Last updated: 2026-08-26
This policy explains what personal data SignAS processes, why, and for how long. SignAS is operated by Martin Barth, an individual based in the Czech Republic, who acts as data controller for the personal data described here. Contact: martasbarth8@gmail.com.
SignAS does not use cookies, browser tracking, or analytics. Each signing session is identified only by a unique, unguessable signing-link token — no account or login is required to sign a document.
| Data | Purpose | Legal basis |
|---|---|---|
| Signer name, email, phone (if SMS verification is used) | Sending the signing invitation and one-time verification codes | Performance of the signing process the sender initiated on the signer's behalf; legitimate interest |
| IP address and browser user-agent, captured when a signer opens and signs a document | Part of the audit trail evidencing how and from where the document was signed | Legitimate interest — evidentiary integrity of the signature |
| The document itself and the signer's drawn/typed signature image | Producing the signed document | Performance of the signing process |
| Bank iD verified identity data (name, date of birth, and a verified-identity assertion), only when Bank iD verification is used | Binding a verified real-world identity to the signature, as required for an Advanced Electronic Signature | Legitimate interest / legal obligation to produce evidentiary signatures |
| A hash-chained log of envelope events (created, opened, verified, signed) with timestamps | Tamper-evident audit trail supporting the legal validity of the signature | Legitimate interest; legal obligation where the signed document requires it |
SignAS uses the following processors, each bound by their own data processing terms:
Signed documents and their audit trail (including the Certificate of Completion) are retained for as long as they may serve as evidence of the signed agreement — typically for the duration the underlying contract could be legally challenged. Because the audit trail's integrity is itself part of the signature's evidentiary value, individual records within it cannot be selectively deleted while the related document is retained.
Under the GDPR, you may request access to, or correction of, personal data we hold about you. You may also request erasure, though this may not be possible for data forming part of a completed signature's evidentiary record while that record needs to be retained (Art. 17(3)(b)/(e) GDPR — legal claims and legal obligations). To exercise any of these rights, contact martasbarth8@gmail.com. You also have the right to lodge a complaint with the Czech Office for Personal Data Protection (ÚOOÚ).
Documents are stored in a private (non-public) S3 bucket with encryption at rest; the signing private key is held exclusively in AWS KMS and is never exported. Signing links use unguessable, hashed tokens rather than passwords.
SignAS is under active development. This policy will be updated as the service evolves; the "last updated" date above reflects the current version.