Data Processing Addendum (DPA)

Effective date: April 20, 2026

Plain English, first

This document is for B2B customers — businesses that put Signroad in front of their employees or members (for example, a wellness benefit for a company's team). If you are a regular individual user, you do not need to sign this; the main Terms of Service and Privacy Policy cover you.

A DPA spells out what each side is responsible for when a business (the "Controller") hires Signroad (the "Processor") to handle its employees' or members' personal data. GDPR Article 28 requires it. This DPA:

If you are reviewing this before signing a Signroad Business contract, and something looks wrong for your organization, email privacy@signroad.com and we can usually adjust.


1. Parties and structure

This Data Processing Addendum ("DPA") forms part of the Signroad Business Agreement between SignRoad ("Signroad") and the Customer identified in the Business Agreement ("Customer"). The Customer is the Controller, and Signroad is the Processor, of Customer Personal Data.

If there is a conflict between the Business Agreement and this DPA, this DPA controls for matters of data protection.

2. Definitions

Terms like "Personal Data", "Processing", "Data Subject", "Controller", "Processor", and "Supervisory Authority" have the meanings given in the GDPR (Regulation (EU) 2016/679) and, where applicable, the UK GDPR.

"Customer Personal Data" means Personal Data that Customer submits to Signroad, or that Signroad collects on Customer's behalf, as part of providing the service — for example, Customer's employees' or members' email addresses and the content they put into Signroad.

3. Subject matter, duration, nature, and purpose

4. Categories of data and data subjects

5. Documented instructions

Signroad processes Customer Personal Data only on Customer's documented instructions, which are:

If Signroad believes an instruction violates applicable data protection law, Signroad will tell Customer promptly.

6. Confidentiality

Personnel authorized to process Customer Personal Data are bound by contractual or statutory confidentiality obligations.

7. Security

Signroad implements appropriate technical and organizational measures to protect Customer Personal Data. These are detailed in the Signroad security architecture document and include, at a minimum:

Security measures evolve; Signroad may update them as long as the level of protection does not materially decrease.

8. Sub-processors

Customer authorizes Signroad to engage sub-processors to provide the service. The current sub-processor list is in the Privacy Policy and maintained at the same effective date as this DPA.

9. International transfers

Where Customer Personal Data is transferred from the EU/EEA, UK, or Switzerland to a country that does not have an adequacy decision, the parties rely on:

The SCCs are deemed incorporated into this DPA and are signed by the parties' execution of the Business Agreement.

10. Data subject requests

If a data subject contacts Signroad directly with a rights request (access, deletion, correction, portability, objection), Signroad forwards it to Customer and does not respond substantively unless Customer instructs it to.

Signroad provides tooling — the in-app export and delete flows, plus admin tools for the tenant — that helps Customer fulfill data-subject requests without additional integration work.

11. Personal data breach notification

If Signroad becomes aware of a Personal Data Breach affecting Customer Personal Data, Signroad notifies Customer without undue delay, and in any event within 72 hours of awareness. The notification includes, to the extent known:

Signroad cooperates with Customer on further investigation and reporting to supervisory authorities or data subjects, where Customer is the one legally required to do so.

12. Audit rights

13. Return and deletion

On termination of the Business Agreement, Customer may export Customer Personal Data using the admin tools of the service for up to 30 days after termination. After 30 days, Signroad deletes Customer Personal Data, except where retention is required by law, in which case the data is kept only as long as legally required and remains protected under this DPA.

14. Liability

Liability under this DPA is subject to the limits set in the Business Agreement. Where law does not permit limiting liability for a given claim (for example, claims under GDPR Article 82), that limitation does not apply to the extent law forbids it.

15. Changes

Signroad may update this DPA by giving Customer at least 30 days' notice when the changes are required by a change in law, a sub-processor, or to maintain the security posture. Customer may terminate the affected service on the same 30 days' notice if the change materially reduces the protection of Customer Personal Data and the parties cannot agree on a remedy.

16. Governing law, jurisdiction

This DPA is governed by the law of the State of Wyoming, United States, without prejudice to any data protection law that applies to the Customer or data subject and that cannot be overridden by contract.

17. Contact


Attribution

Adapted from patterns in Automattic's Legalmattic templates, extended with GDPR Article 28 structure common in Processor DPAs. Original and this adaptation are both licensed under CC-BY-SA 4.0. This document is a template, not a negotiated contract; consult an attorney before relying on it for a specific customer.