Data Processing Agreement
Last updated: 11 October 2026
This Data Processing Agreement (“DPA”) forms part of, and is incorporated by reference into, the SigHQ Terms of Service (“Agreement”) between SigHQ (“Processor”) and the organisation using the Service (“Controller” or “Customer”). It applies whenever SigHQ processes personal data on Customer’s behalf in the course of providing the Service.
1. Roles
Customer is the data controller for the personal data of its employees and end users processed through the Service (profile fields, signature usage, and related metadata). SigHQ acts as a data processor, processing that data only on Customer’s documented instructions as set out in this DPA and the Agreement.
2. Subject Matter and Duration
The subject matter of processing is the provision of the SigHQ email signature management platform. Processing continues for the duration of the Agreement and, after termination, for the data-retention period described in the Privacy Policy and Section 12 of the Terms of Service.
3. Nature and Purpose of Processing
SigHQ processes personal data to: authenticate admins and users via Microsoft 365 or Google Workspace OAuth; sync employee profile fields from Microsoft Graph or Google Directory for use in signature templates; render and deliver signature HTML at compose time; and log signature-impression and usage events for the Customer’s own reporting.
4. Categories of Data Subjects
Employees and contractors of Customer who are provisioned as users of the Service.
5. Categories of Personal Data
Name, email address, job title, department, office location, phone/mobile numbers, physical address fields, and a copy of the user’s profile photo (stored by SigHQ and served from SigHQ’s own endpoint), where these fields are made available by Customer’s identity provider and enabled by Customer for use in signatures. Signature delivery events (timestamp, template used, client platform) are also processed.
Rendered signature content and profile photos are additionally held as temporary cached copies on the content delivery network (CDN) of SigHQ’s hosting sub-processor, which forms part of the processing described in Section 3. Cached signature content expires within about 6 minutes and cached profile photos within about 25 hours, in each case including stale-while-revalidate windows. These cached copies are retrievable without authentication by design (so email clients and the Outlook add-in can load them), are keyed to a per-user address that is not publicly listed, and are not retained beyond those periods.
6. Sub-processors
SigHQ engages the following categories of sub-processor to provide the Service: cloud hosting (including CDN edge caching) and database infrastructure, and transactional email delivery. Customer consents to SigHQ’s use of sub-processors that meet a data protection standard equivalent to this DPA. SigHQ remains responsible for sub-processor compliance and will notify Customer of material changes to this list via the Service or by email.
7. Security Measures
SigHQ maintains appropriate technical and organisational measures to protect personal data, including encryption of data in transit, access controls scoped to least privilege, and no storage of OAuth access or refresh tokens: the access token issued at sign-in is used once to read the user’s profile and is then discarded, and sessions are held in a signed, encrypted cookie rather than in our database.
8. International Transfers
Where personal data is transferred outside the region in which it was collected, SigHQ relies on appropriate safeguards recognised under applicable data protection law (such as Standard Contractual Clauses) to ensure an equivalent level of protection.
9. Assistance with Data Subject Rights
SigHQ will provide reasonable assistance to Customer in responding to requests from data subjects exercising their rights (access, rectification, erasure, portability) under applicable data protection law, to the extent Customer cannot reasonably fulfil the request itself using the tools available in the Service.
10. Breach Notification
SigHQ will notify Customer without undue delay after becoming aware of a personal data breach affecting Customer’s data, and will provide information reasonably necessary for Customer to meet its own notification obligations.
11. Deletion and Return of Data
SigHQ returns Customer’s data by self-service export: at any time while Customer has access, the account owner can download Customer’s organisation data (settings, members, signatures, assignment rules and monthly usage) as a ZIP of CSV and HTML files from the Configure page. Customer’s account owner can delete the account from the Configure page; SigHQ then holds the data for 30 days so the deletion can be reversed, and automatically and permanently deletes it at the end of that period. Customer may instead request earlier deletion by written request to privacy@sighq.app, in which case SigHQ will delete Customer’s personal data without waiting for the 30 days, unless retention is required by applicable law. Before deletion, SigHQ aggregates usage counts into anonymised statistics that contain no personal data and no link to Customer, and retains those indefinitely. Temporary CDN cached copies described in Section 5 expire automatically within about 25 hours and are not separately purged.
12. Term
This DPA takes effect when accepted and remains in force for as long as SigHQ processes personal data on Customer’s behalf under the Agreement.
Questions about this DPA can be sent to legal@sighq.app.