In short
- We never sell personal data for money, and we never use documents for advertising or AI training.
- Analytics and advertising tags run only after you accept them, and you can change your mind at any time.
- For documents and signers, the customer who sends the document decides, and we process the data for them.
- You can access, correct, delete, or export your data, and complain to your data protection authority.
Who we are
inSigner is operated by Nubesti LLC, a limited liability company formed in Delaware, United States, with its address at 1111B S Governors Ave STE 23840, Dover, Delaware 19904, United States. For the processing described as ours in this policy, Nubesti is the controller.
Privacy questions and requests go to [email protected] with the subject “Privacy”. That address also reaches the person responsible for data protection at Nubesti, including the encarregado for Brazil, the privacy officer for Quebec, and the grievance officer for India. Where the law requires us to appoint a representative in the European Union or the United Kingdom, the representative’s details will be shown in this section.
Scope and roles
This policy covers insigner.co, the workspace at app.insigner.co, signing pages at sign.insigner.co, the API, the add-ons, our emails, our advertising, support, and the iOS and Android apps once they are released.
Nubesti is the controller for website visitors, account holders, billing, security, support, and marketing. For documents and for the personal data of people invited to sign, the customer who sends the document is the controller, and Nubesti is a processor or service provider that acts on the customer’s instructions under the data processing agreement. If you signed a document, the sender is usually the right first contact for questions about that document.
Personal data we collect
Depending on how you use inSigner, we collect the following personal data:
| Category | Examples | Source |
|---|---|---|
| Account and contact | Name, email address, organization, role, language, and sign-in details | You |
| Billing | Plan, PayPal subscription status and identifier, invoice details, country, and tax identification number | You and PayPal |
| Documents | Files, fields, templates, and the names, email addresses, and phone numbers of signers | The customer |
| Signature evidence | Signature image, consent to sign, timestamps, IP address, device and browser details, and document hashes | The signer and their device |
| Messaging add-ons | Phone number, message status, and the result of a one-time code check | The customer, the signer, Meta, and carriers |
| Identity verification | Identity document images and data, selfie, facial template, liveness result, and registry check results | The signer and Didit |
| Website usage and advertising, with consent | Cookie identifiers, pages viewed, clicks, ad click identifiers, approximate location derived from the IP address, and device type | Your browser, Google, Microsoft, Meta, and TikTok |
| Support and communications | Messages, attachments, and the history of your requests | You |
| Security | IP address, request logs, bot challenge signals, and error reports | Your device and Cloudflare |
We do not ask for sensitive data such as health, religion, or political opinions. Identity documents and biometric data are processed only when a customer turns on KYC for a document, as described on the identity verification page.
Why we use it and our legal bases
When the GDPR, the UK GDPR, the LGPD, or a similar law applies, we rely on these legal bases:
| Purpose | Legal basis |
|---|---|
| Create and run your account and workspace, and provide the service you ordered | Performance of a contract |
| Deliver signing invitations, collect signatures, and keep the evidence record for the customer | Processing for the customer, under the data processing agreement |
| Take payment, issue invoices, and keep accounting and tax records | Contract and legal obligation |
| Protect the service, prevent fraud and abuse, and keep security logs | Legitimate interests in a safe and reliable service |
| Answer support requests and send service messages | Contract and legitimate interests |
| Measure how the website is used with Google Analytics and Microsoft Clarity | Consent |
| Show and measure ads with Google Ads, Microsoft Advertising, Meta, and TikTok | Consent |
| Send product news and offers | Consent, or legitimate interests for existing customers where the law allows it, with an opt-out in every email |
| Comply with the law, answer lawful requests, and defend legal claims | Legal obligation and legitimate interests |
Where we rely on legitimate interests, we have balanced them against your rights, and you can object at any time. Where we rely on consent, you can withdraw it at any time without affecting processing that happened before.
Cookies, analytics, and advertising
We use Google Tag Manager, Google Analytics, Google Ads, Microsoft Advertising, Microsoft Clarity, the Meta Pixel, and the TikTok Pixel on our marketing website only after you accept them in the cookie banner. Before you choose, only strictly necessary storage is used, and Google Consent Mode is set to deny all advertising and analytics storage. We do not run analytics or advertising tags on signing pages or inside documents.
When you accept advertising cookies, we may also send a hashed version of the email address you gave us to Google, Meta, TikTok, or Microsoft to measure sign-ups that came from an ad. The cookie policy lists every cookie, its provider, and how long it lasts.
Identity verification and automated decisions
The KYC add-on uses Didit to compare a selfie with an identity document, check liveness, and, in 36 countries, check data against official or authorized registries. These checks are automated. The result is given to the customer who requested it, who decides what to do. Nubesti does not make decisions that produce legal effects about you based only on automated processing. If a verification affects you, you can ask the sender, or us, for a human review, to express your point of view, and to contest the result.
International transfers
Nubesti is based in the United States, and our providers operate in several countries, including through Cloudflare’s global network. When we transfer personal data from the European Economic Area, the United Kingdom, or Switzerland to a country without an adequacy decision, we use the EU-U.S. Data Privacy Framework and its UK and Swiss extensions where the recipient is certified, or the European Commission’s Standard Contractual Clauses of 2021, with the UK International Data Transfer Addendum and the Swiss amendments where needed.
For transfers from other countries, such as Brazil, Argentina, Colombia, Mexico, South Africa, or India, we use the contractual clauses, consent, or other mechanisms that the local law recognizes. We assess the laws of the destination country and add safeguards such as encryption where they are needed. You can ask for a copy of the relevant safeguards at [email protected].
How long we keep data
We keep personal data only as long as the purpose requires, and then delete or anonymize it:
| Data | Retention |
|---|---|
| Account data | While the account is open, plus 30 days to export after closure |
| Documents and signature evidence | As the customer decides while the workspace is open. After closure, deleted once the 30-day export period ends |
| Backups | Overwritten on a rolling cycle, within 90 days |
| Billing, invoices, and tax records | As long as tax and accounting laws require, usually 5 to 10 years |
| Security logs | Up to 12 months, unless needed to investigate an incident |
| Website analytics | Up to 14 months |
| Advertising cookies | As listed in the cookie policy, never longer than 13 months |
| Support messages | Up to 3 years after the last contact |
| Marketing contacts | Until you unsubscribe, or after 2 years without interaction |
| Identity verification | As described on the identity verification page |
We may keep data for longer when it is needed to comply with a legal obligation, to preserve evidence for a dispute, or under a legal hold.
How we protect data
We use encryption in transit, encryption at rest by our storage providers, access limited to people who need it, and monitoring of the systems that store data. No system is perfectly secure. The security overview describes our measures and how we notify customers and authorities of a personal data breach.
Your rights
Depending on where you live, you have some or all of these rights:
- Know what personal data we hold about you and receive a copy.
- Correct inaccurate or incomplete data.
- Delete your data, subject to legal exceptions.
- Receive your data in a portable format, or have it sent to another provider.
- Object to processing based on legitimate interests, and to direct marketing at any time.
- Restrict processing while a request is being reviewed.
- Withdraw consent at any time, including for cookies.
- Opt out of the sale or sharing of personal data and of targeted advertising.
- Not be subject to a decision based only on automated processing that significantly affects you.
- Not be discriminated against for using your rights.
- Complain to a data protection authority.
To use a right, write to [email protected] with the subject “Privacy request”, or follow the privacy choices page. We answer within one month, or sooner if your local law requires it, and we may ask for information to confirm your identity. The regional privacy rights page explains the rules for each region and country.
Marketing messages
Every marketing email includes a link to unsubscribe. Service messages about your account, security, billing, or a document you sent or need to sign are not marketing, and we will keep sending them while they are needed.
Children
inSigner is a professional service for adults. We do not knowingly collect personal data from children under 16, or under 13 in the United States, and we do not sell or share the data of anyone under 16. If you believe a child has given us personal data, write to [email protected] and we will delete it.
Changes to this policy
We publish changes on this page with a new date. If a change materially affects how we use personal data, we will tell account holders by email, and we will ask for consent again where the law requires it.