Skip to content
DocuFirma

Privacy policy

Last updated: Sep 23, 2026

Draft pending legal review. Details in square brackets must be completed before launch.

1. Data controller

[COMPANY NAME], tax ID [TAX ID], [ADDRESS]. Data protection officer: [DPO EMAIL].

2. User (sender) data

We process your account data (name, email, company, optional tax ID), billing and usage data to provide the service (Art. 6.1.b GDPR), comply with legal obligations (Art. 6.1.c) and improve the service (legitimate interest, Art. 6.1.f).

3. Signer data

For documents sent by our users, DocuFirma acts as a data processor. We process name, email, IP address, device data, approximate location and signing events to produce the signature evidence.

4. Biometric signature data

The signature stroke (coordinates, pressure, tilt and timing) may be biometric data (Art. 9 GDPR). It is only captured with the signer's explicit consent, encrypted with AES-256-GCM, used exclusively as evidence of the signature and kept for [5] years after signing, unless legal proceedings require longer retention.

5. Processors and transfers

We use providers located in, or with servers in, the EU: Supabase (database and storage, Frankfurt), Vercel (hosting, Frankfurt), Stripe (payments), Resend (email), Mensatek (timestamping) and Sentry (error monitoring). Any international transfer relies on standard contractual clauses.

6. Retention

Account data is kept while the account is active. Completed envelopes and their evidence are kept for [5] years to defend potential claims. Invoices are kept for the periods required by tax law.

7. Your rights

You can exercise your rights of access, rectification, erasure, objection, restriction and portability by writing to [PRIVACY EMAIL] or by deleting your account in Settings. You may also lodge a complaint with the Spanish Data Protection Agency (aepd.es).