Privacy Policy
Beta waitlist
If you register for the Touch2Sign beta we store your name, email, contact number (if given), company (if given), and interest so we can contact you about access. Signups are stored in the EU (AWS Ireland) and we email the Touch2Sign team when you register. We do not sell this list. To request deletion, email privacy@touch2sign.com.
1. Who we are
Touch2Sign is an electronic signature and document management platform operated by Touch2Sign Ltd, a company incorporated in the Republic of Ireland (“we”, “us”, “our”). Questions: privacy@touch2sign.com.
2. Data we collect
- Waitlist data — name, email, phone, company, and product interest when you register for beta.
- Account data — name, email, and password (hashed) when you register for the product.
- Organisation & billing data — company name, billing address, plan, currency, payment method tokens (held by our payment partners), invoices, and prepaid credit balances.
- Signing data — name, email, IP address, and device/browser information for each person who signs a document.
- Document content — documents and files you upload or generate.
- Identity verification data — where AES/QES or other IDV is used, verification results from identity providers (we do not store full payment card numbers).
- Communication data — phone numbers used for SMS or RCS signing invitations, if provided.
- Usage & metering data — sends, SMS/RCS, AES/QES events needed for entitlements and billing.
- Usage analytics — pages visited, actions taken, and timestamps via server logs.
- Payment data — billing name and address. Card numbers are processed by our payment partners (NMI and/or Stripe) and are never stored in full by Touch2Sign.
3. How we use your data
- To operate the beta waitlist and tell you when access opens.
- To provide signing and document management.
- To generate legally admissible audit trails for signed documents.
- To send signing invitations, reminders, and completion notices via email, SMS, or RCS.
- To verify document integrity using cryptographic hashing.
- To bill subscriptions, metered usage, modules, and prepaid credits.
- To comply with eIDAS and applicable data protection law.
- To improve and maintain the platform.
4. Legal basis for processing
Under the UK GDPR and EU GDPR, our lawful bases are:
- Contract performance — delivering the service you have subscribed to.
- Legitimate interests — security monitoring, fraud prevention, service improvement, and operating the waitlist.
- Legal obligation — retaining audit records as required by eIDAS and applicable law.
- Consent — where we ask for and receive your explicit consent (for example marketing).
5. Data storage and transfers
Primary data storage is on servers in the EU West (Ireland) AWS region. We do not transfer personal data outside the UK or EEA except where Standard Contractual Clauses or equivalent safeguards are in place. For a Data Processing Agreement, email legal@touch2sign.com.
- Documents and files — AWS S3 (encrypted at rest, AES-256)
- Database — AWS RDS PostgreSQL (encrypted at rest)
- Email delivery — AWS Simple Email Service (SES)
- This website — AWS CloudFront and S3
6. Data retention
- Waitlist signups — kept until you ask us to delete them, or until we close the waitlist and no longer need the list to grant access.
- Signed documents and audit trails — 7 years from the date of signing.
- Account data — duration of the account plus 90 days after closure.
- Unsigned / draft documents — 90 days, then permanently deleted.
- Server logs — 30 days.
7. Data sharing
We do not sell your personal data. We share it only with:
- Sub-processors — AWS (infrastructure), NMI and Stripe (payments), OneID (UK identity verification), eID Easy (qualified signatures), Signicat (Nordic eID), Veriff (optional IDV), and Anthropic (optional AI document analysis). Customer-initiated integrations (for example Clio, HubSpot, Salesforce) process data under your instruction.
- Your organisation — when you sign documents, the sending organisation receives signing and audit data.
- Law enforcement — where required by law or valid court order.
- Successors — in a merger or acquisition, subject to the same privacy obligations.
8. Your rights
Under the UK GDPR and EU GDPR you have the right to access, rectification, erasure (subject to legal retention), portability, object to legitimate interests, and withdraw consent. Email privacy@touch2sign.com — we respond within 30 days.
You may lodge a complaint with the Data Protection Commission (Ireland) or the Information Commissioner’s Office (UK).
9. Cookies
This marketing site uses no advertising cookies. If you accept analytics, we load HubSpot tracking (portal 146170566) to measure page views. The product uses strictly necessary session cookies for authentication and security. Where we use optional analytics, we ask for consent.
10. Security
We use TLS in transit, AES-256 at rest, SHA-256 document integrity hashing, access controls, and regular security reviews. If a breach poses a risk to your rights and freedoms, we will notify you and the relevant supervisory authority within 72 hours.
11. SMS and RCS opt-out
If you receive signing invitations by SMS or RCS, reply STOP to opt out. Opt-outs are processed immediately.
12. Artificial intelligence
Touch2Sign offers optional AI features that analyse documents, draft text, summarise content, and answer questions. When those features are used, you are interacting with an AI system (EU AI Act Art. 50 notices appear in the product). Document content processed for these features is not used to train foundation models.
13. Changes
We may update this policy. The date at the top of this page is the latest revision. Material changes will be emailed to registered account holders.
14. Contact
Touch2Sign Ltd
Privacy: privacy@touch2sign.com
Legal / DPA: legal@touch2sign.com
Web: www.touch2sign.com