Data Processing Agreement
Agreement on the processing of personal data on behalf of the customer under Art. 28 GDPR between the customer (controller) and SeeBubble Media FlexCo (processor). It becomes part of the contract when a plan is purchased.
Last updated: 2026-10-01
1. Subject matter and duration
The subject matter is the provision of the DocTrace platform for collecting electronic signatures on PDF documents with a proof page and a chained audit log. Processing lasts as long as the service contract and ends with deletion under section 8.
2. Nature and purpose of processing
Storing, displaying, sending by e-mail, generating the final version and the proof page, logging the steps and backing up the data, solely to collect and prove signatures on behalf of the customer. The processor does not process the data for its own purposes.
3. Types of data
Master data of recipients (name, e-mail address, optionally company, employee number, location, date of birth), user data (name, e-mail address, roles, login times), uploaded documents and their contents, drawn signatures, final versions, releases after signing, and log data (timestamps, IP addresses, device identifiers).
4. Categories of data subjects
Employees and users of the customer, signers (such as the customer's employees, suppliers, customers and applicants) and persons named in the documents.
5. Obligations of the processor
We process the data only on the customer's documented instructions; using the platform counts as an instruction. All persons involved in processing are bound to confidentiality. We support the customer in answering data subject requests, in data protection impact assessments and in notifications to supervisory authorities, and inform the customer without undue delay of any personal data breach. We notify the customer of instructions that infringe data protection law.
6. Technical and organisational measures
Encrypted connections (TLS); separation of companies in the database (row-level security) and in storage; chained, immutable audit log; storage for originals and final versions without deletion or overwriting; encrypted storage of credentials and keys; release files with their own key (AES-256-GCM) and deletion of the key on expiry; permissions and roles per company; support access read-only, time-limited and visible to the company; daily backups retained for 14 days; hosting in Frankfurt am Main (EU).
7. Sub-processors
The customer consents to the following sub-processors: Google Cloud EMEA Limited (Ireland; servers and storage, Frankfurt am Main data centre, europe-west3), Amazon Web Services EMEA SARL (Luxembourg; Amazon SES for system e-mails, Frankfurt region), alternatively Brevo (Sendinblue SAS, France; system e-mails) and Paddle.com Market Ltd. (United Kingdom; payment processing as merchant of record, processing only the customer's billing and payment data, no data of data subjects).
Data processing agreements are in place with all sub-processors, with EU standard contractual clauses for providers outside the EU. We announce changes at least four weeks in advance; the customer may object for good cause.
8. Deletion and return
After the end of the contract the company's data remains exportable for 30 days (final versions, logs, master data) and is then deleted, unless the company has statutory retention obligations, which it fulfils itself by exporting. Backups are overwritten within a further 14 days. On request we confirm the deletion.
9. Audit rights and evidence
The customer may verify compliance with this agreement through information, evidence and, after notice and to a reasonable extent, audits. We provide the information required for this.
10. Final provisions
Austrian law applies. In case of conflict between this agreement and the terms of service, this agreement prevails on data protection matters. Should any provision be invalid, the remainder of the agreement remains in force.