Data processing agreement (DPA)
Version 1.0.0 · Effective from 7/27/2026
This document defines how Sygnau processes personal data on behalf of your organisation when you use the authorisations service.
It matters because: (1) you remain the controller for participant and family data; (2) Sygnau acts as processor and only processes data to provide the service; (3) this supports GDPR compliance and better protection for everyone.
Subject matter and duration
- Sygnau processes personal data on behalf of the customer to provide the authorisations service.
- Duration matches the service agreement term.
Types of data
- Identity and contact data
- Minors' data when entered by the customer
- Special categories (e.g. health) only if configured by the customer
- Signatures, responses and related documents
Categories of data subjects
- Participants
- Legal representatives / guardians
- Customer organisation users
- Signers
Purpose and limits
- Only providing the service and documented customer instructions
- No incompatible own purposes (e.g. training own models on customer content)
Customer instructions
- Via the product UI and documentation
- The customer is responsible for the lawfulness of instructions
Confidentiality and security
- Authorised staff bound by confidentiality
- Technical and organisational measures: access control, multi-tenant RLS, encryption in transit, backups and audit
Sub-processors
- As listed on the public sub-processors page
- Material changes will be communicated to the customer
International transfers
- Where needed, with appropriate safeguards
Data-subject rights
- Sygnau assists the customer
- Requests received are referred to the customer when appropriate
Security incidents
- Notify the customer without undue delay after confirming a relevant incident
- After human review
Return or deletion
- On service end, per customer instructions and applicable legal retention
Audit and traceability
- Append-only audit logs and reasonable technical evidence