If we cannot resolve it, you may terminate the affected part of the service without penalty and receive a pro-rata refund of prepaid fees for the unused period.
- We impose on every subprocessor, by written contract, data protection obligations no less protective than those in this addendum.
- We remain fully liable to you for the performance of each subprocessor's obligations.
7.Assisting with data subject rights (Article 28(3)(e))
The product gives you direct control over Customer Personal Data. You can view, correct, export and delete documents, recipients, contacts and field values yourself, which will usually be the fastest way to answer a request.
Where a request cannot be answered through the product, we will provide reasonable assistance by appropriate technical and organisational measures, insofar as possible, taking into account the nature of the processing.
If a data subject contacts us directly about Customer Personal Data, we will not respond to the substance ourselves. We will forward the request to you without undue delay and tell the individual to contact you, unless you have instructed us otherwise or the law requires us to respond.
8.Assisting with Articles 32 to 36 (Article 28(3)(f))
Taking into account the nature of the processing and the information available to us, we will assist you in ensuring compliance with your obligations on security, breach notification, data protection impact assessments and prior consultation.
- Breach notification.
- We will notify you without undue delay, and in any event within 48 hours, after becoming aware of a personal data breach affecting Customer Personal Data. The notification will describe the nature of the breach, the categories and approximate number of data subjects and records concerned, the likely consequences, the measures taken or proposed, and a contact point. Where we cannot provide everything at once we will provide it in phases as it becomes available. Notifying you is not an admission of fault.
- Impact assessments.
- We will provide the information reasonably needed for a data protection impact assessment or a transfer impact assessment. The security page and the subprocessor list are written to answer most of it without a call.
9.Deletion and return (Article 28(3)(g))
You may export Customer Personal Data at any time during the term, and for 30 days after termination, using the export tools in the product.
At the end of that 30-day window we will delete Customer Personal Data, unless a law to which we are subject requires us to keep it, in which case we will keep only what is required, for only as long as required, and will continue to protect it under this addendum.
Two exceptions you should plan for
Backups age out on their own cycle rather than being edited to remove individual records, so deleted data may persist in encrypted backups for a short period after deletion. And the hash-chained audit trail is retained with personal identifiers anonymised, because removing entries would break the chain and destroy the integrity guarantee for every other customer's documents as well as yours. Both are permitted by GDPR Article 17(3)(b) and (e).
10.Audits and information (Article 28(3)(h))
We will make available the information necessary to demonstrate compliance with Article 28, and allow for and contribute to audits, including inspections, conducted by you or an auditor you mandate.
- In the first instance we will answer a reasonable security questionnaire and provide our documentation, including the security page, which is written to serve as Annex II.
- Where that is genuinely insufficient, you may conduct an audit no more than once in any twelve-month period, on at least 30 days' written notice, during business hours, without unreasonably disrupting the service, and subject to confidentiality.
- You may audit more frequently following a personal data breach affecting your data, or where a supervisory authority requires it.
- You bear your own audit costs. We bear ours, unless the audit reveals a material breach by us, in which case we bear both.
- An auditor you mandate must not be a competitor of ours, and must sign a confidentiality undertaking.
11.International transfers
Where this addendum involves transferring personal data out of the EEA, the UK or Switzerland to a country without an adequacy decision, including to India, the following apply and are incorporated by reference:
- EEA. The SCCs. Where you are a controller and we are a processor, Module Two applies. Where you are a processor and we are a subprocessor, Module Three applies. Clause 7 (docking) applies. Under Clause 9, Option 2 (general written authorisation) applies with the 30-day notice period in clause 6 above. Under Clause 11, the optional independent dispute resolution body is not used. Under Clause 17, the SCCs are governed by the law of Ireland. Under Clause 18(b), disputes go to the courts of Ireland. Annex I and Annex II are at clauses 16 and 17 below, and Annex III is the subprocessor list.
- United Kingdom. The International Data Transfer Addendum issued by the Information Commissioner under section 119A of the Data Protection Act 2018, appended to the SCCs. Tables 1 to 3 are completed by the corresponding parts of this addendum, and in Table 4 neither party may end the Addendum as set out in Section 19.
- Switzerland. The SCCs as amended so that references to the GDPR are read as references to the Swiss Federal Act on Data Protection, the competent authority is the Federal Data Protection and Information Commissioner, and the term data subject includes legal entities where Swiss law so provides.
If the SCCs are replaced or invalidated, the parties will implement the replacement mechanism without undue delay. Where there is a conflict between the SCCs and the rest of this addendum, the SCCs prevail.
12.Indian law
For processing subject to the Digital Personal Data Protection Act, 2023, you are the Data Fiduciary and we are a Data Processor engaged under a valid contract as section 8(2) requires. We will process Customer Personal Data only under that contract, will implement reasonable security safeguards under section 8(5), and will assist you in meeting your obligations to Data Principals under sections 11 to 14 and in notifying the Data Protection Board and affected Data Principals of a breach under section 8(6).
We also observe Rule 8 of the SPDI Rules, 2011 in relation to sensitive personal data or information.
13.California
For personal information subject to the CCPA, you are the business and we are a service provider. We certify that we understand and will comply with the following restrictions:
- We will not sell or share personal information.
- We will not retain, use or disclose personal information for any purpose other than performing the services specified in the terms, or as otherwise permitted by the CCPA.
- We will not retain, use or disclose personal information outside the direct business relationship between us.
- We will not combine personal information received from you with personal information received from another source, except as the CCPA permits.
- We will notify you if we determine we can no longer meet these obligations, and you may take reasonable steps to stop and remediate unauthorised use.
14.Liability and precedence
Each party's liability under this addendum is subject to the limitation of liability in the terms of service, except where Data Protection Law does not permit that limitation, including as between the parties under the SCCs.
In case of conflict, the order of precedence is: the SCCs, then this addendum, then the terms of service.
This addendum takes effect when you accept the terms of service and continues for as long as we process Customer Personal Data.
15.Getting a signed copy
This addendum applies without signature. If your organisation's process requires a countersigned copy, email legal@dropthedoc.xyz from your account address with your full legal entity name, registered address, the name and title of your signatory, and the Annex I details in clause 16 completed for your use. We will return an executed copy. Naturally, you can sign it through DropTheDoc.
16.Annex I: details of the processing
Item
Data exporter
Detail
The account holder, acting as controller (SCC Module Two) or as processor (Module Three). Contact details are those on the account. Activities: sending documents for electronic signature.
Item
Data importer
Detail
[your registered company name], [your full registered office address], acting as processor. Contact: privacy@dropthedoc.xyz. Activities: providing the DropTheDoc electronic signature service.
Item
Categories of data subjects
Detail
The account holder's personnel and authorised users; recipients, signers, approvers and copy recipients of documents; saved contacts; and any individual whose personal data the account holder chooses to include in a document.
Item
Categories of personal data
Detail
Names, email addresses, job titles and organisation names; document contents and any personal data within them; field values entered by recipients; signature images; IP addresses, browser user-agent strings and event timestamps; and document and signature hashes.
Item
Sensitive data
Detail
Not requested or required by the service. The account holder may include it in a document at its own discretion and under its own lawful basis. Where it is included, the restrictions are the encryption, access control and confidentiality measures in Annex II, applied to all data without distinction.
Item
Frequency of transfer
Detail
Continuous, for the duration of the account.
Item
Nature and purpose of processing
Detail
Hosting, storage, encryption, transmission, display, rendering and conversion of documents; delivery of notifications by email; capture of signatures and field values; generation of completed PDFs and certificates of completion; and creation and retention of an audit trail, all for the purpose of providing an electronic signature service.
Item
Duration of processing
Detail
For the term of the account, plus the 30-day export window, subject to the retention and anonymisation rules in clause 9.
Item
Subprocessors
Detail
As listed at subprocessors, which is Annex III, with the subject matter, nature and duration of each appointment set out there.
Item
Competent supervisory authority
Detail
Determined under Clause 13 of the SCCs: the supervisory authority of the member state in which the data exporter is established, or where the exporter is not established in the EEA, the authority of the member state in which its Article 27 representative is established, or in which the data subjects are located.
17.Annex II: technical and organisational measures
The measures below are summarised here for contractual purposes and described in full on the security page, which forms part of this Annex.
Measure
Pseudonymisation and encryption
What we do
AES-256-GCM authenticated encryption of every document at rest, with the key held outside the data store; TLS in transit with HSTS; bcrypt password hashing at cost 12; session and signing tokens stored only as SHA-256 hashes.
Measure
Confidentiality
What we do
Role-based access control enforced server-side on every route; workspace-scoped data access; least-privilege administrative access with multi-factor authentication; written confidentiality obligations for all personnel.
Measure
Integrity
What we do
Append-only, hash-chained audit trail verified on read and on certificate generation; SHA-256 hashing of original and completed files; flattening of completed PDFs; schema validation of every request payload at the boundary.
Measure
Availability and resilience
What we do
Managed database with point-in-time recovery; redundant object storage; atomic, rollback-capable deployments; scheduled maintenance for reminders, expiry and token purging.
Measure
Restoring availability
What we do
Provider-level backup and restore, with recovery tested as part of deployment rollback.
Measure
Testing and evaluation
What we do
Typechecking, linting and an automated test suite gate every deployment; code review; dependency pinning and advisory monitoring; a health endpoint that surfaces configuration problems without exposing secrets.
Measure
User identification and authorisation
What we do
Individual accounts, no shared logins; revocable sessions; password change invalidates other sessions; optional OAuth 2.0 single sign-on with CSRF-protected state.
Measure
Transfer security
What we do
TLS for all transfers; documents encrypted by us before reaching storage providers, so those providers hold ciphertext; single-use, expiring, revocable signing links.
Measure
Data minimisation and retention
What we do
Only the data needed to deliver and evidence a signature; documented retention schedule; automatic purging of spent sessions and tokens; anonymisation of audit identifiers on document deletion.
Measure
Incident management
What we do
Documented response process with notification to CERT-In, the Data Protection Board of India, EEA and UK supervisory authorities and affected customers within the applicable deadlines; a published vulnerability disclosure channel with safe harbour.
Measure
Subprocessor governance
What we do
Written contracts with equivalent obligations; a published list; 30 days' notice and an objection right before any change.
Version history
- Version 1.0 · 26 July 2026
First publication.