Privacy Policy
This Privacy Policy explains how SignVerse, operated by Vikashan Technologies, collects, uses, discloses, and protects personal data when you use the SignVerse e-signature platform (the “Service”).
1.Data controller
Vikashan Technologies is the controller responsible for personal data processed through the Service, except where we act as a processor on behalf of a customer for the documents and signer data they submit. Contact: privacy@vtuae.com, Vikashan Technologies, Dubai, United Arab Emirates.
2.Personal data we collect
2.1 Data you provide
- Account data: name, email address, organization name, role, and password or federated (Google) identifier.
- Document and recipient data: documents you upload and the names, email addresses, and any fields you add for recipients and signers.
- Signature data: drawn, typed, or uploaded signatures and initials, and consent to sign electronically.
- Support and billing data: messages you send us and information needed to process payments.
2.2 Data we collect automatically
- Verification and audit data: IP address, timestamps, verification method (e.g. email OTP), device and browser information, and approximate geo-location, captured to build the tamper-evident audit trail.
- Usage data: pages viewed, features used, and interaction logs.
- Cookies and similar technologies: as described in our Cookie Policy.
3.How we use personal data
- to provide the Service — create, send, sign, and store documents;
- to authenticate users and signers and to generate forensic audit trails;
- to process subscriptions, payments, and invoices;
- to secure the Service, detect and prevent fraud and abuse, and enforce our Terms;
- to provide customer support and service communications;
- to improve and develop features (using aggregated or de-identified data where practicable);
- to comply with legal obligations and respond to lawful requests.
We do not sell your personal data, and we do not use the content of your documents for advertising.
4.Legal bases (EEA/UK)
Where GDPR or UK GDPR applies, we rely on: performance of a contract (to provide the Service); legitimate interests (security, fraud prevention, product improvement); consent (where required, e.g. certain cookies or marketing); and compliance with legal obligations.
5.Document confidentiality and security
SignVerse applies enterprise-grade encryption to protect personal data in transit and to protect operational secrets at rest with managed key rotation. Every signed document is sealed with a cryptographic hash chain that makes any subsequent modification detectable. Role-based access control, audit logging, request throttling, and a signature-integrity engine complete the defence-in-depth model. No method of transmission or storage is completely secure, but we maintain safeguards designed to protect personal data appropriate to its sensitivity. See our Trust Center → Security page for further detail.
6.Sharing and sub-processors
We share personal data with service providers who process it on our behalf under contract, including: cloud hosting/infrastructure, email and SMS delivery (including one-time passcodes), payment processing, and analytics. We may also disclose data to comply with law, enforce agreements, protect rights and safety, or in connection with a merger or acquisition. A current list of our sub-processors is available on request to privacy@vtuae.com.
7.International transfers
Personal data may be processed in countries other than your own. Where required, we use appropriate safeguards such as the EU Standard Contractual Clauses, the UK International Data Transfer Addendum, or a valid adequacy decision to protect transferred data.
8.Data retention
We retain personal data for as long as your account is active and as needed to provide the Service. By default:
- Account data is retained while the account is active and deleted or anonymized within 90 days of account closure.
- Completed documents and their forensic audit records are retained for 10 years after signing, in line with BFSI and Trust Service Provider record-keeping expectations (e.g. UAE Federal Decree-Law No. 46 of 2021 on Electronic Transactions and Trust Services, CBUAE and SAMA record-retention guidance). You may configure a shorter period for your organization where permitted.
- Security and access logs are retained for at least 12 months for incident response and regulatory investigation.
- Billing records are retained for at least 7 years to satisfy tax and financial-audit obligations.
When no longer needed, personal data is deleted or anonymized.
9.Your privacy rights
Subject to applicable law, you may have the right to access, correct, delete, restrict, or object to processing of your personal data, and to data portability. Where processing is based on consent, you may withdraw it at any time. California residents have rights under the CCPA/CPRA, including to know, delete, correct, and opt out of “sharing,” without discrimination. To exercise rights, contact privacy@vtuae.com. You may also lodge a complaint with your data protection authority. Note that for documents you submitted as a customer, requests from signers may be directed to you as the controller.
10.Children
The Service is not directed to, and we do not knowingly collect personal data from, individuals under 18. If you believe a minor has provided us data, contact us and we will delete it.
11.Do Not Track
The Service does not currently respond to browser “Do Not Track” signals. You can manage cookies as described in our Cookie Policy.
12.Changes to this policy
We may update this Privacy Policy from time to time. Material changes will be notified by posting the updated policy with a new “Last updated” date and, where appropriate, by email.
13.Contact us
Questions or requests: privacy@vtuae.com. Vikashan Technologies, Dubai, United Arab Emirates.