Privacy Policy

Last updated: 4 October 2026

We built SignEdge to record what happened to a document and when, and nothing more. This policy explains what personal data we handle, why, and what you can do about it.

Who we are

SignEdge is provided by AurumCodeWorks. Who we are, our address and contact details: Legal information.

We are the “controller” of your account data. For the content of documents you upload, you are normally the controller and we act as your “processor” under our Data Processing Agreement. Our ICO registration number is ZC265859.

What we collect and why

DataWhyLegal basisHow long
Authenticator app (optional): the shared secret for your authenticator app, stored encrypted, and ten one-time recovery codes, stored only as one-way hashesTo let you log in with an app such as Bitwarden as well as, or instead of, emailed codesContract (securing your account)Until you turn it off or close your account. Finishing an account recovery turns it off.
Do-not-send list (only if you ask): a one-way fingerprint of your email address, added when you decline a request with “I don’t know this sender” and choose to stop anyone sending you documentsTo honour your request not to be sent documents through SignEdgeYour request (and legitimate interests)Kept until you ask us to remove it.
Free-trial record: a one-way fingerprint of your email address (not the address itself), made when you confirm itSo the free trial can only be used once, including after an account is closedLegitimate interests (preventing misuse of the free trial)Kept after your account is deleted, because that is its purpose.
Recovery email (optional): a second address you choose, confirmed with a code. If you ask to recover an account you can't open, we also keep that request (when it was made, when it can be finished, and whether it was cancelled or completed) for a week after it endsTo make password resets safer and to let you back in if you lose access to your emailLegitimate interests (keeping accounts secure)Until you remove it or close your account.
Account: name, email, password (stored only as a salted hash), whether you use two-step verification, plan and trial counters, and your display preferences and defaults for new documentsTo create and run your accountContractWhile your account is open. Deleted when you close it.
Documents you upload, the fields you place, signature images and typed entries, and the names and email addresses of your signersTo provide the signing service for youContract (and your instructions, see “Documents contain other people’s information”)Until you delete the document or your account
Activity trail: who created, sent, opened, reminded and signed, and whenTo show you what happened and keep a record for both sidesContract and legitimate interests (a reliable record)Same as the document
Account activity log: what you did in the app (for example sending or deleting a document, changing settings, inviting a team member) and sign-in events (logins, failed attempts, password and two-step changes), each with the time. Never an IP address, location or the text of a document. A team owner can see the team’s actions. A small number of administrators can see the log to keep the service secure and to investigate problems; looking up a person is itself recorded.To show you what happened on your account, spot misuse and fix problemsLegitimate interests (security and reliability)Actions 12 months, sign-in events 90 days
Service log: what the platform did on its own (scheduled jobs, whether an email could be sent, payment updates received). Holds no document content or email addresses.To run and troubleshoot the serviceLegitimate interests90 days
Contacts: the names and email addresses of people you have sent documents to, saved automatically when you send, so you can pick them again. Private to your account; you can edit, delete any or all of them (Contacts), and they are included when you download your data.To save you retyping signersLegitimate interests (a convenience you can switch off by deleting them)Until you delete them, or 12 months after you last sent to that person
Signed copies: when everyone has signed, SignEdge emails the signed PDF to the sender, to each signer who asked for a copy on the signing page, and to anyone the sender chose to copy in (for example HR or finance), whose name and email the sender typed. The sender is responsible for only copying in people who should have the document.To give each person the finished document without needing an accountContract (signers and sender); legitimate interests (people copied in by the sender)The email is sent once; a file too large to attach (over about 3.5 MB) is sent to each of them as a download link that works for 30 days without logging in. Copy-in addresses are kept with the document until it is deleted
Login sessions, one-time codes, reset links and short-lived security countersTo keep accounts secure and stop abuseLegitimate interestsSessions 30 days, codes 10 minutes, reset links 1 hour, counters about 24 hours
Payment detailsHandled by our payment provider, Polar, the seller of record. We only receive your plan and renewal date.ContractPolar keeps its records as the law requires
Website analytics (only if you accept)To see which pages are usefulConsentSet in our analytics settings, no more than 14 months

What we don’t collect. SignEdge does not record IP addresses or locations in your activity trail or our database, and we don’t use heatmaps, session recordings or advertising trackers. Like any online service, the infrastructure that delivers web traffic handles IP addresses briefly to do its job. We never sell your data. We make no automated decisions about you.

Password safety. When you choose a password we check it against a public list of passwords that have appeared in data breaches (the “Have I Been Pwned” range service). Only the first five characters of a one-way hash of the password are sent, never the password itself and never your email address, so the service can’t tell who you are or what you typed. If a password is on the list we ask you to pick another. Passwords are stored only as salted, peppered, slow hashes.

Documents contain other people’s information

If you upload a document that includes other people’s personal details, especially health, ethnicity, religion, trade union, criminal or financial information, you are responsible for having a good reason to share it and for telling those people. We process that content only on your instructions, to provide the service. Please don’t upload documents you don’t need to.

If you were asked to sign a document

Someone used SignEdge to send you a document. We hold your name, email address, signature, the times you opened and signed it, and a copy of the document, on behalf of the person who sent it. We do this so you can sign and so both of you have a record. The sender decides how long to keep the document, and you can ask them to delete it or give you a copy. For our own records or questions, email hello@signedge.co.uk. You don’t need an account and we won’t send you marketing.

Who we share it with

  • Polar (payments and VAT). Polar is the seller of record for paid plans and is responsible for the payment data it collects.
  • Our hosting, storage and email delivery providers, who process data for us under contract to run the service.
  • Google Analytics, only if you accept analytics cookies.
  • Cloudflare Turnstile, on the sign-up, password reset and account recovery forms only, to tell people from automated scripts. It is usually invisible and we don’t store anything it learns about you.
  • Anyone you choose to send a document to, and the other members of your team if you share a team library.
  • Authorities, if the law requires it.

Transfers outside the UK

Some of these providers, including Polar and Google, are based in or process data in the United States and elsewhere. We only use providers where the UK recognises the country as adequate or where approved safeguards are in place, such as the ICO’s International Data Transfer Agreement or Addendum.

How long we keep it

  • Documents and their activity trails: until you delete them or close your account, or sooner if you choose. In Account you can have finished documents (completed, cancelled, declined or expired) deleted automatically after 30 days, 90 days or a year. Drafts and templates aren’t affected by that setting.
  • Drafts you never send: deleted after 90 days.
  • Contacts (people you have sent documents to): until you delete them, or 12 months after you last sent to that person.
  • Activity and service logs: sign-in events and service entries 90 days, your recorded actions 12 months. When you close your account, entries about you stay without your name or any link to you.
  • Accounts that never confirm their email: deleted after 14 days.
  • Free accounts you stop using (no paid plan, no login for 12 months): deleted with their documents.
  • When you delete your account we erase your account, documents and signed copies straight away. Our platform backups roll off within 30 days. Polar keeps its payment records as the law requires. Emails already delivered and copies other people have downloaded are outside our control, and your name remains on the activity trail of documents owned by other people if you signed or acted on them.

Your rights

You can ask us to give you a copy of your data, correct it, delete it, restrict or stop using it, or move it to another service. Where we rely on your consent you can withdraw it at any time. You can download your data and delete your account yourself from your Account page. For anything else, email hello@signedge.co.uk. We reply within one month and may ask you to prove who you are.

Complaints

If you’re unhappy with how we’ve handled your data, email hello@signedge.co.uk with “Privacy complaint” in the subject. We’ll acknowledge it within 30 days and tell you what we’ve done. You can also complain to the Information Commissioner’s Office at ico.org.uk/make-a-complaint or on 0303 123 1113.

Security

Everything is encrypted in transit. Passwords are salted and hashed, login and reset tokens are stored only as hashes, signing links are long random codes, you can turn on two-step verification by email, and you can add a recovery email so that a password reset needs a code from both addresses. If you lose access to your email, a recovery request is sent to the recovery address, the account's own address is told and can cancel it, and it can only be finished after a 72-hour wait. Access to production data is limited to the person who runs SignEdge. If a breach puts people at risk we will tell the ICO and anyone affected as the law requires.

Children

SignEdge is for people aged 18 and over and isn’t directed at children.

Changes to this policy

If we change this policy in a way that matters, we’ll email account holders at least 30 days before it applies and update the date at the top.