Touch2Sign Policy Library
← All policies

Vendor & Sub-processor Management

Version 1.0 · Draft · Owner: Legal + Security

Download .md →

Vendor & Sub-processor Management Policy

Touch2Sign Ltd

Version: 1.0

Effective date: 11 July 2026

Owner: Robert — Security Lead + [Legal]

Approved by: Robert — CEO / Managing Director

Next review: 11 July 2027


1. Purpose

Establish how Touch2Sign assesses, engages, monitors, and offboards third-party vendors and GDPR sub-processors that process personal data or provide critical infrastructure for the eSignature and eWitness platform.

2. Scope

Applies to all vendors that:

  • Process personal data on behalf of Touch2Sign customers (sub-processors under GDPR Art 28)
  • Host or transmit Touch2Sign production data
  • Provide identity verification, payments, AI, email, or other integrated services

3. Roles

Role Responsibility
Legal DPA negotiation; SCCs; customer sub-processor notifications
Security Lead Security assessment; risk rating; annual review
DPO DPIA for high-risk processors; transfer impact assessments
Engineering Lead Technical integration review; data minimisation
CEO Approval for high-risk or new category vendors

4. Vendor assessment process

4.1 Pre-engagement checklist

Before integrating a new vendor or sub-processor:

  • [ ] Business purpose and data categories documented
  • [ ] Processing location(s) identified (EU, UK, US, other)
  • [ ] DPA or equivalent signed (GDPR Art 28 clauses)
  • [ ] SCCs, UK IDTA, or adequacy decision for non-EEA transfers
  • [ ] SOC 2 Type II and/or ISO 27001 certificate requested and filed
  • [ ] Security questionnaire completed (CAIQ, SIG Lite, or vendor-specific)
  • [ ] Incident notification commitment (≤ 72 hours)
  • [ ] Data return / deletion on termination confirmed
  • [ ] Sub-processor listed in Sub-processor Register (docs/compliance/SUB_PROCESSORS.md)
  • [ ] Customer notification plan if material sub-processor (DPA §5 — 30 days notice)

4.2 Risk rating

Rating Criteria Approval
Low EU-hosted; certified; limited data Security Lead
Medium Non-EU with SCCs; IDV or payments Security Lead + Legal
High Biometric, AI document content, US transfer of customer docs CEO + DPIA

5. Key sub-processors

The following vendors are approved for use subject to ongoing review. Full detail in Sub-processor Register.

Vendor Purpose Location Key safeguards Review
Amazon Web Services Hosting — S3, RDS, Cognito, SES, CloudWatch, App Runner EU (Ireland) eu-west-1 AWS DPA, SCCs; SOC 2, ISO 27001 Annual
Stripe Payment processing, subscriptions US/EU Stripe DPA, SCCs; PCI DSS Annual
OneID Limited UK bank identity verification (AES) UK DPA with OneID; adequacy / safeguards Annual
eID Easy / Dokobit QES signing and EU identity (QTSP) EU (LT/EE) eIDAS QTSP audit; DPA Annual
Anthropic Document Q&A (Aria AI) USA SCCs; data minimisation; DPIA required Semi-annual

Additional processors (Veriff, Signicat, Adyen, AWS Bedrock, etc.) require assessment before production use and entry in the register.

6. SOC reports and certifications

Requirement Action
SOC 2 Type II Request annually; review bridge letter if gap period
ISO 27001 Accept certificate + scope statement
PCI DSS Required for payment processors (Stripe)
eIDAS / QTSP Required for eID Easy QES reliance
Gap remediation Vendor must respond to critical findings before go-live

Reports stored in secure GRC folder — not in public repository.

7. Sub-processor register maintenance

  • Register maintained in docs/compliance/SUB_PROCESSORS.md
  • Reviewed quarterly by Security Lead and Legal
  • Published summary available to customers via DPA §5
  • Changes communicated 30 days before new sub-processor processing (unless emergency with DPA carve-out)

7.1 Customer notification template

```

Subject: Touch2Sign sub-processor update

We are adding [VENDOR] for [PURPOSE]. Processing occurs in [LOCATION].

Safeguards: [SCCs/DPA]. Effective date: [DATE+30d].

Objection period: 30 days per DPA §5.

Contact: legal@touch2sign.com

```

8. Ongoing monitoring

Activity Frequency
Certificate / SOC report renewal Annual
Security news and breach monitoring Continuous
Re-assessment after vendor incident As needed
Contract renewal review At renewal
DPIA refresh (high-risk vendors) Annual or on scope change

Vendor incidents affecting Touch2Sign data: follow Incident Response Plan §7.2 (IDV provider incident playbook).

9. Offboarding

When terminating a vendor:

  1. Revoke API keys and IAM cross-account access
  2. Confirm data deletion or return per DPA
  3. Obtain deletion certificate where available
  4. Remove from Sub-processor Register
  5. Notify customers if sub-processor change affects their data
  6. Update privacy policy and DPA annex if published list changes

10. Prohibited engagements

Without CEO and Legal approval:

  • Vendors in sanctioned jurisdictions
  • Processors refusing DPA or adequate transfer mechanism
  • Storage of customer documents in uncertified consumer cloud tools
  • Sharing production database access with vendor support without time-limited credentials

11. Related documents

  • Sub-processor Register (SUB_PROCESSORS.md)
  • Data Processing Agreement
  • Information Security Policy
  • Incident Response Plan
  • Risk Management Policy

12. Review

Reviewed annually and when adding or removing material sub-processors.


Approval

Name Role Signature Date
Robert CEO / Security Lead Electronic 11 July 2026
Legal

Questions: security@touch2sign.com · privacy@touch2sign.com