Sign HUB

Data Processing Agreement (DPA)

Sign HUB

Last updated: 22 July 2026

Note: This is the standard Data Processing Agreement template — it is formalized individually with each client. Request a signable copy at [email protected].

This document sets out the Data Processing Agreement (DPA) that HUB DESPACHOS Y PYMES, S.L. (CIF B76816875), acting as processor, offers to its clients (professional firms and businesses) acting as controllers, in compliance with Article 28 of Reglamento (UE) 2016/679 (GDPR) and Ley Orgánica 3/2018 (LOPDGDD).

1. Parties

ControllerThe client that contracts the Sign HUB Platform and sends documents for signature to its own signers.
ProcessorHUB DESPACHOS Y PYMES, S.L. (CIF B76816875), registered address at Avenida Benito Pérez Armas, 2 - PTL 2,6 B, Santa Cruz de Tenerife, España, owner and operator of the Sign HUB Platform.

2. Subject matter, duration, nature and purpose

3. Types of data and categories of data subjects

Categories of data subjects: external signers designated by the controller (the controller's own clients, employees or suppliers) — natural persons who never contract directly with HUB Consultores.

Types of data processed:

4. Obligations of the processor (Art. 28.3 GDPR)

HUB Consultores, as processor, undertakes to:

  1. Documented instructions. Process personal data only in accordance with the controller's documented instructions, including with regard to international transfers, unless required to do otherwise by Union or Member State law, in which case it will inform the controller beforehand, unless the law prohibits this on important grounds of public interest.
  2. Reinforced confidentiality. Ensure that persons authorized to process personal data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality. Given that the client is typically an accounting/legal/tax professional firm bound by its own professional secrecy duties, HUB Consultores applies a reinforced confidentiality standard to the data it processes on the controller's behalf.
  3. Security measures (Art. 32 GDPR). Implement appropriate technical and organizational measures, summarized as: encryption in transit (TLS 1.2+) and at rest (AES-256 + Fernet), immutable WORM storage during the retention period, two-factor identification of the signer (link + email OTP), audit logging of access and critical operations, and access restricted to strictly necessary personnel.
  4. Sub-processors. HUB Consultores has the controller's general written authorization to engage the sub-processors listed in the public Subprocessors List. Any intended addition or replacement will be notified to the controller with at least 30 days' prior notice, during which the controller may object on reasonable, documented grounds relating to data protection. HUB Consultores imposes the same data protection obligations set out in this DPA on every sub-processor by way of a contract, remaining fully liable to the controller for the sub-processor's performance.
  5. Assistance with data subject rights. Taking into account the nature of the processing, assist the controller, insofar as this is possible, by appropriate technical and organizational measures, for the fulfilment of the controller's obligation to respond to requests for exercising data subjects' rights under Chapter III GDPR.
  6. Assistance with security and breaches. Assist the controller in ensuring compliance with the obligations set out in Articles 32 to 36 GDPR (security, breach notification to the supervisory authority and to data subjects, data protection impact assessments and prior consultation), taking into account the information available to HUB Consultores.
  7. Deletion or return of data. At the end of the provision of the signature service, at the controller's choice, delete or return all personal data and delete existing copies, except for the subset of signature evidence (declared identity, IP address, user-agent, timestamps, document hashes and the certificate of evidence), which HUB Consultores retains for a minimum of 5 years in its own capacity as controller, as documented in Section 6 below, on the basis of a legal obligation (Art. 17.3.e GDPR, defence of legal claims; Ley 6/2020 on trust services; Reglamento (UE) 910/2014, eIDAS).
  8. Audits. Make available to the controller all information necessary to demonstrate compliance with the obligations laid down in Article 28 GDPR and allow for and contribute to audits, including inspections, conducted by the controller or another auditor mandated by it, up to once per calendar year, subject to at least 30 days' prior written notice and confidentiality of any information accessed.

5. International transfers

Some sub-processors listed in the Subprocessors List are located in the United States (e.g. email delivery and payment processing providers). Any transfer of personal data to those sub-processors is based on:

No transfer of the signature evidence retained by HUB Consultores as controller (Section 6) is made to sub-processors outside the European Economic Area.

6. Double nature: processor and controller

HUB Consultores acts under two different capacities depending on the data set concerned:

7. Term, amendment and governing law

This DPA is governed by Spanish law and remains in force for as long as HUB Consultores processes personal data on behalf of the controller. Any material change to this template will be published on this page; changes to sub-processors follow the 30-day notice procedure described in Section 4.4.

8. Contact and formalization

This page publishes the standard model of the DPA. To formalize a signed copy tailored to your company, or to raise any query regarding this DPA, please contact [email protected].