Data processing agreement
This agreement, in accordance with Article 28 of the GDPR, governs the processing of personal data that NEXTGENWEBS, S.L. (hereinafter, the Processor) carries out on behalf of each customer company of naranjatec firma (hereinafter, the Controller). It forms part of the Terms and conditions and is accepted when purchasing the service.
1. Purpose
The Processor will process the data necessary to provide the naranjatec firma service: generating, hosting and serving the email signatures of the Controller's team.
2. Data and data subjects
- Data subjects: employees and collaborators of the Controller who have a signature in the service, and its administrator users.
- Data: name, job title, department, email, phone numbers, location, website, social media profiles, photograph, custom fields and scheduled messages entered by the Controller or its members.
- No special categories of data are processed, unless the Controller enters them, which it must not do.
3. Duration
For as long as the service is provided. When it ends, the Processor will delete the data or return it to the Controller if the Controller so requests (it may export the data beforehand from the application), unless a law requires it to be retained.
4. Obligations of the Processor
The Processor undertakes to:
- Process the data only on the documented instructions of the Controller, which are those the Controller gives when using the service.
- Ensure the confidentiality of the persons authorised to process the data.
- Apply the security measures of Article 32 of the GDPR: encryption in transit, encrypted passwords, separation of each customer's data, access control, backups and logging of support access.
- Not engage another processor without authorisation. The Controller gives general authorisation for the sub-processors listed below; the Processor will give notice of any changes so that the Controller can object.
- Assist the Controller in responding to data subjects' rights requests and in complying with its obligations regarding security, breach notification and impact assessments.
- Notify the Controller, without undue delay and within a maximum of 48 hours of becoming aware of it, of any personal data breach.
- Make available to the Controller the information necessary to demonstrate compliance with this agreement and allow reasonable audits, with prior notice.
5. Authorised sub-processors
- Stripe Payments Europe, Ltd. — payments (only the Controller's billing data).
- Hosting: NEXTGENWEBS, S.L. (naranjatec), Paterna (Valencia), España.
- Transactional email delivery (invitations, notifications): [email_provider].
Transfers outside the European Economic Area, if any, will be carried out with appropriate safeguards.
6. Obligations of the Controller
The Controller warrants that it has a legal basis to process its team's data and to include it in the signatures, that it has informed the data subjects and that it will not enter unnecessary data.
7. Contact
For any question about this agreement: info@naranjatec.com.
Last updated: October 5, 2026