Data processing addendum
The terms that apply when Signitri processes personal data on your instructions, written for GDPR and POPIA. It sits on top of the terms of use.
Working draft. Not reviewed by counsel, and not binding.
This page is a draft written to hold the shape of the final addendum. No lawyer has reviewed it, Signitri has not adopted it, and it creates no rights or obligations for you or for Signitri. It is not an executed contract, and it must not be relied on in a vendor assessment or a records-of-processing exercise. Passages in square brackets are open questions that must be answered before publication. Corrections go to hello@signitri.com.
1. How this addendum applies
This addendum applies where Signitri processes personal data on your instructions: the contents of the documents you send, and the data of the people you ask to sign them. It forms part of the terms of use. Where the two disagree about personal data, this addendum governs.
[TO BE CONFIRMED: how this addendum is executed — accepted with the terms of use, or signed as a separate counterpart; and whether an enterprise customer may substitute their own paper.]
2. Definitions
“Controller”, “processor”, “personal data”, “processing”, “data subject”, “special categories of personal data” and “personal data breach” carry the meanings given in GDPR Article 4. “Responsible party”, “operator”, “personal information” and “special personal information” carry the meanings given in POPIA section 1. Nothing here restates them, because a paraphrase of a statutory definition is only a way of getting it wrong.
3. Roles
You are the controller, and the responsible party under POPIA. Signitri is the processor, and the operator under POPIA.
For its own account, billing and service-security records, Signitri is a controller in its own right. Those are covered by the privacy notice, not by this addendum.
4. Scope and instructions
Signitri processes personal data only to provide the service, and only on your documented instructions. Your use of the product is an instruction: uploading a document, naming a recipient, setting a signing order, and sending it are all instructions to process the personal data they contain.
Identity verification is a standing instruction and cannot be disabled. If you send a document through Signitri, you are instructing Signitri to collect a government photo ID and a selfie from each signer and to have that checked. Section 12 sets out what that requires of you.
If Signitri believes an instruction breaches data protection law, it will say so rather than carry it out silently.
5. What Signitri undertakes
- To process personal data only as set out in section 4.
- To bind everyone with access to a duty of confidentiality.
- To apply appropriate technical and organizational measures, described in Annex 2.
- To engage subprocessors only on the terms in section 6.
- To assist you with data subject requests, as set out in section 8.
- To notify you of a personal data breach, as set out in section 9.
- To assist with data protection impact assessments and prior consultation, so far as the information sits with Signitri.
- To return or delete personal data at the end, as set out in section 11.
6. Subprocessors
You give general written authorization for Signitri to engage subprocessors. The current list is published at subprocessors. ThisIsMe, which performs identity verification, is a subprocessor and is central to the service — a customer who objects to ThisIsMe is objecting to the product.
Signitri imposes data protection obligations on each subprocessor that are no less protective than those in this addendum, and remains responsible for their performance.
[TO BE CONFIRMED: how customers are notified of a new or replaced subprocessor, the notice period before the change takes effect, the window for objecting, and what happens if an objection cannot be resolved.]
7. International transfers
Signitri, Inc. is a US company and personal data may be processed in the United States and in the countries where its subprocessors operate.
[TO BE CONFIRMED: the transfer mechanism for each corridor — standard contractual clauses and which modules, the UK international data transfer addendum, the POPIA section 72 basis, and whether a transfer impact assessment is available to customers.]
8. Data subject requests
A signer’s request goes to you, because you decided why their data was collected. Signitri passes on any request it receives directly and gives you the tools and information needed to answer it.
[TO BE CONFIRMED: response times for assistance, whether assistance is charged for beyond a threshold, and how a deletion request is handled where the data sits inside a sealed evidence pack that a party may need to rely on.]
9. Personal data breaches
Signitri notifies you without undue delay after becoming aware of a personal data breach affecting personal data processed under this addendum, and provides the information you need to meet your own notification duties.
[TO BE CONFIRMED: the committed notification window in hours, the contact channel used, and what the first notice must contain.]
10. Audits and evidence
[TO BE CONFIRMED: which third-party reports or certifications Signitri makes available, whether an on-site audit is permitted and on what notice, how often, who bears the cost, and whether any of it is limited to particular plans.]
11. Return and deletion
At the end of the service, Signitri returns or deletes the personal data it processes on your behalf, at your choice, unless the law requires it to be kept.
One category needs a decision rather than a default. A sealed evidence pack is the record of a legal act, and the parties to a signed document may need it years later. [TO BE CONFIRMED: whether evidence packs and their identity verification records survive deletion of an account, for how long, on what legal ground, and who can still reach them.]
12. What you undertake
- That you have a lawful basis for the personal data you put into Signitri, including the identity data collected from the signers you name.
- That you have given those people the notice their law requires, before they are asked to hand over an ID and a photograph of their face.
- That the recipient details you enter are accurate, so a document is not delivered to the wrong person.
- That your instructions do not require Signitri to breach data protection law.
[TO BE CONFIRMED: whether the customer must obtain explicit consent for biometric processing in its own name, or whether Signitri collects it in the signing flow — and what the sender is contractually responsible for either way. This allocation is the single most consequential open question in this document.]
Annex 1 — details of processing
Annex 2 — security measures
Two measures can be stated now. The signing backend never receives the document itself, which limits how far a file travels inside the system. And the audit log is append-only: entries are not edited afterward, including by Signitri, because a log that can be rewritten is not evidence.
[TO BE CONFIRMED: the full schedule of technical and organizational measures — encryption in transit and at rest with key management, access control and least privilege, who can view an ID image or a selfie, segregation of environments, logging and monitoring, secure development, vulnerability management, penetration testing cadence, business continuity and disaster recovery, personnel screening and training, and supplier management. It must match the security overview and the answers given in customer security questionnaires.]