Privacy policy for Contractsign

Here you can read how Contractsign processes personal data when you use our platform and services.

Last updated: August 5, 2026

This privacy policy describes how Contractsign ("Contractsign", "we", "us") processes personal data in connection with the use of our website and SaaS platform.

Personal data is processed in accordance with:

  • The EU General Data Protection Regulation (GDPR)
  • The Danish Data Protection Act
  • Other relevant national and EU legislation

1. Data controller

Contractsign
contact@contractsign.io

2. Roles and responsibilities

2.1 When Contractsign is the data controller

Contractsign is the data controller for the processing of personal data relating to:

  • Use of the website
  • Creating and administering user and company accounts
  • Invoicing and payment
  • Support and customer service
  • Marketing (where relevant)

2.2 When Contractsign is the data processor

For documents, contracts, signing processes and other information the Customer uploads to the platform, Contractsign acts as data processor.

In those cases the Customer is the data controller.

The processing is governed by a separate data processing agreement (DPA).

Contractsign does not independently assess the content of documents and does not use customer data for its own purposes.

3. Categories of personal data

We may process the following categories:

  • Identity and contact details (name, email, phone, company)
  • Account information
  • Payment details (via third-party payment providers)
  • Documents, contracts and signature data uploaded by the Customer
  • Technical information (IP addresses, log files, browser and device data)
  • Metadata relating to the signature (timestamp, IP, device and so on)

Contractsign does not knowingly collect sensitive data unless the Customer uploads such data themselves.

4. Purposes and legal bases

4.1 Performance of a contract (GDPR Article 6(1)(b))

  • Providing the platform
  • Administering accounts
  • Carrying out signing processes
  • Customer support

4.2 Legal obligation (Article 6(1)(c))

  • Accounting and bookkeeping
  • Documentation in the event of legal claims

4.3 Legitimate interest (Article 6(1)(f))

  • IT security
  • Preventing abuse
  • Operating, maintaining and improving the platform
  • Measuring the effect of our advertising without using name, email or other contact details

4.4 Consent (Article 6(1)(a))

  • Sending tips, guides and news by email to users who have actively asked for them
  • Marketing and statistics cookies, cf. the cookie policy

Consent is voluntary and can be withdrawn at any time — for marketing emails via the unsubscribe link at the bottom of the email, and for cookies via the cookie settings. Withdrawal does not affect the lawfulness of processing carried out beforehand. Service messages about the documents and signatures you requested yourself are not marketing and are sent regardless.

5. Sub-processors and third-party providers

Contractsign uses the following sub-processors and third-party providers:

  • Cloudflare R2 (EU) — storage of documents and files
  • Laravel Cloud / Amazon Web Services (EU) — hosting and operation of the platform
  • Amazon Web Services Textract (EU, Frankfurt) — text recognition (OCR) of scanned documents
  • OpenAI — AI analysis and AI assistance on documents (data is not used to train AI models)
  • Aspose Words Cloud — document generation and conversion
  • Mailgun (EU) — sending emails
  • sms.dk — sending SMS codes for signing
  • Stripe — payment and invoicing
  • Cloudflare — CDN, security and generation of signature certificates
  • Sentry — technical error monitoring
  • Tawk.to — support chat (only loads once you open the chat yourself)
  • Google and Meta — marketing and ad measurement (only with your consent, see the cookie policy)
  • CustomOrders — conversion measurement for ads (with your consent: name and email; without consent: only an internal id and campaign information, cf. section 4.3)

These providers process personal data only on instructions from Contractsign and under data processing agreements.

6. Transfers to third countries

Some of our providers may be established outside the EU/EEA.

If personal data is transferred to third countries, Contractsign ensures an adequate level of protection through:

  • The European Commission's Standard Contractual Clauses (SCCs)
  • The EU-US Data Privacy Framework (where relevant)
  • Supplementary technical and organisational security measures

7. Use of AI technology

The platform includes AI features (document analysis, questions and answers about documents, and AI-assisted edits). When you use these features, the document's text is sent to our AI provider OpenAI. Scanned documents may also be processed with text recognition at Amazon Web Services (Textract) in the EU. Data is processed:

  • Solely on behalf of the Customer
  • Under a data processing agreement
  • Not for training general AI models
  • Not for Contractsign's own purposes

Contractsign does not carry out independent profiling or automated decisions with legal effect.

For security and abuse-prevention purposes, OpenAI may retain submitted data for a short period (up to 30 days), after which it is deleted at the provider. The data is not used to train AI models.

The website also offers a free AI contract check that can be used without an account. For that processing, Contractsign is an independent data controller — see section 8b.

8. Retention and erasure

Personal data is retained only as long as necessary for the purpose or required by law. Specifically:

  • Unfinished document drafts: deleted automatically after 30 days
  • One-time signing codes: expire after 10 minutes and are deleted on use
  • Contracts: retained until the Customer deletes them; deleted contracts are permanently removed after 30 days, including files
  • Free AI contract check: the uploaded file is deleted immediately after the analysis; the report and the associated IP address are deleted automatically after 7 days
  • Accounts: can be deleted by the user under Settings; deletion is permanent
  • Accounting records (purchase and invoice information): retained for 5 years after the end of the financial year, as required by the Danish Bookkeeping Act

Backups may be retained for a limited period for security reasons.

8a. When you receive a document to sign

If you receive a document to sign via Contractsign, the sender (Contractsign's customer) is the data controller for the processing, and Contractsign is the data processor. When you sign, the following is recorded:

  • The details the sender has provided about you (e.g. name, email, phone number, address and role)
  • The time of signing or rejection
  • IP address and information about your device and browser
  • The consent text shown to you at the point of signing

This information is recorded as legal documentation of the signature (formation of the agreement and preservation of evidence). If you want access, rectification or erasure, contact the sender of the document. You are also welcome to contact contact@contractsign.io and we will help pass your request on.

8b. When you use the free AI contract check

At contractsign.io/contract-check you can upload a contract (PDF) without an account and get an AI-generated analysis. For this processing, Contractsign is an independent data controller. We process:

  • The document's content and text (which may contain personal data appearing in the contract)
  • The document's page count
  • Your IP address (to limit abuse of the free service)

The legal bases are GDPR Article 6(1)(b) (providing the analysis you requested yourself) and Article 6(1)(f) (preventing abuse, cf. section 4.3). For the analysis, the document's text is sent to our AI provider OpenAI (the data is not used to train AI models), and scanned documents may be processed with text recognition at Amazon Web Services (Textract) in the EU. The file is stored temporarily at Cloudflare R2 (EU) and deleted immediately after the analysis; the report and the IP address are deleted automatically after 7 days. For security and abuse-prevention purposes, OpenAI may retain submitted data for a short period (up to 30 days), after which it is deleted at the provider.

Only upload documents you have the right to share. The analysis is advisory, may contain errors and does not constitute legal advice.

9. Security

Contractsign has implemented appropriate technical and organisational security measures, including:

  • Encryption in transit (TLS)
  • Access control
  • Logging
  • Role-based access
  • Secure hosting infrastructure
  • Ongoing security updates

10. Rights of data subjects

Data subjects have the right to:

  • Access
  • Rectification
  • Erasure
  • Restriction
  • Data portability
  • Objection
  • Withdrawal of consent (where processing is based on consent, e.g. marketing cookies)

Requests concerning documents and contracts must be directed to the Customer acting as data controller.
Contractsign assists the Customer to the extent required by law.

11. Limitation of liability

Contractsign is not liable for unlawful or unauthorised processing arising from the Customer's instructions, document content or choice of legal basis.

Any liability is in all cases limited in accordance with our terms and applicable mandatory law.

12. Changes

Contractsign may update this privacy policy. The version in force at any given time is available on the website.

13. Contact and complaints

Questions can be directed to:
contact@contractsign.io

Data subjects have the right to lodge a complaint with:

Contractsign is established in Denmark and is supervised by the Danish Data Protection Agency (Datatilsynet). Under Article 77 GDPR you may lodge your complaint either with Datatilsynet or with the supervisory authority in your own country of residence or workplace.

Datatilsynet
www.datatilsynet.dk