Version 1.0 · Approved · Owner: Privacy Lead
Download .md →Version: 1.0 · Date: July 2026
Processing: IP addresses, user agents, authentication events, API access logs
Lawful basis: GDPR Art 6(1)(f) — Legitimate interests
Owner: Security & Privacy Lead
Touch2Sign collects limited technical data to:
Without security logging, Touch2Sign cannot:
Alternative considered: No logging — rejected as disproportionate security risk for an e-signature platform.
| Factor | Assessment | Nature of data | IP (may be truncated), user agent, timestamps — not special category |
|---|---|
| Data subject expectation | Users expect SaaS providers to secure accounts; signing audit IP is industry standard |
| Impact on data subjects | Low if retention limited and access restricted |
| Safeguards | RBAC on logs, EU storage, retention 90–365 days (security) / per signing retention (audit), encryption |
| Opt-out | Not practical for core security; signing audit required for service delivery (contract/legal obligation) |
Conclusion: Legitimate interest is valid for security logging. Signing audit IP is primarily contract / legal obligation (eIDAS evidence), not LIA alone.
Next review: July 2027 or if logging scope expands (e.g. behavioural analytics).
Approver: _Privacy lead · Date: _
Questions: security@touch2sign.com · privacy@touch2sign.com