GDPR
WoltSign and GDPR: How We Handle Personal Data in E-Signature Workflows
When your customers or employees sign a document through WoltSign, that signing session processes personal data. Here is what WoltSign does with that data, what protections are in place, and where your organization's responsibilities begin. WoltSign is designed to support your GDPR obligations as a data controller.
WoltSign as a data processor under GDPR
Under GDPR, the organization that determines the purposes and means of processing personal data is the data controller. WoltSign is a data processor. It processes personal data (signer names, email addresses, IP addresses, and document content) on behalf of the data controller (your organization) according to your instructions and the terms of a Data Processing Agreement.
WoltSign does not use the personal data it processes through signing workflows for its own purposes beyond operating the service. Personal data may be processed and stored outside your country of residence, including outside the European Economic Area, as described in our Data Processing Agreement. Data is encrypted in transit using TLS and at rest using AES-256.
Data protection controls in WoltSign
Specific technical and organizational measures described in our security documentation and Data Processing Agreement.
| Control | Status |
|---|---|
| Data in transit encryption | TLS between your browser and WoltSign |
| Data at rest encryption | AES-256 for documents, signatures, and metadata |
| Storage and transfers | May include processing outside the EEA; transfer safeguards described in the DPA |
| Data Processing Agreement | Available at DPA |
| Sub-processors | Listed in the DPA, including cloud infrastructure and email delivery |
| Access controls | Role-based access controls with multi-factor authentication support |
| Audit logging | Signing events, document actions, and authentication attempts are logged |
| Data deletion on account cancellation | Customer data deleted or made inaccessible within a reasonable period after termination, subject to legal retention obligations (see DPA Section 11) |
| Data subject access requests | WoltSign provides reasonable technical assistance to the controller, as described in the DPA |
Data Processing Agreement
WoltSign offers a Data Processing Agreement (DPA) to all customers. The DPA describes WoltSign's obligations as a data processor under GDPR Article 28, including sub-processor disclosure, security measures, and data subject rights support.
Download or review the WoltSign DPA at DPA. If you need a countersigned DPA for your records, contact WoltSign at support@woltsign.com.
What your organization is responsible for
WoltSign is a tool in your GDPR compliance program. It is not the entire program.
WoltSign does not determine what personal data your organization collects, how long you retain it, or whether you have a valid legal basis for processing it. Your organization is the data controller for the signing data you collect through WoltSign. You are responsible for:
- Ensuring you have a valid legal basis for collecting signers' personal data (typically contractual necessity or legitimate interest for employment and commercial contracts)
- Providing signers with the privacy disclosures required by GDPR Article 13 or 14
- Responding to data subject rights requests (access, erasure, portability) for data you hold
- Ensuring the document content you send through WoltSign does not contain personal data you are not authorized to process
WoltSign will support your data subject rights requests to the extent they involve data held by WoltSign, as described in the DPA.
Common GDPR questions
- Is WoltSign GDPR compliant?
- WoltSign is designed to support GDPR obligations for customers who process personal data through document signing workflows. GDPR compliance is not a binary status for any tool. It describes a set of practices. WoltSign provides a Data Processing Agreement, processes data only as instructed by the customer, and offers standard contractual clauses. Whether your specific use of WoltSign satisfies your organization's GDPR obligations is a determination your data protection officer or legal team must make.
- Where does WoltSign store my data?
- Personal data may be processed and stored in countries outside your country of residence or outside the European Economic Area. WoltSign uses secure cloud infrastructure providers as sub-processors. The Data Processing Agreement describes international transfer safeguards and lists current sub-processors. For specific data residency requirements, review the DPA and contact WoltSign before deployment.
- Can I get a signed Data Processing Agreement from WoltSign?
- Yes. WoltSign's DPA is available at DPA. If you need a countersigned copy for your records, contact WoltSign's support team at support@woltsign.com. Enterprise plan customers receive DPA execution as part of their onboarding.
- What happens to signing data if I cancel my WoltSign account?
- Upon termination of the Services, customer data is deleted or made inaccessible within a reasonable period, subject to applicable legal retention obligations. Residual copies in secure backups may persist for a limited period before permanent deletion, as described in Section 11 of the Data Processing Agreement.
Next steps
Ready to evaluate WoltSign for your team?
Review the Data Processing Agreement, explore security controls, or start a trial. Enterprise customers can request a countersigned DPA during onboarding.