Legal
Data processing terms
How we process your organisation's data when you use Signed, and what we commit to as your processor under the UK GDPR.
Last updated
1.About these terms
These data processing terms form part of our terms of service. They apply whenever we process personal data for your organisation while we provide Signed, and they set out the commitments that Article 28 of the UK GDPR requires.
Signed is a trading name of Cube Systems Limited, registered in England and Wales with company number 17220899. In these terms "we" and "us" mean Cube Systems Limited, and "you" means the organisation that has accepted our terms of service. Words such as controller, processor, personal data and personal data breach have the meanings they have in the UK GDPR.
If these terms and the terms of service disagree about personal data, these terms apply.
2.Our roles
- You're the controller of the personal data in your customer data. You decide what goes into Signed and why.
- We're your processor. We only process that data to provide Signed to you.
- Agencies and IT providers that manage organisations for clients confirm they have each client's authority to do so. The client may be the controller, with the agency as its processor and us as the agency's sub-processor. These terms apply in the same way.
We're a controller in our own right for account, billing and enquiry data, visits to our website and the security information our systems record. Our privacy policy covers that data.
3.What we process
| Detail | Description |
|---|---|
| Subject matter | Providing Signed: designing, assigning and adding email signatures and banners for your organisation. |
| Duration | While your organisation uses Signed, and until its data is deleted after the organisation is closed. |
| Nature and purpose | Storing, syncing, rendering and serving signatures, reading your directory from Microsoft 365 if you connect it, sending service and test emails, counting signature link clicks, keeping audit logs and giving you support. |
| People the data is about | Your staff and anyone else who gets a signature, your team members who use the portal, and people who click links in your signatures. |
| Types of personal data | Names, email addresses, job titles, departments, company names, phone and mobile numbers, office addresses, social profile links, photos, pronouns, booking links and any custom fields you add. Signature templates and their saved versions, rules, banners, brand kits and uploaded images. The sender address and email type the Outlook add-in sends. Audit log entries. Signature link click records, which hold no IP address or other detail that identifies the person who clicked. |
| Special category data | None is needed. Please don't put special category data, such as health information, into Signed. |
4.Your instructions
We only process customer data on your documented instructions. Those instructions are the terms of service, these terms and the way you set up and use Signed, including what you sync from Microsoft 365, what you import and what you send through the API.
If the law requires us to process customer data in any other way, we'll tell you first unless the law stops us. If we think an instruction breaks data protection law, we'll tell you straight away.
5.Confidentiality
Everyone at Cube Systems Limited and at our sub-processors who can access customer data is bound by a duty of confidentiality. Our staff only access it when they need to, for example to answer a support request you've made or to keep Signed secure.
6.Security
We keep appropriate technical and organisational measures in place to protect customer data, as Article 32 of the UK GDPR requires. They include:
- HTTPS for everything between browsers, Outlook and Signed
- every request checked against the organisation it's for, so one organisation can't reach another's data
- passwords hashed with bcrypt, and session tokens and API keys stored only as SHA-256 hashes
- sign-in cookies that are httpOnly, so scripts on the page can't read them
- read-only access to Microsoft 365 through the User.Read.All permission, with admin consent and a second sign-in to confirm the directory
- a separate client key for each organisation's Outlook add-in, and rate limits on sign-in, sign-up and signature lookups
- API keys with scopes, optional IP allow-lists and expiry dates, shown once and never stored in a readable form
- signature previews shown in sandboxed frames, and uploads limited to PNG, JPEG, GIF and WebP images
- two-factor authentication for Signed staff, and an audit log of changes
Our security page explains these in more detail. We review the measures as Signed changes and may update them, as long as the overall level of protection doesn't go down.
7.Sub-processors
You give us general authorisation to use sub-processors. The current list, with what each one does and where, is on our sub-processors page.
- Each sub-processor works under a written contract with data protection obligations equivalent to these terms.
- We stay responsible to you for their work.
- We'll email your organisation's account owner at least 30 days before we add or replace a sub-processor.
- If you object on reasonable data protection grounds, tell us within those 30 days. We'll try to find a solution. If we can't, you can cancel before the change takes effect, without a cancellation fee.
8.International transfers
Customer data is stored and processed in the UK, on Amazon Web Services in its London region (eu-west-2). We won't transfer it outside the UK unless a lawful safeguard is in place, such as UK adequacy regulations, the International Data Transfer Agreement or the UK Addendum to the EU standard contractual clauses. We'll tell you first, through the sub-processor notice above.
Microsoft 365 is your own service, under your agreement with Microsoft. Where Microsoft keeps your directory is part of that agreement, not ours.
9.Helping you meet your obligations
- Requests from individuals. If someone asks us to access, correct or delete their data in your organisation, we'll pass the request to you and won't answer it ourselves unless you ask us to. You can view, edit, deactivate and delete people in the portal and through the API.
- Security, impact assessments and the ICO. We'll give you the information you reasonably need for your own security, for data protection impact assessments and for any consultation with the Information Commissioner's Office.
10.Personal data breaches
If we become aware of a personal data breach affecting customer data, we'll tell your organisation's account owner without undue delay, and within 48 hours of becoming aware of it.
We'll tell you what happened, the kinds and rough numbers of people and records affected, the likely consequences and what we've done or plan to do about it. If we don't know everything at first, we'll send what we know and follow up as we learn more.
As the controller, you decide whether to tell the ICO and the people affected. We'll help you do that.
11.Deletion at the end
Before you close your organisation, you can ask us for a copy of your people, templates and settings, and we'll send it to you. Organisations with API access can also export them through the Signed API.
When your organisation is closed, access to it stops and we delete its customer data within 90 days, including any copies in backups, unless the law requires us to keep something for longer. Anything we have to keep stays protected by these terms, and we only keep it for as long as we must.
12.Information and audits
We'll give you the information you reasonably need to show that these terms are being met, and answer reasonable security questionnaires.
If that isn't enough, you or an auditor you appoint can audit our compliance, on at least 30 days' notice and no more than once a year, unless a breach or a regulator requires it. The auditor must be bound by confidentiality, and each of us pays our own costs.
13.Liability
Each party's liability under these terms is subject to the limits in the terms of service.
14.Contact us
Email hello@usesigned.co.uk with any question about these terms, or write to Cube Systems Limited, Unit 11, Olney Business Park, Osier Way, Olney, Buckinghamshire, MK46 5FP.