Legal
Data Processing Agreement
A GDPR-compliant Data Processing Agreement (DPA) for all VollSign customers.
Introduction
This Data Processing Agreement ("DPA") forms part of the contract for the use of VollSign services between VollSign GmbH ("Processor") and the customer ("Controller"). It governs the processing of personal data as required by Article 28 of the GDPR.
01
1. Subject and Duration
This DPA covers the processing of personal data of clients and signatories in connection with the provision of the VollSign platform. The DPA is effective for the duration of the main service agreement.
02
2. Nature and Purpose of Processing
VollSign processes personal data on behalf of the Controller for the purpose of creating, managing, and executing digital powers of attorney. Processing includes storage, retrieval, and transmission of data as required by the service.
03
3. Categories of Data Subjects
Clients and signatories of the law firm using VollSign. No special categories of personal data (Article 9 GDPR) are processed unless explicitly enabled by the Controller.
04
4. Technical and Organisational Measures
VollSign implements appropriate technical and organisational measures (TOMs) to ensure a level of security appropriate to the risk, including encryption at rest and in transit, access controls, regular backups, and incident response procedures.
05
5. Sub-Processors
VollSign uses a limited number of sub-processors. A current list is maintained and available at /subprocessors. Customers are notified of any changes with 30 days advance notice.
View Subprocessors06
6. Data Subject Rights
VollSign supports the Controller in fulfilling data subject rights requests (access, rectification, deletion, portability) within the statutory deadlines set by the GDPR.
07
7. Deletion and Return
Upon termination of the service agreement, all personal data will be deleted or returned at the Controller's choice within 30 days, unless retention is required by law.