Skip to content

Legal

Privacy Policy

This policy explains which personal data SignElectronically processes, why, for how long and what you can do about it. It covers the website, the demo, customer accounts and the signing pages that signers open.

Last updated on October 10, 2026

Who we are

SignElectronically is an electronic signature service for business teams, available at signelectronically.com. The controller of your personal data is the administrator of the signelectronically.com service.

For any privacy question or request, write to [email protected].

Our role

We act in two different roles, depending on the data.

  • Controller. For account, billing, website and security data we decide why and how the data is processed.
  • Processor. For the documents a customer uploads and the signer details a customer enters, the customer is the controller and we process the data on their instructions, in order to deliver the signing service. In California terms we act as a service provider.

If you received a document to sign, the company that sent it decides what the document contains and how long it is kept. Requests about that content are best addressed to the sender. We will pass on any request that reaches us.

Data we process

CategoryWhat it includesWhere it comes from
Account dataName, email address, password stored as a hash, two factor settings, team name, role in the teamYou, or the team owner who invited you
Billing dataPlan, billing period, invoices, billing details, the last four digits and brand of the card. Full card numbers never reach our serversYou and our payment operator
DocumentsPDF files uploaded for signing, templates, field values typed by signers, drawn or typed signatures, the sealed PDFThe customer and the signers
Signer dataName, email address, mobile number when an SMS code is required, signing order and statusThe customer who sends the envelope
Audit dataEvents with UTC timestamps, IP address, browser user agent, consent to electronic records, identity check results, document hashesGenerated when people act on an envelope
Demo dataThe PDF and signature used in the homepage demo, IP address and a browser identifier that limits the demo to one runYou
Technical dataServer logs, sign in attempts, session records, API requests made with a customer API keyGenerated automatically
CorrespondenceEmails you send to support and our repliesYou

We do not ask for special categories of personal data. Customers decide what their documents contain and are responsible for having a lawful reason to share it.

Purposes and legal bases

PurposeData usedLegal basis under GDPR
Providing accounts and the signing serviceAccount, documents, signer and audit dataPerformance of a contract, Article 6(1)(b). For signer data, the customer's instructions
Billing and tax recordsBilling dataPerformance of a contract and legal obligation, Article 6(1)(c)
Service emails such as sign in codes, signing requests, reminders and receiptsEmail address, envelope statusPerformance of a contract
Security, fraud and abuse preventionTechnical and audit dataLegitimate interests, Article 6(1)(f)
Running the one time demo and limiting it to one useDemo dataLegitimate interests
Answering support requestsCorrespondence, account dataLegitimate interests or performance of a contract
Defending legal claimsAny of the above, as neededLegitimate interests

We do not sell personal data, we do not use it for advertising, and we do not use documents or signer data to train machine learning models. No decisions with legal effect are made about you by automated means alone.

Audit records

An electronic signature is only as useful as the evidence behind it. For that reason each action on an envelope is recorded with a timestamp, the IP address and the browser user agent, and the record is attached to the completed PDF as a certificate.

Every party to the envelope receives the sealed PDF with this certificate. If you sign a document, the sender and the other signers will therefore see your name, email address, the time you signed and the IP address you signed from. The audit trail page shows what a certificate contains.

The public verify page compares the hash of a file with the hashes on record. The file is checked for a match and is not stored.

Recipients

We share personal data only with service providers that help us run the service, under contracts that limit what they may do with it. We describe them by category.

  • A hosting and infrastructure provider that stores the application, database and files
  • A payment operator that processes card payments and subscriptions
  • An email delivery provider that sends service emails and signing requests
  • An SMS delivery provider that sends one time codes when a sender requires them
  • A provider of bot protection for sign up, password reset and code forms
  • Accounting and legal advisers, where needed

We also disclose data where the law requires it, for example to a court or authority with a valid request, and to the other parties of an envelope as described above. Customers can ask for the current list of subprocessors by email.

International transfers

Customer data is hosted in the European Union. Some providers may process limited data outside the European Economic Area, for example to deliver an email or a text message to a recipient abroad. Where that happens we rely on an adequacy decision or on the standard contractual clauses approved by the European Commission.

Retention

DataHow long we keep it
Demo filesDeleted automatically within 24 hours
Documents, signer data and audit recordsFor as long as the customer's account is active, or until the customer deletes the envelope. Teams on plans with retention rules can set automatic deletion after a number of days
Account dataUntil the account is deleted. After deletion, remaining customer data is removed within 30 days
Invoices and billing recordsFor the period required by tax and accounting law
Server and security logsUp to 12 months
Support correspondenceUp to 3 years after the last message

Signed copies that were already emailed to the parties stay with those parties. Deleting an envelope in an account does not recall them.

Cookies

We use only the cookies needed to run the service.

  • A session cookie that keeps you signed in and protects forms against forged requests
  • An optional cookie that remembers your sign in on a device when you ask for it
  • A cookie that records that the one time demo was used in this browser
  • Cookies set by the bot protection on sign up, password reset and code forms

We do not use advertising cookies or cross site tracking. You can block cookies in your browser, but signing in will not work without the session cookie.

Security

Connections are encrypted in transit, passwords and signing links are stored as hashes, one time codes expire quickly, and access to accounts is limited by role. The measures are described in concrete terms on the security page. No system is free of risk, so if you believe your account was accessed without permission, tell us at once by email.

Your rights

If the GDPR or the UK GDPR applies to you, you have the right to:

  • access the personal data we hold about you and receive a copy
  • have inaccurate data corrected
  • have data erased where there is no reason for us to keep it
  • restrict processing or object to processing based on legitimate interests
  • receive data you gave us in a portable format
  • withdraw consent where processing is based on consent
  • lodge a complaint with the data protection authority of your country

Send requests to [email protected]. We answer within one month. We may ask for information that confirms your identity. Where we act as processor for a customer, we forward the request to that customer and help them respond.

Audit records of completed envelopes are evidence that the parties rely on. Where a customer or the law requires them to be kept, we may not be able to erase them on a signer's request alone.

California residents

If the California Consumer Privacy Act, as amended, applies to you, you have the right to know which personal information we collect and how we use it, to request deletion and correction, and not to be treated differently for exercising these rights. The categories we collect are listed in the table above, namely identifiers, commercial information, internet activity and the content you upload.

We do not sell personal information and we do not share it for cross context behavioral advertising. You or an authorized agent can make a request by email at the address above.

Children

The service is intended for businesses and is not directed at anyone under 18. We do not knowingly collect personal data from children.

Changes

We update this policy when the service or the law changes. The date at the top shows the latest version. If a change is significant, account owners are told by email before it takes effect.

Contact

Questions about this policy and requests about your data go to [email protected]. The rules for using the service are in the Terms of Service.