This DPA is automatically incorporated into the Terms of Service. If you require negotiated terms, contact legal@doksign.no.
1. Definitions
Terms defined in the GDPR have the same meaning here. "Customer" = the controller. "Doksign" = the processor. "Personal Data" = personal data processed under the Service.
2. Subject matter, duration, nature, purpose
Subject matter: provision of the Doksign Service. Duration: while the agreement is in force, plus any post-termination obligations below. Nature and purpose: hosting, processing and transmission of Customer documents and recipient interaction telemetry, for the purpose of electronic signature collection and evidence retention.
3. Categories of data and subjects
- Data subjects: Customer's authorised users; Customer's recipients (signatories or other invited parties); other parties whose data Customer includes in documents.
- Categories of data: identifying data (name, email), business contact data, signature image or text, IP address, device and user-agent, document body and metadata, audit-trail metadata, one-time-code attempt records.
4. Obligations of the controller (Customer)
Customer warrants it has a lawful basis for processing all Personal Data uploaded to or routed through the Service, including for any special category data, and that recipients have been informed as required by applicable law.
5. Obligations of the processor (Doksign)
5.1 Processing instructions
Doksign shall process Personal Data only on documented Customer instructions (including this DPA, the Terms, and configurations made in the Service), unless required otherwise by EU or Member State law. Where so required, Doksign will inform Customer before processing, unless that law prohibits the notification on important grounds of public interest.
5.2 Confidentiality
Personnel with access are bound by confidentiality.
5.3 Security (Art. 32)
Doksign implements the technical and organisational measures set out in Annex II.
5.4 Sub-processors
Customer authorises the sub-processors listed at the trust centre. Doksign will give at least 30 days' notice of additions or replacements; Customer may object on reasonable grounds and, if not resolved, terminate the affected portion of the Service.
5.5 Data subject requests
Doksign will assist Customer to respond to data subject requests (Art. 12–22). Self-service tooling in the Service covers most cases; bespoke assistance may incur fees per the Terms.
5.6 Security assistance & DPIA
Doksign will assist Customer with Art. 32–36 obligations to the extent of the information available to Doksign, taking into account the nature of processing.
5.7 Breach notification
Doksign will notify Customer without undue delay and within 24 hours of becoming aware of a personal data breach affecting Customer's data, with the information then known. Updates will follow as the investigation progresses.
5.8 Audit
Customer may request a remote audit annually with reasonable notice and at Customer expense. Doksign holds no third-party security certification at this time and does not claim one; where a certification is later obtained, its report replaces this paragraph.
5.9 Deletion or return
On termination, Doksign will, at Customer's choice, return or delete Personal Data per the schedule in our privacy notice and applicable law, except where retention is required (for example Bokføringsloven for billing records).
The evidence chain is treated separately and deliberately: it is anonymised rather than deleted, so that the record of what happened to a document survives the erasure of the personal data inside it. See Annex II.
6. International transfers
Default: EU only. Where any transfer outside the EEA is necessary, the Standard Contractual Clauses (Module 3, processor-to-processor) shall apply, supplemented by appropriate technical and organisational measures per EDPB Recommendations 01/2020.
7. Liability
Back-to-back with the Terms. Nothing in this DPA limits a data subject's rights under the GDPR.
8. Term and termination
Co-terminous with the Terms.
9. Governing law
Norwegian law, subject to mandatory EU privacy law.
Annex I — Description of processing
I-A — Parties
Controller: Customer (per signup form). Processor: Signatur Labs AS, Oslo, Norway.
I-B — Transfer description
See § 3 above. Frequency: continuous. Duration: term of agreement plus retention period.
I-C — Competent supervisory authority
Datatilsynet (Norway).
Annex II — Technical and organisational measures
These are the measures implemented in the Service. Measures that depend on how a given deployment is operated — backup schedule, key management, network edge — are marked as such and are confirmed per deployment before this DPA is offered. Annex II is a contractual commitment, so nothing is listed here that the software does not do.
Access control. Every route denies by default: authentication is enforced globally and a route is public only where it explicitly declares itself so, with the resulting public surface pinned in the repository and reviewed on change. Authorisation is role-based (owner, admin, member) and scoped to a workspace on every request. Two-factor authentication (TOTP and passkeys) is available to every user and can be enforced for all members of a workspace by its owner.
Evidence integrity. Every document event is SHA-256 hashed and chained to the one before it, in an append-only log that is never edited or purged. A scheduled job re-verifies every chain and raises an alarm on any break. The chain is exportable as JSON with its verification verdict, and a completed document is sealed with a hash anyone can check without an account.
Separation of legal and operational records. The evidence chain is distinct from the operational audit log. The operational log has a retention purge; the evidence chain does not, and outlives the document it describes. On erasure the chain is redacted rather than deleted, so integrity survives the removal of personal data.
Data in transit. TLS between all endpoints.
Abuse controls. Rate limiting on authentication and on the signing routes. One-time codes are single-use, budgeted, and never written to the evidence chain.
Logging. Structured application logs with request correlation. Request bodies for the signing scope are excluded from capture, because those carry signer names, drawn signatures and one-time codes.
Confirmed per deployment. Encryption at rest, object-storage configuration, backup schedule and restore testing, key management and rotation, network edge and WAF, and personnel controls are properties of the hosting environment rather than of the software. They are agreed and evidenced per deployment before this DPA is executed.
Annex III — Sub-processors
Current list at the trust centre, with name, purpose, region and transfer mechanism.
Annex IV — Processing instructions
Customer instructs Doksign to process Personal Data to: (a) host customer documents and recipient data; (b) deliver signing flows; (c) maintain audit and evidence; (d) deliver transactional email; (e) provide support; (f) perform billing; (g) detect and respond to abuse and security incidents. Additional instructions may be set in workspace configuration (retention, identity level, branding).