dSign — Privacy Policy
Last updated: August 26, 2026
This policy covers the dSign browser extension, the dSign web portal, and dSign Xchange (document exchange with external signers). It describes what we collect, why, how long we keep it, and who it is shared with.
What we collect
- Account information: your name, email address, and organization, provided at account creation or via Google/Microsoft sign-in.
- Authentication credentials: your password (stored as a salted hash, never in plain text) if you sign in with email/password, or an authentication token if you sign in with Google/Microsoft — used solely to verify your identity and keep you signed in.
- Document content, only while producing your signature: when you submit a PDF/Word/Excel document for signing — including one routed through an integrated document management system (InDoc EDGE) — its content is sent to our signing server solely to produce your digital signature. For every signing method (smart card / USB token, cloud/CSC providers, HalcomOne, InDoc EDGE-routed signing, Click To Sign, Specimen, Office document conversion) the content is processed transiently and never written to disk or a database — held either purely in memory for the duration of the request, or in a short-lived cache (typically retrievable for well under a minute, automatically deleted after that) for the handful of methods where your browser needs a brief moment to pick up the finished result or where a multi-step signing flow needs to hand content off between steps.
- Documents shared via dSign Xchange: dSign Xchange lets your organization send a document to an external recipient for signature, or receive one from another organization. Unlike the signing methods above, Xchange documents ARE stored — encrypted, in a database and storage location kept completely separate from the signing methods above — for as long as the sending organization's configured retention period (30 days by default, organization-configurable). We also store the recipient's email address, name (if provided by the sender), delivery/open/signing status, and, if the recipient did not already have a dSign account, a minimal account created solely to let them sign that document.
- Certificate metadata: public certificate information (subject, issuer, serial number) needed to build the signature. Private keys never leave your smart card, cloud provider, or the issuing authority — dSign never has access to them.
- Audit log: for eIDAS compliance, each signature records the signer's identity, timestamp, IP address, and a cryptographic hash of the signed document, in a tamper-evident log.
- Session cookies (only for organizations using an integrated document management system): read to authenticate document fetch/upload requests on your behalf.
What we do NOT collect
- Browsing history outside of pages where you actively use the signing feature
- Content of pages that are not PDF documents or configured document systems
- Any data for advertising or analytics purposes
How we use it
Solely to provide the signing service: authenticate you, process the document you asked to be signed or exchange, produce a legally valid signature, deliver a shared document to its intended recipient, and maintain the audit trail required by eIDAS Regulation (EU) 910/2014.
Sharing
Data is shared only with: the certificate/signing provider you choose to use (e.g. your smart card's issuing CA, Halcom, or a Cloud Signature Consortium provider), your own organization's administrators (for account and billing management), and — for documents you send or receive via dSign Xchange — the specific external recipient or sending organization you chose to exchange that document with. We do not sell or share data for advertising.
Retention
- Smart card / USB token, cloud signing providers (CSC/primesign), HalcomOne, and InDoc EDGE-routed signing: the document is held only long enough to move it between the steps of the signing process — typically well under a minute, deleted immediately once no longer needed, and automatically purged shortly after even if that handoff never completes (e.g. a closed tab, a lost connection, or a signer who abandons the process partway through). Nothing is ever written to a permanent disk file or database column for these methods.
- Click To Sign, Specimen, and Office (Word/Excel) document conversion: processed entirely in memory for the duration of the request; nothing is written to disk or a database at any point.
- dSign Xchange: the document, and the audit trail of who sent/opened/signed it, is kept for the sending organization's configured retention period (30 days by default) and then automatically deleted. An external recipient's account is limited to the access needed to complete that exchange.
- Audit log: retained indefinitely as a tamper-evident eIDAS compliance record. It never contains document content — only a cryptographic hash, signer identity, and timestamp.
Outside of dSign Xchange, we do not retain a browsable history of previously-signed documents. Once a signature is delivered to you, dSign keeps only the audit log entry (hash + metadata, described above) — not the document itself.
Your rights
Contact your organization's administrator to request access to, correction of, or deletion of your account data, subject to eIDAS audit trail retention requirements for already-completed signatures.
Contact
Support: sign@darhiv.ba