Skip to main content

Legal

Data Processing Agreement

The terms on which we process personal data on your behalf when you send documents through us.

Last updated August 2026.

Which of us is which

When you upload a document and send it to somebody, you decide whose personal data is processed and why. That makes you the controller and us the processor. This agreement sets out what we may do with that data on your instructions.

It applies alongside our terms of service. Where the two conflict on data protection, this document wins.

What we process, and for whom

On your behalf we process:

  • The contents of the documents you upload.
  • The names and email addresses of the recipients you name.
  • The evidence of their actions: when they opened the document, verified their identity, and signed — with IP address and browser.

Our instructions come from you

We process this data only to provide the service and only as your instructions require: sending documents, verifying signers, sealing the result and keeping the record.

We do not use it for our own purposes. We do not sell it. We do not use your documents to train models.

If an instruction from you would breach data protection law, we will tell you rather than carry it out.

Confidentiality

Everyone who can reach this data is bound by confidentiality obligations. Our own administrators can see that a document exists, who it went to and what happened to it — they cannot read its contents.

Sub-processors

We use a small number of providers to send email and store files. Each is bound by terms no weaker than these, and we remain responsible to you for what they do.

We will tell you before adding a sub-processor that handles document contents, and you may object.

Security measures

Concretely, and not as a list of aspirations:

  • Documents are held on private storage and streamed through the application; they are never served from a public URL.
  • Signing links and one-time codes are stored only as SHA-256 hashes. The plain values exist in the recipient's email and nowhere else.
  • Passwords are hashed and cannot be recovered by anyone, including us.
  • Every action on a document is written to an append-only audit log.
  • Access between accounts is denied by policy on every model, checked server side on every request.

When something goes wrong

If we become aware of a breach affecting your data, we will tell you without undue delay and with enough detail for you to meet your own notification duties. We will not wait until we have a complete picture before telling you there is a problem.

Helping you meet your obligations

If one of your recipients asks you for access, correction or deletion, we will help you answer. The interface already lets you export and delete; where it does not, ask us.

Return and deletion

You can export and delete your documents at any time. When your account closes we delete the personal data we hold on your behalf, retaining only the minimum evidence that signatures made through us were validly made — because destroying that would undermine every document you ever signed.

Audits

On reasonable notice we will answer questions about how we process your data, and provide what we have to demonstrate it. We would rather answer a specific question well than host an inspection that tells you little.