1. Parties, status and scope
Orbis Sign is a service of Orbis Digital Ltd (the Provider, Orbis, we or us). The person or organisation buying or using the Service is the Customer. A person invited to sign is a Signer.
Orbis Digital LtdCompany number 17116737
Registered in England and Wales
Registered office: 66 Paul Street, London, EC2A 4NA, United Kingdom
This DPA applies where Orbis processes personal data for the Customer under an Agreement that incorporates it. UK GDPR terms have their statutory meanings. A signed Customer-specific DPA prevails where it conflicts with this version.
2. Instructions and compliance
Orbis will process Customer personal data only on documented instructions, including the Agreement and the Customer's configured use, unless UK law requires otherwise. Where permitted, Orbis will tell the Customer before legally required processing and will promptly inform it if an instruction appears to infringe applicable data-protection law.
3. Personnel and confidentiality
Orbis will restrict access to authorised people who need it to provide or secure the Service and ensure they are subject to confidentiality obligations. The Customer is responsible for its user permissions and for instructions given through its accounts.
4. Security
Orbis will maintain measures appropriate to risk as documented in Annex 2 and the applicable Agreement. Annex 2 describes the application controls included in this DPA and does not make commitments about controls that are not stated there.
Orbis will notify the Customer without undue delay after becoming aware of a personal-data breach affecting Customer data and provide available information reasonably needed for the Customer's obligations. No shorter fixed notification deadline or dedicated notification address is stated.
5. Subprocessors and transfers
The Customer gives general written authorisation for Orbis to use the providers in the Subprocessor Schedule. Orbis will perform appropriate due diligence, impose the data-protection terms required by Article 28, remain responsible as law requires, and give reasonable advance notice of a new provider with an opportunity to raise a reasoned data-protection objection.
Orbis will not make a restricted transfer without a lawful mechanism, required assessment and supplementary measures. The schedule links to current supplier-level information.
6. Assistance and rights requests
Taking account of the nature of processing and information available, Orbis will reasonably assist with data-subject requests, security duties, breach notifications, data protection impact assessments and prior consultation. The Customer will bear reasonable additional costs only where permitted by law and agreed in advance.
7. Return, deletion and audit
At the end of services, Orbis will act on the Customer's documented choice to return or delete Customer personal data, subject to technically available export functions, applicable provider and backup lifecycles, and any UK law requiring storage. Any lawfully retained data remains protected and is used only for that retention purpose. Orbis will distinguish completed deletion from any provider, backup or legal-retention step still pending and will not represent erasure as complete until it has been confirmed. Customers should export required documents and evidence before access ends. No particular post-termination retrieval or backup-erasure interval is guaranteed.
Orbis will provide information reasonably necessary to demonstrate compliance and permit audits as required by Article 28, subject to reasonable security and confidentiality safeguards. The parties will agree reasonable notice, scope and practical arrangements that minimise risk to other customers and the Service.
Annex 1 — Processing details
Subject matter: online preparation, routing, signing, completion evidence, administration and support for Customer documents.
Duration: the Agreement term and any period during which data is returned, deleted, isolated in provider backups, or lawfully retained under section 7.
Nature and purpose: collect, store, organise, retrieve, display, transmit, render, record and delete data needed for Customer-configured workflows and service security.
Data subjects: Customer users, personnel, contractors, clients, counterparties, Signers, witnesses and people mentioned in Customer Content.
Data: contact and account details; document contents and metadata; signature, initials and field responses; telephone and delivery details; consent and disclosure evidence; status, IP address, user-agent, timestamps, provider telemetry and audit events. Customers must not submit special-category or criminal-offence data unless lawful, necessary and permitted by the Agreement.
Annex 2 — Technical and organisational measures
Access and authentication: role and workspace access checks; scrypt password hashes; optional TOTP with encrypted secrets and hashed one-use recovery codes; PostgreSQL-backed sessions; and a Secure, HttpOnly, SameSite=Lax production session cookie.
Signing and application controls: expiring high-entropy signing tokens; optional signer OTP; origin checks; rate limiting; API security headers; input validation on key routes; audit events; and logging redaction for cookie and authorisation headers.
Scope: these terms do not promise a particular hosting or recovery region, RPO/RTO, certification, penetration-test cadence, vulnerability-remediation SLA, malware scanning or content-disarm service. Provider-level transport, storage, backup and infrastructure controls are governed by the applicable supplier service and DPA. Orbis remains responsible for assessing and maintaining measures appropriate to the risk.

