[Go to site: main page, start]

Data Processing Agreement

Updated: May 2026

1. Scope

1.1.

This Data Processing Agreement (the "DPA") forms part of the agreement for the purchase, use and/or licensing of products or services provided by Verciltech LTD, a company incorporated and existing under the laws of Cyprus with registered office at Everest 13, Office 202, Limassol, Cyprus (the “Company”), offered through the website https://pdfgate.com (the "Services"), together with its exhibits, or other incorporated or referenced documents and any other agreement(s) governed by such agreement(s) (the"Agreement"), between the Company and the customer that has executed or agreed to such agreement(s) (the "Customer"). The Customer and the Company will be jointly referred to as the “Parties” and individually as the “Party”.

1.2.

In the course of providing the Services to the Customer under the Agreement, the Company may Process Personal Data on behalf of the Customer in which case the Parties agree to comply with the provisions of this DPA. The provisions of this DPA shall only apply to the extent that the Company (as the Processor) Processes Personal Data on behalf of the Customer (as the Controller) under the Agreement.

1.3.

In case of conflict between any provision of this DPA and any provision or another part of the Agreement, this DPA shall prevail.

1.4.

The DPA is entered into for the term of the Agreement and remains in full force until the Processing of Personal Data is no longer required in the framework or pursuant to the Agreement or longer if required by the applicable law or the Data Protection Legislation.

1.5.

If the Customer has any questions regarding the Processing of Personal Data by the Company, the Customer may send such questions to [email protected].

2. Definitions

2.1.

For the purpose of this DPA, the following terms shall have the following meaning, or as defined throughout this DPA. In case of any doubt or differences with the terms defined in the Data Protection Legislation, the definitions stipulated in the relevant Data Protection Legislation shall prevail.

“Controller” means the natural or legal person, public authority, agency or any other body which, alone or jointly with others, determines the purposes and means of the Processing of Personal Data carried out under its authority, for the purposes of the DPA, being the Customer.

“Data Protection Legislation” means the GDPR together with any other data protection laws resulting from the GDPR and/or all other applicable laws of any country with regard to the protection of Personal Data or privacy.

“Data Subject” means an identified or identifiable natural person to whom the Personal Data relates. An identifiable person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that person. The relevant categories of Data Subjects are identified in this DPA.

“GDPR” means the Regulation 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data.

“Personal Data” means any information relating to a Data Subject within the meaning of Article 4. 1) GDPR. The relevant categories of Personal Data that are provided to the Company by, or on behalf of the Customer, are identified in this DPA.

“Personal Data Breach” means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, Personal Data transmitted, stored or otherwise Processed in connection with the Agreement and the provision of the Services.

“Processing”, “Process(es)” or “Processed” means any operation or set of operation which is performed upon Personal Data or on sets of Personal Data, whether or not by automatic means, such as collection, recording, organization, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction.

“Processor” means a natural or legal person, public authority, agency or any other body which is authorised to process Personal Data on behalf of the Customer, being the Company.

“Security Measures” means the technical and organizational measures within the meaning of Article 32 GDPR aiming at protecting Personal Data against accidental or unlawful destruction or loss, as well as against non-authorised access, alteration or transmission.

“Sub-processor” means any Processor engaged as a sub-processor or subcontractor by the Company and processes Personal Data for, on behalf of and in accordance with the instructions of the Company.

“Supervisory Authority” means an independent public authority which is established by a Member State pursuant to Article 51 GDPR.

“Third Party” means any party who is not a Data Subject, Controller, Processor or Sub-processor under this DPA or a person who is authorised to process Personal Data under the direct authority of the Customer or the Company.

2.2.

Any other terms used in this DPA but not defined will have the same meaning as in the Data Protection Legislation or the Agreement.

3. Details of the Processing

3.1.

Subject-nature: the Processing of Personal Data by the Company as Processor on behalf of Customer as Controller relates to the performance of the Services as described in the Agreement and/or as further specified in the Services-related documentation (if any), and/or as further instructed by the Customer in its use of the Services of the Company.

3.2.

Means of the Processing: systems, software, products, Services, tools and/or servers of the Company.

3.3.

Categories of Personal Data: The Personal Data that will be processed will depend upon the Customer’s use of the Services. To the extent the Customer’s documents, files, inputs, or outputs used with the Services contain Personal Data, it may consist of identifying information of end users (such as name, email address, physical address, IP address, or other unique identifier), financial data, identifying information of third parties with whom data is shared, organization data, and any other Personal Data contained in documents, images and other content or data in electronic form stored or transmitted by the end users via the Services. Where the Customer uses digital signature features, Personal Data may also include signer and recipient names, email addresses, signing status, signature timestamps, envelope metadata, and Personal Data contained in signed documents.

3.4.

Categories of Data Subjects: customers and/or prospective customers, end-users (authorized by the Customer to use the Services), partners, employees, agents or other service providers or contractors of the Customer.

3.5.

Purposes of the Processing: to perform the Services as described in the Agreement, including generating, uploading, processing, transforming, storing, delivering and deleting PDF documents and files, creating and sending digital signature envelopes, tracking signing status, storing signed files, and/or to comply with other documented or written reasonable instructions provided by the Customer where such instructions are consistent with the terms of the Agreement.

3.6.

Retention period(s): the Company will Process Personal Data for the term of the Agreement, unless otherwise agreed upon in writing or as required by applicable law and no longer than is necessary for the purposes for which the Personal Data are Processed, unless applicable law requires longer storage of the Personal Data. PDF files created, uploaded, transformed, or otherwise processed through the Services may be stored for up to two (2) years depending on the retention settings configured by the Customer in the dashboard. Signed files and signature template documents are not automatically deleted by the platform and remain stored until the Customer deletes them manually through the dashboard or through the applicable delete endpoint.

3.7.

Sensitive data: If the Processing involves Personal Data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, or trade union membership, genetic data or biometric data for the purpose of uniquely identifying a natural person, data concerning health or a person’s sex life or sexual orientation, or data relating to criminal convictions and offences, the Company shall apply specific restrictions and/or additional safeguards.

4. General

4.1.

The Company processes Personal Data only on behalf of the Customer and in accordance with the documented or written instructions of the Customer. The Agreement, including this DPA, constitutes the Customer’s complete instruction to the Company with regard to the processing of Personal Data. Any additional or alternative instructions must be provided in writing and agreed upon by the Parties.

4.2.

The Company shall only process Personal Data in accordance with the purposes specified in section 3.5 above, unless required to do so by European Union or Member State law to which the Company is subject.

4.3.

The Company shall immediately inform the Customer if, in its opinion, an instruction infringes the GDPR or other Data Protection Legislation.

4.4.

Any processing of Personal Data by the Company under the Agreement shall be performed in accordance with the applicable Data Protection Legislation. The Company, however, is not responsible for compliance with any laws applicable to the Customer or the Customer’s industry. The Customer shall comply with the applicable Data Protection Legislation, as well as any other laws applicable to the Customer or the Customer’s industry. The Customer is solely responsible for the lawfulness of the Personal Data. The Customer represents and warrants that, where it provides any Personal Data to the Company for processing, it has duly informed the relevant Data Subjects of their rights and obligations, and in particular has informed them of the possibility of the Company processing their Personal Data on the Customer’s behalf and in accordance with its instructions. The Customer represents and warrants that the processing of the Personal Data under this DPA is lawful.

4.5.

The Company ensures that Personal Data is only disclosed to personnel or persons acting on behalf of the Company who are authorized to process the Personal Data and who require access to perform the Services and/or tasks under the Agreement. The Company ensures that persons authorized to process the Personal Data and/or its Sub-processors have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality.

5. Transfer of Personal Data

5.1.

The Company agrees to keep all Personal Data and its processing strictly confidential and shall not disclose or reveal it, in whole or in part, directly or indirectly, to any Third Party, unless with the prior written consent of the Customer or as required by law.

5.2.

The Customer agrees to allow transfers of Personal Data outside the country from which it was originally collected, provided that such transfers are required in connection with the provision of the Services under the Agreement and take place in accordance with Data Protection Legislation, including, without limitation, completing any prior assessments required by Data Protection Legislation.

5.3.

Where the Company transfers Personal Data collected in the European Economic Area to a country outside the European Economic Area without an adequacy decision under Article 45 of the GDPR, the Company shall transfer such Personal Data pursuant to the Standard Contractual Clauses approved by the European Commission, provided that the conditions for using the Standard Contractual Clauses are met.

6. Security Measures

6.1.

The Company shall implement and maintain appropriate technical and organizational Security Measures to ensure a level of security appropriate to the risks, in accordance with Article 32 of the GDPR. These measures include, but are not limited to, the use of secure cloud infrastructure provided by Amazon Web Services (AWS), which complies with recognized international security standards and certifications such as ISO 27001 and SOC 2. The Company employs encryption in transit and at rest, access control and authentication mechanisms, regular backups, monitoring, and other safeguards designed to protect Personal Data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure, or access. The Customer may request the Company to provide an updated description of the implemented Security Measures at any time.

7. Sub-processor

7.1.
The Customer acknowledges and agrees that the Company may engage Sub-processors for the provision of the Services under the Agreement and that the Company may transfer Personal Data to these Sub-processors in this context. The current Sub-processors engaged by the Company are:
  • Amazon Web Services (AWS) – Cloud hosting and infrastructure provider offering secure data centers and storage, located within the European Union (or other regions as applicable).
  • MongoDB Atlas – Managed database service hosted on AWS, used for secure data storage and management.
  • Stripe, Inc. – Payment processing services provider, located in the United States (data transfers covered by Standard Contractual Clauses).
  • SendGrid (Twilio Inc.) – Transactional email delivery provider, located in the United States (data transfers covered by Standard Contractual Clauses).
  • DigitalOcean, LLC – Cloud computing and backup services provider, located in the United States and the European Union (data transfers covered by Standard Contractual Clauses).
The Company shall inform the Customer, upon request, about all Sub-processors engaged that process Personal Data under the Agreement.
7.2.

The Company shall inform the Customer of any intended changes concerning the addition or replacement of Sub-processors, thereby providing the Customer with the opportunity to raise any reasonable concerns. The Company will consider such concerns in good faith, but the use of new or replacement Sub-processors shall not be subject to the Customer’s approval.

7.3.

The Company shall ensure that each engaged Sub-processor is bound by written contractual terms or standard Data Processing Agreements provided by the respective Sub-processor, which include data protection obligations no less protective than those contained in this DPA. The Company relies only on reputable Sub-processors that demonstrate compliance with applicable Data Protection Legislation.

7.4.

The Company shall remain fully responsible to the Customer for the performance of the Sub-processor’s obligations in accordance with its contract with the Company. The Company shall notify the Customer of any failure by a Sub-processor to fulfil its contractual obligations.

8. Assistance and information obligations

8.1.

Taking into account the nature of the processing and the information available to the Company, the Company shall assist the Customer (i) through appropriate technical and organizational measures, insofar as this is possible, for the fulfillment of the Customer’s obligation to respond to requests for exercising the Data Subject’s rights laid down in Chapter III of the GDPR, and (ii) in ensuring compliance with the obligations set forth in Articles 32–36 of the GDPR. The Company shall assist the Customer in carrying out Data Protection Impact Assessments in accordance with Article 35 of the GDPR.

8.2.

The Company shall make available to the Customer all information necessary to demonstrate compliance with the GDPR and, in particular, with the obligations laid down in Article 28 of the GDPR.

8.3.

The Company shall be entitled to invoice the Customer on a time-and-material basis at the then-current rates for any time expended in providing assistance under this section 8.

9. Audits

9.1.

The Customer is entitled to reasonably verify the Company’s compliance with this DPA and the applicable Data Protection Legislation, provided that the Company shall have no obligation to provide confidential and/or proprietary information. To this extent, the Customer may, upon written request and with prior notice of thirty (30) calendar days, at its own expense, instruct acknowledged audit professionals to execute such audit or inspection: (i) once every twelve (12) months, provided that such audit inquiries take place during normal office hours, do not unreasonably impact the Company’s regular operations, and are not incompatible with applicable legislation or the instructions of a competent authority; (ii) where a competent data protection authority requires this under Data Protection Legislation; or (iii) following a Personal Data Breach.

9.2.

Before the commencement of any such audit inquiries, the Parties shall mutually agree upon the scope, timing, and duration of the audit, including applicable conditions of confidentiality. During such audit, the Company shall provide reasonable cooperation and assistance to the auditors.

9.3.

The Customer shall promptly notify the Company of any non-compliance discovered during the course of such audit. Audit reports, any other information to which the Customer or the audit professionals have access pursuant to any audit activities, as well as any attestation of the implementation of Security Measures, shall be considered confidential information.

9.4.

The Company shall be entitled to invoice the Customer on a time-and-material basis at the then-current applicable rates for any time expended in connection with such audit inquiries.

10. Personal Data Breaches

10.1.

In the event of a Personal Data Breach, and irrespective of its cause, the Company shall notify the Customer without undue delay after becoming aware of such Personal Data Breach, specifying, where known or readily identifiable: (i) the nature of the Personal Data Breach; (ii) the categories and approximate number of Data Subjects and Personal Data records concerned; (iii) any remedial actions taken or proposed to be taken to address the Personal Data Breach, to mitigate its effects, and to prevent its re-occurrence; and (iv) the identity and contact details of any other contact person from whom more information can be obtained.

10.2.

The Party responsible for the Personal Data Breach shall, without undue delay, further investigate the incident and keep the other Party informed of the progress of the investigation. The responsible Party shall take reasonable steps to minimize the impact of the breach. The Parties agree to fully cooperate in such investigations and to assist each other in complying with any applicable notification requirements and procedures.

11. Termination

11.1.

Without prejudice to any provisions of the GDPR, in the event that the Company is in breach of its obligations under this DPA, the Customer may instruct the Company to suspend the processing of Personal Data until the Company complies with the DPA or until the Agreement is terminated in accordance with section 11.2 below. The Company shall promptly inform the Customer if it is unable to comply with this DPA, for any reason.

11.2.
The Customer shall be entitled to terminate the Agreement insofar as it concerns Processing of Personal Data in accordance with the DPA if:
  • the Processing of Personal Data by the Company has been suspended by the Customer pursuant to point 11.1 above and if compliance with the DPA is not restored within one month following suspension
  • the Company is in substantial or persistent breach of the DPA or its obligations under the GDPR
  • the Company fails to comply with a binding decision of a competent court or the competent supervisory authority/ies regarding its obligations pursuant to the DPA or the GDPR.
11.3.

The Company shall be entitled to terminate the Agreement insofar as it concerns Processing of Personal Data under the DPA where, after having informed the Customer that its instructions infringe applicable legal requirements, the Customer insists on compliance with the instructions and where the Customer is in breach of the terms of this DPA and fails to remedy such breach within one month from the date of being notified in writing of such breach.

12. Return and/or deletion of Personal Data

12.1.

Following termination of the Agreement, the Company shall, at the choice of the Customer and at the latest sixty (60) calendar days after the last effective day of this DPA and/or the Agreement, either delete all Personal Data processed on behalf of the Customer and certify to the Customer that it has done so, or return all Personal Data to the Customer and delete existing copies, unless European Union or Member State law requires longer storage of the Personal Data. Until the data is deleted or returned, the Company shall continue to ensure compliance with this DPA.

12.2.

Upon written request by the Customer, the Company shall provide the Customer with a readable copy of the Personal Data stored on its systems, in a standard and commonly used format. The costs related to such request or copy shall be borne by the Customer.

13. Liability

13.1.

The Company shall be liable for any damage caused by the Processing of Personal Data under this DPA and/or the Agreement only where it has failed to comply with the applicable Data Protection Legislation specifically directed at Processors, and/or where it has acted outside or contrary to the lawful instructions of the Customer.

13.2.

The provisions of the Agreement regarding limitation of liability shall fully apply to the Processing of Personal Data by the Company under this DPA and/or the Agreement. In any event, the Company’s aggregate maximum liability under this DPA shall be limited to an amount equal to the total fees paid by the Customer to the Company under the Agreement. The right to claim damages attributable to the Company shall irrevocably expire six (6) months after the occurrence of the alleged breach or error. The Customer must provide a written notice of default within the aforementioned term, including a detailed description of the issue.

14. Governing Law and Jurisdiction

14.1.

This DPA shall be governed by and construed in accordance with the laws of the Republic of Cyprus. Any disputes arising out of or in connection with this DPA shall be subject to the exclusive jurisdiction of the competent courts of Cyprus.