Legal

Data Processing Addendum

Version 2026.09 · effective 22 August 2026

Who this is for. Every notary and firm with a workspace here. Your clients' documents and signers are yours: you decide what happens to them, we carry out your instructions. This is the agreement that says so, and it applies automatically — you do not need to sign or request it.

1 · Parties and scope

This addendum forms part of the Terms of Service between you (“Customer”, the controller) and Self Service Notary, operated at selfservicenotary.com (“Processor”). It applies whenever we process personal data on your behalf, and it takes effect when you accept the Terms — no separate signature is needed. Where it conflicts with the Terms on data protection, this addendum wins.

It uses the meanings given in the EU General Data Protection Regulation (GDPR) and, where it applies to you, the UK GDPR.

2 · What we process, and why

Subject matter: providing the signing, sealing, notarisation, verification and portal services described in the Terms. Duration: for as long as your account is open — deletion follows closure immediately, and export is available at any time beforehand. Nature and purpose: storage, encryption, rendering, sealing, transmission, hashing, the delivery of invitations, results and text messages, and — where enabled — drafting an advisory summary from a job's own activity, never from the contents of a document.

Categories of data subject: your clients, signers, witnesses, and the people you invite into your workspace. Categories of personal data: names, email addresses, phone numbers where given, the contents of documents you or your clients upload, appointment details, IP addresses and device information in audit records, and session recordings where you use live video. Special categories: photo-ID images and liveness capture — biometric data used to identify a person — where an identity check is requested.

3 · Our obligations

  • We process personal data only on your documented instructions — which include your use of the product's features — unless the law requires otherwise, in which case we tell you first unless that law forbids it.
  • Everyone with access is bound by confidentiality.
  • We keep the security measures in section 4 and do not weaken them during the term.
  • We help you meet your own obligations: responding to data-subject requests, keeping data secure, notifying breaches, and carrying out impact assessments — with the information we actually hold.
  • We tell you without undue delay after becoming aware of a personal data breach affecting your data — and, where feasible, within 72 hours — with what we know and what we are doing about it.
  • You can export your data at any time while the account is open. On closure we delete or return it immediately, except for what the law requires us to keep and for the ledger entries described in section 7 — so export before you close.
  • We make available the information needed to show compliance with this addendum, and allow audits of it — satisfied first by our documentation and answers, and by an on-site audit only where that is genuinely insufficient.

4 · Security measures

  • Documents are encrypted at rest under a key derived per workspace and held by us as your processor, so that we can render, seal and deliver them; a raw read of the underlying storage returns ciphertext. This is not end-to-end encryption, and we do not describe it as such.
  • Identity evidence is encrypted under a separate key and is not embedded in any sealed document.
  • All traffic is encrypted in transit under a strict browser security policy; sessions are bound to a single domain, so one tenant's domain cannot carry another's session.
  • Access to a workspace is scoped to its owner and the members that owner invites, with roles that limit what each of them may do.
  • Every consequential action is written to an append-only audit trail, and the integrity of a sealed document is independently checkable against a published key.
  • Storage in the EU jurisdiction is available for documents and identity evidence in workspaces that require it. Service metadata is processed globally; a session recording is captured by the video provider and moved into that storage afterwards.
  • Retention controls are yours to set where a retention period is a choice, and are honoured.

5 · Sub-processors

You give us general authorisation to engage the sub-processors listed at Sub-processors. We impose data protection obligations on each of them no less protective than these, and we remain responsible to you for what they do. We update that page at least 14 days before a new sub-processor starts processing your data; if you object on reasonable data protection grounds within that period, tell us and — where we cannot offer an alternative — you may terminate the affected service.

6 · International transfers

Where personal data is transferred out of the EEA or the UK, we rely on the safeguards in our agreements with the receiving provider, including the European Commission's standard contractual clauses — module two, controller to processor — and the UK International Data Transfer Addendum to them, where they apply. Where the Swiss FADP applies, those clauses are read with the amendments its authority requires. Self Service Notary is established in United Arab Emirates; EU-residency storage is available where you need documents and identity evidence to stay in the EU.

7 · The ledger, and what deletion cannot reach

Sealing writes a cryptographic hash and a signed claim into an append-only ledger. That entry contains no document, no file name and no document contents — a hash cannot be reversed into the thing it was computed from. It is also permanent: a chain that could be edited would prove nothing, and printed QR codes must keep verifying for years. Deleting a document removes the document; revoking it changes the verdict a verifier sees. Neither erases the entry, and you should tell the people whose documents you seal that this is how the proof works.

8 · Contact

Data protection questions and requests under this addendum: privacy@selfservicenotary.com.