Skip to content

Legal

Data Processing Agreement

The Article 28 processing terms between Cecur Limited and customers of CecurSign.

Version 1.1Last updated 21 August 2026

This data processing agreement ("DPA") forms part of the CecurSign Terms of Service between Cecur Limited (Companies Registration Office registration number 815071) ("Processor", "Cecur") and the Customer ("Controller"). It applies where Cecur processes personal data on the Controller's behalf in providing the CecurSign service, and is intended to satisfy Article 28(3) GDPR and, for UK customers, the UK GDPR equivalent.

Relationship to the portal DPA. The Cecur portal at cecur.io has its own data processing terms covering the account and team administration relationship. This DPA governs processing inside the CecurSign product; the portal DPA governs the portal. The two are drafted to be consistent and neither varies the other.

1. Roles and scope

1.1 The Controller is the controller and Cecur is the processor for: personal data contained in documents, proposals, templates and contact lists the Controller submits; data about Recipients processed on the Controller's instructions; and the Evidence Records (audit trail, signature images, IP addresses, browser user agent strings and timestamps) the service generates for the Controller's envelopes. The Evidence Records are generated because, and only because, the Controller instructed a signing transaction; they belong to the Controller's processing.

1.2 Cecur acts as an independent controller, not as processor, only for: account holder registration and authentication data; billing data; support tickets; and the limited use of Evidence Records and request metadata needed for the security, integrity and abuse prevention of the platform itself, for compliance with law binding on Cecur, and for the establishment, exercise or defence of Cecur's own legal claims. That processing is described in the CecurSign Privacy Notice.

1.3 The service is engineered so that Evidence Records for sent and completed envelopes cannot be edited or selectively deleted by anyone, including Cecur. Clause 9 sets out how that interacts with deletion instructions.

2. Details of processing (Article 28(3) particulars)

  • Subject matter: provision of the CecurSign electronic signature and proposal platform.
  • Duration: the term of the Terms of Service, plus the period until deletion or return under clause 9.
  • Nature and purpose: hosting, storage, transmission, rendering and display of documents; collection of electronic signatures and approvals; generation of evidence records; sending of transactional email and, where enabled, SMS; document verification.
  • Categories of data subjects: the Controller's personnel (authorised users); the Controller's clients, counterparties and other persons invited to sign or approve documents; persons whose data appears in document content.
  • Categories of personal data: names; email addresses; phone numbers (where SMS verification is used); signature images and typed signatures; field values entered during signing; IP addresses and browser user agent strings; timestamps of signing events; any personal data contained in document content, which the Controller alone determines. The Controller should not submit special category data unless it has satisfied itself of a lawful basis; the service does not require it.

3. Controller instructions

3.1 Cecur will process personal data only on the Controller's documented instructions, including regarding transfers, unless required to do otherwise by EU, Irish or (where UK GDPR applies) UK law, in which case Cecur will inform the Controller before processing unless the law prohibits it.

3.2 The Terms of Service, this DPA, and the Controller's use of the service's features (sending an envelope, choosing recipients, enabling verification options, deleting a draft) are the documented instructions. The Controller acknowledges that generating tamper-evident Evidence Records for every sent envelope is a standing instruction inherent in using the service.

3.3 Cecur will inform the Controller if, in its opinion, an instruction infringes the GDPR or other data protection law.

4. Confidentiality

Cecur ensures that persons authorised to process the personal data are bound by contractual or statutory obligations of confidentiality.

5. Security

5.1 Cecur implements the technical and organisational measures described in Annex 2, taking into account the state of the art, the costs of implementation and the nature, scope, context and purposes of processing, as required by Article 32 GDPR.

5.2 Annex 2 is an honest statement of what is in place today. It does not claim encryption at rest or certifications, because neither exists. It states where Cecur's own servers and databases are located, the European Union, but it does not give a data residency guarantee, because email delivery involves a transfer to the United States (clause 10).

6. Sub-processors

6.1 The Controller gives general written authorisation to the sub-processors listed in Annex 1. The maintained list is published at cecursign.io/sub-processors.

6.2 Cecur will give the Controller at least 14 days prior notice of any intended addition or replacement of a sub-processor, by email to the account owner. If the Controller reasonably objects on data protection grounds within 14 days of the notice, the parties will discuss in good faith; if no resolution is found, the Controller may terminate the affected service.

6.3 Cecur imposes on each sub-processor data protection obligations no less protective than this DPA, and remains liable for its sub-processors' performance.

7. Data subject rights

Taking into account the nature of the processing, Cecur will assist the Controller by appropriate technical and organisational measures, insofar as possible, in fulfilling the Controller's obligation to respond to data subject requests under Chapter III GDPR. If a data subject contacts Cecur directly about processing under this DPA, Cecur will pass the request to the Controller without undue delay.

8. Assistance, breach notification and records

8.1 Cecur will assist the Controller in ensuring compliance with Articles 32 to 36 GDPR (security, breach notification, data protection impact assessments and prior consultation), taking into account the nature of processing and the information available to Cecur.

8.2 Cecur will notify the Controller without undue delay, and in any event within 72 hours of becoming aware of a personal data breach affecting the Controller's personal data, and will provide the information reasonably required for the Controller's own notification obligations.

8.3 Cecur will make available to the Controller information reasonably necessary to demonstrate compliance with Article 28, and will allow for and contribute to audits, including inspections, conducted by the Controller or its mandated auditor, subject to reasonable notice, at most once per year unless required by a supervisory authority, and under confidentiality. Cecur may first satisfy an audit request with documentation and written answers.

9. Deletion and return

9.1 On termination of the service, at the Controller's choice, Cecur will delete or return the personal data processed under this DPA and delete existing copies, unless EU, Irish or applicable UK law requires storage.

9.2 Evidence Records. The Controller instructs, and acknowledges, that Evidence Records for sent and completed envelopes are tamper-evident by design: individual records cannot be edited, and selective deletion of an individual record from a retained chain is refused because it would destroy the evidential integrity of the remainder. Deletion under this clause therefore operates at the level of the Controller's whole account (or whole envelopes within a full account deletion), which removes the documents, signatures and audit chains together. Where the Controller or a data subject seeks erasure of an individual record within a retained chain, Cecur may refuse to the extent the records are necessary for compliance with a legal obligation or for the establishment, exercise or defence of legal claims (Articles 17(3)(b) and 17(3)(e) GDPR), and will instead restrict processing of the affected records to those purposes.

9.3 Read-only export access remains available for 30 days after termination. After that period, Cecur will delete the Controller's data within 90 days of a written request. No automated deletion schedule is implemented; deletion is carried out as a deliberate staff operation.

9.4 What deletion covers. Deletion under this clause covers both the Controller's records in the CecurSign database and the stored document files themselves — uploaded source documents, completed signed documents and completion certificates — held in the document storage service listed in Annex 1. Document files are removed as part of the same staff operation rather than automatically, so a deletion is complete when both halves have been carried out. Backups are overwritten on their own cycle and are not individually edited; a record already deleted from the live service is not restored from a backup.

10. International transfers

10.1 Cecur's own application servers and databases are located in the European Union.

10.2 Cecur will not transfer personal data processed under this DPA outside the EEA and the UK except to the sub-processors in Annex 1 or with the Controller's authorisation, and in each case with a valid transfer mechanism under Chapter V GDPR (for transfers subject to UK GDPR, the UK Addendum to the EU Standard Contractual Clauses or the UK extension to an adequacy framework, as applicable). Annex 1 identifies which sub-processors are outside the EEA. Clause 10.1 is therefore not a data residency guarantee: transactional email is delivered from the United States.

11. Liability and order of precedence

Liability under this DPA is subject to the limitations and exclusions in the Terms of Service, except where the GDPR does not permit that. If this DPA conflicts with the Terms of Service on data protection matters, this DPA prevails.

Annex 1: Sub-processors

Internal Cecur services (Cecur Home, the Cecur notification service, DocVault, the PDF rendering worker) are operated by Cecur Limited itself and are not sub-processors. The maintained public list is at cecursign.io/sub-processors; the table below is the list as at the date of this DPA.

Sub-processors engaged by Cecur Limited for the CecurSign service
Sub-processorPurposeDataLocation
Auth0 (Okta, Inc.)Identity and authentication for the Controller's authorised usersNames, email addresses, credentials, authentication events
Resend (Resend, Inc.)Transactional email delivery (signing invitations, reminders, completion notices)Recipient names and email addresses; email content including document names and signing linksUnited States
Cloudflare, Inc.Content delivery of the PDF viewer library used to display documents for signingSigner's IP address, browser user agent and referring page. No document content and no form data are sentUnited States
Twilio Inc.SMS delivery for signer verificationMobile numbers, message contentEngaged only if SMS verification is enabled; currently disabled platform-wide
OVHcloudManaged PostgreSQL database hostingAll personal data held in the CecurSign databaseEuropean Union
Our hosting providerHosting of application servers and document object storageAll personal data including document filesEuropean Union
Stripe Payments Europe, Ltd / Stripe, Inc.Payment processing, via the Cecur Home portalBilling contact and payment dataCecur acts as controller for billing; listed for transparency

Cecur has not yet named the company that hosts its application servers and document object storage. Its location is stated above; the name will be added to this Annex, to the published sub-processor list and to the privacy notice once it is confirmed. Every other sub-processor above is named.

Timestamp authorities (Sigstore, DigiCert, GitHub) receive only a cryptographic hash and no personal data, and are therefore not sub-processors; they are listed in the privacy notice for transparency.

Annex 2: Technical and organisational measures

This annex states what is actually implemented as at the date of this document. It also serves as the security schedule referred to in the Terms of Service.

  • Hosting location: our application servers and databases are located in the European Union. This is a statement of location, not a residency guarantee; clause 10 and Annex 1 identify the sub-processors that operate outside the EEA.
  • Transport encryption: TLS for all web, API and email traffic; the database connection to the managed cluster uses TLS with certificate verification.
  • Access control: all authentication through Auth0 or hashed credentials (Argon2id); API keys stored as digests only; session cookies are HttpOnly; signing links use 256-bit random tokens; access codes are rate limited with lockout.
  • Tenant isolation: every tenant-scoped query filters by tenant id; verified by code review across the request paths.
  • Integrity of evidence: audit events are hash-chained; database triggers refuse UPDATE on audit rows unconditionally and refuse DELETE except for never-sent drafts; document fingerprints are recorded and source documents are re-verified on read.
  • Isolation of risky processing: rendering of author-supplied HTML runs in a separate worker process with no database connection, no inbound HTTP and blocked page network egress; author HTML is sanitised against a single allow-list before rendering.
  • Least egress: outbound webhook destinations are checked against internal address ranges to prevent server-side request forgery.
  • Backups: database backups are taken daily. They are currently a single copy and do not include document files.

Not currently in place, stated for honesty

Encryption at rest; ISO 27001, SOC 2 or comparable certification; a contractual uptime commitment; a guarantee that all personal data remains in the UK or the EEA (our own servers and databases are in the European Union, but transactional email is delivered from the United States); automated retention or deletion schedules; automated breach detection and alerting.