SignGrant

Subprocessors

Last updated October 1, 2026

When Orange Studios, LLC (“SignGrant”) processes personal data on a customer's behalf, we use the companies below to help. Each handles personal data only to provide the service listed, under a written agreement that requires confidentiality, appropriate security and data-protection terms no less protective than our Data Processing Addendum. This list is the one referred to in that addendum.

Our subprocessors

SubprocessorWhat it doesPersonal data involvedLocation
Railway
Railway Corporation
Application hosting and the storage volume that holds the database and uploaded files.All customer content: account details, releases, signing records, photos, ID images, signed PDFs.United States
Cloudflare R2
Cloudflare, Inc.
Off-site backups of the database and uploaded files.Copies of everything on the storage volume. Deleted files are removed from backups within 30 days.United States
Postmark
ActiveCampaign, LLC
Delivering the emails SignGrant sends: signing links, signed copies, team invitations, password resets.Recipient email address and name, message content, and attached signed release PDFs.United States
Anthropic
Anthropic, PBC
Reading past releases uploaded to Import (paid plans only) to suggest the release's details. Used only when a customer uploads a document to Import.The uploaded document: its text or page images, which can include names, contact details and signatures. Not used to train models.United States

Services a customer chooses

These are not our subprocessors, because the customer decides to use them:

  • Google Drive, Dropbox, Microsoft OneDrive. If a customer connects one, SignGrant copies signed releases and shoot photos into that customer's own storage account. The provider acts for the customer, not for SignGrant.
  • OpenTimestamps and the Bitcoin blockchain. Only a one-way SHA-256 fingerprint of a signed release is submitted. It contains no personal data.

International transfers

Our subprocessors are based in the United States. Where personal data from the EEA, the UK or Switzerland is transferred there, we rely on the Standard Contractual Clauses (and the UK Addendum) described in our Data Processing Addendum, or on the EU–US Data Privacy Framework where the subprocessor is certified.

Changes to this list

We'll email each account owner at least 30 days before we add or replace a subprocessor that will handle customer personal data, and update this page. A customer who reasonably objects on data-protection grounds can write to [email protected]within that time; we'll work with them on an alternative, and if there isn't one, they can close their account and export their data first.

SignGrant