Preamble
This Data Processing Addendum ("DPA") supplements the Master Terms of Service and applies whenever JHS Solutions LLC ("Company," "Processor," "Service Provider," "we," "our," or "us") processes Personal Information or Personal Data on behalf of a business customer ("Customer," "Controller," or "Business") in connection with the Portal Platform™ and related services.
This DPA establishes the responsibilities of the parties regarding the processing of Personal Data and is intended to support compliance with applicable privacy and data protection laws.
This DPA forms part of the Portal Platform Legal Suite™ and should be read together with:
LEGAL-001 — Master Terms of Service;
LEGAL-002 — Privacy Policy;
LEGAL-003 — Communications Policy;
LEGAL-004 — Security Policy;
LEGAL-005 — AI Services Policy;
LEGAL-006 — Electronic Signature Disclosure & Consent;
LEGAL-007 — Cookie Policy;
LEGAL-008 — Acceptable Use Policy;
LEGAL-009 — Trust Center™ Policy;
LEGAL-010 — Record Retention Policy;
LEGAL-011 — Accessibility Statement;
LEGAL-012 — Subprocessors & Third-Party Services Policy;
and all other applicable Platform policies.
ARTICLE I — Purpose, Scope and Processing Principles
1.1 Purpose
The purpose of this DPA is to establish the obligations of the Company and the Customer concerning the processing of Personal Data.
This DPA addresses:
processing instructions;
confidentiality;
security;
Subprocessors;
international transfers;
data subject rights;
security incidents;
audits;
deletion and return of data;
legal compliance.
1.2 Scope
This DPA applies whenever the Company processes Personal Data on behalf of a Customer through:
Portal Platform™;
eSignare®;
Customer Workspace;
Signer Portal;
Administrator Portal;
Trust Center™;
Dispatch Center™;
APIs;
AI Services;
Enterprise Services;
Mobile Applications;
future Company products.
1.3 Definitions
For purposes of this DPA:
Controller means the organization that determines the purposes and means of processing Personal Data.
Processor means the Company when processing Personal Data on behalf of a Customer.
Personal Data or Personal Information means information relating to an identified or identifiable individual, as defined by applicable law.
Processing includes collecting, storing, organizing, using, transmitting, disclosing, securing, deleting, or otherwise handling Personal Data.
Subprocessor means a third party engaged by the Company to process Personal Data on its behalf.
1.4 Processing Instructions
The Company will process Personal Data only:
in accordance with Customer instructions;
as necessary to provide Platform services;
as required by applicable law;
as described in the Master Terms of Service and Privacy Policy.
If the Company believes an instruction violates applicable law, it may notify the Customer before carrying out the instruction where legally permitted.
1.5 Nature of Processing
Processing activities may include:
document management;
electronic signatures;
document delivery;
authentication;
communications;
identity verification;
fraud prevention;
Trust Center™ verification;
audit logging;
billing;
customer support;
AI-assisted features;
API services;
record retention;
future Platform services.
1.6 Categories of Personal Data
Depending on the Customer's use of the Platform, Personal Data processed may include:
names;
email addresses;
telephone numbers;
mailing addresses;
account information;
authentication information;
IP addresses;
device information;
audit information;
document contents;
transaction history;
payment-related information;
communications;
future data categories submitted by the Customer.
The Company processes only the information reasonably necessary to provide the requested services.
1.7 Categories of Data Subjects
Data subjects may include:
Customers;
Signers;
employees;
contractors;
authorized representatives;
business contacts;
enterprise users;
consumers;
other individuals whose information is submitted through the Platform by the Customer.
1.8 Processing Principles
The Company seeks to process Personal Data according to the following principles:
lawfulness;
fairness;
transparency;
confidentiality;
integrity;
availability;
accountability;
data minimization;
purpose limitation;
continuous improvement.
These principles are applied consistent with applicable law and the Company's operational role as a Processor.
ARTICLE II — Security Measures, Confidentiality, Data Subject Rights and Processing Obligations
2.1 Confidentiality
The Company shall take commercially reasonable steps to ensure that individuals authorized to process Personal Data:
are subject to appropriate confidentiality obligations;
receive appropriate security awareness or operational guidance where applicable;
access Personal Data only as reasonably necessary to perform authorized duties;
comply with applicable contractual and legal obligations.
Confidentiality obligations continue following termination of employment or engagement where applicable.
2.2 Security Measures
The Company seeks to maintain administrative, technical, organizational, and physical safeguards appropriate to the nature of the Personal Data processed.
Security measures may include:
encryption where appropriate;
secure authentication;
Multi-Factor Authentication (MFA);
role-based access controls;
audit logging;
security monitoring;
vulnerability management;
secure software development;
backup procedures;
disaster recovery planning;
incident response procedures;
future security technologies.
Security measures may evolve as technology, threats, and legal requirements change.
2.3 Processing Personnel
Access to Personal Data is limited to personnel, contractors, or authorized Service Providers who require such access to perform authorized business functions.
The Company seeks to apply the principle of least privilege whenever reasonably practicable.
2.4 Subprocessors
The Customer authorizes the Company to engage qualified Subprocessors as reasonably necessary to provide Platform services.
The Company seeks to:
evaluate Subprocessors;
impose appropriate contractual obligations;
require commercially reasonable security measures;
monitor Subprocessor performance where appropriate.
Current categories of Subprocessors are described in LEGAL-012 — Subprocessors & Third-Party Services Policy.
2.5 International Data Transfers
Personal Data may be processed in jurisdictions where:
the Company operates;
authorized Subprocessors operate;
cloud infrastructure is maintained;
disaster recovery systems are located.
Where international transfers occur, the Company seeks to implement commercially reasonable safeguards consistent with applicable legal requirements.
2.6 Data Subject Requests
Where the Company receives a request relating to Personal Data that the Customer controls, the Company may:
notify the Customer where appropriate;
direct the requester to the Customer where legally permissible;
assist the Customer in responding where reasonably practicable and contractually required.
The Customer remains primarily responsible for responding to requests from its own data subjects unless otherwise required by law.
2.7 Customer Instructions
The Company shall process Personal Data only:
as instructed by the Customer;
as necessary to provide Platform services;
as described in applicable agreements;
as required by applicable law.
The Company reserves the right to decline instructions that are technically infeasible, unlawful, or inconsistent with applicable agreements.
2.8 Security Incidents
If the Company becomes aware of a confirmed security incident involving Personal Data processed on behalf of a Customer, the Company may:
investigate the incident;
contain the incident;
implement corrective measures;
coordinate with affected Service Providers;
preserve relevant evidence;
notify the Customer where required by applicable law or contractual obligation.
Notification timing will depend upon:
applicable law;
available information;
the nature of the incident;
operational circumstances.
2.9 Assistance with Compliance
Where reasonably practicable and consistent with applicable agreements, the Company may assist Customers in meeting certain legal obligations relating to Personal Data, including:
responding to lawful requests;
providing available documentation;
supporting security inquiries;
facilitating record exports where supported;
assisting with regulatory inquiries where appropriate.
Such assistance may be subject to technical limitations, reasonable fees, or separate contractual arrangements.
2.10 Audit Rights
Where required by written agreement or applicable law, the Company may provide reasonable information regarding its processing activities to support Customer compliance reviews.
The Company reserves the right to:
protect confidential information;
protect security-sensitive information;
protect trade secrets;
require reasonable advance notice;
require confidentiality agreements;
recover reasonable costs associated with extensive audit requests where permitted by law.
Nothing in this section requires the Company to disclose information that would materially compromise Platform security or another customer's confidential information.
2.11 Return or Deletion of Personal Data
Upon termination of applicable services, and subject to applicable law, contractual obligations, legal holds, and the Company's Record Retention Policy, the Company may:
return Customer Personal Data where supported;
permit Customer export of available records;
securely delete Personal Data;
retain records required by law or legitimate operational requirements.
Backup copies may continue to exist temporarily in accordance with normal disaster recovery and backup rotation processes.
2.12 Customer Responsibilities
The Customer remains responsible for:
determining the lawful basis for processing Personal Data;
providing required notices to data subjects;
obtaining required consents where applicable;
ensuring the accuracy of submitted information;
determining retention requirements applicable to its own business;
responding to data subject requests unless otherwise required by law;
configuring available security features;
protecting Customer credentials;
complying with applicable privacy laws.
The Company does not assume the Customer's legal responsibilities as a Controller unless expressly agreed in writing.
2.13 Government Requests
Where legally permitted, the Company may notify the Customer if it receives a governmental, regulatory, or judicial request seeking Customer Personal Data.
The Company may comply with legally binding requests where required by applicable law.
2.14 Business Continuity
The Company seeks to maintain business continuity and disaster recovery capabilities intended to protect Personal Data against accidental loss or destruction.
Recovery procedures may include:
secure backups;
redundant infrastructure where appropriate;
restoration procedures;
disaster recovery testing;
future resilience technologies.
2.15 Continuous Improvement
The Company continuously evaluates opportunities to improve:
privacy protections;
security controls;
vendor oversight;
processing procedures;
operational resilience;
compliance practices;
documentation;
future privacy technologies.
Processing practices may evolve as legal requirements, customer expectations, and technology continue to develop.
ARTICLE III — Regulatory Compliance, Liability and General Provisions
3.1 Compliance with Applicable Laws
The Company seeks to process Personal Data in accordance with applicable privacy and data protection laws governing its services and operations.
Depending upon the Customer's jurisdiction and the nature of the services provided, applicable laws may include:
United States federal privacy laws;
Florida privacy laws;
state privacy statutes;
electronic transaction laws;
consumer protection laws;
cybersecurity laws;
international privacy laws where applicable to the parties.
Nothing in this DPA shall be interpreted as creating legal obligations beyond those imposed by applicable law or the parties' written agreements.
3.2 Customer Compliance Responsibilities
The Customer acknowledges that it remains responsible for:
determining whether use of the Platform satisfies its legal obligations;
obtaining any legally required notices or consents;
determining the lawful basis for processing Personal Data;
complying with industry-specific regulations applicable to its organization;
ensuring that Personal Data submitted to the Platform has been lawfully collected.
The Company does not provide legal advice regarding Customer compliance obligations.
3.3 Cooperation with Regulatory Authorities
Where required by applicable law, the Company may cooperate with:
courts;
governmental agencies;
regulatory authorities;
law enforcement;
supervisory authorities;
auditors acting under lawful authority.
Where legally permitted, the Company may notify the Customer before disclosing Customer Personal Data in response to legally binding requests.
3.4 Documentation
The Company may maintain documentation supporting its privacy and security program, including:
internal policies;
security procedures;
incident response procedures;
vendor management documentation;
privacy practices;
operational procedures;
training materials;
future compliance documentation.
The Company reserves the right to determine what documentation may be disclosed in order to protect confidential information, security-sensitive information, and trade secrets.
3.5 Availability Disclaimer
The Company seeks to provide reliable processing services using commercially reasonable operational practices.
However, the Company does not warrant that:
processing services will always be uninterrupted;
every third-party provider will remain continuously available;
Internet services will always function normally;
cloud providers will remain continuously operational;
communications networks will always be available.
Temporary interruptions may occur due to maintenance, security events, infrastructure failures, provider outages, force majeure events, or circumstances beyond the Company's reasonable control.
3.6 Limitation of Liability
TO THE MAXIMUM EXTENT PERMITTED BY APPLICABLE LAW, THE COMPANY SHALL NOT BE LIABLE FOR INDIRECT, INCIDENTAL, SPECIAL, CONSEQUENTIAL, EXEMPLARY, OR PUNITIVE DAMAGES ARISING FROM OR RELATING TO:
Customer instructions;
Customer misuse of the Platform;
inaccurate Customer-provided information;
third-party service interruptions;
cloud provider failures;
communications outages;
Internet failures;
cybersecurity incidents beyond the Company's reasonable control;
force majeure events;
circumstances beyond the Company's reasonable control.
Nothing in this section limits liability that cannot lawfully be limited or excluded.
3.7 Relationship to Other Agreements
This Data Processing Addendum supplements:
the Master Terms of Service;
Enterprise Agreements;
Subscription Agreements;
written Statements of Work;
other written agreements governing Platform services.
In the event of a conflict between this DPA and another written agreement specifically governing Personal Data processing, the more specific written agreement shall control with respect to that subject matter.
3.8 Relationship to Other Policies
This DPA forms part of the Portal Platform Legal Suite™ and should be interpreted together with:
LEGAL-001 — Master Terms of Service;
LEGAL-002 — Privacy Policy;
LEGAL-003 — Communications Policy;
LEGAL-004 — Security Policy;
LEGAL-005 — AI Services Policy;
LEGAL-006 — Electronic Signature Disclosure & Consent;
LEGAL-007 — Cookie Policy;
LEGAL-008 — Acceptable Use Policy;
LEGAL-009 — Trust Center™ Policy;
LEGAL-010 — Record Retention Policy;
LEGAL-011 — Accessibility Statement;
LEGAL-012 — Subprocessors & Third-Party Services Policy;
LEGAL-014 — Enterprise Terms;
LEGAL-015 — eSignare Notary™ Terms;
LEGAL-016 — IPEN & RON Supplement; and
any additional legal documents adopted by the Company.
3.9 Amendments
The Company may revise this DPA to reflect:
legal developments;
privacy law changes;
regulatory guidance;
security improvements;
operational enhancements;
Platform expansion;
new products and services;
evolving data processing practices.
Material revisions will be communicated using reasonable electronic methods where required by applicable law or contract.
Continued use of the Platform after the effective date of revised terms constitutes acceptance of the updated DPA to the extent permitted by applicable law.
3.10 Contact Information
Questions regarding this Data Processing Addendum (DPA) or the Company's processing of Personal Data may be submitted to:
JHS Solutions LLC
Email: support@esignare.com
Support is available for matters including:
Data Processing Questions
Personal Data Requests
Data Subject Rights
Data Access Requests
Data Correction Requests
Data Deletion Requests
International Data Transfer Questions
Enterprise Privacy Questions
Compliance Questions
General Customer Support
Additional contact methods and support resources may be published through the Portal Platform™ from time to time.
Where required by applicable law, the Company may designate a privacy, compliance, or legal representative to assist with data processing-related inquiries.
3.11 Governing Law
This Data Processing Addendum shall be governed by the laws of the State of Florida, together with applicable federal laws of the United States, except where another governing law is expressly required by a written Enterprise Agreement or applicable mandatory law.
3.12 Severability
If any provision of this DPA is determined by a court or tribunal of competent jurisdiction to be invalid, illegal, or unenforceable, the remaining provisions shall remain in full force and effect.
Any invalid provision shall be interpreted or modified only to the extent necessary to preserve its intended purpose while maintaining the overall effectiveness of this DPA.
3.13 Survival
The provisions relating to:
confidentiality;
security;
audit rights;
record retention;
legal holds;
dispute resolution;
limitation of liability;
governing law;
and any obligations intended by their nature to survive,
shall remain effective following termination or expiration of the applicable services to the extent permitted by applicable law.
Acknowledgment
BY EXECUTING AN AGREEMENT FOR THE USE OF THE PORTAL PLATFORM™, OR BY CONTINUING TO USE THE PLATFORM WHERE THIS DPA APPLIES, THE CUSTOMER ACKNOWLEDGES THAT IT HAS READ, UNDERSTOOD, AND AGREES TO THIS DATA PROCESSING ADDENDUM.
THE CUSTOMER FURTHER ACKNOWLEDGES THAT JHS SOLUTIONS LLC WILL PROCESS PERSONAL DATA IN ACCORDANCE WITH THIS DPA, APPLICABLE LAW, THE MASTER TERMS OF SERVICE, AND THE COMPANY'S PRIVACY POLICY.
LEGAL-013 — Data Processing Addendum
Version 1.0 RC1 · JHS Solutions LLC