COSigna Privacy  Terms  DPA

Data Processing Agreement

Article 28 GDPR — the terms under which Phileos processes personal data on a customer's behalf.

Provisional draft v0.1 · 2026-06-06 · processor: Phileos (France) · English working version (FR/DE to follow)

Contents
  1. 1. Parties & roles (controller / processor)
  2. 2. Subject-matter, duration, nature & purpose
  3. 3. Categories of data & data subjects
  4. 4. Processing only on documented instructions
  5. 5. Confidentiality
  6. 6. Security of processing (Art. 32)
  7. 7. Subprocessors & change notification
  8. 8. Assistance with data-subject rights & DPIAs
  9. 9. Personal-data-breach notification
  10. 10. Return or deletion on termination
  11. 11. Audit rights
  12. 12. International transfers
  13. Annex A — Subprocessors
  14. Annex B — Technical & Organisational Measures (TOMs)

1. Parties & roles (controller / processor)

This Agreement is between the Customer (for example, a law firm that runs COSigna ceremonies involving its own signers' personal data) and Phileos:

Legal namePhileos Security and Event Services (PSES)
SIRET937 831 899
RCSParis
Registered address60 Rue François 1er, 75008 PARIS
Contactprivacy@phileos.eu

The Customer is the controller of its signers' personal data; Phileos is the processor, acting on the Customer's documented instructions. This Agreement supplements the Terms of Service and forms part of the Art. 28 GDPR arrangement between the parties. Where Phileos processes a person's own account data for Phileos's own purposes, Phileos is the controller for that processing and the Privacy Policy applies instead.

The blind server reshapes this relationship. Because the original document never reaches Phileos (only its SHA-256 hash does) and consent selfies are stored only as end-to-end-encrypted ciphertext, the personal data Phileos can technically access as processor is materially narrower than in a typical SaaS arrangement.

2. Subject-matter, duration, nature & purpose

Subject-matterProcessing of personal data necessary to provide the COSigna signature-ceremony service to the Customer.
DurationFor the term of the Terms of Service / the Customer's use of the service, plus the periods set out in §10 (return/deletion) and any retention required by law or by the evidentiary nature of a closed proof.
NatureHosting, transmission, storage, integrity-protection, timestamp-anchoring of hashes, and (on request) export and erasure — performed by a blind server that does not receive document content.
PurposeTo orchestrate asynchronous multi-party signing ceremonies and produce tamper-evident, independently verifiable proofs.

3. Categories of data & data subjects

Data subjectsThe Customer's signers / ceremony participants (and the Customer's authorised users).
Categories of personal dataEmail addresses; ceremony metadata (parties, state, timestamps, hash-chained attestations); document hashes (not documents); a self-declared signing location; credit-ledger entries; transient IP for rate-limiting.
Special categories (Art. 9)Consent selfies (biometric), processed only as end-to-end-encrypted ciphertext the processor cannot decrypt; no biometric templates are derived or stored. Explicit consent is collected at the controller/data-subject level.
ExcludedDocument content (never received by the processor); payment card data (handled by Stripe, not Phileos).

4. Processing only on documented instructions

Phileos processes personal data only on the Customer's documented instructions, including with regard to transfers, unless required by EU or Member-State law (in which case Phileos informs the Customer of that legal requirement before processing, unless the law prohibits it). The Terms of Service, this Agreement, and the configuration choices the Customer makes in the service constitute the Customer's documented instructions. Phileos will inform the Customer if, in its opinion, an instruction infringes GDPR or other data-protection law.

5. Confidentiality

Phileos ensures that persons authorised to process the personal data are bound by an appropriate duty of confidentiality. Access is limited to personnel who need it to provide or support the service. The blind-server architecture limits, by design, what any person at Phileos can access.

6. Security of processing (Art. 32)

Phileos implements appropriate technical and organisational measures to ensure a level of security appropriate to the risk, as detailed in Annex B — including end-to-end encryption of consent selfies, the blind-server design, hashing and a tamper-evident hash chain, crypto-erasure, encryption at rest and TLS in transit, access controls, and rate-limiting.

7. Subprocessors & change notification

The Customer provides general authorisation for Phileos to engage the subprocessors listed in Annex A. Phileos imposes data-protection obligations on each subprocessor that are no less protective than those in this Agreement, and remains fully liable to the Customer for a subprocessor's performance. Phileos will give the Customer prior notice of any intended addition or replacement of a subprocessor (target: at least [30] days), giving the Customer the opportunity to object on reasonable data-protection grounds.

8. Assistance with data-subject rights & DPIAs

9. Personal-data-breach notification

Phileos notifies the Customer without undue delay after becoming aware of a personal-data breach affecting the Customer's data (target: within [72] hours), providing the information the Customer reasonably needs to meet its own Art. 33–34 obligations. The blind-server design materially limits the personal data exposable in many breach scenarios (no document content; selfie ciphertext is unreadable without the key).

10. Return or deletion on termination

On termination, and at the Customer's choice, Phileos deletes or returns the personal data it processes for the Customer and deletes existing copies, unless EU or Member-State law requires storage. Where the Customer has chosen to retain closed ceremonies as evidence, the non-reversible proof record (hashes + timestamps, carrying no document content) persists by its nature; the personal-data elements (notably the encrypted selfie) remain subject to crypto-erasure on request.

11. Audit rights

Phileos makes available to the Customer the information necessary to demonstrate compliance with Art. 28 and allows for and contributes to audits, including inspections, conducted by the Customer or an auditor it mandates, on reasonable prior notice, during business hours, subject to confidentiality and to safeguards that protect other customers' data and the security of the service. Where available, third-party assessment reports may be provided to satisfy audit requests efficiently.

12. International transfers

Personal data is processed within the EU/EEA (see Annex A); on the current configuration, Standard Contractual Clauses are not required because there is no transfer of personal data outside the EU/EEA. The OpenTimestamps/Bitcoin anchor carries only hashes — no personal data — and is therefore not a transfer of personal data. Should any transfer outside the EU/EEA arise, the parties will put an appropriate transfer mechanism (such as the EU Standard Contractual Clauses) in place beforehand, and this clause will be read to incorporate it.

Annex A — Subprocessors

SubprocessorService providedLocationPersonal data accessed
ScalewayEU hosting + object storageFrance (EU)Service data at rest; selfie ciphertext (opaque); hashes & metadata. No plaintext documents or selfies.
Stripe Payments EuropePayment processingIreland (EU)Billing/card data (Phileos never receives the card number).
Scaleway TEMTransactional emailFrance (EU)Email addresses + service/sign-in messages.
OpenTimestamps calendars + Bitcoin networkPublic timestamp anchoringPublic infrastructureHashes only — no personal data, no document content.

Annex B — Technical & Organisational Measures (TOMs)

MeasureDescription
Blind serverThe original document never reaches Phileos; only its SHA-256 hash is processed. Document confidentiality is structural, not policy-based.
End-to-end encryption of consent selfiesConsent selfies are stored only as ciphertext the server cannot decrypt; no plaintext biometric image is available to the processor.
No biometric templatesNo template/embedding/face-recognition vector is derived or stored; no cross-ceremony matching. Only a one-way hash of the image is committed.
Hashing & tamper-evident hash chainIntegrity is enforced cryptographically; subsequent alteration is detectable.
Crypto-erasureErasure of encrypted personal data by key destruction / ciphertext deletion, recorded in an append-only PII-free erasure_log.
Encryption at rest & in transitServer-side encryption at rest (SSE-AES256) for stored objects; TLS for data in transit.
EU hosting / data residencyPersonal data hosted and processed in the EU (France) — see Annex A.
Access controlsLeast-privilege access; admin endpoints gated; security headers (CSP/HSTS); rate-limiting and abuse prevention (transient IP, not retained as a profile).
Minimal client storageFirst-party localStorage only (session + language). No third-party trackers.

Honest note for reviewers. An independent security assessment / penetration test and a DPIA are commissioned / in progress. The measures above are described accurately; no certification (e.g. ISO 27001, SOC 2) is claimed that Phileos does not hold. Bracketed timeframes (notice periods, breach window) are placeholders for counsel to finalise.

Report bug COSigna — a Cryptographic Ring of Mutual Consent · The ring is strong because the loop is closed. The ring is strong because the loop is closed.