Data Processing Agreement
Last updated: 12 August 2026
This Data Processing Agreement ("DPA") supplements the DeliverySigner Terms of Service and applies where Patience and Fortitude Ltd ("we", "us", "Processor"), trading as DeliverySigner, processes personal data on behalf of a customer ("you", "Controller") in providing the proof of delivery and container operations platform (the "Service"). It reflects the requirements of Article 28 of the UK GDPR.
1. Parties and contact
The Processor is Patience and Fortitude Ltd (registered in England and Wales, company no. 14551744), 20-22 Wenlock Road, London, N1 7GU, England. Data protection enquiries can be sent to hello@deliverysigner.app.
2. Subject matter, duration and purpose
The Processor processes personal data provided by or on behalf of the Controller in connection with the Controller's use of the Service, for the duration of the Controller's subscription and until any applicable retention period expires. The purpose is to deliver the Service as described in the Terms of Service.
3. Categories of personal data
- Driver and user data: names, email addresses, phone numbers, roles and signatures captured through the Service.
- Customer and recipient data: names and contact details of the Controller's customers and delivery recipients.
- Operational data: delivery references, container and seal numbers, addresses, booking times, photographs, and arrival, delivery and departure timestamps.
- Communications data: the content and attachments of emails and messages processed to operate the Service.
- The Processor does not knowingly process special category data. If the Controller submits any, it must inform the Processor in advance.
4. Processing on documented instructions
The Processor processes personal data only on the Controller's documented instructions through the Service's configuration, unless required to do so by UK or EU law. The Controller is responsible for ensuring it has a lawful basis and, where required, has obtained any necessary consents for the data it submits.
5. Confidentiality and personnel
The Processor ensures that persons authorised to process personal data are subject to confidentiality obligations and access personal data only as necessary to operate the Service, on a least-privilege basis.
6. Security measures
The Processor implements appropriate technical and organisational measures, including:
- Encryption in transit (TLS) and encryption at rest via the hosting provider.
- Role-based access controls and authentication.
- Isolation of data by tenant (company) so that one Controller cannot access another's data.
- Logging and monitoring for security and operational integrity.
7. Sub-processors
The Controller authorises the Processor to engage the following sub-processors. The Processor has entered into a written data processing agreement with each sub-processor named below, imposing obligations no less protective than those in this DPA. A current list is maintained and the Processor will notify the Controller of any intended addition or replacement so the Controller may object.
- Stripe, Inc. — payment processing and billing. Processes billing email addresses and transaction references. Stripe DPA.
- Twilio Inc. — SMS and (where enabled) WhatsApp message delivery. Processes recipient phone numbers and message content. Twilio DPA.
- Resend, Inc. — outbound transactional email delivery. Processes sender and recipient email addresses and email content. Resend DPA.
- Google LLC (Google Drive / Google Workspace) — cloud document storage and export, where the Controller connects its own Google Drive account. Processes document files and metadata stored in the Controller's Drive. Google Workspace DPA.
- iLovePDF (iLoveIMG Software S.L.) — PDF compression for exported documents. Processes document files transiently for compression. iLovePDF Privacy.
- CloudMailin Ltd. — inbound email parsing and forwarding. Processes the content and attachments of emails sent to the Service's inbound addresses. CloudMailin Privacy.
- Cloud hosting provider — infrastructure hosting the Service, its database and file storage. Processes all categories of personal data held in the Service.
- AI and OCR providers — services that extract structured data (such as container numbers, addresses and driver instructions) from documents the Controller submits. Process document content transiently for extraction.
The Processor remains responsible for the compliance of its sub-processors and will notify the Controller of any intended change to sub-processors so the Controller may object.
8. Assistance with data subject rights
Taking into account the nature of the processing, the Processor assists the Controller, by appropriate technical and organisational measures, in responding to data subject requests (access, rectification, erasure, restriction, objection and portability). The Controller should submit such requests to hello@deliverysigner.app and the Processor will provide the data and assistance reasonably required.
9. Personal data breach
The Processor will notify the Controller without undue delay after becoming aware of a personal data breach affecting the Controller's data, describe the nature and likely consequences, and take reasonable steps to remediate. The Processor supports the Controller in assessing and, where required, reporting the breach to the ICO and affected individuals.
10. International data transfers
Where a sub-processor processes data outside the United Kingdom or EEA, the Processor relies on appropriate safeguards such as the UK International Data Transfer Agreement, standard contractual clauses, or the provider's certified framework.
11. Deletion, return and retention
On termination of the Controller's subscription, the Controller may export its data through the Service. The Processor will delete the Controller's personal data from live systems, subject to any retention required by law.
To meet UK transport, audit and tax (HMRC) record-keeping obligations, delivery notes, invoices, notification logs and inbound emails are retained for up to six years. A scheduled process runs monthly to automatically and permanently delete records older than six years. Where a data subject requests erasure, the Processor applies pseudonymisation — stripping the individual's personal identifiers from delivery records while retaining the signed delivery note, photographs and attached documents as the Controller's commercial evidence for the six-year period. After the retention period expires, remaining backups are overwritten in line with the Processor's standard schedule.
12. Audit and verification
The Processor makes available information necessary to demonstrate compliance and contributes to audits and inspections. Given the shared nature of the Service, the Controller agrees to rely on the Processor's independent third-party reports and certifications where available, and to contact the Processor before undertaking an on-site audit.
13. Contact
Questions about this DPA can be sent to hello@deliverysigner.app.