Privacy Policy
Abundera Sign exists to produce documents whose authenticity can be verified independently, years from now, without trusting us. To do that we have to handle some signer data and document content. This page explains exactly what we collect, why, how long we keep it, and what rights signers have over it.
1. Who's responsible
Abundera, Inc. (Delaware C-corp, 200 W Sahara Ave Unit 3301, Las Vegas NV 89102) operates Abundera Sign and is the data controller for Sender accounts. For Signer interactions Abundera, Inc. acts as the data processor on behalf of the Sender who initiated the envelope.
2. What we process
2.1 Sender account data
If you create a Sender account to send envelopes through Abundera Sign, we process: name, email address, organization (optional), authentication credentials (passkey or password hash), API keys you generate, billing details (handled by our payment processor, see §6), and product usage events (envelopes created, API calls, login times) for security and rate-limit enforcement.
2.2 Signer identity data
When a Sender adds you as a Signer on an envelope, we process: your name and email (required to deliver the signing link and bind the signature to you), an optional phone number if SMS verification is enabled by the Sender, your IP address, your user-agent string, the timestamps of every event in the signing flow, and your handwritten or typed signature image.
Some verification features are optional and only run if the Sender turns them on for your envelope. When that happens, and after the feature prompts you, we also process: your device's GPS coordinates (browser geolocation), an identity photo you capture, audio or video statement recordings, knowledge-based authentication inputs (name, date of birth, US address, and the last four digits of your SSN, checked against credit-bureau records by the KBA providers listed in §6), and the result of government-ID verification (document type, issuing country, and the biometric match result from the provider listed in §6). These artifacts are sealed into the envelope's evidence package and kept for the retention period in §7.
2.3 Document content
The PDF documents Senders upload, and any text, fields, or annotations Signers add, are stored encrypted at rest. We do not read document contents for any purpose other than serving them back to authorized parties, generating the AI document summary if the Sender enables it, and producing the cryptographic evidence package.
2.4 Cryptographic evidence artifacts
For every signed envelope we generate and retain: PAdES Part 4 (LTV) digital signature blocks embedded in the PDF, RFC 3161 trusted timestamps from independent timestamp authorities, a hash-chained audit trail of every signing event, a per-signer Personal Document Seal (TOTP-compatible verification code), and a downloadable Certificate of Completion summarizing the above.
3. AI document summaries
If a Sender enables the plain-English document summary feature, the document text is sent to our AI inference provider (currently Cloudflare Workers AI; subject to the sub-processor commitments in §6) for summarization. The summary is stored alongside the envelope. Document text is not retained by the inference provider beyond the request lifecycle and is never used to train models.
4. Verification analytics
When someone visits a public verification URL (or enters a Personal Document Seal code), we record the verification event in aggregate (count, country-level geography, day) so the original Sender can see verification activity. We do not record IP addresses or per-user identifiers for verification visits unless the visitor is an authenticated Sender or Signer for that envelope.
5. Cookies and tracking
With one disclosed exception (the affiliate referral cookie below), Abundera Sign uses strictly necessary first-party cookies for authentication and CSRF protection. We do not use third-party tracking pixels, advertising cookies, or analytics SDKs that fingerprint visitors. The portal uses local storage to remember UI preferences (theme, language). No data leaves your browser unless you take an action that requires it.
The one exception is the ab_ref affiliate referral cookie. It is set only when you arrive through an Abundera affiliate's referral link (a URL carrying ?ref=), so we can credit that affiliate if you later subscribe. It is scoped to .abundera.ai (SameSite=Lax, Secure), expires 60 days after your last qualifying visit, and its value never leaves the Abundera family. We do not set it when your browser sends the Global Privacy Control signal, when you have opted out on the hub's Do Not Sell or Share page (which sets a cross-property ab_ref_optout cookie), or for visitors in the EEA, UK, or Switzerland absent explicit consent. Alongside the cookie we keep a server-side referral-visit record (a hashed fingerprint of your IP address, user agent, and language headers) for 24 months, as described in the Affiliate Program Terms §10.
6. Sub-processors we use
| Sub-processor | Purpose | Data shared |
|---|---|---|
| Cloudflare | Hosting, edge compute, R2 object storage, D1 database | All Sender + Signer + document data (encrypted at rest) |
| Stripe | Subscription billing | Sender name, email, billing address, last-4 card digits |
| Resend / ZeptoMail | Transactional email (signing links, completion notifications) | Recipient email, envelope ID, signing URL |
| RFC 3161 Timestamp Authority | Independent trusted timestamps for signature LTV | Document hash only (no PII) |
| Cloudflare Workers AI | Plain-English document summaries (when Sender enables) | Document text (request-scoped, no retention, no training) |
| Twilio | SMS one-time passcodes (when the Sender enables SMS verification) | Signer phone number, passcode message |
| Veriff | Government-ID verification (when the Sender enables ID verification) | Signer name, date of birth, government-ID images, selfie and biometric match result |
| LexisNexis | Knowledge-based authentication (when the Sender enables KBA) | Signer name, date of birth, US address, last 4 SSN digits; answers checked against credit-bureau records |
| Persona | Knowledge-based authentication (alternative KBA provider) | Same categories as LexisNexis |
| BlueNotary | Remote online notarization (when the Sender orders notarization) | Signer name, email, ID-verification data, notarization session recording |
The current canonical list lives at abundera.ai/legal/subprocessors with 30-day change notification. Custom Enterprise contracts can specify additional sub-processor restrictions.
7. How long we keep your data
- Sender account data: retained while your account is active; deleted within 30 days of account closure.
- Signed documents and evidence packages: retained after envelope completion for the period the Sender specifies, then purged. The default is 3 years, up to a plan maximum of 3 years on Starter, 7 years on Professional, or 99 years on Business. The Sender is asked to choose a window matching the document's legal life — how long the instrument stays operative plus the applicable limitation period. Long ceilings exist because some instruments (ground leases, trusts, IP assignments) are legally operative for decades; a window should never be longer than the document needs. This supports legal admissibility and dispute resolution. Senders can extend retention via Enterprise contract or download-and-purge at any time before that window.
- Audit trail (hash chain + signing events): retained for the same period as the signed document it accompanies. Cannot be partially deleted without breaking cryptographic verification.
- Verification logs (aggregate): retained for 24 months in aggregated form.
- Backups: rolling 90-day encrypted backups for disaster recovery.
8. Legal basis for processing (GDPR / EEA Signers)
- Contract (Art. 6(1)(b)), processing necessary to deliver the signed envelope you were asked to sign.
- Legitimate interests (Art. 6(1)(f)), keeping the signed document and its audit trail intact for the retention window. Our interest, and the Sender's, is that the evidence of your signature stays available to establish, exercise or defend a legal claim, which is the reason the document was signed in the first place. You can object under Art. 21 on grounds relating to your situation, and we'll weigh that against the Sender's need to rely on the signature.
- Legitimate interests (Art. 6(1)(f)), fraud prevention, rate limiting, security event logging.
- Explicit consent for ID verification (Art. 9(2)(a)): the facial match our ID-verification provider performs (§6) is biometric processing under Art. 9(1), and it runs only after you expressly agree at the start of the verification step. If you decline, no biometric processing happens and the Sender decides whether signing can continue. The result sealed into the evidence package (document type, issuing country, match result — never your images or a biometric template) is retained under Art. 9(2)(f) (establishment, exercise or defence of legal claims), the same footing as the erasure carve-out in §9.
9. Your rights
Whether you're a Sender or a Signer, you can request: access to the personal data we hold about you, correction of inaccurate data, deletion (subject to the document-retention obligations in §7), data export in a machine-readable format, and a complaint to a supervisory authority.
Deletion has one carve-out: while a signed document is inside its retention window, the evidence record is exempt from erasure under GDPR Article 17(3)(e) (establishment, exercise or defence of legal claims). Personal data outside the evidence record is still deleted on request, and the evidence record itself is purged when the retention window ends.
For Signer-side requests we may need to involve the Sender (the data controller for the envelope you signed). Email dpo@abundera.ai with subject line "Data subject request" and we'll respond within 30 days.
10. "Do not sell or share my personal information"
We do not sell personal information. We do not share personal information for cross-context behavioral advertising. California, Virginia, Colorado, Connecticut, and Utah residents may exercise opt-out rights (which on this service are essentially no-ops because we don't sell or share) by emailing dpo@abundera.ai.
11. Children
Abundera Sign is not intended for anyone under 18. We do not knowingly collect personal information from minors. If you believe a Signer was a minor, contact dpo@abundera.ai.
12. International transfers
Cloudflare's global edge network may store and serve data from any of its data center regions. EU Standard Contractual Clauses are in place with our sub-processors. EEA / UK Senders can request a Data Processing Addendum at abundera.ai/legal/dpa.
13. Security
TLS 1.2+ in transit, AES-256 at rest, signed PAdES PDFs verifiable offline without our servers, hash-chained audit trails detect tampering cryptographically, scoped API keys, optional passkey-only authentication for Senders, rate limits on every authenticated and public endpoint, automated dependency vulnerability scanning, and a published security.txt for vulnerability disclosure.
14. Breach notification
Where a personal data breach is likely to result in a risk to the rights and freedoms of natural persons we will notify the relevant supervisory authority within 72 hours of becoming aware, and notify affected individuals without undue delay where the risk is high.
15. Changes to this policy
Material changes are announced via email to all active Senders at least 30 days before they take effect. The "Last reviewed" date at the top of this page reflects the most recent material update.
16. Contact
Privacy questions: dpo@abundera.ai
Security disclosures: security.txt or security@abundera.ai
Legal: legal@abundera.ai
Abundera, Inc. · 200 W Sahara Ave Unit 3301 · Las Vegas NV 89102 · United States