S Signaxis

Privacy Policy

This is a working draft, not a reviewed legal document. It's written to accurately describe what Signaxis actually collects and does today, but the bracketed [placeholders] below (registered address, EU/UK representative, data protection contact) still need to be filled in and reviewed by a lawyer before this is relied on for real customers in the US, EU, or Australia.

This Privacy Policy explains what personal data Signaxis (operated by Devvista LLC, "we," "us," "our") collects, why, and what rights you have over it — whether you're a Signaxis customer, someone on their team, or a recipient asked to sign a document through our platform.

1. What We Collect

Account data

Document & signing data

Audit log

Every account-affecting action — login, upload, sending a request, viewing or signing a document, administrative actions — is logged with its timestamp, IP address, and user agent. This exists to give you (and, where relevant, us) a reliable record of who did what and when — the same audit trail that gives a signed document its evidentiary value.

2. How We Use It

We do not sell personal data, and we do not use it for advertising.

3. Who We Share It With

We share data only where it's necessary to run the service:

We do not share data with third parties for their own marketing purposes.

4. How We Protect It

Specifically, as implemented in the platform today:

No system is perfectly secure, and encryption in the database is only as strong as the security of the server it runs on — see our engineering notes for what that depends on operationally.

5. How Long We Keep It

We retain account and document data for as long as your account is active, plus a follow-on period to preserve the audit trail of any documents that were signed. If you close your account or ask us to delete data we don't need to retain for a legal or evidentiary reason, we will — today this is a manual request handled by our team at hello@signaxis.com, rather than a self-service control in the product yet.

6. Your Rights

Depending on where you live, you may have some or all of the following rights. Contact us at hello@signaxis.com to exercise any of them.

If you're in the United States

Depending on your state, you may have the right to know what personal data we hold about you, request its deletion, correct it, and opt out of its "sale" or "sharing" (we don't sell or share data for advertising, so there's nothing to opt out of in practice).

If you're in the European Union or United Kingdom

Under GDPR, you have the right to:

Our legal basis for processing is primarily performance of a contract with you (running the service you signed up for) and our legitimate interest in security and fraud prevention. [Placeholder: name an EU/UK representative if required under GDPR Art. 27, and a Data Protection Officer if your processing scale requires one.]

If you're in Australia

Under the Privacy Act 1988 and the Australian Privacy Principles, you have the right to access and request correction of personal data we hold about you. If we experience a data breach that's likely to result in serious harm, we'll notify affected individuals and the Office of the Australian Information Commissioner (OAIC), as required under the Notifiable Data Breaches scheme.

7. Cookies

Signaxis uses one cookie: a session cookie that keeps you logged in. It's strictly necessary for the service to function — we don't use tracking, advertising, or analytics cookies.

8. International Data Transfers

[Placeholder: state where the application and database are actually hosted, and — if that's outside the EEA/UK for an EU/UK customer's data, or outside Australia — what transfer safeguard applies (e.g., Standard Contractual Clauses). This is a real, unresolved question as of this policy's drafting; see the engineering security report for the current state.]

9. Children's Privacy

Signaxis is a business tool and is not directed at, or knowingly used by, children.

10. Data Breach Notification

If a breach affecting your personal data occurs, we'll notify affected customers and, where legally required, the relevant regulator, within the timeframe applicable law requires (for example, 72 hours under GDPR for notifying a supervisory authority).

11. Changes to This Policy

We may update this policy from time to time. We'll update the "Last updated" date above, and for material changes we'll make a reasonable effort to notify account holders directly.

12. Contact

Questions about this policy, or to exercise any of the rights above: hello@signaxis.com.
[Placeholder: registered business address for Devvista LLC.]