Legal · Privacy

Privacy policy

A plain-English summary of what we collect, why we collect it, and the controls you have over it. This isn’t a substitute for legal review — we recommend your counsel read it before signing a DPA.

Last updated · Placeholder text, pending legal review

01

Information we collect

We collect information you give us directly — your name, email address, organization details — when you create an account. We also collect document metadata (file names, signer emails, timestamps, event logs) needed to run the signing service.

We do not read the contents of your uploaded documents. Document bytes are encrypted at rest and we have no operational need to inspect them.

02

How we use your information

We use your information to:

  • Provide, maintain, and improve the legesis service
  • Send transactional emails — envelope status, signing invitations, reminders
  • Process payments and manage subscriptions
  • Detect fraud, abuse, and keep the platform safe
  • Comply with applicable legal obligations
03

Data storage & security

Documents are encrypted at rest with AES-256 and in transit over TLS 1.2+. Production data lives in segregated tenant scopes with audit logging on every privileged operation. We maintain a formal incident response plan and review our security controls annually.

04

Data sharing

We do not sell your data. We share information only with service providers strictly necessary to operate the platform — payment processor, email delivery, cloud infrastructure — and when required by law. A current list of sub-processors is available on request.

05

Data retention

Account data is retained as long as your account is active. Deleted envelopes are purged from our storage within 30 days. You can request full account deletion at any time, and we will comply within 30 days of verification.

06

Your rights

Depending on your jurisdiction (GDPR, CCPA, LGPD, and similar), you may have rights to access, correct, delete, export, or object to the processing of your personal data. Email privacy@legesis.com to exercise any of these.

07

Cookies

We use essential cookies for authentication and session management. Analytics cookies are optional; you can disable them in your browser or via our cookie banner. We do not use tracking cookies for third-party advertising.

08

Changes to this policy

We may update this policy from time to time. For material changes we’ll send email notice to account owners and keep the prior version archived for reference.

09

Contact

For any privacy-related question write to privacy@legesis.com.