Article 28 GDPR — the terms under which Phileos processes personal data on a customer's behalf.
This Agreement is between the Customer (for example, a law firm that runs COSigna ceremonies involving its own signers' personal data) and Phileos:
| Legal name | Phileos Security and Event Services (PSES) |
|---|---|
| SIRET | 937 831 899 |
| RCS | Paris |
| Registered address | 60 Rue François 1er, 75008 PARIS |
| Contact | privacy@phileos.eu |
The Customer is the controller of its signers' personal data; Phileos is the processor, acting on the Customer's documented instructions. This Agreement supplements the Terms of Service and forms part of the Art. 28 GDPR arrangement between the parties. Where Phileos processes a person's own account data for Phileos's own purposes, Phileos is the controller for that processing and the Privacy Policy applies instead.
The blind server reshapes this relationship. Because the original document never reaches Phileos (only its SHA-256 hash does) and consent selfies are stored only as end-to-end-encrypted ciphertext, the personal data Phileos can technically access as processor is materially narrower than in a typical SaaS arrangement.
| Subject-matter | Processing of personal data necessary to provide the COSigna signature-ceremony service to the Customer. |
|---|---|
| Duration | For the term of the Terms of Service / the Customer's use of the service, plus the periods set out in §10 (return/deletion) and any retention required by law or by the evidentiary nature of a closed proof. |
| Nature | Hosting, transmission, storage, integrity-protection, timestamp-anchoring of hashes, and (on request) export and erasure — performed by a blind server that does not receive document content. |
| Purpose | To orchestrate asynchronous multi-party signing ceremonies and produce tamper-evident, independently verifiable proofs. |
| Data subjects | The Customer's signers / ceremony participants (and the Customer's authorised users). |
|---|---|
| Categories of personal data | Email addresses; ceremony metadata (parties, state, timestamps, hash-chained attestations); document hashes (not documents); a self-declared signing location; credit-ledger entries; transient IP for rate-limiting. |
| Special categories (Art. 9) | Consent selfies (biometric), processed only as end-to-end-encrypted ciphertext the processor cannot decrypt; no biometric templates are derived or stored. Explicit consent is collected at the controller/data-subject level. |
| Excluded | Document content (never received by the processor); payment card data (handled by Stripe, not Phileos). |
Phileos processes personal data only on the Customer's documented instructions, including with regard to transfers, unless required by EU or Member-State law (in which case Phileos informs the Customer of that legal requirement before processing, unless the law prohibits it). The Terms of Service, this Agreement, and the configuration choices the Customer makes in the service constitute the Customer's documented instructions. Phileos will inform the Customer if, in its opinion, an instruction infringes GDPR or other data-protection law.
Phileos ensures that persons authorised to process the personal data are bound by an appropriate duty of confidentiality. Access is limited to personnel who need it to provide or support the service. The blind-server architecture limits, by design, what any person at Phileos can access.
Phileos implements appropriate technical and organisational measures to ensure a level of security appropriate to the risk, as detailed in Annex B — including end-to-end encryption of consent selfies, the blind-server design, hashing and a tamper-evident hash chain, crypto-erasure, encryption at rest and TLS in transit, access controls, and rate-limiting.
The Customer provides general authorisation for Phileos to engage the subprocessors listed in Annex A. Phileos imposes data-protection obligations on each subprocessor that are no less protective than those in this Agreement, and remains fully liable to the Customer for a subprocessor's performance. Phileos will give the Customer prior notice of any intended addition or replacement of a subprocessor (target: at least [30] days), giving the Customer the opportunity to object on reasonable data-protection grounds.
GET /account/export, erasure via POST /faces/{hash}/erase (crypto-erasure of the encrypted selfie) and POST /account/delete, with every erasure recorded in an append-only, PII-free erasure_log.Phileos notifies the Customer without undue delay after becoming aware of a personal-data breach affecting the Customer's data (target: within [72] hours), providing the information the Customer reasonably needs to meet its own Art. 33–34 obligations. The blind-server design materially limits the personal data exposable in many breach scenarios (no document content; selfie ciphertext is unreadable without the key).
On termination, and at the Customer's choice, Phileos deletes or returns the personal data it processes for the Customer and deletes existing copies, unless EU or Member-State law requires storage. Where the Customer has chosen to retain closed ceremonies as evidence, the non-reversible proof record (hashes + timestamps, carrying no document content) persists by its nature; the personal-data elements (notably the encrypted selfie) remain subject to crypto-erasure on request.
Phileos makes available to the Customer the information necessary to demonstrate compliance with Art. 28 and allows for and contributes to audits, including inspections, conducted by the Customer or an auditor it mandates, on reasonable prior notice, during business hours, subject to confidentiality and to safeguards that protect other customers' data and the security of the service. Where available, third-party assessment reports may be provided to satisfy audit requests efficiently.
Personal data is processed within the EU/EEA (see Annex A); on the current configuration, Standard Contractual Clauses are not required because there is no transfer of personal data outside the EU/EEA. The OpenTimestamps/Bitcoin anchor carries only hashes — no personal data — and is therefore not a transfer of personal data. Should any transfer outside the EU/EEA arise, the parties will put an appropriate transfer mechanism (such as the EU Standard Contractual Clauses) in place beforehand, and this clause will be read to incorporate it.
| Subprocessor | Service provided | Location | Personal data accessed |
|---|---|---|---|
| Scaleway | EU hosting + object storage | France (EU) | Service data at rest; selfie ciphertext (opaque); hashes & metadata. No plaintext documents or selfies. |
| Stripe Payments Europe | Payment processing | Ireland (EU) | Billing/card data (Phileos never receives the card number). |
| Scaleway TEM | Transactional email | France (EU) | Email addresses + service/sign-in messages. |
| OpenTimestamps calendars + Bitcoin network | Public timestamp anchoring | Public infrastructure | Hashes only — no personal data, no document content. |
| Measure | Description |
|---|---|
| Blind server | The original document never reaches Phileos; only its SHA-256 hash is processed. Document confidentiality is structural, not policy-based. |
| End-to-end encryption of consent selfies | Consent selfies are stored only as ciphertext the server cannot decrypt; no plaintext biometric image is available to the processor. |
| No biometric templates | No template/embedding/face-recognition vector is derived or stored; no cross-ceremony matching. Only a one-way hash of the image is committed. |
| Hashing & tamper-evident hash chain | Integrity is enforced cryptographically; subsequent alteration is detectable. |
| Crypto-erasure | Erasure of encrypted personal data by key destruction / ciphertext deletion, recorded in an append-only PII-free erasure_log. |
| Encryption at rest & in transit | Server-side encryption at rest (SSE-AES256) for stored objects; TLS for data in transit. |
| EU hosting / data residency | Personal data hosted and processed in the EU (France) — see Annex A. |
| Access controls | Least-privilege access; admin endpoints gated; security headers (CSP/HSTS); rate-limiting and abuse prevention (transient IP, not retained as a profile). |
| Minimal client storage | First-party localStorage only (session + language). No third-party trackers. |
Honest note for reviewers. An independent security assessment / penetration test and a DPIA are commissioned / in progress. The measures above are described accurately; no certification (e.g. ISO 27001, SOC 2) is claimed that Phileos does not hold. Bracketed timeframes (notice periods, breach window) are placeholders for counsel to finalise.