Version 2026-10-10

Data Processing Addendum

The processor terms that apply whenever we handle personal data on your behalf.

1. Scope and roles

This addendum forms part of the Geco Signatures Terms of Service between Geco Technologies Ltd ("Processor", "we") and the Customer ("Controller", "you"). It applies to personal data we process on your behalf in providing the service, and is intended to satisfy Article 28 of the UK GDPR and, where applicable, the EU GDPR.

You are the controller (or a processor acting for your own client, in which case you warrant you have that client’s authority). We are your processor and act only on your documented instructions, which are: the Terms, your configuration of the service, and any further written instruction you give us.

2. Details of processing

  • Subject matter: applying email signatures, disclaimers and automatic replies to Microsoft 365 mail and populating them from directory data.
  • Duration: for as long as the workspace exists, plus the 30-day deletion window.
  • Nature and purpose: receipt and modification of mail in transit; reading directory attributes through Microsoft Graph; storing templates and rules; logging delivery outcomes.
  • Categories of data subjects: your staff and mailbox users; people who send mail to or receive mail from them.
  • Categories of personal data: names, job titles, contact details and photos from the directory; email addresses and content of messages in transit; delivery metadata.
  • Special category data: not intended. If mail content happens to contain it, it is processed in memory only and not stored.

3. Our obligations

  • Process personal data only on your instructions, and tell you if we believe an instruction breaks data protection law.
  • Make sure everyone who can access the data is bound by confidentiality and has access only on a need-to-know basis.
  • Keep the technical and organisational measures described on our Security page, and improve them over time rather than weaken them.
  • Help you respond to data subject requests, and tell you without undue delay if we receive one directly.
  • Help you with security, breach notification, data protection impact assessments and consultations with the ICO, taking into account what we know.
  • Tell you without undue delay, and in any event within 48 hours of becoming aware, of a personal data breach affecting your data, with the information you need to meet your own obligations.
  • Delete or return the data at the end of the service, as set out in the Terms, unless the law requires us to keep it.
  • Make available the information you reasonably need to show we comply, and allow audits by you or an auditor you appoint, on reasonable notice, no more than once a year unless a regulator requires otherwise or there has been a breach.

4. Subprocessors

You authorise us to use the subprocessors listed on our Subprocessors page. We will give you at least 30 days’ notice by email before adding or replacing one. If you object on reasonable data protection grounds and we cannot resolve it, you may cancel the affected workspace and we will refund any fees paid for the period after cancellation.

We impose the same obligations on each subprocessor by written contract and remain responsible for their performance.

5. International transfers

The service is hosted in Germany (European Union). We do not transfer your personal data outside the UK or EEA except to subprocessors on our list, and then only under UK adequacy regulations, the International Data Transfer Agreement, or the Addendum to the EU Standard Contractual Clauses, with supplementary measures where needed.

6. Your obligations

You are responsible for the lawfulness of the data you give us access to, for having the right to connect each tenant, for telling your staff about the processing where the law requires, and for configuring the service appropriately (for example which users are licensed and what the signatures contain).

7. Liability and precedence

The liability provisions of the Terms apply to this addendum. If this addendum conflicts with the Terms on a data protection matter, this addendum prevails.