Data Processing Addendum
For organisations that use DocuGrip for work. It is part of our terms from the moment your organisation uses the service — there is nothing to request and nothing to negotiate. If your procurement process needs a signed copy, write to privacy@docugrip.com and we will countersign it within two business days.
Last updated
Who is who
The organisation that uses DocuGrip (“you”) is the controller of the personal data described below. Simulator Arts LLC, which operates DocuGrip (“we”), processes it on your behalf as your processor — or as your sub-processor where you are yourself acting for a client.
Paid plans are sold by Stripe as merchant of record. Stripe handles payment details as an independent controller under its own terms; it is not our sub-processor for that data, and we never see card numbers.
What this covers, and what it does not
Documents opened with the tools are processed without being transmitted. They never reach us, so there is nothing of theirs for us to process and they fall outside this addendum.
It covers the personal data that does reach us when your people use DocuGrip:
Account data — email address, a name if one is given, the identity returned by the sign-in provider, team membership and role, plan and usage counters.
Signature requests — the document sent for signature, stored encrypted, and the names, email addresses, times and activity record of the people invited to sign.
Messages — what your people write to us through the contact and solutions forms or by email.
Our commitments
We process this data only on your documented instructions. This addendum, the terms and the way you configure and use the product are those instructions, and we will tell you if we believe an instruction breaks the law.
Everyone with access to it is bound by confidentiality. We do not sell or share it, and we do not use it for advertising, for profiling or to train AI models. We do not combine it with data from other sources except where the service needs it to work.
Sub-processors
We use a small number of providers, each for one job: hosting and delivery; database, sign-in and encrypted storage; and email delivery. Each is bound by written terms that protect the data at least as well as this addendum. The current list, with names, is available at privacy@docugrip.com.
Before adding or replacing a sub-processor we email team owners at least 14 days in advance. If you object on reasonable data protection grounds and we cannot resolve it, you can end the affected service and we refund the unused, prepaid part.
International transfers
The service and its sub-processors operate from the United States.
For personal data from the European Economic Area, the Standard Contractual Clauses adopted by Commission Decision (EU) 2021/914 are incorporated by reference: Module 2, or Module 3 where you are a processor, with you as data exporter and us as data importer. Clause 7 applies; under Clause 9 option 2 applies with the 14-day notice above; the optional wording in Clause 11 does not apply; Clauses 17 and 18 choose the law and courts of Ireland. Annex I and Annex II of the Clauses are completed by the two sections at the end of this page.
For the United Kingdom, the International Data Transfer Addendum issued by the Information Commissioner applies alongside the Clauses. For Switzerland, the Clauses apply with the adjustments the Federal Act on Data Protection requires.
Helping you meet your own obligations
If one of your people asks to see, correct, export or delete their data, most of it can be handled from the account itself. Where it cannot, send the request to privacy@docugrip.com and we will act on it within ten business days. If a request reaches us directly, we pass it to you rather than answer it ourselves.
For a data protection impact assessment or a question from a supervisory authority, we give you the information we reasonably can about how the service processes the data.
If something goes wrong
If we become aware of a personal data breach affecting your data, we notify you without undue delay and in any case within 48 hours, with what we know at that point: what happened, what data and roughly how many people are involved, what we have done and what we recommend. We follow up as we learn more.
When the service ends
When your organisation stops using DocuGrip, or asks us to, we delete the account data within 30 days. If you want an export first, ask before the account is closed.
Signature request documents are deleted 30 days after the request is completed, declined or expires, whatever else happens. We keep only what the law requires us to keep, such as billing records, and only for as long as it requires.
Audits and security questionnaires
This page, the security page and our written answers to your security questionnaire are how we show compliance. We answer a questionnaire within ten business days.
If that is not enough, you may audit once a year, on 30 days’ written notice, at your own cost and within a scope we agree in advance, in a way that does not expose other customers’ data. We do not hold a third-party certification such as SOC 2 or ISO 27001 yet, and we will not suggest that we do.
US state privacy laws
Where the California Consumer Privacy Act or a similar state law applies, we act as your service provider or contractor. We do not sell or share the personal data, we retain, use and disclose it only for the business purpose of providing DocuGrip to you, we do not combine it with other data except as those laws allow, and we tell you if we can no longer meet these obligations.
Liability and order of precedence
Each side’s liability under this addendum is subject to the limits in the terms. If this addendum and the terms conflict on data protection, this addendum wins; if the Standard Contractual Clauses conflict with either, the Clauses win.
Details of the processing
Subject matter and duration: providing DocuGrip to you, for as long as your organisation uses it and until the data is deleted as described above.
Nature and purpose: storing accounts and plans, sending sign-in, billing and signature request emails, holding encrypted documents while a signature request is open, and answering messages.
People concerned: your staff and other users you give access to, the people you invite to sign, and people who contact us on your behalf.
Data concerned: the account data, signature request data and messages described above. No special category data is needed for any of it. If you choose to send a document containing such data for signature, it is protected by the same encryption as every other document.
Security measures
Documents opened with the tools are processed without transmission, and the site’s content security policy restricts every page to a short, published list of addresses.
Every connection is encrypted in transit.
A document sent for signature is encrypted before it is stored. The key travels only inside the signing links and is not stored with the document.
Sign-in uses one-time codes or an established identity provider, so we hold no passwords. Sessions live in secure, host-only cookies; provider sign-in uses PKCE; sign-in forms are protected against automated abuse and every sensitive endpoint is rate limited.
Production access is limited to the people who run the service, and credentials are held in managed secret storage, never in source code.
Document contents and file names are never written to logs, and there are no advertising or tracking cookies.
The service is checked automatically every day, and security reports are welcome through the security page.
Contact
For anything about this addendum, a countersigned copy, the sub-processor list or a security questionnaire, write to privacy@docugrip.com. A person replies within one business day.