Touch2Sign Policy Library
← All policies

Record of Processing Activities (ROPA)

Version 1.0 · Approved · Owner: Privacy Lead

Download .md →

Record of Processing Activities (ROPA)

Organisation: Touch2Sign Ltd (Republic of Ireland)

Privacy contact: privacy@touch2sign.com

Version: 1.0 · Last updated: July 2026

Review cycle: Annual (or on material product change)


1. Controller activities (Touch2Sign as data controller)

Touch2Sign determines purposes and means for the following processing:

Ref Processing activity Data categories Data subjects Lawful basis (GDPR Art 6) Recipients / sub-processors Retention Transfers
C1 Customer account registration & authentication Name, email, password hash, org name, role Customer users Contract (6(1)(b)) AWS Cognito, RDS, SES Life of account + 90 days EU (Ireland)
C2 Subscription billing & invoicing Name, email, billing address, payment metadata Account admins Contract (6(1)(b)) Stripe 7 years (tax/accounting) EU; Stripe US (SCCs)
C3 Customer support Email, name, ticket content, account ID Customers, signers (if they contact us) Contract / Legitimate interest (6(1)(f)) AWS SES, RDS 2 years EU
C4 Marketing contact form / enquiries Name, email, company, message Prospects Consent (6(1)(a)) or Legitimate interest (B2B) AWS SES, CRM if enabled Until opt-out / 2 years EU
C5 Platform security & fraud prevention IP address (may be truncated), user agent, timestamps, auth events All users Legitimate interest (6(1)(f)) — see LIA AWS CloudWatch, RDS audit 90–365 days EU
C6 Cookie / session management Session ID, consent preference Website visitors Strictly necessary / Consent for non-essential Session / 12 months EU

2. Processor activities (on behalf of customers)

Touch2Sign processes personal data only on documented instructions from the Customer (controller) under the DPA.

Ref Processing activity Data categories Data subjects Customer lawful basis (typical) Sub-processors Default retention
P1 Electronic signature workflow Name, email, signature image/data, IP, device info, timestamps Signers, senders Contract with signer / legal obligation AWS, SES, SNS Customer-configured (min 1y, default 7y)
P2 Document storage & integrity Document content, metadata, SHA-256 hash Signers, parties named in docs Contract / legal obligation AWS S3, RDS Same as P1
P3 Identity verification (AES) Name, bank verification result (OneID) Signers Customer instruction + IDV consent OneID Limited Same as P1
P4 Qualified electronic signature (QES) Identity attributes, signature hash (not full PDF to QTSP) Signers, witnesses (IE) Customer instruction / legal obligation eID Easy (QTSP) Same as P1
P5 eWitness attestation Witness name, phone, OTP, declarations, IP, timestamps Witnesses, signers Customer instruction / legal obligation OneID, eID Easy, SNS Same as P1
P6 Signing invitations (email/SMS) Email, mobile number, document title Signers Customer instruction AWS SES, SNS Until send complete + logs 90d
P7 AI document Q&A (Aria / Sentinel, if enabled) Document text excerpts, signer questions Signers Customer instruction Anthropic (US, SCCs) Same as P1
P8 In-document payments (if enabled) Payment metadata Signers Customer instruction Stripe Per Stripe + customer retention
P9 Audit trail & compliance reports All signing events, IDV level, ERSD acceptance Signers, witnesses Legal obligation / contract AWS RDS, S3 Same as P1

Customer obligation: Provide privacy notices to signers and witnesses; select appropriate signature level; instruct Touch2Sign on retention and erasure.


3. Security measures (summary)

  • TLS 1.2+ in transit; AES-256 at rest (AWS S3, RDS)
  • Role-based access control; MFA for admin accounts
  • Signing tokens time-limited; audit log immutability
  • Sub-processor DPAs and SCCs where required
  • Incident response and 72-hour breach notification commitment

Details: Information Security Policy


4. Data subject rights routing

Request type Touch2Sign role Action
Account holder access/erasure Controller Process per DSAR Procedure
Signer access/erasure Processor Refer to Customer unless Customer instructs Touch2Sign
Complaint to supervisory authority Either Cooperate; DPC (IE) / ICO (UK)

Intake: privacy@touch2sign.com · SLA: 30 days


5. Related documents


6. Approval

Role Name Date Signature
Privacy lead _TBC_
CEO _TBC_

Questions: security@touch2sign.com · privacy@touch2sign.com