01Introduction
This policy explains what personal data Closign collects, why we collect it, who we share it with, and the choices you have. We have kept it in plain language.
Closign is an electronic signature and document workflow service available at closign.io and its related apps, APIs and emails (the "Services"). The Services are operated by Janak Prajapati, a sole proprietor trading as Closign, Ahmedabad, Gujarat, India ("Closign", "we", "us"). If you have any question about this policy, write to support@closign.io.
By using the Services, you acknowledge that we will handle your personal data as described here. Our Terms of Service also apply.
02Who this policy covers and our role
Our role depends on how you use Closign.
| You are | What you do | Our role |
|---|---|---|
| Account holder | You sign up, create a workspace, upload documents and send them for signature | Controller (Data Fiduciary under Indian law) for your account, billing and usage data; processor for the documents and signer details you add |
| Signer | You receive a link to view or sign a document someone sent through Closign | Processor, acting on the sender's instructions. The sender is the controller of your data |
| Visitor | You browse closign.io without an account | Controller for the website and form data you give us |
If you are a signer, the person or business that sent you the document decides why your data is used. Please read their privacy policy too. If you send us a request about your data in a signed document, we will pass it to the sender and help them respond.
If you add other people (signers, team members, contacts), you confirm that you have the right to share their details with us for this purpose.
This policy does not cover third-party websites or apps linked from Closign.
03Information we collect
| Category | Examples | Where it comes from |
|---|---|---|
| Account data | Name, email, password (stored hashed), workspace name, company name, role, the version of the Terms you accepted and when | You, at sign-up and in settings |
| Signer details | Name, email, signing order | The account holder who sends the document |
| Documents | Files you upload, templates, text and form fields | Account holders and signers |
| Signatures | Drawn, typed or uploaded signature images and initials | Signers and account holders |
| Verification data | One-time codes sent by email (stored only as a one-way hash) and whether they were verified | Generated by Closign |
| Audit trail | IP address, browser and device type, time zone, your agreement to sign electronically, and timestamps for sending, opening, viewing, signing and declining | Collected automatically during signing |
| Billing data | Plan, invoices, billing name and address, tax ID (e.g. GSTIN), payment status | You and our payment provider |
| Technical data | IP address, browser, pages requested and error logs kept by our servers | Collected automatically |
| Support and communications | Messages, emails, live chat conversations and feedback you send us, and delivery status of the emails we send you | You, our email providers and our live chat provider |
Payment cards. We never see or store your full card number, CVV or expiry date. Our payment provider handles them and sends us only the payment result and limited details such as the payment method.
What we do not collect. Closign does not currently collect phone numbers, Aadhaar numbers, biometrics, GPS location or live photos, and we do not use advertising trackers. We do not use analytics cookies. We count visits to our public website with Cloudflare Web Analytics, which sets no cookies and is not used in the app or on signing pages. Live chat (Crisp) loads only if you accept it in our cookie notice, and never on signing pages. If we add identity checks such as Aadhaar eSign later, we will update this policy and explain the extra data before you use them.
If you choose not to give us certain data, some features may not work. For example, you cannot sign without adopting a signature.
04AI features and your documents
Closign's AI features only process your content when you use them, and we do not use your documents to train AI models.
- What the AI features do. The template generator drafts a document from your description. The field detector suggests where signature, date and text fields should go on a document you upload.
- What is sent. Only the text needed for the feature you triggered: your prompt, or short parts of your document's text near where fields could go.
- Who runs the model. AI requests are processed by Groq, Inc. (United States). It acts as our service provider and may not use your content for its own purposes.
- No training on your content. We do not use your documents, prompts or signer data to train or fine-tune AI models, unless you give us separate, explicit permission.
- Check the output. AI suggestions can be wrong. You are responsible for reviewing any AI-drafted text or field placement before sending a document. AI output is not legal advice.
- You can avoid AI entirely. Start from a template, or upload a PDF and place the fields yourself. Workspaces can also ask us to switch AI off for them.
05How we use information
We use personal data only to run, secure and improve Closign, and to meet our legal duties. We do not sell personal data.
| Purpose | Legal basis (where the law requires one) |
|---|---|
| Create and manage accounts and workspaces; deliver the Services | Contract with you |
| Send documents, signing requests, email codes, reminders and completion emails | Contract; on the sender's instructions for signers |
| Build the audit trail and completion certificate that prove who signed, when and how | Contract; legitimate interest in proving the validity of signatures; legal obligation |
| Bill you, issue invoices and keep tax records | Contract; legal obligation |
| Prevent fraud, abuse and unauthorised access; secure our systems | Legitimate interest; legal obligation |
| Answer support requests and resolve disputes | Contract; legitimate interest |
| Fix bugs and keep the service reliable, using server logs | Legitimate interest |
| Send product updates and marketing emails | Consent where required; you can opt out any time |
| Comply with law, court orders and lawful requests from authorities | Legal obligation |
Under India's Digital Personal Data Protection Act, 2023, we rely on your consent or on the legitimate uses the Act permits. Where we rely on consent, you can withdraw it at any time; this does not affect processing done before.
07Where data is stored and how we protect it
Your data is stored on our servers at DigitalOcean in Bangalore, India.
International transfers. Closign serves customers in India, the US and elsewhere. Some service providers process data outside India, as listed above (email delivery, live chat, AI and website visit counts). When we transfer data from the EU or UK, we use safeguards such as Standard Contractual Clauses. Transfers from India follow any restrictions notified under the DPDP Act.
Security measures include:
- encryption in transit (HTTPS/TLS) for every connection;
- hashed passwords, and signer email codes stored only as one-way hashes;
- tamper-evident signed PDFs with an audit certificate and a SHA-256 fingerprint;
- documents reachable only through the app, with access checks, never from a public address;
- role-based access, so staff see customer data only when needed for support or security;
- logging of staff actions, and daily database backups.
No system is completely secure. If a breach affects your personal data, we will notify you and the relevant authorities as the law requires. Please keep your password private and tell us at support@closign.io if you notice anything suspicious.
08How long we keep data
We keep data only as long as we need it for the purposes above or as the law requires.
| Data | How long |
|---|---|
| Account data | While your account is active, then deleted or anonymised 30 days after the account is closed |
| Documents and signer data | Until the account holder deletes them or the workspace is closed; then deleted 30 days after closure |
| Audit trails and completion certificates | 8 years after the document is completed, so signatures can be proven in a dispute (also after the document itself is deleted) |
| Billing and tax records | As long as tax and accounting law requires (currently up to 8 years in India) |
| Email codes | Expire within minutes; only the verification result is kept in the audit trail |
| Backups | Database backups are kept for 7 days on a rolling basis |
| Marketing preferences | Your opt-out is kept so we can keep honouring it |
After that, we delete or anonymise the data. Anonymised, aggregated data that cannot identify you may be kept for statistics.
09Your rights
Wherever you live, you can ask us to access, correct, update, export or delete your personal data, and to withdraw consent. Email support@closign.io; we reply within 30 days. You can also request an export or the deletion of your account from your profile settings.
Everyone. You can view and edit most account data in your settings. You can unsubscribe from marketing emails using the link in each email.
India (DPDP Act, 2023). You can request a summary of the data we hold and who we shared it with, correct or erase it, withdraw consent, raise a grievance with our Grievance Officer, and nominate someone to exercise these rights if you die or cannot act. If you are not satisfied with our response, you can complain to the Data Protection Board of India.
EU, EEA and UK (GDPR). You also have the right to restrict or object to processing, to data portability, and not to be subject to decisions based solely on automated processing that significantly affect you. You can complain to your local data protection authority.
California (CCPA/CPRA) and other US states. You can ask what categories of data we collect, use and disclose; request access, correction or deletion; and you will not be treated differently for exercising these rights. We do not sell personal data or share it for cross-context behavioural advertising. We honour Global Privacy Control signals.
Signers. For data inside a document someone sent you, we will forward your request to the sender, who decides on it. We may keep the audit trail where needed to prove the signature or meet legal duties.
We may ask you to verify your identity before acting on a request. Some data may be exempt, for example records we must keep by law.
11Changes, governing law and contact
Changes. We may update this policy as Closign, the law or our providers change. We will post the new version here with a new date. For significant changes, we will also email account holders before they take effect.
Governing law. This policy is governed by the laws of India. Disputes will be handled as set out in our Terms of Service, without limiting any rights you have under the law of the country you live in.
Contact and Grievance Officer
- Name: Janak Prajapati
- Email: support@closign.io
- Address: Janak Prajapati, trading as Closign, Ahmedabad, Gujarat, India
We acknowledge grievances within 3 business days and aim to resolve them within 30 days.