AgreeVia

Data processing addendum

What we do with the personal data in your documents

When you send a document through AgreeVia, the personal data inside it is yours, not ours. This addendum is the Article 28 UK GDPR contract governing how we handle it on your behalf. It applies automatically to every AgreeVia customer — you don't need to sign a separate copy.

Document
Data Processing Addendum
Version
1.1
Effective from
29 August 2026
Supersedes
1.0 (20 August 2026)
Processor
AgreeVia Solutions Ltd
Registered
Scotland, no. SC898504
ICO register
ZC220362
Governing law
Scotland
Contents — 14 sections

1How this fits together

This addendum forms part of the agreement between you and AgreeVia Solutions Ltd, registered in Scotland (company number SC898504). Our Terms of Service and Privacy Policy are the rest of it.

It takes effect when you create an account and lasts as long as we process personal data on your behalf.

Where this addendum and the Terms of Service disagree on data protection, this addendum wins. On anything else, the Terms win.

In this addendum "UK GDPR", "controller", "processor", "personal data", "processing", "data subject" and "personal data breach" have the meanings given in the UK GDPR and the Data Protection Act 2018. "Customer Personal Data" means personal data we process on your behalf, as described in Annex 1.

2Who is what

You are the controller of the personal data in documents you create, upload or send for signature, and of the personal data of the people you invite to sign. You decide what goes into a document and who receives it.

We are the processor of that data. We act only on your instructions.

We are a separate controller — not your processor — of your account data, your subscription, your support messages, and the audit and integrity records the service generates. Section 2 of our Privacy Policy covers that data; this addendum does not apply to it.

Why the audit trail sits outside this addendum The hash-chained event log exists so a signature can be relied on later, including by someone who isn't you. We decide what it records and we won't alter it on request — which makes us its controller, not your processor. In practice that means you cannot instruct us to erase entries from a signed document's trail. Section 10 below, and section 10 of the Privacy Policy, explain the consequences.

3What we do, and only what we do

We process Customer Personal Data only:

  • on your documented instructions — this addendum, the Terms of Service, and the operations you carry out in the app;
  • to provide and secure the service; and
  • where UK or EU law requires something else of us, in which case we'll tell you first unless the law forbids it.

We won't process Customer Personal Data for our own purposes. We won't sell it, and we won't use it to train any AI model.

If we think an instruction from you breaches data protection law, we'll tell you, and we may pause the processing concerned while we resolve it.

The Article 28(3) particulars — subject matter, duration, nature, purpose, categories of data and of data subject — are in Annex 1.

4Confidentiality

Everyone we authorise to process Customer Personal Data is bound by a duty of confidentiality, by contract or by statute, and that duty survives the end of their engagement. Access is limited to people who need it to run the service, and access to production data is logged.

5Security

We implement appropriate technical and organisational measures under Article 32, taking into account the state of the art, the cost of implementation, and the risk to data subjects. Our current measures are in Annex 2.

We may change these measures as the service develops, but not in a way that materially reduces the protection of Customer Personal Data.

6Sub-processors

You give us general authorisation to engage sub-processors. The current list is Annex 3, kept up to date on this page and in section 7 of the Privacy Policy.

Before adding or replacing a sub-processor we'll give you at least 30 days' notice by email or in the app. If you have a reasonable data-protection objection, tell us within those 30 days and we'll work to resolve it. If we can't, you may terminate the affected part of the service and we'll refund any unused prepaid period.

Every sub-processor is engaged under a written contract imposing obligations no less protective than these. We remain fully liable to you for their performance.

7Data subject requests

If a data subject contacts us directly about personal data in one of your documents, we'll tell them to contact you and let you know it happened. We won't respond substantively ourselves unless you ask us to or the law requires it.

Taking into account the nature of the processing, we'll help you meet your obligations to data subjects — access, rectification, erasure, restriction, portability and objection. In practice: you can export any document and its evidence package from within the app, and for anything the app doesn't cover, email [email protected] and we will act on your instruction.

Note the limit in section 10: once a document has been signed, erasure is not available to either of us. Where that's the answer, we say so plainly rather than leave a data subject chasing you for something you cannot deliver.

We may charge for assistance that goes materially beyond this, having told you the cost first.

8Breach notification

We'll tell you about a personal data breach affecting Customer Personal Data without undue delay, and in any event within 24 hours of becoming aware of it — so you can meet your own 72-hour deadline to the ICO.

Our notification will describe the nature of the breach, the categories and approximate number of data subjects and records concerned, the likely consequences, and the measures taken or proposed. Where we can't give all of that at once, we'll give what we have and follow up.

We won't notify the ICO or data subjects on your behalf unless you ask us to.

9Impact assessments and prior consultation

Taking into account the nature of the processing and the information available to us, we'll give you reasonable assistance with data protection impact assessments and any prior consultation with the ICO arising from your use of AgreeVia.

10Deletion and return

You can export your documents and their evidence packages at any time from within the app.

Documents cannot be deleted from within AgreeVia. This is deliberate: a signature is only worth something if the record behind it cannot be quietly removed. Deletion therefore happens on instruction, not by button.

Before a document is signed, email [email protected] and we will delete it, together with its event history, and confirm when it's done — normally well within one month. This is your Article 28(3)(g) deletion right, and we treat a request from you as a documented instruction.

Once anyone has signed, the document is fixed. At the end of the agreement you have 30 days to export, after which we delete Customer Personal Data — subject to two exceptions:

  • Completed documents and their audit trail, kept for the life of the record. We don't delete them on a fixed schedule — a signature is only worth something if the record behind it cannot later be made to disappear. We hold these as controller under section 2, so they fall outside your deletion instruction. When your account closes we remove your name from the ownership record, but the document survives. Section 10 of the Privacy Policy explains why it can't be scrubbed party by party.
  • Backups. Deleted data can persist in rolling backups for up to 30 days before it ages out. It stays protected by this addendum until it's gone, and we don't restore a backup to recover data that has been deleted on request.

Where UK or EU law requires us to keep something longer, we will, and we'll tell you what and why.

11Audits

We'll make available the information reasonably needed to demonstrate compliance with Article 28, including our security documentation and the data protection terms of our sub-processor contracts, redacted for commercial confidentiality.

You may audit us, or appoint an independent auditor to, no more than once in any 12-month period unless a personal data breach or a regulator requires otherwise. Give us 30 days' notice, keep the audit to what's reasonably necessary, don't disrupt the service, and bear your own costs. We may charge for our time on any audit beyond the annual one.

12International transfers

Customer Personal Data is stored in the United Kingdom — our database, file storage and authentication run on AWS London (eu-west-2).

Some sub-processors in Annex 3 are outside the UK. Where personal data is transferred out, we rely on the UK International Data Transfer Addendum to the EU Standard Contractual Clauses, or on UK adequacy regulations where they apply, in each case with a transfer risk assessment. Ask us at [email protected] which safeguard applies to a particular transfer.

By using the service you instruct us to make those transfers and confirm you're satisfied with the safeguards.

13Liability

Each party's liability under this addendum is subject to the limits and exclusions in clause 14 of the Terms of Service. Nothing here limits liability that the law does not allow to be limited, or affects a data subject's rights against either of us under Article 82 UK GDPR.

14Law

This addendum is governed by the law of Scotland, and clause 19 of the Terms of Service applies to any dispute about it.

A1Details of processing

Subject matter. Provision of the AgreeVia electronic signature service.

Duration. For as long as your account is open, plus the retention periods in section 10.

Nature and purpose. Storing, hosting, transmitting, rendering and generating PDF documents; sending signing invitations and completion notices; capturing signatures; producing evidence packages; and, where you use an AI feature, transmitting document text for drafting or summarising.

Types of personal data. Whatever you put in a document, plus: names, email addresses, signature images, the name signed under, IP addresses, device and browser type, and event timestamps.

Categories of data subject. People you invite to sign; anyone else whose personal data appears in a document you upload or generate; and users you add to your plan.

Special category data. Not requested and not supported. If you put it in a document, you're responsible for your own Article 9 condition.

A2Technical and organisational measures

These are the measures referred to in clause 14.4 of the Terms of Service.

  • TLS in transit; encryption at rest on provider infrastructure.
  • Row-level authorisation enforced in the database, so one account cannot read another's records.
  • Every document event written to an append-only log and chained with SHA-256, making alteration detectable.
  • Documents are not deletable from any client session. Deletion of an unsigned document happens only through a restricted internal function that refuses completed documents, frozen audit chains and requests from anyone other than the document's creator.
  • Signing links single-purpose, time-limited and revocable; a creator can cancel a pending invitation.
  • Storage buckets restricted by MIME type and file size, with user-scoped upload paths.
  • Production access limited to what's needed to run the service, and logged.
  • Rolling backups retained for up to 30 days.
  • Secrets held in managed secret storage, never in client code.
  • Breach reported to the ICO within 72 hours where the risk threshold is met, and to affected people without undue delay where the risk is high.

A3Sub-processors

Sub-processorPurposeLocation
SupabaseDatabase, file storage, authenticationAWS London (eu-west-2), United Kingdom
CloudflareDNS, CDN, website and guest-signing pagesGlobal network
ResendTransactional email — signing invitations, completion noticesUnited States
Anthropic PBCClaude API — drafting and analysis, only when an AI feature is usedUnited States
RevenueCatSubscription entitlements and renewalsUnited States
Zoho CorporationSupport emailEuropean Union (Netherlands)
Apple, GoogleApp store payment and refundsUnited States and elsewhere

Apple and Google act as independent controllers for payment data; we never receive card details.