TL;DR. We collect what we need to deliver document signing, evidence collection, and customer support — and nothing more. EU storage by default. The hash-chained evidence trail outlives the document it describes and is anonymised rather than deleted on erasure. Recipients can exercise their rights through the form linked below. We never train AI on your content.
1. Who we are
Signatur Labs AS (org-nr placeholder), Oslo, Norway. We are the controller of personal data we process about our website visitors, customer administrators, recipients of customer documents, and support contacts. For documents and recipient data uploaded by our customers, we act as a processor on behalf of the customer, who is the controller.
Data protection contact: privacy@doksign.no. Supervisory authority: Datatilsynet (Norway).
2. What personal data we collect
Visitors
- Browser data (IP address, user-agent) in server request logs
- Nothing else. This site runs no analytics and sets no analytics cookies.
Customer administrators
- Name, work email, company name, password hash, two-factor secret, locale
- Login IP, device, timestamp, session metadata
We take no card payments and therefore hold no card data. A plan change is a request we approve and invoice separately.
Customer documents and recipient data (we are processor)
- Document title, body, metadata
- Recipient name, email, role label
- Recipient interaction telemetry: IP, device, user-agent, page views, one-time-code attempts, signature image, decline reasons
- The hash-chained evidence trail
Support contacts
- Email, message contents, ticket metadata
3. Why we process (purposes and lawful bases)
| Purpose | Lawful basis |
|---|---|
| Account creation, billing | Art. 6(1)(b) Contract |
| Sending and processing documents for signing (for the customer) | Art. 6(1)(b) Contract with the customer; for recipients, the customer establishes their own basis |
| Audit trail and evidence collection | Art. 6(1)(c) Legal obligation + (f) Legitimate interest (security and evidence) |
| Transactional email (delivery, signing notifications) | Art. 6(1)(b) / (f) |
| Error and security logs | Art. 6(1)(f) Legitimate interest |
4. Special category data (Art. 9)
Customer documents may contain special category data — health information, union membership and the like. We do not request or process such data on a controller basis ourselves. The customer must warrant a lawful basis. We apply the same access controls regardless of content.
5. Who we share with
Sub-processors only, listed publicly at the trust centre. Each has signed a GDPR Art. 28 DPA with us. We notify customers 30 days before adding or replacing one. We may disclose to authorities where legally required, and will narrow the scope and notify customers where permitted.
6. International transfers
Default storage region: EU (eu-central-1). Production sub-processors are EU-domiciled or use EU data-boundary offerings. Where any transfer outside the EEA is necessary, Standard Contractual Clauses apply with supplementary measures.
7. Retention
| Data | Retention |
|---|---|
| Completed signed documents | Per workspace configuration; no fixed default is imposed |
| Evidence chain | Retained independently of the document, and anonymised rather than deleted on erasure |
| One-time codes | Minutes — single-use and discarded |
| Operational audit log | Purged on a configurable schedule, 90 days by default |
| Billing records (Bokføringsloven) | 5 years from end of fiscal year |
The evidence chain is the deliberate exception. It is what makes a signature provable years later, so it survives the deletion of the document it describes — with personal data redacted, and the chain's integrity intact. Deleting it on request would destroy the other party's evidence as well as your own.
Retention for completed documents is configured per workspace, within regulatory minimums.
8. Your rights
- Access (Art. 15) — self-service export in Settings → Privacy, or email us
- Rectification (Art. 16) — edit your profile, or email us
- Erasure (Art. 17) — delete your account in Settings; for embedded data, email us
- Restriction (Art. 18) — email us
- Portability (Art. 20) — the same export returns machine-readable data
- Objection (Art. 21) — email us
- No automated decision-making with legal or similarly significant effects (Art. 22)
Recipients of customer documents can exercise their rights through the data rights form, without an account. You may lodge a complaint with Datatilsynet, or your local supervisory authority, at any time.
9. Security
See the trust centre for what we do and do not claim, stated plainly. In summary: every route denies access by default and the public surface is pinned and reviewed; authorisation is role-based and workspace-scoped; two-factor authentication is available to every user and can be enforced across a workspace; the evidence trail is append-only, hash-chained and re-verified on a schedule; and signing requests are excluded from log capture because they carry signatures and one-time codes.
We hold no security certification and do not claim one.
10. Cookies
See the cookie notice for the full list. In short: one strictly-necessary session cookie, a theme preference in local storage, and no analytics or advertising cookies at all — so there is nothing to opt out of.
11. Children
Doksign is not directed to persons under 16. We do not knowingly collect data from children.
12. Changes
Material changes are notified by email to administrators at least 30 days in advance, and the version and effective date at the top of this page change with them.
13. Contact
privacy@doksign.no · A Norwegian Bokmål version is available on request.