Bring fellow founders on board. Earn 5 free e-signing sends for every successful signup (up to 3×)Bring fellow founders on board. Earn 5 free e-signing sends for every successful signup (up to 3×)Bring fellow founders on board. Earn 5 free e-signing sends for every successful signup (up to 3×)Bring fellow founders on board. Earn 5 free e-signing sends for every successful signup (up to 3×)Bring fellow founders on board. Earn 5 free e-signing sends for every successful signup (up to 3×)Bring fellow founders on board. Earn 5 free e-signing sends for every successful signup (up to 3×)

Privacy Policy

This policy describes which personal data is processed when using E-Signing.io, for what purposes, and what rights you have.

Last updated: February 2026

This is a convenience translation. The German version is legally binding. See the German original.

1. Data controller

EINSZWEIDREI SOLUTIONS UG (haftungsbeschränkt)
Hochstraße 2
56242 Ellenhausen
Deutschland

Represented by Tristan Craemer. Privacy inquiries: datenschutz@e-signing.io. A data protection officer has not been appointed as the statutory thresholds are not met.

2. Two roles: controller and processor

For our customers' own data (account, billing, support) we act as controller. For content you upload to E-Signing.io. Documents, recipient data, attachments, we act exclusively as a processor under Art. 28 GDPR and only on your instructions. Details are set out in our Data Processing Agreement.

3. Data processed, purposes and legal bases

Account and workspace data
  • Name
  • Email address
  • Password hash
  • Role in the workspace
  • Company details
Purpose:
Providing the user account, access control and billing
Legal basis:
Art. 6(1)(b) GDPR (performance of a contract)
Retention:
Until the account is deleted, then removed without undue delay
Documents and templates
  • Content
  • Images and logos
  • Field definitions
  • Payment plans
Purpose:
Creating, sending and signing the documents you upload
Legal basis:
Art. 6(1)(b) GDPR, processed on your behalf under Art. 28 GDPR
Retention:
Until you delete them or the contract ends
Recipient and contact data
  • Name
  • Email address
  • Mobile number
  • Group assignment
Purpose:
Delivering signature links by email and SMS
Legal basis:
Art. 6(1)(b) GDPR, processed on your behalf under Art. 28 GDPR
Retention:
Until you delete them or the contract ends
Signature and evidence data
  • Timestamps of link access, opening and signing
  • IP address of the signing person at the time of signature (stored in clear text in the evidence record, additionally hashed in access logs)
  • User agent
  • Confirmation of the one-time code (masked destination)
  • SHA-256 checksum and timestamp of the final PDF
Purpose:
Evidence of the signature (audit trail) and proof of integrity
Legal basis:
Art. 6(1)(b) and (f) GDPR (provability of the signature)
Retention:
For as long as the signed document is retained; evidence is never altered afterwards
Attachments from signers
  • Uploaded files up to 25 MB
  • File name, size, upload timestamp
Purpose:
Attaching requested evidence to the signed document
Legal basis:
Art. 6(1)(b) GDPR, processed on your behalf under Art. 28 GDPR
Retention:
Until the related transaction is deleted
Usage and log data
  • Short link opens
  • Delivery status of email and SMS
  • Error logs
Purpose:
Operation, security, abuse detection and status display in the dashboard
Legal basis:
Art. 6(1)(f) GDPR (legitimate interest in secure operation)
Retention:
As a rule until the related transaction is deleted

4. Visiting the website and short links

When you visit our pages, we process technically necessary connection data such as IP address, timestamp and user agent to ensure delivery and detect misuse (legitimate interest). When a signature short link is opened, we additionally log the timestamp and a hashed form of the IP address so the sender can track delivery and read status. No advertising-network tracking takes place without your consent (see Section 5).

5. Cookies, consent and analytics

Technically necessary storage mechanisms (in particular to keep you signed in and to store your cookie decision) are used on the basis of § 25(2) no. 2 TDDDG and Art. 6(1)(f) GDPR. They are required for operation and cannot be switched off.

Any service beyond that, in the statistics, marketing and convenience categories, only loads after your explicit consent in the cookie banner (§ 25(1) TDDDG, Art. 6(1)(a) GDPR). Without consent no such script is loaded and no cookie is set; for Google services, Google Consent Mode v2 is additionally pre-set to "denied". You can change or withdraw your decision at any time with effect for the future.

The following consent-based services are currently configured:

  • Zapier Workflow-Element (Zapier Inc., USA), category functional, retention Sitzung; a transfer to the USA cannot be ruled out and is based on Standard Contractual Clauses or the EU-US Data Privacy Framework.

Details on the individual categories and retention periods are available in our cookie notice.

For the visual design we use the Inter, JetBrains Mono and Instrument Serif typefaces. They are served locally from our own servers. There is no request to Google Fonts, no IP address is transmitted to Google and no cookies are set in the process.

Feedback, roadmap and product updates run inside our own application; no external service is embedded. If you submit a post, a vote or a comment, we store its content together with your name and account ID in our own database in the EU. The legal basis is Art. 6(1)(f) GDPR (legitimate interest in support and product improvement).

5a. Subscriptions, payments and invoices

Paid subscriptions are processed through Paddle.com Market Ltd. (Judd House, 18–29 Mora Street, London EC1V 8BT, United Kingdom). Paddle acts as reseller and merchant of record and is an independent controller for payment processing, invoicing and tax remittance.

The data processed includes name, email address, billing and company address, VAT ID where applicable, payment method and order and invoice data; for fraud prevention Paddle additionally processes technical connection data including the IP address. We neither receive nor store full payment credentials (e.g. card numbers) — they remain with Paddle. From Paddle we receive the subscription status, the plan, the term dates and the invoice records.

Inside the signed-in area we additionally load the Paddle.js script (cdn.paddle.com); on public pages it is only loaded after you consent to functional services. It serves solely to process payments securely, recover interrupted payments (Paddle Retain, formerly ProfitWell) and detect fraud; it does not analyse user behaviour and is not used for advertising. In the signed-in area we pass the workspace's Paddle customer ID so payment notices and cancellation flows can be matched to the correct contract. When loaded, Paddle processes technical connection data including the IP address and may set cookies or comparable storage technologies; transfers to third countries (incl. the USA) are based on standard contractual clauses. The legal basis is section 25(2) no. 2 TDDDG (strictly necessary for the service requested by the user) together with Art. 6(1)(b) and (f) GDPR (pre-contractual measures and performance of the contract, legitimate interest in secure payments).

On some pages we embed videos from YouTube (Google Ireland Ltd., Gordon House, Barrow Street, Dublin 4, Ireland) in extended privacy mode (youtube-nocookie.com). Without your consent neither the player nor the preview image is loaded; a placeholder is shown instead. Only once you release the video does your browser connect to YouTube and transmit technical connection data including your IP address; a transfer to the USA is possible and is based on standard contractual clauses. The legal basis is section 25(1) TDDDG and Art. 6(1)(a) GDPR (consent), which you can withdraw at any time via the cookie settings. Flag graphics and award logos are served from our own servers, so no connection to third parties is made.

The legal basis is Art. 6(1)(b) GDPR (performance of the contract) and Art. 6(1)(c) GDPR for the retention of invoice data under commercial and tax law (as a rule ten years, § 147 AO, § 257 HGB). Transfers to the United Kingdom are covered by an adequacy decision of the European Commission; further transfers are based on Standard Contractual Clauses. Paddle's privacy notice is available at paddle.com/legal/privacy.

5b. Zapier element on our website and in the app

On our home page and in the integrations area we offer an embedded element by Zapier Inc. (548 Market St #62411, San Francisco, CA 94104, USA) that lets you build automations („Zaps") directly. The element is not loaded automatically: without your consent to functional third-party content, or your explicit approval for the current visit, no connection to Zapier is established.

Once loaded, the script, stylesheet and fonts are fetched from Zapier's CDN. Zapier receives your IP address, browser and device information and the page you are on, and may set its own cookies inside the element. If you are signed in to our app, we additionally pass your email address so you can start without a separate sign-up. For your use of Zapier itself, Zapier is an independent controller.

The legal basis is your consent under Art. 6(1)(a) GDPR and section 25(1) TDDDG; you can withdraw it at any time with effect for the future via the cookie settings. Transfers to the USA are based on standard contractual clauses and Zapier's certification under the EU-US Data Privacy Framework. Zapier's privacy notice is available at zapier.com/privacy.

6. Signing in with Google or Microsoft (single sign-on)

You can optionally register and sign in to E-Signing.io with a Google or Microsoft account. If you do not use this option, no such data is processed at all.

When signing in with Google we request only the standard scopes openid, email and profile. Google provides us with your Google account ID, email address, display name and, if available, your profile picture URL. Signing in with Microsoft provides the account ID, email address and name accordingly. We do not access any other data from your Google or Microsoft account, such as email, calendar, contacts or files.

We use this data solely to create your user account, recognise you, sign you in and send you service-related messages. It is never shared with third parties for advertising, never used for advertising or profiling, and never used to train AI models. Humans read it only with your explicit consent, for security or abuse investigations, or where required by law.

The legal basis is Art. 6(1)(b) GDPR (performance of the user agreement). The data is stored until you delete your account and removed afterwards. You can revoke the connection at any time in the security settings of your Google or Microsoft account, and delete your E-Signing.io account at any time in the app settings.

Our use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

7. Recipients and processors

We use carefully selected service providers under data processing agreements. Where data is transferred to third countries, we rely on the European Commission's Standard Contractual Clauses.

Optional services, marked as such in the table, are only activated if you connect them yourself. If you connect the Granola integration, for example, we retrieve meeting notes and transcripts from your Granola account on your behalf in order to populate documents. Without a connection no data is transmitted at all; you can disconnect at any time under Integrations.

If you use your own sending domain on the Pro or Business plan, you add records (SPF, DKIM) in your own DNS that allow our email sending provider to send on your behalf. The domain name, sending mailbox and verification status are stored by us and by the sending provider for this purpose. Without your own domain we send from our default address; you can remove the domain at any time in the settings.

ProviderPurposeRegion
SupabaseDatabase hosting, authentication and file storageEU
CloudflareApplication delivery, server runtime and abuse protectionEU / global (edge)
ResendSending invitation, reminder and completion emailsEU / USA
sms-tools.de (SMS-Tools GmbH)Sending SMS invitations and one-time codes; uses GatewayAPI ApS for technical deliveryEU (Germany)
GatewayAPI ApS (Unterauftragsverarbeiter von sms-tools.de)Technical delivery of the SMS to the mobile networks (endpoint api.smsgatewayapi.com)EU (Denmark)
freeTSA (RFC-3161)RFC 3161 timestamp used to seal signed PDFs; not an eIDAS-qualified timestamp serviceEU
Google Ireland Ltd. (Google Sign-In)Optional sign-in with a Google account (single sign-on), only if you use this optionEU / USA
Microsoft Ireland Operations Ltd. (Microsoft Entra ID)Optional sign-in with a Microsoft account (single sign-on), only if you use this optionEU / USA
Paddle.com Market Ltd.Payment processing, subscription management, invoicing and tax remittance as merchant of record (reseller)UK / EU / USA
Cybot A/S (Usercentrics/Cookiebot)Obtaining, managing and documenting cookie consent (consent management platform), including automatic blocking of scripts requiring consentEU (Denmark)
Better Stack (Better Stack s.r.o.)Uptime monitoring of the application and public status pageEU
Granola (optional)Only if you connect the integration yourself: retrieval of meeting notes and transcripts to populate documentsUSA
Zapier (optional)Only if you connect the integration yourself: transmission of events and data to the automations (Zaps) you build, plus creation of shipments and contacts from ZapierUSA
bunny.net (Storage Zones)Regional file storage for uploaded documents, images and attachmentsChosen by the workspace (EU, UK, US, SG, AU, BR, ZA)

8. Signature evidence

To provide evidence of an electronic signature, we log timestamps, delivery routes, the full IP address of the signer at the time of signing, the user agent and, for the advanced signature, confirmation of a one-time code sent to a masked destination. The IP address is recorded in plain text in the signature evidence because it would otherwise lose its evidentiary function; in the plain access logs it is additionally stored as a hash. The finished PDF receives a SHA-256 checksum and an RFC 3161 timestamp. This evidence is inseparably linked to the transaction and is never altered afterwards; it can be verified at /en/verify.

9. Retention and deletion

We store data only as long as necessary for the respective purpose or as required by statutory retention periods. You can fully delete your account in the settings at any time; dependent data is removed accordingly.

10. Your rights

  • Access to the data processed about you (Art. 15 GDPR)
  • Rectification of inaccurate data (Art. 16 GDPR)
  • Erasure (Art. 17 GDPR) and restriction of processing (Art. 18 GDPR)
  • Data portability (Art. 20 GDPR)
  • Objection to processing based on legitimate interests (Art. 21 GDPR)
  • Withdrawal of consent given, with effect for the future (Art. 7 (3) GDPR)

Please direct your request to datenschutz@e-signing.io. If you are a recipient of a document, please contact the sender first, they are responsible for that content; we will forward requests to them.

11. Right to lodge a complaint

You have the right to lodge a complaint with a data protection supervisory authority. The competent authority for us is the Landesbeauftragter für den Datenschutz und die Informationsfreiheit Rheinland-Pfalz, Hintere Bleiche 34, 55116 Mainz, Germany. You may also contact the supervisory authority of your habitual residence or place of work.

12. Changes

We update this policy whenever the application or the legal situation changes. The current version is always available on this page.