This is a product-specific privacy draft, not a statement of current production operations. Confirm the legal entity, vendors, locations, retention periods, and Privacy Officer before publication.
1Scope and accountability
This Privacy Policy describes the practices of [LEGAL ENTITY NAME] (“GetSimpleSign,” “we,” “us,” or “our”) for our website, applications, and electronic-signature service. Our designated Privacy Officer is accountable for personal information under our control and may be contacted at [PRIVACY OFFICER EMAIL].
When an organization sends a document through GetSimpleSign, that organization generally decides why the document and signer information are processed. It is responsible for collection and instructions, while GetSimpleSign acts as its service provider. Questions about document contents should normally be directed to the sender first.
2Information we collect
- Account information: name, work email, organization, membership, role, authentication, and account-security records.
- Agreement information: documents, templates, recipient names and email addresses, field assignments, signatures, signing intent, consent records, timestamps, status, and completed records.
- Technical and security information: IP address, browser and device data, session identifiers, request identifiers, authentication attempts, audit events, and security logs.
- Communications: support requests, feedback, delivery status, bounce information, and correspondence.
- Billing information: plan, usage, invoices, and transaction identifiers. A payment processor may collect card details directly; GetSimpleSign should not store complete card information.
- Website information: essential cookies and basic server logs. This draft assumes no advertising cookies or cross-site behavioural advertising.
3Sources
We receive information from account holders and Signers, organizations that send requests, browsers and devices, and service providers such as email-delivery, hosting, security, support, and payment providers.
4Purposes
- Create and secure accounts and workspaces.
- Upload, process, route, sign, finalize, store, and retrieve agreements.
- Send verification, invitation, routing, reminder, completion, support, billing, and security communications.
- Authenticate users, prevent fraud and abuse, investigate incidents, and protect the Service.
- Maintain audit, usage, delivery, and completion records.
- Provide support, diagnose errors, improve reliability, and understand aggregate usage.
- Meet legal, tax, accounting, regulatory, and dispute-resolution requirements.
- Carry out another purpose disclosed at collection or authorized by valid consent.
5Consent and choices
We seek meaningful consent where required, considering information sensitivity and reasonable expectations. A Signer must affirmatively agree to use electronic records and signatures before signing. A Signer may decline and contact the sender for an alternative.
You may withdraw consent to optional processing, subject to legal or contractual restrictions and reasonable notice. Withdrawal does not invalidate prior lawful processing and may prevent use of some features.
6How we disclose information
We may disclose personal information:
- To the Customer and authorized workspace users that initiated or administer the transaction.
- To transaction participants as needed to display, route, complete, and evidence the agreement.
- To vetted subprocessors providing hosting, object storage, email delivery, malware scanning, monitoring, support, and payments.
- To professional advisers under confidentiality obligations.
- To comply with valid legal process, protect rights and safety, investigate abuse, or complete a corporate transaction subject to safeguards.
- With the individual’s direction or consent.
We do not sell personal information. This draft assumes we do not use document contents or signatures for advertising or train general-purpose artificial-intelligence models on them.
7Processing locations and transfers
The intended production architecture stores agreement PDFs in a private S3 bucket in Canada and stores application records in a protected SQLite deployment selected by the hosting arrangement. Some subprocessors—particularly email, support, monitoring, or payment providers—may process information outside Canada. Information processed elsewhere may be subject to that jurisdiction’s laws. Final locations and subprocessors must be published before launch.
8Retention
We retain information only as long as reasonably required for the stated purposes, documented Customer instructions, and legal obligations. These product defaults are policy settings, not legal advice, and organizations should confirm they fit their obligations.
Deletion may be delayed by legal hold, dispute, statutory requirement, investigation, or backup cycle. We securely delete or de-identify information when retention ends.
9Safeguards
Safeguards are designed to be proportionate to sensitivity and include least-privilege workspace authorization, password hashing, single-use signer tokens stored as cryptographic hashes, encryption in transit, private object storage, file validation and scanning, controlled backups, audit events, monitoring, vendor assessment, and staff confidentiality. Final production claims must match deployed controls.
No safeguard eliminates all risk. Account holders must protect credentials, use accurate recipient addresses, and limit unnecessary information.
10Privacy incidents
We maintain a process to investigate, contain, document, and respond to suspected privacy breaches. Where required, we notify affected Customers, individuals, regulators, or other authorities and maintain breach records. Customer contracts should state incident communication responsibilities.
11Access and correction
You may request access to personal information under our control, ask how it has been used or disclosed, and request correction. We may need to verify identity and may refuse or limit access where law permits or requires, such as where disclosure would reveal another person’s information or protected privilege.
For information in an agreement sent by an organization, contact the sender first. You may also contact [PRIVACY OFFICER EMAIL]. We will respond within applicable legal timeframes.
12Cookies and analytics
Essential cookies may maintain sessions, security, language, and accessibility preferences. If optional analytics or marketing technologies are added, this Policy and the consent interface must be updated before activation. Browser controls can limit cookies, but disabling essential cookies may prevent sign-in or signing.
13Children
The Service is intended for organizations and adults. It is not directed to children. A Customer using the Service for a minor must have lawful authority and use an appropriate consent process.
14Changes
We may update this Policy to reflect legal, service, vendor, or security changes. The effective date will be updated and additional notice provided where changes are material or renewed consent is required.
15Questions and complaints
Contact the Privacy Officer at [PRIVACY OFFICER EMAIL] or [BUSINESS ADDRESS, ONTARIO, CANADA]. We will investigate and explain the outcome. You may also have the right to complain to the Office of the Privacy Commissioner of Canada or the applicable provincial authority.
Privacy sources considered
Confirm the current requirements and obtain legal review.
PIPEDA fair information principlesOPC privacy breach guidanceOPC processing across borders guidance