1.What this is and when it applies
This Data Processing Addendum (“DPA”) is for businesses and other organisations that use Pagestro for work, for example to send documents for signature, send invoices or run a team. It forms part of our Terms of service and applies automatically to every business account, with no separate signature. If you are using Pagestro only for yourself, our Privacy policy is the document that matters.
If your organisation needs a signed copy, email gdpr@pagestro.com.
2.Who is controller and who is processor
You (the business user) are the controller of the personal data you put into Pagestro about other people: the people you send documents to for signature (signers), the people you invoice, your contacts and your team. Pagestro, a service of Sigma Studio (see the Terms for the full legal details), is your processor for that data.
For your own account data (your sign-in details, billing and how you use the site) and for security, fraud prevention and the platform’s own records, Pagestro is a controller in its own right, as described in the Privacy policy.
3.What we do for you as your processor
- Instructions: we process your data only to provide Pagestro to you, following your instructions (what you upload, send, save and delete in the service, and these terms). If we think an instruction breaks the law, we will tell you.
- Confidentiality: only people who need access to run the service can see your data, and they are bound to keep it confidential.
- Security: we use measures that fit the risk, including encryption in transit, access controls, tamper-evident signature records and backups. They are described on our Security page.
- Help with people’s rights: if someone asks us about data we process for you (for example a signer asking for a copy), we pass the request to you, and we help you answer it with the tools in the service or on reasonable request.
- Audits: we give you the information needed to show that we follow this DPA, on request. Because Pagestro runs on shared services, this is done by answers and documents, not by visiting servers.
4.Sub-processors
You allow us to use these sub-processors to run Pagestro, under written terms that protect your data:
- Hosting: website and database. Servers are in the United States.
- Email delivery: sending our account, invoice, signature and newsletter emails and receiving mail sent to our support addresses.
- Payment processing: Paddle, as Merchant of Record for subscriptions (Paddle is an independent controller for payment data).
- Security and content delivery: delivering the website, protecting it from attacks and checking forms for bots.
- Storage: cloud file storage for the files saved to your account.
- Link safety: checking web addresses in links, QR codes, invoices and uploaded PDFs against lists of phishing and malware sites (only the web address is sent).
- Sign-in: a third-party account provider, only if you or your team choose to sign in with a third-party account.
Assistants you connect yourself are your own providers, not our sub-processors.
The current list of sub-processors is available on request at support@pagestro.com, and we send it within 5 working days. We email the owners of business and team accounts at least 14 days before we add or replace a sub-processor. If you object on reasonable data protection grounds, tell us in that time. We will try to find a solution, and if we cannot, you may stop using Pagestro and cancel before the change applies.
5.Data breaches
We take reasonable measures to protect the data we process for you. If we become aware of a breach of security of our systems or those of our sub-processors that leads to loss, change or unauthorised access to your personal data, we tell you without undue delay, and we aim to do so within 48 hours. We will share what we know, what we are doing about it, and help you meet your own duties to tell regulators and the people affected.
You are responsible for securing your own account, devices and credentials (such as passwords, passkeys, sign-in links, API keys and connected apps), and for the people on your team. To the extent the law allows, we are not responsible for a breach that is caused by your systems, devices, credentials or actions, or those of your team, for example a shared, weak or stolen password. You remain responsible for such a breach, including for telling the people and authorities affected. Doing our best is not a guarantee: no system is perfectly secure.
6.Deleting or returning your data
While your account is open you can download or delete your data in the service. When you delete your account, we delete your saved documents, invoices and other data. We keep backup copies for a limited time and then delete them.
The exception is signature requests you sent. They are evidence for you and for the people who signed, so we keep them with their audit trail, even after your account is gone, until 7 years after each request ended (completed, declined, cancelled or expired), and then delete them. During that time they stay protected by this DPA and the Privacy policy. Where the law requires us to keep other records (for example tax records), we keep only those.
7.International transfers
Where personal data from the EEA, Switzerland or the UK is transferred to a country without an adequacy decision, the parties agree that the EU Standard Contractual Clauses (Module 2, controller to processor) and, for the UK, the UK International Data Transfer Addendum, are incorporated into this DPA by reference. You are the data exporter and Pagestro is the data importer. The details they ask for (parties, subject matter, data types and security measures) are in this DPA and our Security page, and the sub-processors are those on the list we send on request (see “Sub-processors”). For the Swiss and UK versions, references to the GDPR are read as references to the local law. Please ask us if you need a signed copy.
8.What data and whose
- People: signers and recipients, people you invoice, your contacts and your team members.
- Data: names, email addresses, postal addresses, the contents of documents and invoices you save or send, signature images, field values, and for signing: IP address, device and browser, and time of each step.
- Why and how long: to provide the service for as long as your account is open, and signature records until 7 years after each request ended.
Contact: gdpr@pagestro.com.