Preamble
JHS Solutions LLC ("Company," "we," "our," or "us") utilizes carefully selected third-party service providers ("Subprocessors" or "Service Providers") to assist in delivering, securing, maintaining, supporting, and improving the Portal Platform™ and related services.
This Policy describes the categories of Service Providers that may process information on behalf of the Company, the safeguards applied when selecting providers, and the Company's approach to vendor management.
This Policy forms part of the Portal Platform Legal Suite™ and should be read together with:
LEGAL-001 — Master Terms of Service;
LEGAL-002 — Privacy Policy;
LEGAL-003 — Communications Policy;
LEGAL-004 — Security Policy;
LEGAL-005 — AI Services Policy;
LEGAL-006 — Electronic Signature Disclosure & Consent;
LEGAL-007 — Cookie Policy;
LEGAL-008 — Acceptable Use Policy;
LEGAL-009 — Trust Center™ Policy;
LEGAL-010 — Record Retention Policy;
LEGAL-011 — Accessibility Statement;
and all other applicable Platform policies.
ARTICLE I — Purpose, Scope and Vendor Management Principles
1.1 Purpose
The purpose of this Policy is to:
promote transparency regarding Service Providers;
explain how Subprocessors support Platform operations;
describe vendor governance practices;
explain data processing responsibilities;
support enterprise compliance reviews;
support customer due diligence;
strengthen trust in the Platform.
1.2 Scope
This Policy applies to all third-party providers supporting:
Portal Platform™;
eSignare®;
Customer Workspace;
Signer Portal;
Administrator Portal;
Trust Center™;
Dispatch Center™;
AI Services;
Enterprise Services;
APIs;
Mobile Applications;
future Company products.
1.3 Definition of Subprocessor
A Subprocessor is a third-party organization engaged by the Company to process, store, transmit, secure, analyze, or otherwise handle information on the Company's behalf in connection with Platform operations.
Not every third-party vendor processes Customer Data. Some providers may only provide infrastructure, software, communications, security, or operational support.
1.4 Vendor Management Principles
The Company seeks to engage providers that demonstrate commercially reasonable standards for:
security;
reliability;
privacy;
operational resilience;
legal compliance;
confidentiality;
business continuity;
customer support.
Vendor management practices evolve as technology and business requirements change.
1.5 Vendor Selection
When selecting Service Providers, the Company may evaluate factors including:
security practices;
privacy practices;
contractual commitments;
operational experience;
service availability;
technical capabilities;
regulatory compliance;
reputation;
financial stability where appropriate.
Selection criteria may vary depending upon the services provided.
1.6 Categories of Service Providers
The Company may utilize providers supporting:
cloud infrastructure;
secure hosting;
document storage;
authentication;
identity verification;
payment processing;
subscription billing;
communications;
email delivery;
SMS messaging;
MMS messaging;
WhatsApp messaging;
push notifications;
artificial intelligence;
machine learning;
optical character recognition (OCR);
translation;
analytics;
customer support;
monitoring;
cybersecurity;
backup services;
disaster recovery;
enterprise integrations;
developer services;
future Platform capabilities.
1.7 Continuous Improvement
The Company reserves the right to add, replace, suspend, or discontinue Service Providers as technology, security requirements, operational needs, customer expectations, or legal requirements evolve.
Updated Subprocessors may be reflected through this Policy or other publicly available Company documentation.
ARTICLE II — Categories of Service Providers, Data Processing and Vendor Governance
2.1 General Use of Service Providers
The Company may engage qualified Service Providers to assist in operating, securing, maintaining, improving, and supporting the Platform.
Service Providers perform only those services reasonably necessary to support the Company's legitimate business operations.
The Company seeks to engage providers that maintain commercially reasonable administrative, technical, organizational, and contractual safeguards appropriate to the services performed.
2.2 Cloud Infrastructure Providers
The Company may utilize cloud infrastructure providers for services including:
application hosting;
virtual servers;
databases;
object storage;
file storage;
networking;
content delivery;
disaster recovery;
scalable computing;
future cloud technologies.
Cloud providers may process information solely for purposes authorized by the Company and subject to applicable contractual obligations.
2.3 Document Storage Providers
The Platform may utilize secure storage providers to maintain:
uploaded documents;
executed documents;
Certificates of Completion™;
Verification records;
audit files;
backups;
archived records;
temporary processing files;
future document repositories.
Storage providers do not determine ownership of Customer Data.
2.4 Communications Providers
The Company may utilize communications providers to transmit:
email;
SMS;
MMS;
WhatsApp messages;
push notifications;
voice notifications where available;
customer support communications;
security alerts;
Multi-Factor Authentication codes;
marketing communications where permitted;
future communication services.
Communications providers process information necessary to deliver requested communications.
Delivery is subject to network availability, carrier policies, recipient device capabilities, spam filtering, and circumstances beyond the Company's reasonable control.
2.5 Payment and Billing Providers
Payment providers may process information relating to:
subscription payments;
invoices;
receipts;
refunds;
payment authorization;
recurring billing;
tax calculations where applicable;
fraud prevention;
financial reporting;
future payment services.
The Company seeks to utilize providers that comply with applicable payment security standards appropriate to their services.
The Company generally does not store complete payment card information when secure third-party payment processing services are used.
2.6 Identity Verification Providers
Where identity verification services are offered, the Company may engage qualified providers to assist with:
identity verification;
document verification;
authentication;
fraud detection;
risk assessment;
account protection;
future identity technologies.
Identity verification providers act as technology service providers and do not make legal determinations regarding identity or authority.
2.7 Artificial Intelligence Providers
The Company may utilize AI providers to support services including:
conversational assistance;
language processing;
translation;
OCR;
document summarization;
intelligent search;
fraud detection assistance;
accessibility;
workflow automation;
future AI functionality.
The Company seeks to engage AI providers that maintain commercially reasonable security and privacy practices.
Use of AI providers remains subject to the Company's AI Services Policy and Privacy Policy.
2.8 Analytics Providers
Analytics providers may assist the Company in understanding:
Platform performance;
feature usage;
operational metrics;
customer experience;
software reliability;
system performance;
future analytical capabilities.
Where appropriate, analytics information may be aggregated, anonymized, or de-identified.
2.9 Cybersecurity Providers
The Company may utilize security service providers supporting:
threat detection;
vulnerability management;
intrusion detection;
monitoring;
security testing;
incident response;
fraud prevention;
endpoint protection;
future cybersecurity services.
Cybersecurity providers assist the Company in protecting Platform operations but do not eliminate every cybersecurity risk.
2.10 Customer Support Providers
Customer support providers may assist with:
help desk services;
ticket management;
technical troubleshooting;
customer communications;
knowledge management;
enterprise support;
future customer service technologies.
Support providers receive access only to the information reasonably necessary to provide requested assistance.
2.11 API and Integration Providers
The Company may utilize integration providers supporting:
APIs;
enterprise integrations;
workflow automation;
document exchange;
authentication;
developer services;
future interoperability services.
API providers remain subject to applicable contractual, technical, and security requirements.
2.12 International Processing
Service Providers may process information in jurisdictions where they maintain operations.
Where international processing occurs, the Company seeks to implement commercially reasonable safeguards consistent with applicable legal requirements.
The geographic location of processing may vary depending upon:
the selected provider;
service availability;
redundancy;
disaster recovery;
customer configuration;
applicable law.
2.13 Vendor Monitoring
The Company may periodically evaluate Service Providers through activities including:
contract reviews;
operational assessments;
security evaluations;
privacy reviews;
performance monitoring;
incident reviews;
customer feedback;
compliance reviews where appropriate.
Vendor evaluation frequency may vary depending upon operational risk.
2.14 Customer Rights
Subject to applicable law, contractual obligations, and Platform functionality, Customers may have the ability to:
request information regarding categories of Service Providers;
review publicly available Company policies;
request applicable privacy information;
exercise applicable privacy rights;
request enterprise documentation where available.
The Company reserves the right to protect confidential business information, trade secrets, security-sensitive information, and proprietary vendor relationships where permitted by law.
2.15 Future Service Providers
As the Platform evolves, the Company may engage additional Service Providers supporting:
artificial intelligence;
identity verification;
digital credentials;
blockchain technologies where appropriate;
advanced cybersecurity;
international communications;
regulatory compliance;
accessibility;
enterprise services;
future Platform functionality.
The Company reserves the right to replace, add, suspend, or discontinue Service Providers without prior notice where reasonably necessary to support business operations, security, legal compliance, or technological improvements.
ARTICLE III — Security, Confidentiality, Compliance and General Provisions
3.1 Security Requirements for Service Providers
The Company seeks to engage Service Providers that maintain commercially reasonable administrative, technical, organizational, and physical safeguards appropriate to the services they perform.
Depending upon the nature of the services provided, the Company may evaluate factors including:
information security practices;
access controls;
authentication procedures;
encryption capabilities;
incident response processes;
business continuity planning;
disaster recovery capabilities;
operational resilience;
personnel security practices;
contractual confidentiality obligations.
The Company may modify its evaluation criteria as technology, legal requirements, and industry practices evolve.
3.2 Confidentiality
Service Providers receiving access to Company or Customer information are generally expected to maintain appropriate confidentiality obligations consistent with the services provided.
Confidentiality obligations may arise through:
written agreements;
applicable law;
contractual obligations;
professional responsibilities.
The Company seeks to limit access to information to that reasonably necessary for authorized business purposes.
3.3 Data Protection
Where Service Providers process Customer information on behalf of the Company, the Company seeks to require commercially reasonable safeguards appropriate to the nature of the processing.
Such safeguards may include:
access restrictions;
secure communications;
encryption where appropriate;
authentication controls;
audit logging;
monitoring;
secure storage;
secure disposal;
contractual data protection commitments.
Data protection responsibilities are further described in the Company's Privacy Policy and applicable agreements.
3.4 Vendor Incident Response
If the Company becomes aware of a security incident involving a Service Provider that may materially affect Platform operations or Customer information, the Company may:
investigate the matter;
coordinate with the affected provider;
assess operational impact;
implement mitigation measures;
suspend affected integrations where appropriate;
notify Customers where required by applicable law;
improve internal safeguards;
evaluate continued use of the provider.
The timing and content of any notification will depend upon applicable legal requirements, the nature of the incident, and information reasonably available to the Company.
3.5 Vendor Changes
The Company may add, replace, suspend, or discontinue Service Providers at any time where reasonably necessary to:
improve security;
improve reliability;
improve performance;
satisfy legal requirements;
support new Platform functionality;
reduce operational risk;
improve customer experience;
respond to business needs.
Enterprise customers with contractual notification rights will receive notice consistent with their applicable agreements.
3.6 Customer Responsibilities
Customers remain responsible for:
evaluating whether the Platform meets their business requirements;
reviewing publicly available Company policies;
maintaining appropriate internal security practices;
configuring available security features;
protecting account credentials;
complying with applicable legal obligations.
Customers are encouraged to conduct their own vendor due diligence appropriate to their regulatory and business requirements.
3.7 Regulatory Compliance
The Company seeks to operate the Platform in accordance with applicable laws governing:
privacy;
cybersecurity;
electronic transactions;
consumer protection;
commercial communications;
contractual obligations;
record retention;
financial reporting where applicable;
accessibility;
other applicable legal requirements.
The Company may revise vendor governance practices as regulatory requirements evolve.
3.8 Availability Disclaimer
Third-party services are provided through independent organizations.
Accordingly, the Company does not warrant that:
every third-party service will remain continuously available;
every provider will maintain identical service levels;
every communication will be delivered without interruption;
every third-party integration will remain permanently available.
Service interruptions may occur because of provider maintenance, operational failures, cybersecurity incidents, Internet disruptions, governmental actions, or other circumstances beyond the Company's reasonable control.
3.9 Limitation of Liability
TO THE MAXIMUM EXTENT PERMITTED BY APPLICABLE LAW, THE COMPANY SHALL NOT BE LIABLE FOR INDIRECT, INCIDENTAL, SPECIAL, CONSEQUENTIAL, EXEMPLARY, OR PUNITIVE DAMAGES ARISING FROM:
third-party service interruptions;
cloud provider failures;
communications provider outages;
payment processor interruptions;
AI provider limitations;
identity verification provider interruptions;
Internet failures;
force majeure events;
circumstances beyond the Company's reasonable control.
Nothing in this section limits liability that cannot lawfully be limited.
3.10 Relationship to Other Policies
This Subprocessors & Third-Party Services Policy forms part of the Portal Platform Legal Suite™ and should be interpreted together with:
LEGAL-001 — Master Terms of Service;
LEGAL-002 — Privacy Policy;
LEGAL-003 — Communications Policy;
LEGAL-004 — Security Policy;
LEGAL-005 — AI Services Policy;
LEGAL-006 — Electronic Signature Disclosure & Consent;
LEGAL-007 — Cookie Policy;
LEGAL-008 — Acceptable Use Policy;
LEGAL-009 — Trust Center™ Policy;
LEGAL-010 — Record Retention Policy;
LEGAL-011 — Accessibility Statement;
LEGAL-013 — Data Processing Addendum;
LEGAL-014 — Enterprise Terms;
LEGAL-015 — eSignare Notary™ Terms;
LEGAL-016 — IPEN & RON Supplement; and
any additional legal documents adopted by the Company.
Where another policy governs a more specific aspect of third-party processing or vendor management, that policy shall control with respect to that subject matter while this Policy governs the Company's overall approach to Service Providers.
3.11 Amendments
The Company may revise this Policy to reflect:
changes in Service Providers;
technological developments;
legal requirements;
cybersecurity improvements;
operational changes;
Platform expansion;
new products and services.
Material revisions will be communicated using reasonable electronic methods where required by applicable law.
Continued use of the Platform following the effective date of revised policies constitutes acceptance of the updated Policy to the extent permitted by applicable law.
3.12 Contact Information
Questions regarding this Subprocessors & Third-Party Services Policy or the Company's use of subprocessors and third-party service providers may be submitted to:
JHS Solutions LLC
Email: support@esignare.com
Support is available for matters including:
Subprocessor Questions
Third-Party Service Providers
Vendor Management
Data Processing Providers
Security and Compliance Questions
International Data Processing Questions
Enterprise Due Diligence Requests
General Customer Support
Additional contact methods and support resources may be published through the Portal Platform™ from time to time.
Where required by applicable law, the Company may designate a privacy, compliance, or legal representative to assist with subprocessor and third-party service-related inquiries.
3.13 Governing Law
This Policy shall be governed by the laws of the State of Florida, together with applicable federal laws of the United States, except where mandatory law provides otherwise.
3.14 Severability
If any provision of this Policy is determined by a court of competent jurisdiction to be invalid, illegal, or unenforceable, the remaining provisions shall remain in full force and effect.
Any invalid provision shall be interpreted or modified only to the extent necessary to preserve its intended purpose while maintaining the overall effectiveness of this Policy.
Acknowledgment
BY ACCESSING OR USING THE PORTAL PLATFORM™, YOU ACKNOWLEDGE THAT YOU HAVE READ, UNDERSTOOD, AND AGREE TO THIS SUBPROCESSORS & THIRD-PARTY SERVICES POLICY.
YOU FURTHER ACKNOWLEDGE THAT THE COMPANY MAY UTILIZE QUALIFIED THIRD-PARTY SERVICE PROVIDERS TO SUPPORT THE OPERATION, SECURITY, DELIVERY, AND CONTINUOUS IMPROVEMENT OF THE PLATFORM IN ACCORDANCE WITH THIS POLICY AND APPLICABLE LAW.
LEGAL-012 — Subprocessors & Third-Party Services Policy
Version 1.0 RC1 · JHS Solutions LLC