Skip to content
Browse help

Data protection and your obligations

What we do with personal data, and where to find the documents your reviewer will ask for.

Last updated

The three documents a supplier review normally asks for are published and can be sent on as they are: the Data Processing Agreement, the Privacy Notice and the sub-processor list. This page is a map of them rather than a summary, because on anything that matters the documents themselves are what count.

Who is responsible for what

For everything inside an envelope (the document you sent out for signature, together with the people asked to sign it), your company is the data controller and Cecur Limited is your processor. That covers the documents, the identity of the people you invited, the values they enter, their signatures and the evidence records generated about the signing. You decide what to send, to whom and why; we process it on your instructions, under the Data Processing Agreement.

Cecur Limited is the controller for a narrower set of things of its own: your users' account and authentication data, keeping the platform secure and free of abuse, billing through Cecur Home, and support requests. Section 3 of the Privacy Notice sets out the split in full.

What your reviewer will ask for

The Data Processing Agreement carries the details of the processing, the security measures, the sub-processor terms and the deletion and return provisions, and its annexes carry the sub-processor list and the measures in place. Whether your organisation needs a countersigned copy rather than the published one is worth raising with us early, through Support in the left-hand navigation.

Changes to sub-processors

We update the sub-processor list and email the account owner at least 14 days before adding or replacing a sub-processor. Rights to object are in clause 6 of the Data Processing Agreement. If your own compliance process needs to see that page on a schedule, it is a public URL and can be watched.

Your signers are usually not our customers

A person you invite to sign has often never dealt with us before, and is a data subject in their own right. The Privacy Notice is written to serve as the information owed to them under Article 14 of the GDPR, so it is the page to point a recipient at if they ask who we are and what we recorded. Section 4 lists exactly what is captured about a signer, which includes their name and address as you entered them, the values they fill in, their signature, and the time, IP address and browser recorded with each action.

What you send, to whom, and on what lawful basis remains your decision as controller.

Erasure requests about a signed document

Signing evidence is deliberately permanent, and section 6 of the Privacy Notice explains the position in full. In short: where the records evidence a concluded agreement, retention is permitted despite an erasure request to the extent the records are needed to establish, exercise or defend legal claims, and restriction of processing is offered instead. Where you are the controller, the decision is yours and we will assist. Route any request you receive to us through Support and say what has been asked and by whom.

Deletion of a whole account, including its envelopes and audit chains, is possible, and clause 9 of the Data Processing Agreement sets out how and in what period.

Complaints, and where to go

You or a signer can complain to a supervisory authority: in Ireland the Data Protection Commission, in the United Kingdom the Information Commissioner's Office, or the authority where the person lives or works.

We do not sell personal data, we do not use it for advertising, and documents are not sent to any AI service. Where your files are held is covered in Where your documents are kept.