Legal
Data Processing Addendum
Effective date: August 24, 2026
This Addendum applies whenever Quathos LLC processes personal data on behalf of a customer organization using Quathos Sign. The customer is the controller (a “business” under the CCPA); Quathos LLC is the processor (a “service provider”). Where this Addendum conflicts with the Terms of Use, this Addendum governs for the processing of personal data. It is drafted to satisfy Cal. Code Regs. tit. 11, §7051 and the equivalent contracting requirements of the Virginia, Colorado, Connecticut and successor state privacy laws, and — for customers in Brazil — arts. 37 to 39 of the LGPD.
1. Specific business purposes
We process personal data only for these specific purposes, and for no other: (a) receiving and storing documents the customer uploads; (b) delivering signing invitations and reminders by email and SMS; (c) authenticating signers, including identity checks the customer configures; (d) recording the evidence of each signing act and generating evidence reports and dossiers; (e) making signed documents and their evidence available to the customer and to signers; (f) providing support the customer requests; and (g) billing for the Service.
This list is deliberately specific. §7051(a)(2) forbids describing the business purpose in generic terms or by reference to the contract as a whole.
2. No sale, no sharing
We do not sell personal data and we do not share it for cross-context behavioral advertising, as those terms are defined by the CCPA. We do not use personal data to build or improve profiles for advertising, and we do not use it to train models offered to other customers.
3. Use limited to the stated purposes
We do not retain, use, or disclose personal data for any purpose other than the business purposes in section 1, or as otherwise permitted by applicable privacy law. We do not retain, use, or disclose it for any commercial purpose beyond those purposes, and we do not use it outside the direct business relationship with the customer.
We may generate aggregated or de-identified statistics about Service usage that cannot reasonably be linked to any individual, and will not attempt to re-identify them.
4. Same level of protection
We comply with the obligations applicable to us under the CCPA and other applicable privacy laws, and we provide the same level of privacy protection for personal data processed under this Addendum as those laws require of the customer.
5. Customer oversight and audit
The customer may take reasonable and appropriate steps to confirm that we use personal data consistently with its obligations, including requesting our current security documentation and, no more than once every twelve months, a reasonable audit — either a written assessment or an audit conducted at the customer’s expense, on reasonable notice, without disrupting the Service and without access to other customers’ data.
6. Notice when we can no longer comply
If we determine that we can no longer meet our obligations under applicable privacy law, we will notify the customer promptly and in writing.
7. Right to stop and remediate
On notice from the customer of unauthorized use of personal data, we will take reasonable and appropriate steps to stop and remediate that use.
8. Assistance with individual rights requests
We will assist the customer in responding to requests from individuals to know, access, correct, delete, port, opt out, or limit the use of sensitive personal information, and with equivalent rights under other applicable laws. Requests we receive directly from an individual whose data we process for a customer are forwarded to that customer.
One limit is inherent to the Service and stated plainly: signed documents, signature records, evidence dossiers and the audit trail are the proof of a signature. Deleting them would destroy the legal effect of a document the individual signed, including against that individual, and the audit trail is append-only by construction. Where a deletion request reaches that data, we will say so rather than silently decline.
9. Subprocessors
We use subprocessors for hosting, email and SMS delivery, payment processing, and — when the customer enables it — signer identity verification. Each is bound by a written contract imposing obligations equivalent to this Addendum, and we remain responsible for their performance. A current list is available on request, and we will give notice before adding a subprocessor that processes customer personal data.
10. Security, incidents, and deletion
We maintain technical and organizational measures appropriate to the risk, including encryption in transit and at rest, tenant isolation enforced at the database level, least-privilege access, and an append-only audit trail. Personnel with access are bound by confidentiality.
We will notify the customer without undue delay after becoming aware of a personal data breach affecting its data, with the information the customer needs to meet its own notification duties.
On termination, the customer may export its documents and evidence dossiers. After the export window we delete or de-identify personal data, except where retention is required by law or necessary to preserve the proof of signatures already made — see the retention section of the Privacy Policy.
11. International transfers
We process data in the United States and in other countries where our providers operate. Where the law requires it, we adopt appropriate safeguards for international transfers, and for transfers of personal data of individuals in Brazil we observe arts. 33 to 36 of the LGPD.
12. How to execute this Addendum
To have this Addendum countersigned for your organization, write to contact@quathos.com with your legal entity name and address. Absent a separately negotiated agreement, this Addendum applies by its terms to processing carried out through the Service.