Data Processing Agreement (DPA)

Agreement under Art. 28 GDPR between you as controller and EINSZWEIDREI SOLUTIONS UG as processor for the use of E-Signing.io.

Last updated: July 2026 · Version 1.0

This is a convenience translation. The German version is legally binding. See the German original.

1. Parties

Customer (controller): the organisation operating a workspace in E-Signing.io, identified by the company details stored in the workspace.

Provider (processor):

EINSZWEIDREI SOLUTIONS UG (haftungsbeschränkt)
Hochstraße 2
56242 Ellenhausen
Deutschland

2. Subject matter, nature and duration

The subject matter is the provision of the E-Signing.io platform for creating, sending, electronically signing and archiving documents. Processing is automated, takes place in EU-based data centres, and lasts for the duration of the usage agreement. It ends upon account deletion or termination.

3. Data subjects and categories of data

Data subjects include the customer's employees as well as recipients and signers of sent documents. Processed data includes contact details (name, email, mobile number), document content, uploaded attachments, and signature evidence (timestamps, hashed IP address, user agent, one-time code confirmations, checksums).

4. Right to issue instructions

We process personal data solely on documented instructions from the customer. Use of the application by authorised users is deemed an instruction. Further instructions must be sent in text form to datenschutz@e-signing.io. If we believe an instruction is unlawful, we will inform the customer.

5. Confidentiality

All persons involved in processing are bound to confidentiality and instructed on the applicable data protection requirements. Access to customer data is limited to what is necessary for operation and support.

6. Technical and organisational measures (Art. 32 GDPR)

Transportverschlüsselung

Sämtliche Verbindungen zur Anwendung, zur Datenbank und zum Dateispeicher erfolgen ausschließlich über TLS.

Verschlüsselung im Ruhezustand

Datenbank- und Speicherinhalte werden vom Hosting-Dienstleister verschlüsselt abgelegt.

Mandantentrennung

Jeder Workspace ist logisch getrennt. Der Zugriff wird auf Datenbankebene über Row-Level-Security-Richtlinien erzwungen, nicht nur in der Oberfläche.

Zugriffskontrolle und Rollen

Rollenmodell aus Superadmin, Admin und Mitarbeiter. Rechte werden serverseitig geprüft; Rollen liegen in einer separaten Tabelle.

Authentifizierung

Anmeldung mit E-Mail und Passwort, Bestätigung der E-Mail-Adresse per 6-stelligem Code. Für die fortgeschrittene Signatur zusätzlich Einmal-Code per SMS oder E-Mail.

Protokollierung und Integrität

Jeder Vorgang erhält einen fortlaufenden Audit-Trail. Signierte PDFs werden mit SHA-256-Prüfsumme und Zeitstempel versiegelt und sind danach schreibgeschützt.

Zugriffsbeschränkung auf Links

Signatur- und Anhanglinks sind zeitlich befristet; abgelaufene oder widerrufene Links werden serverseitig blockiert.

Löschung und Rückgabe

Konten und Workspaces können vollständig gelöscht werden; abhängige Daten werden kaskadierend entfernt. Auf Anforderung stellen wir Daten vor der Löschung bereit.

7. Subprocessors

The customer consents to the use of the following subprocessors. We will inform the customer of any changes with reasonable notice; the customer may object.

SubprocessorServiceData categoriesRegion
SupabaseHosting der Datenbank, Authentifizierung und DateispeicherKonto- und Workspace-Daten, Dokumente, Empfängerdaten, Anhänge, ProtokolleEU
CloudflareAuslieferung der Anwendung, Server-Laufzeit und Schutz vor MissbrauchVerbindungsdaten (IP-Adresse, User-Agent), Anfrageinhalte im TransitEU / global (Edge)
ResendVersand von Einladungs-, Erinnerungs- und Abschluss-E-MailsE-Mail-Adresse, Name, Betreff/Inhalt, ZustellstatusEU / USA
sms-tools.deVersand von SMS-Einladungen und Einmal-CodesMobilnummer, Nachrichtentext, ZustellstatusEU
freeTSA (RFC-3161-Zeitstempeldienst)Qualifizierter Zeitstempel für die Versiegelung signierter PDFsAusschließlich der SHA-256-Hashwert des PDFs — keine InhalteEU

8. Support obligations

We support the customer with data subject requests, data protection impact assessments, and notification obligations under Art. 33 and 34 GDPR. If we become aware of a personal data breach, we will notify the customer without undue delay, providing all available details.

9. Audit and evidence rights

We demonstrate compliance with our obligations on request — primarily through the documentation on this page, evidence provided by our subprocessors, and information provided in text form. On-site audits are possible by prior arrangement and without disrupting operations.

10. Deletion and return

After the contract ends, we delete the processed data or return it upon request, unless a statutory retention obligation applies. The customer can export signed documents and their evidence as a PDF at any time.

11. Conclusion and documentation

This agreement is accepted upon registration with E-Signing.io; acceptance is logged with date and version in the workspace and can be viewed under Workspace settings → Legal. A countersigned copy is available on request at datenschutz@e-signing.io.

Further information is available in our Privacy Policy and under Legal validity.

Diese Angaben werden vom Anbieter gepflegt und beschreiben den aktuellen Stand der Anwendung. Sie stellen keine Rechtsberatung dar und ersetzen keine individuelle Prüfung.