Touch2Sign

Data Processing Agreement

Last updated: 12 August 2026 · Version 1.1

Download PDF →Request signed DPA
This Data Processing Agreement (“DPA”) forms part of the Touch2Sign Terms of Service and applies to all Touch2Sign customers who process personal data of EU/EEA or UK data subjects.

Data Processor: Touch2Sign Ltd, a company incorporated in the Republic of Ireland (“Touch2Sign”, “we”, “us”)

Data Controller: The entity that has agreed to the Touch2Sign Terms of Service (“Customer”, “you”)

1. Definitions

“Personal Data” means any information relating to an identified or identifiable natural person as defined under GDPR Article 4(1).

“Processing” means any operation performed on Personal Data, including collection, storage, use, disclosure, and deletion.

“Sub-processor” means any third party engaged by Touch2Sign to process Personal Data on behalf of the Customer.

“GDPR” means Regulation (EU) 2016/679 and, in the context of the UK, the UK GDPR as retained in domestic law.

2. Processing of Personal Data

Subject matter: Provision of electronic signature, document management, and identity verification services.

Duration: For the term of the Customer’s Touch2Sign subscription and as required by applicable law thereafter.

Nature and purpose: Processing of Personal Data to facilitate document signing, signer identity verification, audit trail generation, and related services.

Categories of personal data: Name, email address, IP address, device information, signature data, identity verification data (where IDV is used), billing and metering metadata, and document metadata.

Categories of data subjects: Document signatories, witnesses, and Customer’s end users.

3. Customer (Controller) Obligations

The Customer shall:

  • Ensure it has a lawful basis for processing Personal Data through Touch2Sign
  • Provide required privacy notices to data subjects
  • Ensure it does not instruct Touch2Sign to process Personal Data in violation of applicable law
  • Notify Touch2Sign immediately of any data subject requests or regulatory inquiries

4. Touch2Sign (Processor) Obligations

Touch2Sign shall:

  • Process Personal Data only on documented instructions from the Customer
  • Ensure persons authorised to process Personal Data are bound by confidentiality
  • Implement appropriate technical and organisational security measures aligned with ISO 27001 and SOC 2 programmes (certification in progress)
  • Notify the Customer without undue delay (within 72 hours) upon becoming aware of a Personal Data breach
  • Assist the Customer in fulfilling data subject rights requests
  • Delete or return all Personal Data upon termination of services
  • Make available all information necessary to demonstrate compliance with GDPR Article 28

5. Sub-processors

The Customer grants general authorisation for Touch2Sign to engage the following sub-processors:

Sub-processorPurposeLocation
Amazon Web Services (AWS)Infrastructure hosting, document storage, databaseEU (Ireland)
AWS SESTransactional email deliveryEU (Ireland)
AWS SNSSMS OTP and signing invitationsEU (Ireland)
OneID LimitedUK bank-backed identity verification (AES)UK
eID Easy / DokobitQualified electronic signatures (QES)EU (Lithuania/Estonia)
Signicat ASNordic eID identity verificationEU (Norway)
VeriffDocument and biometric identity verification (optional)EU/USA (SCCs if US)
AnthropicAI document analysis (optional)USA (SCCs applied)
NMIPayment gateway (preferred SaaS billing rail; optional in-doc)USA / acquirer-dependent (DPA + SCCs as applicable)
StripePayment processing (alternate SaaS rail; in-doc default)USA/EU (SCCs applied)

Touch2Sign will notify the Customer of intended changes to sub-processors with at least 30 days' notice where practicable. The Customer may object on reasonable data-protection grounds within that period. Current register: see also docs maintained for due diligence and Privacy Policy.

6. International Data Transfers

Personal Data is primarily processed within the EU/EEA. Where Personal Data is transferred to countries outside the EU/EEA (e.g., Anthropic in the USA), Touch2Sign relies on Standard Contractual Clauses (SCCs) as adopted by the European Commission, or other appropriate safeguards under GDPR Chapter V.

For UK data subjects, transfers rely on the UK International Data Transfer Agreement (IDTA) or equivalent safeguards.

7. Data Retention and Deletion

Touch2Sign retains Personal Data for the duration of the Customer’s subscription plus a maximum of 90 days following termination, unless a longer retention period is required by law. Upon written request, Touch2Sign will delete or return Personal Data within 30 days.

Signed documents are retained for the period configured by the Customer (minimum 1 year, maximum 10 years) to comply with legal requirements for electronic signature evidence.

8. Audit Rights

The Customer may, upon 30 days’ written notice and no more than once per year, conduct an audit of Touch2Sign’s processing activities, or commission a qualified third-party auditor to do so. Touch2Sign will cooperate fully and provide access to relevant systems and documentation.

As an alternative, Touch2Sign may provide its current ISO 27001 Stage 1 / SOC 2 Type I report (when available) and security documentation to satisfy audit requirements.

9. Liability

Each party’s liability under this DPA is subject to the limitations and exclusions set out in the Touch2Sign Terms of Service.

10. Governing Law

This DPA is governed by the laws of the Republic of Ireland. Any disputes shall be subject to the exclusive jurisdiction of the Irish courts.

For questions about this DPA, contact legal@touch2sign.com · Privacy Policy · Terms of Service · Pricing Terms