Version 1.0 · Draft · Owner: Legal + Security
Download .md →Touch2Sign Ltd
Version: 1.0
Effective date: 11 July 2026
Owner: Robert — Security Lead + [Legal]
Approved by: Robert — CEO / Managing Director
Next review: 11 July 2027
Establish how Touch2Sign assesses, engages, monitors, and offboards third-party vendors and GDPR sub-processors that process personal data or provide critical infrastructure for the eSignature and eWitness platform.
Applies to all vendors that:
| Role | Responsibility | Legal | DPA negotiation; SCCs; customer sub-processor notifications |
|---|---|
| Security Lead | Security assessment; risk rating; annual review |
| DPO | DPIA for high-risk processors; transfer impact assessments |
| Engineering Lead | Technical integration review; data minimisation |
| CEO | Approval for high-risk or new category vendors |
Before integrating a new vendor or sub-processor:
docs/compliance/SUB_PROCESSORS.md) | Rating | Criteria | Approval | Low | EU-hosted; certified; limited data | Security Lead |
|---|---|---|
| Medium | Non-EU with SCCs; IDV or payments | Security Lead + Legal |
| High | Biometric, AI document content, US transfer of customer docs | CEO + DPIA |
The following vendors are approved for use subject to ongoing review. Full detail in Sub-processor Register.
| Vendor | Purpose | Location | Key safeguards | Review | Amazon Web Services | Hosting — S3, RDS, Cognito, SES, CloudWatch, App Runner | EU (Ireland) eu-west-1 | AWS DPA, SCCs; SOC 2, ISO 27001 | Annual |
|---|---|---|---|---|
| Stripe | Payment processing, subscriptions | US/EU | Stripe DPA, SCCs; PCI DSS | Annual |
| OneID Limited | UK bank identity verification (AES) | UK | DPA with OneID; adequacy / safeguards | Annual |
| eID Easy / Dokobit | QES signing and EU identity (QTSP) | EU (LT/EE) | eIDAS QTSP audit; DPA | Annual |
| Anthropic | Document Q&A (Aria AI) | USA | SCCs; data minimisation; DPIA required | Semi-annual |
Additional processors (Veriff, Signicat, Adyen, AWS Bedrock, etc.) require assessment before production use and entry in the register.
| Requirement | Action | SOC 2 Type II | Request annually; review bridge letter if gap period |
|---|---|
| ISO 27001 | Accept certificate + scope statement |
| PCI DSS | Required for payment processors (Stripe) |
| eIDAS / QTSP | Required for eID Easy QES reliance |
| Gap remediation | Vendor must respond to critical findings before go-live |
Reports stored in secure GRC folder — not in public repository.
docs/compliance/SUB_PROCESSORS.md ```
Subject: Touch2Sign sub-processor update
We are adding [VENDOR] for [PURPOSE]. Processing occurs in [LOCATION].
Safeguards: [SCCs/DPA]. Effective date: [DATE+30d].
Objection period: 30 days per DPA §5.
Contact: legal@touch2sign.com
```
| Activity | Frequency | Certificate / SOC report renewal | Annual |
|---|---|
| Security news and breach monitoring | Continuous |
| Re-assessment after vendor incident | As needed |
| Contract renewal review | At renewal |
| DPIA refresh (high-risk vendors) | Annual or on scope change |
Vendor incidents affecting Touch2Sign data: follow Incident Response Plan §7.2 (IDV provider incident playbook).
When terminating a vendor:
Without CEO and Legal approval:
SUB_PROCESSORS.md) Reviewed annually and when adding or removing material sub-processors.
Approval
| Name | Role | Signature | Date | Robert | CEO / Security Lead | Electronic | 11 July 2026 |
|---|---|---|---|
| Legal |
Questions: security@touch2sign.com · privacy@touch2sign.com