Data protection

Privacy policy

This policy explains who processes your data, for which purposes, where it is stored and how to exercise your rights.

Controller and GDPR roles

FORGE LABS, 9 rue Jean-Jacques Rousseau, 21000 Dijon, France, is the controller for account, service security, billing, support and its own marketing processing.

For documents, contacts and signature workflows uploaded by a customer, that customer generally determines the purpose and acts as controller; Forge Labs then processes the data as processor under its instructions.

Data processed

  • identity, email address, organisation and role;
  • documents, signer names and contact details;
  • consents, OTP events, timestamps, IP address and technical context;
  • subscription, invoices and Stripe identifiers — SignEuropa does not store full card numbers;
  • support messages and cookie preferences;
  • with your consent, viewed pages and aggregated conversion steps, without form content.

Purposes and legal bases

Data is used to provide the service and contract, authenticate users and signers, build evidence, bill, prevent abuse, provide support and comply with legal obligations. Depending on the context, the legal basis is contract, legal obligation, legitimate interests in securing and improving the service, or consent for optional uses.

Location and recipients

The production database, PDFs and evidence packages are stored in France on Scaleway infrastructure managed by Forge Labs. Supporting technical services, including email delivery, may run on other servers located in the European Union.

Data is accessible to authorised Forge Labs staff, authorised members of the customer workspace, relevant signers and strictly necessary processors. Payments are handled by Stripe, which may perform certain international processing under the safeguards described in its own documentation.

Optional audience measurement is performed by a self-hosted Umami instance operated by Forge Labs. It receives no identity, email address, form content or document content.

Retention periods

The standard policy assigns an end date to each evidence package: up to 10 years after sealing, to support the establishment, exercise or defence of legal claims and integrity verification. Customers must select a period appropriate to their documents and obligations. An erasure request may be limited where retention remains necessary for legal claims.

Account data is retained during the service relationship and then as needed for closure and claims; accounting records are retained for 10 years; contact requests are retained for no more than 3 years after the last exchange unless a legal duty or dispute requires otherwise.

Security and minimisation

SignEuropa applies logical organisation separation, access controls, unique signing links, email OTP, attempt limits, short sessions, SHA-256 fingerprints and a chained evidence log. Public verification returns neither identities nor document content.

Your rights

You may request access, rectification, erasure, restriction, portability or object to certain processing. Email contact@signeuropa.eu and identify the relevant workspace. Proof of identity may be requested where there is reasonable doubt. You may also lodge a complaint with the CNIL.

CNIL