This Data Processing Agreement is between you, the SignPad customer (referred to as the Customer or Controller), and Brix Super Group Pty Ltd (ACN 692 753 674), trading as SignPad (referred to as SignPad or the Processor).
This DPA records how SignPad processes personal information on behalf of the Customer in connection with the SignPad service. It supplements the terms of service and the privacy policy. If anything in this DPA conflicts with those, the DPA wins (for processing matters only).
For documents the Customer sends through SignPad:
| Item | Description |
|---|---|
| Subject matter | Electronic signature collection, audit trail generation, document storage and delivery on behalf of the Customer. |
| Duration | The term of the Customer's subscription, plus any post-termination retention period stated in the terms of service. |
| Nature | Receiving, storing, displaying, transmitting and stamping electronic documents and the associated audit metadata. |
| Purpose | Providing the SignPad service per the Customer's instructions. |
| Types of data | Names, email addresses, IP addresses, geolocation derived from IP, device summaries, signature images, and any personal information contained in the body of the documents the Customer uploads. |
| Categories of data subject | The Customer's employees, signers, recipients and viewers. |
SignPad will process personal information only on the Customer's documented instructions. Using the SignPad product (uploading, sending, configuring branding, inviting team members) constitutes documented instructions. The Customer warrants it has obtained all necessary consents from data subjects.
SignPad ensures that any of its personnel authorised to process personal information are bound by appropriate confidentiality obligations.
SignPad implements appropriate technical and organisational measures to protect personal information against accidental or unlawful destruction, loss, alteration, unauthorised disclosure or access. The current measures are described in the security page and include at minimum:
The Customer authorises SignPad to engage the sub-processors listed in privacy policy section 7. SignPad will notify the Customer at least 30 days before adding or replacing a sub-processor. The Customer may object on reasonable data-protection grounds; if SignPad cannot accommodate the objection, the Customer may terminate the affected service for a pro-rated refund.
If a data subject contacts SignPad directly with a request to access, correct, delete, restrict, port or object to processing, SignPad will, where reasonably possible, forward the request to the Customer within 5 business days. SignPad will provide reasonable assistance to the Customer in responding to data subject requests, taking into account the nature of the processing and the information available to SignPad.
If SignPad becomes aware of a personal data breach affecting the Customer's data, SignPad will notify the Customer without undue delay and in any event within 72 hours of becoming aware. The notification will include the nature of the breach, the categories and approximate number of data subjects, the likely consequences, and the measures taken or proposed to address the breach.
The Customer's data is stored in Australia (AWS Sydney). SignPad may transfer personal information outside Australia only as described in the privacy policy, and only with appropriate safeguards including, where required, the EU Standard Contractual Clauses (Commission Implementing Decision (EU) 2021/914) or equivalent.
SignPad maintains records of processing activities in accordance with Article 30(2) GDPR (or equivalent under the Privacy Act) and will make them available to the Customer upon reasonable request.
The Customer (or its independent auditor) may audit SignPad's compliance with this DPA once per 12-month period, on at least 30 days' written notice, during business hours, with reasonable scope, and at the Customer's expense. Audits must not unreasonably interfere with SignPad's operations or compromise other customers' confidentiality. SignPad may discharge this obligation by providing SOC 2 or equivalent third-party audit reports once those become available.
On termination of the subscription, the Customer has the timeframe stated in the terms of service section 21 to export their data. After that period, SignPad will delete the Customer's data within 90 days, except where it is required by law to retain a copy.
SignPad's liability under this DPA is subject to the limitation of liability in the terms of service section 18. Nothing in this DPA limits any liability that cannot be limited under applicable law.
If this DPA conflicts with the terms of service, this DPA prevails for matters of personal data processing. For everything else, the terms of service prevail.
This DPA is governed by the laws of Queensland, Australia, and the laws of the Commonwealth of Australia that apply in Queensland.
For data-protection matters, contact sign@signpad.com.au with "DPA" in the subject line.