GDPR

WoltSign and GDPR: How We Handle Personal Data in E-Signature Workflows

When your customers or employees sign a document through WoltSign, that signing session processes personal data. Here is what WoltSign does with that data, what protections are in place, and where your organization's responsibilities begin. WoltSign is designed to support your GDPR obligations as a data controller.

Your role

WoltSign as a data processor under GDPR

Under GDPR, the organization that determines the purposes and means of processing personal data is the data controller. WoltSign is a data processor. It processes personal data (signer names, email addresses, IP addresses, and document content) on behalf of the data controller (your organization) according to your instructions and the terms of a Data Processing Agreement.

WoltSign does not use the personal data it processes through signing workflows for its own purposes beyond operating the service. Personal data may be processed and stored outside your country of residence, including outside the European Economic Area, as described in our Data Processing Agreement. Data is encrypted in transit using TLS and at rest using AES-256.

Controls

Data protection controls in WoltSign

Specific technical and organizational measures described in our security documentation and Data Processing Agreement.

ControlStatus
Data in transit encryptionTLS between your browser and WoltSign
Data at rest encryptionAES-256 for documents, signatures, and metadata
Storage and transfersMay include processing outside the EEA; transfer safeguards described in the DPA
Data Processing AgreementAvailable at DPA
Sub-processorsListed in the DPA, including cloud infrastructure and email delivery
Access controlsRole-based access controls with multi-factor authentication support
Audit loggingSigning events, document actions, and authentication attempts are logged
Data deletion on account cancellationCustomer data deleted or made inaccessible within a reasonable period after termination, subject to legal retention obligations (see DPA Section 11)
Data subject access requestsWoltSign provides reasonable technical assistance to the controller, as described in the DPA
Agreement

Data Processing Agreement

WoltSign offers a Data Processing Agreement (DPA) to all customers. The DPA describes WoltSign's obligations as a data processor under GDPR Article 28, including sub-processor disclosure, security measures, and data subject rights support.

Download or review the WoltSign DPA at DPA. If you need a countersigned DPA for your records, contact WoltSign at support@woltsign.com.

Shared responsibility

What your organization is responsible for

WoltSign is a tool in your GDPR compliance program. It is not the entire program.

WoltSign does not determine what personal data your organization collects, how long you retain it, or whether you have a valid legal basis for processing it. Your organization is the data controller for the signing data you collect through WoltSign. You are responsible for:

  • Ensuring you have a valid legal basis for collecting signers' personal data (typically contractual necessity or legitimate interest for employment and commercial contracts)
  • Providing signers with the privacy disclosures required by GDPR Article 13 or 14
  • Responding to data subject rights requests (access, erasure, portability) for data you hold
  • Ensuring the document content you send through WoltSign does not contain personal data you are not authorized to process

WoltSign will support your data subject rights requests to the extent they involve data held by WoltSign, as described in the DPA.

FAQ

Common GDPR questions

Is WoltSign GDPR compliant?
WoltSign is designed to support GDPR obligations for customers who process personal data through document signing workflows. GDPR compliance is not a binary status for any tool. It describes a set of practices. WoltSign provides a Data Processing Agreement, processes data only as instructed by the customer, and offers standard contractual clauses. Whether your specific use of WoltSign satisfies your organization's GDPR obligations is a determination your data protection officer or legal team must make.
Where does WoltSign store my data?
Personal data may be processed and stored in countries outside your country of residence or outside the European Economic Area. WoltSign uses secure cloud infrastructure providers as sub-processors. The Data Processing Agreement describes international transfer safeguards and lists current sub-processors. For specific data residency requirements, review the DPA and contact WoltSign before deployment.
Can I get a signed Data Processing Agreement from WoltSign?
Yes. WoltSign's DPA is available at DPA. If you need a countersigned copy for your records, contact WoltSign's support team at support@woltsign.com. Enterprise plan customers receive DPA execution as part of their onboarding.
What happens to signing data if I cancel my WoltSign account?
Upon termination of the Services, customer data is deleted or made inaccessible within a reasonable period, subject to applicable legal retention obligations. Residual copies in secure backups may persist for a limited period before permanent deletion, as described in Section 11 of the Data Processing Agreement.

Next steps

Ready to evaluate WoltSign for your team?

Review the Data Processing Agreement, explore security controls, or start a trial. Enterprise customers can request a countersigned DPA during onboarding.