← ConsensusDesk

Security & Data

This page explains the protections and data-handling principles used by ConsensusDesk in plain language.

Encryption and access

Sensitive customer, agreement, signing and audit information stored by ConsensusDesk is encrypted at rest using tenant-specific encryption keys. Connections to the service are protected in transit using HTTPS/TLS. Access to customer workspaces is controlled through authenticated user accounts and workspace memberships.

Agreement evidence

ConsensusDesk records agreement versions and relevant signing evidence. Once an agreement is signed, the exact signed PDF is archived rather than recreated later. Integrity information, including a SHA-256 hash and file size, is stored with the archived document.

Data protection roles

ConsensusDesk acts as data controller for data used for its own account administration, authentication, billing, security and legal obligations. When ConsensusDesk processes agreement or recipient data on a customer's instructions, the customer is normally the controller and ConsensusDesk acts as processor. Processor activities are governed by the applicable Data Processing Agreement.

Data minimisation, retention and deletion

Customers should only place information in ConsensusDesk that is necessary for their agreements. Retention, deletion and export depend on the type of record, the customer's subscription, applicable data-protection requirements and legal obligations. Signed evidence may need to be retained where there is a legitimate or legal reason to preserve it.

Service providers

ConsensusDesk may rely on specialist providers for infrastructure, e-mail, payments, identity or qualified trust services. Where they process personal data on behalf of ConsensusDesk, appropriate contractual and data-protection arrangements are required.

Questions or security reports

Contact albert@computernoerden.dk. Please do not include passwords or unnecessary personal data in your message.

This page describes the service at a high level. Contractual data-processing obligations are governed by the applicable Terms, Privacy Policy and Data Processing Agreement.