
Data Processing Addendum
Effective October 1, 2026
This Data Processing Addendum (“DPA”) is part of the Terms of Service between Orange Studios, LLC (“SignGrant”, “we”) and the customer who holds a SignGrant account (“Customer”, “you”). It applies automatically whenever we process Customer Personal Data subject to the GDPR, the UK GDPR, the Swiss FADP or a similar law. If you need a countersigned copy for your records, email [email protected].
In short: you decide what goes into your releases; we store and process it only to run SignGrant for you, keep it secure, tell you quickly if something goes wrong, help you answer requests from the people in your releases, and delete or return it when you leave.
1. Scope and roles
Customer Personal Data means the personal data that you or the people you send releases to put into SignGrant: the contents of releases, Model Directory entries, photos, ID images, signatures, signing records and uploaded documents. Annex 1 describes it in detail.
For Customer Personal Data, you are the controller and SignGrant is your processor. If you are yourself a processor for someone else (for example a studio acting for a client), SignGrant is your subprocessor, and you confirm you are authorised to give us the instructions in this DPA. SignGrant is the controller of your own account and billing details, which our Privacy Policy covers and this DPA does not.
2. Our processing
We will process Customer Personal Data only:
- to provide SignGrant to you as described in the Terms and the product: creating, sending, signing, storing, exporting and syncing your releases;
- on your documented instructions, which are the Terms, this DPA, and what you do in the product (including features you switch on, such as cloud sync or Import); and
- as required by law, in which case we'll tell you beforehand unless the law forbids it.
We will tell you if we think an instruction breaks data-protection law. We do not sell Customer Personal Data, use it for advertising, or use it to train AI models.
3. Confidentiality
People at SignGrant can access Customer Personal Data only when needed to run, secure or support the service, and are bound by confidentiality obligations.
4. Security
We maintain the technical and organisational measures in Annex 2, and will keep a level of security appropriate to the risk. We may update them if the result is not less protective.
5. Subprocessors
You give us general authorisation to use the subprocessors on our subprocessor list. Each is bound by a written agreement with data-protection obligations no less protective than this DPA, and we remain responsible for their performance. We will email each account owner at least 30 days before adding or replacing a subprocessor; you may object on reasonable data-protection grounds by writing to [email protected] within that time, and if we can't resolve it you may close your account (and export your data) without penalty.
6. Helping with requests from individuals
If someone asks us directly to access, correct, delete, restrict or port data in your releases, we will not answer on the merits; we'll refer them to you where we can identify you, and tell you about the request. We help you respond by:
- letting you view, edit and delete releases, saved models and photos in the app;
- on request to [email protected], giving you a complete export of your account's data (a ZIP of structured data and all uploaded files), normally within 10 business days; and
- deleting data you ask us to delete, subject to section 10.
Signed releases are often legal records. Whether a particular release can be deleted or must be kept is your decision as controller. The signed PDF and audit PDF are intentionally never rewritten after signing.
7. Personal data breaches
We will notify the account owner by email without undue delay, and in any case within 72 hours, after becoming aware of a personal data breach affecting Customer Personal Data. The notice will describe, as far as we then know, the nature of the breach, the data and approximate number of people affected, likely consequences and the measures taken or proposed, and we'll add details as we learn them. Deciding whether to notify authorities or individuals is your responsibility as controller; we will give reasonable help.
8. Other assistance and audits
We will give reasonable help with your data-protection impact assessments and with consultations with a supervisory authority, taking into account the nature of the processing and the information available to us. We will make available the information needed to show we meet this DPA, such as our security descriptions and subprocessor agreements, and answer reasonable security questionnaires. If that is not enough to meet a legal requirement, you may audit us once a year on 30 days' notice, during business hours, under confidentiality and without disrupting the service or exposing other customers' data; each side bears its own costs.
9. International transfers
SignGrant and its subprocessors are based in the United States. Where Customer Personal Data from the EEA, the UK or Switzerland is transferred to a country without an adequacy decision, the parties agree that the following apply, and are incorporated into this DPA by reference:
- the European Commission's Standard Contractual Clauses (Decision (EU) 2021/914): Module Two (controller to processor) or Module Three (processor to subprocessor) as applies, with the Customer as data exporter and SignGrant as data importer; clause 7 (docking) is included; in clause 9 Option 2 (general authorisation) applies with the notice period in section 5; in clause 11 the optional independent dispute-resolution body is not used; in clause 17 Option 1 applies, governed by the law of Ireland; and in clause 18 the courts of Ireland. Annexes I to III are Annex 1, Annex 2 and our subprocessor list;
- for the UK, the UK International Data Transfer Addendum to those clauses; and for Switzerland, the same clauses read with the changes the Swiss FADP requires.
If another mechanism, such as the EU–US Data Privacy Framework, validly covers the transfer, the parties may rely on it instead while it remains valid. If the clauses and this DPA conflict, the clauses win. We will tell you if we can no longer meet them.
10. Return and deletion
You can export and delete your data at any time. When your account is closed, we delete Customer Personal Data from our systems within 30 days, and from backups within a further 30 days, except where law requires us to keep something, in which case we will keep it only for that purpose. Please make sure you have an export before closing an account: we delete files from the live service and cannot restore them afterwards.
Two things can remain. A one-way public fingerprint of each signed release may stay in the Bitcoin blockchain through OpenTimestamps; it contains no personal data and can't be removed. And we keep a keyed one-way hash of former members' email addresses with the number of free-plan releases used, to prevent abuse of the free allowance.
11. Liability and precedence
The limits and exclusions of liability in the Terms apply to this DPA, to the extent the law allows. If this DPA and the Terms conflict about the processing of Customer Personal Data, this DPA wins. This DPA lasts as long as we process Customer Personal Data for you.
Annex 1: Details of processing
- Subject matter and duration: providing SignGrant to the Customer, for as long as the Customer has an account and until deletion under section 10.
- Nature and purpose: hosting, storing, retrieving, displaying, emailing and electronically capturing signatures on model, property and related releases; producing signed and audit PDFs; backing up; and, if enabled, copying files to the Customer's own cloud storage and reading uploaded releases with an AI model (Import).
- People whose data is processed: models, performers and talent; parents or guardians of minors; property owners; witnesses; and the Customer's photographers, studio staff and team members.
- Types of personal data: names, email addresses, telephone numbers, postal addresses, dates of birth, signatures, photos of people and properties, and signing records (IP address, device and browser details, timestamps, language). For forms that call for it: gender and ethnicity, and, for U.S. §2257 records, photos of government-issued identification.
- Special categories: ethnicity (where a form asks for it, which may reveal racial or ethnic origin) and anything sensitive the Customer enters in free-text fields. These are collected only when the Customer chooses a form that asks for them, and the Customer is responsible for having a lawful basis and, where needed, explicit consent. Photos of government ID are not special-category data but are high-risk, and are stored with the same protections.
- Frequency: continuous, while the account is in use.
- Retention: until the Customer deletes it or closes the account, then as described in section 10.
Annex 2: Security measures
- Transport security: all access to the service is over encrypted connections (HTTPS).
- Authentication: passwords are stored only as salted one-way hashes; the session cookie is HTTP-only and expires after seven days; repeated failed sign-ins from one IP address or against one account are rate-limited; email addresses must be confirmed before releases can be created; single sign-on is available.
- Access control: each customer's releases, files and settings are separated by account, and only that account's members can see them. Platform-admin actions on accounts (password resets, plan changes, exports, deletions) are logged.
- Secrets: access keys for connected cloud storage are encrypted (AES-256-GCM) and never stored in readable form.
- Integrity: each signed release gets a signing audit trail and an independently verifiable timestamp, and the executed PDF is never rewritten after signing.
- Resilience: continuous database replication and regular copies of uploaded files to off-site storage; deleted files are removed from backups within 30 days.
- Data minimisation: no advertising or analytics trackers; the contents of releases are not used to train AI models; only what a form requires is collected.
- Subprocessors: chosen and contracted as described in section 5.
- Incident response: breaches are handled and notified as in section 7.