Compliance
General Privacy Statement
The general Privacy Policy applies to all business areas in Maestro Soft and to all websites, products and cloud services controlled by Maestro Soft.
See the Maestro Soft Privacy Statement.
Product Terms Signant
The terms and conditions apply to customers of the Signant service. The terms and conditions must be accepted in order to use Signant.
Terms of use for Signatories
These terms apply to the natural person that the service uses electronic identification for electronic signatures.
See Terms of use for Signatories.
Maestro Soft Terms and Conditions
The Terms and Conditions regulates the general provisions of the customer agreement.
Data processor agreement
The Data Processor Agreement regulates how Maestro Soft AS processes personal data on behalf of the Customer when carrying out the ‘Signant’ service.
The Data Processor Agreement is a part of the Terms and conditions found under section C.
Use of sub-processors
The following table list vendors that qualify as sub-processors in regard to the Data Processor Agreement.
Vendor |
Purpose |
Categories of data processed |
Locations |
Amazon.com |
Cloud and PAAS provider - Web servers, Storage, Network etc. |
Production customer data is stored in AWS Frankfurt, Germany. Customer data backups are stored in AWS Stockholm, Sweden. |
AWS Frankfurt, Germany AWS Stockholm, Sweden |
Stø AS |
Electronic identification and signing using Norwegian BankID. |
Identity and transaction data associated with identification and signing. Signant does not send national identity numbers to the provider, but may receive them to verify the signatory’s identity against the expected person. Signing normally uses a document hash. In fallback signing flows, the PDF document is transferred and may contain personal data. |
Norway. Covers BankID identification and signing, including backups and support access. |
Buypass AS |
Electronic identification, personal signing and business signing using enterprise certificates. |
Identity and transaction data associated with identification and signing, and enterprise certificate information for business signing. Signant does not send national identity numbers to the provider, but may receive them to verify the signatory’s identity against the expected person. Signing normally uses a document hash. In fallback signing flows, the PDF document is transferred and may contain personal data. The identity of the person authorising business signing is retained in Signant and is not sent to Buypass. |
Norway. Covers identification, signing and BCSS/HSM services, including backups and support access. |
CGI AB |
Electronic identification and signing using Swedish BankID. |
Identity and transaction data associated with identification and signing. Signant does not send national identity numbers to CGI. PDF documents may be transferred for signing and may contain personal data. |
CGI datacenter in Sweden |
EID Easy OÜ |
Electronic identification and signing using Danish MitID, Finnish FTN and Finnish Varmennekortti. |
Identity and transaction data associated with identification and signing. Signant does not send national identity numbers to EID Easy. PDF documents may be transferred for signing and may contain personal data. |
|
Belgian Mobile ID (itsme) |
Electronic identification and signing using Dutch iDIN. |
Identity and transaction data associated with identification and signing. The provider does not receive the document. |
|
Link Mobility AS |
Recipient name, telephone number, email address and signing link included in the SMS. |
EU/EEA. Listed storage locations for the service: Microsoft Azure within the EU/EEA and Globalconnect AB in Sweden. |
|
Filemail AS |
Secure transfer of documents on the customer’s instructions. |
Transferred documents and any personal data contained in them, accompanying archive indexes, recipient contact details and transfer metadata |
Files are normally stored within the EU/EEA, based on uploads originating from Norway or Germany. |
Signant Devop Security
The Signant Devop Security gives transparent information on security- and operational data related to the Signant service.
Service Lever Agreement
The purpose of the Service Level Agreement is to manifest the level of service to a common perception of what quality and assurance to expect from the service. The Service Level Agreement also describe consequence actions as a result of a service level not fulfilling the defined expectations.
See the Service Level Agreement document.
SCASC Practice Statement - WYSIWYS Assurance
The Practice Statement describes how Signant ensures What You See Is What You Sign (WYSIWYS) for end-users during the signature creation process.
See the SCASC Practice Statement
Code of conduct
Maestro business requires trust from customers, authorities, shareholders and society at large. In order to gain confidence, we are dependent on professionalism, skill and high ethical standards at all levels. This applies both to the Group's business operations and the way in which every one of us acts.
See our Code of conduct document
Certifications
Maestro Soft AS is certified according to the standard ISO/IEC 27001 - information security management system.
