Privacy Policy
Effective date: July 5, 2026 · Version 1.0
This policy explains how OwnSig Inc. handles personal data across (a) our public websites, (b) the OwnSig service, and (c) email recipients who interact with signatures managed by our customers.
1. Website visitors
We collect standard server logs (truncated IP, user agent, pages viewed) for security and capacity planning, retained for 30 days. Public-site analytics are first-party only: a cookieless aggregate layer (path, UTM parameters, referrer host, coarse country from the edge geo header, device class — no stored IP and no identifier) runs in every region, and an optional first-party visitor cookie for multi-session analytics runs only under the applicable consent regime (prior opt-in in the EU/UK/Switzerland/Canada/Brazil; opt-out elsewhere, with Global Privacy Control honoured automatically). We do not run third-party advertising trackers and we do not sell personal data. Full cookie inventory: Cookie Policy; choices: Your privacy choices.
2. Account holders (our customers)
For account holders we process: registration details (name, work email, password hash), organisation settings, billing records, support communications, and product telemetry (feature usage events tied to pseudonymous user identifiers). Legal bases: performance of contract, legitimate interest in improving and securing the service, and legal obligations for billing records.
3. Employee directory data (processed for customers)
When a customer connects HRIS, identity, or mail-platform integrations, we process employee directory attributes (name, title, department, phone, photo, office location) as a processor on the customer's instructions, under our Data Processing Addendum with Standard Contractual Clauses where applicable. Current subprocessors are listed at /legal/subprocessors. Customers on residency plans control the storage region, including per-employee pinning for employees located in GDPR-protected jurisdictions.
4. Email recipients
Signature click tracking is server-side and privacy-preserving by design. When a recipient clicks a tracked link we record: link token, timestamp, coarse browser family, referrer domain, and country. We do not store raw IP addresses (used transiently to derive country and then discarded), full user agents, cookies, device identifiers, or any identifier of the recipient. This data does not identify a natural person.
One organisation-controlled exception — the message log. An organisation administrator can explicitly enable a message log that stores the subject line and recipient addressesof that organisation's own signature-carrying emails, so its analytics can be searched by subject or recipient. This is off by default, captures metadata only (never message bodies), is visible only to that organisation's analytics administrators, is used solely for the organisation's own analytics, and is never used across tenants, for enrichment, or for any OwnSig purpose. Where enabled, the organisation is the controller of this data and is responsible for its lawful basis; OwnSig processes it on the organisation's instructions under the DPA.
An organisation that enables the message log may additionally enable the adaptive signature state machine, which uses that same logged data to vary which signature an employee's outbound emails carry based on how often they email a given recipient. This looks up the current recipient's address against the message log (so that address is sent to OwnSig for the lookup) and derives only a count, two dates, and a coarse topic label — never the message content itself.
5. AI features
If your organisation enables Penna with bring-your-own-key, prompts are sent to your chosen provider. With managed AI, prompts are processed by our contracted providers under terms prohibiting training on your content. We log AI usage metadata (who used it, when, success/failure) but not prompt content in telemetry.
5a. Structural training data (self-serve plans)
To improve our signature-creation AI, Free and Pro workspaces may contribute the structure of saved signatures: the template used, styling choices (colours, fonts, icon sets), which field types are filled in, and a rendered layout skeleton in which every personal value is replaced by a placeholder token beforeanything is stored. Names, email addresses, phone numbers, postal addresses, URLs, photos, banner images, and free-text content are never captured. The dataset is keyed by a salted one-way hash, so examples cannot be traced back to a workspace from the dataset itself. Administrators can opt out at any time under Policies → Product improvement & AI training; opting out also deletes everything previously captured from that workspace. Enterprise and Enterprise Sovereign tenants are always excluded at the source — no capture occurs, regardless of settings.
6. Your rights
Depending on your jurisdiction you may have rights to access, correct, export, delete, or restrict processing of your personal data. Account holders can exercise most of these directly in Settings; otherwise contact privacy@ownsig.com. Where we act as processor, we route requests to the relevant customer — whose administrators have in-product tooling for both access (a per-person DSAR export under Team) and erasure (a permanent, audit-logged per-member deletion covering analytics and logging records). You may lodge a complaint with your supervisory authority.
7. Retention and security
Customer Data is retained for the life of the account plus 35 days after deletion. Telemetry is retained 13 months. We protect data with TLS 1.2+, AES-256 at rest, role-based access, audit logging, and an incident-response programme with 72-hour breach notification. See the security page for the full control set.
8. Contact
Controller: OwnSig Inc. · privacy@ownsig.com. EU/UK representatives are listed in the DPA. Changes to this policy are posted here with an updated effective date.