1Scope and accountability
This Privacy Policy describes the practices of A1 AI Agents Inc. (“we,” “us,” or “our”), the company that operates the GetSimpleSign electronic-signature service, for our website, applications, and that service. Our designated Privacy Officer is accountable for personal information under our control and may be contacted at [email protected].
When an organization sends a document through GetSimpleSign, that organization generally decides why the document and signer information are processed. It is responsible for collection and instructions, while we act as its service provider. Questions about document contents should normally be directed to the sender first.
The Service is offered to organizations established in Canada outside Quebec. We do not offer it to organizations in Quebec, the European Economic Area, or the United Kingdom, and we do not market it there. A Customer may send an agreement to a Signer in any location; where we process a Signer’s personal information we apply the practices described in this Policy regardless of where that person is.
2What we will never do with your documents
We do not sell personal information, and we never have.
We do not use documents, templates, signatures, or recipient information to train, fine-tune, or evaluate any artificial-intelligence model — not our own, and not a third party’s — and our service providers are not permitted to do so either.
We do not use document contents for advertising, and we do not use advertising cookies or cross-site behavioural tracking anywhere on our website or in the Service.
We state this plainly because the company that operates GetSimpleSign is an artificial-intelligence company, and you are entitled to know exactly where the line is. If that ever changes we will say so here first, in advance, and not by quietly editing this page.
3Information we collect
- Account information: name, work email, organization, membership, role, authentication, and account-security records.
- Agreement information: documents, templates, recipient names and email addresses, field assignments, signatures, signing intent, consent records, timestamps, status, and completed records.
- Technical and security information: IP address, browser and device data, session identifiers, request identifiers, authentication attempts, audit events, and security logs.
- Communications: support requests, feedback, delivery status, bounce information, and correspondence.
- Billing information: plan, usage, invoices, and transaction identifiers. Our payment processor collects card details directly; we do not store complete card numbers.
- Website information: essential cookies and basic server logs. We do not use advertising cookies or cross-site behavioural advertising.
- Prospect information: where we write to someone about the Service, we hold their name, work email, organization, role, a note recording how we know them, and a record of what we sent and whether a link in it was opened. This is a small list of people we already know, added by hand. We do not buy lists, we do not scrape addresses, and we do not enrich these records from third-party data providers. Every message says who is writing and how to stop hearing from us, and a request to stop is honoured permanently.
Prospect information is the one category here that is not about a customer, a signer, or a visitor, so it is worth being precise about what it is not. It is not document information, and nothing in it is used to train an artificial-intelligence model — the commitment in Section 2 is unchanged and unqualified. Where a model helps draft a message, it is sent the note about how we know the person so the message is specific rather than generic; that processing is covered in Section 8 and the provider is named on our sub-processors page.
4Sources
We receive information from account holders and Signers, organizations that send requests, browsers and devices, and service providers such as email-delivery, hosting, security, support, and payment providers.
5Purposes
- Create and secure accounts and workspaces.
- Upload, process, route, sign, finalize, store, and retrieve agreements.
- Send verification, invitation, routing, reminder, completion, support, billing, and security communications.
- Authenticate users, prevent fraud and abuse, investigate incidents, and protect the Service.
- Maintain audit, usage, delivery, and completion records.
- Provide support, diagnose errors, and improve reliability; and create aggregated, de-identified information about how the Service is used, which excludes document contents, signatures and recipient information and cannot reasonably be used to identify anyone.
- Meet legal, tax, accounting, regulatory, and dispute-resolution requirements.
- Carry out another purpose disclosed at collection or authorized by valid consent.
6Consent and choices
We seek meaningful consent where required, considering information sensitivity and reasonable expectations. A Signer must affirmatively agree to use electronic records and signatures before signing. A Signer may decline and contact the sender for an alternative.
You may withdraw consent to optional processing, subject to legal or contractual restrictions and reasonable notice. Withdrawal does not invalidate prior lawful processing and may prevent use of some features.
7How we disclose information
We may disclose personal information:
- To the Customer and authorized workspace users that initiated or administer the transaction.
- To transaction participants as needed to display, route, complete, and evidence the agreement.
- To vetted service providers supporting hosting, file storage, email delivery, malware scanning, monitoring, support, and payments.
- To professional advisers under confidentiality obligations.
- To comply with valid legal process, protect rights and safety, investigate abuse, or complete a corporate transaction subject to safeguards.
- With the individual’s direction or consent.
Where we process personal information on a Customer’s behalf, our Data Processing Addendum sets out the terms that apply.
8Processing locations and transfers
Account and workspace records are held on servers operated by Amazon Web Services in the Canada Central region (Montréal, Canada). Agreement documents and encrypted database backups are stored separately, in private access-controlled object storage, also in the Canada Central region. No account or document data is stored outside Canada.
Two things leave the country, and only these two. Twilio SendGrid delivers our email, and Stripe processes payments; both operate principally in the United States, so the information handled by them — recipient email addresses, message content and delivery status in SendGrid’s case, and billing name, address and transaction records in Stripe’s — may be subject to that jurisdiction’s laws, including lawful access by its authorities. Document contents are not sent to either of them.
A third is planned and is not processing anything yet. Anthropic, in the United States, will help draft the messages described under prospect information in Section 3 — it would receive a name, an organization, a role, and the note recording how we know that person. It would not receive account information, document contents, templates, signatures, or recipient information of any kind. Its commercial terms do not permit training on what is sent, so the commitment in Section 2 holds without qualification. It is listed as planned, with a date, on our sub-processors page.
Our current service providers are listed on our sub-processors page. We will give at least 30 days’ notice there, and by email to Customers who ask to be notified, before a new provider begins processing personal information.
9Retention
We retain information only as long as reasonably required for the stated purposes, documented Customer instructions, and legal obligations. These product defaults are policy settings, not legal advice, and organizations should confirm they fit their obligations.
One exception, stated plainly. The IP address and browser recorded at the moment a person signs are part of the completion record for that agreement, so they are kept with it for seven years rather than deleted at twelve months. We cannot remove them from it and would not want to be able to: the record of a signature is held in a form that nothing in this service can edit after the fact, which is most of what makes it worth having. If you want an agreement and its record deleted, ask us and we will, subject to the paragraph below.
Deletion may be delayed by legal hold, dispute, statutory requirement, investigation, or backup cycle. We securely delete or de-identify information when retention ends, on the schedule above rather than on request alone.
10Safeguards
Safeguards are designed to be proportionate to sensitivity and include restricting each person to the workspace access their role requires, protecting stored passwords, issuing signing links that work only once and only for the intended recipient, encrypting information in transit, keeping uploaded files in private storage, validating and scanning uploaded files, controlled backups, activity records, monitoring, assessment of service providers, and staff confidentiality obligations.
No safeguard eliminates all risk. Account holders must protect credentials, use accurate recipient addresses, and limit unnecessary information.
11Privacy incidents
We maintain a process to investigate, contain, document, and respond to suspected privacy breaches.
If we become aware of a breach of security safeguards affecting a Customer’s personal information, we will notify that Customer without undue delay and in any event within 72 hours of confirming it. The notice will describe what we know about what happened, what information was involved, what we have done, and what we recommend — enough for the Customer to meet its own reporting obligations, including to the Office of the Privacy Commissioner of Canada and to affected individuals. We will provide reasonable further assistance and keep the records the law requires.
Where we are the organization accountable for the information, we will notify affected individuals and regulators ourselves where the law requires it.
12Access and correction
You may request access to personal information under our control, ask how it has been used or disclosed, and request correction. We may need to verify identity and may refuse or limit access where law permits or requires, such as where disclosure would reveal another person’s information or protected privilege.
For information in an agreement sent by an organization, contact the sender first. You may also contact [email protected]. We will respond within applicable legal timeframes.
13Cookies and analytics
Essential cookies maintain sessions, security, language, and accessibility preferences. Our website also offers a privacy choice between essential-only and analytics. No analytics, advertising, or cross-site tracking technology is loaded today, on either choice; the setting is stored in your browser so that your preference is already recorded if we introduce analytics later. We will update this Policy and describe what is loaded before that happens. Browser controls can limit cookies, but disabling essential cookies may prevent sign-in or signing.
14Children
The Service is intended for organizations and adults. It is not directed to children. A Customer using the Service for a minor must have lawful authority and use an appropriate consent process.
15Changes
We may update this Policy to reflect legal, service, vendor, or security changes. The effective date will be updated and additional notice provided where changes are material or renewed consent is required.
16Questions and complaints
Contact the Privacy Officer at [email protected] or Toronto, Ontario, Canada. We will investigate and explain the outcome. You may also have the right to complain to the Office of the Privacy Commissioner of Canada or the applicable provincial authority.
References
The Canadian privacy guidance this Policy is written against. Provided for reference; not part of this Policy.
PIPEDA fair information principlesOPC privacy breach guidanceOPC processing across borders guidance