SIGNBY KODAR

DRAFT · PENDING LEGAL REVIEW

Data Processing Agreement

This DPA forms part of the Terms and sets out how Kodar OÜ (the “Processor”) processes personal data on behalf of a customer workspace (the “Controller”) under Article 28 of the GDPR.

LAST UPDATED 9 July 2026 · Kodar OÜ · Tallinn, Estonia

01Roles

The Controller is the customer whose workspace uploads documents and invites signers. The Processor is Kodar OÜ. The Processor processes personal data only on the Controller's documented instructions, which include using the platform as designed.

02Subject-matter and scope

Subject-matter
Providing the e-signing platform and collecting qualified electronic signatures.
Duration
For the term of the customer's use of the service.
Nature & purpose
Storing documents, collecting signatures, sealing ASiC-E containers, notifications, and audit logging.
Data subjects
The customer's users and the signers they invite.
Categories of data
Names, national identity codes, emails, phone numbers, certificates, signatures, and document/event metadata.

03Processor obligations

The Processor will: process only on documented instructions; ensure persons authorised to process are bound by confidentiality; implement appropriate technical and organisational security measures (Art. 32); assist the Controller with data-subject requests and with Art. 32–36 obligations; and, at the Controller's choice, delete or return personal data at the end of the service, save where retention is legally required.

04Sub-processors

The Controller authorises the Processor to engage sub-processors under written terms no less protective than this DPA. Current sub-processors include the platform's hosting and email providers, the payment provider (Montonio), and the trust service provider (SK ID Solutions AS). The Processor will give notice of intended changes and allow reasonable objection.

05International transfers

Processing takes place in the EU/EEA. Any transfer outside the EEA is covered by an adequacy decision or Standard Contractual Clauses with supplementary measures as needed.

06Security and breach notification

The Processor maintains measures appropriate to the risk and, on becoming aware of a personal-data breach affecting the Controller's data, notifies the Controller without undue delay with the information needed for the Controller to meet its Art. 33/34 obligations.

07Audit

The Processor makes available information necessary to demonstrate compliance with Art. 28 and allows for and contributes to audits, including inspections, conducted by the Controller or an auditor it mandates, subject to reasonable confidentiality and scheduling.

08Contact

Data-protection queries and requests to conclude a signed copy of this DPA: privacy@kodar.io.

Questions about this document? Contact privacy@kodar.io. See also our Privacy Policy, Terms, DPA, and Cookie Policy.

SIGN BY KODAR© 2026 · Tallinn, EstoniaeIDAS QUALIFIED · EE · LV · LT