Electronic signature policy
Last updated: Sep 23, 2026
Draft pending legal review. Details in square brackets must be completed before launch.
1. Signature type
Biometric advanced electronic signature under Article 26 of Regulation (EU) 910/2014 (eIDAS), complemented by a qualified timestamp under its Articles 41 and 42.
2. Signer identification
The signer receives by email a unique link with 256 bits of entropy. Only the SHA-256 hash of the link is stored. Name, email, IP address, user agent, device, approximate location and the event timeline are recorded.
3. Signature creation
After reviewing the whole document and accepting the consent (a versioned, recorded text), the signer draws their signature. For every point we capture coordinates, pressure, tilt, pointer type and a high-resolution timestamp.
4. Integrity and sealing
We compute the SHA-256 fingerprint of every original document, of the biometric file and of the final signed PDF. An RFC 3161 timestamp is requested from Mensatek (policy OID 1.3.6.1.4.1.5734.3.18.1) over the latter and over the evidence certificate.
5. Verification
Anyone can verify a document at docufirma.es/verify with its code or fingerprint. The timestamp can be checked independently with OpenSSL (openssl ts -verify).
6. Evidence retention
Evidence is kept encrypted for [5] years. Access is restricted to server processes and, upon request, to judicial authorities.