Legal
Data processing agreement
Last updated 2026-01-01. This document is a working template provided with the platform; have qualified counsel review and adapt it to your jurisdiction and business before relying on it.
This DPA applies where Accordify processes personal data on behalf of a customer (the controller) under the Terms of Service and forms part of them.
Roles and scope
Customer is controller; Accordify is processor. Subject matter: providing the eSignature service. Categories of data subjects: customer users and their signers. Categories of data: identity and contact data, document content, signing evidence.
Processor obligations
- Process only on documented instructions.
- Ensure personnel are bound by confidentiality.
- Implement appropriate technical and organizational measures (Art. 32), described in the security overview.
- Assist with data-subject requests via export and erasure tooling; legal-hold exceptions apply to sealed records.
- Notify the controller without undue delay of a personal data breach.
- Delete or return data at the end of services subject to retention obligations.
- Allow and contribute to audits.
Sub-processors
Cloudflare, Supabase, Clerk, Stripe, Upstash, Sectigo (timestamps, no personal data beyond a document hash). A current list is available on request; customers are notified of changes.
International transfers
Standard Contractual Clauses (Module 2 and 3) are incorporated where personal data leaves the EEA/UK.