Data processing agreement
This data processing agreement (the DPA) forms part of the agreement between Signedup and each customer under our terms of service (the Terms). It sets out the terms that Article 28 of the UK General Data Protection Regulation requires for the personal data we process on a customer's behalf. It applies automatically when a customer accepts the Terms, and it does not need to be signed. If your organisation needs a copy signed by both parties, email legal@signedup.io with your organisation's legal name and address and we will send one. A signed copy contains these terms.
1. Definitions
1.1 Words defined in the Terms have the same meaning in this DPA. Controller, processor, data subject, personal data, personal data breach, processing and supervisory authority have the meanings given to them in the UK General Data Protection Regulation.
1.2 Sub-processor means any third party we engage to process Customer Personal Data.
1.3 Security Breach means a personal data breach affecting Customer Personal Data while it is processed by us or by a Sub-processor. It does not include unsuccessful attempts or activities that do not compromise the security of Customer Personal Data, such as pings, port scans, blocked sign-in attempts or denial of service attacks.
1.4 Transfer Mechanism means a lawful basis for transferring personal data outside the United Kingdom or the European Economic Area, as described in clause 12.
2. Roles and scope
2.1 You are the controller of Customer Personal Data and we are your processor. Where you are yourself a processor acting for another controller, you warrant that your instructions, including your appointment of us, are authorised by that controller, and we act as your sub-processor.
2.2 This DPA does not apply to personal data that we process as a controller, such as account, billing and support information and Service Data. Our privacy notice describes that processing.
2.3 Schedule 1 describes the processing. Schedule 2 describes our technical and organisational measures.
3. Your responsibilities as controller
3.1 You must comply with Data Protection Law as controller. Clause 7.3 of the Terms, which sets out your responsibilities for your lists, forms part of this DPA.
3.2 Without limiting clause 3.1, you are solely responsible for the accuracy, quality and legality of Customer Personal Data and the means by which you obtained it; for your lawful basis; for the information you give to data subjects; for the validity and evidence of any consent; for deciding how long Customer Personal Data is kept; for responding to data subjects' requests and complaints; and for deciding whether to notify a supervisory authority or data subjects of a Security Breach, and doing so.
3.3 You must not provide the kinds of data that clause 7.3(f) of the Terms prohibits. Our measures are designed for the data described in Schedule 1 and not for those kinds of data. If you provide them, you do so in breach of the Agreement, and to the extent the law allows, we are not responsible for any failure of our measures to meet a higher standard that those kinds of data would require.
3.4 You confirm that you have reviewed Schedule 2 and our security page, and that you have decided that the measures described provide a level of security appropriate to the risk of your processing.
3.5 Clause 15 of the Terms applies to any claim arising from your breach of this DPA or of Data Protection Law.
4. Processing only on your instructions
4.1 We process Customer Personal Data only on your documented instructions, unless the law of the United Kingdom, or of a member state of the European Union where that law applies to us, requires us to process it. In that case we will tell you of the requirement before processing, unless that law prohibits us from doing so on important grounds of public interest.
4.2 Your documented instructions are the Agreement, including this DPA, your configuration of the Service, and the actions taken in the Service by your Authorised Users and by the people using your forms, as the Service allows. They are your complete instructions. Any further instruction must be agreed in writing, and we may charge for carrying it out.
4.3 We will tell you promptly if, in our opinion, an instruction infringes Data Protection Law. We are not obliged to carry out a legal review of your instructions, and we may decline to act on an instruction we believe infringes Data Protection Law until you have confirmed or changed it.
4.4 We do not process Customer Personal Data for any purpose of our own. Clause 6.3 of the Terms applies.
5. Confidentiality of personnel
5.1 We ensure that everyone we authorise to process Customer Personal Data has committed to confidentiality or is under an appropriate statutory obligation of confidentiality.
5.2 We limit access to Customer Personal Data to those who need it in order to provide, support, secure or maintain the Service.
6. Security
6.1 We implement and maintain the technical and organisational measures described in Schedule 2, as required by Article 32 of the UK General Data Protection Regulation.
6.2 The measures are subject to technical progress and development. We may change them, provided we do not materially reduce the overall level of security of the Service.
6.3 You are responsible for the security matters within your control, including those set out in clause 5 of the Terms.
7. Sub-processors
7.1 You give us general written authorisation to engage Sub-processors. You authorise the Sub-processors listed on our sub-processors page on the date you accept the Terms.
7.2 We engage each Sub-processor under a written contract imposing data protection obligations that provide the same protection as this DPA, to the extent required by Article 28(4) of the UK General Data Protection Regulation. We remain liable to you for each Sub-processor's performance of those obligations, subject to clause 14 of the Terms.
7.3 We will give at least 30 days' notice before a new or replacement Sub-processor starts to process Customer Personal Data, by updating our sub-processors page and by emailing your account owner.
7.4 Where we must replace a Sub-processor urgently to protect the security of Customer Personal Data or to keep the Service running, and it is not reasonably possible to give the notice in clause 7.3, we may give shorter notice, or notice as soon as practicable after the change. Your right to object under clause 7.5 then runs for 30 days from that notice.
7.5 You may object to a change by emailing privacy@signedup.iowithin the notice period, on reasonable grounds relating to data protection that you explain. We will discuss the objection with you in good faith. If we cannot reasonably accommodate it, for example by not using that Sub-processor for your Customer Personal Data, your sole and exclusive remedy is to terminate the Agreement by notice before the change takes effect, or, under clause 7.4, before the end of the objection period. If you do, we will refund any Fees you have paid for the period after termination.
7.6 If you do not object within the notice period, you are treated as having accepted the change.
8. Assistance
8.1 Taking into account the nature of the processing, we assist you, insofar as this is possible, to respond to requests from data subjects to exercise their rights. We do this principally through the self-service tools in the Service: the people on your lists can view, correct, export and erase their own records and unsubscribe without involving you or us, and your Authorised Users can view, export, edit and remove records.
8.2 If we receive a request or complaint from a data subject about Customer Personal Data and can identify you as the controller, we will pass it to you without undue delay. We will not respond to it ourselves, except to direct the person to you or where the law requires us to.
8.3 Taking into account the nature of the processing and the information available to us, we assist you to meet your obligations under Articles 32 to 36 of the UK General Data Protection Regulation by making available this DPA, Schedule 2, our security page and the information described in clause 11.
8.4 Any assistance beyond clauses 8.1 to 8.3 that we agree to give is provided at your cost, at our reasonable rates.
9. Security Breaches
9.1 We will notify you without undue delay after becoming aware of a Security Breach, and where feasible within 72 hours of becoming aware of it.
9.2 As far as it is available to us, we will give you a description of the nature of the Security Breach, including the categories and approximate number of data subjects and records concerned, its likely consequences, the measures taken or proposed to address it, and a point of contact. Where we cannot provide all of that at once, we will provide it in phases without further undue delay.
9.3 We will take reasonable steps to contain and investigate a Security Breach and to reduce its effects.
9.4 You are responsible for deciding whether to notify a supervisory authority or data subjects, and for doing so. We will not notify them on your behalf unless the law requires us to. We will give you the information described in clause 9.2 to help you.
9.5 Our notification of a Security Breach is not an acknowledgement of fault or liability.
9.6 We will send notifications to the email address of your account owner, which you must keep up to date.
10. Return and deletion
10.1 You can export Customer Personal Data at any time during the Agreement and the Read-only Period using the export tools in the Service. That is how we return it.
10.2 At the end of the Read-only Period, which lasts 60 days, we delete Customer Personal Data from the live Service. Copies in our backups expire within a further 35 days and, until they do, are kept protected and are not processed for any other purpose. If you ask us in writing, we will delete it earlier.
10.3 For the purposes of Article 28(3)(g), by letting the Read-only Period end, or by asking us to delete Customer Personal Data, you choose deletion rather than return for any data you have not exported.
10.4 We may keep Customer Personal Data where the law of the United Kingdom requires us to, only for as long as it requires, and we will keep it protected and not process it for any other purpose.
10.5 If you ask us in writing after deletion, we will confirm in writing that it has taken place.
11. Information and audits
11.1 We make available the information necessary to demonstrate our compliance with Article 28 of the UK General Data Protection Regulation through this DPA, Schedule 2, our security page, our sub-processors page and, no more than once in any 12 months, written answers to a reasonable security or data protection questionnaire. If we hold an independent certification or report in future, we will make it available on request. This is how we meet your right to information under Article 28(3)(h).
11.2 An audit or inspection of our processing may take place only where:
- a supervisory authority with jurisdiction over you requires it;
- a Security Breach affecting your Customer Personal Data has been confirmed; or
- the information provided under clause 11.1 is not sufficient to demonstrate our compliance with Article 28, and you have explained in writing why it is not.
11.3 Any audit or inspection must take place no more than once in any 12 months, unless a supervisory authority requires otherwise; on at least 30 days' written notice setting out its proposed scope; during business hours on Business Days; remotely wherever reasonably possible; and in a way that minimises disruption to the Service. It must be carried out by you or by an independent auditor who is not our competitor and who is bound by written obligations of confidentiality acceptable to us. It will not include access to other customers' data or to our Sub-processors' premises or systems, for which we will provide the information those Sub-processors make available. You will bear its cost, including our reasonable time at our then-current rates, give us a copy of any report, and treat everything you learn as our Confidential Information.
12. Transfers outside the United Kingdom
12.1 We and our Sub-processors may transfer Customer Personal Data outside the United Kingdom in accordance with Data Protection Law. You authorise transfers to the Sub-processors listed on our sub-processors page.
12.2 Where a Transfer Mechanism is required, the transfer relies on one of the following: UK adequacy regulations, including the UK Extension to the EU-US Data Privacy Framework where the recipient is certified under it; the International Data Transfer Agreement, or the International Data Transfer Addendum to the European Commission's Standard Contractual Clauses, issued by the Information Commissioner under section 119A of the Data Protection Act 2018; or another mechanism permitted by Data Protection Law.
12.3 Where Regulation (EU) 2016/679 applies to your transfer of Customer Personal Data to us, the transfer relies on the European Commission's adequacy decision for the United Kingdom while it remains in force. If it ceases to be in force, the Standard Contractual Clauses adopted by Commission Implementing Decision (EU) 2021/914 are incorporated into this DPA, using Module Two where you are a controller and Module Three where you are a processor, with the general authorisation option in Clause 9 and the notice period in clause 7.3, Irish law and courts for Clauses 17 and 18, and Schedules 1 and 2 and our sub-processors page completing their Annexes.
12.4 A copy of the relevant safeguards is available on request to privacy@signedup.io, with commercially confidential terms removed.
13. Liability
13.1 Each party's liability under or in connection with this DPA, and under Data Protection Law as between the parties, is subject to clause 14 of the Terms, including its single aggregate limit, which applies to the Terms and this DPA together.
13.2 Nothing in this DPA limits any right that a data subject has against either party under Data Protection Law.
14. Duration
14.1 This DPA continues for as long as we process Customer Personal Data, including during the Read-only Period and until the copies in our backups have expired.
15. General
15.1 For matters relating to the processing of Customer Personal Data, this DPA prevails over the Terms, and any Transfer Mechanism incorporated by clause 12 prevails over this DPA to the extent the law requires. An Order Form prevails only where it expressly states that it overrides this DPA.
15.2 We may change this DPA as clause 17 of the Terms describes, and also where a change is needed to comply with Data Protection Law or with guidance from a supervisory authority, or to adopt a new Transfer Mechanism.
15.3 We keep the records of processing that Article 30(2) requires, and we cooperate with the Information Commissioner on request in the performance of its tasks.
15.4 This DPA is governed by the law of England and Wales, and clause 21.8 of the Terms applies to it, except where a Transfer Mechanism requires otherwise.
Schedule 1: Details of the processing
Subject matter
The provision of the Service to you under the Agreement.
Duration
The term of the Agreement, the Read-only Period, and the further period until the copies in our backups expire, as described in clause 10.
Nature of the processing
Collecting details through your forms and your imports; recording, organising, storing, retrieving and displaying them to your Authorised Users; letting the people on your lists update their own details; exporting them at your request or theirs; sending the messages the Service needs in order to work, namely sign-in and confirmation links and the requests to check details that you choose to send; handling bounces and complaints and keeping a suppression list; and erasing and deleting records.
Purpose
To provide the Service in accordance with the Agreement and your instructions.
Categories of data subjects
The people on your lists, who are typically your employees, workers, contractors, volunteers, members, residents or other contacts; and your Authorised Users, to the extent they are recorded in your audit log.
Categories of personal data
Email addresses; names and any other details your forms ask for, and the answers given; list membership and status; the history of each person's consent and changes, including the date and time, the version of the form shown, and the network address and browser from which each action was taken; bounce, complaint and suppression status; entries in your audit log, including the Authorised User who acted, what they did and the network address used; and the contents of files you upload for import while that import is prepared.
Special category personal data
None is intended. Clause 7.3(f) and (g) of the Terms set out what you must not provide and the assessment you must make where a list may itself reveal sensitive information.
Frequency
Continuous, for the duration described above.
Deletion during the Agreement
You decide how long Customer Personal Data is kept and can remove it at any time. In addition, the Service removes records automatically as follows: a request to join a list that is never confirmed is removed after 30 days; a person who erases their own record is held for 30 days so that an accidental erasure can be reversed, and is then removed together with their consent history; and a person who is no longer on any of your lists is removed once their record is at least 30 days old. Files uploaded for import are deleted when the import is completed or cancelled. Your audit log is kept for as long as your account exists. Clause 10 applies when the Agreement ends.
Sub-processors
As listed on our sub-processors page, with the purpose of each and the country in which it holds data.
Schedule 2: Technical and organisational measures
The following describe what our measures achieve. They are described by outcome rather than by implementation, and may change as clause 6.2 allows.
Separation between customers. Access to an organisation's data is limited to that organisation. The limit is derived from the membership record of the person who has signed in, never from a value that person can supply, so no parameter can be altered to reach another customer's data. This property is checked by automated tests that run on every change we make.
Authentication. There are no passwords anywhere in the Service. Authorised Users sign in with a single-use link that expires after 20 minutes and is consumed on first use. Links are stored only in a form from which a working link cannot be reconstructed, and where two attempts are made to use the same sign-in link at the same moment, only one succeeds.
Encryption. Connections to the Service require Transport Layer Security, and browsers are instructed to refuse unencrypted connections to it in future. Stored data and the backup copies of it are encrypted at rest.
Location. Customer Personal Data at rest is held in the United Kingdom or the European Union. Backup copies are held in the European Union.
Resilience. A backup copy is taken every night and expires after 35 days, and restoring from a copy has been rehearsed.
Abuse prevention. Public forms and sign-in are protected by rate limits and by checks against automated abuse. Addresses that bounce or complain are suppressed, so they cannot be reintroduced by a later import.
Logging and diagnostics. Operational logging is designed to exclude personal data, and error reporting is configured not to send network addresses or personal data.
Personnel. Access to production data is limited to the people who operate the Service, is used only to operate, support and secure it, and is subject to the confidentiality obligations in clause 5.
Accountability. Administrative actions within your organisation are written to an audit log that you can read and export, so that you can demonstrate compliance without asking us for records.
Data minimisation and erasure. Unconfirmed and erased records are removed automatically as described in Schedule 1, and a person on your list can erase their own record without holding an account and without involving you.
Changes to this document
This version was published on 15 September 2026. It replaces our adoption of the Common Paper Standard Data Processing Agreement, version 1.1, for all customers from that date.