Privacy Policy

1. Who's responsible

Abundera, Inc. (Delaware C-corp, 200 W Sahara Ave Unit 3301, Las Vegas NV 89102) operates Abundera Sign and is the data controller for Sender accounts. For Signer interactions Abundera, Inc. acts as the data processor on behalf of the Sender who initiated the envelope.

2. What we process

2.1 Sender account data

If you create a Sender account to send envelopes through Abundera Sign, we process: name, email address, organization (optional), authentication credentials (passkey or password hash), API keys you generate, billing details (handled by our payment processor, see §6), and product usage events (envelopes created, API calls, login times) for security and rate-limit enforcement.

2.2 Signer identity data

When a Sender adds you as a Signer on an envelope, we process: your name and email (required to deliver the signing link and bind the signature to you), an optional phone number if SMS verification is enabled by the Sender, your IP address, your user-agent string, the timestamps of every event in the signing flow, and your handwritten or typed signature image.

Some verification features are optional and only run if the Sender turns them on for your envelope. When that happens, and after the feature prompts you, we also process: your device's GPS coordinates (browser geolocation), an identity photo you capture, audio or video statement recordings, knowledge-based authentication inputs (name, date of birth, US address, and the last four digits of your SSN, checked against credit-bureau records by the KBA providers listed in §6), and the result of government-ID verification (document type, issuing country, and the biometric match result from the provider listed in §6). These artifacts are sealed into the envelope's evidence package and kept for the retention period in §7.

2.3 Document content

The PDF documents Senders upload, and any text, fields, or annotations Signers add, are stored encrypted at rest. We do not read document contents for any purpose other than serving them back to authorized parties, generating the AI document summary if the Sender enables it, and producing the cryptographic evidence package.

2.4 Cryptographic evidence artifacts

For every signed envelope we generate and retain: PAdES Part 4 (LTV) digital signature blocks embedded in the PDF, RFC 3161 trusted timestamps from independent timestamp authorities, a hash-chained audit trail of every signing event, a per-signer Personal Document Seal (TOTP-compatible verification code), and a downloadable Certificate of Completion summarizing the above.

3. AI document summaries

If a Sender enables the plain-English document summary feature, the document text is sent to our AI inference provider (currently Cloudflare Workers AI; subject to the sub-processor commitments in §6) for summarization. The summary is stored alongside the envelope. Document text is not retained by the inference provider beyond the request lifecycle and is never used to train models.

4. Verification analytics

When someone visits a public verification URL (or enters a Personal Document Seal code), we record the verification event in aggregate (count, country-level geography, day) so the original Sender can see verification activity. We do not record IP addresses or per-user identifiers for verification visits unless the visitor is an authenticated Sender or Signer for that envelope.

5. Cookies and tracking

With one disclosed exception (the affiliate referral cookie below), Abundera Sign uses strictly necessary first-party cookies for authentication and CSRF protection. We do not use third-party tracking pixels, advertising cookies, or analytics SDKs that fingerprint visitors. The portal uses local storage to remember UI preferences (theme, language). No data leaves your browser unless you take an action that requires it.

The one exception is the ab_ref affiliate referral cookie. It is set only when you arrive through an Abundera affiliate's referral link (a URL carrying ?ref=), so we can credit that affiliate if you later subscribe. It is scoped to .abundera.ai (SameSite=Lax, Secure), expires 60 days after your last qualifying visit, and its value never leaves the Abundera family. We do not set it when your browser sends the Global Privacy Control signal, when you have opted out on the hub's Do Not Sell or Share page (which sets a cross-property ab_ref_optout cookie), or for visitors in the EEA, UK, or Switzerland absent explicit consent. Alongside the cookie we keep a server-side referral-visit record (a hashed fingerprint of your IP address, user agent, and language headers) for 24 months, as described in the Affiliate Program Terms §10.

6. Sub-processors we use

Sub-processorPurposeData shared
CloudflareHosting, edge compute, R2 object storage, D1 databaseAll Sender + Signer + document data (encrypted at rest)
StripeSubscription billingSender name, email, billing address, last-4 card digits
Resend / ZeptoMailTransactional email (signing links, completion notifications)Recipient email, envelope ID, signing URL
RFC 3161 Timestamp AuthorityIndependent trusted timestamps for signature LTVDocument hash only (no PII)
Cloudflare Workers AIPlain-English document summaries (when Sender enables)Document text (request-scoped, no retention, no training)
TwilioSMS one-time passcodes (when the Sender enables SMS verification)Signer phone number, passcode message
VeriffGovernment-ID verification (when the Sender enables ID verification)Signer name, date of birth, government-ID images, selfie and biometric match result
LexisNexisKnowledge-based authentication (when the Sender enables KBA)Signer name, date of birth, US address, last 4 SSN digits; answers checked against credit-bureau records
PersonaKnowledge-based authentication (alternative KBA provider)Same categories as LexisNexis
BlueNotaryRemote online notarization (when the Sender orders notarization)Signer name, email, ID-verification data, notarization session recording

The current canonical list lives at abundera.ai/legal/subprocessors with 30-day change notification. Custom Enterprise contracts can specify additional sub-processor restrictions.

7. How long we keep your data

8. Legal basis for processing (GDPR / EEA Signers)

9. Your rights

Whether you're a Sender or a Signer, you can request: access to the personal data we hold about you, correction of inaccurate data, deletion (subject to the document-retention obligations in §7), data export in a machine-readable format, and a complaint to a supervisory authority.

Deletion has one carve-out: while a signed document is inside its retention window, the evidence record is exempt from erasure under GDPR Article 17(3)(e) (establishment, exercise or defence of legal claims). Personal data outside the evidence record is still deleted on request, and the evidence record itself is purged when the retention window ends.

For Signer-side requests we may need to involve the Sender (the data controller for the envelope you signed). Email dpo@abundera.ai with subject line "Data subject request" and we'll respond within 30 days.

10. "Do not sell or share my personal information"

We do not sell personal information. We do not share personal information for cross-context behavioral advertising. California, Virginia, Colorado, Connecticut, and Utah residents may exercise opt-out rights (which on this service are essentially no-ops because we don't sell or share) by emailing dpo@abundera.ai.

11. Children

Abundera Sign is not intended for anyone under 18. We do not knowingly collect personal information from minors. If you believe a Signer was a minor, contact dpo@abundera.ai.

12. International transfers

Cloudflare's global edge network may store and serve data from any of its data center regions. EU Standard Contractual Clauses are in place with our sub-processors. EEA / UK Senders can request a Data Processing Addendum at abundera.ai/legal/dpa.

13. Security

TLS 1.2+ in transit, AES-256 at rest, signed PAdES PDFs verifiable offline without our servers, hash-chained audit trails detect tampering cryptographically, scoped API keys, optional passkey-only authentication for Senders, rate limits on every authenticated and public endpoint, automated dependency vulnerability scanning, and a published security.txt for vulnerability disclosure.

14. Breach notification

Where a personal data breach is likely to result in a risk to the rights and freedoms of natural persons we will notify the relevant supervisory authority within 72 hours of becoming aware, and notify affected individuals without undue delay where the risk is high.

15. Changes to this policy

Material changes are announced via email to all active Senders at least 30 days before they take effect. The "Last reviewed" date at the top of this page reflects the most recent material update.

16. Contact

Privacy questions: dpo@abundera.ai
Security disclosures: security.txt or security@abundera.ai
Legal: legal@abundera.ai
Abundera, Inc. · 200 W Sahara Ave Unit 3301 · Las Vegas NV 89102 · United States