Data Processing Addendum
Last updated: 11 July 2026
Version 2.0 | Incorporated into the Business Terms (clause 2.1) | Effective from 11 July 2026
1. Background and relationship to the Agreement
1.1 This Data Protection Addendum (DPA) forms part of, and is incorporated into, the Business Terms between you (the Customer) and N90 Labs Limited, a company registered in England and Wales (company number 17006232) whose registered office is at 71-75 Shelton Street, Covent Garden, London WC2H 9JQ (the Supplier, we or us) (the Agreement). Terms defined in the Agreement have the same meaning in this DPA unless defined differently here.
1.2 This DPA records the terms on which the Supplier processes personal data on the Customer’s behalf in connection with the Subscribed Services. Where there is any inconsistency on a data-protection matter, this DPA prevails over the rest of the Agreement (other than the Standard Pricing Terms as to price and plan-specific matters), consistent with the order of priority in clause 2.2 of the Agreement. This DPA applies to the Supplier’s processing of Customer Personal Data that is subject to the UK GDPR and/or, where applicable, the EU GDPR.
1.3 This DPA takes effect on the Effective Date of the Agreement and continues for as long as the Supplier processes Customer Personal Data.
2. Definitions
2.1 In this DPA:
Data Protection Laws means all laws relating to data protection and privacy that apply to the processing under this DPA, including the UK GDPR (as defined in section 3(10) of the Data Protection Act 2018), the Data Protection Act 2018 (DPA 2018), the Privacy and Electronic Communications (EC Directive) Regulations 2003 (PECR), and the Data (Use and Access) Act 2025 (DUAA) to the extent in force, together with any guidance and codes of practice issued by the Information Commissioner’s Office (ICO). Where the processing is subject to it, Data Protection Laws also includes Regulation (EU) 2016/679 (the EU GDPR) and applicable EU member-State data-protection law, together with guidance and codes issued by a competent EU supervisory authority.
controller, processor, data subject, personal data, processing, personal data breach and supervisory authority have the meanings given in the UK GDPR. Where the EU GDPR applies to the processing, those terms also bear the meanings given in the EU GDPR.
Customer Personal Data means the personal data contained within the Customer Data that the Supplier processes as processor on the Customer’s behalf in providing the Subscribed Services, as described in Annex 1.
Sub-processor means any third party engaged by the Supplier to process Customer Personal Data.
Recipient means a person to whom a completed copy of a signed Document is sent through the Subscribed Services, without being a Signatory.
Data-Protection Losses means all liabilities, claims, demands, actions, proceedings, losses, damages, compensation, costs and expenses (including reasonable legal and professional costs), and — to the extent permitted by law — administrative fines and penalties, in each case arising out of or in connection with any breach of the Data Protection Laws or of this DPA.
UK Addendum means the International Data Transfer Addendum to the EU Standard Contractual Clauses issued by the ICO; and IDTA means the International Data Transfer Agreement issued by the ICO. EU GDPR means Regulation (EU) 2016/679 (General Data Protection Regulation); and EU SCCs means the standard contractual clauses approved by European Commission Implementing Decision (EU) 2021/914.
3. Roles of the parties
3.1 The parties acknowledge that, for the Customer Personal Data described in Annex 1, the Customer is the controller and the Supplier is the processor. This includes the contents of Documents the Customer uploads, and the names, email addresses and (where used) mobile numbers of Signatories and Recipients that the Customer provides.
3.2 The Supplier acts as an independent controller — not as processor — for the limited personal data described as such in its Privacy Policy (squigggle.io/privacy), namely: the Customer’s own account and administration data; the verification and audit-trail data the Supplier generates to evidence a signature (such as one-time-passcode events, timestamps, IP addresses and user agents); and data processed for security, fraud prevention, billing and analytics. This DPA does not apply to that processing, which the Supplier carries out under its Privacy Policy. The parties agree this reflects the Supplier’s need to maintain the independent evidential integrity of signatures and audit trails.
3.3 Each party shall comply with its own obligations under Data Protection Laws. The Customer warrants that it has a lawful basis for the processing it instructs, that it has provided all notices and (where required) obtained all consents needed for the Supplier to process Customer Personal Data as contemplated by the Agreement, including in relation to Signatories and Recipients. Where Customer Personal Data includes special-category personal data (Article 9 of the UK GDPR and the EU GDPR) or personal data relating to criminal offences (Article 10), the Customer warrants that it has a lawful basis and, where required, an Article 9 condition for that processing, and remains responsible for it.
4. Processing on documented instructions
4.1 The Supplier shall process Customer Personal Data only on the Customer’s documented instructions (including as to international transfers), unless required to do otherwise by law that applies to the Supplier; in which case the Supplier shall, where that law permits, inform the Customer first. In addition, the Supplier shall not sell Customer Personal Data, and shall not process it for its own purposes, for cross-context behavioural advertising, or otherwise outside the direct business relationship with the Customer, except as necessary to provide the Services or as required by law. This does not restrict the Supplier’s processing of the data for which it is an independent controller under clause 3.2.
4.2 The Agreement, this DPA (including Annex 1), and the Customer’s configuration and use of the Subscribed Services through its Authorised Users, constitute the Customer’s complete documented instructions. The Supplier shall inform the Customer if, in its opinion, an instruction infringes Data Protection Laws.
5. Confidentiality of personnel
5.1 The Supplier shall ensure that persons authorised to process Customer Personal Data are subject to an appropriate duty of confidentiality and process the data only as instructed.
6. Security
6.1 Taking into account the state of the art, the costs of implementation, and the nature, scope, context and purposes of processing, as well as the risk to individuals, the Supplier shall implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk, as described in Annex 2. These include encryption of Customer Personal Data at rest and in transit, access controls, and cryptographic integrity protection of signed Documents (ECDSA P-256 and SHA-256 hashing).
7. Sub-processors
7.1 The Customer gives the Supplier general written authorisation to engage Sub-processors to process Customer Personal Data. The current Sub-processors, with each one’s purpose, location and transfer safeguard, are listed at squigggle.io/legal/sub-processors and in Annex 3.
7.2 The Supplier shall give the Customer at least 30 days’ notice of any intended addition or replacement of a Sub-processor (by updating that page and, where the Customer has subscribed to notifications, by notice), during which the Customer may object on reasonable data-protection grounds. If the parties cannot resolve a reasonable objection, the Customer may terminate the affected Subscribed Services.
7.3 The Supplier shall impose on each Sub-processor, by written contract, data-protection obligations no less protective than those in this DPA, and remains liable to the Customer for each Sub-processor’s performance.
8. Assistance with data-subject rights
8.1 Taking into account the nature of the processing, the Supplier shall assist the Customer by appropriate technical and organisational measures, insofar as this is possible, to fulfil the Customer’s obligation to respond to requests by data subjects exercising their rights under Chapter III of the UK GDPR (including access, rectification, erasure, restriction, portability and objection). Where the EU GDPR applies, this clause applies equally to the equivalent data-subject rights under the EU GDPR.
8.2 The Supplier shall: (a) promptly notify the Customer if it receives a request directly from a data subject relating to Customer Personal Data, and shall not respond to that request itself except on the Customer’s documented instructions or as required by law; and (b) make available within the Subscribed Services, or otherwise provide reasonable assistance enabling the Customer, to locate, access, export, correct and delete Customer Personal Data.
8.3 The parties acknowledge that, under the DUAA, a controller’s search in response to an access request need only be reasonable and proportionate, and the response period may be paused while the controller verifies the requester’s identity or seeks clarification. The Supplier’s assistance under this clause 8 shall be consistent with that standard.
9. Assistance with data-subject complaints (section 164A DPA 2018)
9.1 The Supplier shall provide the Customer with reasonable assistance to enable the Customer to comply with its duty under section 164A of the DPA 2018 (as inserted by the DUAA) to facilitate the making of, and to acknowledge and respond to, complaints by data subjects about the processing of their personal data.
9.2 In particular, the Supplier shall: (a) without undue delay forward to the Customer any complaint or communication it receives directly from a data subject that concerns the Customer’s processing of Customer Personal Data, and shall not respond on the substance itself (beyond acknowledging receipt and directing the individual to the Customer) unless the Customer instructs otherwise or the law requires; (b) provide the Customer, on request, with information in the Supplier’s possession that the Customer reasonably needs to acknowledge such a complaint within the statutory period (currently 30 days) and to investigate and respond without undue delay; and (c) not hold itself out to data subjects as responsible for handling complaints that are the Customer’s responsibility as controller.
9.3 Where a complaint concerns personal data for which the Supplier is the controller under clause 3.2, the Supplier shall handle it under its own Privacy Policy and complaints process, and shall keep the Customer reasonably informed where the complaint also touches the Customer’s processing.
10. Personal data breaches, DPIAs and prior consultation
10.1 The Supplier shall notify the Customer without undue delay, and in any event within 72 hours, after becoming aware of a personal data breach affecting Customer Personal Data, and shall provide the Customer with sufficient information, as it becomes available, to enable the Customer to meet its own breach-notification obligations to the ICO and to affected data subjects. Where the EU GDPR applies, references in this clause to the ICO include the relevant EU supervisory authority.
10.2 Taking into account the nature of the processing and the information available to it, the Supplier shall provide the Customer with reasonable assistance with data protection impact assessments and any prior consultation with the ICO under Articles 35 and 36 of the UK GDPR.
11. International transfers
11.1 The Supplier shall not transfer Customer Personal Data outside the United Kingdom except where an appropriate safeguard for the transfer is in place — a UK adequacy regulation, the IDTA, or the UK Addendum to the EU Standard Contractual Clauses — or another lawful transfer mechanism under Data Protection Laws. The safeguard applying to each Sub-processor is identified at squigggle.io/legal/sub-processors. The Supplier provides the Subscribed Services to customers in the United Kingdom, and Customer Personal Data originates in the United Kingdom; transfers therefore rely on the UK safeguards described above. If the Supplier begins providing the Subscribed Services to customers established in the European Economic Area, or otherwise processes Customer Personal Data originating in the EEA, the parties shall put in place the EU SCCs (Module Two (controller to processor), or Module Three (processor to processor), as applicable), or another lawful transfer mechanism under the EU GDPR, at that time — with Annexes 1, 2 and 3 to this DPA populating the corresponding annexes.
12. Return or deletion on termination
12.1 On the end of the provision of the Subscribed Services relating to processing, the Supplier shall, at the Customer’s choice, delete or return all Customer Personal Data and delete existing copies, unless the law requires the Supplier to keep it.
12.2 The Customer acknowledges that, as set out in the Agreement and the Privacy Policy, the Supplier retains the audit trail and certificate of completion for each signed Document as an evidential record for 7 years from completion (and up to 12 years for a signed deed), retains the signed Document files for 2 years from closure of the Customer’s account (and longer where the law requires), and retains certain records for longer where the law requires. Such retained data continues to be protected under this DPA until deleted, and residual copies in isolated encrypted backups are deleted on the Supplier’s ordinary backup cycle (currently within 7 days).
13. Records, information and audit
13.1 The Supplier shall make available to the Customer information reasonably necessary to demonstrate compliance with Article 28 of the UK GDPR and this DPA, and shall allow for and contribute to audits, including inspections, conducted by the Customer or an auditor it mandates. References to Article 28 of the UK GDPR include Article 28 of the EU GDPR where it applies.
13.2 To protect the security and confidentiality of the Supplier’s systems and its other customers’ data, audits shall take place on at least five Business Days’ prior written notice, not more than once in any 12-month period (unless required by a supervisory authority or following a personal data breach), during business hours, and subject to reasonable confidentiality and security conditions. The Supplier may satisfy an audit request by providing a current third-party audit report or certification where available.
14. Liability
14.1 Each party’s liability arising out of or in connection with this DPA is subject to the exclusions and limitations of liability set out in the Agreement.
Annex 1 — Details of the processing
Subject matter: provision of the Subscribed Services (electronic-signature platform) under the Agreement.
Duration: for the term of the Agreement, plus the evidential and legal retention periods described in clause 12.2.
Nature and purpose: hosting, storage, transmission, processing and display of Documents and signer data to enable documents to be sent, verified, signed and returned, and to generate and preserve audit trails and certificates of completion.
Types of personal data: names; email addresses; mobile numbers (where SMS/WhatsApp delivery is used); signature images; and any personal data contained within the contents of the Customer’s Documents (which the Customer controls and may include special category data if the Customer chooses to upload it).
Categories of data subjects: the Customer’s Authorised Users; Signatories; Recipients; and any individuals whose personal data appears in the Customer’s Documents.
Annex 2 — Technical and organisational measures
The Supplier maintains at least the following measures:
- Encryption of Customer Personal Data in transit (TLS) and at rest.
- Cryptographic integrity protection of signed Documents using ECDSA P-256 signing and SHA-256 hashing, with tamper-evident certificates of completion and a platform seal.
- Role-based access controls, least-privilege access, and authentication controls for personnel.
- Network and application security controls, logging and monitoring, and regular security assessments.
- Routine encrypted backups used only for business continuity and disaster recovery, isolated from the live environment.
- Organisational measures: confidentiality obligations on personnel, and vendor due diligence on Sub-processors.
Annex 3 — Sub-processors
The current list of Sub-processors — including each one’s purpose, the personal data it processes, its location and the international-transfer safeguard — is maintained at squigggle.io/legal/sub-processors and presently includes:
- Supabase (database, storage and authentication);
- Vercel (application hosting and compute);
- Resend (transactional email, including one-time passcodes);
- Stripe (payments);
- Sentry (error monitoring);
- Google Cloud (document conversion);
- PostHog (product analytics and masked session replay);
- Google Workspace (Gmail — support-email inbox);
- Linear (support-ticket management); and
- Anthropic (AI-assisted triage of support requests).
Document control
Version 1.0 — March 2026 (superseded)
Version 2.0 — 11 July 2026 (current version)