Loading...
Loading...
This DPA outlines how SignQuick processes personal data on behalf of our customers in compliance with GDPR.
Last updated: March 1, 2026
Fully compliant with GDPR Articles 28-36
All data encrypted with AES-256-GCM end-to-end
Data stored exclusively on EU-hosted infrastructure
Data deleted within 30 days of account termination
SignQuick processes personal data solely for the purpose of providing e-signature services as instructed by the data controller (customer). Processing includes document storage, signature capture, signer identification, and audit trail generation.
Personal data processed includes: signer names, email addresses, IP addresses, browser metadata, signature images, and document content. Processing activities include encryption, secure storage, transmission to authorized recipients, and audit logging.
SignQuick implements industry-leading security measures including AES-256-GCM end-to-end encryption, zero-knowledge architecture, TLS 1.3 for data in transit, role-based access controls, and continuous infrastructure monitoring. All encryption keys are derived client-side.
SignQuick engages the following sub-processors for service delivery. Customers are notified of changes to sub-processors at least 30 days in advance. Each sub-processor is bound by contractual data protection obligations.
SignQuick assists data controllers in fulfilling data subject requests including access, rectification, erasure, portability, and restriction of processing. Requests are processed within 72 hours of receipt.
In the event of a personal data breach, SignQuick will notify the data controller without undue delay and no later than 48 hours after becoming aware of the breach. Notification includes the nature of the breach, affected data categories, and remedial measures taken.
| Provider | Purpose | Location |
|---|---|---|
| Vercel | Application hosting & CDN | EU (Frankfurt) |
| Neon | Database hosting | EU (Frankfurt) |
| Stripe | Payment processing | EU (Dublin) |
Enterprise customers can request a customized Data Processing Agreement.
Contact Us