We manage contracts using Docusign.
The chief executive and operations coordinator have an account. Contracts are uploaded and signatures can be requested via the interface.
Privacy and GDPR
Docusign’s GDPR Basics and How DocuSign Can Help says that Docusign relies on binding corporate rules:
How is DocuSign preparing for the GDPR? As an organization focused on earning customers’ trust and handling their documents with care, DocuSign has developed a strong compliance culture and robust security — reflected in its ISO 27001 certification and its approved Binding Corporate Rules (BCR). BCR is one of three approaches to ensure adequate privacy protection for personal data exported from the EU to countries like the United States.