Legal — effective 1 January 2025

Data Processing Agreement

If the Dutch and the English text differ, the Dutch version prevails. The Dutch text is at /dpa.

GDPR Article 28 compliant agreement between Paramantis Solutions B.V. (processor) and your organisation (controller). Governs all personal data processed through the Paramant relay service.

Zero-knowledge summary: Paramantis operates a zero-knowledge relay for transfers and for browser-created signing requests. Those payloads are encrypted client-side before they reach our infrastructure, so outside the hosted signing ceremony on the /v1 API we hold only ciphertext and cannot access the content. The hosted signing ceremony on the /v1 API is the exception the Controller should be aware of: there the document is supplied to Paramantis in readable form so that Paramantis can run the ceremony, and Paramantis is a processor of that content for the life of the envelope. We process only the minimum technical metadata required to route and expire transfers.

1. Parties

ProcessorParamantis Solutions B.V. (“Paramantis”), Harderwijk, the Netherlands, KvK 42115132. The service is operated on Hetzner Online GmbH, NBG1, Nuremberg, Germany. Contact: privacy@paramant.app
ControllerThe organisation identified in the signature form below
Effective dateDate of electronic signature

2. Subject matter and scope

This agreement governs the processing of personal data by Paramantis on behalf of the Controller in connection with the Paramant relay and signing services, including all sector relays: healthcare, legal, finance, IoT, and general.

Paramantis acts exclusively as a processor. The Controller determines the purposes and means of processing. The subject matter is secure relay of encrypted files, encrypted document delivery for signing requests and associated metadata between authenticated parties.

3. Nature, purpose, and duration of processing

NatureGhost Pipe and ParaShare (the ParaSend web app) payloads are stored in RAM only and destroyed after retrieval or TTL expiry. ParaSign request documents are encrypted in the browser and may be persisted as ciphertext until the signing envelope expires.
PurposeSecure point-to-point file transfer and encrypted delivery of documents for signing as instructed by the Controller
DurationCoterminous with the service subscription. Transfer payloads are destroyed within their transfer TTL. ParaSign ciphertext and envelope records are destroyed at envelope expiry.
Personal data categoriesAny personal data embedded in transferred files (content encrypted, invisible to processor); API key contact email; device identifiers (hashed in CT log)
Data subjectsAny natural persons whose data appears in files transferred via the service

4. Processor obligations

Paramantis shall:

  1. Process personal data only on documented instructions from the Controller, unless required to do so by Union or Member State law to which Paramantis is subject
  2. Ensure that persons authorised to process personal data have committed to confidentiality or are under an appropriate statutory obligation of confidentiality
  3. Implement appropriate technical and organisational measures in accordance with Article 32 GDPR (see Section 7)
  4. Assist the Controller with obligations under Articles 32–36 GDPR, taking into account the nature of processing and the information available to Paramantis
  5. At the choice of the Controller, delete or return all personal data after the end of provision of processing services, and delete existing copies unless Union or Member State law requires storage of the personal data
  6. Make available to the Controller all information necessary to demonstrate compliance with obligations laid down in Article 28 GDPR, and allow for and contribute to audits and inspections
  7. Immediately inform the Controller if, in its opinion, an instruction infringes GDPR or other applicable data protection law

5. Sub-processors

The Controller provides general authorisation for Paramantis to use the following sub-processors:

Sub-processorLocationPurposeData transferred
Hetzner Online GmbHGermany (NBG1)Infrastructure hostingEncrypted transfer payloads in RAM; encrypted ParaSign document capsules persist until the envelope expires: 30 days unless the request asks for another term, and never longer than 365 days
Resend (Plus Five Five, Inc.)US (Standard Contractual Clauses)Transactional email: account and billing notices, signing invitations, and invitations to collect a file sent to named recipientsThe recipient email address, the subject and the message. For a signing invitation, the complete personal access link. For a send to named recipients, the file name chosen by the Controller, and a one-time link that does not by itself open the file. No document plaintext and no encryption key
Mollie B.V.Netherlands (EU)Payment processing for paid plansThe amount, a plan description, and the payment metadata the relay sets: accountId, product, plan, interval. No email address is sent while recurring billing is off, which is how production runs. Card details are entered on Mollie’s own pages and never reach Paramantis
Moneybird B.V.Netherlands (EU)Bookkeeping, only where the operator has connected an administrationThe invoice or credit note: number, date, description, amounts and VAT, the billing details entered by the Controller (company name, invoice address, VAT number), the email address, and the PDF of the document. No transfer, file or signature data

Current status of each sub-processor, with what it receives and never receives: /en/partners.

Paramantis will notify the Controller at least 14 days in advance of any intended changes to sub-processors, giving the Controller the opportunity to object.

6. International transfers

One transfer outside the EEA: transactional email. All relay infrastructure is in the EU (Hetzner DE, NBG1). Email (only the email address and the invite link, never the document or a key) still goes through Resend Inc. in the United States for now. The transfer is covered by Standard Contractual Clauses (Commission Implementing Decision (EU) 2021/914). Payments run through Mollie B.V. in the Netherlands. Bookkeeping runs through Moneybird B.V., also in the Netherlands, only where the operator has connected an administration. No other personal data is transferred outside the EEA.

That is the one exception in the chain; we are moving to a Dutch provider. It joins the list in section 5 only once the contract is in place, and you hear about it at least 14 days in advance.

7. Technical and organisational measures (Article 32)

MeasureImplementation
Encryption in transitTLS 1.3 minimum on all relay endpoints
End-to-end encryption of contentFile payloads are encrypted client-side and, outside the hosted signing ceremony on the /v1 API, the relay holds only ciphertext. Authenticated web app and SDK transfers use the ML-KEM-768 + ECDH P-256 hybrid (NIST FIPS 203); browser-encrypted links and the two extensions use AES-256-GCM with the key in the URL fragment and no key exchange.
Encryption at restGhost Pipe and ParaShare payloads remain RAM-only. ParaSign request documents created in the browser are stored only as browser-encrypted AES-256-GCM capsules; the relay does not receive the decryption key. Documents submitted to the hosted signing ceremony on the /v1 API are held by the relay and sealed at rest under a key the relay holds.
Data minimisationFilenames not stored in plaintext (enc_meta ciphertext only); device IDs hashed SHA3-256 in CT log; no logging of payload content
Access controlAPI key authentication on all relay endpoints; admin panel protected with TOTP MFA and per-IP rate limiting (5 attempts per 15 minutes)
Audit loggingCertificate Transparency log: transfer hashes and device key commitments, no payload content; tamper-evident Merkle tree
Integrity and availabilityauditd (49 CIS L2 rules), AIDE daily file integrity check, AppArmor enforcing, CIS Ubuntu 24.04 L2 benchmark: 114 checks
Infrastructure hardeningDocker containers: read-only FS, no-new-privileges, cap_drop ALL, non-root user; HSTS max-age=63072000
Vulnerability managementIndependent security audit completed April 2026; see security audit summary

8. Personal data breach notification

Paramantis will notify the Controller without undue delay, and in any case within 48 hours, after becoming aware of a personal data breach affecting data processed under this agreement. Notification will be sent to the email address provided in the signature form below and will include, to the extent available: the nature of the breach; categories and approximate number of data subjects and records affected; likely consequences; and measures taken or proposed to address the breach.

9. Audit rights

The Controller may request a compliance review, no more than once per calendar year, by providing at least 30 days’ written notice to privacy@paramant.app. Paramantis will provide relevant documentation and, where applicable, access to system configurations. Physical on-site access requires prior agreement on scope, scheduling, and reasonable costs.

10. Liability

Liability of each party for breach of this agreement is governed by Article 82 GDPR. Paramantis’s aggregate contractual liability is limited to the total fees paid by the Controller in the 12 months preceding the event giving rise to the claim, except in cases of wilful misconduct or gross negligence.

11. Term and termination

This agreement is effective from the date of signature and remains in force for the duration of the Controller’s service subscription. Upon termination, Paramantis will delete all personal data within 30 days, except where retention is required by applicable law. The CT log (containing only hashed identifiers, no payload content) may be retained for audit and compliance purposes.

12. Governing law and jurisdiction

This agreement is governed by the law of the Federal Republic of Germany. Any dispute arising under or in connection with this agreement shall be subject to the exclusive jurisdiction of the courts of Germany.


Sign electronically

Enter your details below to sign this agreement. You will receive a countersigned copy by email immediately.

✓ Agreement signed
A countersigned copy has been sent to
Keep your reference number. Questions: privacy@paramant.app
Enterprise / healthcare addenda: For NEN 7510, NIS2, or sector-specific addenda to this agreement, email privacy@paramant.app with your sector and requirements. Enterprise contracts with custom SLAs and jurisdiction clauses are available on request.