Data Processing Agreement

Version 1 · 6 October 2026

This agreement governs our processing of personal data on your behalf. It is required by Article 28(3) of the GDPR, and it forms part of the Terms of Service. You accept it when you create an account.

It follows the structure of the European Commission's standard contractual clauses for controllers and processors, adopted by Implementing Decision (EU) 2021/915. Where anything here is less protective than those clauses, the clauses prevail.

The English text is authoritative.


The parties

Controller: you, the business holding the Kavix account. Processor: Yossi Raz trading as Innovago ("Kavix").

You decide what is collected and why. We store and process it on your instructions. Neither of us is the other's controller for this data.

Annex I — the processing

Subject matter. Collecting and storing agreements signed by your customers.

Duration. For as long as your account is open, plus the grace period described in clause 8.

Nature and purpose. Displaying your agreement to the people you send it to; recording their details and their signature; storing the record so that you can prove the agreement was made; sending a copy by email where an address is given.

Categories of data subject. Your customers — the people who sign.

Categories of personal data.

  • name
  • telephone number
  • email address, where given
  • the signature image they draw
  • a national identity number, only if you enable that field and record why you need it
  • technical data captured with the signature: IP address and browser string

Special categories. None. Kavix must not be used to collect data revealing health, religion, political opinion, trade union membership, biometric or genetic data, sex life or orientation. A drawn signature is not biometric data for this purpose; it is not used to identify anyone by its characteristics.

1. Processing only on your instructions

We process this data only on your documented instructions. Your use of the Service is that instruction. We will not process it for our own purposes, and we will never use it to train models, build profiles, or inform anything other than operating the Service for you.

If we believe an instruction breaches data protection law, we will tell you and may decline it.

2. Confidentiality

Everyone with access is bound to confidentiality. In practice that is one person, the operator, and access is used for operating and supporting the Service rather than reading records.

3. Security

The measures in place, stated plainly enough to be checked:

  • Isolation between businesses is enforced by the database. Each row carries its tenant; the database refuses access to any other, regardless of what the application asks for. The application connects as a role that cannot override this.
  • The archive cannot be edited. Changing or deleting a signed record is rejected by the database, not merely avoided by the application.
  • Per-record encryption. Personal data is encrypted with a key unique to that record, wrapped by a key unique to your business, wrapped by a key held outside the database. A copy of the database alone decrypts nothing.
  • Passwords, session tokens and email links are stored only as hashes.
  • Transport encryption on every connection.
  • Rate limits on sign-in and on public signing pages.
  • Hosting in the European Union.

4. Sub-processors

You give general authorisation for the sub-processors listed below. We will give at least 30 days' notice before adding or replacing one, and you may object; if you do and we cannot resolve it, you may terminate and export your data.

Sub-processor Purpose Location
Vercel application hosting Frankfurt, Germany
Neon database Frankfurt, Germany
Brevo (Sendinblue) transactional email France
Google optional sign-in, where the account holder chooses it EU/US

Each is bound by terms no less protective than this agreement. If a sub-processor fails, we answer to you for it — not them.

5. Data subject rights

We will assist you in answering requests from your customers, taking into account the nature of the processing. In practice the Service does most of this for you:

  • access and portability — open or export any record from the archive
  • rectification — a correction is recorded as a new event; history is never rewritten
  • erasure — destroying the record's key renders the personal data permanently unreadable while leaving the proof that an agreement existed

If a request reaches us directly we will not answer it ourselves. We will pass it to you without undue delay, because the answer is yours to give.

Erasure is not automatic. Article 17(3) withdraws the right where processing is necessary for the establishment, exercise or defence of legal claims, and a signed agreement within its limitation period sits there. The Service records refusals with a reason and a date, as it records fulfilments.

6. Personal data breach

We will notify you without undue delay after becoming aware of a breach affecting your data, with what we know: what happened, which categories and roughly how many records, the likely consequences, and what we are doing.

Notifying your supervisory authority within 72 hours is your obligation as controller. We will give you what you need to do it.

7. Assistance with your own obligations

We will help you with data protection impact assessments and prior consultation where our processing is relevant, by supplying accurate information about how the Service works.

8. Deletion or return at the end

When your account or a business closes, you choose: we return the data, or we delete it. Export is always available first, and you should take it — your own retention duty survives leaving, and you cannot meet it from a service you no longer have.

After a grace period of 30 days from closure, the keys are destroyed and the personal data becomes permanently unreadable. The grace period exists so that an accidental or malicious closure can be undone, and so that you have time to collect your export.

We retain no copy afterwards, except the account-level record of which document versions you accepted and when — for which we are the controller, under the Privacy Policy.

9. Audits

We will make available the information needed to demonstrate compliance with this agreement, and allow audits, including inspections, by you or an auditor you appoint. Given the size of the Service, in the first instance that means answering a written questionnaire and providing this documentation; an on-premises inspection is not meaningful for a service with no premises.

10. International transfers

Processing takes place in the European Union. We will not transfer personal data outside the EU/EEA without a lawful transfer mechanism, and we will tell you first.

Israel, where the operator is located, is the subject of a European Commission adequacy decision.

11. Liability and precedence

Where this agreement conflicts with the Terms of Service, this agreement prevails for anything concerning the processing of your customers' personal data.


Kavix, by Innovago — privacy@innovago.com

Drafted after reading Article 28 and the Commission's standard clauses, not by a lawyer. It will be reviewed by one before the Service is offered commercially, and the review will start from the Commission's clauses rather than from this text.