Skip to content
  • Product
  • Pricing
  • Docs
  • Verify
  • Trust
ENSK
Sign inStart free
  • Product
  • Pricing
  • Docs
  • Verify
  • Trust
  • Sign in
ENSK

Legal

Data processing agreement

The terms under which UniqTec s.r.o. processes personal data on behalf of TrustInk customers (Article 28 GDPR).

Version
draft-2026-09-26
Dated
26 September 2026

Documents

  • Terms of service
  • Privacy notice
  • Data processing agreement

On this page

  1. Parties and scope
  2. Subject matter, duration, nature and purpose
  3. Data subjects and categories of data
  4. Obligations of the processor
  5. Sub-processors
  6. Location and transfers
  7. Deletion
  8. Annex: technical and organisational measures

Draft: This document is pending legal review. It shows the structure and intent of our terms and will change before it takes effect.

Parties and scope

This agreement is between the customer who uses TrustInk (the controller) and UniqTec s.r.o., Slovakia (the processor). It forms part of the terms of service and applies to all personal data the processor handles on the controller’s behalf when providing TrustInk.

Subject matter, duration, nature and purpose

  • Subject matter: collecting electronic signatures on documents the controller sends.
  • Duration: for as long as the controller uses TrustInk, and until the data is deleted as described below.
  • Nature and purpose: storing documents, sending invitations and reminders, confirming signers with one-time codes, recording signing steps, issuing a certificate per signer, producing the signed PDF and the sealed evidence summary, and delivering webhooks and events to the controller.

Data subjects and categories of data

  • Data subjects: the participants the controller invites to sign, and any other people named in the documents the controller uploads.
  • Categories of data: first and last name, email address, phone number (when codes are sent by SMS), optional address and gender if the controller supplies them, the document and its content, the drawn signature, timestamps, IP address and browser of each signing step, and the certificate issued to the signer.
  • The controller does not upload special categories of data unless it has assessed that it may.

Obligations of the processor

The processor:

  1. processes the data only on the controller’s documented instructions, which are these terms, the API calls and the portal settings, unless the law requires otherwise;
  2. ensures that everyone who can access the data is bound to confidentiality;
  3. takes the technical and organisational measures in the annex;
  4. engages sub-processors only as described below;
  5. helps the controller answer data subjects’ requests and meet its obligations under Articles 32 to 36 GDPR, taking into account the nature of the processing;
  6. notifies the controller of a personal data breach without undue delay, and in any case within [48] hours of becoming aware of it;
  7. deletes or returns the data at the end of the service, as described below;
  8. makes available the information needed to demonstrate compliance and allows for audits, with reasonable notice and at most once a year unless a breach gives reason for more.

Sub-processors

The controller authorises the sub-processors listed on the trust page. The processor informs the controller of an intended addition or replacement at least 30 days in advance; the controller may object on reasonable grounds and, if no solution is found, terminate the affected service. The processor imposes the same data protection obligations on each sub-processor.

Location and transfers

The data is stored and processed in the EU (AWS, Ireland, eu-west-1). A transfer outside the EU happens only with appropriate safeguards under Chapter V GDPR.

Deletion

Documents and participant data are kept for the retention period the controller’s plan and settings allow, and deleted when it ends, when the controller deletes a case, or within [30] days after the end of the contract. Signed documents already delivered to the controller or participants are outside the processor’s control.

Annex: technical and organisational measures

  • Hosting in AWS eu-west-1, with data encrypted at rest and in transit (TLS).
  • The keys of the TrustInk certificate authorities and the document seal are held in AWS Key Management Service; their private halves never leave it.
  • Access to production limited to named staff, with multi-factor authentication and audit logs.
  • API access by OAuth 2.0 client credentials; webhook payloads signed with HMAC.
  • Separation of customers’ data by tenant in every request.
  • Monitoring and alarms on failures.
  • [To be completed and reviewed before the agreement is signed.]

Questions about this document? Contact us ·Current versions as JSON

A digital handshake, available anytime.

Product

  • How it works
  • Signing at the counter
  • Pricing
  • Verify a document

Developers

  • Documentation
  • Quickstart
  • API reference

Company

  • Trust and security
  • Contact
  • Report a vulnerability

Legal

  • Terms
  • Privacy
  • Data processing agreement

© 2026 UniqTec s.r.o. · TrustInk is a product of UniqTec s.r.o., Slovakia.

Hosted in the EU (AWS eu-west-1).