# Tally Sign Data Processing Addendum

**Effective date:** September 27, 2026
**Last updated:** September 27, 2026

This Data Processing Addendum ("**DPA**") is between Tally Integrations LLC, organized under the laws of the State of Nevada (mailing address: available on request from support@tallysign.com) ("**Tally**", "**we**", "**us**"), and the company that has accepted the [Tally Sign Terms of Service](/legal/terms-of-service) (the "**Terms**") ("**Customer**", "**you**").

It explains how Tally handles personal data that it processes for you when your company uses Tally Sign. It forms part of the Terms.

## In brief

This summary doesn't replace the DPA below.

- **Scope:** personal data in the documents, signing records and emails that Tally handles for you. Our own account, sign-in, billing and security records are covered by our [Privacy Policy](/legal/privacy-policy) instead.
- **Where:** stored in the United States. Transfers from the EEA, UK and Switzerland use the Standard Contractual Clauses and the UK Addendum. We aren't certified under the Data Privacy Framework.
- **Subprocessors:** Railway, Resend, OpenRouter and the hosts that run our current AI model (Anthropic's Claude models), as listed on our [Subprocessors](/legal/subprocessors) page. All of them process data in the United States. We give 30 days' notice before adding or replacing one, including a new AI model provider, and you can object.
- **AI:** Tally doesn't use your data to train AI models. You can have the in-app AI assistant turned off for your company (Section 5.4).
- **Breaches:** we tell you without undue delay, and within 72 hours of becoming aware (Section 12).
- **Security:** Annex II lists what we do, including single sign-on (SAML and OpenID Connect) on every plan, and, in its Section 14, what we don't do yet (for example, no SOC 2 report and no multi-factor sign-in of our own).
- **Deletion:** everything is deleted 6 months after an account is paused, or sooner if you ask. We return your data first if you ask before then (Section 13).

---

## 1. How this DPA works

1.1 **When it applies.** This DPA applies when you accept the Terms, and for as long as Tally processes Customer Personal Data (defined in Section 2). You don't need to sign anything separately. If you need a signed copy for your records, email support@tallysign.com and we will countersign this version.

1.2 **Who it covers.** This DPA covers personal data that Tally processes **on your behalf** in providing the Service. It doesn't cover personal data that Tally handles **for its own purposes** as a controller or "business", such as your Users' account and sign-in details, billing records, security records and support correspondence, or the limited processing described in Section 3.5. Our [Privacy Policy](/legal/privacy-policy) describes that processing.

1.3 **Order of precedence.** If there is a conflict about the processing of Customer Personal Data, the following apply in this order: (a) the Standard Contractual Clauses and UK Addendum, where they apply under Section 10; (b) a Signed Agreement (as defined in the Terms), but only where it gives Customer Personal Data more protection than this DPA; (c) this DPA, including the Subprocessors page; (d) the Terms. Nothing overrides (a). Fees, refunds and limits of liability are governed by the Terms, except where this DPA expressly says otherwise or the Standard Contractual Clauses require otherwise.

1.4 **Related documents.** This DPA refers to our [Terms of Service](/legal/terms-of-service), [Privacy Policy](/legal/privacy-policy), [Subprocessors](/legal/subprocessors) page, [Acceptable Use Policy](/legal/acceptable-use-policy) and [Electronic Records and Signature Disclosure](/legal/electronic-signature-disclosure).

---

## 2. Definitions

Capitalized words not defined here, such as "Account", "Account Owner", "Connected AI App", "Customer Content", "Service" and "User", have the meaning in the Terms. The definitions below add to them. In addition:

- "**Applicable Data Protection Law**" means every data protection and privacy law that applies to the processing of Customer Personal Data under this DPA. That includes, where they apply: the EU General Data Protection Regulation 2016/679 ("**GDPR**"); the GDPR as it forms part of UK law, together with the UK Data Protection Act 2018 ("**UK GDPR**"); the Swiss Federal Act on Data Protection ("**FADP**"); the California Consumer Privacy Act as amended by the California Privacy Rights Act, and its regulations ("**CCPA**"); and other US state consumer privacy laws.
- "**Customer Personal Data**" means personal data in Customer Content that Tally processes on your behalf in providing the Service. It includes personal data in documents, templates, field values, signatures, signed PDFs, attachments, uploads, audit trails, comments and suggested edits, emails sent on your behalf, data read from a Salesforce org you connect, and content your Users send to the in-app AI assistant. Annex I describes it in detail.
- "**Recipient**" means anyone you send a document to through the Service, whether to sign it or to get a copy. A "**Signer**" is a Recipient you ask to sign. Recipients don't need a Tally Sign account.
- "**Paused**" means the state an Account is in under the Terms after a trial ends without a plan, or after the 14-day grace period that follows a failed payment or the end of a subscription. While Paused, Users can't send documents or use the AI assistant, but can still sign in, view, download and pay to resume, and Recipients can still sign documents that were already sent.
- "**Security Incident**" means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, Customer Personal Data held by Tally or its Subprocessors.
- "**Subprocessor**" means a third party that Tally engages to process Customer Personal Data, including a provider that one of Tally's Subprocessors uses to perform its service for Tally (such as a model host that OpenRouter passes requests to).
- "**Standard Contractual Clauses**" or "**SCCs**" means the standard contractual clauses approved by the European Commission in Implementing Decision (EU) 2021/914.
- "**UK Addendum**" means the International Data Transfer Addendum to the EU Commission Standard Contractual Clauses issued by the UK Information Commissioner under section 119A of the Data Protection Act 2018, as in force from time to time.

Terms such as "controller", "processor", "data subject", "personal data", "processing" and "supervisory authority" have the meanings given in the GDPR. "Business", "service provider", "contractor", "sell" and "share" have the meanings given in the CCPA. Where another law uses an equivalent term, the equivalent term applies.

---

## 3. Roles and scope

3.1 **Your role and ours.** For Customer Personal Data, you are the controller (or "business" under the CCPA) and Tally is your processor (or "service provider"). If you use the Service to process personal data on behalf of your own client, you are a processor, and Tally is your subprocessor. In that case you confirm that your controller has authorized the instructions you give us and our use of Subprocessors, and you are responsible for passing on to your controller any notices we give you under this DPA.

3.2 **Details of processing.** Annex I sets out the subject matter, nature, purpose and duration of the processing, the types of Customer Personal Data, and the categories of data subjects.

3.3 **Services you connect or direct us to use.** When you or your Users tell the Service to send Customer Personal Data to a third party, that third party receives it under your own arrangements with it. It is not Tally's Subprocessor, and Tally isn't responsible for what it does with the data. This includes:

- (a) **Connected AI Apps**, such as ChatGPT or Claude. Any User can connect one to their own access. The app can then read, create, edit, send, remind, void and delete documents as that User, within your Account. What the Service returns to the app goes to that app's provider under the User's own account and terms. That can include document and template content, Recipient names, email addresses, titles and companies, signing status and decline reasons, recent audit-trail events (which can include names, email addresses and comment excerpts), data from your Salesforce org, links that let someone sign a pending document as the Recipient, and download links to completed PDFs. A completed PDF includes the Certificate of Completion, which shows each Signer's IP address and device details. This is separate from the in-app AI assistant in Section 8.4, even where the same company is involved. Section 4.2 explains how connections are revoked.
- (b) **Your Salesforce org.** When Tally reads data from your org, processes it in the Service, or writes records, Files or configuration into your org, that is processing of Customer Personal Data under this DPA. Once data is in your org, Salesforce's processing of it, and what you and your org's automations do with it, are governed by your own agreement with Salesforce, and Salesforce isn't Tally's Subprocessor.
- (c) **Automation destinations.** Messages to Slack, Microsoft Teams or Discord, webhooks to addresses you choose, and automation emails to addresses you enter.
- (d) **Recipients themselves.** Signed PDFs, including the Certificate of Completion, are emailed to every party and can be downloaded again from the signing link (Annex I, Section B.5).
- (e) **Your identity provider.** If you set up single sign-on, your identity provider (such as Okta, Microsoft Entra ID or Google Workspace) signs your Users in to Tally Sign and sends Tally their name and email address. Tally sends it only the sign-in request, which can include the User's email address. Your identity provider acts under your own agreement with it, not as Tally's Subprocessor. Likewise, Google, Microsoft and Salesforce aren't Tally's Subprocessors when a User chooses to sign in with them.

3.4 **Tally's permitted internal uses.** Tally may also use Customer Personal Data, only as far as necessary and as Applicable Data Protection Law allows, to:

- (a) keep the Service secure, and detect, prevent and investigate fraud, abuse, security incidents and breaches of the Terms or the [Acceptable Use Policy](/legal/acceptable-use-policy);
- (b) fix errors and keep the Service working as intended;
- (c) apply the fair-use and AI usage limits described in the Terms;
- (d) meet its legal obligations;
- (e) establish, exercise or defend legal claims; and
- (f) create aggregated or de-identified statistics about how the Service is used (not the content of documents, templates, emails or AI inputs) to maintain and improve the Service, provided that Tally takes reasonable measures so the statistics can't be linked to a person, publicly commits not to re-identify them, and contractually requires anyone it shares them with to make the same commitment.

These are the kinds of internal purposes permitted to a service provider under 11 CCR §7050(a). Tally won't use Customer Personal Data for any other purpose.

3.5 **Where Tally acts as a controller.** To the extent Tally decides the purposes of processing under Section 3.4(a), (c) and (e), such as keeping Signers' IP addresses in its security and server logs, Tally acts as an independent controller for that processing and is responsible for it under Applicable Data Protection Law. Our [Privacy Policy](/legal/privacy-policy) tells Recipients about it.

3.6 **No AI training.** Tally won't use Customer Personal Data, including in de-identified or aggregated form, to train, fine-tune or evaluate AI models, or to develop AI features for other customers.

---

## 4. Your responsibilities

4.1 **Lawful instructions and data.** You are responsible for:

- (a) having a lawful basis for the Customer Personal Data you put into the Service and for each instruction you give;
- (b) giving any notices to, and getting any consents from, data subjects that the law requires. This includes privacy notices to Recipients about the documents you send them. Our [Privacy Policy](/legal/privacy-policy) tells Recipients that the sender is responsible for their data;
- (c) the accuracy of Customer Personal Data, including Recipients' names and email addresses;
- (d) deciding whether an electronic signature is appropriate for each document, as described in the Terms; and
- (e) not putting special categories of personal data, criminal-offence data, government identification numbers, financial account numbers or children's data into the Service unless you have a lawful basis to do so and have taken into account the measures in Annex II, including those listed in its Section 14.

4.2 **Your security settings.** You control parts of the Service's security: who has an account and what role they have, how they sign in (including single sign-on and whether it is required), API keys, Connected AI Apps, the Salesforce user you connect with, and the destinations your automations send to. When someone leaves your company, or you suspect their account is compromised, you must:

- (a) remove or disable the User;
- (b) revoke any API keys they created or had access to; and
- (c) use "Disconnect all apps" in Settings if they connected a Connected AI App.

Removing a User ends their sessions, API keys and app connections along with their access. Changing a password doesn't revoke API keys or app connections, so do (b) and (c) as well when you're only changing credentials. If you use single sign-on, removing the person from your identity provider stops new sign-ins through it, but doesn't remove the User from Tally Sign or end sessions that already exist, so you must still do (a) (Annex II, Sections 2, 4 and 14).

4.3 **Keeping your contact details current.** We send notices under this DPA to your Notice Contacts (as defined in the Terms: the Account Owner, every admin and your billing email address), to anyone registered under Section 8.3, and to any security contact you register under Section 12.3. You must keep those addresses current and able to receive email.

4.4 **Keeping what you need.** You are responsible for downloading and keeping any documents, signed PDFs and audit trails you need for your own legal, tax or record-keeping obligations before they are deleted under Section 13.

---

## 5. Processing only on your instructions

5.1 **Instructions.** Tally will process Customer Personal Data only on your documented instructions, unless the law that applies to Tally requires otherwise. In that case Tally will tell you about that legal requirement before processing, unless the law prohibits telling you.

5.2 **What counts as your instructions.** You instruct Tally to process Customer Personal Data:

- (a) to provide the Service under the Terms and this DPA;
- (b) as your Users direct through the Service, including by sending documents, setting up automations, connecting Salesforce or Connected AI Apps, creating API keys, and using the in-app AI assistant;
- (c) to transfer Customer Personal Data as described in Section 10; and
- (d) as you otherwise direct in writing, where Tally agrees that the instruction is consistent with the Terms.

5.3 **Instructions we believe are unlawful.** Tally will tell you promptly if, in its opinion, an instruction infringes Applicable Data Protection Law. Tally may suspend processing under that instruction until you confirm or change it. Tally doesn't give legal advice and has no duty to review your instructions for legal compliance.

5.4 **The AI assistant.** When a User uses the in-app AI assistant, you instruct Tally to send the content described in Annex I, Section B.6 to the Subprocessors that provide the assistant (Section 8.4). The assistant works only on drafts, templates and email designs, not on documents that have been sent. The Service doesn't yet have a setting that lets you turn the assistant off yourself. Your Account Owner can ask us at privacy@tallysign.com to turn it off for your Account, and we will do so within 5 business days. While it is off, no Customer Personal Data is sent to OpenRouter or any model host.

---

## 6. Confidentiality and Tally personnel

6.1 **Confidentiality.** Tally will make sure that every person it authorizes to process Customer Personal Data is bound by a written duty of confidentiality or an appropriate statutory duty.

6.2 **Need-to-know access.** Tally will limit access to Customer Personal Data to personnel who need it to provide, support, secure or maintain the Service, or to comply with law.

6.3 **Support sign-in.** A small number of named Tally platform administrators may access your Account and Customer Personal Data, including by signing in to the Service as one of your Users, only:

- (a) to provide support you or your Users ask for;
- (b) to investigate a security, abuse or technical problem, or a suspected breach of the Acceptable Use Policy, affecting your Account or the Service; or
- (c) where the law requires it.

How support sign-ins work:

- A support sign-in lasts at most 2 hours. During it, the administrator has the same access as the User.
- A banner is shown to the Tally staff member during the session, and Tally logs who signed in, as which User, and when. The Service doesn't notify you or the User automatically.
- If Tally signs in without a request from you or your Users, it will tell your Account Owner within 5 business days afterwards, unless the law or an active investigation prevents it.
- On request, Tally will give you a list of support sign-ins to your Account in the previous 12 months.
- During a support sign-in, Tally won't send, sign, void, remind, unlock or delete documents, or change Users, billing or integrations, unless you or the User asked it to or it is needed to stop an active security threat.
- **Actions taken during a support sign-in are currently recorded in document audit trails and Certificates of Completion under the name of the User Tally signed in as, not the staff member's name.** Tally's own log shows when a support session was active.

---

## 7. Security

7.1 **Security measures.** Tally will implement and maintain the technical and organizational measures described in Annex II, which are the measures Tally takes under Article 32 of the GDPR for the Service.

7.2 **Known gaps.** Annex II, Section 14 lists measures Tally doesn't currently have. You should take them into account when you decide what data to put into the Service. This doesn't reduce Tally's own obligations under Article 32 of the GDPR or other Applicable Data Protection Law.

7.3 **Changes.** Tally may update the measures in Annex II over time, but won't reduce the overall level of protection they provide during your subscription.

---

## 8. Subprocessors

8.1 **General authorization.** You give Tally general authorization to engage the Subprocessors listed on our [Subprocessors](/legal/subprocessors) page. Annex III reproduces that list as of the effective date. You also authorize Tally to add or replace Subprocessors by following this Section.

8.2 **Our obligations for Subprocessors.** For every Subprocessor, Tally will:

- (a) have a written agreement that imposes data protection obligations at least as protective as those in this DPA, to the extent they apply to the service the Subprocessor provides, including the restrictions required of a service provider's sub-service providers under the CCPA. Where a Subprocessor uses its own providers to perform its service for Tally (for example, OpenRouter passing requests to the model host that runs the selected AI model), Tally will require that Subprocessor to impose equivalent obligations on them;
- (b) limit what the Subprocessor can access to what it needs to provide its service; and
- (c) remain fully liable to you for the acts and omissions of each Subprocessor as if they were Tally's own, subject to Section 15.

8.3 **Notice of changes.** At least 30 days before a new or replacement Subprocessor starts processing Customer Personal Data, Tally will update the Subprocessors page and email your Notice Contacts and anyone at your company who has asked for these notices by emailing privacy@tallysign.com. The notice will name the Subprocessor and say what it will do, what Customer Personal Data it will process, and where.

8.4 **AI model providers.** The in-app AI assistant sends requests through OpenRouter to a host that runs the AI model Tally has selected. As of the effective date, the assistant uses Anthropic's Claude models.

- (a) **Routing.** OpenRouter chooses which host serves each request. For the current model, that is Anthropic itself or a cloud provider that OpenRouter routes to (such as Amazon Bedrock or Google Vertex AI), in the United States. These hosts are listed on the Subprocessors page.
- (b) **Data use.** OpenRouter and the model hosts process assistant content to return the reply. Under their terms, they don't use it to train AI models. They may keep it for a limited time to monitor for abuse and to meet their legal obligations. Tally doesn't store the conversation with the assistant (Annex I, Section B.6).
- (c) **Changing the model provider or host.** Moving the assistant to a model from a different provider, or to a host that isn't listed, is adding a new Subprocessor. Section 8.3 applies, and Tally won't send Customer Personal Data to it until the notice period has run. You can have the assistant turned off at any time under Section 5.4.

8.5 **Objecting.** You may object to a new Subprocessor on reasonable grounds relating to data protection by emailing privacy@tallysign.com within the notice period and explaining why. Tally will work with you in good faith to address the concern, for example by suggesting a change in how you use the affected feature. For an AI model provider, you may have the in-app AI assistant turned off for your Account under Section 5.4, and if you do, Tally won't send your Customer Personal Data to the new provider.

8.6 **If we can't resolve the objection.** If Tally can't reasonably resolve your objection before the change takes effect, you may end your subscription, or stop using the affected feature, by written notice to privacy@tallysign.com before the change takes effect. Termination under this Section takes effect on the date in your notice, which may be before the end of your billing period despite the cancellation rules in the Terms. No further fees will be charged after that date, and no early-termination fee applies. This is your only remedy for an objection to a Subprocessor.

8.7 **Urgent replacements.** If Tally must replace a Subprocessor urgently to keep the Service running or secure, for example because a provider stops operating or suffers a security incident, Tally may do so with shorter notice. Tally will give notice as soon as it reasonably can, and Sections 8.5 and 8.6 still apply.

8.8 **Copies of Subprocessor terms.** On request, Tally will give you the data protection terms it has with a Subprocessor. Tally may remove commercial terms and anything confidential first. This satisfies Clause 9(c) of the SCCs.

---

## 9. US state privacy laws

9.1 **Service provider terms.** Where the CCPA or another US state privacy law applies to Customer Personal Data, Tally acts as your service provider, contractor or processor, and Tally:

- (a) will not **sell** or **share** Customer Personal Data;
- (b) will process Customer Personal Data only for the **business purposes** set out in Annex I (providing the Service to you) and the internal purposes listed in Section 3.4, and won't retain, use or disclose it for any other purpose, including any other commercial purpose;
- (c) won't retain, use or disclose Customer Personal Data outside the direct business relationship between you and Tally;
- (d) won't combine Customer Personal Data with personal data it receives from or on behalf of anyone else, or collects from its own interactions with a consumer, except as the CCPA and its regulations permit;
- (e) will comply with the obligations that apply to it under the CCPA and give Customer Personal Data the level of privacy protection the CCPA requires;
- (f) will tell you if it decides it can no longer meet its obligations under the CCPA or this DPA;
- (g) lets you take reasonable and appropriate steps to make sure Tally uses Customer Personal Data in a way that is consistent with your obligations under the CCPA, through the information and audit rights in Section 14;
- (h) lets you, after notice to Tally, take reasonable and appropriate steps to stop and remediate any use of Customer Personal Data that isn't authorized, including by asking Tally to confirm in writing that specific Customer Personal Data has been deleted;
- (i) will help you respond to consumer requests as described in Section 11;
- (j) will cooperate reasonably, at your request, with risk assessments and cybersecurity audits that the CCPA regulations require you to carry out, as far as they concern the Service; and
- (k) won't attempt to re-identify any de-identified data it receives from you or creates under Section 3.4(f).

9.2 **Certification.** Tally certifies that it understands the restrictions in Section 9.1 and will comply with them.

9.3 **Other state laws.** The duties in Sections 5, 6, 8, 11, 13 and 14 are also intended to meet the processor contract requirements of other US state consumer privacy laws, such as those of Virginia, Colorado and Connecticut.

---

## 10. International transfers

10.1 **Where Customer Personal Data is processed.** Tally is based in the United States, and the Service stores Customer Personal Data in the United States. Tally doesn't offer a choice of hosting region. All Subprocessors process Customer Personal Data in the United States, as listed in Annex III.

10.2 **No DPF certification.** Tally is not currently certified under the EU-US Data Privacy Framework, the UK Extension to it, or the Swiss-US Data Privacy Framework. Tally relies on the safeguards in this Section.

10.3 **Transfers from the EEA.** To the extent Customer Personal Data subject to the GDPR is transferred from you to Tally in a country that doesn't have an adequacy decision, the SCCs are incorporated into this DPA by reference and apply as follows:

- (a) **Module Two** (controller to processor) applies where you are a controller. **Module Three** (processor to processor) applies where you are a processor.
- (b) You are the "data exporter" and Tally is the "data importer".
- (c) **Clause 7** (docking clause) applies.
- (d) **Clause 9(a):** Option 2 (general written authorization) applies. The time period for notice of changes is the period in Section 8.3 of this DPA.
- (e) **Clause 11(a):** the optional language doesn't apply.
- (f) **Clause 13(a):** the competent supervisory authority is the one identified in Annex I, Section C.
- (g) **Clause 17:** Option 1 applies, and the governing law is the law of Ireland.
- (h) **Clause 18(b):** disputes are resolved by the courts of Ireland.
- (i) **Annex I** of the SCCs is completed by Annex I of this DPA. **Annex II** of the SCCs is completed by Annex II of this DPA. **Annex III** of the SCCs is completed by Annex III of this DPA.
- (j) The audit rights in Clause 8.9, the Subprocessor rules in Clause 9 and the deletion rules in Clauses 8.5 and 16(d) are carried out as described in Sections 14, 8 and 13 of this DPA, to the extent consistent with the SCCs.

10.4 **Transfers from the UK.** To the extent Customer Personal Data subject to the UK GDPR is transferred to Tally, the SCCs apply as described in Section 10.3, as amended by the UK Addendum, which is incorporated by reference. For the UK Addendum:

- (a) **Table 1:** the parties' details are those in Annex I, Section A.
- (b) **Table 2:** the selected modules and clauses are those in Section 10.3.
- (c) **Table 3:** the appendix information is in Annexes I, II and III of this DPA.
- (d) **Table 4:** either party may end the UK Addendum as allowed by its Section 19.

10.5 **Transfers from Switzerland.** To the extent Customer Personal Data subject to the FADP is transferred to Tally, the SCCs apply as described in Section 10.3, with these changes:

- (a) references to the GDPR include the FADP;
- (b) the competent supervisory authority is the Swiss Federal Data Protection and Information Commissioner;
- (c) "Member State" in Clause 18(c) doesn't exclude data subjects in Switzerland from bringing claims where they habitually reside; and
- (d) Clause 17 and Clause 18(b) remain as set out in Section 10.3.

10.6 **Onward transfers.** Tally receives Customer Personal Data in the United States under the SCCs and UK Addendum as described above. Each Subprocessor processes it in the United States and is bound by a written agreement with the same data protection obligations, as Clause 8.8 of the SCCs requires. If Tally ever engages a Subprocessor that processes Customer Personal Data outside the United States, it will say where under Section 8.3 and put in place a transfer safeguard recognized by Applicable Data Protection Law, such as the SCCs (Module Three).

10.7 **Government requests.** If a public authority asks Tally for Customer Personal Data, Tally will:

- (a) try to redirect the authority to request the data directly from you;
- (b) tell you promptly, unless the law prohibits it;
- (c) assess whether the request is lawful and challenge it where there are reasonable grounds to do so; and
- (d) disclose only the minimum data the request requires.

This Section adds to, and doesn't limit, Clause 15 of the SCCs where they apply.

10.8 **Transfer impact assessment.** On request, Tally will give you its transfer impact assessment covering its processing and its Subprocessors, and any other information you reasonably need to complete your own.

---

## 11. Helping with data subject requests

11.1 **Tools in the Service.** Users can do some of this work themselves:

- view Recipients and their details on each document;
- download signed PDFs, which include the Certificate of Completion and audit trail;
- edit or delete drafts and custom templates, and delete voided documents;
- remove attachments and uploads; and
- remove Users.

11.2 **What the Service doesn't let you do yourself.** The Service doesn't currently offer a bulk export, a self-service way to delete the Account, or a way to delete documents that have been completed or declined. When a User is removed, their name and email stay on the documents, audit events and comments they were part of.

11.3 **Our help.** Taking into account the nature of the processing, Tally will help you, by appropriate technical and organizational measures, to respond to requests from data subjects to exercise their rights under Applicable Data Protection Law. These include requests for access, correction, deletion, restriction, portability and objection. Where you can't meet a request with the tools in Section 11.1, Tally will, on your written instruction to privacy@tallysign.com:

- (a) provide a copy of the Customer Personal Data about the data subject that Tally holds in the Service, in a commonly used machine-readable format;
- (b) correct or delete specific Customer Personal Data in drafts, templates and Account records; and
- (c) delete an entire sent, completed or declined document, including its signed PDF and audit trail.

Tally won't edit the content, signatures, audit trail or Certificate of Completion of a sent, completed or declined document. You are responsible for the consequences of any deletion you instruct, including toward other parties to the document. Deleting data in the Service doesn't change copies that Recipients or other parties already received (Section 3.3). Tally will respond without undue delay and in time for you to meet the deadline that applies to you.

11.4 **Requests sent to Tally.** If Tally receives a request from a data subject about Customer Personal Data and can identify you from it, Tally will pass it to you without undue delay and tell the data subject it has done so. Tally won't otherwise respond to the request itself, except where you authorize it or the law requires it. This doesn't apply to requests about data Tally controls, such as a User's own account records, which Tally answers directly.

11.5 **Cost.** Tally won't charge for reasonable help under this Section. Tally may charge a reasonable fee based on its costs for deleting sent, completed or declined documents under Section 11.3(c), or where requests are manifestly unfounded, excessive or unusually burdensome, as far as Applicable Data Protection Law permits. Tally will tell you the fee before doing the work.

---

## 12. Security Incidents

12.1 **Notice to you.** Tally will notify you without undue delay after becoming aware of a Security Incident, and in any event within 72 hours. Tally "becomes aware" when it has a reasonable degree of certainty that a Security Incident affecting your Customer Personal Data has occurred, including when a Subprocessor tells Tally about one. Tally will promptly investigate any event that reasonably suggests a Security Incident. If Tally can't give all the information in Section 12.2 within that time, it will give what it has and provide the rest in stages.

12.2 **What the notice will contain.** The notice will include, as far as Tally knows at the time:

- (a) the nature of the Security Incident, including, where possible, the categories and approximate number of data subjects and records concerned;
- (b) the likely consequences;
- (c) the measures Tally has taken or proposes to take to address it and reduce its possible harm; and
- (d) a contact point for more information.

12.3 **How we'll notify you.** Tally will send the notice by email to your Notice Contacts, to anyone registered under Section 8.3, and to any security contact you register by emailing security@tallysign.com. If email may be affected by the incident, Tally will also post a notice in the Service.

12.4 **Investigation and help.** Tally will:

- (a) investigate the Security Incident;
- (b) take reasonable steps to contain it and reduce its harm;
- (c) keep you informed of material developments;
- (d) give you the information and help you reasonably need to meet your own obligations to notify supervisory authorities and data subjects; and
- (e) where the Security Incident was caused by Tally's or its Subprocessors' breach of this DPA, reimburse your reasonable costs of investigating and containing it and of notifications that the law requires you to make, subject to the Enhanced Cap in the Terms (Section 15).

12.5 **Who notifies regulators and data subjects.** You decide whether to notify supervisory authorities, data subjects or anyone else about a Security Incident that affects Customer Personal Data. Tally won't notify them on your behalf, or name you, without your approval, unless the law requires it.

12.6 **Not an admission.** Notifying you of, or responding to, a Security Incident is not an admission by Tally of any fault or liability.

12.7 **Unsuccessful attempts.** Unsuccessful attempts that don't compromise the security of Customer Personal Data aren't Security Incidents. Examples are failed sign-in attempts, pings, port scans and denial-of-service attempts that don't lead to access to Customer Personal Data.

12.8 **Our procedure and your reports.** Tally will maintain a written incident response procedure. To report a suspected Security Incident or a vulnerability to Tally, email security@tallysign.com.

---

## 13. Deletion and return of Customer Personal Data

13.1 **While your subscription is active.** Tally keeps Customer Personal Data for as long as your Account is active, unless your Users delete it using the Service or you instruct Tally to delete it. Tally doesn't automatically delete documents, audit trails or other Customer Personal Data from an active Account.

13.2 **Getting your data out.** Users can download signed PDFs at any time, including while your Account is Paused. Each signed PDF includes the Certificate of Completion and audit trail. Tally will never block downloading while an Account is Paused or suspended. The Service doesn't currently include a bulk export tool. At any time before deletion, your Account Owner or an admin can ask at privacy@tallysign.com for a copy of all of your Account's completed, declined and voided documents, each with its Certificate of Completion and audit trail, plus a list of each document's Recipients, status and key dates in a machine-readable format (such as CSV), and any other Customer Personal Data you ask for (such as drafts, templates, uploaded files and attachments) in a commonly used machine-readable format. Tally provides it free of charge, through a secure download link, within 30 days. If you ask before the deletion date, Tally won't delete the Account until it has delivered the copy and you have had at least 14 days to download it.

13.3 **When the Service ends.** Under the Terms, your Account is Paused when:

- (a) a free trial ends without a paid plan, in which case the Account is Paused immediately; or
- (b) a paid subscription ends, because it was cancelled (cancellation takes effect at the end of the billing period) or because payment failed, in which case the Account is Paused after a 14-day grace period.

While the Account is Paused, Tally keeps Customer Personal Data and processes it only as needed for what a Paused Account can still do. Users can sign in, view, download and pay to resume. Documents that were already sent continue through signing, including the related emails, reminders, and any automations and Salesforce updates you set up. You can void documents that are still out for signature if you don't want them signed.

If the Terms are terminated, for example by either party for breach, the Account is treated as Paused from the termination date, and Sections 13.2 and 13.4 apply. The 6-month period doesn't start while an Account is only suspended.

13.4 **Deletion after 6 months Paused.** If the Account stays Paused for 6 months from the date it was Paused, Tally will permanently delete the Account and all Customer Personal Data in the Service. That includes documents, templates, signed PDFs, audit trails, attachments, uploads, images, User accounts, single sign-on settings, and the files stored for the Account. Before deletion, Tally sends the warnings described in the Terms to your Notice Contacts, including about 30 days and at least 7 days before the deletion date. Deletion won't happen until at least 7 days after the final warning has been sent, so it can happen somewhat later than 6 months. Deletion is permanent: Tally won't restore deleted data, and you can't recover it.

13.5 **Your choice between deletion and return.** Article 28(3)(g) of the GDPR lets you choose whether your data is deleted or returned at the end of the Service. You make that choice as follows:

- if you download your data, or ask for its return under Section 13.2, before deletion, Tally returns it and then deletes it under Section 13.4 or 13.6;
- otherwise, you choose deletion under Section 13.4.

13.6 **Deleting earlier.** Your Account Owner may ask Tally to delete the Account and all Customer Personal Data sooner by emailing privacy@tallysign.com. Tally will verify the request with the Account Owner and then delete the data within 30 days, unless the law requires Tally to keep it. Early deletion doesn't depend on paying any amount you owe, and doesn't entitle you to a refund except as the Terms provide.

13.7 **Copies that remain for a time.** Some copies aren't removed at the moment of deletion:

- (a) **Backups.** Our hosting provider keeps backups of our database on a daily, weekly and monthly schedule. Backups contain Customer Personal Data as it was when the backup was taken, including document content, Recipient details, field values, signatures and audit trails. Backups taken before September 25, 2026, when files moved to separate file storage, also contain signed PDFs and uploaded files. Deleted data remains in backups until they expire, no more than 3 months after deletion. Deleted files may remain in our file storage provider's recovery copies until they are removed from backups, up to 3 months after deletion. Tally doesn't use backups except to recover the Service from a failure or loss of data. If Tally restores a backup, it will re-apply every deletion made since that backup was taken before the restored data is used, using a record it keeps of deleted Accounts (Account ID, name and deletion date only) for as long as it keeps backups.
- (b) **Server logs**, which can contain email addresses and email subject lines, are kept until they expire, no more than 30 days after they are written.
- (c) **Salesforce sync status.** A small record of the Salesforce sync steps for each document (Salesforce record IDs and step status) is kept until Tally removes it, no later than 12 months after deletion.
- (d) **Cached images.** Copies of logos and images kept in Recipients' browsers, or by email providers that display them, may remain after deletion (Annex II, Section 8).
- (e) **Subprocessor records.** Subprocessors may keep limited records, such as email delivery logs, under their own retention terms, as described on the Subprocessors page.

Until these copies are gone, this DPA continues to protect them, and Tally won't use them for any other purpose.

13.8 **What deletion doesn't reach.** Deletion in the Service doesn't affect copies that are outside Tally's control, including:

- emails and signed PDFs already delivered to Recipients and others;
- data written into your Salesforce org;
- data sent to Connected AI Apps; and
- data sent to your automation destinations.

13.9 **Tally's own records.** Tally may keep records it holds as a controller for its own purposes, as described in the [Privacy Policy](/legal/privacy-policy), for the periods stated there. These include billing records, and Tally's log of platform administration and support actions, which can contain Users' names and email addresses and is kept for 24 months.

13.10 **Legal holds.** If the law requires Tally to keep any Customer Personal Data, Tally will keep it only as long as, and only for the purposes, the law requires, and will continue to protect it under this DPA.

13.11 **Confirmation.** Tally emails the Account Owner when the Account has been deleted. On request, Tally will confirm in writing that deletion under this Section has taken place. Tally won't give that confirmation until it has checked that the Account's stored files have been deleted.

---

## 14. Information and audits

14.1 **Information.** Tally will make available the information you reasonably need to show compliance with Article 28 of the GDPR and the other Applicable Data Protection Laws. This includes this DPA, its Annexes and the Subprocessors page. Tally doesn't currently hold third-party security certifications, audit reports or penetration test reports.

14.2 **Security questionnaires.** Once every 12 months, and after any Security Incident affecting your Customer Personal Data, Tally will answer a reasonable written security and privacy questionnaire you send.

14.3 **Audits.** You may audit Tally's compliance with this DPA under these conditions:

- (a) you give at least 30 days' written notice to privacy@tallysign.com, with a proposed scope;
- (b) the audit takes place no more than once in any 12-month period, unless a supervisory authority requires it or it follows a Security Incident affecting your Customer Personal Data;
- (c) the audit is carried out by you or an independent auditor who isn't a competitor of Tally and is bound by confidentiality obligations;
- (d) the audit takes place during normal business hours, in a way that doesn't unreasonably disrupt Tally's business;
- (e) the audit is carried out through documents, remote sessions and interviews, and the auditor doesn't access other customers' data or Tally's systems directly, unless a supervisory authority requires more;
- (f) each party bears its own costs, except that Tally may charge its reasonable costs for time beyond 8 hours per year, which it will estimate before the audit. If the audit shows a material breach of this DPA, Tally bears its own costs and will reimburse your reasonable audit costs, and will fix the breach promptly; and
- (g) the audit report is confidential to both parties, and you give Tally a copy.

14.4 **DPIAs and prior consultation.** Taking into account the nature of the processing and the information available to Tally, Tally will give you reasonable help with data protection impact assessments and prior consultations with supervisory authorities about your use of the Service, as required by Articles 35 and 36 of the GDPR and similar laws. Tally will first point you to the information in this DPA and its Annexes. Tally may charge a reasonable fee for help that goes beyond that, where Applicable Data Protection Law permits.

14.5 **SCCs.** Where the SCCs apply, this Section is how Tally will meet Clauses 8.9(c) and 8.9(d).

---

## 15. Liability

15.1 **Terms apply.** Each party's liability arising out of or relating to this DPA, including under the SCCs as far as they permit, is subject to the exclusions and limitations of liability in the Terms, including the Enhanced Cap for data claims. This DPA and the Terms together are one agreement for the purpose of those limits, so the limits apply to all claims in total, not separately to each document.

15.2 **What this Section doesn't limit.** Nothing in this DPA limits:

- (a) a party's liability to data subjects under the third-party beneficiary rights in the SCCs; or
- (b) any liability that can't be limited under the law that applies.

15.3 **No other third-party rights.** Nobody other than you and Tally has rights under this DPA, except data subjects under the SCCs where they apply.

---

## 16. Term, changes and general terms

16.1 **Duration.** This DPA lasts as long as Tally processes Customer Personal Data. Sections that by their nature should continue after that, such as Sections 13 and 15, continue.

16.2 **Changes.** Tally may update this DPA only:

- (a) to reflect changes in Applicable Data Protection Law or in guidance or decisions of a supervisory authority or court; or
- (b) to adopt new or replacement standard contractual clauses or transfer mechanisms.

An update won't reduce the overall protection this DPA gives Customer Personal Data, except where the law requires it. Tally will post updates on this page and email your Notice Contacts at least 30 days before an update that materially affects your rights takes effect, unless the law requires a faster change. Subprocessor changes follow Section 8 instead.

16.3 **Governing law.** This DPA is governed by the law of the State of Nevada, and disputes about it are resolved as set out in the Terms, including the Terms' arbitration provisions and, where a dispute goes to court, the state and federal courts located in the State of Nevada. This Section doesn't apply where the SCCs or Applicable Data Protection Law require otherwise.

16.4 **Severability.** If any part of this DPA is invalid or unenforceable, the rest stays in effect. The invalid part will be treated as changed as little as needed to make it valid.

16.5 **Contacts.**

- Privacy and data protection requests: privacy@tallysign.com
- Security incidents and vulnerabilities: security@tallysign.com
- Legal notices: support@tallysign.com
- Support and billing: support@tallysign.com
- Postal: Tally Integrations LLC, available on request from support@tallysign.com
- EU and UK representatives: Tally hasn't appointed a representative in the EU or the UK, or a data protection officer. Send any request to privacy@tallysign.com.

---

## Annex I: Details of processing

### A. List of parties

**Data exporter**

- **Name, address and contact:** the Customer, as shown in its Tally Sign Account (company name, address and Account Owner's email address).
- **Activities relevant to the transfer:** using Tally Sign to create, send, negotiate, sign and store documents, and the related features described in the Terms.
- **Role:** controller (Module Two), or processor on behalf of its own client (Module Three).
- **Signature and date:** by accepting the Terms, which incorporate this DPA.

**Data importer**

- **Name:** Tally Integrations LLC (Tally Sign)
- **Address:** available on request from support@tallysign.com
- **Contact:** privacy@tallysign.com
- **EU and UK representatives:** none appointed. Contact privacy@tallysign.com.
- **Activities relevant to the transfer:** providing the Service to the data exporter.
- **Role:** processor (Module Two), or subprocessor (Module Three).
- **Signature and date:** by making the Service available under the Terms, which incorporate this DPA.

### B. Description of processing and transfer

**B.1 Categories of data subjects**

- **Recipients:** Signers and copy (CC) Recipients of documents, who are usually the Customer's clients, prospects, suppliers, employees or contractors.
- **Users:** the Customer's staff who use Tally Sign, including Salesforce users who hold a seat, as they appear in documents, audit trails, comments and emails.
- **Sender contacts:** people named in sender profiles the Customer sets up, such as name, title, email, phone and address.
- **People named in content:** anyone whose personal data the Customer puts into documents, templates, attachments, uploads or merge values, or brings in from a connected Salesforce org, such as contacts on Salesforce records.
- **People in negotiation:** anyone who writes comments or suggests edits on a document.

**B.2 Categories of personal data**

- **Identity and contact details:** name, email address, job title, company and role in the document. Phone numbers and addresses where the Customer or a Recipient enters them.
- **Document content:** titles, text, merge values, prices and other terms, attachments, uploaded PDF and Word files and their page images, and images, including any personal data the Customer includes.
- **Field values:** everything a Recipient types into fields on a document.
- **Signatures and initials:** drawn signatures and initials, stored as images, and typed signatures, stored as text with the chosen font.
- **Signing and audit records:**
  - when a signing link was first opened, when the Recipient viewed, signed or declined, and the time recorded for consent to electronic signatures (currently the time of signing);
  - decline reasons;
  - IP address and browser user-agent string for link opens, views, signing and declining. The first link open can be made automatically by an email provider's security scanner, whose IP address is then recorded;
  - the method of signing, including in-person signing hosted by a User;
  - the document fingerprint (SHA-256 hash); and
  - the audit trail of events, whose detail text includes names and email addresses.
- **Negotiation content:** comments, suggested edits and change requests, with the author's name and email.
- **Email content:** messages sent on the Customer's behalf, including subject lines, message text, and signed PDFs attached to completion and automation emails.
- **Salesforce data:** fields from the records a document is sent from, quote lines, contacts used as Recipients, and Salesforce users' names, emails, titles and active status for seat management. Salesforce users' details are Customer Personal Data until a seat is assigned. The Tally Sign user account created for a seat holder is then handled by Tally as a controller under the Privacy Policy.
- **AI assistant content:** see B.6.

The Service doesn't collect Recipients' location. It records IP address and user agent only.

**B.3 Sensitive data**

Tally doesn't ask for or need special categories of personal data. The Customer controls what goes into documents and fields, and is responsible for any sensitive data it chooses to include (Section 4.1(e)). The safeguards that apply to all Customer Personal Data are those in Annex II. Tally applies no additional restrictions to sensitive data.

**B.4 Frequency of the transfer**

Continuous, for as long as the Customer uses the Service.

**B.5 Nature and purpose of the processing**

Tally processes Customer Personal Data to provide the Service to the Customer under the Terms. Processing operations are:

- hosting, storing and backing up data;
- building and editing documents and templates;
- converting uploaded files and rendering PDFs, which happens inside Tally's own hosted application;
- sending emails on the Customer's behalf;
- presenting documents for signature and recording consent, link opens, views, signatures, declines and comments;
- producing the signed PDF and Certificate of Completion, and sending it to every party. By default the certificate shows each Signer's name, email address, IP address and device details, and every party to the document receives it. By sending a document, the Customer instructs Tally to do this;
- syncing with a connected Salesforce org, including reading record data and writing records, Files and status back;
- making the configuration changes in a connected Salesforce org that the Terms describe, such as deploying Flows for send rules, adding a remote-site setting and a trusted site, setting the connected app's refresh-token policy, adding lookup fields and actions used by the Tally Sign package, and assigning Tally Sign permission sets;
- running automations the Customer sets up, in Tally Sign or through Salesforce Flows;
- responding to Connected AI Apps as the approving User;
- running the in-app AI assistant when a User uses it;
- providing support; and
- the internal purposes in Section 3.4.

These are the "business purposes" for the CCPA.

**B.6 AI assistant content**

When a User uses the in-app AI assistant, Tally sends the following to OpenRouter and the model host that runs the selected model:

- **For templates and drafts:**
  - the title, theme, page size, page header and footer, and the text of every block (with images left out);
  - the signing roles and, where entered, each signer's name, email address, title and company;
  - the values of fill-ins on the page, and the sending email's subject and message, signing order and expiry;
  - the company's name and legal name, today's date and, for Salesforce templates, the Salesforce object the template uses;
  - if the User's latest message mentions a company's web domain or a work email address, what that company's own public website says its name and address are (Tally reads this from the website itself); and
  - the recent conversation with the assistant, and any pictures the User attaches.
- **For the email designer:** the company name, brand color, whether the company has a logo or cover photo, the current email design, subject and message text, the recent conversation, and any pictures the User attaches.

Tally doesn't store the conversation with the assistant. It keeps only usage records: who used it, when, which model, how much, and whether it succeeded. Pictures attached in the email designer are saved as email images so they can appear in the Customer's emails (Annex II, Section 8). The assistant doesn't make decisions about individuals. Tally doesn't use Customer Personal Data to train, fine-tune or evaluate AI models (Section 3.6).

**B.7 Duration and retention**

For the term of the Customer's use of the Service, plus the Paused period, and then until deletion under Section 13, including the time residual copies take to expire under Section 13.7. While the Account is active, Customer Personal Data is kept until the Customer deletes it or asks Tally to (Sections 11 and 13).

**B.8 Transfers to Subprocessors**

As described in Annex III, for the purposes and durations stated there.

### C. Competent supervisory authority

- **Established in the EEA:** where the data exporter is established in the EEA, the supervisory authority of the Member State where it is established.
- **Not established in the EEA, with a representative:** where the data exporter isn't established in the EEA but has appointed a representative under Article 27(1) of the GDPR, the supervisory authority of the Member State where the representative is established.
- **Not established in the EEA, without a representative:** the supervisory authority of the Member State where the data subjects whose data is transferred are located. Where there is more than one, the authority of the Member State in which the data exporter's main relevant data subjects are located.
- **UK:** the Information Commissioner's Office.
- **Switzerland:** the Federal Data Protection and Information Commissioner.

---

## Annex II: Technical and organizational security measures

This Annex describes the measures Tally has in place for Tally Sign. Section 14 lists measures Tally does **not** currently have, so that you can make an informed assessment.

**1. Hosting and infrastructure**

- The application and its Postgres database run on Railway, a cloud hosting provider, in its US West region (California, United States).
- Signed PDFs, attachments, uploads, logos and images are kept in a private Railway object storage bucket in San Jose, California, United States.
- The production database isn't reachable at a public address.
- Database backups are taken daily, weekly and monthly through the hosting provider and kept for up to 3 months.

**2. Access by Users**

- **Ways to sign in:** Users sign in with an email address and password, with Google, Microsoft or Salesforce, or through their company's own identity provider using single sign-on.
- **Password storage:** passwords are stored only as scrypt hashes with a unique random salt per password, and compared in constant time. Users who join through Google, Microsoft, Salesforce or single sign-on have no password until they set one.
- **Password rules:** passwords must be at least 8 characters. Common passwords (checked against a short built-in list), passwords made of repeated characters, and the user's own email address are rejected.
- **Google, Microsoft and Salesforce sign-in:**
  - Google and Microsoft sign-in use OpenID Connect with PKCE and a one-time nonce. Tally checks the signature, audience, issuer and expiry of the provider's ID token.
  - Tally accepts only an email address the provider says is verified. For Microsoft work accounts, that means Microsoft confirms the email domain's owner verified it.
  - Salesforce sign-in uses OAuth with PKCE, reads who signed in, and revokes the Salesforce token straight away. It signs a person in only to a company that the Salesforce org is connected to: to the User holding that Salesforce user's seat, to a User with the same verified email, or through a pending invitation or free seat under the company's seat rules.
  - After the first sign-in, a person is recognized by the provider's stable account ID, not by email address. Tally never receives their password at the provider.
- **Single sign-on (SAML 2.0 and OpenID Connect), on every plan:**
  - Owners and admins set it up in Settings. It must pass a test sign-in before it can be turned on or required, and changing the identity provider's details requires a new test.
  - **SAML:** Tally accepts only a response to a sign-in request it started in the same browser, signed by a certificate the company saved, addressed to that company's connection, and no more than 10 minutes old.
  - **OpenID Connect:** authorization code flow with PKCE and a one-time nonce. Tally checks the ID token's signature, audience and issuer. The client secret is encrypted with AES-256-GCM.
  - **Email domains:** a company proves it owns an email domain with a DNS TXT record. Only one company can verify a given domain.
  - **Joining automatically:** off by default. If a company turns it on, only people at its verified domains can join through its identity provider, as members, and only while seats remain.
  - **Requiring single sign-on:** a company can require it for everyone except the Account Owner, who keeps another way in if the identity provider is unavailable. When it is required, other Users can't sign in to the web application, or approve a Connected AI App, with a password or with Google, Microsoft or Salesforce. Section 14 lists what requiring it doesn't cover.
  - Controls in the company's identity provider, such as multi-factor authentication and conditional access, apply to sign-ins through it. Tally doesn't see or enforce them.
- **Sign-ins in progress:** the details of a sign-in in progress are kept in a signed cookie that scripts can't read, expires after 15 minutes and is used once.
- **Sessions:** browser sessions use signed tokens in cookies that scripts on the page can't read (httpOnly). They expire after 30 days. Signing out ends the session in that browser only.
- **Checks on every request:** for signed-in browser sessions, every request checks that the user still exists, isn't disabled, and belongs to a company that isn't suspended, and that the session hasn't been ended by a password change. For API keys and Connected AI Apps, every request checks that the company isn't suspended and the user isn't disabled.
- **Password changes:** changing or resetting a password signs the user out of every browser session. It doesn't revoke API keys or Connected AI App connections. Those are revoked separately (Section 4).
- **New-browser alerts:** users are emailed when their account is signed in to from a browser it hasn't seen before, whichever sign-in method is used. The email shows the time, device, IP address and, where available, approximate location.
- **Password resets:**
  - links are single-use and expire after 1 hour;
  - they are stored only as hashes;
  - using a link cancels every other open link for the account;
  - an account can request at most 3 links in 15 minutes; and
  - the response doesn't reveal whether an account exists.
- **Other security emails:** users are emailed when their password is changed, and at the old address when the sign-in email is changed.
- **Invitations:** invitation links are stored only as hashes and expire after 14 days.
- **Roles:** each company has one owner, plus admins and members. Only owners and admins can manage the team, billing, the company profile, single sign-on, Salesforce and API keys, and disconnect Connected AI Apps. Any User can connect a Connected AI App to their own access.

**3. Tenant isolation**

Database queries made through user sessions, API keys, Connected AI Apps and the Salesforce package are limited to the caller's company. The exceptions are the files that are public by design (Section 8) and the legacy access key described in Section 14.

**4. APIs and Connected AI Apps**

- **API keys:**
  - owners and admins create and revoke them in Settings;
  - keys are random and stored only as hashes;
  - the time each key was last used is recorded; and
  - keys don't expire. They stay valid until revoked, even if the User who created them is removed.
- **Connected AI Apps:**
  - connections use OAuth 2.1 with PKCE (S256) required;
  - access tokens last 1 hour, and refresh tokens last 90 days and are renewed when used;
  - a connected app acts as the User who approved it, within that User's company;
  - the consent screen tells the User what the app can do; and
  - owners and admins can revoke every connected app for the company at once ("Disconnect all apps"). There is no way to revoke a single connection in the Service. Removing a User stops the apps that User approved from working; changing their password doesn't.
- **What Connected AI Apps receive:** the content listed in Section 3.3(a) of this DPA. The tools don't return Recipients' IP addresses or user agents directly, but a download link to a completed PDF gives access to its Certificate of Completion, which contains them.
- **Send confirmation:** the function a Connected AI App uses to send a document requires the app to state that the User approved sending, and tells the app to get the User's explicit approval first. Tally can't verify that a person actually approved. This is a safeguard against accidental sends, not an access control. The functions for reminding, voiding and deleting tell the app to ask the User first but don't require a statement. API keys can send documents without a confirmation step.

**5. Salesforce connection**

- Connecting Salesforce uses OAuth 2.0 with PKCE. Only owners and admins can connect.
- Salesforce access and refresh tokens are encrypted in the database with AES-256-GCM.
- The Salesforce package authenticates to Tally with a secret that Tally stores only as a hash.
- Pages shown inside Salesforce can be framed only by Tally Sign itself and Salesforce domains.
- The editor opened from inside Salesforce uses a separate session limited to that document (or to the automations screen). It lapses after 2 hours without activity.
- Activity records written to Salesforce don't include IP addresses.

**6. Signing links and Recipients**

- Each Recipient gets a unique signing link containing 24 random bytes.
- Links stop working for signing when a document is voided, declined, expired or unlocked for editing, and are replaced when a document is re-sent or a new version is issued.
- After a document is completed, each Signer's link keeps working to view and download the signed PDF until the Account is deleted.
- Signing pages tell search engines not to index them.
- Recipients must tick a consent box in an electronic records and signature dialog before filling in any field.

**7. Document integrity and audit trail**

- **Fingerprint at sending:** when a document is sent, its content is frozen and a SHA-256 fingerprint is computed over the content and attached exhibits.
- **Changed content is refused:** signing is refused if the content changed after the Recipient's page loaded.
- **Completed and declined documents are locked:** they can't be edited or deleted in the application. A document that is out for signature can be voided, or unlocked for editing, which clears signatures already collected and stops the old links. A new version can also be issued, for example after a suggested edit is accepted, which clears signatures already given. Voided documents, and unlocked documents that are back in draft, can be deleted, and deleting a document deletes its audit trail. Unlocking is recorded in the audit trail.
- **Signed PDF hash:** the SHA-256 hash of the final signed PDF is stored and logged. The fingerprint is included in the PDF's metadata and in the Certificate of Completion.
- **Audit trail:** link opens, views, signing, declines, sending, reminders and other events are logged with timestamps. Recipient actions are logged with IP address and user agent. Consent to electronic signatures is recorded on the Recipient's record at the time of signing.

**8. File storage**

- **Private storage:** signed PDFs, exhibits, uploads and images are kept in private object storage, organized by company.
- **Downloads:** downloads are served through presigned links that expire after 5 minutes, and only after the application has authorized the request. Other download and upload links are signed and expire within 2 hours.
- **Upload checks:** uploaded files are checked against a SHA-256 hash.
- **Public by design:** some files are served without sign-in so they can appear in emails, signing pages, signed PDFs and Salesforce: company logos and cover images, images placed in documents and emails (including pictures attached in the AI email designer), and page images of PDF or Word files a User uploads. Each has a web address containing a long random code that can't practically be guessed, but anyone who obtains the address, for example from a forwarded email, can open the file, and the address doesn't expire. The file stays available until it is deleted from the Account or the Account is deleted. Browsers that have opened it may keep a cached copy for up to a year, and logos and email images may also be cached by email providers. Page images of uploaded files show the full content of those pages.

**9. Encryption**

- **In transit:** the Service is accessed over HTTPS. In production, cookies are marked Secure, so browsers send them only over HTTPS. Tally connects to its email, billing, AI, Salesforce and identity providers over HTTPS.
- **At rest (application level):** Salesforce tokens, single sign-on client secrets and the AI provider key are encrypted with AES-256-GCM. Passwords, API keys, invitation links, reset links and the Salesforce package secret are stored only as hashes.
- **At rest (storage level):** the database, backups and files are stored with our hosting provider, Railway, under its security controls. Tally doesn't make a separate commitment about storage-level encryption.

**10. Input handling and outbound requests**

- **Sanitizing content:** document content is sanitized to remove unsafe HTML.
- **Automation webhooks:**
  - webhooks can go only to public HTTPS addresses;
  - after the address is looked up, requests to private and internal network addresses are blocked, and redirects aren't followed;
  - chat tool webhooks are limited to the Slack, Microsoft Teams and Discord hosts; and
  - webhook deliveries can be signed with a customer-held secret (HMAC-SHA256).
- **Identity provider and website lookups:** when Tally fetches a company's identity provider metadata, OpenID configuration or tokens, it uses only public HTTPS addresses, never private or internal network addresses. The AI assistant's company-website lookup also skips private and internal addresses.
- **Identity provider metadata:** SAML metadata containing a DOCTYPE or entity declarations is refused.
- **Billing notifications:** notifications from the billing provider are accepted only with a valid signature.

**11. Data minimization**

- PDF rendering, Word file conversion and PDF parsing run inside Tally's own hosted application. No third-party service receives those files.
- The AI assistant works only on drafts, templates and email designs, not on sent documents. Images already in documents aren't sent to it. Tally doesn't store AI conversations.
- The Service doesn't use analytics, advertising or tracking tools, and doesn't store Recipients' location.
- Tally Sign doesn't use open or click tracking in its emails.

**12. Tally personnel and platform administration**

- Platform administration access is limited to named Tally personnel, listed in the server's configuration rather than set from inside the application.
- Platform administrators can suspend a company or disable a user. Suspension blocks the web application, API keys, Connected AI Apps and the Salesforce package for that company. Signers can still sign documents already sent.
- Support sign-in as a customer's User works as described in Section 6.3 of this DPA.
- Deleting a company requires the administrator to type the company's name to confirm.

**13. Abuse and usage controls**

- The AI assistant has a per-company limit on requests per hour and a monthly spending cap for each company.
- The password-reset limit described in Section 2 applies.

**14. Measures not currently in place**

As of the effective date, Tally doesn't have the following. You should take this into account (Section 7.2).

- **Certifications and testing:** no third-party security certification or audit report, such as SOC 2 or ISO 27001, and no penetration test.
- **User sign-in protection:** Tally doesn't offer its own multi-factor authentication. Companies that use single sign-on can require it in their identity provider. There is no lockout or rate limit on password sign-in attempts.
- **Limits of required single sign-on:** requiring single sign-on doesn't end sessions, API keys or Connected AI App connections that already exist. The Account Owner can always sign in another way. The editor opened inside Salesforce relies on the Salesforce connection, not on single sign-on. Removing a person from the identity provider doesn't remove their Tally Sign User, and there is no automatic provisioning (SCIM).
- **Administrator sign-in:** Tally platform administrators sign in the same ways as other users. Tally doesn't require multi-factor authentication or limit sign-in attempts for administrator accounts.
- **Other rate limits:** no rate limits on signing pages, the API and connected-app endpoint, sign-up or email volume, beyond those in Section 13.
- **Credential lifetime and offboarding:** API keys don't expire. Connected AI Apps can be revoked only company-wide. Removing a User stops their API keys and app connections from working (Section 4.2 of this DPA).
- **Legacy access key:** one legacy access key, held by Tally in its server configuration, predates per-company API keys. It gives access to the Account of the first company created on the platform, which is Tally's own internal company account. It isn't stored as a hash, can't be revoked in Settings, and isn't subject to suspension checks. It gives no access to any other company's data.
- **Security headers:** no page of the application can be framed by another website, except that pages shown inside Salesforce can be framed by Salesforce domains. The application sends an HTTP Strict Transport Security (HSTS) header, so browsers only reach it over HTTPS.
- **PDF-from-link downloads:** Connected AI Apps can ask the Service to download a PDF from an https address. This download doesn't yet apply the private-address checks used for webhooks, and follows redirects.
- **Public files:** the files described in Section 8 as public by design aren't protected by sign-in or expiring links.
- **Support sessions:** actions taken during a support session are recorded under the User's name, not marked as Tally's (Section 6.3 of this DPA).
- **Monitoring:** no automated security monitoring or alerting. Server logs are kept by the hosting provider for 30 days.
- **Encryption at rest:** no application-level encryption of document content, signatures, IP addresses or PDFs.
- **Signer identity checks:** no check of a Recipient's identity beyond control of the email address the signing link is sent to. No SMS codes, knowledge-based questions or ID checks.
- **Cryptographic signatures on PDFs:** no certificate-based digital signature or trusted timestamp on signed PDFs.
- **Uptime and recovery:** Tally doesn't currently make commitments about uptime, recovery time or backup restore testing.

**15. Reporting vulnerabilities**

Security researchers and customers can report vulnerabilities to security@tallysign.com. Tally will acknowledge a report within 5 business days.

---

## Annex III: Subprocessors

The current list, with any changes, is on our [Subprocessors](/legal/subprocessors) page. As of the effective date it is:

| Subprocessor | What it does | Customer Personal Data involved | When | Location |
|---|---|---|---|---|
| Railway (Railway Corporation) | Hosts the application, Postgres database, file storage and database backups; receives server logs | All Customer Personal Data held in the Service. Server logs can include email addresses and subject lines | Always | United States. Application and database: US West (California). File storage: San Jose, California |
| Resend (Plus Five Five, Inc.) | Delivers every email Tally Sign sends, from mail.tallysign.com | Recipient and sender names and email addresses, subject lines, message text, reply-to addresses, and attachments, including the signed PDF with its Certificate of Completion, and images of document sections in negotiation emails | Always | United States |
| OpenRouter (OpenRouter, Inc.) | Passes in-app AI assistant requests to a host that runs the selected model | The AI assistant content described in Annex I, B.6 | Only when a User uses the AI assistant | United States |
| Hosts of the selected AI model (currently Anthropic's Claude models): Anthropic, or cloud providers OpenRouter routes to, such as Amazon Bedrock or Google Vertex AI (reached through OpenRouter) | Generates the AI assistant's replies | The AI assistant content described in Annex I, B.6 | Only when a User uses the AI assistant | United States |

**Not Subprocessors.** The following aren't Subprocessors:

- Stripe (Stripe, Inc.), which Tally uses for its own billing as a controller. It receives the Customer's company name, billing email address and account identifier, not Customer Personal Data;
- Google, Microsoft and Salesforce when Users sign in with them, and your own identity provider when you use single sign-on (Section 3.3(e)). They send Tally sign-in details about your Users, which Tally handles as a controller under the [Privacy Policy](/legal/privacy-policy);
- services you connect or direct Tally to send data to, listed in Section 3.3; and
- services that receive no Customer Personal Data.

The [Subprocessors](/legal/subprocessors) page explains each.
