signcloud Retour à l'accueil

Data Processing Agreement (DPA)

This agreement forms part of the Terms. It governs the processing that MILONO HOLDING (254 Rue Vendôme, 69003 Lyon, France — the "Processor") carries out on behalf of the customer (the "Controller") when the customer uses the SignCloud Services, pursuant to Article 28 GDPR.

1. Subject matter, duration, nature and purpose

Processing consists of hosting, sealing, transmitting, verifying and retaining documents, signature evidence, identity-verification data and e-mail evidence, strictly to provide the Services, for the duration of the contract plus the retention periods chosen by the Controller.

2. Data and data subjects

  • Signature: documents and their content; signers' surname, first name, e-mail, mobile number, IP, signature image; audit events.
  • Identity: identity-document data and images, liveness/selfie captures (processed for the verification then deleted — see privacy policy), company identifiers.
  • Mail: message content and attachments (encrypted at rest), sender and recipient addresses, delivery transcripts.

Data subjects: the Controller's staff, its signers, recipients and verified persons.

3. Processor's obligations

The Processor: processes only on documented instructions (the use of the Services constituting such instructions); ensures persons authorised are bound by confidentiality; implements the technical and organisational measures described on the Security page (TLS, encryption at rest for vault content, hashed passwords, chained audit logs, per-organisation isolation, 2FA); assists the Controller with data-subject requests and Articles 32-36; notifies the Controller without undue delay and at the latest within 48 hours of becoming aware of a personal-data breach affecting its data; makes available the information necessary to demonstrate compliance and allows audits (once per year, at the Controller's cost, with 30 days' notice, without access to other customers' data).

4. Sub-processors

The Controller gives general authorisation for the sub-processors listed in the privacy policy (hosting o2switch — France; encrypted backups: Hetzner, Germany (European Union); Stripe; OpenAI when AI features are used; RFC 3161 timestamp authority receiving only fingerprints). The Processor informs the Controller at least 30 days before adding or replacing a sub-processor; the Controller may object on legitimate grounds, in which case it may terminate the affected Service.

5. Transfers

Data is hosted in France with encrypted backups in the European Union. Where a sub-processor involves a transfer outside the EU (e.g. Stripe, OpenAI), it is governed by an adequacy decision or the European Commission's Standard Contractual Clauses.

6. End of processing

Upon termination, the Processor returns the data in a standard format then deletes it, except data subject to a statutory retention duty or legal hold, retained in isolation for the applicable duration only. The evidence-retention packages (10/20/50 years) chosen by the Controller survive termination as agreed.

7. Contact

Data-protection contact: contact@signcloud.fr. A countersigned copy of this DPA is available on request for the Controller's records.

Version 1.0 — 21 August 2026.

signcloud

Traceable electronic signature: consent, OTP and verifiable integrity.

Product

Features Pricing FAQ Modules & integrations API & developers Security

Legal

Legal notice Terms Privacy (GDPR) Cookies

Contact

contact@signcloud.fr Sign up Log in
eIDAS framework Encrypted & SHA-256 sealed SMS verification Hosted in the European Union Data protection
© 2026 SignCloud — All rights reserved. · Simple/advanced electronic signature (not qualified under eIDAS).