Last updated: 8 August 2026

Data Processing Agreement

This Data Processing Agreement (“DPA”) is entered into between Albert M. Morales Palleja, a sole trader (empresario individual / autónomo) established in Spain, NIF 53073266F, operating under the trade name LaunchSign (“Processor”, “LaunchSign”), Calle Girona 161, 08402 Granollers, Barcelona, Spain, and the Customer (“Controller”) who has agreed to the LaunchSign Terms of Service.

This DPA forms part of the Terms of Service and applies wherever the Customer uses LaunchSign to process personal data of third parties (for example, processing personal data of campaign recipients, guest reviewers, or other data subjects on behalf of the Customer's own clients or end users).

1. Definitions

  • “GDPR” means Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016.
  • “Personal Data”, “Processing”, “Data Subject”, “Controller”, “Processor”, and “Supervisory Authority” have the meanings given in Article 4 GDPR.
  • “Customer Data” means personal data that the Controller submits to LaunchSign for processing in the course of using the service.
  • “Sub-processor” means any third party engaged by LaunchSign to process Customer Data.

2. Roles and subject matter

The parties acknowledge that, with respect to Customer Data, the Customer acts as Controller and LaunchSign acts as Processor. LaunchSign will only process Customer Data on documented instructions from the Customer, including those set out in the Terms of Service and this DPA, unless required to do so by applicable law.

The subject matter, nature, purpose, duration, and types of personal data processed are determined by the Customer's use of the service. LaunchSign does not determine the purposes of processing Customer Data.

3. Customer obligations

The Customer warrants and represents that:

  • It has a valid legal basis under GDPR to collect and process Customer Data and to instruct LaunchSign to process it.
  • It has provided data subjects with appropriate privacy notices describing the processing.
  • It is authorised to enter into this DPA on behalf of all entities within its group whose Customer Data is processed through the service.

4. Processor obligations

LaunchSign will:

  • Process Customer Data only on documented instructions from the Customer, unless required by applicable law (in which case LaunchSign will, where permitted, notify the Customer before processing).
  • Ensure that persons authorised to process Customer Data are bound by confidentiality obligations.
  • Implement and maintain appropriate technical and organisational measures as set out in Section 6.
  • Assist the Customer in responding to Data Subject requests by providing available functionality in the platform (e.g., data export and deletion tools).
  • Assist the Customer, taking into account the nature of processing, in fulfilling its obligations under Articles 32–36 GDPR (security, breach notification, data protection impact assessments).
  • At the Customer's choice, delete or return all Customer Data upon termination of services, unless storage is required by applicable law.
  • Make available all information necessary to demonstrate compliance with this DPA and allow for audits, subject to reasonable notice and confidentiality obligations.

5. Sub-processors

The Customer authorises LaunchSign to engage the sub-processors listed in the Privacy Policy(Section 5). LaunchSign will give the Customer at least 30 days' written notice before adding or replacing a sub-processor. If the Customer objects to a new sub-processor, it may terminate the affected services within that notice period.

LaunchSign ensures that all sub-processors are bound by data processing agreements requiring at minimum the same level of protection as this DPA.

6. Security measures

Taking into account the state of the art, the costs of implementation, and the nature, scope, context, and purposes of processing, as well as the risks to data subjects, LaunchSign implements and maintains:

  • Encryption of Customer Data in transit (TLS 1.2 or higher) and at rest (AES-256 or equivalent)
  • Role-based access controls limiting access to Customer Data to personnel who need it to perform their responsibilities
  • Logical separation of Customer Data between tenants
  • Procedures for testing, assessing, and evaluating the effectiveness of technical and organisational measures
  • A documented incident response procedure including notification to the Customer in accordance with Section 7

7. Personal data breach notification

LaunchSign will notify the Customer without undue delay, and in any case within 72 hours of becoming aware, of any accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, Customer Data (“Breach”). The notification will include, to the extent known at the time:

  • A description of the nature of the Breach, including categories and approximate number of data subjects and records affected
  • Contact details of LaunchSign's data protection point of contact
  • Likely consequences of the Breach
  • Measures taken or proposed to address the Breach

Breach notifications should be sent to: privacy@launchsign.io. The Customer remains responsible for notifying its own supervisory authority and data subjects as required.

8. International transfers

LaunchSign will not transfer Customer Data outside the European Economic Area (EEA) without ensuring that an adequate level of protection is in place, through:

  • An adequacy decision by the European Commission; or
  • Standard Contractual Clauses (SCCs) approved by the European Commission

Our sub-processors that operate outside the EEA are covered by SCCs. Details of transfer mechanisms are available on request.

9. Audit rights

The Customer may, upon written request and at least 30 days' prior notice, conduct an audit of LaunchSign's processing activities covered by this DPA, no more than once per year, during normal business hours, and at the Customer's expense. LaunchSign may satisfy this obligation by providing an independent third-party audit report (e.g., SOC 2 Type II) in lieu of a direct audit.

10. Governing law

This DPA is governed by Spanish law and subject to the exclusive jurisdiction of the courts of Barcelona, Spain, consistent with the Terms of Service.

11. Requesting a countersigned DPA

Customers on the Pro or Enterprise plan who require a countersigned DPA for their own compliance purposes may request one by emailing privacy@launchsign.iowith the subject line “DPA request”. Please include your company name, registered address, and contact details. We aim to respond within five business days.

12. Contact

Data protection queries: privacy@launchsign.io