This DPA forms part of the Agreement entered into between SIS and you (the “Customer”) on the Effective Date (as defined in the Agreement). "SIS" means the entity with whom you entered into the Agreement and all references to the Agreement shall include this DPA (including the Standard Contractual Clauses, as defined below).
All capitalized terms not defined in this DPA shall have the meanings set forth in the Agreement. This DPA applies where, and only to the extent that, SIS processes your Personal Data that is protected by Applicable Privacy Laws and regulations applicable to the processing of Personal Data under this DPA. Signatures of assent of SIS and Customer to the Agreement will be deemed signature to, and acceptance and agreement of, this DPA and the Standard Contractual Clauses incorporated hereto.
| “Agreement” | means the written or electronic agreement between the Customer and SIS for the provision of Products by SIS to the Customer. |
| “Affiliates” | means, in respect of SIS, those entities which own or control, are owned or controlled by, or are under common ownership or control with SIS, as further https://signinapp.com/terms/affiliated-companies/ |
| “Applicable Privacy Laws” | means any data privacy, security or protection laws or regulations to the extent applicable to the processing of Personal Data under this DPA, including any binding laws or regulations ratifying, implementing, adopting, supplementing or replacing the foregoing; in each case, to the extent in force, and as such are updated, amended or replaced from time to time. |
| “Authorized Personnel” | means an individual (including without limitation an employee, temporary worker or agency worker) who is authorized to process Personal Data under the authority of SIS. |
| “Customer Personal Data” | means any personal data that SIS processes on behalf of the Customer as a processor pursuant to the Agreement, and as more particularly described in this DPA. |
| “Data Subject Request” | means a request from a Data Subject to exercise their data subject rights with respect to the Personal Data, as granted by Applicable Privacy Laws. |
| “Instructions” | means Customer’s written instructions to SIS directing SIS to process the Personal Data as provided under the Agreement, this DPA, through Customer’s use of the features and functionality of the Products provided by SIS pursuant to the Agreement or as otherwise mutually agreed by authorized signatories of both parties in writing. |
| “Personal Data Breach” | means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, Personal Data in SIS’s possession or under its control (including when transmitted or stored by SIS). |
| “Products” | means the products purchased by Customer under the Agreement. |
| “Sensitive Data” | means (a) social number, passport number, driver’s license number, or similar identifier; (b) payment card number; (c) employment, financial, genetic, biometric or health information; (d) racial, ethnic, affiliation, union membership, or sexual information; (e) account passwords; or (f) other information that falls within the definition of “special categories of data” under applicable Applicable Privacy Laws. |
| “Standard Contractual Clauses” or (“SCCs” or “Clauses”) | means (i) the standard contractual clauses for international transfers published by the European Commission on June 4, 2021 governing the transfer of European Area Personal Data to Third Countries as adopted by the European Commission and the Swiss Federal Data Protection and Information Commissioner (“Swiss FDPIC”) relating to data transfers to Third Countries (collectively “EU SCCs”); (ii) the international data transfer addendum (“UK Transfer Addendum”) adopted by the UK Information Commissioner’s Office (“UK ICO”) for data transfers from the UK to Third Countries; or (iii) any similar such clauses by a data protection regulator relating to data transfers to Third Countries; or (iv) any successor clauses to (i) – (iii). |
| “Sub-processor” | means any person or entity, including SIS’s Affiliates, appointed by or on behalf of SIS in connection with the processing of Personal Data in connection with the Agreement. |
| “Third Country” | means countries that, where so regulated by Applicable Privacy Laws, have not received an adequacy decision from an applicable authority relating to data transfers, including regulators such as the European Commission, UK ICO, or Swiss FDPIC. |
|
In this DPA, the following terms (and any substantially similar terms as defined under Applicable Privacy Laws) shall have the meanings and otherwise be interpreted in accordance with Applicable Privacy Law: “Business”, “Data Controller”, “Data Processor”, “Data Subject”, “Sale”, “Service Provider”, “Share”, “Supervisory Authority”, “Process(ing)” and “Transfer”. |
|
Processing of data
Data Exporter:
Name, address and contact information:
As provided under the Agreement.
Activities relevant to the data transferred under the Clauses:
Receipt of the Products under the Agreement.
Signature and date:
As provided under the Agreement.
Data Importer:
Name:
Sign In Solutions Inc.
Address:
150 2nd Ave N, Suite 1540 St. Petersburg FL, USA 33701
Contact information for privacy and data protection:
Jason Mordeno: Global Privacy Officer
privacy@signinsolutions.com
Activities relevant to the data transferred under the Clauses:
The provision, maintenance and securing of the Products
Signature and date:
As provided under the Agreement.
SIS shall:
Provide an appropriate level of technical and organizational measures, including relevant security and compliance controls aligned to the categories or nature of Customer Data, as necessary to protect against potential harm resulting from a data breach, including, but not limited to:
a. Governance, Risk and Compliance Controls
• Governance - SIS maintains a governance, risk and compliance program, that is a set of processes, policies and procedures in order to operate in accordance with relevant laws, regulations and industry standards;
• Risk - SIS manages risk frameworks that identify and manage risks to technology and data processing systems;
• Compliance - SIS maintains security and compliance processes and conducts audits that examines our controls with management and the safeguarding of customer data;
b. Infrastructure Security Controls
• Monitoring - SIS maintains security monitoring systems, including, but not limited to, detecting and preventing intrusion, monitoring traffic and monitoring file integrity;
• Authentication - SIS maintains effective authentication processes that are maintained to protect Customer Data (e.g., multi factor authentication for privileged access or restricted information);
• Vulnerability Management - SIS has a defined policy and process that establishes requirements for assessing and managing vulnerabilities;
c. Network Security Controls
• Access Points - SIS maintains the authentication and and supervision of access rights with access to the network and by applying technical policies to prevent any internal and external threats posed by the access;
• Network Management of Roles and Responsibilities - defines authorized groups, roles and responsibilities for management of network components;
• System and Security Events/Firewalls - SIS automatically logs system and security events, reviews logs on a periodic basis, issues identified are investigated and resolved in a timely manner;
d. Data Security Controls
• Technical and Organizational Policies - SIS has processes in place for the classification, management, access, use, destruction of data;
• Encryption - SIS encrypts data in transmit, in transit, at rest and in storage by utilizing industry standard encryption tools;
• Encryption Keys - SIS safeguards the security and confidentiality of all encryption keys associated with encrypted Customer Data;
• Role Based Access Controls - SIS practices the method of least privilege which limits user access to authorized individuals;
• Scheduled Backups - SIS backs up Customer Data on a regular basis as required by the Customer and ensuring that any back up data is subject to appropriate Security Measures as necessary to protect the confidentiality, integrity and availability of Customer Data;
The parties agree that personal data transferred between and by the parties to Third Countries shall be subject to the Standard Contractual Clauses to the extent applicable and as further set forth under the DPA.
A. The parties acknowledge the importance of the protection of personal data and the legal restrictions on international transfers of such data to Third Countries.
B. Accordingly, the parties agree to abide by the GDPR, UK DPA 2018, and Swiss DPA, and other Applicable Privacy Laws recognizing the Standard Contractual Clauses or similar principles, as applicable, and enter into these standard contractual clauses to ensure that transfers of personal data to Third Countries are lawful and subject to adequate data protections. To the extent a transfer of personal data is subject to Article 3(2) of the GDPR, this Annex C shall not apply.
With respect to Processing of applicable personal data:
By entering into the DPA, the Parties are deemed to be signing the applicable Standard Contractual Clauses.
Last updated: 1 February, 2026
Jason Mordeno, Global Privacy and Data Protection Officer