Skip to main content

Qwoty’s Role

When using Qwoty, two distinct data processing roles apply:
RoleDescription
Data ControllerYou (the organisation using Qwoty) determine the purposes and means of processing
Data ProcessorQwoty processes personal data on your behalf according to your instructions
As the data controller, you are responsible for:
  • Obtaining appropriate consent or legal basis for processing
  • Informing data subjects about how their data is used
  • Responding to data subject access requests
  • Ensuring compliance with GDPR requirements
As the data processor, Qwoty:
  • Processes data only according to your documented instructions
  • Implements appropriate technical and organisational security measures
  • Assists with data subject requests when needed
  • Maintains records of processing activities

Data Processing

Qwoty processes personal data necessary to provide its services:
Data CategoryExamplesPurpose
Identity DataName, email addressUser accounts, recipient identification
Document DataUploaded PDFs, field valuesDocument storage and signing
Signature DataSignature images, signing timestampsRecording signing actions
Audit DataIP addresses, browser information, action logsAudit trail and verification
Data is processed for the following purposes:
  • Delivering documents to recipients
  • Recording signatures and other recipient actions
  • Generating signed documents with audit trails
  • Sending email notifications and transactional communications

Data Storage Locations

Qwoty primarily stores data within the European Economic Area (EEA). Application data and document storage use AWS infrastructure in the EU (Ireland and Paris). Backups are maintained in geographically separate EU locations.

Data Subject Rights

GDPR grants individuals specific rights regarding their personal data. As the data controller, you are responsible for fulfilling these requests:
RightDescription
AccessData subjects can request a copy of their personal data
RectificationData subjects can request correction of inaccurate data
ErasureData subjects can request deletion of their data (“right to be forgotten”)
PortabilityData subjects can request their data in a machine-readable format
RestrictionData subjects can request limited processing of their data
ObjectionData subjects can object to certain types of processing
Qwoty will assist with data subject requests where technically feasible. Up to five (5) requests per calendar month, or those requiring fewer than two (2) hours of effort, are included at no additional charge. Beyond this threshold, assistance is billed at Qwoty’s then-current professional services rate.

Data Deletion

Qwoty supports data deletion to help fulfil erasure requests:
  • Users can delete their own accounts
  • Account deletion removes profile data and authentication credentials
  • Administrators can remove members from the organisation
  • Document owners can delete documents at any stage
  • Deletion removes the document, recipient data, and associated audit logs
Upon termination of the agreement, Qwoty will:
  • Delete all personal data from primary systems within 10 business days
  • Delete data from backup systems within 90 days, in line with the standard backup retention cycle
Customers have 30 days from the termination date to export their data from the platform before deletion proceeds.Consult with legal counsel to establish appropriate retention policies, particularly for signed contracts where legal obligations may require you to retain records independently.

Data Processing Agreement

A Data Processing Agreement (DPA) is required by GDPR when a data controller engages a data processor. Qwoty’s DPA is incorporated directly into the General Terms and Conditions — accepting the GTC constitutes acceptance of the DPA. The DPA covers:
  • Qwoty’s obligations as a data processor
  • Sub-processor authorisation and change notification (30-day advance notice)
  • Technical and organisational security measures (Annex 2)
  • International data transfer mechanisms
  • A DPA is available upon request support@qwoty.io.

This page is provided for informational purposes only and does not constitute legal advice. GDPR compliance depends on your specific circumstances, including how you use Qwoty, what data you process, and your organisation’s obligations. Consult with qualified legal counsel to determine your GDPR obligations, draft appropriate privacy notices, establish lawful bases for processing, and implement compliant data handling procedures.