NevTan Sign
NevTan Sign

Data processing addendum

Our commitments as your data processor

This Data Processing Addendum describes how Nevtan processes personal data on behalf of customers using Nevtan Sign, and is designed to support compliance with the GDPR, UK GDPR, and equivalent global privacy legislation.

Effective Date: June 6, 2026 — Last Updated: June 6, 2026. This Data Processing Addendum ("DPA") forms part of the Terms of Service, Subscription Agreement, Order Form, or other written agreement ("Agreement") between Nevtan ("Processor") and the Customer ("Controller") governing the use of Nevtan Sign and related services (the "Services"). This DPA applies where Nevtan processes Personal Data on behalf of the Customer in connection with the Services. In the event of a conflict between this DPA and the Agreement, the terms of this DPA shall prevail with respect to the processing of Personal Data. This DPA is designed to support compliance with applicable global data protection laws, including the GDPR, UK GDPR, and equivalent privacy legislation in other jurisdictions. Enterprise customers may execute a signed version of this DPA by contacting privacy@nevtan.com.

Jump to a part

Definitions
Scope & roles
Processor obligations
Subprocessors & transfers
Data subject rights
Incidents & audits
Retention & deletion
General provisions
Annexes

Part 1 — Definitions


1. Definitions

The following terms have the meanings set out below. Capitalized terms not defined here have the meaning given in the Agreement.

TermDefinition
Applicable Data Protection LawsAll privacy and data protection laws applicable to the processing of Personal Data under this DPA, including without limitation the GDPR, UK GDPR, and equivalent national, state, or regional privacy legislation in any relevant jurisdiction.
ControllerThe entity that determines the purposes and means of processing Personal Data. In the context of this DPA, the Customer acts as Controller.
ProcessorThe entity that processes Personal Data on behalf of the Controller. In the context of this DPA, Nevtan acts as Processor.
Personal DataAny information relating to an identified or identifiable natural person ("Data Subject"), as defined under Applicable Data Protection Laws.
ProcessingAny operation or set of operations performed on Personal Data, whether or not by automated means, including collection, storage, organization, structuring, use, transmission, disclosure, restriction, erasure, and destruction.
Data SubjectA natural person whose Personal Data is processed under this DPA.
Security IncidentA confirmed breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, Personal Data transmitted, stored, or otherwise processed.
SubprocessorA third-party service provider engaged by Nevtan to process Personal Data on behalf of Customers in connection with the Services.
Standard Contractual Clauses (SCCs)The standard contractual clauses for the transfer of personal data to third countries as approved by the European Commission, and as may be amended or replaced from time to time.

Part 2 — Scope & Roles


2. Scope and Purpose

This DPA governs Nevtan's processing of Personal Data on behalf of the Customer in connection with the Services, including:

Electronic signature and document workflow services
User account management and authentication
Notification and communication services
Audit trail maintenance and document lifecycle tracking
Customer support and service operations
API and integration services
Platform security monitoring and operations

A full description of the processing activities covered by this DPA is set out in .

3. Relationship of the Parties

The Customer acts as Controller and Nevtan acts as Processor in respect of Personal Data processed under this DPA.

Nevtan shall process Personal Data solely in accordance with the documented instructions of the Customer, as set out in this DPA and the Agreement, unless otherwise required by applicable law. Where Nevtan is required by law to process Personal Data other than in accordance with Customer instructions, Nevtan shall inform the Customer of that requirement before processing, to the extent permitted by law.

4. Customer Responsibilities

The Customer is responsible for:

Establishing and maintaining a valid legal basis for processing Personal Data under Applicable Data Protection Laws
Obtaining all required consents from Data Subjects prior to processing their Personal Data through the Services
Providing lawful instructions to Nevtan regarding the processing of Personal Data
Maintaining the accuracy and completeness of Personal Data provided to the Services
Complying with all obligations applicable to Controllers under Applicable Data Protection Laws

Customer warrants that it has the necessary rights and authority to provide Personal Data to Nevtan for processing under this DPA.

Part 3 — Processor Obligations


5. Processor Obligations

Nevtan shall, in its capacity as Processor:

Process Only on Instructions

Process Personal Data solely in accordance with Customer's documented instructions and the Agreement, unless required by applicable law.

Confidentiality

Ensure that all personnel authorized to access or process Personal Data are subject to binding confidentiality obligations.

Security

Implement and maintain appropriate technical and organizational measures to protect Personal Data as described in Section 6.

Assist with Compliance

Provide reasonable assistance to enable Customer to comply with its obligations under Applicable Data Protection Laws, including in relation to Data Subject rights, DPIAs, and security obligations.

Data Subject Rights

Promptly notify Customer of any Data Subject request received directly by Nevtan, and assist Customer in fulfilling such requests where required.

Notify of Conflicts

Inform Customer if Nevtan considers an instruction to be in conflict with Applicable Data Protection Laws, before proceeding with processing.

6. Security Measures

Nevtan maintains a layered security program incorporating administrative, technical, and physical safeguards appropriate to the risk, designed to protect Personal Data against unauthorized access, disclosure, alteration, and loss.

A summary of current security controls is set out in . Key measures include:

Access Controls

Role-based access controls, least-privilege principles, and multi-factor authentication for administrative access.

Encryption

Encryption of Personal Data in transit using modern transport protocols and at rest using industry-standard encryption.

Infrastructure Security

Network segmentation, firewalls, intrusion monitoring, and security logging across cloud infrastructure.

Operational Security

Documented incident response procedures, change management controls, and periodic personnel access reviews.

Availability Controls

Data backup procedures, disaster recovery processes, and redundancy controls to support service continuity.

Vulnerability Management

Regular security testing, vulnerability scanning, and patch management to identify and remediate risks.

Nevtan may update security measures from time to time, provided that such updates do not materially diminish the overall level of protection afforded to Personal Data.

Part 4 — Subprocessors & International Transfers


7. Subprocessors

Customer provides general authorization for Nevtan to engage Subprocessors to assist in providing the Services. Nevtan shall:

Conduct reasonable due diligence on Subprocessors prior to engagement
Impose data protection obligations on Subprocessors that are no less protective than those set out in this DPA
Remain responsible to Customer for the performance of Subprocessors' obligations under this DPA to the extent required by Applicable Data Protection Laws

A current list of Subprocessors is available at /subprocessors.

Nevtan will provide reasonable advance notice of material changes to the Subprocessor list. Customers who object to a new Subprocessor on data protection grounds may notify Nevtan in writing within fourteen (14) days of notice, and the parties will work in good faith to resolve the concern.

8. International Data Transfers

Where Personal Data is transferred from the European Economic Area, United Kingdom, or other jurisdictions with data transfer restrictions to a country not recognized as providing an adequate level of data protection, Nevtan shall implement appropriate safeguards in accordance with Applicable Data Protection Laws. Such safeguards may include:

Standard Contractual Clauses (SCCs) as approved by the European Commission
The UK International Data Transfer Addendum (UK Addendum)
Binding corporate rules or other approved transfer mechanisms
Other applicable derogations or mechanisms permitted under Applicable Data Protection Laws

Where SCCs or equivalent mechanisms are required, they are incorporated into this DPA by reference and the relevant module will apply based on the nature of the transfer.

Part 5 — Data Subject Rights & Government Requests


9. Data Subject Requests

If Nevtan receives a request directly from a Data Subject relating to the processing of Customer's Personal Data, Nevtan shall:

Notify Customer without undue delay, to the extent permitted by applicable law
Refrain from responding to the request except as instructed by Customer or as required by applicable law

Customer is responsible for responding to Data Subject requests in accordance with its obligations under Applicable Data Protection Laws. Nevtan will provide reasonable assistance to facilitate Customer's compliance.

Part 6 — Security Incidents & Audits


11. Security Incident Notification

Nevtan shall notify Customer without undue delay, and in any event within seventy-two (72) hours where practicable, after becoming aware of a confirmed Security Incident affecting Customer Personal Data. Notification will include, to the extent then known:

The nature of the Security Incident and categories of Personal Data affected
The approximate number of Data Subjects and records involved
The likely consequences of the Security Incident
The measures taken or proposed to address the incident and mitigate its effects

Notification by Nevtan does not constitute an admission of fault or liability. Nevtan will provide updates as additional information becomes available.

12. Audits and Assessments

Upon reasonable written request and subject to confidentiality obligations, Nevtan will provide Customer with documentation demonstrating compliance with this DPA. Such documentation may include:

Security summaries and certifications
Third-party audit reports (e.g., SOC 2 Type II where available)
Compliance attestations
Relevant policy documentation

Customer-initiated on-site audits are limited to once per calendar year unless required by applicable law or following a confirmed Security Incident. Audits must be conducted with reasonable prior written notice, during normal business hours, and subject to reasonable confidentiality requirements. Audit costs are borne by Customer unless the audit reveals material non-compliance.

Part 7 — Data Retention & Deletion


13. Data Retention

Customer controls the retention periods for Personal Data stored within the Services through its account settings and configuration. Nevtan may retain Personal Data beyond Customer-specified periods only to the extent:

Required by applicable law or regulation
Necessary for security, audit, or backup purposes
Required to enforce contractual rights
14. Return and Deletion of Data

Upon expiration or termination of the Agreement, and subject to applicable law, Nevtan shall, at Customer's written election:

Make Customer Personal Data available for export in a commercially reasonable format; and/or
Delete or anonymize Customer Personal Data within a commercially reasonable timeframe following Customer's request

Nevtan shall certify such deletion upon Customer's request. Residual copies held in backup systems will be deleted in accordance with Nevtan's standard backup rotation schedules unless earlier deletion is required by law.

Part 8 — General Provisions


15. Liability

The liability limitations set out in the Agreement apply to this DPA to the maximum extent permitted by Applicable Data Protection Laws. Nothing in this DPA limits either party's liability to the extent that such liability cannot be limited under applicable law.

16. Term and Termination

This DPA remains in effect for as long as Nevtan processes Personal Data on behalf of Customer. Termination of the Agreement automatically terminates this DPA, subject to any ongoing processing obligations required by applicable law and the data deletion obligations set out in Section 14.

17. Governing Law

This DPA shall be governed by the governing law specified in the Agreement, unless otherwise required by Applicable Data Protection Laws. Where Applicable Data Protection Laws mandate a specific governing law or jurisdiction for data processing agreements, such requirements shall take precedence.

18. Order of Precedence

In the event of any conflict or inconsistency between the documents governing the parties' relationship, the following order of precedence applies:

    1
    Applicable Data Protection Laws
    2
    This Data Processing Addendum
    3
    The Agreement (Terms of Service or Master Service Agreement)
    4
    Any applicable Order Form or Statement of Work
19. Contact Information

Privacy and data protection inquiries regarding this DPA may be directed to:

Website: nevtan.com

Annexes


Annex A — Description of Processing Activities

This Annex sets out the details of processing activities carried out by Nevtan as Processor on behalf of the Customer as Controller, as required under Applicable Data Protection Laws.

Subject Matter — Provision of electronic signature and document workflow services through the Nevtan Sign platform.
Duration — For the term of the Agreement and any applicable post-termination retention period as specified in this DPA.
Nature of Processing — Collection, storage, organization, transmission, retrieval, use, disclosure, restriction, and deletion of Personal Data.
Purpose of Processing — Provision and operation of the Services; user authentication and access management; document workflow execution and tracking; customer support and technical operations; security monitoring and incident management; service improvement and analytics (aggregated, de-identified where possible).
Categories of Data Subjects — Customer employees and administrators; contractors and authorized users; customers' clients and counterparties; vendors and business partners; document signers and recipients; authorized representatives.
Categories of Personal Data — Identity data (name, username, job title, organization); contact data (email address, telephone number); authentication data (login history, session records, security event logs); signature data (electronic signature records and associated metadata); document data (uploaded document contents, as determined by Customer); audit trail data (timestamps, IP addresses, access and action records); technical data (device identifiers, browser information, session tokens).
Special Categories of Data — Not anticipated by default. Customer is responsible for ensuring that special category or sensitive data is not processed through the Services without appropriate safeguards and legal basis.
Annex B — Security Controls Summary

This Annex provides a summary of the technical and organizational security measures implemented by Nevtan to protect Personal Data, as required under Article 32 GDPR and equivalent provisions under Applicable Data Protection Laws.

Access Management

Role-based access controls (RBAC) limiting access to authorized personnel; least-privilege access principles; MFA for administrative access; regular access reviews.

Encryption

Encryption of Personal Data in transit using TLS/HTTPS; encryption at rest using industry-standard algorithms; encryption key management procedures.

Infrastructure Security

Secure, audited cloud infrastructure providers; network segmentation and VPN controls; firewall and perimeter security; intrusion detection and centralized log management.

Vulnerability & Patch Management

Regular vulnerability scanning and security testing; timely patching based on risk severity; third-party dependency monitoring; pre-deployment security review.

Incident Response

Documented security incident response procedures; defined escalation and notification processes; post-incident review; 72-hour breach notification capability.

Business Continuity

Regular data backups with defined recovery objectives; disaster recovery plans and periodic testing; redundant infrastructure; change management controls.

Personnel Security

Confidentiality obligations for all personnel with access to Personal Data; security awareness training; background checks; access revocation on role change or departure.

Vendor Risk Management

Due diligence on Subprocessors prior to engagement; data protection obligations imposed on all Subprocessors; periodic review of Subprocessor compliance.

This Security Controls Summary reflects Nevtan's current practices and may be updated from time to time. Customers may request the most current version, available third-party audit reports, or additional security documentation by contacting security@nevtan.com.

Annex C — Execution (Optional, For Signed DPA Requests)

This DPA is effective by reference as part of the Agreement and does not require a separate signature to take effect. Enterprise customers who require a countersigned copy for internal compliance or procurement purposes may request one by contacting privacy@nevtan.com. The signed DPA, once executed by both parties, supplements and forms part of the Agreement.