# Record of Processing Activities (ROPA)

**Organisation:** Touch2Sign Ltd (Republic of Ireland)  
**Privacy contact:** privacy@touch2sign.com  
**Version:** 1.0 · **Last updated:** July 2026  
**Review cycle:** Annual (or on material product change)

---

## 1. Controller activities (Touch2Sign as data controller)

Touch2Sign determines purposes and means for the following processing:

| Ref | Processing activity | Data categories | Data subjects | Lawful basis (GDPR Art 6) | Recipients / sub-processors | Retention | Transfers |
|-----|---------------------|-----------------|---------------|---------------------------|----------------------------|-----------|-----------|
| C1 | Customer account registration & authentication | Name, email, password hash, org name, role | Customer users | **Contract** (6(1)(b)) | AWS Cognito, RDS, SES | Life of account + 90 days | EU (Ireland) |
| C2 | Subscription billing & invoicing | Name, email, billing address, payment metadata | Account admins | **Contract** (6(1)(b)) | Stripe | 7 years (tax/accounting) | EU; Stripe US (SCCs) |
| C3 | Customer support | Email, name, ticket content, account ID | Customers, signers (if they contact us) | **Contract** / **Legitimate interest** (6(1)(f)) | AWS SES, RDS | 2 years | EU |
| C4 | Marketing contact form / enquiries | Name, email, company, message | Prospects | **Consent** (6(1)(a)) or **Legitimate interest** (B2B) | AWS SES, CRM if enabled | Until opt-out / 2 years | EU |
| C5 | Platform security & fraud prevention | IP address (may be truncated), user agent, timestamps, auth events | All users | **Legitimate interest** (6(1)(f)) — see LIA | AWS CloudWatch, RDS audit | 90–365 days | EU |
| C6 | Cookie / session management | Session ID, consent preference | Website visitors | **Strictly necessary** / **Consent** for non-essential | — | Session / 12 months | EU |

---

## 2. Processor activities (on behalf of customers)

Touch2Sign processes personal data **only on documented instructions** from the Customer (controller) under the [DPA](/legal/dpa).

| Ref | Processing activity | Data categories | Data subjects | Customer lawful basis (typical) | Sub-processors | Default retention |
|-----|---------------------|-----------------|---------------|--------------------------------|----------------|-------------------|
| P1 | Electronic signature workflow | Name, email, signature image/data, IP, device info, timestamps | Signers, senders | Contract with signer / legal obligation | AWS, SES, SNS | Customer-configured (min 1y, default 7y) |
| P2 | Document storage & integrity | Document content, metadata, SHA-256 hash | Signers, parties named in docs | Contract / legal obligation | AWS S3, RDS | Same as P1 |
| P3 | Identity verification (AES) | Name, bank verification result (OneID) | Signers | Customer instruction + IDV consent | OneID Limited | Same as P1 |
| P4 | Qualified electronic signature (QES) | Identity attributes, signature hash (not full PDF to QTSP) | Signers, witnesses (IE) | Customer instruction / legal obligation | eID Easy (QTSP) | Same as P1 |
| P5 | eWitness attestation | Witness name, phone, OTP, declarations, IP, timestamps | Witnesses, signers | Customer instruction / legal obligation | OneID, eID Easy, SNS | Same as P1 |
| P6 | Signing invitations (email/SMS) | Email, mobile number, document title | Signers | Customer instruction | AWS SES, SNS | Until send complete + logs 90d |
| P7 | AI document Q&A (Aria / Sentinel, if enabled) | Document text excerpts, signer questions | Signers | Customer instruction | Anthropic (US, SCCs) | Same as P1 |
| P8 | In-document payments (if enabled) | Payment metadata | Signers | Customer instruction | Stripe | Per Stripe + customer retention |
| P9 | Audit trail & compliance reports | All signing events, IDV level, ERSD acceptance | Signers, witnesses | Legal obligation / contract | AWS RDS, S3 | Same as P1 |

**Customer obligation:** Provide privacy notices to signers and witnesses; select appropriate signature level; instruct Touch2Sign on retention and erasure.

---

## 3. Security measures (summary)

- TLS 1.2+ in transit; AES-256 at rest (AWS S3, RDS)  
- Role-based access control; MFA for admin accounts  
- Signing tokens time-limited; audit log immutability  
- Sub-processor DPAs and SCCs where required  
- Incident response and 72-hour breach notification commitment  

Details: [Information Security Policy](/legal/policies/information-security)

---

## 4. Data subject rights routing

| Request type | Touch2Sign role | Action |
|--------------|-----------------|--------|
| Account holder access/erasure | Controller | Process per [DSAR Procedure](/legal/policies/dsar) |
| Signer access/erasure | Processor | Refer to Customer unless Customer instructs Touch2Sign |
| Complaint to supervisory authority | Either | Cooperate; DPC (IE) / ICO (UK) |

**Intake:** privacy@touch2sign.com · **SLA:** 30 days

---

## 5. Related documents

- [DPIA — Platform](/legal/policies/dpia)  
- [Sub-processor register](../SUB_PROCESSORS.md)  
- [International transfer register](../INTERNATIONAL_TRANSFER_REGISTER.md)  
- [Data retention policy](/legal/policies/data-retention)  
- [Privacy Policy](/privacy)

---

## 6. Approval

| Role | Name | Date | Signature |
|------|------|------|-----------|
| Privacy lead | _TBC_ | | |
| CEO | _TBC_ | | |
