Version 1.0 · Draft · Owner: DPO
Download .md →Touch2Sign Ltd
Version: 1.0
Effective date: 11 July 2026
Owner: [DPO / Privacy Lead]
Approved by: Robert — CEO / Managing Director
Next review: 11 July 2027
Define how Touch2Sign receives, verifies, and responds to requests from individuals exercising rights under GDPR Articles 15–22 and UK GDPR. Ensures responses within statutory timeframes and clarifies Touch2Sign's role as controller vs processor.
Applies to requests from:
Covers rights of access, rectification, erasure, restriction, portability, and objection.
| Channel | Detail | Primary email | privacy@touch2sign.com |
|---|---|
| Postal | [Touch2Sign Ltd registered address] |
| Web form | Link from Privacy Policy (when published) |
All DSARs logged in DSAR Register within 2 business days of receipt.
| Scenario | Touch2Sign role | Who responds | Signer data processed on behalf of customer (documents, audit trail) | Processor | Forward to customer controller; assist per DPA §6 |
|---|---|---|
| Touch2Sign account billing, marketing, website analytics | Controller | Touch2Sign responds directly |
| Employee data | Controller | HR + DPO |
When Touch2Sign is processor, the customer organisation is controller and primary respondent. Touch2Sign assists within 30 days and DPA terms.
| Milestone | Target | Acknowledgement of receipt | 5 business days |
|---|---|
| Identity verification complete | 10 business days |
| Full response | 30 calendar days from receipt |
| Extension (complex requests) | + 60 days with reason notified to data subject |
| Processor assistance to customer | 30 calendar days from customer request |
Record in DSAR Register:
| Field | Description | DSAR ID | DSAR-YYYY-NNN |
|---|---|
| Date received | |
| Requester name and contact | |
| Rights exercised | Access / erasure / etc. |
| Touch2Sign role | Controller / processor |
| Customer org (if applicable) | |
| Status | Open / verifying / in progress / closed |
Before disclosing personal data:
Search relevant systems:
| System | Data | RDS | users, recipients, audit_log, org membership |
|---|---|
| S3 | Signed PDFs linked to requester (if access request) |
| Cognito | Account attributes |
| Support tickets | Tickets referencing requester |
| Stripe | Billing metadata (controller requests only) |
| Sub-processors | Query OneID / eID Easy if IDV data requested — via DPA |
Document search scope and any data not found.
DPO reviews for exemptions (Art 15(4), manifestly unfounded/excessive requests Art 12(5)), conflicts with other data subjects' rights, and erasure limitations (signature evidence retention).
Provide response in structured, commonly used, machine-readable format where portability requested (JSON or CSV + PDF copies of documents).
Access response includes:
Update DSAR Register; retain record 3 years.
| Right | Touch2Sign action | Access (Art 15) | Export personal data; explain processing |
|---|---|
| Rectification (Art 16) | Correct inaccurate account data; notify customer controller for document content |
| Erasure (Art 17) | Per Data Retention Policy; may refuse where signature evidence required |
| Restriction (Art 18) | Flag account pending dispute resolution |
| Portability (Art 20) | Provide machine-readable export where processing automated + consent/contract |
| Objection (Art 21) | Assess; stop marketing; document legitimate interest balancing |
If request refused or partially fulfilled:
Manifestly unfounded or excessive requests: charge reasonable fee or refuse per Art 12(5) — DPO + Legal approval required.
When request concerns signer data for a customer organisation:
Template available to customers in DPA annex.
First request free. Repeated or manifestly unfounded requests may incur reasonable administrative fee per GDPR Art 12(5).
Reviewed annually and after significant DSAR volume or regulatory guidance changes.
Approval
| Name | Role | Signature | Date | Robert | CEO | Electronic | 11 July 2026 |
|---|---|---|---|
| DPO / Privacy Lead |
Questions: security@touch2sign.com · privacy@touch2sign.com