Dazr Sign data processing agreement

Parties and scope

This agreement is between the organisation that uses Dazr Sign (the controller) and Dazr, Viale Cesare Poggi 1, 15061 Arquata Scrivia (AL), Italy, VAT IT 02801250065 (“Dazr”, the processor). It applies when someone sends documents with Dazr Sign for a company, a public body or their own business, including documents an app sends for them through the Dazr Sign API. It does not cover documents sent for private purposes, or the data Dazr processes as a controller: Dazr Identity accounts and sign-in, the security of the service, and payments.

What Dazr processes

Instructions

Dazr processes the data only on the controller’s documented instructions: using Dazr Sign as intended, and this agreement. Dazr tells the controller if it believes an instruction breaks data protection law. Dazr does not use the contents of documents for any other purpose.

What Dazr does

Sub-processors

The controller authorises Dazr to use the sub-processors listed in the Dazr Sign trust centre, which also says where they are. Dazr binds them by written contract to the same data protection obligations as this agreement and remains responsible for them. Dazr announces a new or replaced sub-processor at least 30 days in advance, on that page and by email to the senders concerned. The controller may object on reasonable grounds; if Dazr cannot meet the objection, the controller may stop using Dazr Sign.

Where the data is processed

Where the data is stored, and how transfers outside the European Economic Area are covered, is described in the Dazr Sign privacy notice. The same safeguards apply under this agreement.

Security measures

Personal data breaches

Dazr tells the controller without undue delay, and at the latest within 72 hours of becoming aware of it, about a personal data breach that affects its data, with what is known about its nature, its likely consequences and the measures taken. Dazr helps the controller with its own notifications. Notices go to the email address of the sender’s Dazr Identity account.

Requests from data subjects

Senders can download and delete their documents themselves. When someone asks Dazr about a document an organisation sent, Dazr passes the request on to that organisation and does not answer it on its own, unless the law requires it.

Deletion and return

The controller can download every signed copy and audit trail at any time, and delete documents in Dazr Sign. A deleted document is gone at once; deleting the sender’s Dazr Identity account deletes all the documents they sent. Copies in Dazr’s encrypted database backups disappear as the backups expire, within 12 months; the PDFs themselves are not in these backups. Dazr keeps data longer only where EU or member state law requires it.

Audits

Dazr answers reasonable questions about how it meets this agreement. Once every 12 months, the controller, or an independent auditor it appoints under confidentiality, may audit Dazr with 30 days’ notice, during business hours and without access to other customers’ data. Dazr may charge a reasonable fee for further audits.

Liability and precedence

Liability under this agreement follows the Dazr Sign terms of use; nothing limits the rights of data subjects under Article 82 GDPR. On data protection, this agreement prevails over the terms of use and the privacy notice.

Contact