Skip to content
ProductSecurityPricingDevelopersContact
EN· English
  • EN · English
  • ES · Español
  • DE · Deutsch
  • FR · Français
  • IT · Italiano
  • PT · Português
Sign inStart free
ProductSecurityPricingDevelopersContactSign in
Home/Legal/Data processing agreement

Privacy and data

Data processing agreement

The processor terms for documents and signer data, including the EU Standard Contractual Clauses. Ask if you need a signed copy.

Updated September 22, 2026Effective September 22, 2026

On this page
  1. Scope and precedence
  2. Roles
  3. Details of the processing
  4. Customer instructions
  5. Confidentiality
  6. Security measures
  7. Subprocessors
  8. Assistance
  9. Personal data breaches
  10. Return and deletion
  11. Audits
  12. International transfers
  13. U.S. state privacy laws
  14. Other laws and government requests

In short

  • We process customer personal data only on the customer’s documented instructions.
  • The EU Standard Contractual Clauses and the UK Addendum are included by reference.
  • We tell customers about a personal data breach without undue delay, and within 48 hours of confirming it.
  • We give notice before adding a subprocessor, and customers can object.

01Scope and precedence

This data processing agreement (“DPA”) forms part of the terms of service between Nubesti LLC and each business customer. It applies when Nubesti processes personal data inside customer content on the customer’s behalf, under the GDPR, the UK GDPR, the Swiss Federal Act on Data Protection, the California Consumer Privacy Act and other U.S. state privacy laws, the Brazilian LGPD, and any other data protection law that applies (together, “data protection laws”).

If this DPA conflicts with the terms of service, this DPA controls for personal data. If it conflicts with the Standard Contractual Clauses, the clauses control. A customer who needs a countersigned copy can request it at [email protected].

02Roles

The customer is the controller, or a processor acting for its own client, and Nubesti is the processor or service provider. Nubesti is a separate controller for account, billing, security, and support data, as described in the privacy policy.

03Details of the processing

This section is the description of the processing required by article 28 of the GDPR:

ItemDescription
Subject matterProviding inSigner: hosting documents, sending signing invitations, collecting signatures, keeping evidence records, and running the add-ons the customer turns on
DurationThe term of the subscription, plus the export and deletion periods in this DPA
Nature and purposeStorage, transmission, display, signature collection, hashing, messaging, identity verification, support, and security
Data subjectsThe customer’s users, signers, and people named in documents
Personal dataNames, email addresses, phone numbers, job titles, signatures, IP addresses, device details, timestamps, and any personal data the customer puts in documents
Special categoriesBiometric data and identity document data, only when the customer turns on KYC. Other special categories only if the customer includes them in documents
FrequencyContinuous, while the service is used

04Customer instructions

Nubesti processes customer personal data only on the customer’s documented instructions. The terms of service, this DPA, and the customer’s configuration of the workspace are the complete instructions. Other instructions must be in writing to [email protected]. We will tell the customer if we believe an instruction breaks data protection laws, or if the law requires processing that goes beyond the instructions, unless that law prohibits telling them.

The customer is responsible for having a lawful basis for the processing, for the notices it gives to signers, and for the accuracy of the data it provides.

05Confidentiality

Everyone who processes customer personal data for Nubesti is bound by a duty of confidentiality and accesses the data only when their work requires it.

06Security measures

Nubesti maintains technical and organizational measures appropriate to the risk, including:

AreaMeasures
EncryptionTLS for data in transit, and encryption at rest by the storage providers
Access controlLeast privilege, individual accounts, multi-factor authentication for administrative access, and prompt removal of access
IntegritySHA-256 document hashes and an ordered event record for each signing
AvailabilityManaged infrastructure on a global network, and backups on a rolling cycle
Application securityDependency updates, code review, bot protection, and rate limiting
Monitoring and incidentsLogging, alerting, and an incident response process
ProvidersWritten data protection terms and a security review before a subprocessor is used

07Subprocessors

The customer gives Nubesti a general authorization to use the subprocessors listed on the subprocessors page. Each subprocessor is bound by written terms that protect personal data at least as well as this DPA, and Nubesti remains responsible for its subprocessors.

We will update the subprocessors page, and email customers who ask to be notified at [email protected], at least 15 days before a new subprocessor starts processing customer personal data, except in an emergency. The customer may object on reasonable data protection grounds within that period. If we cannot resolve the objection, the customer may terminate the affected service and receive a refund of prepaid fees for the unused period.

08Assistance

Taking into account the nature of the processing, Nubesti will help the customer answer requests from data subjects, carry out data protection impact assessments, consult supervisory authorities, and meet its security obligations. If we receive a request directly from a data subject about customer content, we will pass it to the customer and will not answer it ourselves, unless the customer asks us to.

09Personal data breaches

Nubesti will notify the customer without undue delay, and in any case within 48 hours, after confirming a personal data breach that affects customer personal data. The notice will describe, as far as known, the nature of the breach, the categories and approximate number of people and records concerned, the likely consequences, and the measures taken or proposed. We will update the customer as we learn more, and we will not notify authorities or data subjects on the customer’s behalf unless the customer asks us to or the law requires it.

10Return and deletion

When the subscription ends, the customer has 30 days to export customer content. After that, Nubesti deletes customer personal data from active systems, and backups are overwritten within 90 days, unless the law requires us to keep it. On request, we confirm deletion in writing.

11Audits

Nubesti will provide the information reasonably needed to show compliance with this DPA, including answers to a security questionnaire once a year. If the customer or its supervisory authority needs an audit that this information cannot satisfy, it may be carried out by an independent auditor bound by confidentiality, with at least 30 days’ notice, during business hours, without access to other customers’ data, and at the customer’s cost unless the audit finds a material breach.

12International transfers

Where customer personal data is transferred from the European Economic Area to Nubesti or a subprocessor in a country without an adequacy decision, the Standard Contractual Clauses approved by Commission Implementing Decision (EU) 2021/914 apply and are incorporated by reference: module two where the customer is a controller, and module three where it is a processor. Clause 7 does not apply. Under clause 9, option 2 applies with the notice period in this DPA. The optional wording in clause 11 does not apply. Under clause 17 the clauses are governed by Irish law, and under clause 18 the courts of Ireland have jurisdiction. The annexes are completed by this DPA and the subprocessors page.

For the United Kingdom, the International Data Transfer Addendum issued by the Information Commissioner applies. For Switzerland, the clauses apply with references to the Swiss Federal Act on Data Protection and the Federal Data Protection and Information Commissioner. Where a recipient is certified under the EU-U.S. Data Privacy Framework, that framework may be relied on instead. For other countries, the parties use the mechanism that the local law requires.

13U.S. state privacy laws

For the California Consumer Privacy Act and similar state laws, Nubesti is a service provider or processor. Nubesti will not sell or share customer personal data, will not retain, use, or disclose it outside the direct business relationship or for any purpose other than providing the service, and will not combine it with personal data from other sources, except as those laws allow. Nubesti will comply with those laws, give the same level of protection they require, and tell the customer if it can no longer meet its obligations. The customer may take reasonable steps to stop and remedy unauthorized use.

14Other laws and government requests

Where the LGPD, the Colombian Law 1581 of 2012, the Argentine Law 25,326, the Mexican federal data protection law, the South African POPIA, or a similar law applies, the obligations of this DPA apply to the customer personal data covered by that law. Requests from public authorities for customer personal data are handled as described in the government requests policy.

Questions about this policy go to [email protected].

Back to top

Related policies

Privacy Policy

What we collect for accounts, documents, signatures, add-ons, advertising, and support, and how to use your rights.

Cookie Policy

The cookies we use, why, for how long, and how to accept, reject, or change your choice at any time.

Identity verification and biometrics

How the KYC add-on checks identity documents, selfies, and registries, and how biometric data is protected and deleted.

Mobile app data

The iOS and Android apps are planned and not yet a public download. They will follow these same policies.

Subprocessors

The companies that host the service, deliver messages, verify identity, take payment, and measure advertising.

Legal center

Terms, privacy, cookies, data processing, identity verification, and signature policies for inSigner, published by Nubesti LLC.

Your documents. Your signatures.
Your control.

A clear electronic signature service for sending, signing, sealing, and verifying important documents.

Start freeDocumentation

Evidence receipt

Agreement completed

Signer
Verified
Timestamp
Recorded
Document hash
7F3A…91C2

01Simple to start

02Unlimited documents

03Evidence-ready

Product

  • Features
  • Pricing
  • Templates
  • API and webhooks
  • Add-ons
  • Signature creator

Resources

  • Documentation
  • Changelog
  • Blog
  • FAQ
  • Help Center
  • Roadmap

Company

  • About inSigner
  • Contact
  • Security
  • Enterprise
  • Legal Center
  • Free signing

Popular Guides

  • Where inSigner is legal
  • E-signature legality
  • How to sign a PDF
  • Sign documents online

Compare inSigner

  • vs Documenso
  • vs DocuSign
  • vs PandaDoc
  • vs Adobe Sign
  • vs HelloSign
  • vs SignNow
  • vs Zoho Sign
  • vs YouSign
  • vs DocuSeal

Countries

  • Australia
  • United Kingdom
  • United States
  • Japan
  • European Union
  • Germany
  • France
  • Spain
  • Italy
  • See all countries
LegalPrivacy PolicyTerms of ServiceDisclaimerSecurityYour privacy choices

© 2026 inSigner. All rights reserved.

EN· English
  • EN · English
  • ES · Español
  • DE · Deutsch
  • FR · Français
  • IT · Italiano
  • PT · Português

Electronic signatures for teams everywhere.

Your privacy, your choice

We use strictly necessary cookies to run this site. With your permission, we also use analytics cookies to improve it and advertising cookies to measure our ads. You can change your choice at any time from Cookie settings in the footer. Read the cookie policy

Your browser sends a Global Privacy Control signal, so advertising stays off unless you turn it on here.

Cookie settings

Choose which optional cookies we may use. Strictly necessary cookies are always on because the site cannot work without them. Read the cookie policy

Your browser sends a Global Privacy Control signal, so advertising stays off unless you turn it on here.

  • Strictly necessary

    Security, bot protection, sign-in, signing sessions, and remembering this choice. Provided by inSigner and Cloudflare.

    Always on
  • Help us understand how the site is used so we can improve it. Provided by Google Analytics and Microsoft Clarity.

  • Measure our ads and show relevant ads on other sites. Provided by Google Ads, Microsoft Advertising, Meta, and TikTok.