Business Privacy & DPA Readiness
Effective date: April 20, 2026 Last updated: April 20, 2026
Plain English, first
This page is for businesses, teams, and partners that want to use SignRoad with their members. It explains how to request a signed Data Processing Addendum (DPA), how we handle EU data-protection questions, and what we still need to finalize before a B2B launch.
If you are a regular individual user, the Privacy Policy, Terms of Service, and GDPR Notice cover you.
Requesting a signed DPA
The Data Processing Addendum in our legal documents is a template. Before a B2B relationship begins, both sides should review and sign a copy that matches the actual Business Agreement and Order Form.
To start that process:
- Email privacy@signroad.com with the subject line "DPA request".
- Include the organization name, number of expected members, and any jurisdiction-specific requirements.
- We will return a draft within 5 business days.
EU / EEA / UK representative (Article 27)
SignRoad is incorporated in Wyoming, United States. Under GDPR Article 27, a non-EU controller or processor must designate an EU representative once it offers goods or services to, or monitors the behavior of, people in the EU / EEA / UK.
- Current status: We have not appointed a local EU representative because the active EU / EEA / UK user population has not yet reached the threshold where one is required. privacy@signroad.com serves as the privacy contact in the meantime.
- Trigger: Once the number of active EU / EEA / UK users reaches the threshold set by our legal counsel, we will appoint a representative in an EU member state and update this page and the GDPR Notice.
- How to ask: Email privacy@signroad.com with "EU representative" in the subject.
International transfers
For transfers outside the EU / EEA / UK, we rely on:
- the EU-US Data Privacy Framework, where the provider is certified;
- Standard Contractual Clauses (2021/914) for other providers;
- the UK International Data Transfer Addendum for UK data;
- supplementary technical and contractual measures where needed.
You can request a copy of the transfer safeguards for any provider at privacy@signroad.com.
Security and audit documentation
On request, we can provide:
- a high-level security architecture summary;
- the current sub-processor list;
- answers to standard security questionnaires; and
- a record of any personal-data breach affecting your members.
Please allow 10 business days for non-urgent requests.
B2B launch checklist
Before SignRoad is offered as a team or employer benefit, we will complete:
- [ ] Countersigned DPA for the business customer.
- [ ] EU / EEA / UK Article 27 representative, if needed.
- [ ] Finalization of the operational email sub-processor.
- [ ] A published transparency report and status page.
- [ ] A dedicated support and escalation path for business customers.
Contact
- Privacy and DPA questions: privacy@signroad.com
- General support: support@signroad.com
- Postal: SignRoad, Privacy Team, 1309 Coffeen Avenue, Suite 1200, Sheridan, WY 82801, USA