Signant Documentation

Compliance

General Privacy Statement

The general Privacy Policy applies to all business areas in Maestro Soft and to all websites, products and cloud services controlled by Maestro Soft.

See the Maestro Soft Privacy Statement.

 

Product Terms Signant

The terms and conditions apply to customers of the Signant service. The terms and conditions must be accepted in order to use Signant.

See Product Terms Signant.

 

Terms of use for Signatories

These terms apply to the natural person that the service uses electronic identification for electronic signatures.

See Terms of use for Signatories.  

 

Maestro Soft Terms and Conditions

The Terms and Conditions regulates the general provisions of the customer agreement.

 

Data processor agreement

The Data Processor Agreement regulates how Maestro Soft AS processes personal data on behalf of the Customer when carrying out the ‘Signant’ service.

The Data Processor Agreement is a part of the Terms and conditions found under section C.

 

Use of sub-processors

The following table list vendors that qualify as sub-processors in regard to the Data Processor Agreement.

 

Vendor

Purpose

Categories of data processed

Locations

Amazon.com

Cloud and PAAS provider - Web servers, Storage, Network etc.

Production customer data is stored in AWS Frankfurt, Germany. Customer data backups are stored in AWS Stockholm, Sweden.

AWS Frankfurt, Germany

AWS Stockholm, Sweden

Stø AS

Electronic identification and signing using Norwegian BankID.

Identity and transaction data associated with identification and signing. Signant does not send national identity numbers to the provider, but may receive them to verify the signatory’s identity against the expected person. Signing normally uses a document hash. In fallback signing flows, the PDF document is transferred and may contain personal data.

Norway. Covers BankID identification and signing, including backups and support access.

Buypass AS

Electronic identification, personal signing and business signing using enterprise certificates.

Identity and transaction data associated with identification and signing, and enterprise certificate information for business signing. Signant does not send national identity numbers to the provider, but may receive them to verify the signatory’s identity against the expected person. Signing normally uses a document hash. In fallback signing flows, the PDF document is transferred and may contain personal data. The identity of the person authorising business signing is retained in Signant and is not sent to Buypass.

Norway. Covers identification, signing and BCSS/HSM services, including backups and support access.

CGI AB

Electronic identification and signing using Swedish BankID.

Identity and transaction data associated with identification and signing. Signant does not send national identity numbers to CGI. PDF documents may be transferred for signing and may contain personal data.

CGI datacenter in Sweden

EID Easy OÜ

Electronic identification and signing using Danish MitID, Finnish FTN and Finnish Varmennekortti.

Identity and transaction data associated with identification and signing. Signant does not send national identity numbers to EID Easy. PDF documents may be transferred for signing and may contain personal data.


Belgian Mobile ID (itsme)

Electronic identification and signing using Dutch iDIN.

Identity and transaction data associated with identification and signing. The provider does not receive the document.


Link Mobility AS


Recipient name, telephone number, email address and signing link included in the SMS.

EU/EEA. Listed storage locations for the service: Microsoft Azure within the EU/EEA and Globalconnect AB in Sweden.

Filemail AS

Secure transfer of documents on the customer’s instructions.

Transferred documents and any personal data contained in them, accompanying archive indexes, recipient contact details and transfer metadata

Files are normally stored within the EU/EEA, based on uploads originating from Norway or Germany.

 

 

 

Signant Devop Security

The Signant Devop Security gives transparent information on security- and operational data related to the Signant service.

 

Service Lever Agreement

The purpose of the Service Level Agreement is to manifest the level of service to a common perception of what quality and assurance to expect from the service. The Service Level Agreement also describe consequence actions as a result of a service level not fulfilling the defined expectations.

See the Service Level Agreement document.

 

SCASC Practice Statement - WYSIWYS Assurance

The Practice Statement describes how Signant ensures What You See Is What You Sign (WYSIWYS) for end-users during the signature creation process.

See the SCASC Practice Statement

 

Code of conduct

Maestro business requires trust from customers, authorities, shareholders and society at large. In order to gain confidence, we are dependent on professionalism, skill and high ethical standards at all levels. This applies both to the Group's business operations and the way in which every one of us acts.

See our Code of conduct document

 

 

Certifications

Maestro Soft AS is certified according to the standard ISO/IEC 27001 - information security management system.

ISO27001certified