This policy explains how we handle personal information when you use eSign at the eSign website, receive a signing invitation, sign an agreement, provide identity evidence, or contact us about the service. It covers our signing website and its connected email, SMS, template API, optional signer accounts and backup features.
1. Who is responsible for your information?
eSignDocs operates this eSign service. When we decide why and how your information is used, we are its data controller.
For privacy questions, requests, complaints or an alternative to a photo check, contact admin@esigndocs.co.uk, with “eSign privacy” in the subject if convenient. You do not have to use a particular form or wording. You can also write to eSignDocs, 73 Brewster Street, Liverpool, L20 9NG.
Where another organisation sends an agreement and we process its information solely on its instructions, that organisation is responsible for the agreement and its processing purposes. Its details should appear in the invitation, agreement or identity-check notice. We assist it with privacy requests under our processing arrangements. We remain responsible for processing we independently undertake for our own service administration, security and legal obligations. Contact us if you are unsure which organisation is responsible.
Company workspaces
Each company workspace has its own documents, templates and members. Authorised members can access information in their workspace. The service’s master administrator can administer workspaces and delivery settings. A personal signer account can show documents from different workspaces only where the account is entitled to access them, such as documents sent to its verified email address.
2. The information we collect and where it comes from
We receive information from you, the organisation preparing an agreement, its authorised staff and connected business systems, and delivery or hosting providers. The information depends on the features used:
- Contact and account details: names, email addresses, mobile numbers, organisation, signing role and order, staff account details and permissions, and optional signer account details (name, email, a one-way password hash and email-verification records).
- Agreements and signatures: original and completed documents, information entered in form fields, typed or drawn signature appearances, signing instructions, approvals and your signing acknowledgements, including your declaration that you have read all pages before signing. A document may contain addresses, prices and other information supplied by its sender or signers.
- Signing and security records: document identifiers and fingerprints, invitation and verification events, consent wording and its version or fingerprint, server timestamps, IP addresses, browser information, access attempts and the actions recorded during the signing process.
- Communications: invitation, reminder and completion messages, their recipients and delivery results, SMS provider references, and correspondence with us. Messages can include document titles, signing links and access codes.
- Optional identity evidence: a selfie and photographs of the front and, if requested, back of an ID document, such as a passport or driving licence. These images may show a portrait, name, date of birth, address, signature, nationality, document number and expiry date. Only provide the information requested for your check; cover details the sender does not need while leaving the portraits clear.
- Optional local face-comparison information: temporary facial features derived from the two photographs, a similarity score, an outcome such as inconclusive, and the comparison method. Section 4 explains this processing and your choices.
- Review and administration records: the reviewer, decision, relevant notes, time of review, requests for another method, withdrawal or deletion records, backup status and API activity.
Camera access starts only after you choose to open the camera and grant your device's permission. The capture feature takes a still photograph, without audio. You can preview it before choosing to upload it, select a suitable existing image, or request another method.
Please avoid adding unnecessary information about other people or sensitive matters to a document or review note. We do not use the face-comparison feature to infer ethnicity, health, gender, emotions or other personal characteristics.
Optional signer accounts and saved signatures
You can sign as a guest. If you choose an account, we verify your email address before showing agreements sent to it. For an SMS invitation, you must separately add the agreement from its verified signing session after signing. We store the account's document links and verification record so you can access your completed documents later. We use the existing website login and password-reset system; we do not store your password as readable text.
You can optionally save a typed or drawn signature appearance for reuse. We encrypt that preference in the website database. It is a reusable visual mark, not automatic permission to sign: you still choose and confirm it for each agreement. You can replace or remove it in My signature. Removing it does not change signatures already recorded on agreements. Signing evidence records your declaration that you have read all pages; it does not independently verify that you read them.
You can also upload an unsigned PDF to sign yourself from your verified account. We store its review copy, draft fields, account ownership, completed PDF and signing record so you can prepare, sign and download it. This flow does not send you a signing invitation. The report records authenticated-account signing and when your account email was verified; it does not claim that a fresh email code was used when you signed. Choosing your stored appearance and giving the final confirmation are separate from storing that preference. These documents are held in the same workspace as other agreements and are accessible to its authorised staff; they follow the document backup and retention rules below.
Email verification codes expire after 15 minutes and can only be used once. Expired challenge records are removed by subsequent code requests or scheduled cleanup. Rate-limit records remain temporarily to control abuse. Account details and the optional signature preference remain until removed or the account is closed; contact us to request account closure. Agreement records are considered separately under the retention policy below. Changing account email requires verification of the new email before document access resumes.
3. Why we use information and our lawful bases
We use the UK GDPR lawful basis appropriate to each purpose:
| Purpose | Lawful basis |
|---|---|
| Prepare and administer an agreement with you personally, and take steps you request before entering it | Performance of a contract or steps at your request before a contract: Article 6(1)(b). |
| Manage business agreements involving company representatives; send necessary signing messages; maintain reliable signing evidence; support users and resolve disputes | Legitimate interests: Article 6(1)(f). Our interests are running our business, communicating with the right people, recording agreements and establishing or defending legal claims. We consider the necessity of the processing and its effect on you. |
| Protect accounts and documents, investigate misuse, prevent fraud and maintain service availability | Legitimate interests: Article 6(1)(f), subject to the same balancing of interests and individual rights. This basis does not by itself authorise biometric recognition. |
| Collect and manually review optional selfie and ID uploads | Consent: Article 6(1)(a). You can choose an alternative and withdraw permission for these uploads. |
| Perform the optional local biometric face comparison | Consent under Article 6(1)(a) and explicit consent for special category biometric data under Article 9(2)(a). |
| Keep records or disclose information where a specific legal requirement applies, for example an applicable accounting requirement or binding court order | Compliance with a legal obligation: Article 6(1)(c). We can explain the obligation relevant to a particular request or record. |
We do not treat agreeing to an agreement, reading this policy or opening a signing link as consent to biometric processing. Where an agreement itself requires sensitive personal information for another purpose, the responsible organisation must identify an appropriate lawful basis and, where required, a separate special category condition and explain that purpose. This policy is not blanket permission to collect sensitive information.
4. Selfies, ID photographs and local face comparison
Some agreements request a photo check; others do not. The request explains who is responsible, why the images are needed, which images are requested and their deletion period.
If local face comparison is selected, we ask for your explicit consent before accepting images for that purpose. Software running on the same server as eSign compares the face in your selfie with the portrait in your ID photograph. It calculates facial features in memory and a similarity score for that pair. It does not search a database of other people. We do not send these images to an external identity-verification service or use them to train a model.
The facial features are not saved as a reusable face template. The images and temporary score are kept privately for the review and the limited period described in section 9. Authorised staff see the images and result. The service's hosting environment still processes the information; “local” does not mean that hosting providers have no involvement or that the server is necessarily in the UK.
A member of staff makes the decision in every case. A similarity score is not a probability that you are the person named on the ID. The tool can make mistakes and can be affected by image quality, age differences, lighting and other factors. It does not establish whether an ID is genuine, current or stolen, and it does not check liveness, consult a government database or certify identity. A favourable result does not automatically permit signing; an unfavourable result does not automatically reject you.
You can use “Request another way to verify” or contact the address in the request. We will arrange a suitable manual alternative without biometric comparison and without penalising you for declining it. For example, this may involve an agreed check with an authorised member of staff. Signing may wait while that check is completed. Tell us if you need an accessibility adjustment.
You can withdraw consent using “Withdraw permission & delete my images” while you have access to the upload controls, or by contacting us. This removes the active uploads and temporary comparison result. A comparison already processing may finish in memory, but its result will not be retained after withdrawal. Withdrawal does not make earlier lawful processing unlawful, cancel a signature already given, or erase an agreement that we have a separate lawful reason to retain. A minimal record of consent, withdrawal and any completed staff decision may remain for accountability and relevant claims; it contains no reusable face template.
5. Signing evidence and what other parties can see
Authorised parties may receive the completed agreement, its completion report and a separate signed evidence file. These can include participants' names and contact details, signature appearances, form entries, acknowledgements, signing order, timestamps and recorded activity. The evidence file can include IP addresses and browser information used to document events. These records help explain how the agreement was signed and detect changes to the document or evidence.
Where a photo check was used, the shared record contains a limited account of the method and staff decision at signing, including relevant image fingerprints. It does not include the separate selfie or ID uploads, facial feature vectors, similarity score or private review notes. Information deliberately included in the agreement itself will, however, remain part of that agreement.
If you choose Create signing copy for a protected PDF, we retain the uploaded original unchanged alongside a separate visual review copy. The original, including its contents and any earlier signatures, is attached inside the completed PDF, available to authorised participants and included in relevant document backups. Its fingerprint and the relationship between the two files are recorded in the signing evidence. Existing certificates apply to the original; they are not transferred onto the newly signed pages.
Newly completed PDFs contain a cryptographic document seal using a certificate issued by this workspace. Its public certificate and fingerprint are shared in the PDF and technical evidence; the private key is not shared. This checks integrity against the workspace key and does not independently certify a person's identity or provide an independent timestamp.
The record describes activity observed by eSign. Email or mobile access and a local photo comparison are not certified identity verification or a qualified electronic signature. Other agreement parties are responsible for their own handling of copies they receive.
6. Who receives information?
We give access according to purpose and responsibility. Recipients may include:
- Authorised eSign staff, the organisation sending the agreement, its authorised reviewers, and the agreement parties who need the relevant document and signing evidence.
- Hosting, server administration, security, maintenance and email providers supporting the service. These providers operate the server, help protect the service and carry signing messages. Contact us for the current provider and processing-location details relevant to your agreement.
- Twilio and telecommunications providers, when SMS invitations, codes, reminders or delivery notifications are used. They process mobile numbers, message content and delivery information. The separate selfie and ID uploads are not attached to these SMS messages.
- Google, when we back up data to our connected Google Drive account. Section 7 explains what those backups contain and how document copies are protected.
- Organisations operating connected plugins or systems that create agreements through an authorised template API connection or retrieve their permitted agreement status and files. They receive only what their authorised connection makes available; the template API does not provide access to the separate identity uploads.
- Professional advisers, insurers, regulators, courts, law enforcement or another recipient where disclosure is necessary and lawful for advice, a claim, an applicable legal duty or a legitimate business transfer. We limit disclosure to what is appropriate for that purpose.
Providers acting as our processors must handle information under appropriate contractual instructions. Some recipients, including agreement parties or communications carriers, may act as independent controllers for their own processing. We do not sell personal information or use this signing service to build advertising profiles. Signing contact details are not automatically subscribed to marketing.
7. Google Drive backups and document copies
We may keep two kinds of backup in the connected Drive account:
- Workspace recovery archives: encrypted archives containing documents, signing evidence, activity and delivery records, templates, workflows, API records and settings needed for recovery. They require the recovery password.
- Completed-document ZIP copies: the full signed PDF with its completion report, original review PDF, signed JSON evidence, workspace public key and an explanatory file. Completed-document copies can be stored with or without a ZIP password, according to the sender’s backup settings. A copy stored without password protection can be read by anyone who obtains it. Protection depends on access to the Drive account and on how downloaded copies are stored and shared.
The eSign backup feature does not create public sharing links. Filename and date metadata remain visible in Drive. The separate selfie and ID uploads, facial feature vectors and temporary comparison results are excluded from these eSign backups. Minimal consent and staff-review records may be included. Website accounts, saved-signature preferences, account-to-SMS-document links and active account verification codes are excluded from the eSign workspace archive. Separate protected website or hosting backups may contain account data and encrypted saved-signature preferences.
Separate hosting or whole-server backups are different: they may contain the encrypted database records holding identity images and temporary results. Retention depends on the separate hosting backup schedule. We assess the recovery period needed, backup frequency, security risk, legal holds and the retention needs of the underlying records. You can ask us for the current schedule; the app’s document-export settings do not control hosting backups. We restrict access and apply deletion requirements when recovering data. A photograph embedded by a sender within an agreement is part of that agreement and is not excluded as a separate identity upload.
8. International processing
Ask us for the hosting location and provider details applicable to your agreement. Email, telecommunications and cloud providers may process information in other countries, including the United States. Running the comparison locally does not eliminate the international processing involved in those separate services.
For restricted transfers from the UK, we use an applicable UK adequacy arrangement or appropriate safeguards, such as an International Data Transfer Agreement or the UK Addendum to approved standard contractual clauses, together with the assessment and additional protections required for that transfer. You can contact us for information about the countries and safeguards applying to your information and how to obtain a copy of the relevant safeguards, subject to necessary redactions. We do not rely on biometric consent as general permission for unrelated overseas transfers.
9. How long we keep information
We keep identifiable information for the purpose that justifies it and review whether it remains necessary:
| Information | Retention approach |
|---|---|
| Separate selfie and ID uploads, and temporary comparison results | The period shown in your request, normally 30 days from the first upload and configurable from 1 to 90 days. Earlier deletion is available by withdrawal or staff action. Access expires at the deadline; scheduled tasks remove the stored data. Technical failures can delay scheduled deletion and must be corrected. |
| Facial feature vectors | Held in the comparison process's working memory only; not deliberately saved to files, a face database, signing evidence or backups. |
| Agreements, signatures and supporting evidence | For as long as needed to administer the agreement and related project, meet relevant record-keeping duties, and establish or defend claims. We assess the agreement type, completion or termination date, warranties, applicable legal time limits and any actual dispute. We do not apply the short photo-deletion period to the agreement. |
| Minimal consent and staff-review records | For the period necessary to account for the check and support the related agreement or a relevant claim. Raw images and temporary scores follow the shorter period above. |
| Invitations, delivery history, support correspondence and API records | While needed to complete or troubleshoot the relevant request, maintain the related agreement record, investigate a specific incident or resolve a complaint or claim. We remove unnecessary content when those purposes end. |
| Optional signer accounts and saved-signature preferences | While you keep the account or preference, subject to our review of whether it remains needed; you can remove the saved signature or request account closure. Signed agreements follow their separate retention period. |
| Staff accounts and access records | While access is needed, followed by any limited retention necessary for security, accountability or a relevant claim. |
| Server and security logs | For the limited period needed to operate and troubleshoot the service, detect misuse and investigate security incidents. We assess the type of log, incident risk, any open investigation and relevant legal requirements. A specific incident may require a longer, restricted hold. Contact us for the current server-log schedule. |
| Backups | Workspace archives rotate according to the configured number of versions; the default is 30 versions, not 30 days. Individual document copies are kept separately and must be removed in line with the agreement's retention needs. Hosting backups follow the period in section 7. |
The app does not automatically delete agreements or individual Drive document copies solely because they reach a particular age. We manage that retention separately. Relevant records may be held longer for an actual dispute, legal obligation or preservation requirement; this is not permission to retain every record indefinitely.
Where deletion is appropriate, it also applies to copies under our control. Backup copies may remain until their scheduled replacement or deletion and are restricted from ordinary use in the meantime. If we restore a backup, we reapply applicable deletions. We cannot automatically erase copies already lawfully supplied to another independent controller, but will handle any notification obligations and explain the position.
10. Cookies and device storage
The eSign software uses essential functionality to maintain authorised sessions and protect the service. Its signing-session cookie, whose name starts rpsign_session_, normally lasts one hour. Website login and authentication cookies are used for staff and signer account access; their duration depends on the login and “remember me” settings. A login test cookie may be used to check that cookies work. Browser permission for the camera is separate from these cookies.
The eSign software does not include advertising cookies or analytics tracking. Additional hosting or security components may set their own cookies. The separate cookie policy describes the app’s essential storage. Contact us about any additional hosting or security cookies you see. Where consent is required for any additional technology, it will be requested before that technology is used. You can manage cookies through your browser; blocking essential cookies may prevent login or signing. Avoid using shared devices for private documents, and close the signing page or sign out after use.
11. How we protect information
Controls include HTTPS, restricted staff access, protected signing sessions, encrypted storage for private eSign records and identity uploads, audit records and controlled backup access. The local comparison service accepts authenticated requests only through the server's local interface; it is not a public face-search service. The software keeps temporary comparison data out of its request logs.
These controls depend on proper server administration and authorised staff handling. Email, SMS and downloaded unencrypted document copies have their own exposure risks. Keep invitation links and access codes private and tell us promptly if they go to the wrong person. No system can guarantee absolute security. We investigate personal data incidents and make notifications to affected people and the regulator where legally required.
12. Your choices and rights
You may have rights to access your information, correct inaccuracies, request erasure or restriction, and receive certain information in a portable format. The availability of each right depends on the processing and applicable law.
You can object to processing based on our legitimate interests. Explain any circumstances you want us to consider. We will assess the objection and explain whether there are grounds to continue.
You can withdraw consent for optional uploads and biometric comparison at any time, using the controls described in section 4 or contacting us. You can ask for a human review, challenge a photo-check decision and provide other relevant information. We do not use the comparison to make solely automated decisions with legal or similarly significant effects.
Contact admin@esigndocs.co.uk to exercise your rights. We may ask for proportionate information to confirm identity or authority before disclosing private information; we do not automatically require a passport for every request. Requests are normally free. We aim to respond without undue delay and normally within one month. If a permitted extension, clarification or identity check affects the deadline, we will explain it. Where we cannot fulfil a request, we will explain why and how to challenge the decision.
Required signing details are identified in the request. Without the necessary agreement and contact information, we may be unable to provide this electronic signing route. Refusing optional biometric processing does not by itself prevent you using an agreed manual alternative. Correcting a completed agreement may require an explanatory record or a replacement agreement rather than silently changing the historical signed file.
13. Complaints
Please contact admin@esigndocs.co.uk if you are unhappy with our handling of information. We will acknowledge a data protection complaint within 30 days, investigate without undue delay, keep you informed and explain the outcome and any action we take.
You also have the right to complain to the Information Commissioner's Office (ICO), the UK data protection regulator, at ico.org.uk/make-a-complaint. Contacting us first may help resolve the issue but does not remove your right to raise a concern with the regulator.
14. Children and changes to this policy
This service is intended for business agreements and adult users. It is not designed to collect children's biometric information. Contact us before submitting identity information for someone under 18 so that an appropriate process can be considered.
We may update this policy when the service, our practices or applicable requirements change. The date at the top identifies the latest version. We will provide additional notice where a material change requires it and obtain fresh consent before using biometric information for a new purpose requiring consent.