• Strictly necessary Sign-in, security, signing sessions and your time zone. Closign can't work without these. closign-session, remember_web_…, XSRF-TOKEN, tz, cookie-notice
    Always on
  • Live chat Chat with our team from any page. Our chat provider, Crisp, sets cookies to keep the conversation going and receives your IP address and browser details. Off until you switch it on. crisp-client/…
  • Analytics and advertising We don't use analytics or advertising cookies. Website visits are counted without cookies (Cloudflare Web Analytics). If that changes, we'll ask you first.
    Not used
Read the Cookie Policy
ID-verified signing soon Join waitlist

Privacy Policy

Effective Oct 8, 2026 · Updated Oct 8, 2026
Contentsexpand_more
In short. We collect what we need to run Closign, keep it on our servers in India, never sell it, and never use your documents to train AI. You can see, correct, export or delete your data by writing to support@closign.io.

01Introduction

This policy explains what personal data Closign collects, why we collect it, who we share it with, and the choices you have. We have kept it in plain language.

Closign is an electronic signature and document workflow service available at closign.io and its related apps, APIs and emails (the "Services"). The Services are operated by Janak Prajapati, a sole proprietor trading as Closign, Ahmedabad, Gujarat, India ("Closign", "we", "us"). If you have any question about this policy, write to support@closign.io.

By using the Services, you acknowledge that we will handle your personal data as described here. Our Terms of Service also apply.

02Who this policy covers and our role

Our role depends on how you use Closign.

You areWhat you doOur role
Account holderYou sign up, create a workspace, upload documents and send them for signatureController (Data Fiduciary under Indian law) for your account, billing and usage data; processor for the documents and signer details you add
SignerYou receive a link to view or sign a document someone sent through ClosignProcessor, acting on the sender's instructions. The sender is the controller of your data
VisitorYou browse closign.io without an accountController for the website and form data you give us

If you are a signer, the person or business that sent you the document decides why your data is used. Please read their privacy policy too. If you send us a request about your data in a signed document, we will pass it to the sender and help them respond.

If you add other people (signers, team members, contacts), you confirm that you have the right to share their details with us for this purpose.

This policy does not cover third-party websites or apps linked from Closign.

03Information we collect

CategoryExamplesWhere it comes from
Account dataName, email, password (stored hashed), workspace name, company name, role, the version of the Terms you accepted and whenYou, at sign-up and in settings
Signer detailsName, email, signing orderThe account holder who sends the document
DocumentsFiles you upload, templates, text and form fieldsAccount holders and signers
SignaturesDrawn, typed or uploaded signature images and initialsSigners and account holders
Verification dataOne-time codes sent by email (stored only as a one-way hash) and whether they were verifiedGenerated by Closign
Audit trailIP address, browser and device type, time zone, your agreement to sign electronically, and timestamps for sending, opening, viewing, signing and decliningCollected automatically during signing
Billing dataPlan, invoices, billing name and address, tax ID (e.g. GSTIN), payment statusYou and our payment provider
Technical dataIP address, browser, pages requested and error logs kept by our serversCollected automatically
Support and communicationsMessages, emails, live chat conversations and feedback you send us, and delivery status of the emails we send youYou, our email providers and our live chat provider

Payment cards. We never see or store your full card number, CVV or expiry date. Our payment provider handles them and sends us only the payment result and limited details such as the payment method.

What we do not collect. Closign does not currently collect phone numbers, Aadhaar numbers, biometrics, GPS location or live photos, and we do not use advertising trackers. We do not use analytics cookies. We count visits to our public website with Cloudflare Web Analytics, which sets no cookies and is not used in the app or on signing pages. Live chat (Crisp) loads only if you accept it in our cookie notice, and never on signing pages. If we add identity checks such as Aadhaar eSign later, we will update this policy and explain the extra data before you use them.

If you choose not to give us certain data, some features may not work. For example, you cannot sign without adopting a signature.

04AI features and your documents

Closign's AI features only process your content when you use them, and we do not use your documents to train AI models.

  • What the AI features do. The template generator drafts a document from your description. The field detector suggests where signature, date and text fields should go on a document you upload.
  • What is sent. Only the text needed for the feature you triggered: your prompt, or short parts of your document's text near where fields could go.
  • Who runs the model. AI requests are processed by Groq, Inc. (United States). It acts as our service provider and may not use your content for its own purposes.
  • No training on your content. We do not use your documents, prompts or signer data to train or fine-tune AI models, unless you give us separate, explicit permission.
  • Check the output. AI suggestions can be wrong. You are responsible for reviewing any AI-drafted text or field placement before sending a document. AI output is not legal advice.
  • You can avoid AI entirely. Start from a template, or upload a PDF and place the fields yourself. Workspaces can also ask us to switch AI off for them.

05How we use information

We use personal data only to run, secure and improve Closign, and to meet our legal duties. We do not sell personal data.

PurposeLegal basis (where the law requires one)
Create and manage accounts and workspaces; deliver the ServicesContract with you
Send documents, signing requests, email codes, reminders and completion emailsContract; on the sender's instructions for signers
Build the audit trail and completion certificate that prove who signed, when and howContract; legitimate interest in proving the validity of signatures; legal obligation
Bill you, issue invoices and keep tax recordsContract; legal obligation
Prevent fraud, abuse and unauthorised access; secure our systemsLegitimate interest; legal obligation
Answer support requests and resolve disputesContract; legitimate interest
Fix bugs and keep the service reliable, using server logsLegitimate interest
Send product updates and marketing emailsConsent where required; you can opt out any time
Comply with law, court orders and lawful requests from authoritiesLegal obligation

Under India's Digital Personal Data Protection Act, 2023, we rely on your consent or on the legitimate uses the Act permits. Where we rely on consent, you can withdraw it at any time; this does not affect processing done before.

06Who we share information with

We share personal data only with the parties below, and only as much as each needs.

  • Other parties to a document. When you send a document, its contents, the signers' names and the audit trail are shared with everyone on that document.
  • Anyone holding a completed document. Our verify page lets anyone with the signed PDF, or its document ID and fingerprint, check that it is genuine. It shows the document name, the sending workspace, when it was completed, and each signer's name, partly hidden email address and signing time. It never shows the document's contents or anyone's IP address, and it reveals nothing to someone without the document.
  • Your workspace. Admins and members of a workspace can see documents and activity in that workspace, based on their role.
  • Service providers that help us run Closign, under terms that limit their use of the data (this is our full list; we update it here when it changes):
ServiceProviderData involved
Cloud hosting and storageDigitalOcean (Bangalore, India)All Service data
Email deliveryResend (United States); Brevo (France) as a backupNames, email addresses, notification content
PaymentsRazorpay (India)Billing details, payment status
AI processingGroq (United States)Prompts and document text for AI requests you make
Website visit countsCloudflare (United States)Pages viewed on our public website, referring site, browser and approximate country; no cookies
Live chat (only if you accept it)Crisp (France)Chat messages, IP address, browser and device details, the page you chat from, and your name and email when you are signed in or give them in the chat
  • Authorities. When the law, a court or a government body requires it, or to protect someone's safety, our rights, or to stop fraud.
  • Business transfers. If Closign is merged, acquired or sells assets, data may move to the new owner, who must respect this policy. We will tell you before that happens.

07Where data is stored and how we protect it

Your data is stored on our servers at DigitalOcean in Bangalore, India.

International transfers. Closign serves customers in India, the US and elsewhere. Some service providers process data outside India, as listed above (email delivery, live chat, AI and website visit counts). When we transfer data from the EU or UK, we use safeguards such as Standard Contractual Clauses. Transfers from India follow any restrictions notified under the DPDP Act.

Security measures include:

  • encryption in transit (HTTPS/TLS) for every connection;
  • hashed passwords, and signer email codes stored only as one-way hashes;
  • tamper-evident signed PDFs with an audit certificate and a SHA-256 fingerprint;
  • documents reachable only through the app, with access checks, never from a public address;
  • role-based access, so staff see customer data only when needed for support or security;
  • logging of staff actions, and daily database backups.

No system is completely secure. If a breach affects your personal data, we will notify you and the relevant authorities as the law requires. Please keep your password private and tell us at support@closign.io if you notice anything suspicious.

08How long we keep data

We keep data only as long as we need it for the purposes above or as the law requires.

DataHow long
Account dataWhile your account is active, then deleted or anonymised 30 days after the account is closed
Documents and signer dataUntil the account holder deletes them or the workspace is closed; then deleted 30 days after closure
Audit trails and completion certificates8 years after the document is completed, so signatures can be proven in a dispute (also after the document itself is deleted)
Billing and tax recordsAs long as tax and accounting law requires (currently up to 8 years in India)
Email codesExpire within minutes; only the verification result is kept in the audit trail
BackupsDatabase backups are kept for 7 days on a rolling basis
Marketing preferencesYour opt-out is kept so we can keep honouring it

After that, we delete or anonymise the data. Anonymised, aggregated data that cannot identify you may be kept for statistics.

09Your rights

Wherever you live, you can ask us to access, correct, update, export or delete your personal data, and to withdraw consent. Email support@closign.io; we reply within 30 days. You can also request an export or the deletion of your account from your profile settings.

Everyone. You can view and edit most account data in your settings. You can unsubscribe from marketing emails using the link in each email.

India (DPDP Act, 2023). You can request a summary of the data we hold and who we shared it with, correct or erase it, withdraw consent, raise a grievance with our Grievance Officer, and nominate someone to exercise these rights if you die or cannot act. If you are not satisfied with our response, you can complain to the Data Protection Board of India.

EU, EEA and UK (GDPR). You also have the right to restrict or object to processing, to data portability, and not to be subject to decisions based solely on automated processing that significantly affect you. You can complain to your local data protection authority.

California (CCPA/CPRA) and other US states. You can ask what categories of data we collect, use and disclose; request access, correction or deletion; and you will not be treated differently for exercising these rights. We do not sell personal data or share it for cross-context behavioural advertising. We honour Global Privacy Control signals.

Signers. For data inside a document someone sent you, we will forward your request to the sender, who decides on it. We may keep the audit trail where needed to prove the signature or meet legal duties.

We may ask you to verify your identity before acting on a request. Some data may be exempt, for example records we must keep by law.

10Cookies, marketing and children

Cookies. We use only essential cookies: to keep you signed in, protect forms against forgery, remember your time zone, and remember that you closed the cookie notice. We do not use analytics or advertising cookies. Blocking essential cookies may stop the Services from working. See our Cookie Policy.

Marketing. We send product news and offers only where the law allows or you have agreed. Unsubscribe any time using the email link or by writing to us. You will still receive service emails such as signing requests, receipts and security alerts.

Children. Closign is for people aged 18 or older who can enter into a contract. We do not knowingly collect data from anyone under 18. If you believe a minor has given us data, contact us and we will delete it.

11Changes, governing law and contact

Changes. We may update this policy as Closign, the law or our providers change. We will post the new version here with a new date. For significant changes, we will also email account holders before they take effect.

Governing law. This policy is governed by the laws of India. Disputes will be handled as set out in our Terms of Service, without limiting any rights you have under the law of the country you live in.

Contact and Grievance Officer

  • Name: Janak Prajapati
  • Email: support@closign.io
  • Address: Janak Prajapati, trading as Closign, Ahmedabad, Gujarat, India

We acknowledge grievances within 3 business days and aim to resolve them within 30 days.

Contact Privacy questions and grievances: support@closign.io. Grievance Officer: Janak Prajapati, trading as Closign, Ahmedabad, Gujarat, India.