SignAS — Data Usage Policy

Last updated: 2026-08-26

This policy explains what personal data SignAS processes, why, and for how long. SignAS is operated by Martin Barth, an individual based in the Czech Republic, who acts as data controller for the personal data described here. Contact: martasbarth8@gmail.com.

SignAS does not use cookies, browser tracking, or analytics. Each signing session is identified only by a unique, unguessable signing-link token — no account or login is required to sign a document.

1. What we collect and why

DataPurposeLegal basis
Signer name, email, phone (if SMS verification is used)Sending the signing invitation and one-time verification codesPerformance of the signing process the sender initiated on the signer's behalf; legitimate interest
IP address and browser user-agent, captured when a signer opens and signs a documentPart of the audit trail evidencing how and from where the document was signedLegitimate interest — evidentiary integrity of the signature
The document itself and the signer's drawn/typed signature imageProducing the signed documentPerformance of the signing process
Bank iD verified identity data (name, date of birth, and a verified-identity assertion), only when Bank iD verification is usedBinding a verified real-world identity to the signature, as required for an Advanced Electronic SignatureLegitimate interest / legal obligation to produce evidentiary signatures
A hash-chained log of envelope events (created, opened, verified, signed) with timestampsTamper-evident audit trail supporting the legal validity of the signatureLegitimate interest; legal obligation where the signed document requires it

2. Who else processes this data

SignAS uses the following processors, each bound by their own data processing terms:

3. Retention

Signed documents and their audit trail (including the Certificate of Completion) are retained for as long as they may serve as evidence of the signed agreement — typically for the duration the underlying contract could be legally challenged. Because the audit trail's integrity is itself part of the signature's evidentiary value, individual records within it cannot be selectively deleted while the related document is retained.

4. Your rights

Under the GDPR, you may request access to, or correction of, personal data we hold about you. You may also request erasure, though this may not be possible for data forming part of a completed signature's evidentiary record while that record needs to be retained (Art. 17(3)(b)/(e) GDPR — legal claims and legal obligations). To exercise any of these rights, contact martasbarth8@gmail.com. You also have the right to lodge a complaint with the Czech Office for Personal Data Protection (ÚOOÚ).

5. Security

Documents are stored in a private (non-public) S3 bucket with encryption at rest; the signing private key is held exclusively in AWS KMS and is never exported. Signing links use unguessable, hashed tokens rather than passwords.

6. Status of this policy

SignAS is under active development. This policy will be updated as the service evolves; the "last updated" date above reflects the current version.