Legal
Privacy Policy
This policy explains which personal data SignElectronically processes, why, for how long and what you can do about it. It covers the website, the demo, customer accounts and the signing pages that signers open.
Last updated on October 10, 2026
Who we are
SignElectronically is an electronic signature service for business teams, available at signelectronically.com. The controller of your personal data is the administrator of the signelectronically.com service.
For any privacy question or request, write to [email protected].
Our role
We act in two different roles, depending on the data.
- Controller. For account, billing, website and security data we decide why and how the data is processed.
- Processor. For the documents a customer uploads and the signer details a customer enters, the customer is the controller and we process the data on their instructions, in order to deliver the signing service. In California terms we act as a service provider.
If you received a document to sign, the company that sent it decides what the document contains and how long it is kept. Requests about that content are best addressed to the sender. We will pass on any request that reaches us.
Data we process
| Category | What it includes | Where it comes from |
|---|---|---|
| Account data | Name, email address, password stored as a hash, two factor settings, team name, role in the team | You, or the team owner who invited you |
| Billing data | Plan, billing period, invoices, billing details, the last four digits and brand of the card. Full card numbers never reach our servers | You and our payment operator |
| Documents | PDF files uploaded for signing, templates, field values typed by signers, drawn or typed signatures, the sealed PDF | The customer and the signers |
| Signer data | Name, email address, mobile number when an SMS code is required, signing order and status | The customer who sends the envelope |
| Audit data | Events with UTC timestamps, IP address, browser user agent, consent to electronic records, identity check results, document hashes | Generated when people act on an envelope |
| Demo data | The PDF and signature used in the homepage demo, IP address and a browser identifier that limits the demo to one run | You |
| Technical data | Server logs, sign in attempts, session records, API requests made with a customer API key | Generated automatically |
| Correspondence | Emails you send to support and our replies | You |
We do not ask for special categories of personal data. Customers decide what their documents contain and are responsible for having a lawful reason to share it.
Purposes and legal bases
| Purpose | Data used | Legal basis under GDPR |
|---|---|---|
| Providing accounts and the signing service | Account, documents, signer and audit data | Performance of a contract, Article 6(1)(b). For signer data, the customer's instructions |
| Billing and tax records | Billing data | Performance of a contract and legal obligation, Article 6(1)(c) |
| Service emails such as sign in codes, signing requests, reminders and receipts | Email address, envelope status | Performance of a contract |
| Security, fraud and abuse prevention | Technical and audit data | Legitimate interests, Article 6(1)(f) |
| Running the one time demo and limiting it to one use | Demo data | Legitimate interests |
| Answering support requests | Correspondence, account data | Legitimate interests or performance of a contract |
| Defending legal claims | Any of the above, as needed | Legitimate interests |
We do not sell personal data, we do not use it for advertising, and we do not use documents or signer data to train machine learning models. No decisions with legal effect are made about you by automated means alone.
Audit records
An electronic signature is only as useful as the evidence behind it. For that reason each action on an envelope is recorded with a timestamp, the IP address and the browser user agent, and the record is attached to the completed PDF as a certificate.
Every party to the envelope receives the sealed PDF with this certificate. If you sign a document, the sender and the other signers will therefore see your name, email address, the time you signed and the IP address you signed from. The audit trail page shows what a certificate contains.
The public verify page compares the hash of a file with the hashes on record. The file is checked for a match and is not stored.
Recipients
We share personal data only with service providers that help us run the service, under contracts that limit what they may do with it. We describe them by category.
- A hosting and infrastructure provider that stores the application, database and files
- A payment operator that processes card payments and subscriptions
- An email delivery provider that sends service emails and signing requests
- An SMS delivery provider that sends one time codes when a sender requires them
- A provider of bot protection for sign up, password reset and code forms
- Accounting and legal advisers, where needed
We also disclose data where the law requires it, for example to a court or authority with a valid request, and to the other parties of an envelope as described above. Customers can ask for the current list of subprocessors by email.
International transfers
Customer data is hosted in the European Union. Some providers may process limited data outside the European Economic Area, for example to deliver an email or a text message to a recipient abroad. Where that happens we rely on an adequacy decision or on the standard contractual clauses approved by the European Commission.
Retention
| Data | How long we keep it |
|---|---|
| Demo files | Deleted automatically within 24 hours |
| Documents, signer data and audit records | For as long as the customer's account is active, or until the customer deletes the envelope. Teams on plans with retention rules can set automatic deletion after a number of days |
| Account data | Until the account is deleted. After deletion, remaining customer data is removed within 30 days |
| Invoices and billing records | For the period required by tax and accounting law |
| Server and security logs | Up to 12 months |
| Support correspondence | Up to 3 years after the last message |
Signed copies that were already emailed to the parties stay with those parties. Deleting an envelope in an account does not recall them.
Cookies
We use only the cookies needed to run the service.
- A session cookie that keeps you signed in and protects forms against forged requests
- An optional cookie that remembers your sign in on a device when you ask for it
- A cookie that records that the one time demo was used in this browser
- Cookies set by the bot protection on sign up, password reset and code forms
We do not use advertising cookies or cross site tracking. You can block cookies in your browser, but signing in will not work without the session cookie.
Security
Connections are encrypted in transit, passwords and signing links are stored as hashes, one time codes expire quickly, and access to accounts is limited by role. The measures are described in concrete terms on the security page. No system is free of risk, so if you believe your account was accessed without permission, tell us at once by email.
Your rights
If the GDPR or the UK GDPR applies to you, you have the right to:
- access the personal data we hold about you and receive a copy
- have inaccurate data corrected
- have data erased where there is no reason for us to keep it
- restrict processing or object to processing based on legitimate interests
- receive data you gave us in a portable format
- withdraw consent where processing is based on consent
- lodge a complaint with the data protection authority of your country
Send requests to [email protected]. We answer within one month. We may ask for information that confirms your identity. Where we act as processor for a customer, we forward the request to that customer and help them respond.
Audit records of completed envelopes are evidence that the parties rely on. Where a customer or the law requires them to be kept, we may not be able to erase them on a signer's request alone.
California residents
If the California Consumer Privacy Act, as amended, applies to you, you have the right to know which personal information we collect and how we use it, to request deletion and correction, and not to be treated differently for exercising these rights. The categories we collect are listed in the table above, namely identifiers, commercial information, internet activity and the content you upload.
We do not sell personal information and we do not share it for cross context behavioral advertising. You or an authorized agent can make a request by email at the address above.
Children
The service is intended for businesses and is not directed at anyone under 18. We do not knowingly collect personal data from children.
Changes
We update this policy when the service or the law changes. The date at the top shows the latest version. If a change is significant, account owners are told by email before it takes effect.
Contact
Questions about this policy and requests about your data go to [email protected]. The rules for using the service are in the Terms of Service.