Data Processing Agreement

The DPA, in plain English.

Last updated: 16 June 2026 · Version 1.0
Heads up. This DPA is automatically incorporated into our terms of service for every Business-plan customer. You don't need a signed copy to use SignPad. If your procurement team needs a counter-signed PDF version, email sign@signpad.com.au with "DPA request" in the subject line, we'll send one back within 2 business days.

1. The parties

This Data Processing Agreement is between you, the SignPad customer (referred to as the Customer or Controller), and Brix Super Group Pty Ltd (ACN 692 753 674), trading as SignPad (referred to as SignPad or the Processor).

2. Purpose

This DPA records how SignPad processes personal information on behalf of the Customer in connection with the SignPad service. It supplements the terms of service and the privacy policy. If anything in this DPA conflicts with those, the DPA wins (for processing matters only).

3. Roles

For documents the Customer sends through SignPad:

4. Subject matter, duration, nature and purpose

ItemDescription
Subject matterElectronic signature collection, audit trail generation, document storage and delivery on behalf of the Customer.
DurationThe term of the Customer's subscription, plus any post-termination retention period stated in the terms of service.
NatureReceiving, storing, displaying, transmitting and stamping electronic documents and the associated audit metadata.
PurposeProviding the SignPad service per the Customer's instructions.
Types of dataNames, email addresses, IP addresses, geolocation derived from IP, device summaries, signature images, and any personal information contained in the body of the documents the Customer uploads.
Categories of data subjectThe Customer's employees, signers, recipients and viewers.

5. Customer instructions

SignPad will process personal information only on the Customer's documented instructions. Using the SignPad product (uploading, sending, configuring branding, inviting team members) constitutes documented instructions. The Customer warrants it has obtained all necessary consents from data subjects.

6. Confidentiality

SignPad ensures that any of its personnel authorised to process personal information are bound by appropriate confidentiality obligations.

7. Security measures

SignPad implements appropriate technical and organisational measures to protect personal information against accidental or unlawful destruction, loss, alteration, unauthorised disclosure or access. The current measures are described in the security page and include at minimum:

8. Sub-processors

The Customer authorises SignPad to engage the sub-processors listed in privacy policy section 7. SignPad will notify the Customer at least 30 days before adding or replacing a sub-processor. The Customer may object on reasonable data-protection grounds; if SignPad cannot accommodate the objection, the Customer may terminate the affected service for a pro-rated refund.

9. Data subject requests

If a data subject contacts SignPad directly with a request to access, correct, delete, restrict, port or object to processing, SignPad will, where reasonably possible, forward the request to the Customer within 5 business days. SignPad will provide reasonable assistance to the Customer in responding to data subject requests, taking into account the nature of the processing and the information available to SignPad.

10. Personal data breach

If SignPad becomes aware of a personal data breach affecting the Customer's data, SignPad will notify the Customer without undue delay and in any event within 72 hours of becoming aware. The notification will include the nature of the breach, the categories and approximate number of data subjects, the likely consequences, and the measures taken or proposed to address the breach.

11. International transfers

The Customer's data is stored in Australia (AWS Sydney). SignPad may transfer personal information outside Australia only as described in the privacy policy, and only with appropriate safeguards including, where required, the EU Standard Contractual Clauses (Commission Implementing Decision (EU) 2021/914) or equivalent.

12. Records

SignPad maintains records of processing activities in accordance with Article 30(2) GDPR (or equivalent under the Privacy Act) and will make them available to the Customer upon reasonable request.

13. Audits

The Customer (or its independent auditor) may audit SignPad's compliance with this DPA once per 12-month period, on at least 30 days' written notice, during business hours, with reasonable scope, and at the Customer's expense. Audits must not unreasonably interfere with SignPad's operations or compromise other customers' confidentiality. SignPad may discharge this obligation by providing SOC 2 or equivalent third-party audit reports once those become available.

14. Return or deletion at the end of services

On termination of the subscription, the Customer has the timeframe stated in the terms of service section 21 to export their data. After that period, SignPad will delete the Customer's data within 90 days, except where it is required by law to retain a copy.

15. Liability

SignPad's liability under this DPA is subject to the limitation of liability in the terms of service section 18. Nothing in this DPA limits any liability that cannot be limited under applicable law.

16. Conflict

If this DPA conflicts with the terms of service, this DPA prevails for matters of personal data processing. For everything else, the terms of service prevail.

17. Governing law

This DPA is governed by the laws of Queensland, Australia, and the laws of the Commonwealth of Australia that apply in Queensland.

18. Contact

For data-protection matters, contact sign@signpad.com.au with "DPA" in the subject line.