CalmSign
Legal

Privacy policy

We handle documents people sign, so the short version matters: we collect what the signature needs, we keep it only as long as it is useful, and we do not sell any of it.

Last updated 18 August 2026

1. Who we are

CalmSign is an electronic signature service operated by CalmSign, a company established in Estonia. This policy covers the marketing site at usecalmsign.com and the application at app.usecalmsign.com. You can reach us at hello@usecalmsign.com about anything in it.

There are two roles to keep straight. For your account — your email address, your plan, your billing record — we are the data controller. For the documents you create and the people you send them to, you are the controller and we are your processor: we hold and transmit that content on your instructions. If you need a data processing agreement for that relationship, ask us and we will send one.

2. What we collect

  • Account details. The email address you sign up with, a hashed password, your plan, and — on Business accounts — the members you invite.
  • Document content. Whatever you write or upload, plus the names and email addresses of the people you send it to. We do not read it, mine it, or use it to train anything.
  • Signature and audit records. For each signing event: the signer's name and email address, the IP address they signed from, their browser and operating system, a UTC timestamp for every step, and the SHA-256 hash of the sealed document. This is the evidence that makes a signature worth anything, so it is deliberately detailed.
  • Billing. Paid plans are charged through our payment processor. Card numbers go to them, never to us; we keep the plan, the amount, and the invoice record.
  • Support messages. If you email us, we keep the thread so the next person to pick it up has the context.
  • Aggregate site statistics. Page views and referrers on the marketing site, with no personal identifiers — see cookies and analytics.

4. Cookies and analytics

This marketing site sets no cookies at all. Our analytics are provided by Plausible, which is cookieless: it counts a page view and a referrer, stores no cookie, builds no cross-site profile, and produces no data that identifies you. That is why you have not been shown a cookie banner — there is nothing to consent to.

The application sets a single strictly necessary cookie to keep you signed in. We run no advertising pixels, no session recording, and no third-party trackers anywhere in the signing experience. A person opening a signing link is not tracked; they are there to sign a document, not to be measured.

5. Who we share data with

We do not sell personal data, and we do not share it for cross-context behavioural advertising. We use a short list of sub-processors to run the service:

  • Infrastructure provider — application hosting, database, and encrypted backups.
  • Transactional email provider — delivery of signing links, reminders, and completed copies.
  • Payment processor — subscription billing for paid plans.
  • Plausible Analytics — aggregate, cookieless statistics for the marketing site only.

Each is bound by a contract that limits them to processing on our instructions. We will publish notice of a material change to this list before it takes effect. We may also disclose data where the law genuinely requires it, and we will tell you unless we are legally barred from doing so.

6. International transfers

We keep the current list of sub-processors, including the countries each one operates in, and will send it to you on request at hello@usecalmsign.com. Where a sub-processor operates outside the European Economic Area, that transfer is covered by an adequacy decision where one exists, and otherwise by the European Commission's Standard Contractual Clauses together with the UK International Data Transfer Addendum. You can request a copy of the safeguards that apply to a specific transfer.

7. How long we keep things

  • Documents. Until you delete them, or until 30 days after you close your account.
  • Audit records. For as long as the document they belong to exists. Deleting a document deletes its audit trail with it.
  • Account data. While the account is open, then 30 days, after which it is removed.
  • Billing records. 7 years, because tax law requires it.
  • Support email. 24 months.
  • Encrypted backups. Rotated out within 30 days, so a deleted document can persist in a backup for that long before it is gone for good.

One honest caveat: the audit trail is what makes a signed document defensible. We cannot strip a signer's name, timestamp, or IP address out of a completed record while leaving the signature intact. If that data has to go, the document goes with it.

8. Your rights and how to use them

If the GDPR or UK GDPR applies to you, you have the right to access your data, correct it, erase it, restrict or object to how we process it, take it elsewhere in a portable format, and withdraw consent. If the CCPA or CPRA applies to you, you have the right to know what we collect, to delete it, to correct it, and to opt out of sale or sharing — we do neither, so there is nothing to opt out of — and we will not treat you differently for asking.

Email hello@usecalmsign.com and say what you want. We will verify that the request comes from you, then answer within 30 days (45 where the CCPA allows longer). It is free unless a request is repetitive or excessive, in which case we will tell you before doing anything.

You can also complain to a supervisory authority. In the UK that is the Information Commissioner's Office; in the EU it is the authority for the country you live in. We would rather you came to us first, but it is your call. Our lead supervisory authority is the Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon). Because CalmSign is established in the EU, we are not required to appoint an Article 27 representative.

9. If you signed a document, not sent one

You do not need a CalmSign account to sign, and we do not create one for you. The person or company who sent you the document decides what it contains and how long it is kept — they are the controller for that record, and we act on their instructions. Write to us anyway if it is easier: we will pass your request to them, tell you who they are, and help where we are allowed to.

10. How we protect your data

Data is encrypted in transit with TLS and at rest with AES-256. Every completed document carries a SHA-256 seal, so any later alteration is detectable rather than merely forbidden. Access to production data is limited to the people who need it to operate the service, and it is logged.

No system is perfect. If a breach affects your data and creates a real risk to you, we will notify you and the relevant authority — within 72 hours of becoming aware where the GDPR requires it — and we will say what happened rather than what sounds best. More detail on how the seal and audit trail work is on the security page.

11. Children

CalmSign is a business tool and is not intended for children. We do not knowingly collect data from anyone under 16. If you believe a child has given us data, tell us and we will delete it.

12. Changes to this policy

When this policy changes we update the date at the top of the page. If a change materially affects how we handle your data, we will email account holders before it takes effect rather than relying on you to re-read the page.

13. Contact us

Questions, requests, or corrections: hello@usecalmsign.com. Our terms of service cover the rest of the relationship, and contact lists the quickest route for everything else.