In short
- We process customer personal data only on the customer’s documented instructions.
- The EU Standard Contractual Clauses and the UK Addendum are included by reference.
- We tell customers about a personal data breach without undue delay, and within 48 hours of confirming it.
- We give notice before adding a subprocessor, and customers can object.
Scope and precedence
This data processing agreement (“DPA”) forms part of the terms of service between Nubesti LLC and each business customer. It applies when Nubesti processes personal data inside customer content on the customer’s behalf, under the GDPR, the UK GDPR, the Swiss Federal Act on Data Protection, the California Consumer Privacy Act and other U.S. state privacy laws, the Brazilian LGPD, and any other data protection law that applies (together, “data protection laws”).
If this DPA conflicts with the terms of service, this DPA controls for personal data. If it conflicts with the Standard Contractual Clauses, the clauses control. A customer who needs a countersigned copy can request it at [email protected].
Roles
The customer is the controller, or a processor acting for its own client, and Nubesti is the processor or service provider. Nubesti is a separate controller for account, billing, security, and support data, as described in the privacy policy.
Details of the processing
This section is the description of the processing required by article 28 of the GDPR:
| Item | Description |
|---|---|
| Subject matter | Providing inSigner: hosting documents, sending signing invitations, collecting signatures, keeping evidence records, and running the add-ons the customer turns on |
| Duration | The term of the subscription, plus the export and deletion periods in this DPA |
| Nature and purpose | Storage, transmission, display, signature collection, hashing, messaging, identity verification, support, and security |
| Data subjects | The customer’s users, signers, and people named in documents |
| Personal data | Names, email addresses, phone numbers, job titles, signatures, IP addresses, device details, timestamps, and any personal data the customer puts in documents |
| Special categories | Biometric data and identity document data, only when the customer turns on KYC. Other special categories only if the customer includes them in documents |
| Frequency | Continuous, while the service is used |
Customer instructions
Nubesti processes customer personal data only on the customer’s documented instructions. The terms of service, this DPA, and the customer’s configuration of the workspace are the complete instructions. Other instructions must be in writing to [email protected]. We will tell the customer if we believe an instruction breaks data protection laws, or if the law requires processing that goes beyond the instructions, unless that law prohibits telling them.
The customer is responsible for having a lawful basis for the processing, for the notices it gives to signers, and for the accuracy of the data it provides.
Confidentiality
Everyone who processes customer personal data for Nubesti is bound by a duty of confidentiality and accesses the data only when their work requires it.
Security measures
Nubesti maintains technical and organizational measures appropriate to the risk, including:
| Area | Measures |
|---|---|
| Encryption | TLS for data in transit, and encryption at rest by the storage providers |
| Access control | Least privilege, individual accounts, multi-factor authentication for administrative access, and prompt removal of access |
| Integrity | SHA-256 document hashes and an ordered event record for each signing |
| Availability | Managed infrastructure on a global network, and backups on a rolling cycle |
| Application security | Dependency updates, code review, bot protection, and rate limiting |
| Monitoring and incidents | Logging, alerting, and an incident response process |
| Providers | Written data protection terms and a security review before a subprocessor is used |
Subprocessors
The customer gives Nubesti a general authorization to use the subprocessors listed on the subprocessors page. Each subprocessor is bound by written terms that protect personal data at least as well as this DPA, and Nubesti remains responsible for its subprocessors.
We will update the subprocessors page, and email customers who ask to be notified at [email protected], at least 15 days before a new subprocessor starts processing customer personal data, except in an emergency. The customer may object on reasonable data protection grounds within that period. If we cannot resolve the objection, the customer may terminate the affected service and receive a refund of prepaid fees for the unused period.
Assistance
Taking into account the nature of the processing, Nubesti will help the customer answer requests from data subjects, carry out data protection impact assessments, consult supervisory authorities, and meet its security obligations. If we receive a request directly from a data subject about customer content, we will pass it to the customer and will not answer it ourselves, unless the customer asks us to.
Personal data breaches
Nubesti will notify the customer without undue delay, and in any case within 48 hours, after confirming a personal data breach that affects customer personal data. The notice will describe, as far as known, the nature of the breach, the categories and approximate number of people and records concerned, the likely consequences, and the measures taken or proposed. We will update the customer as we learn more, and we will not notify authorities or data subjects on the customer’s behalf unless the customer asks us to or the law requires it.
Return and deletion
When the subscription ends, the customer has 30 days to export customer content. After that, Nubesti deletes customer personal data from active systems, and backups are overwritten within 90 days, unless the law requires us to keep it. On request, we confirm deletion in writing.
Audits
Nubesti will provide the information reasonably needed to show compliance with this DPA, including answers to a security questionnaire once a year. If the customer or its supervisory authority needs an audit that this information cannot satisfy, it may be carried out by an independent auditor bound by confidentiality, with at least 30 days’ notice, during business hours, without access to other customers’ data, and at the customer’s cost unless the audit finds a material breach.
International transfers
Where customer personal data is transferred from the European Economic Area to Nubesti or a subprocessor in a country without an adequacy decision, the Standard Contractual Clauses approved by Commission Implementing Decision (EU) 2021/914 apply and are incorporated by reference: module two where the customer is a controller, and module three where it is a processor. Clause 7 does not apply. Under clause 9, option 2 applies with the notice period in this DPA. The optional wording in clause 11 does not apply. Under clause 17 the clauses are governed by Irish law, and under clause 18 the courts of Ireland have jurisdiction. The annexes are completed by this DPA and the subprocessors page.
For the United Kingdom, the International Data Transfer Addendum issued by the Information Commissioner applies. For Switzerland, the clauses apply with references to the Swiss Federal Act on Data Protection and the Federal Data Protection and Information Commissioner. Where a recipient is certified under the EU-U.S. Data Privacy Framework, that framework may be relied on instead. For other countries, the parties use the mechanism that the local law requires.
U.S. state privacy laws
For the California Consumer Privacy Act and similar state laws, Nubesti is a service provider or processor. Nubesti will not sell or share customer personal data, will not retain, use, or disclose it outside the direct business relationship or for any purpose other than providing the service, and will not combine it with personal data from other sources, except as those laws allow. Nubesti will comply with those laws, give the same level of protection they require, and tell the customer if it can no longer meet its obligations. The customer may take reasonable steps to stop and remedy unauthorized use.
Other laws and government requests
Where the LGPD, the Colombian Law 1581 of 2012, the Argentine Law 25,326, the Mexican federal data protection law, the South African POPIA, or a similar law applies, the obligations of this DPA apply to the customer personal data covered by that law. Requests from public authorities for customer personal data are handled as described in the government requests policy.