Dazr Sign data processing agreement
Last updated 6 October 2026 · For organisations that send documents with Dazr Sign at sign.dazr.eu or through the Dazr Sign API.
If a translation of this page differs from the English version, the English version applies.
Parties and scope
This agreement is between the organisation that uses Dazr Sign (the controller) and Dazr, Viale Cesare Poggi 1, 15061 Arquata Scrivia (AL), Italy, VAT IT 02801250065 (“Dazr”, the processor). It applies when someone sends documents with Dazr Sign for a company, a public body or their own business, including documents an app sends for them through the Dazr Sign API. It does not cover documents sent for private purposes, or the data Dazr processes as a controller: Dazr Identity accounts and sign-in, the security of the service, and payments.
What Dazr processes
- Subject matter and purpose. Providing Dazr Sign: storing documents, sending signing requests and reminders, collecting signatures and field values, sealing the signed copy, keeping the audit trail, and answering the check page and the Dazr Sign API.
- Personal data. Names and email addresses of recipients, the values they enter, signatures and initials, the audit trail (times, sign-in method, approximate country, a short description of the device and a one-way hash of the IP address), the certificate details of qualified signers, and any personal data in the documents themselves.
- Data subjects. The controller’s staff who send documents, the people who receive and sign them, such as employees, customers and suppliers, and people named in the documents.
- Duration. For as long as the documents are kept in Dazr Sign: until the sender deletes them or deletes their Dazr Identity account.
Instructions
Dazr processes the data only on the controller’s documented instructions: using Dazr Sign as intended, and this agreement. Dazr tells the controller if it believes an instruction breaks data protection law. Dazr does not use the contents of documents for any other purpose.
What Dazr does
- Everyone at Dazr who can access the data is bound to confidentiality.
- Dazr takes the security measures described below and in the trust centre (Article 32 GDPR).
- Dazr helps the controller answer requests from data subjects, and with data protection impact assessments and consultations with supervisory authorities, as far as the nature of the processing allows.
- Dazr gives the controller the information needed to show compliance with Article 28 GDPR, and allows and contributes to audits as described below.
Sub-processors
The controller authorises Dazr to use the sub-processors listed in the Dazr Sign trust centre, which also says where they are. Dazr binds them by written contract to the same data protection obligations as this agreement and remains responsible for them. Dazr announces a new or replaced sub-processor at least 30 days in advance, on that page and by email to the senders concerned. The controller may object on reasonable grounds; if Dazr cannot meet the objection, the controller may stop using Dazr Sign.
Where the data is processed
Where the data is stored, and how transfers outside the European Economic Area are covered, is described in the Dazr Sign privacy notice. The same safeguards apply under this agreement.
Security measures
- All traffic is encrypted with HTTPS, and browsers are told to use only HTTPS (HSTS).
- Each document is encrypted at rest with its own key (AES-256-GCM), on top of our providers’ own encryption.
- Only the sender and the recipients can open a document. Each signing link works only for the address it was sent to, after the signer confirms that address.
- When everyone has signed, Dazr seals the PDF with a PAdES signature, so any later change shows, and adds the audit trail.
- Requests are rate-limited, and browsers run only the scripts we list (Content Security Policy).
- Only the few people at Dazr who run the service can access its systems.
Personal data breaches
Dazr tells the controller without undue delay, and at the latest within 72 hours of becoming aware of it, about a personal data breach that affects its data, with what is known about its nature, its likely consequences and the measures taken. Dazr helps the controller with its own notifications. Notices go to the email address of the sender’s Dazr Identity account.
Requests from data subjects
Senders can download and delete their documents themselves. When someone asks Dazr about a document an organisation sent, Dazr passes the request on to that organisation and does not answer it on its own, unless the law requires it.
Deletion and return
The controller can download every signed copy and audit trail at any time, and delete documents in Dazr Sign. A deleted document is gone at once; deleting the sender’s Dazr Identity account deletes all the documents they sent. Copies in Dazr’s encrypted database backups disappear as the backups expire, within 12 months; the PDFs themselves are not in these backups. Dazr keeps data longer only where EU or member state law requires it.
Audits
Dazr answers reasonable questions about how it meets this agreement. Once every 12 months, the controller, or an independent auditor it appoints under confidentiality, may audit Dazr with 30 days’ notice, during business hours and without access to other customers’ data. Dazr may charge a reasonable fee for further audits.
Liability and precedence
Liability under this agreement follows the Dazr Sign terms of use; nothing limits the rights of data subjects under Article 82 GDPR. On data protection, this agreement prevails over the terms of use and the privacy notice.
Contact
- Privacy and data requests: privacy@dazr.eu
- Security: security@dazr.eu
- General: hello@dazr.eu
- Post: Dazr, Viale Cesare Poggi 1, 15061 Arquata Scrivia (AL), Italy