Digicust

Data Processing Agreement (DPA)

Austria · English · Austrian law

Dated 23 July 2026

APPENDIX 2 – DATA PROCESSING AGREEMENT (DPA)

1. Scope, roles and processing

1.1. Appendix 2 applies to the extent Digicust processes personal data for the Customer. The Customer acts as controller or as processor for an upstream controller; Digicust acts accordingly as processor or subprocessor. If the Customer acts as processor, it ensures that the processing, its instructions and the engagement of Digicust are covered by its agreement with the upstream controller and that all required authorisations are in place. Applicable data protection law means the GDPR and any other data protection law mandatorily applicable to the relevant processing.

1.2. The subject matter, duration, nature and purpose, types of data and categories of data subjects are set out in Appendix 2-A. Processing continues until personal data processed on behalf of the Customer has been returned or erased.

1.3. Data protection roles are determined by the relevant processing purpose. Personal Customer Data and Customer-related usage, permission and log data processed by Digicust on documented instructions to provide the Platform or agreed support remain processing on behalf of the Customer. Digicust acts as an independent controller to the extent it processes contract, contact, user-account and billing data, and the technical metadata and security logs necessary for its own contract and account administration, billing, fraud and abuse prevention, information security, compliance with its own legal obligations, or the establishment, exercise or defence of legal claims. Details, legal bases and retention periods are provided in the current Privacy Policy at https://www.digicust.com/en/privacy/. It serves solely to provide information required by data protection law, does not form part of the Agreement or this DPA and does not expand any processing purpose or legal basis; mandatory rights and information obligations remain unaffected. Digicust does not use data processed on behalf of the Customer for its own advertising, general model training or independent product development.

2. Instructions and confidentiality

2.1. Digicust processes personal data only on documented instructions from the Customer, including with regard to transfers to a third country or an international organisation. The Agreement, agreed Platform use and lawful settings made by authorised users constitute documented instructions. Further instructions are given in text form.

2.2. If Union law or Member State law to which Digicust is subject requires processing other than on the Customer's documented instructions, Digicust informs the Customer of that legal requirement before processing unless the law prohibits such information on important grounds of public interest. If Digicust considers an instruction to infringe data protection law, it informs the Customer without undue delay and suspends the affected processing pending clarification to the extent legally permissible.

2.3. Access is limited to authorised persons who are bound by confidentiality and appropriately trained. Digicust limits permissions according to tasks and protection needs.

3. Security

3.1. Taking into account the state of the art, implementation costs, the nature, scope, context and purposes of processing and the likelihood and severity of risks, Digicust implements appropriate technical and organisational measures under Article 32 GDPR. The agreed measures are set out in Appendix 2-B.

3.2. Digicust regularly reviews the effectiveness of the measures and may replace them with equivalent or more effective measures, provided the agreed level of protection is not reduced. Digicust informs the Customer of material changes before implementation; urgently required security changes are notified without undue delay afterwards.

4. Subprocessors and third-country transfers

4.1. The Customer grants Digicust general authorisation to engage further processors. The initial set approved and active at conclusion of the Agreement is determined exclusively by Section A of Appendix 2-C. Section B lists planned providers for transparency only; their first engagement remains fully subject to clauses 4.2 and 4.3. Digicust provides Appendix 2-C in a form capable of being stored before acceptance. For each provider, Appendix 2-C states at least the legal entity and address; purpose and scope; data types; hosting and processing regions; third-country or remote access; transfer basis and supplementary safeguards; and engagement status and date last reviewed or updated. Approval covers only the provider, purpose, data, region and transfer configuration disclosed there.

4.2. Digicust informs the Customer by email at the most recently notified contract or data protection contact address at least 30 calendar days before adding or replacing a subprocessor and before any material change to its purpose, scope, processing region or third-country or remote access. No later than conclusion of the Agreement, the Customer provides Digicust with a current contract or data protection contact email address for these notices, keeps it operational, monitors it regularly and notifies Digicust of changes without undue delay in text form. Unless the Customer provides a separate data protection contact address, the contract contact email address stated in the Offer applies. The notice includes the information needed for a data protection assessment. In the event of unforeseeable urgency for security, legal or continuity reasons, Digicust may, to the extent objectively necessary and notwithstanding the period in the first sentence and the objection period under clause 4.3, suspend the affected processing or temporarily switch to an already approved subprocessor. A subprocessor not yet approved receives personal data only after prior notice and an objection period that is reasonable in the circumstances or the Customer's express consent. Digicust informs the Customer of the urgency and the measure taken without undue delay; in all other respects, the objection and termination rights under clause 4.3 remain unaffected.

4.3. The Customer may object within 14 calendar days after receipt for substantiated data protection reasons. Without a timely objection, the change is deemed approved. If the Customer objects in time, Digicust does not use the relevant subprocessor for the Customer's data pending resolution. The parties seek an appropriate data-protection-compliant solution. If no reasonable alternative is available, either party may terminate the objectively affected Platform scope; Digicust refunds prepaid fees pro rata for the period after termination.

4.4. Digicust imposes on each subprocessor, by contract or other binding legal act, the same data protection obligations that apply to Digicust under Appendix 2, in particular regarding appropriate technical and organisational measures. Digicust remains fully responsible to the Customer for the subprocessor's performance of those obligations.

4.5. Processing takes place as a rule within the European Union or European Economic Area. A transfer to a third country or an international organisation takes place only on the Customer's documented instructions and in compliance with Chapter V GDPR. Approval of a subprocessor whose third-country or remote access was disclosed to the Customer in a form capable of being stored under clause 4.1 or 4.2 constitutes such an instruction. Digicust relies on an adequacy decision or appropriate safeguards, in particular applicable Standard Contractual Clauses, conducts required transfer assessments and implements necessary supplementary measures. If the transfer basis ceases to apply, Digicust suspends the affected transfer, informs the Customer and resumes it only after establishing a lawful transfer basis.

5. Assistance and personal data breaches

5.1. Taking into account the nature of processing, Digicust assists the Customer, insofar as possible through appropriate technical and organisational measures, with responding to requests for the exercise of data subject rights and, taking into account the information available, with compliance with Articles 32 to 36 GDPR. Requests received directly by Digicust from data subjects are forwarded without undue delay and are not answered on the merits without instructions.

5.2. Digicust notifies the Customer of a personal data breach affecting personal data processed on behalf of the Customer without undue delay after becoming aware of it. To the extent available, the notice includes the nature and scope, affected data and persons, likely consequences, measures taken or proposed and a contact. Missing information is provided without undue delay as it becomes available.

5.3. Digicust documents relevant incidents, assists with containment and remediation and reasonably supports the Customer with data protection impact assessments, prior consultations and required notifications to supervisory authorities and data subjects.

6. Evidence and audits

6.1. Digicust provides all information required to demonstrate compliance with Article 28 GDPR and Appendix 2. Current certificates, audit reports, security documentation and structured questionnaires are used as the primary means of verification to the extent they adequately serve the audit purpose.

6.2. Digicust allows for and contributes to audits, including inspections, conducted by the Customer or a qualified auditor mandated by the Customer and bound by confidentiality. Such audits generally take place once in each twelve-month period, during normal business hours and on at least 30 calendar days' notice. Additional audits and shorter reasonable notice are permitted following a relevant data protection incident, specific doubts about compliance, an order of a supervisory authority or other urgency.

6.3. Audits must not unreasonably interfere with operations, security, other customers' data, source code or trade secrets. Equivalent evidence is given priority to the extent that it fully serves the audit purpose; this does not restrict the statutory audit right. Mandatory powers of supervisory authorities remain unaffected.

7. Return and erasure

7.1. After completion of the processing services under the Agreement, Digicust, at the Customer's choice, erases or returns all personal data processed on the Customer's behalf and erases existing copies unless mandatory law requires retention. Unless the Customer requests earlier return or erasure, this takes place after the retrieval period under Appendix 1 clause 6.2 or a mandatory period expiring later. Data in active systems are then erased without undue delay. Unless Appendix 1 clause 6.4 or mandatory law requires earlier full erasure, backup copies are erased or overwritten in the documented regular rotation cycle and protected from use in production systems until then. The export, switching, retrieval and erasure rights under Appendix 1 clause 6 remain unaffected.

8. Customer duties

8.1. The Customer is responsible for the lawfulness, transparency, purpose limitation, data minimisation and accuracy of data and instructions. It ensures required legal bases and information. If it acts as processor, it additionally ensures the required authorisation of the upstream controller and aligned instructions. If its agreement with the upstream controller contains additional data protection obligations, the parties agree them with Digicust in an addendum before the affected processing begins; until then, that processing does not begin. It transfers special-category or criminal-offence data only after express agreement of additional safeguards.

8.2. The Customer protects its own accounts, devices, interfaces and credentials and promptly reports suspected unauthorised use. It ensures that its instructions and use of the Platform do not infringe data subject rights.

9. Term, liability and precedence

9.1. Appendix 2 applies as long as Digicust processes personal data on behalf of the Customer or return, evidence or erasure duties remain outstanding. Ordinary cooperation under Appendix 2 is included in the agreed fee. Extraordinary Customer-requested work outside Digicust's statutory and contractual duties may, after prior coordination, be charged at the agreed rate or otherwise at the hourly rate under Appendix 1 clause 3.4; this does not apply to the extent the work was caused by Digicust's breach.

9.2. Liability is governed by Appendix 1. Mandatory claims, in particular under Article 82 GDPR, powers of supervisory authorities and statutory rights of recourse remain unaffected.

9.3. Mandatorily applicable Standard Contractual Clauses and expressly agreed data protection addenda prevail over Appendix 2. Otherwise, the governing law and jurisdiction in the Agreement apply. Appendix 2 alone does not create joint controllership; any actually different allocation of roles must be separately agreed before the affected processing begins.

APPENDIX 2-A – DESCRIPTION OF PROCESSING

This Appendix applies exclusively to the modules and functions agreed in the Offer, enabled for the Customer and actually used by the Customer.

Description of processing
Subject matter and purpose: Provision, operation, security, backup, integration and support of the Digicust AI Platform to support or automate the customs, foreign-trade and compliance processes determined by the Customer. This includes in particular document and email processing, customs declarations and transmission, tariff classification, export-control and party screening, supplier, origin, preferential-origin, CBAM and emissions management, and integrations.
Nature of processing: Automated or user-directed receipt, import, reading, extraction, structuring, translation, classification, matching, checking, calculation, storage, logging, backup, display, export, transmission on instructions and erasure, and the generation of drafts, screening and classification results, risk indicators and decision-support outputs.
Duration: During the Agreement term and thereafter until complete return or erasure in accordance with Appendix 2 clause 7.
Data types: Depending on the module: business, contact, communication, user, permission, identification, usage, log and support data; emails, attachments and trade and accompanying documents; invoice, payment, order, shipment, transport, customs and reference data; goods, material, tariff, provenance, origin, preference, licence, end-use and dual-use data; sanctions and party-screening data including name variants, date of birth, nationality, and ownership and control relationships; supplier, CBAM, production, energy, emissions, evidence and verification data; content and results of authority messages, checks, corrections and audit trails. Targeted processing of special categories of personal data under Article 9 GDPR or personal data relating to criminal convictions and offences under Article 10 GDPR is not agreed and requires an express supplemental agreement.
Data subjects: Users, employees, contacts, representatives, management-body members and beneficial owners of the Customer, its customers, suppliers and other entities involved in customs, transport, foreign-trade or compliance processes; persons subject to party, sanctions or export-control screening and included in comparison data used for such screening; other persons whose data appears in processed messages, documents or authority communications.

APPENDIX 2-B – TECHNICAL AND ORGANISATIONAL MEASURES

The measures are applied on a risk basis. Digicust may use equivalent or more effective measures without reducing the agreed level of protection.

Organisation and personnel

  • documented responsibilities for data protection, information security and incidents;
  • confidentiality obligations and regular role-based training;
  • documented joiner, role-change and leaver processes;
  • regular effectiveness reviews and risk-based improvement of measures.

Identity, access and tenant separation

  • personalised accounts, role-based permissions and least-privilege principle;
  • multi-factor authentication for privileged and other risk-relevant access;
  • regular access reviews and prompt removal of rights no longer needed;
  • logical tenant separation and controlled administrative production access;
  • logging of security-relevant access and administrative changes;
  • data classification and pseudonymisation where technically provided.

Transmission, storage and development

  • appropriate encryption in transit and, where required by risk and the state of the art, at rest;
  • controlled interfaces and transfer channels for agreed integrations;
  • traceability of entries, changes and erasures;
  • separated development, test and production processes where technically applicable;
  • change, approval and CI/CD controls for production changes;
  • data minimisation and restricted use of production personal data for testing.

Availability and recovery

  • monitoring and logging, including capacity and availability monitoring;
  • documented backup and recovery procedures;
  • infrastructure protection through appropriate network, firewall, endpoint, system and malware controls;
  • incident response, escalation, emergency and recovery processes;
  • procedures for recoverability and resilience;
  • physical safeguards of the data-centre providers used.

Vulnerabilities, providers and data lifecycle

  • risk-based patch, update and vulnerability processes;
  • documented selection and oversight of security-relevant subcontractors;
  • traceable retention, export, blocking and erasure processes, including for log data;
  • privacy-friendly default settings and controls ensuring processing in accordance with instructions;
  • erasure from active systems and backups in accordance with Appendix 2 clause 7.

APPENDIX 2-C – SUBPROCESSOR REGISTER

This Register was last reviewed and updated on 21 July 2026. Section A contains the initial set approved and active at conclusion of the Agreement. It comprises eight providers engaged directly by Digicust and Nebius B.V. as Inceptron’s downstream subprocessor. Section B lists two planned providers for transparency only. Regional storage does not automatically exclude disclosed remote access or other international processing.

A. Approved and active subprocessors

1. Google Cloud

Subprocessor information
Legal entity and registered address: Google Cloud EMEA Limited, 70 Sir John Rogerson’s Quay, Dublin 2, Ireland
Purpose and scope: Google AI services and data analytics
Customer data processed: Customer documents, prompts, extracted information, model inputs and outputs, including personal data contained in Customer Data
Hosting and processing: Belgium, region europe-west1
Third-country or remote access: Potential access by Google personnel or approved subprocessors outside the EEA is permitted only under the Google DPA and the requirements of Chapter V GDPR.
Transfer basis: EU Standard Contractual Clauses or another applicable lawful transfer basis, in particular an adequacy decision
Supplementary safeguards: Encryption, access controls, confidentiality obligations, logging, monitoring and subprocessor security assessments
Status and date: Active; last reviewed and updated on 20 July 2026

2. Hetzner

Subprocessor information
Legal entity and registered address: Hetzner Online GmbH, Industriestraße 25, 91710 Gunzenhausen, Germany
Purpose and scope: Infrastructure hosting and backup storage
Customer data processed: All data categories described in Appendix 2-A to the extent contained in hosted Platform instances, databases, logs or backups
Hosting and processing: Germany, Nuremberg and Falkenstein
Third-country or remote access: No. Under the DPA used, data hosted in the EU is processed within the EU, including technical and customer support.
Transfer basis: Not applicable to the current EU configuration; any future third-country transfer requires a basis under Articles 44 to 46 GDPR and the change notice required by this Appendix.
Supplementary safeguards: ISO/IEC 27001:2022, access controls, available encryption measures, logging, monitoring, data separation and physical data-centre security
Status and date: Active; last reviewed and updated on 20 July 2026

3. Microsoft Azure

Subprocessor information
Legal entity and registered address: Microsoft Ireland Operations Limited, One Microsoft Place, South County Business Park, Leopardstown, Dublin 18, D18 P521, Ireland
Purpose and scope: Infrastructure hosting, document storage, database services, monitoring and AI inference; OpenAI models are currently used through Microsoft Azure AI Foundry in Germany West Central.
Customer data processed: Customer documents, extracted data, prompts and outputs, account data, identifiers, contact information, logs and other personal data contained in Customer Data
Hosting and processing: Europe: West Europe in the Netherlands, Germany West Central in Germany, North Europe in Ireland and Switzerland North in Switzerland; Azure AI Foundry for the current use of OpenAI models: Germany West Central
Third-country or remote access: Switzerland is outside the EU and EEA but is covered by a European Commission adequacy decision. Limited further third-country access by Microsoft or its subprocessors may occur under the Microsoft DPA.
Transfer basis: For Switzerland, the adequacy decision under Article 45 GDPR; for other third-country access, the EU Standard Contractual Clauses and, where applicable, the EU-US Data Privacy Framework
Supplementary safeguards: Encryption in transit and at rest, time-limited least-privilege access, confidentiality, logging, monitoring, SOC 2 controls and government-access safeguards
Status and date: Active; last reviewed and updated on 20 July 2026

4. Amazon Web Services

Subprocessor information
Legal entity and registered address: Amazon Web Services EMEA SARL, 38 Avenue John F. Kennedy, L-1855 Luxembourg, Luxembourg
Purpose and scope: Primary AI inference and document analysis through Amazon Bedrock
Customer data processed: Customer documents, prompts, extracted information, model inputs and outputs, including personal data contained in Customer Data
Hosting and processing: Primary region Frankfurt, eu-central-1; Digicust uses models configured for EU regional processing and geographic EU inference profiles, without global routing.
Third-country or remote access: Payload data is processed in the selected EU regions. Exceptional access or transfer may occur only where requested by Digicust, required to prevent fraud or abuse, or required by law.
Transfer basis: EU Standard Contractual Clauses or an applicable adequacy decision if a third-country transfer exceptionally occurs
Supplementary safeguards: Encryption, identity and access controls, logging, monitoring, restricted operator access, and no foundation-model-provider access to prompts or outputs in the configuration used
Status and date: Active; last reviewed and updated on 20 July 2026

5. Cloudflare

Subprocessor information
Legal entity and registered address: Cloudflare, Inc., 101 Townsend Street, San Francisco, California 94107, USA
Purpose and scope: DNS, CDN, Web Application Firewall, DDoS protection, traffic routing and edge security
Customer data processed: IP addresses, traffic and security logs, account email addresses, and Customer Data transmitted, routed or cached through Cloudflare
Hosting and processing: Cloudflare’s globally distributed edge network, including EU locations
Third-country or remote access: Yes. Cloudflare and its subprocessors may process personal data outside the EEA, including in the United States.
Transfer basis: EU-US Data Privacy Framework and EU Standard Contractual Clauses where the Data Privacy Framework or another adequacy decision does not apply
Supplementary safeguards: Encryption, strong multi-factor authentication, zero-trust and least-privilege access, logging, monitoring, intrusion detection, ISO/IEC 27001 and ISO/IEC 27018 controls and SOC 2 Type II audits
Status and date: Active; last reviewed and updated on 20 July 2026

6. Sentry

Subprocessor information
Legal entity and registered address: Functional Software, Inc. d/b/a Sentry, 45 Fremont Street, 8th Floor, San Francisco, California 94105, USA
Purpose and scope: Error tracking, performance monitoring and related technical support
Customer data processed: Error and performance data, IP addresses, email addresses, user identifiers and other personal data contained in application events
Hosting and processing: Primary event-data storage in Frankfurt, Germany, for Digicust’s EU organisation
Third-country or remote access: Yes. Account information, configuration, audit logs and certain metadata may be stored in the United States; Sentry and its subprocessors may also process data outside the EEA.
Transfer basis: EU-US Data Privacy Framework; supplemented by the EU Standard Contractual Clauses where the Data Privacy Framework does not apply
Supplementary safeguards: Encryption, PII scrubbing, multi-factor authentication, access controls, audit logging, penetration testing, SOC 2 controls and government-request safeguards
Status and date: Active; EU data storage confirmed by Digicust; last reviewed and updated on 20 July 2026

7. Lyceum Technology

Subprocessor information
Legal entity and registered address: Lyceum Technology Germany GmbH, Ackerstraße 39, 10115 Berlin, Germany
Purpose and scope: AI inference
Customer data processed: Customer documents, prompts, model inputs and outputs, identifiers, contact information, API calls and technical logs
Hosting and processing: Data centres in the EU
Third-country or remote access: Processing takes place primarily in the EU and EEA. Third-country access may occur only through an approved subprocessor and under the Lyceum DPA.
Transfer basis: EU Standard Contractual Clauses or another valid Chapter V GDPR mechanism if a third-country transfer occurs
Supplementary safeguards: Restricted need-to-know access, confidentiality obligations, technical and organisational security measures, and equivalent obligations imposed on subprocessors
Status and date: Active; last reviewed and updated on 20 July 2026

8. Inceptron

Subprocessor information
Legal entity and registered address: Inceptron AB, Scheelevägen 15, 223 70 Lund, Sweden
Purpose and scope: AI inference and related platform operations
Customer data processed: Customer documents and other Customer content, prompts, inputs and outputs, identifiers, metadata, operational and security logs, monitoring data, usage information and billing information
Hosting and processing: Exclusively within the EU and EEA, specifically in Finland and France, through Nebius B.V., the downstream subprocessor disclosed under Section A.9
Third-country or remote access: None. All listed data is stored and processed exclusively within the EU and EEA. No Inceptron or Nebius personnel outside the EU or EEA can access Digicust data, and no third-country transfers occur.
Transfer basis: Not applicable to the current EU configuration because no third-country transfer occurs
Supplementary safeguards: TLS in transit, encryption at rest, least-privilege access, confidentiality, monitoring, incident response, vulnerability management, no API-payload retention by default and no model training using those payloads
Status and date: Active; confirmed in writing and last reviewed and updated on 21 July 2026

9. Nebius as Inceptron’s downstream subprocessor

Subprocessor information
Legal entity and registered address: Nebius B.V., Schiphol Boulevard 165, 1118 BG Schiphol, the Netherlands
Purpose and scope: Infrastructure hosting and compute for Inceptron’s EU-region workloads
Customer data processed: Customer documents and other Customer content, API request and response payloads, prompts, inputs and outputs, identifiers, metadata, operational and security logs, monitoring data, usage information and billing information
Hosting and processing: Exclusively in Finland and France within the EU and EEA
Third-country or remote access: None. All listed data is stored and processed exclusively within the EU and EEA. No Inceptron or Nebius personnel outside the EU or EEA can access Digicust data, and no third-country transfers occur.
Transfer basis: Not applicable to the current EU configuration because no third-country transfer occurs
Supplementary safeguards: TLS in transit, encryption at rest, least-privilege access, confidentiality obligations, monitoring, incident response and vulnerability management
Status and date: Active as Inceptron’s downstream subprocessor under Schedule 3 to the Inceptron DPA; confirmed in writing and last reviewed and updated on 21 July 2026

B. Planned providers

Inclusion in this Section constitutes neither approval nor commencement of processing. Before first engagement, Digicust shall complete the notice and objection procedure under Appendix 2 clauses 4.2 and 4.3.

1. OpenAI

Subprocessor information
Legal entity and registered address: OpenAI Ireland Ltd., 1st Floor, The Liffey Trust Centre, 117–126 Sheriff Street Upper, Dublin 1, D01 YC43, Ireland
Planned purpose and scope: Secondary AI inference and specific fallback tasks through a future direct API connection
Potential Customer data: Prompts, document content and model outputs, including personal data contained in Customer documents
Planned hosting and processing: European regional processing for Digicust’s direct API organisation following completion of contracting and technical activation; the region actually configured will be disclosed in the change notice.
Third-country or remote access: OpenAI Ireland does not currently process data directly for Digicust. Following activation, system data or remote access may occur under the OpenAI DPA and Chapter V GDPR.
Planned transfer basis: An adequacy decision under Article 45 GDPR or appropriate safeguards under Article 46 GDPR, in particular the EU Standard Contractual Clauses
Supplementary safeguards: Encryption in transit and at rest, access controls, confidentiality obligations and no use of API Customer Data for model training by default
Status and date: Planned, not active. OpenAI models are currently used solely through Microsoft Azure AI Foundry in Germany West Central. Notice under Appendix 2 clause 4.2 will be given before any direct activation. Last updated on 20 July 2026.

2. Nebul

Subprocessor information
Legal entity and registered address: Nebul B.V., Sylviusweg 74, 2333 BE Leiden, the Netherlands
Planned purpose and scope: AI inference
Potential Customer data: Personal data provided by the Customer, including prompts, model inputs and outputs, identifiers, document content and technical usage data
Planned hosting and processing: Amsterdam, the Netherlands
Third-country or remote access: No, under the planned configuration; Customer Data is intended to be processed exclusively in EU regions.
Planned transfer basis: Not applicable to the planned EU configuration
Supplementary safeguards: ISO/IEC 27001:2022, TLS, access controls, two-factor authentication, logging, monitoring, intrusion detection, confidentiality, data isolation and no AI training using Customer Data
Status and date: Contracted for prospective use but not active and not currently processing Customer Data. Notice under Appendix 2 clause 4.2 will be given before activation. Last reviewed and updated on 20 July 2026.

The version of this Appendix provided before acceptance constitutes the initial set approved at conclusion of the Agreement. Changes are governed exclusively by Appendix 2 clauses 4.2 and 4.3.

Customer-side signature

Sign the DPA as a PDF

Choose between signing directly in your browser and downloading a PDF for external signature. Both copies provide for the Customer signature only.

Sign in browser & create PDF

Enter the relevant Customer details below. A customer-signed PDF is then created locally.

Enter details

Download PDF & sign externally

Download the complete PDF with a blank Customer signature page and sign it in your PDF application or on paper.

Local PDF creationThis form does not transmit your entries to Digicust or store them on the website.

Minimal A4 PDFThe PDF contains selectable contract text, document evidence and only the relevant signature fields.

Browser-signature note: The typed name is placed in the PDF locally as a simple electronic signature. It is not cryptographically verified and is not a qualified electronic signature. Use the external PDF route for a certificate-based signature.

Sign as the Customer in your browser

Fields marked * are required. The signature date and creation time are recorded automatically.

For example, the offer number or Agreement name.

The full name is also used as the typed electronic signature.

Required contract or data-protection contact under DPA clause 4.2.

Email the signed PDF

The PDF is not transmitted automatically. If applicable, sign it externally, attach the completed file manually and send it to info@digicust.com.

Prepare email
Digicust FlexCo
FN 538643y
Am Felde 2, Haus 3, Top 2
2431 Enzersdorf an der Fischa
Österreich
info@digicust.com