Data Processing Agreement (DPA)
Agreement under Art. 28 GDPR between you as controller and EINSZWEIDREI SOLUTIONS UG as processor for the use of E-Signing.io.
Last updated: July 2026 · Version 1.0
1. Parties
Customer (controller): the organisation operating a workspace in E-Signing.io, identified by the company details stored in the workspace.
Provider (processor):
2. Subject matter, nature and duration
The subject matter is the provision of the E-Signing.io platform for creating, sending, electronically signing and archiving documents. Processing is automated, takes place in EU-based data centres, and lasts for the duration of the usage agreement. It ends upon account deletion or termination.
3. Data subjects and categories of data
Data subjects include the customer's employees as well as recipients and signers of sent documents. Processed data includes contact details (name, email, mobile number), document content, uploaded attachments, and signature evidence (timestamps, hashed IP address, user agent, one-time code confirmations, checksums).
4. Right to issue instructions
We process personal data solely on documented instructions from the customer. Use of the application by authorised users is deemed an instruction. Further instructions must be sent in text form to datenschutz@e-signing.io. If we believe an instruction is unlawful, we will inform the customer.
5. Confidentiality
All persons involved in processing are bound to confidentiality and instructed on the applicable data protection requirements. Access to customer data is limited to what is necessary for operation and support.
6. Technical and organisational measures (Art. 32 GDPR)
Sämtliche Verbindungen zur Anwendung, zur Datenbank und zum Dateispeicher erfolgen ausschließlich über TLS.
Datenbank- und Speicherinhalte werden vom Hosting-Dienstleister verschlüsselt abgelegt.
Jeder Workspace ist logisch getrennt. Der Zugriff wird auf Datenbankebene über Row-Level-Security-Richtlinien erzwungen, nicht nur in der Oberfläche.
Rollenmodell aus Superadmin, Admin und Mitarbeiter. Rechte werden serverseitig geprüft; Rollen liegen in einer separaten Tabelle.
Anmeldung mit E-Mail und Passwort, Bestätigung der E-Mail-Adresse per 6-stelligem Code. Für die fortgeschrittene Signatur zusätzlich Einmal-Code per SMS oder E-Mail.
Jeder Vorgang erhält einen fortlaufenden Audit-Trail. Signierte PDFs werden mit SHA-256-Prüfsumme und Zeitstempel versiegelt und sind danach schreibgeschützt.
Signatur- und Anhanglinks sind zeitlich befristet; abgelaufene oder widerrufene Links werden serverseitig blockiert.
Konten und Workspaces können vollständig gelöscht werden; abhängige Daten werden kaskadierend entfernt. Auf Anforderung stellen wir Daten vor der Löschung bereit.
7. Subprocessors
The customer consents to the use of the following subprocessors. We will inform the customer of any changes with reasonable notice; the customer may object.
| Subprocessor | Service | Data categories | Region |
|---|---|---|---|
| Supabase | Hosting der Datenbank, Authentifizierung und Dateispeicher | Konto- und Workspace-Daten, Dokumente, Empfängerdaten, Anhänge, Protokolle | EU |
| Cloudflare | Auslieferung der Anwendung, Server-Laufzeit und Schutz vor Missbrauch | Verbindungsdaten (IP-Adresse, User-Agent), Anfrageinhalte im Transit | EU / global (Edge) |
| Resend | Versand von Einladungs-, Erinnerungs- und Abschluss-E-Mails | E-Mail-Adresse, Name, Betreff/Inhalt, Zustellstatus | EU / USA |
| sms-tools.de | Versand von SMS-Einladungen und Einmal-Codes | Mobilnummer, Nachrichtentext, Zustellstatus | EU |
| freeTSA (RFC-3161-Zeitstempeldienst) | Qualifizierter Zeitstempel für die Versiegelung signierter PDFs | Ausschließlich der SHA-256-Hashwert des PDFs — keine Inhalte | EU |
8. Support obligations
We support the customer with data subject requests, data protection impact assessments, and notification obligations under Art. 33 and 34 GDPR. If we become aware of a personal data breach, we will notify the customer without undue delay, providing all available details.
9. Audit and evidence rights
We demonstrate compliance with our obligations on request — primarily through the documentation on this page, evidence provided by our subprocessors, and information provided in text form. On-site audits are possible by prior arrangement and without disrupting operations.
10. Deletion and return
After the contract ends, we delete the processed data or return it upon request, unless a statutory retention obligation applies. The customer can export signed documents and their evidence as a PDF at any time.
11. Conclusion and documentation
This agreement is accepted upon registration with E-Signing.io; acceptance is logged with date and version in the workspace and can be viewed under Workspace settings → Legal. A countersigned copy is available on request at datenschutz@e-signing.io.
Further information is available in our Privacy Policy and under Legal validity.
Diese Angaben werden vom Anbieter gepflegt und beschreiben den aktuellen Stand der Anwendung. Sie stellen keine Rechtsberatung dar und ersetzen keine individuelle Prüfung.