Data Processing Agreement
If your organisation is subject to GDPR or similar laws, Coventract acts as your data processor. This page summarises our DPA and lets you request a countersigned copy.
Key terms
1. Roles of the parties
The Customer is the data controller and Coventract is the data processor. Coventract processes personal data only on the Customer's documented instructions and to provide the service.
2. Subject-matter & duration
Processing lasts for the term of the customer agreement and covers the creation, signing, storage and management of contracts and related records.
3. Types of data & data subjects
Names, email addresses, IP addresses, device information, signatures and the contents of documents the Customer chooses to process. Data subjects include the Customer’s users and their counterparties.
4. Security measures
Encryption in transit (TLS) and at rest, role-based access controls, a SHA-256 tamper-evidence seal on signed documents, and an append-only audit trail. See the Trust Center for details.
5. Sub-processors
The Customer authorises the sub-processors listed below. We will give reasonable notice before adding a new sub-processor so the Customer can object.
6. Personal data breaches
We will notify the Customer without undue delay after becoming aware of a personal data breach affecting their data, with the information needed to meet their obligations.
7. International transfers
Where personal data is transferred across borders, appropriate safeguards (such as Standard Contractual Clauses) apply. Our primary hosting region is asia-east1.
8. Return & deletion
On termination, and at the Customer’s choice, we will return or delete the personal data, subject to any retention required by law.
9. Audit
We will make available information necessary to demonstrate compliance and allow for reasonable audits on request, subject to confidentiality.
10. Provider commitment
By publishing and accepting this Agreement, Coventract agrees to and is bound by its terms. When you sign electronically below, a binding agreement is formed between both parties — no separate signature from Coventract is required. A countersigned PDF copy is available on request.
Approved sub-processors
| Provider | Purpose | Location |
|---|---|---|
| Google Cloud / Firebase | Hosting, database, authentication, file storage | Google Cloud (asia-east1) |
| Google AI (Gemini) | AI clause drafting, review and explanation | United States / global |
| Resend | Transactional email delivery | United States / EU |
| PayPal | Payment processing for subscriptions and invoices | United States / global |
Accept & sign electronically
Sign the DPA now on behalf of your organisation. We record the time, your IP and device, and a hash of the version you agree to — and email you a confirmation.
Prefer a mutually-executed copy? Request one and we’ll email a countersigned DPA.
Request a countersigned DPA
This page is general information and not legal advice. See also our e-signature legality and Trust Center.