Legal document — United States

Data Processing Addendum (DPA)

This Data Processing Addendum forms part of the Terms of Service (United States) and applies to business customers (organizations) that use Kligrafia to process the personal data of third parties — signers, employees, or their own end customers.

Last updated:
July 22, 2026
Effective date:
July 22, 2026

1. Purpose and scope

A growing number of U.S. state comprehensive privacy laws — including the California Consumer Privacy Act as amended by the California Privacy Rights Act (CCPA/CPRA), and the analogous processor-contract requirements of the Virginia Consumer Data Protection Act (VCDPA), the Colorado Privacy Act (CPA), the Connecticut Data Privacy Act (CTDPA), and the Texas Data Privacy and Security Act (TDPSA) — require a written contract between a business and any “service provider” or “processor” it engages to process personal data on its behalf. This document (the “DPA”) is that contract: it governs the processing of personal data that Those Who Build Dreams, Inc. (the “Processor” or “Kligrafia”) carries out on behalf of the business customer (the “Controller” or the “Customer”) in connection with the Kligrafia service in the United States.

This DPA applies automatically when an organization subscribes to a Kligrafia plan that involves processing the personal data of third parties, and is incorporated by reference into the Terms of Service. For individually negotiated arrangements (custom clauses, specific indemnities, or sector-specific addenda), contact us at [email protected].

2. Definitions

Terms defined under applicable U.S. state privacy law keep their statutory meaning. In particular:

  • Consumer / data subject: the individual whose personal data is processed.
  • Controller / business: the party that decides the purposes and means of processing — here, the Customer.
  • Processor / service provider: the party that processes personal data on the Controller's behalf — here, Kligrafia.
  • Subprocessor: a third party engaged by the Processor to carry out specific processing tasks.
  • Sell / share: have the meanings given to those terms under the CPRA; Kligrafia does neither with personal data processed under this DPA.
  • Security incident: any breach of security leading to the unauthorized destruction, loss, alteration, or access to personal data.
  • Documented instructions: the Controller's instructions set out in this DPA, the Terms of Service, and the account configuration within the platform.

3. Roles of the parties

The Customer acts as Controller of the personal data it uploads, manages, or processes through the platform (including, in particular, the data of the signers it invites). Kligrafia acts as Processor with respect to that data, limiting itself to processing it in accordance with the Customer's documented instructions.

With respect to the Customer's own account data (billing data, data of the Customer's own member users, and operational telemetry), Kligrafia acts as Controller, and those operations are governed by our Privacy Policy.

4. Nature and purpose of processing

Kligrafia will process the Customer's personal data for the following purposes only, limited to what is strictly necessary to provide the Service:

  • enabling electronic signature of documents by the Customer and its invited signers;
  • verifying the identity of signers (KYC) and performing liveness checks;
  • generating auditable evidence of each transaction (audit trail, timestamp, evidence report) with evidentiary value under the ESIGN Act and UETA;
  • securely storing documents and related artifacts;
  • providing AI-assisted analysis features when the Customer enables them;
  • responding to support requests from the Customer or its users;
  • complying with legal obligations applicable to the Processor.

Kligrafia will not process the Customer's data for any purpose other than those listed here without the Controller's prior, documented instruction, and will not sell that data or share it for cross-context behavioral advertising, and will not combine it with personal data received from other sources except as permitted by applicable law.

5. Categories of data and data subjects

Data subjectCategories of data
The Customer's usersName, email, role, encrypted password, MFA data, sessions, activity logs.
Signers invited by the CustomerName, email, government ID number, document image, liveness selfie, derived biometric vectors (sensitive personal information), IP address, user-agent, timestamp.
Content of the documentsAny personal data the Customer chooses to include in the uploaded PDFs.

6. Duration

This DPA remains in effect for as long as the Customer maintains an active Kligrafia subscription. Obligations that by their nature must survive (confidentiality, legal retention, defense of legal rights) continue after termination.

7. Processor obligations

As Processor, Kligrafia commits to:

  • process data exclusively in accordance with the Controller's documented instructions;
  • bind personnel with access to personal data to a duty of confidentiality;
  • apply the technical and organizational measures described in Section 9;
  • not sell personal data, not share it for cross-context behavioral advertising, and not retain, use, or disclose it for any purpose outside the direct business relationship with the Controller;
  • promptly notify the Controller of any legally binding request for disclosure of personal data by a government authority, unless legally prohibited from doing so;
  • reasonably assist the Controller in meeting its obligations under applicable state privacy law, including responding to consumer requests (Section 10) and cooperating with a state regulator when legally required to do so;
  • delete or return personal data at the end of the engagement, per Section 14;
  • not engage a new subprocessor for the processing described in this DPA without providing the notice described in Section 8.

8. Subprocessors

The Customer generally authorizes Kligrafia to use the following subprocessors, with each of whom Kligrafia has entered into a contract imposing data-protection obligations equivalent to those in this DPA. Among them, U.S.-based document and database hosting and identity verification are the subprocessors most directly relevant to the processing described in this DPA:

SubprocessorPurposeCountry
Stripe Inc.Procesamiento de pagos y suscripcionesEE.UU.
Cloudflare R2 (Cloudflare Inc.)Almacenamiento de documentos PDF y reportes de evidenciaEE.UU. / global
Anthropic, PBCModelos de IA para análisis de cláusulas, extracción de campos y chatEE.UU.
TruoraVerificación de identidad (cédula, OCR, biometría con prueba de vida)Colombia / LATAM
ResendEnvío de correos transaccionalesEE.UU.
Proveedor de PostgreSQL gestionadoBase de datos relacional con cifrado en reposo y row-level securityEE.UU. / UE
Autoridad de timestamping (TSA)Sellado de tiempo RFC 3161 para firmas y reportes de evidenciaUE

We will notify the Customer of any new or changed subprocessor at least thirty (30) days in advance. The Customer may object on reasonable grounds; if we cannot reach a resolution, the Customer may terminate its subscription without penalty for the unconsumed portion.

9. Technical and organizational measures

Kligrafia maintains the following measures, reviewed periodically:

  • encryption in transit (TLS 1.2+) and at rest (AES-256);
  • row-level security in the database, segregating data by organization;
  • multi-factor authentication available for administrative roles;
  • identity management on the principle of least privilege;
  • audit logs with a hash chain and extended retention;
  • encrypted backups with periodic restoration testing;
  • vulnerability monitoring across dependencies and environments;
  • a documented business-continuity and disaster-recovery plan;
  • internal incident-management policies and personnel training.

10. Assistance with consumer/data subject requests

When a consumer exercises a privacy right directly with Kligrafia regarding data processed on the Customer's behalf, we will redirect them to the Controller to fulfill the request, unless applicable law requires us to respond directly. Kligrafia will reasonably assist the Controller in responding within the timelines required by applicable state privacy law, including by providing exports, technical deletions, or processing information as needed.

11. Security incident notification

In the event of a security incident affecting personal data processed on the Customer's behalf, Kligrafia will notify the Controller without undue delay, and where feasible within seventy-two (72) hours of becoming aware of the incident, including:

  • the nature of the incident and the categories of data potentially affected;
  • the approximate number of data subjects involved;
  • containment measures taken or planned;
  • mitigation recommendations for the Controller;
  • a point of contact for technical follow-up.

Where applicable law requires a security incident to be reported to a state attorney general or other regulator, Kligrafia will cooperate with the Controller to prepare the technical information needed for that report, without substituting for the Controller's own obligation to make it when the obligation is the Controller's to fulfill.

12. International data transfers

Data processed under this DPA is processed, in whole or in part, on infrastructure located in the United States. A limited number of subprocessors process data outside the United States, as disclosed in Section 8 and further detailed in Section 6 of our Privacy Policy. We require those subprocessors to contractually commit to confidentiality and security obligations consistent with this DPA.

13. Audits

The Customer has the right to reasonably verify compliance with this DPA. To avoid interfering with operations, audits are preferably carried out through (i) delivery of technical compliance reports and, where available, (ii) third-party certifications. On-site audits are reserved for justified cases, with reasonable notice, during business hours, and at the Customer's cost, unless a material breach is found.

14. Return or deletion on termination

At the end of the Service, and at the Controller's election, Kligrafia will return personal data in a structured export format or delete it, except for data that must be retained under a legal obligation (for example, evidence reports during their applicable retention period).

15. Limitation of liability

Aggregate liability under this DPA is subject to the same quantitative limits set out in the Terms of Service (capped at the amounts actually paid during the twelve months preceding the event giving rise to the claim), except where applicable law imposes a stricter, non-waivable standard.

16. Governing law and venue

This DPA is governed by the laws of the [U.S. state of incorporation of Those Who Build Dreams, Inc. — pending], without regard to its conflict-of-laws principles, subject to any mandatory provisions of state privacy law applicable to the processing described in this DPA.