1. Who we are
CalmSign is an electronic signature service operated by CalmSign, a company established in Estonia. This policy covers the marketing site at usecalmsign.com and the application at app.usecalmsign.com. You can reach us at hello@usecalmsign.com about anything in it.
There are two roles to keep straight. For your account — your email address, your plan, your billing record — we are the data controller. For the documents you create and the people you send them to, you are the controller and we are your processor: we hold and transmit that content on your instructions. If you need a data processing agreement for that relationship, ask us and we will send one.
2. What we collect
- Account details. The email address you sign up with, a hashed password, your plan, and — on Business accounts — the members you invite.
- Document content. Whatever you write or upload, plus the names and email addresses of the people you send it to. We do not read it, mine it, or use it to train anything.
- Signature and audit records. For each signing event: the signer's name and email address, the IP address they signed from, their browser and operating system, a UTC timestamp for every step, and the SHA-256 hash of the sealed document. This is the evidence that makes a signature worth anything, so it is deliberately detailed.
- Billing. Paid plans are charged through our payment processor. Card numbers go to them, never to us; we keep the plan, the amount, and the invoice record.
- Support messages. If you email us, we keep the thread so the next person to pick it up has the context.
- Aggregate site statistics. Page views and referrers on the marketing site, with no personal identifiers — see cookies and analytics.
3. Why we collect it, and our legal basis
Under the GDPR we rely on four bases, depending on the data:
- Performance of a contract. Running your account, storing your documents, delivering signing links, generating the sealed copy and its audit trail, and taking payment.
- Legitimate interests. Keeping the service secure, preventing abuse and fraud, diagnosing faults, and understanding in aggregate which pages are useful. We balance these against your interests and keep the data minimal.
- Legal obligation. Invoices and tax records, and responding to lawful requests.
- Consent. Product email you have opted into. You can withdraw consent at any time without affecting anything else.
6. International transfers
We keep the current list of sub-processors, including the countries each one operates in, and will send it to you on request at hello@usecalmsign.com. Where a sub-processor operates outside the European Economic Area, that transfer is covered by an adequacy decision where one exists, and otherwise by the European Commission's Standard Contractual Clauses together with the UK International Data Transfer Addendum. You can request a copy of the safeguards that apply to a specific transfer.
7. How long we keep things
- Documents. Until you delete them, or until 30 days after you close your account.
- Audit records. For as long as the document they belong to exists. Deleting a document deletes its audit trail with it.
- Account data. While the account is open, then 30 days, after which it is removed.
- Billing records. 7 years, because tax law requires it.
- Support email. 24 months.
- Encrypted backups. Rotated out within 30 days, so a deleted document can persist in a backup for that long before it is gone for good.
One honest caveat: the audit trail is what makes a signed document defensible. We cannot strip a signer's name, timestamp, or IP address out of a completed record while leaving the signature intact. If that data has to go, the document goes with it.
8. Your rights and how to use them
If the GDPR or UK GDPR applies to you, you have the right to access your data, correct it, erase it, restrict or object to how we process it, take it elsewhere in a portable format, and withdraw consent. If the CCPA or CPRA applies to you, you have the right to know what we collect, to delete it, to correct it, and to opt out of sale or sharing — we do neither, so there is nothing to opt out of — and we will not treat you differently for asking.
Email hello@usecalmsign.com and say what you want. We will verify that the request comes from you, then answer within 30 days (45 where the CCPA allows longer). It is free unless a request is repetitive or excessive, in which case we will tell you before doing anything.
You can also complain to a supervisory authority. In the UK that is the Information Commissioner's Office; in the EU it is the authority for the country you live in. We would rather you came to us first, but it is your call. Our lead supervisory authority is the Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon). Because CalmSign is established in the EU, we are not required to appoint an Article 27 representative.
9. If you signed a document, not sent one
You do not need a CalmSign account to sign, and we do not create one for you. The person or company who sent you the document decides what it contains and how long it is kept — they are the controller for that record, and we act on their instructions. Write to us anyway if it is easier: we will pass your request to them, tell you who they are, and help where we are allowed to.
10. How we protect your data
Data is encrypted in transit with TLS and at rest with AES-256. Every completed document carries a SHA-256 seal, so any later alteration is detectable rather than merely forbidden. Access to production data is limited to the people who need it to operate the service, and it is logged.
No system is perfect. If a breach affects your data and creates a real risk to you, we will notify you and the relevant authority — within 72 hours of becoming aware where the GDPR requires it — and we will say what happened rather than what sounds best. More detail on how the seal and audit trail work is on the security page.
11. Children
CalmSign is a business tool and is not intended for children. We do not knowingly collect data from anyone under 16. If you believe a child has given us data, tell us and we will delete it.
12. Changes to this policy
When this policy changes we update the date at the top of the page. If a change materially affects how we handle your data, we will email account holders before it takes effect rather than relying on you to re-read the page.
13. Contact us
Questions, requests, or corrections: hello@usecalmsign.com. Our terms of service cover the rest of the relationship, and contact lists the quickest route for everything else.