Sygnau

Privacy policy

Version 1.0.0 · Effective from 7/27/2026

Who processes data: (a) Sygnau as controller for account, billing and platform security; (b) the customer organisation as controller for participants, signatures and content; Sygnau acts as processor under the DPA.

Data: account, organisation, participants, authorisations, responses and signatures, scanned documents, technical metadata, audit events and billing.

Purposes: provide the service, authentication, signing and tracking, support, security, billing and legal compliance, and product improvement via aggregated usage analytics (PostHog EU, no participant PII).

Legal bases: contract performance, legitimate interests (security), legal obligation where applicable, and consent when required. Special categories: under customer instructions.

Processors: Supabase, Vercel, Resend, Stripe, OpenAI (when enabled), Google (OAuth), PostHog EU (product analytics without PII).

International transfers with appropriate safeguards where applicable.

Retention per active account, legal duties and DPA policies.

Rights vis-à-vis the relevant controller. Contact: signoo.app@gmail.com.

Minors: customer responsibility.

Security: RLS, encryption in transit, private storage, append-only audit.

Breaches: internal register with human review before legal notices.

Cookies and analytics: essential technical cookies only (session, locale, active organisation). Product analytics (PostHog Cloud EU) runs without non-essential cookies and does not send participant emails, names, or documents.

Sygnau · 7458052