base0 logobase0
  • How it works
  • Features
  • Comparison
  • Pricing
  • Blogs
  • Sign in
  • Get started

Data Processing Agreement

Effective Date: June 1, 2026
Version: 1.0
Operated by: ("base0", "we", "us")
Address: India
Contact: [email protected]

This Data Processing Agreement ("DPA") supplements the base0 Terms of Service(the "Agreement") entered into between the Customer and base0, a service operated by . By using base0's services, Customer enters into this DPA on behalf of itself and, where applicable, its Affiliates. Terms not defined in this DPA shall have the meaning set forth in the Agreement.

Note: base0 is currently operating as an unregistered entity. Upon formal incorporation, this DPA will be updated to reflect the registered legal entity details. The obligations and protections described herein remain fully in effect regardless.

1. Definitions

1.1 Affiliate
An entity that directly or indirectly owns 50% or more of a party's equity, or is under common control with a party through such ownership.

1.2 Authorized Sub-Processor
A third party who requires access to Customer Personal Data to enable base0 to perform its obligations, as listed in Exhibit B or subsequently authorized under Section 3 of this DPA.

1.3 Customer Account Data
Personal data relating to the Customer's relationship with base0, including names, contact information, and billing details of authorized account users.

1.4 Customer Usage Data
Service usage data collected in connection with providing the Services, including activity logs, IP addresses, access times, and performance data.

1.5 Data Protection Laws
All applicable laws and regulations relating to personal data processing, including: (i) the EU General Data Protection Regulation (GDPR) 2016/679; (ii) the UK GDPR and Data Protection Act 2018; (iii) the California Consumer Privacy Act (CCPA); (iv) India's Digital Personal Data Protection Act (DPDPA) 2023; and any amendments or successor legislation thereto.

1.6 Personal Data
Any information relating to an identified or identifiable natural person, as defined under applicable Data Protection Laws.

1.7 Data Subject
A natural person whose Personal Data is processed under this DPA, including both Customer account holders and document Signers.

1.8 Services
The e-signature and document workflow platform provided by base0 as described in the Agreement.

1.9 Standard Contractual Clauses (SCCs)
The standard contractual clauses approved by the European Commission (Decision 2021/914) for transfers of personal data to third countries not covered by an adequacy decision.

2. Roles and Responsibilities

2.1 Controller and Processor

The parties acknowledge that with regard to the processing of Personal Data:

  • Customer acts as the Data Controller — determining the purposes and means of processing.
  • base0 acts as the Data Processor — processing Personal Data solely on Customer's documented instructions.
  • Where Customer itself acts as a processor on behalf of a third party, base0 acts as a Sub-Processor.

2.2 Customer Obligations

Customer shall:

  • Process Personal Data in compliance with all applicable Data Protection Laws.
  • Ensure its instructions to base0 do not cause base0 to violate applicable law.
  • Be solely responsible for the accuracy, quality, and legality of Personal Data provided to base0.
  • Obain all necessary consents from Data Subjects, including document Signers, prior to submitting their data to the Services.
  • Not provide Personal Data to base0 in violation of the Agreement or applicable laws.

2.3 base0 Obligations

base0 shall:

  • Process Personal Data only on Customer's documented instructions, unless required by applicable law.
  • Inform Customer if, in base0's opinion, an instruction infringes applicable Data Protection Laws.
  • Ensure personnel authorized to process Personal Data are bound by confidentiality obligations.
  • Implement and maintain appropriate technical and organizational security measures as described in Exhibit C.
  • Notify Customer without undue delay (and in any event within 48–72 hours) upon becoming aware of a Personal Data Breach.
  • Assist Customer in fulfilling its obligations to respond to Data Subject Requests.
  • Upon termination of the Agreement, delete or return all Personal Data at Customer's choice, unless applicable law requires retention.

3. Sub-Processors

3.1 Authorization

Customer acknowledges and provides general written authorization for base0 to engage the sub-processors listed in Exhibit B to process Personal Data in connection with the Services.

3.2 New Sub-Processors

base0 will provide at least 15 days' prior notice before authorizing any new sub-processor to access Personal Data. Notice will be provided via email to Customer's registered address or via update to the sub-processor list at base0.tech/sub-processors.

Customer may object to a new sub-processor within 10 days of notice, in writing, on grounds related to data protection. If base0 cannot accommodate the objection within a reasonable period, Customer may terminate the affected Services without penalty, upon written notice to base0.

3.3 Sub-Processor Obligations

base0 will impose data protection obligations on each Authorized Sub-Processor that are no less protective than those in this DPA. base0 remains liable to Customer for the performance of each sub-processor's obligations.

4. Security of Personal Data

base0 shall implement and maintain appropriate technical and organizational measures to ensure a level of security appropriate to the risk. These measures are detailed in Exhibit C and further summarized on our Security & Compliance page. They include:

  • Encryption of Personal Data in transit (HTTPS/TLS) and at rest (AWS S3 server-side encryption).
  • Access controls and authentication for internal systems.
  • Audit logging of all document lifecycle events.
  • Document hash generation (SHA-256) at signing completion to ensure tamper-evidence.
  • Regular review and testing of security measures.
  • Backup and recovery procedures for Customer data.

5. Transfers of Personal Data

5.1 International Transfers

base0's infrastructure is currently hosted on AWS services (US region) and NeonDB. Customer acknowledges that Personal Data may be processed in the United States and other jurisdictions outside the EEA, UK, or India.

5.2 Transfer Safeguards

Where Personal Data is transferred outside the EEA or UK to a jurisdiction without an EU adequacy decision, base0 will ensure appropriate safeguards are in place, including:

  • Reliance on the EU Standard Contractual Clauses (Module 2: Controller to Processor) as incorporated by reference into this DPA.
  • Any supplementary measures reasonably necessary to maintain an equivalent level of protection.

5.3 India Transfers

For processing governed by India's DPDPA 2023, base0 will comply with applicable cross-border data transfer restrictions and will execute any required Data Processing Agreements under Indian law upon Customer request.

5.4 EU Region Option

Customers with specific EU data residency requirements may contact [email protected] to discuss dedicated EU-region hosting arrangements. base0 will endeavor to accommodate such requests as infrastructure capacity allows.

6. Rights of Data Subjects

base0 shall, upon becoming aware of a Data Subject Request relating to Customer's Personal Data, promptly notify Customer and direct the Data Subject to submit their request to Customer.

base0 shall provide Customer with reasonable assistance to fulfill Data Subject Requests including:

  • Access: Providing Customer with the ability to retrieve Personal Data stored in the Services via the dashboard or API.
  • Erasure: Deleting Personal Data from base0 systems upon Customer's written instruction, subject to legal retention requirements.
  • Portability: Providing Personal Data in a machine-readable format upon Customer request.
  • Rectification: Allowing Customer to correct inaccurate Personal Data through the Services.

Customer is solely responsible for communicating Data Subject Request outcomes to the relevant individuals.

7. Data Breach Notification

In the event of a confirmed Personal Data Breach, base0 will:

  • Notify Customer without undue delay, and in any event within 48–72 hours of becoming aware of the breach.
  • Provide, to the extent known at the time: the nature of the breach, categories and approximate number of data subjects affected, likely consequences, and measures taken or proposed.
  • Cooperate with Customer in any required notifications to supervisory authorities or affected Data Subjects.

Notification to Customer does not constitute an acknowledgment of fault or liability by base0.

8. Retention and Deletion

base0 retains Customer Personal Data for as long as the Customer's account is active or as necessary to provide the Services. Specifically:

  • Signed documents and associated signing records are retained indefinitely until Customer requests deletion, to support Customer's record-keeping requirements.
  • Upon account deletion, Customer Personal Data will be purged from active systems within 30 days, and from backups within 90 days.
  • Signer Personal Data (email, IP, signing event records) follows the same retention schedule as the associated document.
  • base0 may retain aggregated, anonymized usage data that cannot identify any individual after account deletion.

9. Audits and Compliance Demonstration

base0 shall, upon reasonable written notice (minimum 30 days) and no more than once per calendar year, provide Customer with:

  • Responses to information security questionnaires.
  • Summary documentation of security practices and controls.
  • Evidence of any relevant third-party certifications or assessments.

base0 reserves the right to charge a reasonable fee for audit assistance that exceeds standard documentation requests. Physical on-site audits are not supported at this time but may be accommodated upon mutual written agreement. For an overview of our security measures, encryption protocols, and infrastructure compliance certifications, please see our dedicated Security & Compliance page.

10. Conflict

In the event of any conflict or inconsistency between this DPA and the Agreement, this DPA shall prevail with respect to data protection matters. For all other matters, the Agreement prevails.

If Customer and base0 have entered into separate Standard Contractual Clauses, those SCCs shall prevail over this DPA to the extent of any conflict regarding international data transfers.

11. Governing Law

This DPA shall be governed by and construed in accordance with the laws of India (Indian IT Act 2000 and DPDPA 2023) unless Customer is located in the EU/EEA, in which case Irish law shall apply for GDPR purposes, or the United Kingdom, in which case UK law shall apply.

For EU customers, this DPA is supplemented by the EU Standard Contractual Clauses (Module 2), which are incorporated by reference and deemed executed upon Customer's acceptance of the Agreement.

Exhibit A — Details of Processing

Subject MatterElectronic signature and document workflow services
DurationFor the term of the Agreement and as required by applicable law thereafter
Nature of ProcessingCollection, storage, transmission, display, and deletion of Personal Data in connection with document signing workflows
Purpose of ProcessingTo enable Customers to send, sign, track, and store electronic documents and signatures
Categories of Personal DataNames, email addresses, IP addresses, phone numbers (SMS), handwritten or typed signatures, document content uploaded by Customer, audit trail metadata (timestamps, device info)
Categories of Data SubjectsCustomer account holders (senders), document recipients (signers), and any individuals whose data is included in uploaded document content

Exhibit B — Authorized Sub-Processors

Sub-ProcessorPurposeLocationData Touched
Amazon Web Services (AWS S3)Document and file storageUnited StatesDocuments, signatures, file metadata
Amazon Web Services (AWS EC2)Backend application hostingUnited StatesAll data in transit through the application
Neon Technologies (NeonDB)Database hosting (PostgreSQL)United StatesAll structured user and document data
Resend Inc.Transactional email delivery (signing links, notifications)United StatesSigner email addresses, signing link tokens
Dodo PaymentsPayment processingUnited States / EUBilling and payment data only (no document data)

Exhibit C — Technical and Organizational Security Measures

MeasureDetails
Encryption in TransitAll data transmitted between users and base0 services is encrypted using HTTPS/TLS. Signing links are single-use tokenized URLs transmitted over encrypted channels.
Encryption at RestDocuments and files stored in AWS S3 use server-side encryption (AES-256). NeonDB database is encrypted at rest.
Document IntegrityA SHA-256 cryptographic hash is computed and stored for each finalized signed document, enabling tamper detection.
Access ControlsAccess to production systems is restricted to authorized personnel. Role-based access controls are enforced.
Audit LoggingAll document lifecycle events (sent, delivered, opened, signed, completed, declined) are logged with timestamps, IP addresses, and device metadata.
Signer AuthenticationSigners are authenticated via secure, single-use tokenized links delivered to their registered email address, proving control of the email account.
Consent CaptureA consent screen is presented to every signer before any document interaction, capturing explicit consent to conduct the transaction electronically.
Data BackupCustomer data stored in NeonDB is backed up regularly. AWS S3 versioning is enabled for document storage.
Breach Responsebase0 maintains an internal incident response process. Confirmed breaches are escalated immediately with Customer notification within 48–72 hours.
Sub-Processor Reviewbase0 reviews sub-processor security practices and relies on their published compliance certifications (e.g., AWS ISO 27001, SOC 2).
Employee AccessAccess to Customer Personal Data is limited to personnel with a legitimate business need. All team members are bound by confidentiality obligations.
base0 logobase0•

Helping teams sign agreements faster and more securely. Built for founders, legal, and enterprises alike.

Newsletter

Stay updated on new features, security improvements, and product news from base0.

Quick Links

DashboardPricingVerify DocumentSecurityResources

Legal

Data Processing AgreementPrivacy PolicyTerms & Conditions

Company

About UsBlogContact Us

Connect With Us

[email protected][email protected]

base0•

© 2026 Base0. All Rights Reserved.
Terms and Conditions/Privacy Policy