Privacy Policy

Effective:

This Privacy Policy explains how SecuSign ("we", "us", "our") collects, uses, and protects information when you use our services, websites, and applications (collectively, the "Services").

Data controller

SecuSign Solutions Co., Ltd.
23/8 Moo 1, Khao Sam Sip Hap, Tha Maka, Kanchanaburi, Thailand 71120
Contact: [email protected]

Overview
  1. What we collect
  2. How we use information
  3. Legal bases (GDPR) / PDPA / CCPA
  4. Cookies & local storage
  5. Data retention
  6. Sharing & transfers
  7. Security
  8. Your rights
  9. Self-hosted deployments
  10. Changes
  11. Contact

1) Information we collect

  • Account data: name, email, password hash, organization name (if provided).
  • Envelope data: documents you upload, recipients, placement of fields, signature images, audit logs, timestamps, and IP/user-agent for verification.
  • Usage & diagnostics: basic logs (request paths, status codes), crash reports, and performance metrics.
  • Payment data (SaaS only): plan, billing status, and processor IDs processed by our payment provider. We do not store full card details.

2) How we use information

  • Provide and operate the Services (render PDFs, route invites, collect signatures).
  • Generate audit trails and verification artifacts (QR/ledger).
  • Prevent abuse, secure accounts, and troubleshoot.
  • Comply with legal obligations and enforce our Terms.
  • Communicate service notices, updates, and security alerts.

3) Legal bases & regional notices

GDPR (EEA/UK): We process personal data on the bases of contract (Art. 6(1)(b)), legitimate interests (security, abuse prevention; Art. 6(1)(f)), legal obligation (Art. 6(1)(c)), and consent where applicable (Art. 6(1)(a)).

Thailand PDPA: We act as a data controller for hosted SaaS accounts and as a processor for customer-controlled envelopes. We honor data subject rights to access, correction, deletion, and objection/withdrawal of consent.

CCPA/CPRA (California): We do not sell personal information. You may request access or deletion of your data as described below.

4) Cookies & local storage

We use strictly necessary cookies for session authentication and CSRF protection. Optional analytics cookies are disabled by default. Your envelope state (e.g., page zoom, UI prefs) may use local storage on your device.

5) Data retention

  • Accounts: retained while your account is active and as required by law.
  • Envelopes & audit logs: retained per your workspace retention settings; deleted envelopes are purged from active storage and later from backups on a rolling schedule.
  • Server logs: typically 30–90 days, unless needed for security or legal reasons.

6) Sharing & cross-border transfers

We share data with service providers that help deliver the Services (e.g., email delivery, storage, payment processing) under contracts that require appropriate safeguards. Data may be processed outside your country. Where required, we use appropriate transfer mechanisms (e.g., SCCs).

7) Security

  • Encryption in transit (HTTPS/TLS); encryption at rest for hosted storage.
  • Role-based access controls, least-privilege credentials, and audit trails.
  • Defense-in-depth for document integrity (immutable ledger with QR verification).

8) Your rights

You may access, correct, download, or delete personal data by visiting account settings or contacting us. We will respond as required by applicable laws. If we process data on behalf of a customer, we may redirect your request to that customer.

9) Self-hosted deployments

If you deploy SecuSign on infrastructure you control, you act as the data controller for documents and recipient data. You are responsible for configuring security, backups, retention, and regional compliance. Our software may send optional telemetry only if you enable it.

10) Changes

We may update this Policy. We will notify you of material changes via the Service or email. Your continued use of the Service after the effective date constitutes acceptance.

11) Contact

Questions or requests: [email protected]