Data processing addendum
Our commitments as your data processor
This Data Processing Addendum describes how Nevtan processes personal data on behalf of customers using Nevtan Sign, and is designed to support compliance with the GDPR, UK GDPR, and equivalent global privacy legislation.
Effective Date: June 6, 2026 — Last Updated: June 6, 2026. This Data Processing Addendum ("DPA") forms part of the Terms of Service, Subscription Agreement, Order Form, or other written agreement ("Agreement") between Nevtan ("Processor") and the Customer ("Controller") governing the use of Nevtan Sign and related services (the "Services"). This DPA applies where Nevtan processes Personal Data on behalf of the Customer in connection with the Services. In the event of a conflict between this DPA and the Agreement, the terms of this DPA shall prevail with respect to the processing of Personal Data. This DPA is designed to support compliance with applicable global data protection laws, including the GDPR, UK GDPR, and equivalent privacy legislation in other jurisdictions. Enterprise customers may execute a signed version of this DPA by contacting privacy@nevtan.com.
Jump to a part
Part 1 — Definitions
1. Definitions
The following terms have the meanings set out below. Capitalized terms not defined here have the meaning given in the Agreement.
| Term | Definition |
|---|---|
| Applicable Data Protection Laws | All privacy and data protection laws applicable to the processing of Personal Data under this DPA, including without limitation the GDPR, UK GDPR, and equivalent national, state, or regional privacy legislation in any relevant jurisdiction. |
| Controller | The entity that determines the purposes and means of processing Personal Data. In the context of this DPA, the Customer acts as Controller. |
| Processor | The entity that processes Personal Data on behalf of the Controller. In the context of this DPA, Nevtan acts as Processor. |
| Personal Data | Any information relating to an identified or identifiable natural person ("Data Subject"), as defined under Applicable Data Protection Laws. |
| Processing | Any operation or set of operations performed on Personal Data, whether or not by automated means, including collection, storage, organization, structuring, use, transmission, disclosure, restriction, erasure, and destruction. |
| Data Subject | A natural person whose Personal Data is processed under this DPA. |
| Security Incident | A confirmed breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, Personal Data transmitted, stored, or otherwise processed. |
| Subprocessor | A third-party service provider engaged by Nevtan to process Personal Data on behalf of Customers in connection with the Services. |
| Standard Contractual Clauses (SCCs) | The standard contractual clauses for the transfer of personal data to third countries as approved by the European Commission, and as may be amended or replaced from time to time. |
Part 2 — Scope & Roles
2. Scope and Purpose
This DPA governs Nevtan's processing of Personal Data on behalf of the Customer in connection with the Services, including:
A full description of the processing activities covered by this DPA is set out in .
3. Relationship of the Parties
The Customer acts as Controller and Nevtan acts as Processor in respect of Personal Data processed under this DPA.
Nevtan shall process Personal Data solely in accordance with the documented instructions of the Customer, as set out in this DPA and the Agreement, unless otherwise required by applicable law. Where Nevtan is required by law to process Personal Data other than in accordance with Customer instructions, Nevtan shall inform the Customer of that requirement before processing, to the extent permitted by law.
4. Customer Responsibilities
The Customer is responsible for:
Customer warrants that it has the necessary rights and authority to provide Personal Data to Nevtan for processing under this DPA.
Part 3 — Processor Obligations
5. Processor Obligations
Nevtan shall, in its capacity as Processor:
Process Only on Instructions
Process Personal Data solely in accordance with Customer's documented instructions and the Agreement, unless required by applicable law.
Confidentiality
Ensure that all personnel authorized to access or process Personal Data are subject to binding confidentiality obligations.
Security
Implement and maintain appropriate technical and organizational measures to protect Personal Data as described in Section 6.
Assist with Compliance
Provide reasonable assistance to enable Customer to comply with its obligations under Applicable Data Protection Laws, including in relation to Data Subject rights, DPIAs, and security obligations.
Data Subject Rights
Promptly notify Customer of any Data Subject request received directly by Nevtan, and assist Customer in fulfilling such requests where required.
Notify of Conflicts
Inform Customer if Nevtan considers an instruction to be in conflict with Applicable Data Protection Laws, before proceeding with processing.
6. Security Measures
Nevtan maintains a layered security program incorporating administrative, technical, and physical safeguards appropriate to the risk, designed to protect Personal Data against unauthorized access, disclosure, alteration, and loss.
A summary of current security controls is set out in . Key measures include:
Access Controls
Role-based access controls, least-privilege principles, and multi-factor authentication for administrative access.
Encryption
Encryption of Personal Data in transit using modern transport protocols and at rest using industry-standard encryption.
Infrastructure Security
Network segmentation, firewalls, intrusion monitoring, and security logging across cloud infrastructure.
Operational Security
Documented incident response procedures, change management controls, and periodic personnel access reviews.
Availability Controls
Data backup procedures, disaster recovery processes, and redundancy controls to support service continuity.
Vulnerability Management
Regular security testing, vulnerability scanning, and patch management to identify and remediate risks.
Nevtan may update security measures from time to time, provided that such updates do not materially diminish the overall level of protection afforded to Personal Data.
Part 4 — Subprocessors & International Transfers
7. Subprocessors
Customer provides general authorization for Nevtan to engage Subprocessors to assist in providing the Services. Nevtan shall:
A current list of Subprocessors is available at /subprocessors.
Nevtan will provide reasonable advance notice of material changes to the Subprocessor list. Customers who object to a new Subprocessor on data protection grounds may notify Nevtan in writing within fourteen (14) days of notice, and the parties will work in good faith to resolve the concern.
8. International Data Transfers
Where Personal Data is transferred from the European Economic Area, United Kingdom, or other jurisdictions with data transfer restrictions to a country not recognized as providing an adequate level of data protection, Nevtan shall implement appropriate safeguards in accordance with Applicable Data Protection Laws. Such safeguards may include:
Where SCCs or equivalent mechanisms are required, they are incorporated into this DPA by reference and the relevant module will apply based on the nature of the transfer.
Part 5 — Data Subject Rights & Government Requests
9. Data Subject Requests
If Nevtan receives a request directly from a Data Subject relating to the processing of Customer's Personal Data, Nevtan shall:
Customer is responsible for responding to Data Subject requests in accordance with its obligations under Applicable Data Protection Laws. Nevtan will provide reasonable assistance to facilitate Customer's compliance.
10. Government and Legal Requests
Nevtan may be required to disclose Personal Data in response to a valid legal obligation, including a court order, government request, or regulatory requirement. Where legally permitted, Nevtan will:
Nevtan will disclose only the minimum Personal Data necessary to satisfy the legal obligation.
Part 6 — Security Incidents & Audits
11. Security Incident Notification
Nevtan shall notify Customer without undue delay, and in any event within seventy-two (72) hours where practicable, after becoming aware of a confirmed Security Incident affecting Customer Personal Data. Notification will include, to the extent then known:
Notification by Nevtan does not constitute an admission of fault or liability. Nevtan will provide updates as additional information becomes available.
12. Audits and Assessments
Upon reasonable written request and subject to confidentiality obligations, Nevtan will provide Customer with documentation demonstrating compliance with this DPA. Such documentation may include:
Customer-initiated on-site audits are limited to once per calendar year unless required by applicable law or following a confirmed Security Incident. Audits must be conducted with reasonable prior written notice, during normal business hours, and subject to reasonable confidentiality requirements. Audit costs are borne by Customer unless the audit reveals material non-compliance.
Part 7 — Data Retention & Deletion
13. Data Retention
Customer controls the retention periods for Personal Data stored within the Services through its account settings and configuration. Nevtan may retain Personal Data beyond Customer-specified periods only to the extent:
14. Return and Deletion of Data
Upon expiration or termination of the Agreement, and subject to applicable law, Nevtan shall, at Customer's written election:
Nevtan shall certify such deletion upon Customer's request. Residual copies held in backup systems will be deleted in accordance with Nevtan's standard backup rotation schedules unless earlier deletion is required by law.
Part 8 — General Provisions
15. Liability
The liability limitations set out in the Agreement apply to this DPA to the maximum extent permitted by Applicable Data Protection Laws. Nothing in this DPA limits either party's liability to the extent that such liability cannot be limited under applicable law.
16. Term and Termination
This DPA remains in effect for as long as Nevtan processes Personal Data on behalf of Customer. Termination of the Agreement automatically terminates this DPA, subject to any ongoing processing obligations required by applicable law and the data deletion obligations set out in Section 14.
17. Governing Law
This DPA shall be governed by the governing law specified in the Agreement, unless otherwise required by Applicable Data Protection Laws. Where Applicable Data Protection Laws mandate a specific governing law or jurisdiction for data processing agreements, such requirements shall take precedence.
18. Order of Precedence
In the event of any conflict or inconsistency between the documents governing the parties' relationship, the following order of precedence applies:
19. Contact Information
Privacy and data protection inquiries regarding this DPA may be directed to:
Privacy
privacy@nevtan.comWebsite: nevtan.com
Annexes
Annex A — Description of Processing Activities
This Annex sets out the details of processing activities carried out by Nevtan as Processor on behalf of the Customer as Controller, as required under Applicable Data Protection Laws.
Annex B — Security Controls Summary
This Annex provides a summary of the technical and organizational security measures implemented by Nevtan to protect Personal Data, as required under Article 32 GDPR and equivalent provisions under Applicable Data Protection Laws.
Access Management
Role-based access controls (RBAC) limiting access to authorized personnel; least-privilege access principles; MFA for administrative access; regular access reviews.
Encryption
Encryption of Personal Data in transit using TLS/HTTPS; encryption at rest using industry-standard algorithms; encryption key management procedures.
Infrastructure Security
Secure, audited cloud infrastructure providers; network segmentation and VPN controls; firewall and perimeter security; intrusion detection and centralized log management.
Vulnerability & Patch Management
Regular vulnerability scanning and security testing; timely patching based on risk severity; third-party dependency monitoring; pre-deployment security review.
Incident Response
Documented security incident response procedures; defined escalation and notification processes; post-incident review; 72-hour breach notification capability.
Business Continuity
Regular data backups with defined recovery objectives; disaster recovery plans and periodic testing; redundant infrastructure; change management controls.
Personnel Security
Confidentiality obligations for all personnel with access to Personal Data; security awareness training; background checks; access revocation on role change or departure.
Vendor Risk Management
Due diligence on Subprocessors prior to engagement; data protection obligations imposed on all Subprocessors; periodic review of Subprocessor compliance.
This Security Controls Summary reflects Nevtan's current practices and may be updated from time to time. Customers may request the most current version, available third-party audit reports, or additional security documentation by contacting security@nevtan.com.
Annex C — Execution (Optional, For Signed DPA Requests)
This DPA is effective by reference as part of the Agreement and does not require a separate signature to take effect. Enterprise customers who require a countersigned copy for internal compliance or procurement purposes may request one by contacting privacy@nevtan.com. The signed DPA, once executed by both parties, supplements and forms part of the Agreement.
