Privacy policy
Version 1.0.0 · Effective from 7/27/2026
Who processes data: (a) Sygnau as controller for account, billing and platform security; (b) the customer organisation as controller for participants, signatures and content; Sygnau acts as processor under the DPA.
Data: account, organisation, participants, authorisations, responses and signatures, scanned documents, technical metadata, audit events and billing.
Purposes: provide the service, authentication, signing and tracking, support, security, billing and legal compliance.
Legal bases: contract performance, legitimate interests (security), legal obligation where applicable, and consent when required. Special categories: under customer instructions.
Processors: Supabase, Vercel, Resend, Stripe, OpenAI (when enabled), Google (OAuth).
International transfers with appropriate safeguards where applicable.
Retention per active account, legal duties and DPA policies.
Rights vis-à-vis the relevant controller. Contact: signoo.app@gmail.com.
Minors: customer responsibility.
Security: RLS, encryption in transit, private storage, append-only audit.
Breaches: internal register with human review before legal notices.
Cookies: essential only.