This policy explains what personal data RemoSign collects, why, on what legal basis, how long it is kept, and what you can demand from us. It is written to be read, not to be survived. If anything here is unclear, write to info@remosign.com and we will answer.
The RemoSign service is operated by the RemoSign operator ("we", "us"). For any privacy matter you can reach us by email, or through the contact box on our home page. Both reach the same inbox and both are answered: info@remosign.com
RemoSign is operated automatically. Documents are prepared, delivered, signed, returned and deleted by the system, without a human being opening them and without anyone reviewing their content. Our staff access a document only in the rare case that you ask us to, in writing, to resolve a fault. This is a deliberate design choice and one of the strongest privacy protections we can offer you.
Automated operation of this kind is not automated decision-making in the sense of Article 22 GDPR: the system carries out the instructions you give it and does not evaluate you, score you, or decide anything about you.
RemoSign handles personal data in two distinct capacities, and your rights differ depending on which applies:
If you are a private individual signing for purely personal or household purposes (a lease with a neighbour, an agreement within the family, a private sale), data-protection law generally does not treat you as a controller at all (GDPR Article 2(2)(c)). In that case RemoSign is the sole controller of that data and answers directly for it, and you need do nothing.
Practical consequence for business use: if a signer asks us to delete a contract you sent them, we cannot decide that alone. We forward the request to you, the controller, and assist you in answering it.
You are under no statutory obligation to give us personal data. Without the necessary details, however, the signing service cannot function.
We do not deliberately collect special categories of data (health, beliefs, biometric identification, and the like). A signature drawn on screen is stored as an image of that drawing; it is not processed to identify anyone by unique physical characteristics, and is therefore not biometric data. If you place special-category data inside a document you upload, you do so as controller and under your own responsibility.
Your details reached us from the person who sent you the document. We did not collect them from you, and we did not choose to process them. The categories are those listed in section 3: your name, email address, phone number where given, the signature you draw, and the technical record of the signing steps. We use them for one purpose only: delivering the document to you, recording that the signing took place, and returning the signed copy.
Your address is never used for marketing, never sold, never passed to any other customer, and never used to build a profile of you. The document itself is deleted automatically after the retention period in section 9.
Where the sender uses RemoSign for business purposes, they are the controller of your data and we are their processor: send correction or erasure requests to them, and if you write to us instead we will pass the request on and help them answer it. Where the sender is a private individual acting in a personal capacity, RemoSign is the controller and you may exercise every right in section 11 directly against us at info@remosign.com.
Where we rely on legitimate interest, we have weighed it against your rights and are ready to explain that assessment on request.
This section is as important as the rest, and we intend to be held to it:
Only the providers required to operate the platform, and only to the extent required: infrastructure and hosting, payment processing, and email delivery. Each is bound by a written contract with confidentiality and security obligations, and none is permitted to use the data for its own purposes. A current list of these processors is available to customers on request at info@remosign.com.
Beyond that, we disclose data only where we are legally compelled to, or where it is necessary to establish or defend legal claims or to protect the safety of people. If a request for data is legally invalid, we refuse it.
Data is stored on servers located in the United Kingdom and is administered by the operator from Israel. Both the United Kingdom and Israel hold a European Commission adequacy decision, meaning the Commission has determined that they provide a level of data protection essentially equivalent to that of the European Union. Personal data can therefore move from the EEA to us lawfully on the basis of adequacy, with no Standard Contractual Clauses required. Where a specific transfer ever falls outside an adequacy decision, we apply the European Commission's Standard Contractual Clauses.
For security reasons we do not publish the identity of our infrastructure providers, our network addresses, or our system architecture. Customers who need this information for a due-diligence or procurement process can request it under a confidentiality undertaking.
When a retention period ends, data is deleted or irreversibly anonymised.
We apply technical and organisational measures appropriate to the risk: transport encryption, encryption at rest for identification numbers, password hashing, access restricted on a need-to-know basis, session and device limits, optional two-factor authentication, and logging of sensitive actions. No system connected to the internet can be guaranteed absolutely secure, and we will not pretend otherwise. If a breach occurs that is likely to result in a risk to your rights, we will, without undue delay, notify the competent supervisory authority and, where the law requires, you.
Wherever you are, you may ask us to: access the data we hold about you, correct it, delete it, restrict or object to its processing, receive it in a portable format, and withdraw any consent you have given. Write to info@remosign.com. We answer within one month, and will tell you if we need longer and why. Exercising these rights is free; we charge nothing and will not make the service worse because you asked.
If we cannot identify you from the request, we may ask for enough information to be sure we are not handing your data to someone else. You always have the right to complain to your local data-protection authority. The regional annexes below name them.
The service is intended for adults acting in a professional or contractual capacity. We do not knowingly collect data about anyone under 18. If you believe a minor's data reached us, write to info@remosign.com and it will be removed.
The site uses strictly necessary and functional cookies only: keeping you signed in, protecting forms against forgery, and remembering your language choice. There are no analytics, advertising, or tracking cookies, which is why you see a short notice rather than a consent manager. Should a non-essential cookie ever be introduced, it will be set only after your explicit consent.
We may update this policy. Material changes are published on this page with a new effective date, and where the change affects you significantly we will also notify you by email.
The sections above apply to everyone. The following add rights and information specific to where you are.
Processing is governed by the GDPR and, for the United Kingdom, the UK GDPR and Data Protection Act 2018. You have the rights in Articles 15 to 22 GDPR, as described above, and the right to lodge a complaint with the supervisory authority of your country of residence, place of work, or the place of the alleged infringement. In the United Kingdom that is the Information Commissioner's Office. We rely on adequacy decisions for transfers, as set out in section 8. We do not carry out large-scale monitoring or large-scale processing of special-category data, and have therefore not appointed a Data Protection Officer; privacy questions are handled at info@remosign.com.
Processing is subject to the Protection of Privacy Law, 5741-1981, including Amendment 13, and the regulations made under it. You are not legally obliged to provide data; you do so voluntarily, and without it the service cannot be delivered. You may inspect the data held about you, request its correction, and request its deletion, and you may complain to the Privacy Protection Authority. Identification numbers, where entered, are held encrypted.
Processing is subject to the Lei Geral de Proteção de Dados (Law 13.709/2018). Your rights under Article 18 include confirmation of processing, access, correction, anonymisation or deletion of unnecessary or excessive data, portability, information about shared parties, and revocation of consent. The legal bases we rely on correspond to Article 7, II, V and IX: legal obligation, performance of a contract, and legitimate interest. As a small processing agent within the meaning of ANPD Resolution CD/ANPD No. 2/2022 we are not required to formally designate an encarregado, and we maintain instead the direct communication channel that resolution requires: info@remosign.com. The supervisory authority is the ANPD.
Processing is subject to the Act on the Protection of Personal Information. Purposes of use are those set out in section 5. Personal data is stored in the United Kingdom; the United Kingdom maintains a comprehensive data-protection regime (the UK GDPR and the Data Protection Act 2018) with an independent supervisory authority, and is recognised as adequate by both the European Commission and the Personal Information Protection Commission of Japan. Requests for disclosure, correction, cessation of use, or deletion of retained personal data, and complaints, are handled free of charge at info@remosign.com.
For users in the United Arab Emirates, processing is subject to Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data; for users in the Kingdom of Saudi Arabia, to the Personal Data Protection Law and its implementing regulations. You have rights of access, correction, deletion, restriction, and objection, and the right to complain to the competent national authority. Where local law requires data to remain within the country, tell us before you upload. The service stores data outside the Gulf states, as stated in section 8.
We do not sell personal information and we do not share it for cross-context behavioural advertising, as those terms are defined in the California Consumer Privacy Act. We do not use sensitive personal information for purposes requiring a right to limit. California residents may exercise their rights to know, delete, correct and opt out through the same address below, and we will not discriminate against anyone who does.