SIGNBY KODAR

DRAFT · PENDING LEGAL REVIEW

Data Processing Agreement

This DPA forms part of the Terms and sets out how Kodar Tarkvara OÜ (the “Processor”) processes personal data on behalf of a customer workspace (the “Controller”) under Article 28 of the GDPR.

LAST UPDATED 19 August 2026 · Kodar Tarkvara OÜ · Sõpruse pst 221-10, 13422 Tallinn, Estonia · REG. 17337554

01Roles

The Controller is the customer whose workspace uploads documents and invites signers. The Processor is Kodar Tarkvara OÜ. The Processor processes personal data only on the Controller's documented instructions, which include using the platform as designed.

02Subject-matter and scope

Subject-matter
Providing the e-signing platform and collecting qualified electronic signatures.
Duration
For the term of the customer's use of the service.
Nature & purpose
Storing documents, collecting signatures, sealing ASiC-E containers, notifications, and audit logging.
Data subjects
The customer's users and the signers they invite.
Categories of data
Names, national identity codes, emails, phone numbers, certificates, signatures, and document/event metadata.

03Processor obligations

The Processor will: process only on documented instructions; ensure persons authorised to process are bound by confidentiality; implement appropriate technical and organisational security measures (Art. 32); assist the Controller with data-subject requests and with Art. 32–36 obligations; and, at the Controller's choice, delete or return personal data at the end of the service, save where retention is legally required.

04Sub-processors

The Controller authorises the Processor to engage the sub-processors listed below under written terms no less protective than this DPA. The Processor will give notice of intended changes and allow the Controller a reasonable opportunity to object.

Neon Inc.
Managed PostgreSQL database and, through Neon Auth, the identity store holding account credentials and sessions. EU — AWS eu-central-1 (Frankfurt).
Vercel Inc.
Application hosting, serverless request handling and scheduled jobs. US-incorporated; platform regions per deployment (see transfers).
Object storageNAMED ON REQUEST
S3-compatible object storage for uploaded PDFs and sealed ASiC-E containers. EU/EEA bucket (a deployment requirement).
Validation-engine hostingNAMED ON REQUEST
Hosts the container-validation service that re-checks an uploaded ASiC-E container against the EU Trusted List. It receives the container being validated. Engaged only where container validation is configured. Region set per deployment.
SK ID Solutions AS
Qualified trust service — issues signers' qualified certificates and performs Smart-ID / Mobile-ID signing. Estonia.
Send by Kodar (Kodar Tarkvara OÜ)
Transactional email — signing invitations, reminders and status notices. Estonia; sending worker hosted on Railway Corp. (below).
Railway Corp.
Hosts the Send by Kodar sending worker, which handles recipient names and addresses. US-incorporated; deployment region not confirmed (see transfers).
Montonio
Payment processing for paid workspaces. Card data never reaches our systems. Estonia.

Two entries are marked NAMED ON REQUEST: the object-storage provider and the host of the container-validation service are both fixed per deployment rather than in the platform's source code. The Processor will name the live providers on request at privacy@kodar.io rather than publish a provider it may not be using.

05International transfers

Documents, signer records and the sealed containers are stored in the EU/EEA: the database runs in AWS eu-central-1 (Frankfurt) and the object-storage bucket is required to be in an EU/EEA region.

Two sub-processors are US-incorporated — Vercel Inc., which hosts the application, and Railway Corp., which hosts the Send by Kodar sending worker and therefore handles recipient names and email addresses. Their deployment regions are set per deployment and are not asserted here. Any resulting transfer relies on an adequacy decision or on Standard Contractual Clauses with supplementary measures as needed.

The two sub-processors marked NAMED ON REQUEST above are likewise fixed per deployment: the object-storage bucket is required to be in an EU/EEA region, and the validation-engine host and its region are stated to the Controller on request.

06Security and breach notification

The Processor maintains measures appropriate to the risk and, on becoming aware of a personal-data breach affecting the Controller's data, notifies the Controller without undue delay with the information needed for the Controller to meet its Art. 33/34 obligations.

07Audit

The Processor makes available information necessary to demonstrate compliance with Art. 28 and allows for and contributes to audits, including inspections, conducted by the Controller or an auditor it mandates, subject to reasonable confidentiality and scheduling.

08Contact

Data-protection queries and requests to conclude a signed copy of this DPA: privacy@kodar.io.

Questions about this document? Contact privacy@kodar.io. See also our Privacy Policy, Terms, DPA, and Cookie Policy.

SIGN BY KODAR© 2026 · Tallinn, EstoniaeIDAS QUALIFIED · EE · LV · LT