Data Processing Agreement

GetSigning's standard DPA under UK GDPR Article 28.

This applies automatically, no signature needed

This DPA is a standard document forming part of GetSigning's Terms of Service. It takes effect from whichever is earliest: accepting the Terms of Service, continued use of the Services, or the date below. There is nothing to sign or return.

Last updated: 26 September 2026

1. Parties and background

This Data Processing Agreement ("DPA") is entered into between:

(1) The customer identified on the applicable order or account for the GetSigning service ("Customer", "Controller"); and

(2) Goggle Software Ltd, a company registered in England and Wales, trading as GetSigning, ICO registration number ZA919631 ("GetSigning", "Processor"),

each a "party" and together the "parties".

This DPA forms part of, and is incorporated into, the agreement between the Customer and GetSigning for the provision of the GetSigning e-signature platform (the "Principal Agreement"). It applies whenever GetSigning processes personal data on behalf of the Customer in the course of providing that service.

This DPA reflects the parties' obligations under the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018, in particular Article 28 UK GDPR concerning the processing of personal data by a processor on behalf of a controller.

Questions about this DPA, or requests relating to data protection, can be sent to GetSigning's data protection contact at dpo@gogglesoftware.co.uk.

2. Definitions

In this DPA, the following terms have the meanings set out below. Terms not defined here have the meanings given in UK GDPR and the Data Protection Act 2018.

3. Subject matter and duration

GetSigning processes Customer Data as a Processor, on behalf of the Customer as Controller, for the duration of the Principal Agreement, or for as long as GetSigning holds Customer Data afterwards under Section 10 (Deletion and return of data).

4. Nature and purpose of processing

GetSigning processes Customer Data to provide the Services: preparing documents for signature, sending signing invitations, capturing consent and signatures, recording an audit trail of signing activity, storing signed documents, and sending related notifications (for example webhooks and status emails) that the Customer has configured.

5. Types of personal data and categories of data subjects

Personal data processed may include: names, email addresses, IP addresses, timestamps, authentication and consent records, signature images, and the content of any documents the Customer uploads for signature. Data subjects are the Customer's own signing parties (for example, the Customer's clients, counterparties, or staff) and, where applicable, the Customer's own users of the platform.

6. GetSigning's obligations as Processor

GetSigning shall:

7. Sub-processors

The Customer authorises GetSigning to engage the following Sub-processors in connection with the Services:

Sub-processorPurposeLocation of processing
DigitalOceanApplication hosting and database storageLondon, UK
AWS (Amazon Simple Email Service)Sending transactional emailsLondon, UK (eu-west-2)
CloudflareDNS, content delivery and network protectionGlobal network
StripePayment processingEU / US

GetSigning will give the Customer at least 30 days' notice before appointing a new Sub-processor, or replacing an existing one, by email to the Customer's registered account contact. If the Customer objects on reasonable data protection grounds within that period, the parties will discuss the objection in good faith; if it is not resolved, the Customer may terminate the affected part of the Services without penalty.

GetSigning remains liable for the acts and omissions of its Sub-processors to the same extent GetSigning would be liable if performing their services directly, and imposes data protection obligations substantially similar to this DPA on each Sub-processor.

8. Security

GetSigning maintains technical and organisational measures appropriate to the risk, including:

9. Assistance with data subject rights

GetSigning's platform is self-service: the Customer creates, sends and manages its own documents and signing parties directly within it. Where a data subject contacts GetSigning directly to exercise a right under the Data Protection Legislation in relation to Customer Data, GetSigning will promptly forward the request to the Customer and will not itself respond, except to confirm receipt, unless required to do otherwise by law. GetSigning is a small team and does not carry out bespoke data subject request work on the Customer's behalf. The self-service search, export and deletion tools within the platform are the means by which the Customer meets its own obligations to data subjects.

10. Deletion and return of data

Documents still in draft (not yet sent for signature) can be deleted by the Customer at any time within the platform.

Once a document has been sent for signature, or has been signed, GetSigning retains the document and its audit trail for the duration of the Principal Agreement. This is because the audit trail exists to provide evidence of the signing process, and altering or removing it after the fact would undermine that purpose. The Customer can export copies of signed documents and their audit trails at any time.

On termination of the Principal Agreement, the Customer's self-service export tools remain available for 30 days, during which the Customer should export any Customer Data it wishes to keep. After that period, and subject to any longer retention period required by law, GetSigning will delete Customer Data. GetSigning does not provide a bespoke data return service.

11. Audits

GetSigning publishes standard information about its security measures and current Sub-processors on its website, and keeps that information up to date. As a small team, GetSigning does not complete bespoke security questionnaires, take part in vendor risk assessments, provide on-site audits, or permit third-party inspection of its systems or premises.

12. Personal data breach notification

GetSigning will notify the Customer without undue delay, and in any event within 72 hours of becoming aware, of any Personal Data Breach affecting Customer Data, and will provide information reasonably available to it to help the Customer meet its own notification obligations, and will take reasonable steps to mitigate the effects of the breach.

13. International transfers

Customer Data is hosted and processed within the UK. Some Sub-processors (Stripe, and the parent entities of AWS and Cloudflare) are incorporated outside the UK. Where personal data is transferred outside the UK, GetSigning relies on an adequate safeguard recognised under the Data Protection Legislation, such as the UK's International Data Transfer Addendum to the EU Standard Contractual Clauses, or the Sub-processor's own adequacy or certification basis, before making the transfer.

14. Liability

Each party's liability arising out of or in connection with this DPA is subject to the limitations and exclusions of liability set out in the Principal Agreement. Nothing in this DPA limits either party's liability for matters which cannot lawfully be limited or excluded, including liability for a party's own breach of the Data Protection Legislation.

15. General

This DPA is governed by the laws of England and Wales. In the event of any conflict between this DPA and the Principal Agreement in relation to the processing of personal data, this DPA prevails.

This DPA is a standard document forming part of GetSigning's Terms of Service. It takes effect, without any separate signature, from whichever is earliest: the Customer's acceptance of the Terms of Service, the Customer's continued use of the Services, or the date at the top of this DPA.