1. Overview
When your organization uses Sigigo to capture and store evidence records that contain personal data, Sigigo generally acts as a data processor and your organization acts as the data controller (or processor acting on behalf of another controller).
Our Data Processing Agreement (DPA) incorporates GDPR Article 28 requirements and, where applicable, UK GDPR processor terms. It is available to customers upon request and is included in enterprise order forms.
2. Subject matter and duration
Processing is limited to providing evidence infrastructure services — ingesting signed events, storing metadata and configured payloads, batching, verification, export, and retention according to your tenant configuration for the term of your subscription.
3. Nature and purpose of processing
Processing supports audit, compliance, security, and operational evidence programs — including EU AI Act Article 12 logging, deployer oversight records, and EU Data Act access/share evidence when you configure relevant event types.
- Ingest and store event envelopes, signatures, hashes, and optionally canonical payloads.
- Generate Merkle batches, verification proofs, and export packages.
- Apply retention, erasure, and legal hold policies per your instructions.
- Operate Private Commitment Mode where only commitments and public metadata are stored on Sigigo systems.
4. Categories of data and subjects
Categories depend on your implementation. They may include identifiers, professional data, inference metadata, transaction references, and other fields you choose to log. Data subjects may include your employees, customers, applicants, or other individuals affected by your systems.
You control what is logged. Sigigo provides configuration, minimization guidance, and commitment mode to reduce processor scope.
5. Processor obligations
Sigigo commits to:
- Process personal data only on documented instructions from the controller, including regarding international transfers.
- Ensure personnel confidentiality and appropriate training.
- Implement Article 32 security measures proportionate to risk.
- Assist with data subject requests, DPIAs, and supervisory authority inquiries as required by law and contract.
- Delete or return personal data at end of service, subject to legal retention and integrity requirements.
- Make available information necessary to demonstrate compliance and allow audits on reasonable notice.
- Notify the controller without undue delay after becoming aware of a personal data breach.
6. Sub-processors
We use infrastructure and service providers to deliver the platform. A current list is published on our Sub-processors page. We impose data protection terms on sub-processors and notify customers of material changes per the DPA.
7. International transfers
Where processing involves transfers from the EEA, UK, or Switzerland, we offer EU region deployment and Standard Contractual Clauses. Customers may restrict processing locations through sovereignty profiles documented in order forms.
8. Request a DPA
Email legal@sigigo.com with your company name, contact details, and deployment region. We will provide our standard DPA for signature or review alongside your order form.