Working draft. Not reviewed by counsel, and not binding.

This page is a draft written to hold the shape of the final notice. No lawyer has reviewed it, Signitri has not adopted it, and it creates no rights or obligations for you or for Signitri. Every passage in square brackets is an open question that must be answered before publication — the retention periods in particular are blank rather than guessed. Until they are filled, do not rely on anything below. Corrections go to hello@signitri.com.

Signitri asks people for a photograph of their government photo ID and a photograph of their face, so that a signature can be attached to a person. That is a lot to ask of someone who has never heard of the company. This notice is written to be read, not to be survived.

1. The two roles Signitri plays

For an account holder’s own data — name, email address, team membership, billing — Signitri decides why and how it is processed. Signitri is the controller, and the responsible party under POPIA.

For the contents of a document and the data of the people asked to sign it, Signitri acts on the sender’s instructions. The sender is the controller; Signitri is the processor, and the operator under POPIA. The terms of that relationship are in the data processing addendum.

Put plainly, if you were asked to sign something: the organization that sent it decided why your data was collected. Signitri handles it for them, and the parts of this notice about your rights tell you who to ask first.

2. What is collected

Account data

Name, email address, password credentials, organization and team membership, role, and the settings you choose. Signitri stores credentials in hashed form. [TO BE CONFIRMED: exact account fields, and whether phone numbers are collected for account holders as well as recipients.]

Document data

The files you upload, the fields you place on them, the names, email addresses and phone numbers of the recipients you name, the order you set for signing, and the messages you send alongside a document.

Identity verification data — the most sensitive thing here

To verify a signer, Signitri collects an image of a government photo ID — passport, driver’s license or national ID card — the data printed on it, including the ID number, full name, date of birth and expiry date, and a selfie taken at the moment of signing.

The selfie is used to confirm a live person is present and to compute a face match against the photo on the ID. That is biometric processing: measurements of a person’s physical characteristics, used to identify them. Under GDPR it is a special category of personal data. Under POPIA it is special personal information. Illinois, Texas and Washington regulate it under their own statutes, and other US states are adding rules.

This is the most sensitive category the product handles, and it is the one where vague language would be a failure. [TO BE CONFIRMED: who inside Signitri can view an ID image or a selfie and under what controls; whether a biometric template is stored or only a score; whether the images are encrypted at rest and with what key management; the destruction schedule; and the written-consent and retention-schedule requirements imposed by Illinois BIPA, Texas CUBI and Washington law.]

Signature data

A drawn signature is not kept only as a picture. Signitri records the path of the stroke, the timing between points along it, and the pressure where the device reports it. That is behavioral biometric data — information about how you write, not only what you wrote.

It is recorded because it is part of what makes a signature defensible when someone later says it was not theirs. It is disclosed here because it is collected, and a notice that skipped it would be hiding the interesting part.

Typed and uploaded signatures do not carry stroke data. [TO BE CONFIRMED: whether stroke data is retained inside the sealed evidence pack, retained separately, or discarded after the signature image is produced; and whether it counts as biometric data under each of the statutes named above.]

Audit data

Every action is written to an audit log: who opened a document and when, the IP address and browser they used, which fields they completed, when the document was delivered and over which channel, and the time of each event in UTC. The audit log is the evidence. It does not get edited, including by Signitri, and it is retained with the document it belongs to.

Billing data

Payment is handled by Stripe. Signitri stores subscription state, seat counts and invoices rather than full card numbers. [TO BE CONFIRMED: precisely which billing fields Signitri stores and which stay with the payment provider.]

Support and communications

Messages you send to Signitri, and the records needed to answer them.

3. What the signing backend never receives

The system that applies signatures never receives the document itself. That limits how far your file travels inside the product, and it is worth stating because the usual assumption is the opposite. [TO BE CONFIRMED: the precise technical description of this boundary, so the sentence above is exactly true and can be shown to be.]

4. Why each thing is collected

  • To run the service you asked for, or that the sender asked for on your behalf.
  • To verify identity, because a signature nobody can attach to a person is not worth much, and because the sender required it before you were invited to sign.
  • To produce an evidence pack that holds up when a signature is challenged.
  • To bill account holders and to prevent abuse of the service.
  • To meet legal obligations, including records the law requires be kept.

[TO BE CONFIRMED: the lawful basis for each purpose under GDPR Article 6, the Article 9 condition relied on for biometric data, the POPIA section 27 justification for special personal information, and where consent is the basis, the exact wording and timing of the consent request.]

5. How long it is kept

These are the numbers a regulator asks for first. They are blank because a plausible number written by someone who does not set the schedule is worse than an admitted gap.

Account and team records[TO BE CONFIRMED]
Documents and evidence packs[TO BE CONFIRMED]
Government photo ID images[TO BE CONFIRMED]
Selfies and liveness captures[TO BE CONFIRMED]
Face-match scores and outcomes[TO BE CONFIRMED]
Signature stroke data[TO BE CONFIRMED]
Audit logs[TO BE CONFIRMED]
Billing records[TO BE CONFIRMED]

[TO BE CONFIRMED: every value in the table above, whether any of them differ by plan or by jurisdiction, what a customer can shorten, and what happens to each category when an account closes.]

6. Who it is shared with

  • ThisIsMe, which performs identity verification.
  • The other companies listed on the subprocessor page, each for one stated purpose.
  • The organization that sent you a document, which receives the verification outcome for each signer and the sealed evidence pack.
  • Authorities, where the law requires disclosure.

[TO BE CONFIRMED: exactly what the sender sees — whether the ID image and the selfie are visible to them, or only the outcome and the score. This is a material disclosure to signers and it must be stated exactly.]

Signitri does not sell personal data and does not share it for cross-context behavioral advertising.

7. Where it is processed

Signitri, Inc. is a US company, and data may be processed in the United States. [TO BE CONFIRMED: hosting regions, whether EU or South African data can be kept in region, and the transfer mechanism relied on for data leaving the EEA, the UK and South Africa — standard contractual clauses, the UK addendum, and the POPIA section 72 basis.]

8. Your rights

Under GDPR you can ask for access to your data, correction, erasure, restriction of processing, portability, and you can object to processing. POPIA gives rights of access, correction, deletion and objection. Several US states give comparable rights, including the right to know and to delete.

If you signed a document, send the request to the organization that sent it — they decided why your data was collected. Signitri will pass on requests it receives and help the sender answer them.

One limit, stated rather than buried: a sealed evidence pack is the record of a legal act, and removing part of it would destroy what it exists to prove. [TO BE CONFIRMED: how erasure requests are handled where the data sits inside a sealed evidence pack a party may need to rely on, which exemption is relied on, and what a signer is told when a request is refused on that ground.]

9. Scores, thresholds and human review

The face match produces a score. A score below the threshold does not block anyone — it sends the verification to a person, who looks at it and decides.

[TO BE CONFIRMED: whether a rejection can ever be issued without a human looking at it, what the signer is told, and how they contest it. GDPR Article 22 requires this section to be exact.]

10. Children

Signitri is not intended for use by anyone under 18. [TO BE CONFIRMED: the age threshold, what happens if a signer turns out to be a minor, and how that interacts with identity documents already submitted.]

11. Security

The measures behind all of this are described in the security overview. [TO BE CONFIRMED: the specific technical and organizational measures to be named here, matched to the schedule in the data processing addendum.]

12. Who to contact

hello@signitri.com. [TO BE CONFIRMED: dedicated privacy mailbox; the data protection officer, if one is appointed; the EU representative under GDPR Article 27; the UK representative; the POPIA information officer registered with the Information Regulator; and the registered entity address.]

13. Changes to this notice

[TO BE CONFIRMED: how changes are notified, the notice period before a material change takes effect, and whether prior versions stay available.]