This DPA forms part of the Agreement entered into between Sign In Solutions (“Sign In Solutions” or “SIS”) and you (the “Customer”) on the Effective Date (as defined in the Agreement). "Sign In Solutions" means the entity with whom you entered into the Agreement and “we” or “us” means Sign In Solutions, and all references to the Agreement shall include this DPA (including the Standard Contractual Clauses, as defined below).
All capitalized terms not defined in this DPA shall have the meanings set forth in the Agreement. This DPA applies where, and only to the extent that, SIS processes your Personal Data that is protected by Applicable Privacy Laws and regulations applicable to the processing of Personal Data under this DPA. Signatures of assent of SIS and Customer to the Agreement will be deemed signature to, and acceptance and agreement of, this DPA and the Standard Contractual Clauses incorporated hereto.
| “Agreement” | means the written or electronic agreement between the Customer and SIS for the provision of Products by SIS to the Customer. |
| “Affiliates” | means, in respect of SIS, those entities which own or control, are owned or controlled by, or are under common ownership or control with SIS, as further set out in Annex D. |
| “Applicable Privacy Laws” | includes all laws, regulations and other legal requirements applicable to Customer or SIS. This may include, for example, the General Data Protection Regulation (Regulation (EU) 2016/679) (“GDPR”); equivalent requirements in the United Kingdom including the UK General Data Protection Regulation and the Data Protection Act 2018 (“UK GDPR”); the California Consumer Privacy Act and associated regulations (“CCPA”), and the California Privacy Rights Act and its implementing related regulations when effective (“CPRA”); the Personal Information Protection and Electronic Documents Act, SC 2000, c.5 (“PIPEDA”); Australia’s Privacy Act 1988 and the Australian Privacy Principles (the “Privacy Act”); the Virginia Consumer Data Protection Act when effective (“VCDPA”); the Utah Consumer Privacy Act when effective (“UCPA”), and the Colorado Privacy Act and related regulations when effective (“CPA”). |
| “Authorized Personnel” | means an individual (including without limitation an employee, temporary worker or agency worker) who is authorized to process Personal Data under the authority of SIS. |
| “Customer Personal Data” | means any personal data that SIS processes on behalf of the Customer as a processor pursuant to the Agreement, and as more particularly described in this DPA. |
| “Data Subject Request” | means a request from a Data Subject to exercise their data subject rights with respect to the Personal Data, as granted by Applicable Privacy Laws. |
| “Instructions” | means Customer’s written instructions to SIS directing SIS to process the Personal Data as provided under the Agreement, this DPA, through Customer’s use of the features and functionality of the Products provided by SIS pursuant to the Agreement or as otherwise mutually agreed by authorized signatories of both parties in writing. |
| “Personal Data Breach” | means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, Personal Data in SIS’s possession or under its control (including when transmitted or stored by SIS). |
| “Products” | means the products purchased by Customer under the Agreement. |
| “Sensitive Data” | means (a) social number, passport number, driver’s license number, or similar identifier; (b) payment card number; (c) employment, financial, genetic, biometric or health information; (d) racial, ethnic, affiliation, union membership, or sexual information; (e) account passwords; or (f) other information that falls within the definition of “special categories of data” under applicable Applicable Privacy Laws. |
| “Standard Contractual Clauses” or (“SCCs” or “Clauses”) | means (i) the standard contractual clauses for international transfers published by the European Commission on June 4, 2021 governing the transfer of European Area Personal Data to Third Countries as adopted by the European Commission and the Swiss Federal Data Protection and Information Commissioner (“Swiss FDPIC”) relating to data transfers to Third Countries (collectively “EU SCCs”); (ii) the international data transfer addendum (“UK Transfer Addendum”) adopted by the UK Information Commissioner’s Office (“UK ICO”) for data transfers from the UK to Third Countries; or (iii) any similar such clauses by a data protection regulator relating to data transfers to Third Countries; or (iv) any successor clauses to (i) – (iii). |
| “Sub-processor” | means any person or entity, including SIS’s Affiliates, appointed by or on behalf of SIS in connection with the processing of Personal Data in connection with the Agreement. |
| “Third Country” | means countries that, where so regulated by Applicable Privacy Laws, have not received an adequacy decision from an applicable authority relating to data transfers, including regulators such as the European Commission, UK ICO, or Swiss FDPIC. |
|
In this DPA, the following terms (and any substantially similar terms as defined under Applicable Privacy Laws) shall have the meanings and otherwise be interpreted in accordance with Applicable Privacy Law: “Business”, “Data Controller”, “Data Processor”, “Data Subject”, “Sale”, “Service Provider”, “Share”, “Supervisory Authority”, “Process(ing)” and “Transfer”. |
|
Processing of data
Data Exporter:
Name, address and contact information:
As provided under the Agreement.
Activities relevant to the data transferred under the Clauses:
Receipt of the Products under the Agreement.
Signature and date:
As provided under the Agreement.
Data Importer:
Name:
Sign In Solutions Inc.
Address:
150 2nd Ave N, Suite 1540 St. Petersburg FL, USA 33701
Contact information for privacy and data protection:
Jason Mordeno: Global Privacy Officer
privacy@signinsolutions.com
Activities relevant to the data transferred under the Clauses:
The provision, maintenance and securing of the Products
Signature and date:
As provided under the Agreement.
SIS shall:
Provide an appropriate level of technical and organizational measures, including relevant security and compliance controls aligned to the categories or nature of Customer Data, as necessary to protect against potential harm resulting from a data breach, including, but not limited to:
1. Governance, Risk and Compliance Controls
|
Sign In Solutions Products: Enterprise Visitor Management; Compliance; Workspace |
SOC2 Type II (C.4: Privacy, Security, Availability, Confidentiality) Attestation Report SOC2 Type II: US CCPA + EU GDPR Attestation Report ISO27001 ISMS Accredited Certification |
|
Sign In App Products: App Visitor Management and SwipedOn |
SOC2 Type II (C.1: Security only) Attestation Report ISO27001 ISMS Accredited Certification |
|
Sign In App Sub-Products: Scheduling; Central Record |
ISO27001 ISMS Accredited Certification |
2. Data Security Controls
3. Cybersecurity Controls
4. Infrastructure Security Controls
5. Application Security Controls
6. Network Security Controls
The parties agree that personal data transferred between and by the parties to Third Countries shall be subject to the Standard Contractual Clauses to the extent applicable and as further set forth under the DPA.
By entering into the DPA, the Parties are deemed to be signing the applicable Standard Contractual Clauses.
| Sign In App Ltd, a company incorporated pursuant to the laws of England, having a registered address at 4 Waterside Way, Northampton, England, NN4 7XD with company registration number: 08516772 |
| Sign In App SL, a company incorporated pursuant to the laws of Spain, having a registered address at PS De La Castellana 40, 8 28046 Madrid, Spain with NIF: B02651354 |
| Sign In App Inc., a company incorporated in Delaware having a registered address 16192 Coastal Highway, Lewes, Delaware 19958-9776 |
| Sign In Solutions Inc., a company incorporated in Delaware having an office address at 150 2nd ave N, ste 1540 St. Petersburg FL 33701 |
| Sign In Enterprise Inc., a company incorporated pursuant to the laws of British Columbia, having an office address at 150 2nd ave N, ste 1540 St. Petersburg FL 33701 and its wholly owned Subsidiary Traction Guest Corp. |
| Sign In Compliance Inc., a company incorporated in Delaware having an office address at 150 2nd ave N, ste 1540 St. Petersburg FL 33701 |
| Sign In Workspace ApS, a company incorporated pursuant to the laws of Denmark having an office address at Firskovvej 18a, 2800 Lyngby, Denmark |
| SwipedOn Ltd, a company incorporated pursuant to the laws of New Zealand, having a registered address at 1/115 The Strand, Tauranga 3110, New Zealand with company registration number: 655878. |
This GDPR and UK GDPR Addendum (this “GDPR and UK Addendum”) supplements the DPA or Agreement between the Parties governing the processing of Personal Data. This GDPR and UK Addendum applies when the GDPR or UK GDPR applies to SIS’s Software and Services interaction with applicable Personal Data. Unless otherwise defined in this GDPR and UK Addendum, all capitalized terms are defined by the DPA or Agreement.
These SIS CCPA Terms (“CCPA Terms”) supplements the DPA and other Agreement between the Parties when the California Consumer Privacy Act of 2018 (“CCPA”) or California Privacy Rights Act of 2020 (“CPRA”) applies to access, use or otherwise processing of “Personal Information” (as defined and applied in CCPA or CPRA) by the parties. Unless otherwise defined in these CCPA Terms, all capitalized terms are defined by the DPA or Agreement.
The parties each agree and certify, with respect to any Personal Information it receives from the other party under circumstances where the receiving party is acting as a Service Provider, and not already in such receiving party’s possession, that it will operate as a Service Provider and will not: (a) retain, use, or disclose Personal Information except as permitted in an agreement between the parties and under CCPA or CPRA, or (b) sell or share Personal Information.
These CCPA Terms do not limit or reduce any other data privacy commitments either party may have under an agreement between the parties.
Last updated: August 23, 2025.
Jason Mordeno, Global Privacy and Data Protection Officer