# Vendor & Sub-processor Management Policy

**Touch2Sign Ltd**  
**Version:** 1.0  
**Effective date:** 11 July 2026  
**Owner:** Robert — Security Lead + [Legal]  
**Approved by:** Robert — CEO / Managing Director  
**Next review:** 11 July 2027

---

## 1. Purpose

Establish how Touch2Sign assesses, engages, monitors, and offboards third-party vendors and GDPR sub-processors that process personal data or provide critical infrastructure for the eSignature and eWitness platform.

## 2. Scope

Applies to all vendors that:

- Process personal data on behalf of Touch2Sign customers (sub-processors under GDPR Art 28)  
- Host or transmit Touch2Sign production data  
- Provide identity verification, payments, AI, email, or other integrated services  

## 3. Roles

| Role | Responsibility |
|------|----------------|
| **Legal** | DPA negotiation; SCCs; customer sub-processor notifications |
| **Security Lead** | Security assessment; risk rating; annual review |
| **DPO** | DPIA for high-risk processors; transfer impact assessments |
| **Engineering Lead** | Technical integration review; data minimisation |
| **CEO** | Approval for high-risk or new category vendors |

## 4. Vendor assessment process

### 4.1 Pre-engagement checklist

Before integrating a new vendor or sub-processor:

- [ ] Business purpose and data categories documented  
- [ ] Processing location(s) identified (EU, UK, US, other)  
- [ ] **DPA** or equivalent signed (GDPR Art 28 clauses)  
- [ ] **SCCs**, UK IDTA, or adequacy decision for non-EEA transfers  
- [ ] SOC 2 Type II and/or ISO 27001 certificate requested and filed  
- [ ] Security questionnaire completed (CAIQ, SIG Lite, or vendor-specific)  
- [ ] Incident notification commitment (**≤ 72 hours**)  
- [ ] Data return / deletion on termination confirmed  
- [ ] Sub-processor listed in **Sub-processor Register** (`docs/compliance/SUB_PROCESSORS.md`)  
- [ ] Customer notification plan if material sub-processor (DPA §5 — **30 days** notice)  

### 4.2 Risk rating

| Rating | Criteria | Approval |
|--------|----------|----------|
| **Low** | EU-hosted; certified; limited data | Security Lead |
| **Medium** | Non-EU with SCCs; IDV or payments | Security Lead + Legal |
| **High** | Biometric, AI document content, US transfer of customer docs | CEO + DPIA |

## 5. Key sub-processors

The following vendors are approved for use subject to ongoing review. Full detail in **Sub-processor Register**.

| Vendor | Purpose | Location | Key safeguards | Review |
|--------|---------|----------|----------------|--------|
| **Amazon Web Services** | Hosting — S3, RDS, Cognito, SES, CloudWatch, App Runner | EU (Ireland) eu-west-1 | AWS DPA, SCCs; SOC 2, ISO 27001 | Annual |
| **Stripe** | Payment processing, subscriptions | US/EU | Stripe DPA, SCCs; PCI DSS | Annual |
| **OneID Limited** | UK bank identity verification (AES) | UK | DPA with OneID; adequacy / safeguards | Annual |
| **eID Easy / Dokobit** | QES signing and EU identity (QTSP) | EU (LT/EE) | eIDAS QTSP audit; DPA | Annual |
| **Anthropic** | Document Q&A (Aria AI) | USA | SCCs; data minimisation; DPIA required | Semi-annual |

Additional processors (Veriff, Signicat, Adyen, AWS Bedrock, etc.) require assessment before production use and entry in the register.

## 6. SOC reports and certifications

| Requirement | Action |
|-------------|--------|
| SOC 2 Type II | Request annually; review bridge letter if gap period |
| ISO 27001 | Accept certificate + scope statement |
| PCI DSS | Required for payment processors (Stripe) |
| eIDAS / QTSP | Required for eID Easy QES reliance |
| Gap remediation | Vendor must respond to critical findings before go-live |

Reports stored in secure GRC folder — not in public repository.

## 7. Sub-processor register maintenance

- Register maintained in `docs/compliance/SUB_PROCESSORS.md`  
- Reviewed **quarterly** by Security Lead and Legal  
- Published summary available to customers via DPA §5  
- Changes communicated **30 days** before new sub-processor processing (unless emergency with DPA carve-out)  

### 7.1 Customer notification template

```
Subject: Touch2Sign sub-processor update

We are adding [VENDOR] for [PURPOSE]. Processing occurs in [LOCATION].
Safeguards: [SCCs/DPA]. Effective date: [DATE+30d].

Objection period: 30 days per DPA §5.
Contact: legal@touch2sign.com
```

## 8. Ongoing monitoring

| Activity | Frequency |
|----------|-----------|
| Certificate / SOC report renewal | Annual |
| Security news and breach monitoring | Continuous |
| Re-assessment after vendor incident | As needed |
| Contract renewal review | At renewal |
| DPIA refresh (high-risk vendors) | Annual or on scope change |

Vendor incidents affecting Touch2Sign data: follow **Incident Response Plan** §7.2 (IDV provider incident playbook).

## 9. Offboarding

When terminating a vendor:

1. Revoke API keys and IAM cross-account access  
2. Confirm data deletion or return per DPA  
3. Obtain deletion certificate where available  
4. Remove from Sub-processor Register  
5. Notify customers if sub-processor change affects their data  
6. Update privacy policy and DPA annex if published list changes  

## 10. Prohibited engagements

Without CEO and Legal approval:

- Vendors in sanctioned jurisdictions  
- Processors refusing DPA or adequate transfer mechanism  
- Storage of customer documents in uncertified consumer cloud tools  
- Sharing production database access with vendor support without time-limited credentials  

## 11. Related documents

- Sub-processor Register (`SUB_PROCESSORS.md`)  
- Data Processing Agreement  
- Information Security Policy  
- Incident Response Plan  
- Risk Management Policy  

## 12. Review

Reviewed **annually** and when adding or removing material sub-processors.

---

**Approval**

| Name | Role | Signature | Date |
|------|------|-----------|------|
| Robert | CEO / Security Lead | Electronic | 11 July 2026 |
| | Legal | | |
