01
Controller or processor
We act in two capacities, and your rights route differently under each.
- For account data we are the controller. Your profile, workspace, plan and sign-in history exist because you signed up with us, and everything on this page is our answer for them.
- For documents we are a processor. The workspace that sends a document decides what is in it and who receives it — they are the controller, and we act on their instructions. If you were sent something and want it changed or removed, the sender is the right first door; if you cannot reach them, write to [email protected].
What is actually collected in each case is itemized on the privacy page, which this page deliberately does not repeat.
02
The lawful bases
Where we are the controller, each use of data rests on one of three bases.
| What we do | Basis |
|---|---|
| Run your account and move the documents you send | Contract — Art. 6(1)(b) |
| Defend accounts and signatures: failed sign-in counts, rate limits, verification checks, the audit trail | Legitimate interests — Art. 6(1)(f) |
| Integrations you connect yourself, like Google Drive or Dropbox | Consent, given by connecting — withdrawn by disconnecting |
For documents a workspace sends, the lawful basis is the sender’s to establish — usually their contract with you, or their legitimate interest in getting an agreement signed. We process on their instructions and add no purposes of our own.
03
Your rights, article by article
The two rights people actually exercise are built into the product, so they need nobody’s permission.
- Portability — Art. 20. Account settings exports your data as a machine-readable download, on demand.
- Erasure — Art. 17. Schedule deletion under Account settings. Thirty days’ grace with a reminder, then the purge described below runs.
- Rectification — Art. 16. Your profile is editable directly; nothing about you is held that you cannot see and change there.
- Access, objection, restriction — Arts. 15, 18, 21. Write to [email protected]. A person answers, not a queue.
If you signed something but never made an account, your data sits with the sender’s workspace and requests route through them first. Where the sender cannot be reached we handle it ourselves — by hand, honestly: there is no signer dashboard, a person does it.
If you think we have this wrong, you can complain to your supervisory authority — though we would rather hear it from you first.
04
What erasure actually deletes
This is erasure, not a flag in a database: when the grace period ends, your row is deleted.
- Gone with the account: sessions, passkeys, saved signatures, notification preferences, connected accounts, API keys and memberships. Drafts, in-flight and voided documents are purged with their files — and so is anything already in your trash, since trashing it was itself the request.
- Kept as records: completed and declined documents, with their audit trails intact. A signed agreement is the other party’s evidence as much as yours, and your deletion is not their consent to destroy it. That retention rests on Art. 17(3)(e) — data needed to establish or defend legal claims.
- Records stop pointing at you. Kept documents are re-attributed to an inert placeholder that can never sign in. The audit trail stays truthful because each entry snapshots who acted at the time — it references no live account.
- No share link outlives its owner unrevoked. Links you created either pass to someone who can still revoke them, or are revoked on the spot.
How long everything else lives is on the privacy page; the same line, seen from the contract’s side, is in the terms.
05
Transfers outside the EU
We use a short list of providers, each receiving only what its job needs — the list, and what each one sees, is on the privacy page. Some are in the United States; where that is so we rely on the transfer safeguards those providers publish, such as their Data Privacy Framework certification or standard contractual clauses.
We do not sell your data, in any jurisdiction, under any arrangement.
06
A DPA, and our sub-processors
If your organization needs a data processing agreement, ask through the contact page or at [email protected] and we will send one back. Security questionnaires get the same treatment.
Our sub-processors are the services table on the privacy page — one list, kept in one place, so the DPA and the policy cannot quietly disagree with each other.
07
The other EU question: is the signature valid?
Different law — that one is eIDAS, not GDPR, but it is usually why an EU reader is on this page, so here is the honest answer.
What we provide is a simple electronic signature backed by unusually strong evidence: a sealed PDF, a hash-chained audit trail, and a certificate recording who acted, when and from where. Under eIDAS a signature cannot be denied legal effect solely because it is electronic, and this tier is used for ordinary commercial agreements across the EU.
What we do not offer is a qualified electronic signature — the certificate-based tier some written-form documents require, such as certain employment and property matters. If your document is one of those, we would rather tell you here than have you find out in a dispute. None of this page is legal advice.