Bring fellow founders on board. Earn 5 free e-signing sends for every successful signup (up to 3×)Bring fellow founders on board. Earn 5 free e-signing sends for every successful signup (up to 3×)Bring fellow founders on board. Earn 5 free e-signing sends for every successful signup (up to 3×)Bring fellow founders on board. Earn 5 free e-signing sends for every successful signup (up to 3×)Bring fellow founders on board. Earn 5 free e-signing sends for every successful signup (up to 3×)Bring fellow founders on board. Earn 5 free e-signing sends for every successful signup (up to 3×)

Data Processing Agreement (DPA)

Agreement under Art. 28 GDPR between you as controller and EINSZWEIDREI SOLUTIONS UG as processor for the use of E-Signing.io.

Last updated: February 2026 · Version 2.0

This is a convenience translation. The German version is legally binding. See the German original.

1. Parties

Customer (controller): the organisation operating a workspace in E-Signing.io, identified by the company details stored in the workspace.

Provider (processor):

EINSZWEIDREI SOLUTIONS UG (haftungsbeschränkt)
Hochstraße 2
56242 Ellenhausen
Deutschland

2. Subject matter, nature and duration

The subject matter is the provision of the E-Signing.io platform for creating, sending, electronically signing and archiving documents. Processing is automated and lasts for the duration of the usage agreement. It ends upon account deletion or termination.

The database, file storage and application logic are operated in data centres within the European Union. For the delivery of static assets and for dispatch we use services with globally distributed locations (content delivery network, email and SMS delivery), which may involve transfers to third countries, in particular the USA. These transfers are listed in Section 7 and are based on Standard Contractual Clauses (Implementing Decision (EU) 2021/914) or on an adequacy decision of the European Commission, supplemented by technical measures (encryption in transit and at rest, data minimisation).

3. Data subjects and categories of data

Data subjects include the customer's employees as well as recipients and signers of sent documents. Processed data includes contact details (name, email, mobile number), document content, uploaded attachments, and signature evidence (timestamps, the IP address in clear text within the signature evidence and hashed in access logs, user agent, one-time code confirmations, checksums).

4. Right to issue instructions

We process personal data solely on documented instructions from the customer. Use of the application by authorised users is deemed an instruction. Further instructions must be sent in text form to datenschutz@e-signing.io. If we believe an instruction is unlawful, we will inform the customer.

5. Confidentiality

All persons involved in processing are bound to confidentiality and instructed on the applicable data protection requirements. Access to customer data is limited to what is necessary for operation and support.

6. Technical and organisational measures (Art. 32 GDPR)

Encryption in transit

All connections to the application, the database and file storage run exclusively over TLS.

Encryption at rest

Database and storage contents are stored encrypted by the hosting provider.

Tenant separation

Every workspace is logically separated. Access is enforced at database level through row-level security policies, not just in the interface.

Access control and roles

Role model of superadmin, admin and member. Permissions are checked server-side; roles are held in a separate table.

Authentication

Sign-in with email and password, email confirmation via a 6-digit code. Advanced signatures additionally require a one-time code by SMS or email.

Two-factor authentication and passkeys

Accounts can additionally be protected with an authenticator app (TOTP) or with passkeys based on the WebAuthn standard. Passkeys are bound to the e-signing.io domain and are phishing-resistant.

Logging and integrity

Every transaction receives a continuous audit trail. Signed PDFs are sealed with a SHA-256 checksum and a timestamp and are write-protected afterwards.

Restricted link access

Signature and attachment links are time-limited; expired or revoked links are blocked server-side.

Deletion and return

Accounts and workspaces can be deleted at any time by the customer. Personal data (profile, contacts, templates, drafts, integrations) is removed irreversibly. A full data export (ZIP with JSON and signed PDFs) can be requested at any time before deletion.

Retention of signed documents

After an erasure request, signed contracts and their evidence chain are no longer processed but kept in a locked archive: six years under § 257 HGB, ten years where payment or invoicing data is involved under § 147 AO (Art. 17(3)(b), Art. 18 GDPR). Once the period ends they are deleted automatically. Every erasure is logged in pseudonymised form.

7. Subprocessors

The customer consents to the use of the following subprocessors. We will inform the customer of any changes with reasonable notice; the customer may object.

SubprocessorServiceData categoriesRegion
SupabaseDatabase hosting, authentication and file storageAccount and workspace data, documents, recipient data, attachments, logsEU
CloudflareApplication delivery, server runtime and abuse protectionConnection data (IP address, user agent), request payloads in transitEU / global (edge)
ResendSending invitation, reminder and completion emailsEmail address, name, subject and content, delivery statusEU / USA
sms-tools.de (SMS-Tools GmbH)Sending SMS invitations and one-time codes; uses GatewayAPI ApS for technical deliveryMobile number, message text, delivery statusEU (Germany)
GatewayAPI ApS (Unterauftragsverarbeiter von sms-tools.de)Technical delivery of the SMS to the mobile networks (endpoint api.smsgatewayapi.com)Mobile number, message text, delivery statusEU (Denmark)
freeTSA (RFC-3161)RFC 3161 timestamp used to seal signed PDFs; not an eIDAS-qualified timestamp serviceOnly the SHA-256 hash of the PDF, no contentEU
Google Ireland Ltd. (Google Sign-In)Optional sign-in with a Google account (single sign-on), only if you use this optionGoogle account ID, email address, name, profile picture URLEU / USA
Microsoft Ireland Operations Ltd. (Microsoft Entra ID)Optional sign-in with a Microsoft account (single sign-on), only if you use this optionMicrosoft account ID, email address, nameEU / USA
Paddle.com Market Ltd.Payment processing, subscription management, invoicing and tax remittance as merchant of record (reseller)Name, email address, billing and company address, VAT ID, payment method (stored at Paddle only), order and invoice data, IP address for fraud preventionUK / EU / USA
Cybot A/S (Usercentrics/Cookiebot)Obtaining, managing and documenting cookie consent (consent management platform), including automatic blocking of scripts requiring consentAnonymised IP address, date and time of consent, user agent, domain visited, scope of the decision, consent IDEU (Denmark)
Better Stack (Better Stack s.r.o.)Uptime monitoring of the application and public status pageTechnical response data of the monitored endpoints, no customer or document contentEU
Granola (optional)Only if you connect the integration yourself: retrieval of meeting notes and transcripts to populate documentsMeeting titles, notes and transcripts of the connected Granola accountUSA
Zapier (optional)Only if you connect the integration yourself: transmission of events and data to the automations (Zaps) you build, plus creation of shipments and contacts from ZapierShipment and recipient data (name, email, phone number, company, status), document names, contact data — depending on the Zap you chooseUSA
bunny.net (Storage Zones)Regional file storage for uploaded documents, images and attachmentsFiles uploaded by the workspaceChosen by the workspace (EU, UK, US, SG, AU, BR, ZA)

Marketing & audience measurement

The following services are loaded only after explicit consent in the cookie banner. Without consent no processing takes place. For Meta and LinkedIn, collection and transmission on the website are subject to joint controllership under Art. 26 GDPR; any further processing is carried out under the sole responsibility of the respective provider.

No analytics or marketing service is currently enabled. No such data is collected.

8. Support obligations

We support the customer with data subject requests, data protection impact assessments, and notification obligations under Art. 33 and 34 GDPR. If we become aware of a personal data breach, we will notify the customer without undue delay, providing all available details.

9. Audit and evidence rights

We demonstrate compliance with our obligations on request, primarily through the documentation on this page, evidence provided by our subprocessors, and information provided in text form. On-site audits are possible by prior arrangement and without disrupting operations.

10. Deletion and return

After the contract ends, we delete the processed data or return it upon request, unless a statutory retention obligation applies. The customer can export signed documents and their evidence as a PDF at any time.

11. Conclusion and documentation

This agreement is accepted upon registration with E-Signing.io; acceptance is logged with date and version in the workspace and can be viewed under Workspace settings → Legal. A countersigned copy is available on request at datenschutz@e-signing.io.

Further information is available in our Privacy Policy and under Legal validity.