Skip to content
DocuFirma

Electronic signature policy

Last updated: Sep 23, 2026

Draft pending legal review. Details in square brackets must be completed before launch.

1. Signature type

Biometric advanced electronic signature under Article 26 of Regulation (EU) 910/2014 (eIDAS), complemented by a qualified timestamp under its Articles 41 and 42.

2. Signer identification

The signer receives by email a unique link with 256 bits of entropy. Only the SHA-256 hash of the link is stored. Name, email, IP address, user agent, device, approximate location and the event timeline are recorded.

3. Signature creation

After reviewing the whole document and accepting the consent (a versioned, recorded text), the signer draws their signature. For every point we capture coordinates, pressure, tilt, pointer type and a high-resolution timestamp.

4. Integrity and sealing

We compute the SHA-256 fingerprint of every original document, of the biometric file and of the final signed PDF. An RFC 3161 timestamp is requested from Mensatek (policy OID 1.3.6.1.4.1.5734.3.18.1) over the latter and over the evidence certificate.

5. Verification

Anyone can verify a document at docufirma.es/verify with its code or fingerprint. The timestamp can be checked independently with OpenSSL (openssl ts -verify).

6. Evidence retention

Evidence is kept encrypted for [5] years. Access is restricted to server processes and, upon request, to judicial authorities.