Privacy Policy
Last updated: September 8, 2026
[placeholders]
below (registered address, EU/UK representative, data protection contact) still need to be filled in
and reviewed by a lawyer before this is relied on for real customers in the US, EU, or Australia.
This Privacy Policy explains what personal data Signaxis (operated by Devvista LLC, "we," "us," "our") collects, why, and what rights you have over it — whether you're a Signaxis customer, someone on their team, or a recipient asked to sign a document through our platform.
1. What We Collect
Account data
- Name, email address, and a securely hashed password (we never store your actual password — see Section 4).
- If you enable two-factor authentication: an encrypted authentication secret, and hashed one-time backup codes.
Document & signing data
- The documents/templates you upload or create, and the field values placed on them.
- A recipient's name and email address, and whatever they type or draw into a document's fields — including a drawn signature image where used.
- The IP address and browser user-agent recorded at the moment a document is viewed and signed.
- Timestamps for every step: created, viewed, signed, or revoked.
Audit log
Every account-affecting action — login, upload, sending a request, viewing or signing a document, administrative actions — is logged with its timestamp, IP address, and user agent. This exists to give you (and, where relevant, us) a reliable record of who did what and when — the same audit trail that gives a signed document its evidentiary value.
2. How We Use It
- To operate the service: render documents, generate and email signing links, produce the final signed PDF.
- To secure your account: fraud/abuse prevention, rate-limiting, login lockouts, audit logging.
- To provide support when you contact us.
- To meet legal obligations, including retaining records that support a signed document's enforceability.
We do not sell personal data, and we do not use it for advertising.
3. Who We Share It With
We share data only where it's necessary to run the service:
- Email delivery — signing links are sent via Gmail or a custom SMTP account you connect (Business/Enterprise), or via Signaxis's own shared sending address (Free plan). The email content (the signing link and your message) passes through whichever of these you're using.
- Hosting — [placeholder: name the hosting provider/location once decided — see the Section 8 note on data location].
- Legal requirements — if compelled by valid legal process.
We do not share data with third parties for their own marketing purposes.
4. How We Protect It
Specifically, as implemented in the platform today:
- Passwords are hashed with bcrypt — never stored, or even visible to us, in plain form.
- A document's submitted field values (names, ID numbers, drawn signatures, and similar) are encrypted at rest with AES-256-GCM before being stored.
- Two-factor authentication secrets are likewise encrypted at rest; backup codes are hashed like a password.
- Every account is protected by rate-limited login attempts and automatic lockout after repeated failures.
- Signing links use a high-entropy random token; only its hash is stored, and it works exactly once.
- Multi-tenant isolation: one customer's account can never reach another's data through the application.
No system is perfectly secure, and encryption in the database is only as strong as the security of the server it runs on — see our engineering notes for what that depends on operationally.
5. How Long We Keep It
We retain account and document data for as long as your account is active, plus a follow-on period to preserve the audit trail of any documents that were signed. If you close your account or ask us to delete data we don't need to retain for a legal or evidentiary reason, we will — today this is a manual request handled by our team at hello@signaxis.com, rather than a self-service control in the product yet.
6. Your Rights
Depending on where you live, you may have some or all of the following rights. Contact us at hello@signaxis.com to exercise any of them.
If you're in the United States
Depending on your state, you may have the right to know what personal data we hold about you, request its deletion, correct it, and opt out of its "sale" or "sharing" (we don't sell or share data for advertising, so there's nothing to opt out of in practice).
If you're in the European Union or United Kingdom
Under GDPR, you have the right to:
- access the personal data we hold about you;
- request correction of inaccurate data;
- request erasure ("right to be forgotten"), subject to our legal need to retain signed-document records;
- request a portable copy of your data;
- object to or request restriction of certain processing;
- lodge a complaint with your local data protection supervisory authority.
Our legal basis for processing is primarily performance of a contract with you (running the service you signed up for) and our legitimate interest in security and fraud prevention. [Placeholder: name an EU/UK representative if required under GDPR Art. 27, and a Data Protection Officer if your processing scale requires one.]
If you're in Australia
Under the Privacy Act 1988 and the Australian Privacy Principles, you have the right to access and request correction of personal data we hold about you. If we experience a data breach that's likely to result in serious harm, we'll notify affected individuals and the Office of the Australian Information Commissioner (OAIC), as required under the Notifiable Data Breaches scheme.
7. Cookies
Signaxis uses one cookie: a session cookie that keeps you logged in. It's strictly necessary for the service to function — we don't use tracking, advertising, or analytics cookies.
8. International Data Transfers
[Placeholder: state where the application and database are actually hosted, and — if that's outside the EEA/UK for an EU/UK customer's data, or outside Australia — what transfer safeguard applies (e.g., Standard Contractual Clauses). This is a real, unresolved question as of this policy's drafting; see the engineering security report for the current state.]
9. Children's Privacy
Signaxis is a business tool and is not directed at, or knowingly used by, children.
10. Data Breach Notification
If a breach affecting your personal data occurs, we'll notify affected customers and, where legally required, the relevant regulator, within the timeframe applicable law requires (for example, 72 hours under GDPR for notifying a supervisory authority).
11. Changes to This Policy
We may update this policy from time to time. We'll update the "Last updated" date above, and for material changes we'll make a reasonable effort to notify account holders directly.
12. Contact
Questions about this policy, or to exercise any of the rights above:
hello@signaxis.com.
[Placeholder: registered business address for Devvista LLC.]