Data Processing Agreement
GetSigning's standard DPA under UK GDPR Article 28.
This DPA is a standard document forming part of GetSigning's Terms of Service. It takes effect from whichever is earliest: accepting the Terms of Service, continued use of the Services, or the date below. There is nothing to sign or return.
Last updated: 26 September 2026
1. Parties and background
This Data Processing Agreement ("DPA") is entered into between:
(1) The customer identified on the applicable order or account for the GetSigning service ("Customer", "Controller"); and
(2) Goggle Software Ltd, a company registered in England and Wales, trading as GetSigning, ICO registration number ZA919631 ("GetSigning", "Processor"),
each a "party" and together the "parties".
This DPA forms part of, and is incorporated into, the agreement between the Customer and GetSigning for the provision of the GetSigning e-signature platform (the "Principal Agreement"). It applies whenever GetSigning processes personal data on behalf of the Customer in the course of providing that service.
This DPA reflects the parties' obligations under the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018, in particular Article 28 UK GDPR concerning the processing of personal data by a processor on behalf of a controller.
Questions about this DPA, or requests relating to data protection, can be sent to GetSigning's data protection contact at dpo@gogglesoftware.co.uk.
2. Definitions
In this DPA, the following terms have the meanings set out below. Terms not defined here have the meanings given in UK GDPR and the Data Protection Act 2018.
- "UK GDPR" means the UK General Data Protection Regulation, as it forms part of UK law by virtue of the Data Protection Act 2018.
- "Data Protection Legislation" means the UK GDPR, the Data Protection Act 2018, and any other applicable law relating to the processing of personal data.
- "Personal Data", "Processing", "Controller", "Processor", "Data Subject" and "Personal Data Breach" have the meanings given in the UK GDPR.
- "Customer Data" means the personal data submitted to, or generated within, the GetSigning platform by or on behalf of the Customer, including the personal data of signing parties (name, email address, IP address, authentication details, signature image, and the content of documents sent for signature).
- "Sub-processor" means any third party engaged by GetSigning to process Customer Data on GetSigning's behalf in connection with the Principal Agreement.
- "Services" means the GetSigning e-signature platform, including document preparation, sending, signing, storage, audit trail generation, and related functionality, as provided under the Principal Agreement.
3. Subject matter and duration
GetSigning processes Customer Data as a Processor, on behalf of the Customer as Controller, for the duration of the Principal Agreement, or for as long as GetSigning holds Customer Data afterwards under Section 10 (Deletion and return of data).
4. Nature and purpose of processing
GetSigning processes Customer Data to provide the Services: preparing documents for signature, sending signing invitations, capturing consent and signatures, recording an audit trail of signing activity, storing signed documents, and sending related notifications (for example webhooks and status emails) that the Customer has configured.
5. Types of personal data and categories of data subjects
Personal data processed may include: names, email addresses, IP addresses, timestamps, authentication and consent records, signature images, and the content of any documents the Customer uploads for signature. Data subjects are the Customer's own signing parties (for example, the Customer's clients, counterparties, or staff) and, where applicable, the Customer's own users of the platform.
6. GetSigning's obligations as Processor
GetSigning shall:
- process Customer Data only on the Customer's documented instructions, including as set out in the Principal Agreement and this DPA, unless required to do otherwise by UK law;
- ensure that personnel authorised to process Customer Data are subject to a duty of confidentiality;
- implement appropriate technical and organisational measures as set out in Section 8 (Security);
- not engage a Sub-processor without complying with Section 7 (Sub-processors);
- provide the Customer with self-service tools within the Services (document and party search, export, and deletion) so the Customer can respond to data subject requests itself, as set out in Section 9;
- assist the Customer in ensuring compliance with obligations relating to the security of processing, breach notification, and data protection impact assessments, taking into account the information available to GetSigning;
- provide the Customer with self-service export and deletion tools so the Customer can obtain or remove Customer Data at the end of the provision of the Services, as set out in Section 10;
- make available to the Customer standard compliance information as set out in Section 11.
7. Sub-processors
The Customer authorises GetSigning to engage the following Sub-processors in connection with the Services:
| Sub-processor | Purpose | Location of processing |
|---|---|---|
| DigitalOcean | Application hosting and database storage | London, UK |
| AWS (Amazon Simple Email Service) | Sending transactional emails | London, UK (eu-west-2) |
| Cloudflare | DNS, content delivery and network protection | Global network |
| Stripe | Payment processing | EU / US |
GetSigning will give the Customer at least 30 days' notice before appointing a new Sub-processor, or replacing an existing one, by email to the Customer's registered account contact. If the Customer objects on reasonable data protection grounds within that period, the parties will discuss the objection in good faith; if it is not resolved, the Customer may terminate the affected part of the Services without penalty.
GetSigning remains liable for the acts and omissions of its Sub-processors to the same extent GetSigning would be liable if performing their services directly, and imposes data protection obligations substantially similar to this DPA on each Sub-processor.
8. Security
GetSigning maintains technical and organisational measures appropriate to the risk, including:
- encryption of Customer Data in transit and at rest;
- role-based access controls restricting access to Customer Data to personnel who need it to perform the Services;
- a hash-chained audit trail recording signing activity (consent, signature, and viewing events) so that records cannot be altered undetected;
- account-level authentication and API key based access control for programmatic access;
- regular review of infrastructure and dependencies for known vulnerabilities.
9. Assistance with data subject rights
GetSigning's platform is self-service: the Customer creates, sends and manages its own documents and signing parties directly within it. Where a data subject contacts GetSigning directly to exercise a right under the Data Protection Legislation in relation to Customer Data, GetSigning will promptly forward the request to the Customer and will not itself respond, except to confirm receipt, unless required to do otherwise by law. GetSigning is a small team and does not carry out bespoke data subject request work on the Customer's behalf. The self-service search, export and deletion tools within the platform are the means by which the Customer meets its own obligations to data subjects.
10. Deletion and return of data
Documents still in draft (not yet sent for signature) can be deleted by the Customer at any time within the platform.
Once a document has been sent for signature, or has been signed, GetSigning retains the document and its audit trail for the duration of the Principal Agreement. This is because the audit trail exists to provide evidence of the signing process, and altering or removing it after the fact would undermine that purpose. The Customer can export copies of signed documents and their audit trails at any time.
On termination of the Principal Agreement, the Customer's self-service export tools remain available for 30 days, during which the Customer should export any Customer Data it wishes to keep. After that period, and subject to any longer retention period required by law, GetSigning will delete Customer Data. GetSigning does not provide a bespoke data return service.
11. Audits
GetSigning publishes standard information about its security measures and current Sub-processors on its website, and keeps that information up to date. As a small team, GetSigning does not complete bespoke security questionnaires, take part in vendor risk assessments, provide on-site audits, or permit third-party inspection of its systems or premises.
12. Personal data breach notification
GetSigning will notify the Customer without undue delay, and in any event within 72 hours of becoming aware, of any Personal Data Breach affecting Customer Data, and will provide information reasonably available to it to help the Customer meet its own notification obligations, and will take reasonable steps to mitigate the effects of the breach.
13. International transfers
Customer Data is hosted and processed within the UK. Some Sub-processors (Stripe, and the parent entities of AWS and Cloudflare) are incorporated outside the UK. Where personal data is transferred outside the UK, GetSigning relies on an adequate safeguard recognised under the Data Protection Legislation, such as the UK's International Data Transfer Addendum to the EU Standard Contractual Clauses, or the Sub-processor's own adequacy or certification basis, before making the transfer.
14. Liability
Each party's liability arising out of or in connection with this DPA is subject to the limitations and exclusions of liability set out in the Principal Agreement. Nothing in this DPA limits either party's liability for matters which cannot lawfully be limited or excluded, including liability for a party's own breach of the Data Protection Legislation.
15. General
This DPA is governed by the laws of England and Wales. In the event of any conflict between this DPA and the Principal Agreement in relation to the processing of personal data, this DPA prevails.
This DPA is a standard document forming part of GetSigning's Terms of Service. It takes effect, without any separate signature, from whichever is earliest: the Customer's acceptance of the Terms of Service, the Customer's continued use of the Services, or the date at the top of this DPA.