← SignedBy

Privacy Policy

Effective July 14, 2026

This Privacy Policy explains how SignedBy, operated by SPRK10 B.V., a company incorporated in the Netherlands (“we,” “us,” or “our”), handles personal data — including how we collect, use, protect, and otherwise process it — when you use signedby.ai, whether as an account holder (“Sender”) or as someone asked to sign a document (“Signer”). Because the data we handle serves different purposes, we act in different roles depending on the data involved, as explained in the section immediately below.

1. Our role: when we are a controller and when we are a processor

The capacity in which we handle personal data — and the obligations that apply to us — depends on the data involved.

When we are a controller: We determine the purposes and means of processing, and therefore act as a controller, for account holder and Sender data, billing information, signup and marketing attribution data (including UTM parameters), and usage and technical security logs.

When we are a processor:We act as a processor for Signer data, uploaded document content, field values and signatures, and the audit trail generated for a Customer's documents. In each of these cases the Customer is the controller, the Customer's own privacy notice governs that processing, and we process the data only on the Customer's documented instructions under our Data Processing Addendum (DPA). We describe this processing here only for transparency. Because the Customer (Sender) is the controller for this data, the Customer is responsible for informing its recipients about this processing — including the audit-trail and activity tracking involved in signing — as described in our Terms of Service and Data Processing Addendum.

2. Information we collect

We collect the following categories of information:

  • Account information: your name, email address, and organization details when you sign up.
  • Documents and field data:the PDFs you upload, the field values Signers enter (including typed or drawn signature images), and template configurations. We handle this content as a processor on the Customer's (Sender's) behalf.
  • Signer information:the name and email address of anyone you send a document to. We handle this information as a processor on the Sender's behalf.
  • Audit trail data:for every action taken on a document (created, sent, viewed, consent given, signed, declined, completed, voided), we record a timestamp, IP address, browser/device (“user agent”) string, and a cryptographic hash of the signed document. We generate this audit trail as a processor on the Customer's behalf, and we also retain it as an independent controller to keep the signing process legally defensible under ESIGN/UETA and the EU eIDAS Regulation (No 910/2014). It is not used for advertising.
  • Engagement data:for Senders on paid plans, we record how long a Signer spends viewing each page of a document before signing (aggregated dwell time per page, not exact scroll position or keystrokes), so the Sender can see whether a document was actually read. We handle this data as a processor on the Sender's behalf.
  • Billing information: if you subscribe to a paid plan, our payment processor, Stripe, collects your payment card details directly — SignedBy never sees or stores full card numbers.
  • Usage data: basic technical logs (e.g. request metadata) needed to operate and secure the service.

3. How we use information

We use the information above to:

  • Provide the core service — rendering documents, routing them to Signers, and producing signed PDFs;
  • Send transactional email, such as signing invitations, reminders, and completion notices;
  • Power optional AI-assisted features — suggesting where to place signature and text fields, drafting a document from your description, and summarizing a document's contents — by sending the relevant document text to Mistral AI for analysis;
  • Maintain the audit trail required for a legally defensible electronic signature;
  • Process subscription payments and manage billing;
  • Secure the service and prevent abuse;
  • Improve and develop the service, using only aggregated or anonymised data and never Signer data or customer document content; and
  • Comply with legal obligations.

We do not sell personal data, and we do not use document content to serve advertising.

4. Who we share data with

We share personal data only with the service providers (“sub-processors”) needed to run SignedBy, each of which is contractually bound to protect it:

  • Supabase — hosts our database and handles account authentication;
  • Cloudflare (R2) — stores uploaded and signed document files;
  • Resend — delivers transactional email (invitations, reminders, notices);
  • Mistral AI— the AI provider behind optional field-suggestion, document-drafting, and summary features; only document text relevant to a feature you use is sent, and it is not used to train Mistral's models;
  • Stripe — processes subscription payments;
  • Vercel — hosts the application itself.

We may also disclose information if required by law, subpoena, or legal process, or to protect the rights, property, or safety of SignedBy, our users, or the public. A full sub-processor list is maintained in our Data Processing Addendum.

5. Data retention

We retain signed documents and their audit trail for as long as your account is active, because retrievable, reproducible records are a legal requirement for electronic signatures under ESIGN and the EU eIDAS Regulation (No 910/2014). If you delete a document or close your account, we will delete the underlying files and personal data within a reasonable period, except where we are required to retain it for legal, tax, or dispute-resolution purposes. Where we act as a processor, the retention, deletion, or return of document content and audit-trail data follows the Customer's instructions and our Data Processing Addendum.

6. Security

Documents are encrypted in transit (TLS) and at rest. Access to signer-facing signing links is controlled by an unguessable, single-use token rather than a shared password. We restrict internal access to Customer Data to what is needed to operate and support the service. No method of transmission or storage is 100% secure, and we cannot guarantee absolute security.

7. Your rights

Under the EU General Data Protection Regulation (GDPR) and, depending on where you live, other applicable privacy laws, you may have the right to access, correct, export, restrict, or delete personal data we hold about you, or to object to certain processing. You can exercise most of these rights directly from your account settings, or by emailing privacy@signedby.ai. You also have the right to lodge a complaint with your local data protection authority — in the Netherlands, this is the Autoriteit Persoonsgegevens. Where we act as a processor on behalf of a Sender (for example, for a Signer's data), we will direct your request to that Sender or assist them in responding, consistent with our Data Processing Addendum.

8. International users and data transfers

SignedBy is operated by SPRK10 B.V. from the Netherlands. Several of our sub-processors (see Section 4) are based in the United States. Where personal data is transferred outside the European Economic Area, we rely on appropriate safeguards recognized under GDPR, such as the European Commission's Standard Contractual Clauses, to protect that data. For each US-incorporated sub-processor, we conduct a Transfer Impact Assessment and execute the Standard Contractual Clauses (together with any supplementary measures identified) before any transfer takes place. Mistral AI, the AI provider for AI-assisted features, is based in France, keeping that processing within the European Economic Area.

9. Children's privacy

SignedBy is not directed to children under 18, and we do not knowingly collect personal data from them.

10. Changes to this policy

We may update this Privacy Policy from time to time. If we make material changes, we will provide reasonable notice, such as by email or an in-product notice, before the changes take effect.

11. Contact

Questions about this policy, or requests regarding your personal data, can be sent to privacy@signedby.ai.