Data processing agreement
When you send a document through Pixasign, the people who receive and sign it are your contacts, not ours. You are the controller of their data and we are your processor. These are the terms of that, as UK GDPR Article 28 requires. They form part of our terms of service and apply automatically - you do not need to sign anything separately, though we will sign a copy on request. Last updated 8 September 2026.
1. Roles
You are the controller. Pixacomms Ltd (company number 15861826) is the processor. We process personal data only on your documented instructions, which are: run the Pixasign service as described, and produce the evidence trail that goes with it.
2. What we process for you
| Item | Detail |
|---|---|
| Subject matter | Sending documents for electronic signature and sealing them |
| Duration | For as long as your account is open, plus 30 days |
| Data subjects | Your staff who use the account, and the recipients you send documents to |
| Categories of data | Name, email address, IP address, approximate location derived from it, browser user-agent, timestamps of viewing and signing, the signature image or typed name, and the contents of the documents you upload |
| Special category data | None is requested. If your documents contain any, you remain the controller of it and must have your own lawful basis |
3. Sub-processors
We use these, and only these. We will give you 30 days’ notice by email before adding one, and if you object on reasonable data-protection grounds you may terminate without penalty.
| Sub-processor | Purpose | Location |
|---|---|---|
| Hetzner Online GmbH | Hosting and storage | Nuremberg, Germany |
| Stripe Payments Europe Ltd | Payments and subscriptions (billing data only) | Ireland |
| Brevo (Sendinblue SAS) | Sending signing invitations and account email | France |
| 1984 ehf | Off-site backup storage. Backups are encrypted on our server before they are sent, and the key that decrypts them is never held on this machine, so the backup host cannot read what it stores | Reykjavík, Iceland |
Location lookup for the evidence trail runs on our own server against a local database. No IP address is sent to any third party for it.
4. Where the data is
Live data is held in Germany. Encrypted backups are held in Iceland. Both are within the EEA, which the UK recognises as adequate, so no additional transfer mechanism is required. We do not transfer personal data outside the UK or the EEA, and nothing is held in the United States.
That last point is deliberate rather than incidental. Our infrastructure is not subject to the US CLOUD Act, which allows US authorities to compel a US-headquartered provider to hand over data it holds anywhere in the world. The major e-signature platforms are US companies.
5. Security
The measures we take are set out in full on our security page. In summary: HTTPS everywhere with HSTS, passwords stored only as hashes, optional two-factor authentication, documents held on encrypted storage, tenant separation enforced in the data layer, single-use expiring signing links, and hash-chained audit events so the record cannot be altered without detection.
6. Confidentiality
Everyone with access to your data is bound by confidentiality obligations, and access is limited to those who need it to run or support the service.
7. If there is a breach
We will tell you without undue delay and within 48 hours of becoming aware of a personal data breach affecting your data, with what we know, what we are doing, and what we suggest you do. Reporting to the ICO is your call as controller, and we will give you what you need for it.
8. Helping you meet your obligations
If a data subject asks you for access, correction or deletion, we will help you answer. You can export or delete data yourself from within the product; where you cannot, email us and we will do it.
9. Audit
On reasonable notice, and no more than once a year unless a regulator requires otherwise, we will answer a written security questionnaire and provide the information you reasonably need to satisfy yourself we are meeting these terms.
10. Deletion at the end
When your account closes we delete your data within 30 days, including from backups on their normal rotation, which completes within 90 days. Sealed documents you have already downloaded stay verifiable without us - that is deliberate, and it is why the seal is worth having.
11. Sign a copy
These terms apply without signature. If your procurement process needs a countersigned copy, email privacy@pixacomms.com and we will send one back, signed through Pixasign.