Data Processing Addendum
Last Updated: June 23, 2026
1. Introduction
This Data Processing Addendum ("DPA") forms part of the agreement between WoltSign, operated by Devkrest Technologies Private Limited("WoltSign", "we", "us", or "Processor"), and the customer using WoltSign's Services ("Customer" or "Controller").
This DPA applies where WoltSign processes personal data on behalf of the Customer in connection with the provision of the Services described in the Terms of Service.
By using the Services, the Customer agrees to the terms of this DPA. This DPA is incorporated into and subject to the Terms of Service.
2. Definitions
For the purposes of this DPA:
- Controller means the Customer who determines the purposes and means of processing personal data.
- Processor means WoltSign, which processes personal data on behalf of the Controller.
- Data Subject means the individual to whom the personal data relates.
- Personal Data means any information relating to an identified or identifiable natural person.
- Processing means any operation performed on personal data, including collection, storage, use, disclosure, or deletion.
- Sub-processor means any third party engaged by WoltSign to process personal data in connection with the Services.
- Data Protection Laws means all applicable laws and regulations relating to the processing of personal data, including GDPR and equivalent national or regional legislation where applicable.
3. Scope and Purpose of Processing
WoltSign processes personal data solely for the purpose of providing the Services to the Customer, as described in the Terms of Service.
The categories of personal data processed may include:
- Names and email addresses of account holders and document signers
- Document content uploaded by the Customer
- Signature and authentication records
- IP addresses and device information associated with signing events
- Audit trail records
WoltSign does not process personal data for any purpose other than fulfilling its obligations under the Terms of Service and this DPA, unless required by law.
4. Customer Obligations
The Customer, as Controller, represents and warrants that:
- It has a lawful basis for processing personal data and for engaging WoltSign as a processor.
- It has provided all required notices and obtained all necessary consents from data subjects.
- Its instructions to WoltSign for processing personal data comply with applicable Data Protection Laws.
- It is responsible for the accuracy, quality, and legality of the personal data it submits to the Services.
5. WoltSign Obligations
WoltSign, as Processor, agrees to:
- Process personal data only on documented instructions from the Customer, unless required to do so by applicable law.
- Ensure that personnel authorized to process personal data are bound by appropriate confidentiality obligations.
- Implement appropriate technical and organizational security measures as described in Section 7.
- Assist the Customer in responding to data subject rights requests, to the extent reasonably practicable.
- Notify the Customer of any personal data breach without undue delay, as described in Section 9.
- Delete or return personal data to the Customer upon termination of the Services, subject to applicable legal retention requirements.
- Provide reasonable assistance to the Customer in meeting its obligations under Data Protection Laws.
6. Sub-processors
The Customer authorizes WoltSign to engage sub-processors to assist in providing the Services. WoltSign will ensure that sub-processors are bound by data protection obligations equivalent to those in this DPA.
Current sub-processors used by WoltSign may include:
- Cloud infrastructure providers — for hosting and storing data
- DodoPayments — for payment and subscription processing (Privacy Policy)
- Razorpay — for payment and subscription processing (Privacy Policy)
- Email delivery providers — for transactional notifications
- Security and monitoring providers — for platform integrity
WoltSign will notify the Customer of any intended changes to sub-processors and provide the Customer an opportunity to object where required by applicable law.
7. Security Measures
WoltSign implements appropriate technical and organizational measures to protect personal data against unauthorized access, loss, alteration, or disclosure. These measures include:
- Encryption of personal data in transit using TLS
- Encryption of personal data at rest
- Access controls and role-based permissions
- Audit logging and monitoring
- Secure authentication mechanisms
- Regular security assessments
No security measure can guarantee absolute protection. WoltSign will review and update its security practices as appropriate.
8. Data Subject Rights
The Customer is responsible for handling data subject rights requests (such as access, rectification, erasure, and portability) in relation to personal data processed through the Services.
WoltSign will provide reasonable technical assistance to the Customer in fulfilling such requests, to the extent the data is accessible within the platform.
Data subjects wishing to exercise their rights should contact the Customer directly.
9. Personal Data Breach Notification
In the event of a personal data breach affecting Customer data, WoltSign will:
- Notify the Customer without undue delay after becoming aware of the breach.
- Provide available information about the nature of the breach, categories of data affected, and measures taken or proposed.
- Cooperate with the Customer in its investigation and remediation of the breach.
The Customer is responsible for determining whether a breach must be reported to relevant supervisory authorities or data subjects.
10. International Data Transfers
Personal data may be processed and stored in countries outside the Customer's country of residence or outside the European Economic Area.
Where such transfers occur, WoltSign will take appropriate steps to ensure an adequate level of protection for the transferred personal data, consistent with applicable Data Protection Laws.
11. Data Retention and Deletion
WoltSign retains personal data for as long as necessary to provide the Services and as required by applicable law.
Upon termination of the Services:
- Customer data will be deleted or made inaccessible within a reasonable period, subject to legal retention obligations.
- Residual copies in secure backups may persist for a limited period before permanent deletion.
12. Audit Rights
The Customer may request reasonable information from WoltSign to demonstrate compliance with this DPA, subject to confidentiality constraints.
WoltSign may satisfy such requests by providing relevant certifications, security documentation, or summary reports in lieu of full on-site audits.
13. Term and Termination
This DPA remains in effect for as long as WoltSign processes personal data on behalf of the Customer.
This DPA terminates automatically upon expiry or termination of the Terms of Service, subject to any surviving obligations regarding data deletion and confidentiality.
14. Governing Law
This DPA shall be governed by the same laws applicable to the Terms of Service, without regard to conflict of law principles.
15. Related Resources
- How WoltSign supports GDPR for data processing roles, controls, and shared responsibilities
- How WoltSign supports India DPDP for Data Fiduciary and Data Processor roles under the DPDP Act
- Security — Encryption, access controls, and audit logging
16. Contact Information
For questions relating to this DPA or data processing practices, please contact:
WoltSign
Operated by Devkrest Technologies Private Limited
OFFICE, E-208 Ganesh Glory 11, Jagatpur Rd,
Sarkhej - Gandhinagar Hwy, near BSNL, Jagatpur,
Ahmedabad, Gujarat 382470, India
Email: support@woltsign.com