Privacy Policy
Last updated: 2026-07-31
1. What we collect
Account data: when you create a SignFox account we collect your name, email address, and organization details.
Signer data: when you sign a document sent through SignFox we record your name, email address, IP address, browser user agent, your signature (drawn image or typed name), and your consent record — including the exact version of the consent text you agreed to. This information forms the legal evidence trail for the signature.
Documents: the PDF documents that organizations upload for signing, and the completed, signed versions of those documents.
2. Why we collect it
We process this data to provide the e-signature service: delivering documents to signers, capturing legally valid signatures, and producing a tamper-evident audit trail and certificate of completion that serves as evidence of who signed what, when, and how. We do not sell personal data or use it for advertising.
3. Where your data is stored
SignFox is available in two deployment modes. On self-hosted (on-premises) installations, all data — documents, signatures, and audit records — resides on infrastructure controlled entirely by the customer organization; SignFox (the company) has no access to it. On SignFox Cloud, data is stored on infrastructure we operate, encrypted in transit and at rest, and isolated per organization.
4. Sub-processors and third parties
Depending on configuration, the following third parties may process limited data:
- Resend — transactional email delivery (signer names and email addresses).
- Razorpay — subscription billing on SignFox Cloud (billing contact and payment details).
- Org-configured endpoints — timestamp authorities (TSA), OCSP/CRL responders for long-term validation, and Aadhaar eSign Service Providers (ESPs), when an organization enables these features. These receive only the data required for the cryptographic operation.
5. Retention
Document and envelope retention is configurable by each organization. Audit records and signature evidence are retained for as long as the associated signed document exists, to preserve the evidentiary integrity of completed signatures. Deleting an envelope removes its documents and signature images in accordance with the organization's settings.
6. Your rights
You may request access to, correction of, or erasure of your personal data. If you signed a document as a recipient, please direct your request to the organization that sent you the document — they are the data controller for that transaction. For anything else, or if you cannot reach the sending organization, contact us at hello@signfox.co. Note that erasure of signature evidence may be limited where retention is required to preserve the legal validity of a completed signature or to comply with law.
7. Security
All traffic is encrypted with TLS. Secrets — signing-certificate material, passphrases, and API credentials — are encrypted at rest with AES-256-GCM. Every signature event is written to a hash-chained, tamper-evident audit log, and completed documents carry SHA-256 integrity hashes so any modification is detectable.
8. DPDP Act and GDPR
SignFox is designed to support compliance with India's Digital Personal Data Protection Act, 2023 (DPDP Act) and the EU General Data Protection Regulation (GDPR): explicit consent capture, purpose limitation, data minimization, and — via self-hosted deployment — full data residency control. Organizations using SignFox remain responsible for their own compliance obligations as data fiduciaries/controllers.
9. Changes and contact
We may update this policy from time to time; the "Last updated" date above reflects the latest revision, and material changes will be announced to account owners. Questions? Email hello@signfox.co.