Legal

Data Processing Addendum

This Data Processing Addendum ("DPA") forms part of the Terms of Service at app.digitalsign.co/terms (or other written agreement) between Nead, LLC, doing business as digitalsign.co ("Processor", "digitalsign.co" or "we"), and the customer ("Customer"). It applies whenever digitalsign.co processes Customer Personal Data on the Customer's behalf. It takes effect when the Customer accepts the Terms; no separate signature is needed. Customers who want a countersigned copy can request one at [email protected].

Last updated October 1, 2026

1. Definitions

  • "Data Protection Laws" means all laws that apply to the processing of Customer Personal Data under the Agreement, including the EU General Data Protection Regulation 2016/679 ("GDPR"), the UK GDPR and Data Protection Act 2018, the Swiss Federal Act on Data Protection, and US state privacy laws such as the California Consumer Privacy Act as amended ("CCPA").
  • "Customer Personal Data" means personal data within Customer Data (as defined in the Terms) that digitalsign.co processes on the Customer's behalf.
  • "Security Incident" means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, Customer Personal Data.
  • "Sub-processor" means a third party engaged by digitalsign.co that processes Customer Personal Data.
  • "Standard Contractual Clauses" or "SCCs" means the clauses approved by the European Commission in Implementing Decision (EU) 2021/914.
  • Terms such as "controller", "processor", "data subject", "personal data" and "processing" have the meanings given in the GDPR; "business", "service provider" and "sell" have the meanings given in the CCPA.

2. Roles and scope

The Customer is the controller (or, where it acts for its own clients, a processor) of Customer Personal Data, and digitalsign.co is its processor (or sub-processor). Annex 1 describes the processing. digitalsign.co is an independent controller only for the account, billing and usage information it processes to run its business, as described in its Privacy Policy at app.digitalsign.co/privacy.

3. Customer instructions

  • digitalsign.co will process Customer Personal Data only on the Customer's documented instructions. The Agreement, this DPA and the Customer's configuration and use of the Service (including publishing content to screens, configuring data connections, webhooks, rules and automations, and requesting screenshots) are the Customer's complete instructions. Additional instructions require written agreement.
  • digitalsign.co will tell the Customer if it believes an instruction infringes Data Protection Laws, unless the law prohibits that.
  • The Customer is responsible for the lawfulness of the processing it instructs, including having a lawful basis and any consents needed to display personal data (such as images of people or names) on screens in public or workplace spaces, and for the accuracy of the data it provides.

4. Processor obligations

  • Confidentiality. Personnel authorized to process Customer Personal Data are bound by confidentiality obligations, and access is limited to those who need it.
  • Security. digitalsign.co implements and maintains the technical and organizational measures in Annex 2, and may update them provided the overall level of protection is not reduced.
  • No other use. digitalsign.co will not sell or share Customer Personal Data, use it for its own purposes (including training AI models), or combine it with personal data from other customers or sources, except as permitted by Data Protection Laws for a service provider.
  • Assistance. Taking into account the nature of the processing, digitalsign.co will assist the Customer with data protection impact assessments and prior consultations with authorities, to the extent the Customer cannot do so using the Service.

5. Data subject requests

The Service lets the Customer access, export, correct and delete Customer Personal Data, including deleting media, designs, data connections and users. If digitalsign.co receives a request directly from a data subject about Customer Personal Data, it will refer the data subject to the Customer (without responding itself, unless required by law) and give reasonable help where the Customer cannot fulfil the request through the Service.

6. Sub-processors

  • The Customer gives general authorization for digitalsign.co to engage Sub-processors. The current list, with each Sub-processor's purpose and location, is at app.digitalsign.co/subprocessors and forms Annex 3.
  • digitalsign.co will give at least 30 days' notice before a new Sub-processor starts processing Customer Personal Data, by updating that page and notifying account owners by email or in the application.
  • The Customer may object on reasonable data protection grounds within that notice period by writing to [email protected]. The parties will discuss the concern in good faith. If digitalsign.co cannot reasonably accommodate it, the Customer may terminate the affected part of the Service and receive a refund of prepaid fees for the remaining term.
  • digitalsign.co imposes data protection obligations on each Sub-processor that are no less protective than this DPA, and remains responsible for its Sub-processors' performance.
  • Data sources, webhooks, embedded content and other services the Customer chooses to connect or display are not Sub-processors: the Customer instructs digitalsign.co to exchange data with them, and their processing is governed by the Customer's own arrangements with them.

7. Security incidents

digitalsign.co will notify the Customer without undue delay, and in any event within 48 hours, after becoming aware of a Security Incident affecting Customer Personal Data. The notice will describe, to the extent known, the nature of the incident, the categories and approximate number of data subjects and records concerned, the likely consequences, and the measures taken or proposed. digitalsign.co will provide further information as it becomes available, take reasonable steps to contain and remedy the incident, and assist the Customer with its own notification obligations. Notification is not an acknowledgment of fault.

8. Return and deletion

During the subscription, the Customer can export and delete Customer Personal Data using the Service. When the Customer deletes its organization or the Agreement ends, digitalsign.co will delete Customer Personal Data within 30 days, unless the law requires it to be kept. Residual copies in backups are deleted as backups expire on their rolling schedule (no more than 12 months) and remain protected by this DPA until then. Content already downloaded to the Customer's players remains on those devices until the Customer resets or clears them.

9. Audits

digitalsign.co will make available the information reasonably necessary to demonstrate compliance with this DPA, including by answering reasonable security questionnaires and providing summaries of its security measures. If that information is not sufficient to satisfy an obligation under Data Protection Laws or a regulator's request, the Customer may, at its own cost and no more than once a year (unless following a Security Incident or regulator request), conduct an audit on at least 30 days' notice, during business hours, in a way that does not disrupt the Service or compromise other customers' data or digitalsign.co's confidential information. Auditors must be bound by confidentiality.

10. International transfers

  • digitalsign.co hosts its servers and database in the European Union (Germany), with content delivered through a global edge network. Some Sub-processors process Customer Personal Data in the United States, as listed at app.digitalsign.co/subprocessors.
  • EEA. Where Customer Personal Data subject to the GDPR is transferred to a country without an adequacy decision, the SCCs are incorporated into this DPA: Module Two (controller to processor) where the Customer is a controller, and Module Three (processor to processor) where the Customer is a processor. For the SCCs: the optional docking clause (Clause 7) applies; Clause 9 option 2 (general authorization) applies with the notice period in Section 6; the option in Clause 11 does not apply; Clause 17 option 1 applies, with the law of Ireland; the courts of Ireland are chosen under Clause 18(b); and Annexes I to III are completed by Annexes 1 to 3 of this DPA. The supervisory authority is that of the Customer's EU representative or establishment, as Clause 13 provides.
  • UK. For transfers subject to UK data protection law, the International Data Transfer Addendum issued by the UK Information Commissioner (version B1.0) applies, completed with the information in this DPA; either party may end it as permitted by its Section 19.
  • Switzerland. For transfers subject to Swiss law, the SCCs apply with references to the GDPR read as references to the Swiss Federal Act on Data Protection, and the Swiss Federal Data Protection and Information Commissioner is the competent authority.
  • Where digitalsign.co or a Sub-processor is certified under the EU-US Data Privacy Framework or a successor mechanism, it may rely on that instead. If a transfer mechanism is invalidated, the parties will cooperate to put an alternative in place.

11. US state privacy laws

For Customer Personal Data subject to the CCPA or similar US state laws, digitalsign.co is a service provider (or processor). digitalsign.co will not sell or share it, will not retain, use or disclose it outside the direct business relationship with the Customer or for any purpose other than performing the Service, will not combine it with personal information from other sources except as permitted by law, will comply with applicable obligations and provide the same level of privacy protection the law requires, and will notify the Customer if it can no longer meet its obligations. The Customer may take reasonable steps to stop and remediate unauthorized use. digitalsign.co certifies that it understands these restrictions.

12. Liability and general terms

Each party's liability under this DPA is subject to the limitations in the Terms, except where Data Protection Laws or the SCCs do not allow it. If this DPA conflicts with the Terms, this DPA controls for data protection matters; if it conflicts with the SCCs, the SCCs control. This DPA lasts as long as digitalsign.co processes Customer Personal Data.

13. Annex 1: Details of processing

ItemDescription
PartiesData exporter: the Customer, as identified in its account, acting as controller (or processor). Data importer: Nead, LLC (digitalsign.co), [email protected], acting as processor (or sub-processor).
Subject matterProviding the Service under the Agreement.
DurationThe term of the Agreement, plus up to 30 days for deletion (and backup expiry as described in Section 8).
Nature and purposeStoring, transforming and delivering media and designs to the Customer's screens; generating designs, text and images with AI on the Customer's request; fetching and receiving data from connections the Customer configures and displaying it; running schedules, rules and automations; managing screens and players, including telemetry, remote commands and screenshots on request; recording playback for analytics and proof of play; support and security.
Data subjectsThe Customer's users; individuals appearing in media, designs or data the Customer uploads, generates or connects (such as staff, customers or models); and individuals whose information appears in the Customer's data connections.
Categories of personal dataUser names, email addresses and roles; images, video and audio of people the Customer uploads; names and other information in designs, prompts and connected data; screen and device telemetry including IP addresses; screenshots of screen content; playback logs; and records of actions taken in the Service.
ViewersNone. The Service does not collect personal data about people who view the Customer's screens.
Special categoriesNone. The Customer must not send special categories of personal data.
FrequencyContinuous, while the Customer uses the Service.
RetentionFor the term of the Agreement, unless the Customer deletes data sooner; deletion as in Section 8.

14. Annex 2: Technical and organizational measures

  • Encryption: TLS for data in transit; stored credentials for data connections encrypted with AES-256-GCM; sign-in links, session tokens, device tokens, webhook tokens and API keys stored only as hashes.
  • Authentication: passwordless sign-in through single-use links that expire after 15 minutes; revocable sessions; screens paired with short-lived codes and authenticated with per-device tokens.
  • Access control: role-based permissions enforced in the service layer; API keys act with no more than their creator's current permissions.
  • Customer isolation: every query is scoped to the Customer's organization; media is stored under organization-specific paths and served through signed, expiring links.
  • Data minimization: the player collects no data about viewers; screenshots are taken only on request; weather lookups send location coordinates only.
  • Application security: input validation on every boundary; protection against cross-site request forgery and server-side request forgery; rate limiting on sign-in; incoming webhooks authenticated by secret tokens or signatures; dependency auditing.
  • Logging and monitoring: an audit log of security-relevant actions and changes, available to the Customer; health checks on the Service.
  • Availability and recovery: regular encrypted database backups stored off-server, durable object storage for media, offline playback on players, and tested restores.
  • Secure development: code review, automated tests, and separation of development and production environments.
  • Personnel: confidentiality obligations and least-privilege access for personnel.
  • Incident response: a documented process for containment, investigation and customer notification.

15. Annex 3: Sub-processors

The Sub-processors authorized under Section 6 are listed at app.digitalsign.co/subprocessors.