This agreement governs how Signater processes, as a processor, the personal data you submit to the Platform — in particular Signer data. It forms an integral part of the Terms of Service.
Last updated on August 30, 2026
This Data Processing Agreement ("DPA") is entered into between the Customer and the Signater entity it contracts with under Section 2 of the Terms of Service — Signater LLC, 2125 Biscayne Blvd, Ste 204 #27075, Miami, Florida 33137, USA, or Signater Tecnologia Ltda, CNPJ 50.348.626/0001-61, Alameda Rio Negro, 503, Suite 2020, Alphaville, Barueri/SP, 06454-000, Brazil ("Signater"). It forms an integral part of the Terms of Service and applies whenever the Customer, in using the Platform, submits personal data of third parties — in particular of Signers — for processing by Signater on the Customer's behalf.
The Customer enters into this DPA by accepting the Terms of Service or by using the Platform; no separate signature is required. If this DPA conflicts with the Terms of Service, this DPA prevails with respect to the processing of personal data; in all other matters, the Terms of Service prevail. The current version of this DPA is always available at signater.com/data-processing-agreement.
1.1 Capitalized terms not defined in this DPA — such as Platform, Customer, User, Signer, Envelope, Document and Plan — have the meaning given to them in the Terms of Service.
1.2 For the purposes of this DPA:
2.1 With respect to Customer Personal Data, the Customer acts as Controller: the Customer decides which Documents to send, designates Signers, chooses authentication and identity-verification methods, and determines the purposes of that processing. Signater acts as Processor, processing Customer Personal Data on the Customer's behalf and in accordance with the instructions described in Section 3.
2.2 This DPA does not apply to Personal Data that Signater processes as a Controller — such as account registration, authentication, billing, support, Platform usage telemetry, and communications with the Customer and its Users. That processing is governed by the Privacy Policy.
2.3 As Controller, the Customer represents and warrants that it:
3.1 The Customer's complete and documented instructions to Signater consist of: (i) this DPA; (ii) the Terms of Service; and (iii) the Customer's and its Users' use of the Platform, including the settings of each Envelope, the authentication and verification methods required of each Signer, and the features the Customer enables — such as the artificial intelligence features described in the AI Terms.
3.2 Signater will process Customer Personal Data only in accordance with those instructions, unless required to do otherwise by law or by an order of a competent authority. In that case, Signater will inform the Customer before processing, unless the law prohibits that communication.
3.3 Instructions additional to, or different from, those described in Section 3.1 require the parties' prior written agreement and may be subject to additional fees.
3.4 If Signater considers that an instruction from the Customer infringes applicable Data Protection Law, it may notify the Customer and suspend performance of that instruction until the matter is resolved, without being in breach of this DPA.
4.1 Signater's processing of Customer Personal Data has the scope described below.
| Element | Description |
|---|---|
| Nature of the processing | Collection, receipt, storage, transmission, processing and display of Personal Data in the operation of the Platform: hosting Documents; orchestrating electronic-signature workflows; sending notifications by email, SMS and WhatsApp; authenticating and verifying the identity of Signers where required by the Customer; generating the audit trail and signature certificates; and providing artificial intelligence features where enabled by the Customer. |
| Purpose | To provide the Customer with the service contracted under the Terms of Service, including producing and preserving the evidence of completed signatures. |
| Duration | For the term of the Terms of Service and for as long as the Customer keeps Envelopes and Documents in the account, subject to the periods set out in the Data Retention Policy and to the legal and evidentiary retention described there. |
| Categories of Data Subjects | Signers; the Customer's Users; third parties whose Personal Data appears in the content of Documents submitted by the Customer. |
| Categories of Personal Data | Identification and contact data (name, email, phone number, CPF or another identity document number, where required by the Customer); the content of Documents, which may include any categories of data the Customer places in them; signature and initials images; device and connection data (IP address, browser, operating system); IP-based geolocation and, where provided by the Signer, device geolocation; and the records of actions, dates and times that make up the audit trail. |
| Sensitive Personal Data | Only where the Customer requires the corresponding verification steps: selfies, liveness-check images and photos of identity documents, submitted to automated face comparison by a specialized Subprocessor. The content of Documents may also contain sensitive data placed there by the Customer. |
4.2 Images collected in identity-verification steps are used for the one-time verification of the Signer and preserved as evidence of the signature. Signater does not use them to build a persistent biometric database or for any purpose other than providing the service. How these features work, including the use of automated verification, is described in the AI Terms and in the Privacy Policy.
5.1 Confidentiality of personnel. Signater ensures that the persons authorized to process Customer Personal Data are bound by contractual or statutory confidentiality obligations and that access is limited to what is necessary to provide the service.
5.2 Technical and organizational measures. Signater maintains security measures designed to protect Customer Personal Data against unauthorized access and against accidental or unlawful destruction, loss, alteration, disclosure or dissemination, including:
5.3 Assistance to the Customer. Taking into account the nature of the processing and the information available to it, Signater will provide the Customer with reasonable assistance: (i) in responding to Data Subject requests, through the Platform's features and, where those are not sufficient, through additional reasonable measures; and (ii) in complying with the Customer's obligations regarding the security of processing, the notification of incidents and, where required, data protection impact assessments. Assistance beyond the Platform's features may be subject to reasonable fees, communicated to the Customer in advance.
5.4 Requests received directly. If Signater receives a request from a Data Subject relating to Customer Personal Data, it will direct the Data Subject to the Customer, where the Customer is identifiable, and will inform the Customer of the request, unless legally prohibited from doing so. Signater may respond to the request directly where required by law.
6.1 The Customer grants Signater a general authorization to engage Subprocessors in the provision of the service. The current list of Subprocessors, with each one's function and processing location, is available on the Subprocessors page.
6.2 Signater will give Customers reasonable advance notice, by email or through a notice on the Platform, of material changes to the Subprocessor list — such as the addition of a new Subprocessor with access to Customer Personal Data.
6.3 If the Customer has an objection to a new Subprocessor based on reasonable data protection grounds, it must notify Signater within 15 days of the notice, by email to [email protected]. The parties will seek a solution in good faith; if none is possible, the Customer may terminate its Plan subscription as set out in the Terms of Service, as its sole and exclusive remedy for the objection.
6.4 Signater enters into a contract with each Subprocessor imposing data protection obligations equivalent in substance to those of this DPA, to the extent applicable to the service the Subprocessor provides, and remains liable to the Customer for the Subprocessors' performance under Section 11.
7.1 The Customer acknowledges that the processing of Customer Personal Data involves international transfers — including to Brazil, to the United States and to other countries where Signater and its Subprocessors operate, as indicated on the Subprocessors page — and authorizes those transfers.
7.2 Signater carries out those transfers on the basis of Article 33 of the LGPD, adopting appropriate safeguards such as contractual clauses containing data protection obligations and safeguards offered by the providers themselves. Where the GDPR applies to a transfer, Signater relies on the European Union's Standard Contractual Clauses or another recognized transfer mechanism.
8.1 Signater will notify the Customer without undue delay after confirming a Security Incident, using the account's contact details or a notice on the Platform.
8.2 To the extent the information is reasonably available at the time, the notification will describe the nature of the incident; the categories and approximate number of Data Subjects and Personal Data records affected; the measures taken or recommended; and a point of contact. Information not available at the time of the notification will be provided as it becomes available.
8.3 Notification of a Security Incident is not an acknowledgment of fault or liability by Signater. As Controller, the Customer is responsible for assessing and complying with its own notification obligations to supervisory authorities — including the Brazilian data protection authority (ANPD) — and to Data Subjects.
8.4 The Platform's availability and operational incidents can be followed in real time on the public status page at status.signater.com. That page covers availability and does not replace the Security Incident notifications provided for in clause 8.1.
9.1 Upon the Customer's written and reasoned request, Signater will make available reasonable information and reports to demonstrate compliance with this DPA.
9.2 Requests under Section 9.1 are limited to one in any 12-month period, except where required by a competent authority or following a Security Incident affecting the Customer. The Customer bears the reasonable costs of responding. Responses will in no event include access to other customers' data, to Signater's trade secrets, or to third-party systems and facilities. Where applicable Data Protection Law grants the Customer a broader audit right, the parties will agree in advance, in good faith, on the scope, duration, and confidentiality and security conditions of its exercise, subject to the same frequency and cost limits set out in this Section.
9.3 Information the Customer obtains through an audit is confidential and may be used only to verify compliance with this DPA.
10.1 While the Terms of Service are in force, the Customer can export its Documents and signature certificates directly from the Platform.
10.2 After the contractual relationship ends, Signater will, upon the Customer's written request to [email protected], delete or return Customer Personal Data within a reasonable period, except for Personal Data whose retention is necessary to comply with a legal or regulatory obligation or for the regular exercise of rights — including signature evidence, audit trails and certificates, which may be retained for the periods described in the Data Retention Policy.
10.3 Residual copies may temporarily persist in backups and internal systems until they are deleted in the normal cycle of those systems, and remain protected by the measures of this DPA for as long as they exist. In the absence of a request from the Customer, Customer Personal Data is handled in accordance with the Data Retention Policy.
11.1 Each party's liability arising out of this DPA is subject to the exclusions and the limitation of liability set out in the Terms of Service, which apply to the parties' contractual obligations as a whole, including those under this DPA, except where the law does not permit such limitation.
11.2 Each party is responsible for complying with the obligations that Data Protection Law assigns to its role — the Customer as Controller and Signater as Processor. Signater is not liable for damages arising from the Customer's instructions, from the absence of a legal basis for processing determined by the Customer, or from the content of Documents.
12.1 This DPA remains in force for as long as the Terms of Service are in force and, after their termination, for as long as Signater processes Customer Personal Data. Sections 5, 8, 9, 10, 11 and 13 survive termination to the extent necessary.
12.2 Signater may update this DPA, including to reflect the evolution of the Platform and of the law. Material changes will be announced with reasonable advance notice, by email or through a notice on the Platform. Continued use of the Platform after a new version takes effect constitutes acceptance.
13.1 This DPA is governed by the same law, and subject to the same venue, that apply to the Terms of Service for the relevant contracting entity: the laws of the State of Florida and the courts of Miami-Dade County for Signater LLC; Brazilian law and the courts of Barueri/SP for Signater Tecnologia Ltda (Section 22 of the Terms of Service). This choice does not deprive Data Subjects or the Customer of mandatory data protection rights granted by the laws of their own jurisdiction, which remain unaffected.
13.2 Questions about this DPA, data protection requests and communications to Signater's data protection officer (Encarregado) should be directed to [email protected].
13.3 Related documents: Privacy Policy, Data Retention Policy, Subprocessors, AI Terms and the Legal Center.