GDPR Article 28 compliant agreement between PARAMANT (processor) and your organisation (controller). Governs all personal data processed through the PARAMANT relay service.
| Processor | PARAMANT — operated on Hetzner Online GmbH, NBG1, Nuremberg, Germany. Contact: privacy@paramant.app |
| Controller | The organisation identified in the signature form below |
| Effective date | Date of electronic signature |
This agreement governs the processing of personal data by PARAMANT on behalf of the Controller in connection with the PARAMANT relay and signing services, including all sector relays: healthcare, legal, finance, IoT, and general.
PARAMANT acts exclusively as a processor. The Controller determines the purposes and means of processing. The subject matter is secure relay of encrypted files, encrypted document delivery for signing requests and associated metadata between authenticated parties.
| Nature | Ghost Pipe and ParaShare payloads are stored in RAM only and destroyed after retrieval or TTL expiry. ParaSign request documents are encrypted in the browser and may be persisted as ciphertext until the signing envelope expires. |
| Purpose | Secure point-to-point file transfer and encrypted delivery of documents for signing as instructed by the Controller |
| Duration | Coterminous with the service subscription. Transfer payloads are destroyed within their transfer TTL. ParaSign ciphertext and envelope records are destroyed at envelope expiry. |
| Personal data categories | Any personal data embedded in transferred files (content encrypted, invisible to processor); API key contact email; device identifiers (hashed in CT log) |
| Data subjects | Any natural persons whose data appears in files transferred via the service |
PARAMANT shall:
The Controller provides general authorisation for PARAMANT to use the following sub-processors:
| Sub-processor | Location | Purpose | Data transferred |
|---|---|---|---|
| Hetzner Online GmbH | Germany (NBG1) | Infrastructure hosting | Encrypted transfer payloads in RAM; encrypted ParaSign document capsules may persist until envelope expiry |
| Resend Inc. | US (SCC applied) | Transactional email, including optional signing invitations | Email address and message; for an optional signing invitation, the complete personal access link; no document plaintext |
PARAMANT will notify the Controller at least 14 days in advance of any intended changes to sub-processors, giving the Controller the opportunity to object.
All relay infrastructure is located in the EU (Hetzner DE, NBG1). Resend Inc. operates in the United States; the transfer is covered by Standard Contractual Clauses (Commission Decision 2021/914/EU, Module 1). No other personal data is transferred outside the EEA.
| Measure | Implementation |
|---|---|
| Encryption in transit | TLS 1.3 minimum on all relay endpoints |
| End-to-end encryption of content | File payloads encrypted client-side with ML-KEM-768 + ECDH P-256 hybrid (NIST FIPS 203). Relay holds only ciphertext. |
| Encryption at rest | Ghost Pipe and ParaShare payloads remain RAM-only. ParaSign request documents are stored only as browser-encrypted AES-256-GCM capsules; the relay does not receive the decryption key. |
| Data minimisation | Filenames not stored in plaintext (enc_meta ciphertext only); device IDs hashed SHA3-256 in CT log; no logging of payload content |
| Access control | API key authentication on all relay endpoints; admin panel protected with TOTP MFA and per-IP rate limiting (5 attempts/min) |
| Audit logging | Certificate Transparency log — transfer hashes and device key commitments, no payload content; tamper-evident Merkle tree |
| Integrity and availability | auditd (49 CIS L2 rules), AIDE daily file integrity check, AppArmor enforcing, CIS Ubuntu 24.04 L2 benchmark — 114 checks |
| Infrastructure hardening | Docker containers: read-only FS, no-new-privileges, cap_drop ALL, non-root user; HSTS max-age=63072000 |
| Vulnerability management | Independent security audit completed April 2026 — see security audit summary |
PARAMANT will notify the Controller without undue delay, and in any case within 48 hours, after becoming aware of a personal data breach affecting data processed under this agreement. Notification will be sent to the email address provided in the signature form below and will include, to the extent available: the nature of the breach; categories and approximate number of data subjects and records affected; likely consequences; and measures taken or proposed to address the breach.
The Controller may request a compliance review, no more than once per calendar year, by providing at least 30 days’ written notice to privacy@paramant.app. PARAMANT will provide relevant documentation and, where applicable, access to system configurations. Physical on-site access requires prior agreement on scope, scheduling, and reasonable costs.
Liability of each party for breach of this agreement is governed by Article 82 GDPR. PARAMANT’s aggregate contractual liability is limited to the total fees paid by the Controller in the 12 months preceding the event giving rise to the claim, except in cases of wilful misconduct or gross negligence.
This agreement is effective from the date of signature and remains in force for the duration of the Controller’s service subscription. Upon termination, PARAMANT will delete all personal data within 30 days, except where retention is required by applicable law. The CT log (containing only hashed identifiers, no payload content) may be retained for audit and compliance purposes.
This agreement is governed by the law of the Federal Republic of Germany. Any dispute arising under or in connection with this agreement shall be subject to the exclusive jurisdiction of the courts of Germany.
Enter your details below to sign this agreement. You will receive a countersigned copy by email immediately.