Data Processing Agreement (DPA)
Agreement under Art. 28 GDPR between you as controller and EINSZWEIDREI SOLUTIONS UG as processor for the use of E-Signing.io.
Last updated: February 2026 · Version 2.0
1. Parties
Customer (controller): the organisation operating a workspace in E-Signing.io, identified by the company details stored in the workspace.
Provider (processor):
2. Subject matter, nature and duration
The subject matter is the provision of the E-Signing.io platform for creating, sending, electronically signing and archiving documents. Processing is automated and lasts for the duration of the usage agreement. It ends upon account deletion or termination.
The database, file storage and application logic are operated in data centres within the European Union. For the delivery of static assets and for dispatch we use services with globally distributed locations (content delivery network, email and SMS delivery), which may involve transfers to third countries, in particular the USA. These transfers are listed in Section 7 and are based on Standard Contractual Clauses (Implementing Decision (EU) 2021/914) or on an adequacy decision of the European Commission, supplemented by technical measures (encryption in transit and at rest, data minimisation).
3. Data subjects and categories of data
Data subjects include the customer's employees as well as recipients and signers of sent documents. Processed data includes contact details (name, email, mobile number), document content, uploaded attachments, and signature evidence (timestamps, the IP address in clear text within the signature evidence and hashed in access logs, user agent, one-time code confirmations, checksums).
4. Right to issue instructions
We process personal data solely on documented instructions from the customer. Use of the application by authorised users is deemed an instruction. Further instructions must be sent in text form to datenschutz@e-signing.io. If we believe an instruction is unlawful, we will inform the customer.
5. Confidentiality
All persons involved in processing are bound to confidentiality and instructed on the applicable data protection requirements. Access to customer data is limited to what is necessary for operation and support.
6. Technical and organisational measures (Art. 32 GDPR)
All connections to the application, the database and file storage run exclusively over TLS.
Database and storage contents are stored encrypted by the hosting provider.
Every workspace is logically separated. Access is enforced at database level through row-level security policies, not just in the interface.
Role model of superadmin, admin and member. Permissions are checked server-side; roles are held in a separate table.
Sign-in with email and password, email confirmation via a 6-digit code. Advanced signatures additionally require a one-time code by SMS or email.
Accounts can additionally be protected with an authenticator app (TOTP) or with passkeys based on the WebAuthn standard. Passkeys are bound to the e-signing.io domain and are phishing-resistant.
Every transaction receives a continuous audit trail. Signed PDFs are sealed with a SHA-256 checksum and a timestamp and are write-protected afterwards.
Signature and attachment links are time-limited; expired or revoked links are blocked server-side.
Accounts and workspaces can be deleted at any time by the customer. Personal data (profile, contacts, templates, drafts, integrations) is removed irreversibly. A full data export (ZIP with JSON and signed PDFs) can be requested at any time before deletion.
After an erasure request, signed contracts and their evidence chain are no longer processed but kept in a locked archive: six years under § 257 HGB, ten years where payment or invoicing data is involved under § 147 AO (Art. 17(3)(b), Art. 18 GDPR). Once the period ends they are deleted automatically. Every erasure is logged in pseudonymised form.
7. Subprocessors
The customer consents to the use of the following subprocessors. We will inform the customer of any changes with reasonable notice; the customer may object.
| Subprocessor | Service | Data categories | Region |
|---|---|---|---|
| Supabase | Database hosting, authentication and file storage | Account and workspace data, documents, recipient data, attachments, logs | EU |
| Cloudflare | Application delivery, server runtime and abuse protection | Connection data (IP address, user agent), request payloads in transit | EU / global (edge) |
| Resend | Sending invitation, reminder and completion emails | Email address, name, subject and content, delivery status | EU / USA |
| sms-tools.de (SMS-Tools GmbH) | Sending SMS invitations and one-time codes; uses GatewayAPI ApS for technical delivery | Mobile number, message text, delivery status | EU (Germany) |
| GatewayAPI ApS (Unterauftragsverarbeiter von sms-tools.de) | Technical delivery of the SMS to the mobile networks (endpoint api.smsgatewayapi.com) | Mobile number, message text, delivery status | EU (Denmark) |
| freeTSA (RFC-3161) | RFC 3161 timestamp used to seal signed PDFs; not an eIDAS-qualified timestamp service | Only the SHA-256 hash of the PDF, no content | EU |
| Google Ireland Ltd. (Google Sign-In) | Optional sign-in with a Google account (single sign-on), only if you use this option | Google account ID, email address, name, profile picture URL | EU / USA |
| Microsoft Ireland Operations Ltd. (Microsoft Entra ID) | Optional sign-in with a Microsoft account (single sign-on), only if you use this option | Microsoft account ID, email address, name | EU / USA |
| Paddle.com Market Ltd. | Payment processing, subscription management, invoicing and tax remittance as merchant of record (reseller) | Name, email address, billing and company address, VAT ID, payment method (stored at Paddle only), order and invoice data, IP address for fraud prevention | UK / EU / USA |
| Cybot A/S (Usercentrics/Cookiebot) | Obtaining, managing and documenting cookie consent (consent management platform), including automatic blocking of scripts requiring consent | Anonymised IP address, date and time of consent, user agent, domain visited, scope of the decision, consent ID | EU (Denmark) |
| Better Stack (Better Stack s.r.o.) | Uptime monitoring of the application and public status page | Technical response data of the monitored endpoints, no customer or document content | EU |
| Granola (optional) | Only if you connect the integration yourself: retrieval of meeting notes and transcripts to populate documents | Meeting titles, notes and transcripts of the connected Granola account | USA |
| Zapier (optional) | Only if you connect the integration yourself: transmission of events and data to the automations (Zaps) you build, plus creation of shipments and contacts from Zapier | Shipment and recipient data (name, email, phone number, company, status), document names, contact data — depending on the Zap you choose | USA |
| bunny.net (Storage Zones) | Regional file storage for uploaded documents, images and attachments | Files uploaded by the workspace | Chosen by the workspace (EU, UK, US, SG, AU, BR, ZA) |
Marketing & audience measurement
The following services are loaded only after explicit consent in the cookie banner. Without consent no processing takes place. For Meta and LinkedIn, collection and transmission on the website are subject to joint controllership under Art. 26 GDPR; any further processing is carried out under the sole responsibility of the respective provider.
No analytics or marketing service is currently enabled. No such data is collected.
8. Support obligations
We support the customer with data subject requests, data protection impact assessments, and notification obligations under Art. 33 and 34 GDPR. If we become aware of a personal data breach, we will notify the customer without undue delay, providing all available details.
9. Audit and evidence rights
We demonstrate compliance with our obligations on request, primarily through the documentation on this page, evidence provided by our subprocessors, and information provided in text form. On-site audits are possible by prior arrangement and without disrupting operations.
10. Deletion and return
After the contract ends, we delete the processed data or return it upon request, unless a statutory retention obligation applies. The customer can export signed documents and their evidence as a PDF at any time.
11. Conclusion and documentation
This agreement is accepted upon registration with E-Signing.io; acceptance is logged with date and version in the workspace and can be viewed under Workspace settings → Legal. A countersigned copy is available on request at datenschutz@e-signing.io.
Further information is available in our Privacy Policy and under Legal validity.