Touch2SignPrivacy Policy

Privacy Policy

Last updated: 12 August 2026

1. Who we are

Touch2Sign is an electronic signature and document management platform operated by Touch2Sign Ltd, a company incorporated in the Republic of Ireland (“we”, “us”, “our”). If you have questions about this policy, contact us at privacy@touch2sign.com.

2. Data we collect

We collect the following categories of personal data:

  • Account data — name, email address, and password (hashed) when you register.
  • Organisation & billing data — company name, billing address, plan, currency, payment method tokens (held by our payment partners), invoices, and prepaid credit balances / expiry metadata.
  • Signing data — name, email address, IP address, and device/browser information for each person who signs a document.
  • Document content — documents and files you upload or generate within the platform.
  • Identity verification data — where AES/QES or other IDV is used, verification results and related attributes returned by identity providers (we do not store full payment card PANs).
  • Communication data — phone numbers used for SMS or RCS signing invitations, if provided.
  • Usage & metering data — sends, SMS/RCS, AES/QES events, and similar usage needed for entitlements and billing.
  • Usage analytics — pages visited, actions taken, and timestamps, collected via server logs.
  • Payment data — billing name and address. Card numbers are processed and vaulted by our payment partners (NMI preferred SaaS rail; Stripe as configured alternate and for some in-document payments) and are never stored in full by Touch2Sign.

3. How we use your data

  • To provide the signing and document management service.
  • To generate legally admissible audit trails for signed documents.
  • To send signing invitations, reminders, and completion notifications via email, SMS, or RCS.
  • To verify document integrity using cryptographic hashing.
  • To bill subscriptions, metered usage, modules, and prepaid credits, and to display balances and expiry in billing dashboards.
  • To comply with our legal obligations under eIDAS and applicable data protection law.
  • To improve and maintain the platform.

4. Legal basis for processing

Under the UK GDPR and EU GDPR, our lawful bases are:

  • Contract performance — processing necessary to deliver the service you have subscribed to.
  • Legitimate interests — security monitoring, fraud prevention, and service improvement.
  • Legal obligation — retaining audit records as required by eIDAS and applicable law.
  • Consent — where we ask for and receive your explicit consent (e.g. marketing communications).

5. Data storage and transfers

Primary data storage is on servers in the EU West (Ireland) AWS region. We do not transfer personal data outside the UK or EEA except where Standard Contractual Clauses or equivalent safeguards are in place (see our Data Processing Agreement for sub-processor details).

Key infrastructure:

  • Documents and files — AWS S3 (encrypted at rest, AES-256)
  • Database — AWS RDS PostgreSQL (encrypted at rest)
  • Email delivery — AWS Simple Email Service (SES)
  • SMS / RCS delivery — AWS Simple Notification Service (SNS)

6. Data retention

  • Signed documents and audit trails — retained for 7 years from the date of signing to satisfy legal and regulatory requirements.
  • Account data — retained for the duration of your account plus 90 days after closure.
  • Unsigned / draft documents — retained for 90 days then permanently deleted.
  • Server logs — retained for 30 days.

7. Data sharing

We do not sell your personal data. We share it only with:

  • Sub-processors — AWS (infrastructure), NMI and Stripe (payments), OneID (UK identity verification), eID Easy (qualified signatures), Signicat (Nordic eID), Veriff (optional IDV), and Anthropic (optional AI document analysis). Customer-initiated integrations (for example Clio, HubSpot, Salesforce) process data under your instruction. A full list is in our Data Processing Agreement and sub-processor register.
  • Your organisation — when you sign documents, the sending organisation (our customer) receives signing and audit data.
  • Law enforcement — where required by law or valid court order.
  • Successors — in the event of a merger or acquisition, subject to the same privacy obligations.

8. Your rights

Under the UK GDPR and EU GDPR you have the right to:

  • Access — request a copy of the personal data we hold about you.
  • Rectification — correct inaccurate data.
  • Erasure — request deletion, subject to legal retention obligations.
  • Portability — receive your data in a structured, machine-readable format.
  • Object — to processing based on legitimate interests.
  • Withdraw consent — at any time for processing based on consent.

To exercise any of these rights, email privacy@touch2sign.com. We will respond within 30 days.

You also have the right to lodge a complaint with your supervisory authority. In Ireland: the Data Protection Commission. In the UK: the Information Commissioner's Office.

9. Cookies

Touch2Sign uses strictly necessary session cookies for authentication and security. Where we use optional analytics or non-essential cookies, we ask for your consent via our cookie banner. See our Cookie Policy for details.

10. Security

We implement technical and organisational measures including TLS encryption in transit, AES-256 encryption at rest, SHA-256 document integrity hashing, access controls, and regular security reviews. In the event of a data breach that poses a risk to your rights and freedoms, we will notify you and the relevant supervisory authority within 72 hours.

11. SMS and RCS opt-out

If you receive signing invitations by SMS or RCS, you can opt out at any time by replying STOP. Opt-outs are processed immediately and your number will not receive further messages from Touch2Sign.

12. Artificial intelligence (EU AI Act transparency)

Touch2Sign offers optional AI features (Aria and Sentinel) that analyse documents, draft text, summarise content, and answer questions. When you use these features, or when a sender enables them for a signing session, you are interacting with an AI system. We provide notices in the product interface in line with Article 50 of the EU AI Act (Regulation (EU) 2024/1689).

  • Signers — see the Touch2Sign AI & Signing Analysis Disclosure before consenting to electronic signing, and labels on AI briefings, summaries, and Q&A answers.
  • Senders — see Aria branding when drafting with AI; AI-generated drafts include a visible and machine-readable mark.
  • Operators — see Sentinel notices when using Ask AI or cross-contract search.
  • No training — document content processed for these features is not used to train foundation models.

Further detail: EU AI Act Article 50 — Transparency Guide.

13. Changes to this policy

We may update this policy from time to time. The date at the top of this page reflects the latest revision. Material changes will be communicated by email to registered account holders.

14. Contact

Touch2Sign Ltd
Email: privacy@touch2sign.com
Web: https://app.touch2sign.com

Pricing & Commercial Terms · Terms & Conditions · Data Processing Agreement · Policy Library