Skip to content
Glossary

E-Signature & Contract Glossary

28 terms from electronic signatures, eIDAS, GDPR and contract law — explained in plain language.

GDPR compliant · EU-hosted

A

AES-256

AES-256 (Advanced Encryption Standard with a 256-bit key) is a symmetric encryption algorithm considered the gold standard for securing data at rest.

The AES-256 algorithm is approved by the US NIST and used by banks, governments and military organisations worldwide. A 256-bit key means that brute-force cracking would take an astronomically long time. zipzipdoc encrypts every document and its metadata with AES-256-GCM; keys are managed via HSM and rotated every 90 days.

Apostille

An apostille is a certification of a public document under the 1961 Hague Convention, enabling its recognition in member countries without further legalisation.

An apostille is issued by the competent authority of the country where the document was created — in Slovakia, the Ministry of Justice. An electronic signature via platforms like zipzipdoc does not replace an apostille; apostilles are required for public documents (birth certificates, notarial deeds) destined for use abroad. For ordinary commercial contracts between private parties, an apostille is generally not required.

Audit Trail

An audit trail is a chronological record of all events related to a document — who opened, signed or declined it — including timestamps and IP addresses.

In the context of electronic signatures, an audit trail is key evidence in a dispute: it proves that a signature was given by a specific person at a specific time and from a specific location. zipzipdoc generates a detailed audit trail for every document — with OTP verification, signer email, IP address and timestamp — and stores it alongside the PDF.

Advanced Electronic Signature (AdES)

An advanced electronic signature (AdES) is a level of e-signature under eIDAS that is uniquely linked to the signatory, enables verification of their identity and detects any alteration of the document after signing.

AdES meets the requirements of Article 26 of the eIDAS regulation: it is uniquely linked to the signatory, enables their identification, is created using data under the signatory's sole control, and detects any alteration of the document. zipzipdoc creates an advanced signature with OTP verification, which is sufficient for 95% of ordinary commercial documents — NDAs, contracts, purchase orders, employment contracts.

Annex / Exhibit

An annex to a contract is a document attached to the main contract that supplements it — typically containing technical specifications, a price list, schedule or list of deliverables.

An annex forms an integral part of the contract and has the same legal weight. In the event of a conflict between an annex and the main contract text, the annex generally prevails (unless the contract provides otherwise). Annexes can be signed together with the main contract or later as a separate document.

Act No. 272/2016 Coll.

Act No. 272/2016 Coll. on trusted services for electronic transactions in the internal market is the Slovak transposition act implementing the eIDAS regulation.

The Act regulates the conditions for providing trusted services in Slovakia — issuing qualified certificates, timestamps and electronic delivery. Supervision of providers is carried out by the National Security Authority (NBÚ) of the Slovak Republic. The Act has been amended in connection with eIDAS 2.0 and European Digital Identity requirements.

C

Certificate Authority (CA)

A certificate authority is a trusted third party that issues digital certificates confirming the identity of individuals, organisations or servers.

A CA verifies the applicant's identity and issues a certificate signed by its own root certificate — the 'trust anchor'. Browsers and operating systems maintain a list of trusted CAs (e.g. DigiCert, Let's Encrypt). For a qualified electronic signature under eIDAS, the certificate must be issued by an accredited CA listed in the EU's Trusted Service List (TSL).

Contract Amendment

A contract amendment is a written document that modifies or supplements the original contract, while the remaining provisions remain in force.

An amendment must be signed by the same parties as the original contract and must clearly reference the clause or provision it modifies. An electronic signature via zipzipdoc is fully valid for amendments — their legal force is the same as the original contract. The AI in zipzipdoc can generate an amendment based on a description of the change.

Cryptographic Hash Function

A hash function is a mathematical operation that converts input data of any length into a fixed-length output (hash); even a minimal change to the input radically changes the hash.

In the context of digital signatures, a hash function (e.g. SHA-256) creates a 'fingerprint' of the document — the hash is signed, not the entire document. This enables efficient signing and integrity verification: if the document changes after signing, the hash no longer matches the signed value and the signature is invalid.

Certificate Revocation

Certificate revocation is an act by a certificate authority declaring a digital certificate invalid before the end of its normal validity period.

Revocation occurs when a private key is compromised, the owner's identity changes, or at the certificate holder's own request. The CA publishes the revocation in a Certificate Revocation List (CRL) and via OCSP. Signatures created before the revocation remain valid if their timestamp predates the revocation — which is why a qualified timestamp is critical for long-term archiving.

Contract for Work

A contract for work is a contract type under § 536 et seq. of the Slovak Commercial Code (or § 631 of the Civil Code), where the contractor undertakes to perform work and the client undertakes to pay the price.

In commercial relationships (e.g. IT, construction, agencies) it is governed by the Commercial Code. It includes a description of the work, price, performance deadlines, handover and acceptance of work, and liability for defects. For freelancers, the contract for work is the most common legal type for service orders. It can be signed electronically via zipzipdoc.

D

Data Processor

A data processor is a natural or legal person that processes personal data on behalf of and under the instructions of a data controller.

The relationship between a controller and processor must be formalised in a Data Processing Agreement (DPA). A processor must not process data for its own purposes. zipzipdoc acts as a data processor for its customers — processing documents and signers' personal data solely for the purpose of providing the service.

Digital Certificate

A digital certificate is an electronic document that binds a public key to the identity of its owner and is signed by a certificate authority.

A certificate contains the owner's name, their public key, validity period and the CA's digital signature. The most widespread format is X.509. Certificates are used in TLS/HTTPS communication (server certificates) and electronic signing (personal certificates). For a qualified electronic signature, the certificate must be issued by an accredited CA.

DPA (Data Processing Agreement)

A DPA is a contract between a data controller and data processor required by Article 28 of the GDPR as a condition for lawful processing.

A DPA must specify the subject, nature and purpose of processing, types of personal data, categories of data subjects, and processor obligations (confidentiality, security, sub-processors, assisting the controller in fulfilling data subject rights). zipzipdoc has a DPA available for all customers — contact us via our contact form.

Data Controller

A data controller is a natural or legal person that determines the purposes and means of processing personal data.

The controller bears primary responsibility for the lawfulness of processing — they must have a legal basis for each processing activity, inform data subjects, respond to their rights (access, erasure, portability) and conclude a DPA with processors. Typically the controller is a company that collects and uses personal data of customers or employees.

E

eIDAS (EU Regulation No 910/2014)

eIDAS is a regulation of the European Parliament and Council creating a unified legal framework for electronic identification and trust services across the EU.

The eIDAS regulation defines three levels of electronic signature (simple, advanced, qualified), electronic seals, timestamps and electronic delivery. It guarantees mutual recognition of electronic signatures between member states. The updated eIDAS 2.0 (EU Regulation 2024/1183) extends the framework with the European Digital Identity Wallet (EUDIW).

eIDAS 2.0 (EU Regulation 2024/1183)

eIDAS 2.0 is the revision of the original eIDAS regulation in force from May 2024, introducing the European Digital Identity Wallet (EUDIW) and broadening the scope of trust services.

EU Regulation 2024/1183 (eIDAS 2.0) obliges member states to make the European Digital Identity Wallet (EUDIW) available to every EU citizen by 2026. It extends eIDAS with new trust services: electronic archiving, attribute management and remote qualified signatures without a hardware token. For businesses, this means new signer identity-verification methods and the opportunity to integrate EUDIW into e-signing workflows.

Electronic Seal

An electronic seal is the electronic equivalent of a company stamp — it guarantees the origin and integrity of a document issued by an organisation, not a natural person.

Under eIDAS, electronic seals are bound to legal entities (companies, institutions), while electronic signatures are bound to natural persons. A seal is typically used on invoices, confirmations or other documents issued automatically by an organisation where there is no individual signer.

Electronic Signature

An electronic signature is any electronic expression of consent to a document's content — from a scanned handwritten signature to a cryptographically secured qualified signature.

The eIDAS regulation defines three levels: simple, advanced and qualified. For most commercial documents (contracts, NDAs, purchase orders) an advanced electronic signature is sufficient and legally binding across the EU. A qualified signature requires a certificate issued by an accredited CA and a special device (e.g. a smart card).

EUDIW (European Digital Identity Wallet)

EUDIW is an app introduced by eIDAS 2.0 that will allow every EU citizen to store and present digital credentials and identity attributes across the Union.

EU member states are required to make the EUDIW available by 2026. The wallet will allow storing an identity card, driving licence, diplomas, health records or company authorisations and presenting them online or in person without a physical document. For electronic signing, the EUDIW will enable remote qualified signatures (QES) directly from a mobile device — without a hardware token or an in-person visit to a certificate authority.

G

GDPR (EU Regulation 2016/679)

GDPR (General Data Protection Regulation) is an EU regulation on the protection of natural persons with regard to the processing of personal data, applicable from 25 May 2018.

The GDPR introduces obligations for data controllers and processors — lawfulness of processing, data minimisation, information obligations, data subject rights (access, erasure, portability) and mandatory reporting of security incidents within 72 hours. Violations can lead to fines of up to 4% of global turnover or €20 million.

H

HSTS (HTTP Strict Transport Security)

HSTS is an HTTP security header that instructs the browser to communicate with the server exclusively over HTTPS for a period defined by the max-age parameter.

HSTS protects against SSL stripping attacks, where an attacker downgrades communication to unencrypted HTTP. After the first HTTPS contact, the browser remembers the instruction and automatically upgrades all future requests. zipzipdoc uses HSTS with a max-age of one year, the recommended value for production sites.

L

Licence Agreement

A licence agreement is a contract by which an author or rights holder grants the licensee the right to use a work or other intellectual property under agreed conditions.

Licence agreements are concluded for software, musical works, photographs, patents or trademarks. They can be exclusive or non-exclusive, time-limited or perpetual, territorially restricted. The Copyright Act (No. 185/2015 Coll.) requires written form for exclusive licences — an electronic signature satisfies this requirement. zipzipdoc can generate a licence agreement for software or creative works.

Lease Agreement

A lease agreement is a contract type under § 663 of the Slovak Civil Code, by which the lessor grants the lessee the temporary use of an item in exchange for agreed rent.

A lease agreement can cover real estate (apartments, office space, warehouses), movable property (vehicles, machinery) or rights. Special tenant-protection rules apply to residential tenancy. Written form is not always mandatory, but is recommended — in disputes the court examines what was agreed. Commercial leases for offices and warehouses can be signed electronically via zipzipdoc.

M

Mandate Agreement

A mandate agreement is a contract type under § 566 of the Slovak Commercial Code, where the mandatary undertakes to handle a specific commercial matter on behalf of the mandator.

Unlike the contract of mandate under civil law (Civil Code), the mandate agreement is governed by the Commercial Code and applies to business matters. It is typically used for commercial agents, consultants or lawyers acting on behalf of a company. The mandatary does not enter into obligations in their own name — they act for the mandator. It can be signed electronically.

N

NDA (Non-Disclosure Agreement)

An NDA (Non-Disclosure Agreement) is a contract in which one or both parties undertake to maintain the confidentiality of shared information.

An NDA can be unilateral (one party shares sensitive information) or mutual (both parties share confidential information). It typically defines what is considered confidential, the duration of the confidentiality obligation and sanctions for breach. Electronically signing an NDA via zipzipdoc is fully legally binding across the EU. The AI in zipzipdoc can generate an NDA in under a minute.

Notarisation

Notarisation is the verification of the authenticity of a signature or document content by a notary, who confirms the signer's identity and free expression of will.

In Slovakia, notarisation is performed by notaries under Act No. 323/1992 Coll. on notaries and notarial activities. A notarially verified signature (legalisation) is a higher level of verification than an electronic signature. Notarisation is mandatory for certain legal acts (real estate transfer, amendment of an s.r.o.'s articles of association). Ordinary commercial contracts do not require notarisation — an advanced or qualified electronic signature suffices.

O

OCSP (Online Certificate Status Protocol)

OCSP is an internet protocol that enables real-time verification of whether a digital certificate has been revoked before its expiry date.

Instead of downloading a full Certificate Revocation List (CRL), the client sends a simple query to the CA's OCSP server: 'Is certificate No. X valid?'. OCSP responds with 'good', 'revoked' or 'unknown'. In long-term electronic signature archiving, the OCSP check is captured in the timestamp so that the certificate's validity at the time of signing can be proven decades later.

OTP (One-Time Password)

An OTP (One-Time Password) is a one-time code sent via email or SMS that verifies a person's identity during critical actions such as signing a document.

OTP verification adds a layer of authentication — it is not enough to have the signing link; you must also have access to the email or phone to which the code was sent. In the context of an advanced electronic signature under eIDAS, OTP verification contributes to binding the signature to the signer's identity and is part of the audit trail. zipzipdoc sends OTP codes to signers automatically.

P

Purchase Agreement (Contract of Sale)

A purchase agreement is a contract under § 409 of the Commercial Code or § 588 of the Civil Code, by which the seller transfers ownership of an item to the buyer for an agreed purchase price.

A purchase agreement must clearly identify the subject of the sale and the purchase price; for real estate, written form and land registry registration are required. For movable property and business transactions (e.g. sale of goods, equipment or receivables) an electronic signature via zipzipdoc is fully sufficient. The AI in zipzipdoc can generate a purchase agreement based on the provided parameters.

PAdES / XAdES / CAdES (Electronic Signature Formats)

PAdES, XAdES and CAdES are European electronic signature format standards defined by ETSI — specifying how a signature is technically embedded in a PDF, XML or other document.

PAdES (PDF Advanced Electronic Signatures) is the standard for signing PDF documents — the signature is embedded directly in the file and is visible in Adobe Acrobat. XAdES (XML Advanced Electronic Signatures) is used for signing XML documents (invoices, e-government). CAdES (CMS Advanced Electronic Signatures) is designed for binary data and email attachments. All three formats support long-term validation (LTV) with embedded OCSP responses and timestamps. zipzipdoc creates a PAdES signature embedded in the PDF.

PKI (Public Key Infrastructure)

PKI is a set of technologies, policies and procedures for managing digital certificates and cryptographic keys, underpinning both secure internet communication and electronic signatures.

PKI operates on asymmetric cryptography: each participant has a key pair — private (secret, for signing) and public (shared, for verification). A certificate authority (CA) issues a digital certificate binding the public key to the owner's identity. Browsers, servers and email clients use PKI to verify HTTPS and digital signatures.

Q

Qualified Electronic Signature (QES)

A qualified electronic signature (QES) is the highest level of e-signature under eIDAS — it requires a qualified certificate and a qualified signature creation device (QSCD).

QES has the same legal weight as a handwritten signature in all EU member states. It is mandatory for notarial acts, certain administrative proceedings and submissions to authorities. It requires biometric or physical identification (in-person visit, eID card). zipzipdoc creates an advanced signature (AdES), not QES — which covers 95% of ordinary business needs without requiring physical identification.

R

RBAC (Role-Based Access Control)

RBAC is a security model in which permissions are assigned to roles (e.g. admin, editor, viewer) rather than directly to individual users.

RBAC simplifies access rights management in larger teams — instead of setting permissions for each user individually, you simply assign them a role. When an employee changes position, only their role needs to change. In the context of electronic signing platforms, RBAC determines who can send documents, who can only sign, who has access to the audit trail, and who manages the team. zipzipdoc supports admin, member and signer roles.

S

Simple Electronic Signature

A simple electronic signature (SES) is the most basic form of e-signature — for example, a name at the bottom of an email or ticking an 'I agree' checkbox.

SES does not verify the signer's identity or document integrity using cryptographic means. It has the lowest evidentiary value in a dispute, but is sufficient for many informal internal documents. In Slovakia and the EU, SES is recognised, however a court may challenge its validity if a party denies the signature. For important contracts, an advanced or qualified signature is recommended.

SCC (Standard Contractual Clauses)

SCCs are model contractual clauses issued by the European Commission that enable the lawful transfer of personal data from the EU to third countries without an adequate level of protection.

The GDPR prohibits transferring personal data outside the EU/EEA unless the destination country provides an 'adequate' level of protection (Commission decision). Where such protection is absent — e.g. cloud providers with servers in the US — SCCs serve as a substitute mechanism: they contractually bind the recipient to the same protection standards that apply in the EU. The current set of SCCs was issued in 2021, replacing the older templates after the Schrems II ruling.

SHA-256

SHA-256 is a cryptographic hash function from the SHA-2 family that generates a 256-bit fingerprint (hash) of any input data.

SHA-256 is considered a secure cryptographic standard approved by NIST and used in TLS certificates, digital signatures, blockchain and secure password storage. In the context of electronic signing, SHA-256 is used to create a document 'fingerprint' that is signed — ensuring that even a minimal change to the document after signing will be detectable.

Secure Electronic Signature

A secure electronic signature is the term used in Slovak Act No. 272/2016 Coll. corresponding to the advanced electronic signature (AdES) under the eIDAS regulation.

Act No. 272/2016 Coll. distinguishes between a simple electronic signature and a secure electronic signature. The secure signature must satisfy four conditions identical to Article 26 of eIDAS: unique linkage to the signatory, possibility of identification, the signatory's sole control over signing data, and detectability of changes. For communication with Slovak public authorities, a secure electronic signature with a qualified certificate (ZEPeK) is required — which is effectively a qualified signature (QES).

Service Agreement

A service agreement is a commercial contract by which the service provider undertakes to perform agreed activities for the client (e.g. IT support, marketing, consulting) in exchange for remuneration.

A service agreement (SLA) is the most common contract type for B2B service relationships. It typically defines the scope and quality of services (SLA metrics), price and billing terms, duration, notice periods and liability for damages. An electronic signature via zipzipdoc is fully sufficient — the AI in zipzipdoc can generate a service agreement based on a description of the collaboration.

T

Timestamp

A timestamp is a cryptographically verified record of the exact time a document or signature was created, issued by a trusted third party.

Unlike a device's system clock, which can be falsified, a qualified timestamp is issued by an accredited service and is bound to the document content via a hash function. Timestamps are essential for long-term archival of digital signatures, as they allow the validity of a signature to be proven even after the signer's certificate has expired.

TLS (Transport Layer Security)

TLS is a cryptographic protocol that ensures the confidentiality and integrity of data transmitted over the internet — the foundation of HTTPS communication.

TLS 1.3 (RFC 8446, 2018) is the latest and fastest version of the protocol — it simplified the handshake to one round-trip and removes deprecated cipher suites. Older TLS 1.0 and 1.1 versions are now considered insecure and most browsers do not support them. zipzipdoc requires a minimum of TLS 1.2 and prefers TLS 1.3 with Perfect Forward Secrecy.

Ready to try zipzipdoc?

Generate contracts and sign electronically — securely, quickly, eIDAS-compliant.