PRIVACY POLICY
The present Privacy Policy (hereinafter the “Privacy Policy”) is a legally enforceable instrument. By selecting “I agree” you confirm that you have reviewed the document, confirm the content thereof and acknowledge that the relation(s) between you and Signify will be governed by the terms and conditions of this document.
This document governs the matters relating to the processing and protecting Customers’ personal and other data.
This document is an integral and substantive part of Signify’s Standard Terms of Use (hereinafter the “Terms of Use”) (available at the following link: https://portal.signifyapp.com/app/terms/terms_and_conditions) and shall be interpreted together with the said Terms of Use.
In the event of discrepancy between this document and the Terms of Use, the rules set forth in this Privacy Policy shall prevail.
The terms and definitions applied in this document shall be interpreted in accordance with the Terms of Use, unless determined otherwise in this document and/or derived otherwise from the context of the Privacy Policy. Further, where the context requires, certain definitions applied in this Privacy Policy shall have the meaning ascribed to them in the Law of Georgia “on Personal Data Protection”.
- General Provisions
-
Signify taking into account the importance of the personal data and other confidential data (hereinafter collectively referred to as the “Data”), adopts the most advanced measures available to Signify for the purposes of ensuring the protection of the said Data. Signify will always ensure that the safety mechanisms comply with the existing laws of Georgia, best international practice and technical achievements.
-
Confidentiality is a priority. The Privacy Policy sets out information as to the manner and purpose of collecting and processing the Data by Signify from the Customers that use the Signify Platform and Services.
-
The Privacy Policy shall not extend to the web-sites and apps of the Third Parties that may be used by the Customer, including when using the Platform. Prior to visiting any link, the Customer shall familiarize with the terms and conditions of such Third Party, including, the privacy policy and/or other documents related to the data protection.
-
Signify acting in its capacity as the Data Processor set forth under the Law of Georgia “on the Personal Data Protection” receives and processes: (1) the Data provided by the Customer to Signify; (2) as well as the Data available to Signify as a result of the Customer’s use of the Platform and Services.
-
Further, Signify processes the Data of those persons that do not represent the Customers registered on the Platform, provided however that these persons use the Platform for the purposes of executing the signatures (for example, the Visitor that does not represent the Customer registered on the Platform and receives a request from the registered Customer to sign/confirm the Document).
-
Signify processes the Customer Data at least for the period wherein the Customer’s Account is active, whereas the Data of the person(s) indicated in Clause 1.5 of this Privacy Policy at least for the term the Account of the Customer (that has named the said person(s) indicated in Clause 1.5 as a signatory/responsible for confirmation) remains active. Upon deactivation of the Account, the Data of the Customer and/or the Data of the person(s) indicated in Clause 1.5 shall be removed in accordance with the rules of this Privacy Policy, unless such Data is required to be stored for the purposes of ensuring compliance with the requirements set forth by the law.
-
The terms set forth in relation to each category of the Data are governed under the following document available at: https://signifyapp.com/en-GL/policies/privacy-policy/#data-retention-chart
-
Further, in the event Signify acts in its capacity as the Data Processor for the purposes set forth under the Law of Georgia “on Personal Data Protection”, the matters related to the processing of the Data by Signify as the Data Processor, are governed under the Data Protection Agreement available at: https://signifyapp.com/en-GL/policies/privacy-policy/#dpa
-
-
Purposes of Data Processing
-
Signify processes the Data in accordance with the rules and conditions set forth in this Privacy Policy for the purposes of the Customer’s use of the Platform, providing Services to the Customer and optimizing, fixing and improving the processes related to the Platform, as well as for direct marketing purposes. Below list refers to some of the examples as to the use of such Data. Signify:
-
Provides the Customer the Services/products in relation to the Platform (electronic signature, sharing the Document and etc.).\
-
Creates an Account on the Platform.
-
Provides the Customer with the information in relation to the Services.
-
Markets the preferences, products or special measures via e-mail or phone, provides the Customer with marketing information.
-
Detects the Data in relation to the Document, such as: who has reviewed the Document, who has signed the Document, the devices used, time, IP address.
-
Performs testing of the changes in Services and implements new possibilities and/or products.
-
Reacts on the potential problems as to the Service, provides answers to the technical questions and resolved disputed matters.
-
Prevents, examines and reacts to the matters such as fraud, Non-authorized Use of the Services, breach of the Terms of Use or other illegal activities.
-
Complies with the requirements of law, including but not limited to the Anti-Money Laundering normative acts.
-
-
-
Grounds and Rules for Obtaining the Data
-
Signify processes the Data on the basis of the Customer’s and/or the Visitor’s consent to use the Platform and to provide Signify with the Data for the purposes of its processing and/or to allow Signify to obtain/process the Data.
-
By using the Platform/Services the Customer and/or the Visitor agrees to the rules of processing the Data, purposes, grounds and scope set out in this Privacy Policy.
-
The forms of obtaining/receiving the Data by Signify:
-
The Customer’s registration on the Platform or the use of the Platform and provision of the Data (including but not limited to the E-mail, name, surname, Mobile Number and etc.) to Signify for the purposes of using the Platform
-
The Data is available to Signify through the Customer’s and/or the Visitor’s use of the Platform (including but not limited to the IP Address, time of using the Platform, date, place, signatories, time of signing, browser version). Such Data is made available to Signify when the Customer:
-
Creates, signs, sends, shares, receives or views the Document;
-
Creates or revises the Account;
-
Uses the Account;
-
Contacts the Customer Support;
-
Comments on Signify blog, forum or social page.
-
Use the Platform for various Services.
-
-
Further, by using the Platform the Customer provides Signify with the Data concerning other natural persons, when:
-
The Customer initiates the signature and indicates the Data in relation to other natural person(s) (name, surname, E-mail, Mobile Number);
-
Adds other Sub-Customers to the existing Account
-
Provides Signify with an e-mail of an individual who will be provided with the invoice for the purposes serving/receiving the payment invoice by Signify.
-
The Visitor provides Signify with the Data (including but not limited to the e-mail, name, surname) when using the Platform for the purposes of sending a trial document.
-
-
-
-
Categories of the Data being Processed
-
Categories of the Data obtained and processed by Signify:
-
Identifiers: Name, surname, identification number, E-mail, Mobile Number
-
Commercial/transactional Data: billing information, purchased products or Services, bank card data and bank account details, payment methods and information related to the payment;
-
Automatically obtained Data;
-
Data provided through the Customer’s use of the Platform and/or voluntarily provided information when creating the Account;
-
Information on the subscription of the marketing messages and/or cancellation thereof;
-
Information provided through assessing/rating the Services;
-
Information on the time spent on the Platform by the Customer;
-
Additional information indicated in Clause 4.5 of this Privacy Policy being processed upon the Customer’s use of the additional authentication method(s).
-
-
Categories of the Data automatically obtained by Signify:
-
Information on the use of the device and transaction, including but not limited to: the form of the use of the Platform, information on the computer or other device, such as mobile phone or tablet, IP address, unique device identifiers, geolocation, physical location and other characteristics such as operative system and browser, entering the web-site, leaving the web-site and URL, duration of the use of the Platform or Service, date and time, frequency of the use, error detection and other similar data.
-
Transaction Data, for example, identity of the participants and e-mail, transaction subject, history of activities executed by various persons in a transaction (for example: viewing, signing, activating parameters) and personal Data of those persons and their devices – identity, e-mail, IP address, geolocation, physical location and authentication methods, and in no event – the content of the Document.
-
-
Signify confirms that the Document(s) uploaded by the Customer for the purposes of signing thereof and/or the contents thereof are not subject to processing by Signify.
-
The Customer hereby agrees and acknowledges that Signify is entitled to process the Customer Data through filing (including profiling) system.
-
In the event the Customer uses additional authentication methods, Signify additionally obtains and processes the following Data:
-
In the event of SMS authentication:
-
Mobile Number of the signatory;
-
-
In the event of Video identification:
-
Name, surname, identification number, date of birth, nationality, gender of the signatory;
-
Copy of the Passport and ID Card (or other document containing personal Data and used for the purposes of identification);
-
Biometric Data of the signatory: photo/video recording of the face of the signatory recorded through the mobile app or camera, video or audio recording, that is being used for the identification purposes.
-
-
In the event of Qualified E-Signature:
-
Name, surname, identification number, nationality of the signatory.
-
-
-
In the event of signing through the signature pad/tablet:
-
Biometric Data of the signatory (biometrical Data of the signature, including but not limited to the physical force/pressure, pattern of acceleration and etc.) is made available/is subject to processing by the Public Service Development Agency and LEPL Levan Samkharauli National Forensics Bureau only in the event of conducting forensic test in relation to a biometric signature as per SIGNIFY PAD Terms and Conditions.
-
Biometric Data of the signatory (biometric Data of the signatory, including but not limited to the physical force/pressure, pattern of acceleration and etc.) are not made available to Signify;
-
The matters in relation to the processing of the personal Data through the signature pad/tablet is governed by SIGNIFY PAD Terms and Conditions.
-
-
-
Cookies
-
When storing and/or collecting Data Signify uses Cookies that represent files downloaded on the Customer’s device and entailing small amount of information that is being stored in Customer’s technical device by the Customer browser (Chrome, Safari and etc.). Additionally, Cookies represent the memory of the browser in relation to a specific web-site and detect the moment of the Customer’s use of the web-site and are adjusted to the Customer’s requirements. Cookies enable the Customer to adapt the web-site to the Customer’s needs and assist the Customer so that the Customer is not required to adjust the parameters (such as the language of the web-site) for each use.
-
Cookie files enable the web-site to adjust to the Customer. Cookies enable Signify to provide, protect and improve the Services by personalizing content, adjusting the content to the Customer and provide for a safe experience.
-
Cookies may vary and may be of different category: location, registration, marketing, Third Party Cookies and etc.
-
Third-party Cookies mainly refer to the Cookies of the Third Parties conducting analytics (such as, Google analytics). Such Cookie files determine the frequency of the Customer visiting the web-site, duration of each session and etc.
-
Registration and/or Account Cookies provide information on the Customer that has registered through the Account and/or uses the Account, as well as information on the duration of the use of the Account and the Services used.
-
Geolocation Cookies determine the location of the Customer using the web-site.
-
Full limitation of the generation of the Cookies by the browser is impossible. Further, restriction of the Cookies may affect the Customer’s use of the Platform/Services and restrict the use thereof.
-
The Customer may review and use the Cookie parameters:
-
Cookie Settings – Firefox
-
Cookie Settings – Chrome
-
Cookie Settings - Internet Explorer
-
Cookie Settings - Safari.
-
-
Signify uses Cookies for the following purposes: authentication, safety, integrity of the web-site and the product, recommendations, rating and responsiveness, web-site functions and Services, performance, marketing, analytics and research.
-
-
Transmission of the Data and International Transfer
-
General. Signify provides Third Parties with the Data solely in the events set forth in this Privacy Policy and/or in the events prescribed under the applicable rules set forth in the law.
-
Persons that Signify shares the Data with. Signify transmits the Data to the following persons (the Data is transmitted to such persons solely to the extent that is required/necessary for the purposes set forth in this Privacy Policy):
-
Service Providers. The Data is shared with the companies that are being used by Signify for the purposes of supporting the Services related to the Platform. Such companies render services such as storing information, search technologies, analytics, advertisement, messaging, identification systems, fraud detection and/or technical support. The list of the service providers and sub-contractors of Signify is available at: https://signifyapp.com/en-GL/policies/privacy-policy/#sub-subprocessors
-
State or administrative bodies in the events directly prescribed by law.
-
Other Third Parties. Upon the Customer’s request or on the basis of the Customer’s consent, the Data may be transmitted to other Third Parties.
-
-
Other Events. The Data may also be transmitted to the following persons in following scenarios: granting access over the Account by the Customer to another Customer, including granting the authority to use or revise the content of the Account and/or sending out the Document for signing, in which case the data related to the Document available to the person receiving the Document.
-
Data Transmission in other Countries. The Data may also be transmitted to other state provided that the such transfer is executed on the grounds set forth in the law of Georgia “on Personal Data Protection” and the respective state ensures sufficient degree of protection of the data and the rights of the data subject.
-
Data Transmission in other Countries of Insufficient Data Protection Guarantees. In the event the data is transmitted in a state which fails to provide sufficient degree of protection of the data and the rights of the data subject, Signify ensures to conclude a respective Data Processing Agreement in accordance with the requirements of the law. Such agreement shall ensure to provide adequate protection of the personal data of the data subject for the purposes of protecting the data subject. Prior to transmitting the data to the Third Party, Signify shall examine the respective organizational and/or technical measures adopted by the said Third Party intended to protect the protect the data.
-
-
Direct Marketing
-
Customer’s Consent. In the event during the registration or by using the respective tool while using the Platform, the Customer agrees to receive marketing messages from Signify, Signify is entitled to use the name, surname and E-mail of the Customer for the direct marketing purposes and provide such Customer with the marketing messages via the E-mail. For the purposes of this Privacy Policy direct marketing means offering the services by Signify in relation to the Platform via communication means.
-
Message Personalization. Signify is entitled to personalize marketing messages on the basis of the Customer’s history of using the Platform (including, frequency of use, orders, payment).
-
Customer’s Refusal. In the event the Customer does not wish to receive marketing messages from Signify, the Customer is entitled to use the option “Unsubscribe” on the Platform and/or E-mail at any time and object to such marketing messages. Signify shall cease processing of the Data for direct marketing purposes within 7 (seven) business days upon receipt of the Customer’s corresponding request.
-
-
Liability and Further Obligations of Signify acting in its capacity as the Data Processor
-
General. Signify shall be liable for processing, storing of the Data provided to Signify and protecting the confidentiality of such Data.
-
Customer’s Warranty. The Customer that provides Signify with the Data, hereby confirms and warrants that the Customer possesses corresponding legal ground to process and provide such Data to Signify. The Customer shall be fully liable for complying with the said representation/warranty/confirmation.
-
Customer’s Liability in relation to the Documents and the Data. The Customer acting in its capacity as the processor and collector of the Document (acting as the Data Controller for the purposes of the Law) uploaded/shared/received on the Platform and/or the Data entailed therein shall bear full liability in relation to such Document and the content/Data thereof. For the avoidance of any doubt, Signify shall in no event be liable in relation to the Document uploaded/shared/received by the Customer through the Platform and/or processing/collecting the Data entailed therein.
-
-
Security
-
Security Examination. Signify ensures to regularly examine/test the information security of the Platform (including, through the internationally certified Third Party, in accordance with the international practice), whereas such examination/testing complies with the library of the Digital Europe eSignature DSS, that is fully compliant with the PAdES Standard set forth in the eIDAS Regulation (Regulation (EU) No 910/2014 of the European Parliament and of the Council of 23 July 2014 on Electronic Identification and Trust Services for Electronic Transactions in the Internal Market and repealing Directive 1999/93/EC).
-
Data Center. Signify uses the Amazon Web Services (AWS) data center located in Stockholm for storing the data. The Personal Data Protection Service of Georgia recognizes Kingdom of Sweden among the countries where transmission of the Data is considered safe.
-
Encryption. Upon being uploaded on the Platform, the Document is encrypted with AES-256 byte encryption that ensures that the Document and the content thereof is not accessible to the Signify’s employees, including, the database administrator, and is only accessible to those persons that have been granted with such access by the Customer.
-
Incident Reporting. The Customer shall immediately inform Signify on any incident related to Signify’s information security (including the security of the personal or other Data), that the Customer has been made aware of and may affect Signify’s services and/or the Platform. For this purpose, the Customer shall provide Signify with any relevant detail in relation to the incident, including the nature of the incident and its potential effect on Signify’s services and/or the Customer’s information/Data. Further, the Customer shall cooperate with Signify in the process of investigating and resolving the respective incident, provide Signify with necessary information and provide the respective assistance in the process of investigation and resolving the incident. For the purposes of providing information as to the incident the following means of communication shall be used: (i) e-mail: incidents@signifyapp.com and/or (ii) Signify’s online assistance/help tool available at: https://signifyapp.com/en-GL/about/
-
-
Customer Rights
-
The Customer and/or the Data Subject is entitled to:
-
Right to Obtain Information - obtain information on the Data being processed in relation to such Customer/Data Subject, including but not limited to: the particular Data being processed, the purpose of processing thereof, methods of collecting Data/sources of Data, information on the period during which the data is being stored or the criteria for determining such period, information on the rights of the Data Subject, information on the transmission of the Data (if any), information on the automatic processing, including profiling (if any). Further, the Customer/Data Subject is entitled to familiarize with the Data processed in relation to such Customer/Data Subject and request a copy of his/her/its Data by submitting corresponding request on the e-mail indicated in Clause 12. In the event of such request, Signify undertakes to provide the Data Subject with the requested information within 10 (ten) business days upon receipt of such request. The said period may be extended in the events prescribed by the Law.
-
Right to Correct, Update, Complete, Add, Block, Remove and/or Destroy the Data - request to correct, update, complete, add, block, remove and/or destroy the Data, provided however that the request to remove the Data (whether partially or fully) or restrict the processing of the Data (whether partially or fully) may impede the Services or may result in the ceasing of the use of the Services (See. Clause 11). For the avoidance of any doubt, the Customer’s request as to blocking, removing, destroying and/or ceasing of the processing of the Data shall not affect the legality/lawfulness of the processing of the Data prior to raising such request. In the event of such request, Signify undertakes to address such request (and/or provide the information to the Data Subject on such request in the event set forth in Clause 11.3 of this Privacy Policy) within 10 (ten) business days upon receipt of such request. The said period may be extended in the events prescribed by the Law. Signify is entitled to dismiss the Customer’s request in relation to blocking of the Data in the events prescribed by the Law.
-
Right to Refuse Processing of the Data for Marketing Purposes - object to the processing of the Data for direct marketing purposes. In the event the Customer objects to the processing of the Data for direct marketing purposes, exercise of such right does not deprive Signify from using the Customer’s contact/communication Data for the purposes of providing information on the Services. In the event of such request, Signify undertakes to stop processing of the Data of the Data Subject for direct marketing purposes within 7 (seven) business days upon receipt of such request.
-
Right to Withdraw the Consent - withdraw his/her/its consent on the processing of the Data at any time without providing any argumentation/explanation and contact the Personal Data Protection Service of Georgia in the event of claims/complaints and/or file a claim at the court. In the event the Data Subject withdraws his/her/its consent on the processing of the Data, Signify shall act in accordance with Clause 11 of this Privacy Policy.
-
Exercise of the Rights - exercise the rights indicated in this Privacy Policy by serving a notice to Signify on the e-mail indicated in Clause 12. The notice shall comprise the name, surname, address, Mobile Number of the Customer. Signify is entitled to request additional information for the purposes of identifying the Customer. Signify may refuse to satisfy those complaint(s) of the Customer that are unsubstantiated, unreasonably repetitive or excessive.
-
-
-
Termination of the Data Processing
-
The Term of Deletion of the Data - in the event the termination of the Data Processing is based on the Customer’s/Data Subject’s request or the requirement set forth in the law, the processing of the Data and/or its removal/destruction (as per the request) shall take place within reasonably tight deadlines, but no later than within 10 (ten) calendar days upon receipt of such request so that the rights and/or interests of the other parties are not affected.
-
Deletion and Deactivation of the Account upon the Customer’s Request - in the event the Customer’s Account is deleted (wherein the Customer no longer uses the Platform and deletes its Account) Signify shall destroy/erase the Data associated with the Customer within 10 (ten) calendar days upon such deletion (except for the events envisaged in Clauses 11.3-11.5 of this Privacy Policy). Further, the Customer is entitled to request erasure/destruction of the Data in shorter period of time – in such case the Customer’s Data shall be removed by Signify within the term set out in Clause 11.1.
-
Refusal to Satisfy the Subject’s Claim. In the event the Data Subject submits a request envisaged under Clause 11.1, Signify is entitled to dismiss such request in the events set forth by the Law. Signify shall inform the Data Subject thereof within 10 (ten) calendar days upon receipt of such request.
-
Continuation of Data Processing. For the avoidance of any doubt, it is possible and admissible that the necessary amount of the Customer’s Data is still being stored and processed to the extent necessary (notwithstanding the periods of time set in Clauses 11.1 and 11.2), if the processing/storing of such Data is aimed at protection of the interests of another Customer/person. For example, if the Customer requests to remove the Data concerning such Customer, and the Document signed by such Customer is stored in the Account of another Customer, for the purposes of protecting the interests of such another Customer, Signify will ensure to protect the unity of such Document and the information entailed therein and to store/process the information (entailing the Data of all Customers related to such Document) accompanying thereto.
-
Continuation of Data Processing in the Events prescribed by Law. Further, in the events prescribed by the Law Signify may continue to store and process the Customer Data in the event storing of such Data is necessary for the purposes of accounting, dispute resolution, crime prevention and/or complying with the requirements set forth by law.
-
Removal of Data in the Event of No Activity by the Customer on the Platform. On the basis of the terms of this Clause, Signify will automatically remove/delete the Data/Documents related to the Customer’s Account in the event there is no activity by the Customer on the Platform (activity means at least logging in and/or payment of the service fee). In the event there is no activity by the Customer on the Platform, Signify may delete the full information/Data, Documents, templates, configurations, sub-users and etc. upon expiry of the 2 (two) year term from the latest activity of the Customer on the Platform. Further, no later than 10 (ten) calendar days prior to the expiry of the 2 (two) year term Signify will inform/remind the Customer of the expiry of the said term. Further, it is hereby determined that the said rule shall in no event apply to the event wherein Signify terminates the provision of the Services on the basis of Clauses 7(1)(4) and/or 7(1)(5) of the Terms of Use.
11a. Protection of Minor Rights
Signify’s Services are not designed and/or tailored for the persons under the age of 18 (eighteen) or for those persons that are considered as minors under the respective legislation applicable to those persons. Signify does not knowingly collect or request the provision of the minor data and does not provide the minors with the Services. Minor is not authorized to use Signify’s Services. Therefore, if you are a minor we kindly ask you not to use Signify’s Services and/or share your personal data with us.
-
-
Final Provisions
-
This Privacy Policy may be amended in accordance with the rules set forth in the Terms of Use.
-
The communication between the Customer and Signify on the matters related to Data privacy shall be conducted via following e-mail: privacy@signifyapp.com.
-
This Privacy Policy is drawn up in Georgian and English languages. In the event of discrepancy between the Georgian and English versions of this document, the Georgian version shall prevail.
-
Data Processing Agreement
The present Data Processing Agreement (hereinafter the “DPA” or “Annex”) represents the integral and substantive part of the Standard Terms of Use of Signify (hereinafter the “Terms of Use”) (available at: https://signifyapp.com/en-GL/policies/terms-and-conditions/) and “Privacy Policy” (available at: https://signifyapp.com/en-GL/policies/privacy-policy/) (hereinafter the “Privacy Policy”) and shall be interpreted in line with the Terms of Use and the Privacy Policy.
The Terms applied in this Annex are ascribed the same meaning set forth in the Terms of Use and the Privacy Policy unless otherwise derived from this Annex.
WHEREAS,
-
The Customer intends to use the electronic signature Platform [available at: https://signifyapp.com/en-GL/] for the purposes of executing documents through the electronic signature;
-
The Customer processes certain personal data when using the electronic signature Platform / when executing/signing the documents through the Platform;
-
As a result of the Customer’s use of the Platform Signify will process certain personal data collected/stored/uploaded/shared by the Customer;
-
The Parties intend to enter into the Data Processing Agreement governing the Parties’ rights and obligations and ensuring the Parties’ compliance with the applicable statutory requirements;
In consideration of the above, the Parties hereby agree to the following:
-
General Provisions
-
Statutory Compliance. Each Party to the DPA is required to adhere to the obligations and requirements set forth under the personal data protection legislation of Georgia.
-
Authorized Processing of the Data. By agreeing to the present Annex, the Customer hereby authorizes Signify to process the personal data on behalf of the Customer for the purposes of rendering the Services under the Agreement (hereinafter the “Permitted Use”).
-
Party Classification. The Parties hereby agree that for the purposes of rendering the Services under the Agreement, including, when processing any personal data uploaded and/or shared by the Customer to Signify when using the Platform (hereinafter the “Personal Data”), Signify acts in its capacity as the “Data Processor” as determined under the Law of Georgia “on Personal Data Protection” (hereinafter the “Data Protection Law”) and processes the Personal Data on the basis of the said Law and the present DPA. Further, it is hereby declared that for the purposes of the present DPA, the Customer acts as a Data Controller as determined under the Data Protection Law.
-
Any matter related to the Personal Data processing and/or confidentiality that is not governed under this Annex, is governed under the Privacy Policy. In the event of discrepancy between the present Annex and the Privacy Policy, the terms/rules set forth under this Annex shall prevail.
-
-
Obligations of Signify acting in its capacity as the Data Processor
-
Statutory Compliance. Signify shall adhere to the requirements set forth under the Data Protection Law, including the special category of the Personal Data (if any).
-
Data Processing and Customer’s Instructions. Signify shall process the Personal Data solely for the purposes and within the scope prescribed in this Annex and/or the Agreement, as well as the specific written (including via electronic mail) instructions (if any) of the Customer acting in its capacity as the Data Controller under the Data Protection Law. In the event Signify consideres that the Customer’s instructions contradict with the legislation, Signify shall immediately inform the Customer thereon.
-
Explicit Declaration. It is hereby explicitly declared that: (i) Signify’s obligations towards the Customer only entails provision of the Services and the operation of the Platform; and (ii) upon the Customer’s upload/adding/entering of the data on the Platform (wherein the Customer acts in its capacity as the Data Controller), the Customer shall adhere to the legislation in relation to the personal data protection and its respective requirements, including, the requirements related to obtaining of the consent of the data subjects and the information duties related thereto.
-
Categories of the Data Processed. The category of the data, as well as, the purposes of the data processing shall be governed under the Privacy Policy.
-
Confidentiality. Signify will grant access on the Personal Data uploaded/stored/added by the Customer on the Platform solely to those employees that require access to such Personal Data for the purposes of rendering Signify’s Services. Further, Signify undertakes that the said persons will be bound by the obligations equivalent to those set forth under this Annex. Signify hereby represents and warrants that deriving from its activity and/or objectives, there is no severe risk of the permitted processing or violation of the data subject rights.
-
Security. Signify shall maintain appropriate organizational and technical measures to ensure Personal Data security.
-
Data Subject Rights. The Customer bears liability on responding to the requests of the data subjects that are related to the rights as to the Personal Data of such subjects. To the extent possible, Signify, acting in its capacity as the Data Processor, will, upon the request of the Customer, asisst the Customer in the process of responding to the data subject’s respective requests. If the data subject directly refers to Signify, Signify shall immediately refer the data subject to the Customer, acting in its capacity as the Data Controller.
-
Logs/Records related to Data Processing. Signify shall keep records of any actions and/or processes related to data processing in accordance with the law.
-
Monitoring. The Customer is entitled to monitor the processing of Personal Data by Signify and to request Signify to provide the relevant information and documentation. In addition, the Customer is entitled to conduct a technical audit at its own expense to ensure compliance with the rules specified in this Annex. Such audit shall be conducted no more than once a year, and the maximum audit period shall not exceed 3 (three) business days. It is further stipulated that: (i) such audit shall be conducted in compliance with Signify’s relevant security rules and requirements; and (ii) Signify shall be notified at least 30 (thirty) calendar days in advance of each audit. Information obtained within the scope of the audit is confidential information that the Customer shall keep confidential.
-
Provision of information to the Customer. Signify shall provide reasonable assistance to the Customer in the process of conducting a data protection impact assessment provided for by law, upon written request of the Customer. Signify shall provide the Customer with the necessary information related to the permitted processing in order to fulfill the obligations provided for by law.
-
Data storage, Deletion. Signify shall comply with the retention periods of personal data in accordance with the rules and purposes protected by law and the Privacy Policy. In the event that the purpose of data storage no longer exists, Signify is obliged to delete/anonymize the relevant personal data. Signify shall make a copy of the personal data obtained within the framework of the Agreement, which will be available to the Customer upon request.
-
-
Obligations of the Customer as the Data Controller
-
Statutory Compliance. The Customer, acting in its capacity as the Data Controller, is obliged to comply with the requirements provided for by the Data Protection Law and this Annex, including when processing special categories of personal data (if any).
-
Customer’s Liability. The Customer bears liability for: (i) the lawfulness of data processing, including compliance of data processing with the requirements specified in the legislation and/or the legal grounds for permitted processing; (ii) providing information to data subjects and/or obtaining appropriate consent from data subjects regarding data processing; (iii) using the Platform, Services and/or documents that the Customer sends/uploads/signs/archives/reads/stores/deletes via the Platform; (iv) recording processes/actions related to data processing; and (v) if necessary, complying with relevant requirements prior to data processing. Additionally, the Customer is responsible for the protection and security of personal data during the Customer’s use of the Signify Services.
-
Rights of Data Subjects. The Customer shall obliged to respond to the requests of data subjects in accordance with the procedure and within the time limit provided for by law. The liability of Signify, as a Data Controller, with respect to the requests of data subjects is limited only to the obligation specified in Article 2.7 of this Annex.
-
-
Incident
-
Signify shall protect the security of Personal Data and the rights of data subjects, as well as to prevent incident(s) (including a breach of personal data security that leads to unlawful or accidental damage, loss, as well as unauthorized disclosure, destruction, alteration, access to, collection/retrieval of or other unauthorized processing of personal data (hereinafter referred to as an “Incident”)), to implement organizational and technical measures appropriate to the potential and inherent threats to the processing of Personal Data, taking into account the nature of the Personal Data and the risks associated with the Personal Data subjects.
-
Signify is obliged to notify the Customer of a personal data incident immediately, but no later than 24 hours after the incident indicating the following information:
-
the circumstances, nature and time of the incident;
-
the personal data affected by the incident, including the estimated categories and amount of personal data that were unauthorizedly disclosed, damaged, deleted, destroyed, accessed, lost, altered as a result of the incident, as well as the estimated categories and amount of data subjects who were at risk as a result of the incident;
-
the measures taken or planned by Signify to mitigate or eliminate the likely damage caused by the incident;
-
the details of the personal data protection officer or other contact person.
-
-
Signify shall maintain confidentiality of the incident and not to disclose and/or transfer information about the incident to third parties, except as required by law.
-
Signify shall immediately take measures to eliminate the incident and its causes and to inform the Customer about the measures taken. If requested by the Customer, Signify shall provide assistance to the Customer in responding to the incident and fulfilling its obligations under the law, including the notification obligation.
-
-
Signify Personnel and Subcontractors
-
Any Signify employee who will participate in the processing of personal data is obliged not to exceed the scope of the authority granted to him. In addition, Signify is obliged to ensure that such employee is required to maintain the confidentiality of Personal Data, including after the termination of his/her official authority.
-
Signify is entitled only in certain cases and with the prior written consent of the Customer to involve sub-contractors in the processing of Personal Data, to which the conditions set out in this Agreement shall apply without any restrictions. The involvement of a sub-contractor in the processing of personal data does not relieve Signify of its obligations and does not limit its liability for damage arising from the violation of such obligations.
-
The Parties declare and explicitly confirm that, as of the date of execution of this Agreement and the Annex, Signify uses the services of the subcontractors listed at the following link: https://signifyapp.com/en-GL/policies/privacy-policy/#subprocessors. Accordingly, on the basis of this Annex, the Customer grants Signify the authority to provide the Services through the sub-contractors specified in this Article. In the event of a change in the aforementioned subcontractors and/or the engagement of a new sub-contractor by Signify, Signify shall notify the Customer in writing (including electronically) about the engagement/change of the relevant sub-contractor at least 30 (thirty) days prior to the implementation of such engagement/change.
-
In the event that the Customer continues to use the Platform in the event of a change in sub-contractors and/or the engagement of a new subcontractor by Signify, this shall be deemed as the Customer’s consent to the engagement of a new subcontractor and/or the change in subcontractor.
-
-
Data Disclosure
-
When disclosing Personal Data, Signify shall ensure the registration and provision to the Customer (if requested by the Customer): which personal data were disclosed, to whom, when and on what legal basis. This information will be stored together with the Personal Data about the personal data subject for the period of their storage.
-
Signify shall immediately inform the Customer in the event of any third party, including the data subject(s) and the relevant data protection supervisory authority, refers to Signify in relation to the personal data. If requested by the Customer, Signify shall provide reasonable assistance to the Customer in taking measures to respond to the requests of third parties.
-
-
Termination of Data Processing
-
Issues related to the termination of Personal Data processing are governed by the Privacy Policy.
-
The obligations set out in this Annex regarding the processing of Personal Data shall remain in force after the termination of the contractual relationship between the parties for the period for which Signify retains access to the personal data.
-
-
Communication
-
In the event of any request and/or question regarding data processing, the Customer is entitled to contact Signify at the following e-mail address: privacy@signifyapp.com or use the Signify support service available at the following link: https://signifyapp.com/en-GL/help/
-
List of Subcontractors
| Name | Address | Country | Service description |
| Amazon Web Services EMEA SARL, ("AWS Europe") | 38 avenue John F. Kennedy, L-1855 Luxembourg | Luxembourg | Cloud infrastructure and hosting services |
| MagtiCom LLC | 7 A. Politkovkaya st. Tbilisi, Georgia | Georgia | Outbound SMS service (Georgia) |
| Twilio Ireland Limited | 70 Sir John Rogerson's Quay, Dublin 2, Dublin, Ireland D02R296 | Ireland | Outbound SMS service (Global) |
| Cellfie Mobile LTD | 8 Bambis rigi, Tbilisi, Georgia | Georgia | Outbound SMS service (Georgia) |
| Identomat Inc. | 60 Hazelwood Dr, Champaign, IL 61820 USA | USA | Remote identification & ID verification services |
| Zendesk Global Limited | 55 Charlemont Pl Saint Kevin's, Dublin D02 F985, Ireland | Ireland | Customer support & chat |
| Google Cloud EMEA Limited | 70 Sir John Rogerson’s Quay Dublin 2, Ireland | Ireland | AI Data Extraction |
Data Retention Chart
| Processing | Purposes | Data category | Legal basis | Retention period |
| Customer information management | Account creation/authorization/account activation/transaction management/controlling subscription cycle and account usage/inviting new customers/fulfilling customer requests, identifying products and services of interest and providing this information to customers/developing new ways of collaboration and business development | Contact information, socio-demographic, transaction-related, behavioral data, technological, communication, location-related data |
Customer consent; Contractual obligation; Signify's legitimate interests; Signify's statutory obligation |
During the contractual relationship |
| Financial management | Invoice preparation/payment/payment check/debtors | Contact information, socio-demographic, transaction-related, behavioral data, technological, communication, location-related data | Contract | During the contractual relationship, plus ten (10) years from the expiry date |
| Customer support | Customer support/ensuring technical seamlessness/for customer protection and fraud prevention/to manage risks associated with signify and its customers/to comply with laws and regulations relevant to signify/to respond to complaints and find ways to resolve them | Contact information, socio-demographic, transaction-related, behavioral data, technological, communication, location-related data | Contract, our legitimate interests, our statutory obligation | During the contractual relationship, plus ten (10) years from the expiry date |
| Marketing activities and communication/business development | Feedback research | Contact information, socio-demographic, transaction-related, behavioral data, technological, communication, location-related data |
Customer consent/Signify's legitimate interest | Data is retained until consent is withdrawn or as long as necessary to process client feedback |
| Email notification of product updates | During the contractual relationship or until consent is withdrawn | |||
| Communication (via email or other form of communication) about new products and services with potential clients or individuals | In the case of a customer: for the duration of the contractual relationship. In other cases: three (3) years from the last communication or until consent is withdrawn | |||
| Creating a mailing list | In the case of a customer: for the duration of the contractual relationship. In other cases: three (3) years from the last communication or until consent is withdrawn | |||
| Managing account cancellation lists | Three (3) years from the account cancellation request | |||
| Sending invitations to events | During the event plus six (6) months after completion or until consent is withdrawn |