Legal
Privacy Notice
Applies to the CecurSign service at cecursign.io, including its public signing, proposal acceptance and document verification pages.
Version 1.1Last updated 21 August 2026
The service previously ran at sign.cecur.io. That address permanently redirects to cecursign.io, and signing links and verification references issued under the old address continue to work.
Contents
- 1. Who we are
- 2. Who this notice covers
- 3. Controller or processor: our two roles
- 4. What personal data we process
- 5. Purposes and lawful bases
- 6. Evidence records are deliberately permanent
- 7. Retention
- 8. Recipients and sub-processors
- 9. International transfers
- 10. Security
- 11. Your rights
- 12. Automated decision-making
- 13. Children
- 14. Changes to this notice
1. Who we are
CecurSign is operated by Cecur Limited, a company registered in Ireland with the Companies Registration Office under registration number 815071.
To reach us about anything in this notice, including to exercise a right, use our contact form.
We have not appointed a Data Protection Officer. We have assessed Article 37 GDPR and do not consider a DPO mandatory: our core activities do not involve regular and systematic monitoring of data subjects on a large scale, and we do not process special category data on a large scale. We have instead designated the privacy contact above.
2. Who this notice covers
CecurSign is used by three kinds of people, and what we do with your data depends on which you are:
- Account holders: people at a business customer (a firm) who log in to send documents and proposals for signature.
- Signers and recipients: people invited by an account holder to view, sign, approve or decline a document or proposal. You do not need an account, and you may never have dealt with us before receiving a signing invitation. This notice serves as the information we owe you under Article 14 GDPR, and it is linked from signing invitation emails and signing pages.
- Visitors: people browsing the public pages of cecursign.io, including the public document verification page.
3. Controller or processor: our two roles
For what happens inside an envelope, the firm that sent it is the data controller and Cecur Limited is a data processor acting on its instructions. That includes the documents themselves, the identity of the people invited to sign, the field values they enter, their signatures, and the evidence records (audit trail, IP addresses, browser details and timestamps) that the service generates about the signing. The firm decides what documents to send, to whom, and why. If you are a signer and want to know why you were asked to sign something, ask the firm that sent it. Our data processing agreement with business customers governs that processing.
Cecur Limited is itself the data controller for a defined, narrower set of purposes:
- account holder registration, authentication and team management data;
- the security, integrity and abuse prevention of the platform itself, including use of evidence records to detect and investigate misuse of the service;
- billing and subscription data (handled through our Cecur Home portal at cecur.io, which has its own privacy notice);
- support requests;
- processing needed to establish, exercise or defend Cecur's own legal claims, or to comply with a legal obligation binding on Cecur.
In plain terms: the evidence records exist for the sending firm, and we hold them as its processor; we use them for our own purposes only to the limited extent needed to keep the platform trustworthy and to defend ourselves.
4. What personal data we process
All of the following is drawn from what the system actually records.
Account holders
- Name, email address, role and department membership.
- Authentication data: your identity is managed by Auth0 (see section 8); where a legacy password exists on our side it is stored only as an Argon2id hash. API keys are stored only as digests.
- Session data (see the Cookie Notice).
- Saved signatures you create in your signature library (drawn image or typed text).
- Activity connected to envelopes you send: send, void, resend and download events, with timestamps.
- Support tickets you raise, including their contents and the app version they were raised from.
Signers and recipients
- Name and email address, as entered by the sender.
- Mobile phone number, only if the sender chose SMS verification for you. SMS verification is currently disabled platform-wide.
- The contents of the documents you are asked to sign, which are chosen by the sender and may themselves contain personal data about you or others.
- Your signature: a drawn signature image or typed signature text, stored with the completed document and in the evidence records.
- Field values you enter while signing (text, dates, checkboxes and similar).
- Technical evidence recorded with each action: IP address, browser user agent string, and the date and time of each event (viewing, consenting, signing, declining).
- Your consent to sign electronically, recorded as an event in the audit trail.
- Access code attempts, where the sender protected the document with an access code. Attempts are recorded, and five wrong attempts lock the document for fifteen minutes.
Contacts
Account holders can keep a contact book of names and email addresses of people they send documents to. The account holder's firm is the controller of that address book; we store it on the firm's behalf.
Visitors to the public verification page
Anyone holding a completed document's verification reference can view, without an account: whether the audit chain is intact, the names of the signers, the timestamps of their signatures, and the number of recorded events. If you have signed a document through CecurSign, this information about your signature is visible to whoever holds that reference. Ordinary web server logs also apply to public pages.
5. Purposes and lawful bases
Where Cecur Limited is the controller, we rely on the following lawful bases:
| Purpose | Data | Lawful basis (Article 6 GDPR) |
|---|---|---|
| Creating and administering accounts, authentication, team management | Account holder identity and authentication data | Contract (Article 6(1)(b)) |
| Operating the signing service a firm has instructed us to run | Envelope content, signer data, evidence records | We act as processor; the sending firm's own lawful basis applies |
| Security, abuse prevention and rate limiting, including using evidence records to detect misuse of the platform | IP addresses, request metadata, audit events | Legitimate interests (Article 6(1)(f)) in protecting the platform and the integrity of the signatures it produces. Signers are told at the point of signing that their actions are recorded |
| Sending transactional email (signing invitations, reminders, completion notices, account email) | Names, email addresses | Contract, and legitimate interests in delivering the service the sender instructed |
| SMS signer verification, where enabled | Mobile number | Legitimate interests in verifying the signer the sender designated. Currently disabled |
| Billing and subscription management (via Cecur Home) | Billing contact and payment data | Contract; legal obligation for tax and accounting records |
| Support | Ticket contents | Contract |
| Establishing, exercising or defending legal claims | Evidence records | Legitimate interests |
| Compliance with the law | As required | Legal obligation (Article 6(1)(c)) |
We do not sell personal data, we do not use it for advertising, and documents are not sent to any AI service.
6. Evidence records are deliberately permanent
CecurSign's core function is producing evidence that a document was signed, by whom, and when. Audit records are protected by a cryptographic hash chain and, at the database level, cannot be updated by anyone, including us. Deleting an individual record is refused except for draft envelopes that were never sent, because removing one entry would break the evidential integrity of the whole chain.
What this means for erasure requests:
- For evidence about a document a firm sent you, the firm is the controller. We will pass your request to it, and it decides, with our assistance.
- Where the records evidence a concluded agreement, retention is permitted despite an erasure request to the extent the records are necessary for the establishment, exercise or defence of legal claims (Article 17(3)(e) GDPR), or to comply with a legal obligation (Article 17(3)(b)). The whole purpose of a signing evidence record is to prove, years later, that an agreement was made; erasing it on request would defeat the interests of every party to the document, including yours.
- Where erasure is refused on that ground, you can instead ask for restriction of processing (Article 18 GDPR): the record is kept but used only for the evidential purpose, not for anything else. In practice that is already how these records are used.
- Deletion of a firm's entire account, including its envelopes and audit chains, is possible and is carried out as a deliberate, staff-executed operation.
7. Retention
We do not currently operate an automated retention or deletion schedule. In plain terms, the position today is:
- Envelope data, documents, signatures and audit records are retained for as long as the customer's account exists, unless the customer deletes them where the product allows it.
- Draft envelopes can be deleted by the customer; sent and completed envelopes and their audit trails cannot be deleted through the product.
- Removal of a tenant (a firm's whole account) is a deliberate, staff-executed operation, not an automatic one.
8. Recipients and sub-processors
CecurSign runs on infrastructure operated by Cecur Limited and on the third party services below. Internal Cecur platform services (Cecur Home for identity and billing, the Cecur notification service for message dispatch, and DocVault for document storage) are operated by Cecur Limited itself and are not third parties. The maintained list, including notice arrangements for changes, is our sub-processor list.
| Service | Provider | What they process | Location and transfer |
|---|---|---|---|
| Identity and login | Auth0 (Okta, Inc.) | Account holder email, name, authentication events, login credentials | |
| Email delivery | Resend (Resend, Inc., USA) | Recipient email addresses; email content including document names and signing links | United States |
| Document viewer delivery | Cloudflare, Inc. (USA) | Signer's IP address, browser user agent and referring page. No document content is sent | United States |
| SMS delivery | Twilio | Mobile numbers, message content | Not currently enabled; becomes a sub-processor only if SMS verification is switched on |
| Managed database hosting | OVHcloud | All service data held in the CecurSign database | European Union |
| Application and file hosting | Our hosting provider | All service data, including document files | European Union |
| Trusted timestamping | Sigstore, DigiCert and GitHub timestamp authorities | A cryptographic hash only. No personal data, document content or names are sent to these services | Various |
| Payments | Stripe | CecurSign does not process payments itself; billing runs through the Cecur Home portal, whose privacy notice covers Stripe | See the Cecur Home privacy notice |
We have not yet named the company that hosts our application servers and document storage. Its location is stated above, and the name will be added here, to our sub-processor list and to Annex 1 of the Data Processing Agreement once it is confirmed. Every other provider above is named.
We do not use analytics or advertising services on cecursign.io.
9. International transfers
Our own application servers and databases are located in the European Union. That is a statement about where we host. It is not a guarantee that every piece of personal data stays within the EEA, and this notice does not make that wider claim, because some of the third party services in section 8 operate outside it.
- Email delivery (Resend) involves a transfer to the United States. Every signing invitation, reminder and completion notice passes through it, so this applies to ordinary use of the service rather than to an edge case.
- Identity and login (Auth0): the region of our production identity tenant has not been confirmed, so we make no statement about where it holds authentication data.
10. Security
We describe our security honestly. What is in place: TLS encryption for data in transit, including the database connection; passwords hashed with Argon2id; API credentials generated with high entropy and stored only as digests, and signing links generated with 256-bit entropy; strict tenant isolation, with every query scoped to the customer's organisation; an append-only, hash-chained audit trail; and document fingerprints checked when source files are read.
We do not currently hold ISO 27001, SOC 2 or comparable certifications, we do not offer a contractual uptime commitment, and we make no claim in this notice about encryption of data at rest.
11. Your rights
You have the right of access to your personal data, and the rights to rectification, to erasure, to restriction of processing, to data portability, to object to processing based on legitimate interests, and to withdraw consent where processing is based on consent. Section 6 explains the limits that apply to erasure of signing evidence.
Where we act as processor for the firm that sent you a document, we will pass your request to that firm, and you can also contact the firm directly.
To exercise a right, use our contact form.
You also have the right to lodge a complaint with a supervisory authority: in Ireland, the Data Protection Commission (dataprotection.ie); if you are in the United Kingdom, the Information Commissioner's Office (ico.org.uk); or the authority where you live or work.
12. Automated decision-making
We do not carry out automated decision-making, including profiling, that produces legal or similarly significant effects (Article 22 GDPR). Signing a document through CecurSign is a decision made by people; the platform records it.
13. Children
The service is a business tool and is not directed at children.
14. Changes to this notice
We will publish changes to this notice on this page with a new version date, and will notify account holders of material changes.
The rest of our legal documents
- Terms of ServiceThe terms that govern business use of CecurSign, including what the signatures are, what we warrant, and what we do not.
- Data Processing AgreementThe Article 28 processing terms between Cecur Limited and customers of CecurSign, with the sub-processor list and the security measures actually in place.
- Sub-processor ListThe maintained list of third parties that process personal data on behalf of CecurSign customers, and how we notify changes to it.
- Cookie NoticeEvery cookie CecurSign sets is strictly necessary to sign in and stay signed in. There is no analytics, advertising or tracking cookie anywhere on the site.