Privacy notice
In plain terms. We collect what we need to run the service and nothing else. We don't sell your data, we don't advertise to you, and we don't read your documents or use them to train anything. Signing a document necessarily creates a record of who signed and from where - that's the entire point, and we explain exactly what that record contains below.
1. Who we are
GetSigning is a service operated by Goggle Software Ltd. We are the data controller for the purposes of the UK GDPR in respect of the account data described below.
Goggle Software Ltd
128 City Road
London
EC1V 2NX
United Kingdom
Registered in England and Wales, company number 11136456.
Email: hello@gogglesoftware.co.uk
We are registered with the Information Commissioner's Office, the UK's data protection regulator, under registration number ZA919631. You can verify this on the ICO's public register.
Data protection enquiries, including any request to see, correct or delete your data, go to dpo@gogglesoftware.co.uk. That address is monitored by a director; we are a small company and there is no ticket queue between you and someone who can act.
2. Two different roles
This distinction matters, because it decides who you should contact about what.
- We are the controller for the account data of our customers - the people who sign up and pay. That's your name, email, company and billing history.
- We are a processor for the documents our customers upload and the personal data of the people they send them to. If you received a document to sign and want to know why someone holds your data, ask the business that sent it - they decide what to send and to whom. We'll always help them respond.
The terms of that processor relationship are set out in our Data Processing Agreement, which applies automatically to every customer account. Questions about it go to dpo@gogglesoftware.co.uk.
3. What we collect
If you have an account
| Data | Why |
|---|---|
| Name, email, company name | To create and identify your account |
| Password (hashed, never stored readable) | To sign you in securely |
| Company address | To appear on signature certificates and invoices |
| Sign-in times and IP addresses | Security, and detecting unauthorised access |
| Subscription and payment history | Billing, and our legal accounting duties |
| Support emails | To answer you and improve the service |
Card details go directly to Stripe and never reach our servers.
If you were sent a document to sign
| Data | Why |
|---|---|
| Name, email, and optionally company and role | Given to us by the sender so we can address the document to you |
| What you type into the document's fields | To complete the document as intended |
| Your signature - the strokes you draw, or the name you type | To place the signature on the document |
| The signing record (see section 4) | Evidence that the signature is genuine |
4. The signing record
When you open or sign a document we record the following. We're setting it out in full because you're entitled to know precisely what evidence is attached to your signature - it appears on the certificate bound into the completed PDF, which every party receives.
| Recorded | Purpose |
|---|---|
| Date and time you opened and signed, to the second | Establishes when signing took place |
| Your IP address | Evidence of origin, and rate limiting to prevent abuse |
| Approximate location derived from that IP (usually town and country) | Evidence of origin. It is not precise and is not GPS. |
| Browser, operating system and time zone | Corroborates the session |
| Screen size, language and a device fingerprint | Corroborates that the same device completed the whole signing session |
| How many times you opened the link, and when | Shows the document was available to you and reviewed |
| Your confirmation that you agree to sign electronically | Records your intent, which is what makes the signature effective |
The device fingerprint is deliberately coarse - it is a hash of ordinary browser properties such as screen size and language. We do not use canvas fingerprinting, font probing, tracking pixels or any other technique designed to follow you across websites. It exists only to show that one consistent device completed one signing session.
This record cannot be deleted from a completed document, because it is the evidence that makes the signature meaningful. Deleting it would undermine the legal value of an agreement that other people are relying on. See section 10 for how this affects your rights.
5. Why we're allowed to
- Contract - to provide the service you signed up for, and to bill you.
- Legitimate interests - keeping the service secure, preventing fraud and abuse, and producing signature evidence that is reliable enough to be worth having. We've considered the impact on individuals and believe recording this information is what someone signing a contract would reasonably expect.
- Legal obligation - retaining financial records as tax law requires.
- Consent - where you tick to confirm you agree to sign electronically.
6. Who we share it with
We do not sell personal data and we do not share it for advertising. We use the following sub-processors, and no others. Each is named, with what they do and where the data physically sits.
| Who | What for | What they receive | Where |
|---|---|---|---|
| DigitalOcean US company |
Hosting the application, the database and your documents | Everything, encrypted in transit and access controlled | London, UK |
| Amazon Web Services US company |
Sending email, through Amazon SES | Recipient name and email address, the email content, and any attached signed PDF | London, UK eu-west-2 |
| Cloudflare US company |
DNS, TLS and protection against attack | Connection metadata: IP address, requested URL, browser. Not document content, which is never cached | Global edge network UK and EU for UK visitors |
| Stripe Stripe Payments Europe Ltd, Ireland |
Taking payment for credits | Billing name, email and address. Card details go to Stripe directly and never touch our servers | EU and US |
Your documents are stored only in the United Kingdom. They leave the UK in one circumstance: when a completed document is emailed to the parties as an attachment, it travels through Amazon SES in London and then to whatever email provider the recipient uses, which may be anywhere. We attach the signed PDF deliberately, so that everyone who signed keeps their own permanent copy even if this service ceases to exist.
Three of the four companies above are American, even where the data itself sits in the UK. That means the US CLOUD Act could in principle be used to compel disclosure. We would rather state that plainly than imply an insulation we cannot provide. Transfers outside the UK rely on the UK International Data Transfer Addendum, the UK extension to the EU-US Data Privacy Framework, or an adequacy decision, as applicable to each provider.
We will disclose data where the law requires it, but we will not hand over your documents on request without proper legal process. If we are ever compelled to, we will tell you unless we are legally prohibited from doing so.
If we add or change a sub-processor we will update this page and email account holders before the change takes effect.
7. Where it is held
Documents, signature certificates and account data are held on servers in London. They are not replicated to any other country.
Email is sent through Amazon SES in the London region, so the content of a message, including an attached signed contract, is processed in the UK before delivery. Once a message reaches the recipient it is on their own email provider's infrastructure, which is outside our control and may be anywhere.
Backups are held in the same region as the primary data.
8. How long we keep it
| What | Kept for |
|---|---|
| Documents and signature certificates | While your account is open, and until you delete them |
| Audit trails for signed documents | Kept with the document - deleting them would destroy the evidence |
| Account details | While your account is open, then 30 days |
| Invoices and payment records | 7 years, as tax law requires |
| Email delivery records | 90 days for the message body, longer for the fact of sending |
| Security and sign-in logs | 12 months |
| Draft documents never sent | Deleted whenever you delete them |
9. How we protect it
- Everything travels over HTTPS.
- Passwords are hashed with bcrypt. We could not tell you your password if we wanted to.
- Documents are stored outside the web server's reach, so they cannot be served as files by accident. Every download passes a permission check first.
- Signing links are stored only as a hash, so a copy of our database would not yield a working link. They are single-use and expire.
- Audit records are cryptographically chained, so tampering with history is detectable.
- Access to production systems is limited to those who need it.
No system is perfectly secure. If a breach affects your rights, we will tell you and the ICO within the timescales the law requires.
10. Your rights
Under UK GDPR you have the right to: be told how your data is used; get a copy of it; have mistakes corrected; have data deleted; restrict or object to processing; and receive your data in a portable format.
To exercise any of these, email dpo@gogglesoftware.co.uk. We'll respond within one month and won't charge you. We may ask you to confirm who you are first, so that we do not hand someone's data to the wrong person.
Two honest limits
- If a business sent you a document, we are only their processor. We'll pass your request to them promptly and help them answer it, but they decide the outcome.
- We usually cannot erase a completed signature record. Once a document is signed, other parties have a legitimate interest in evidence that the signature is genuine, and that interest doesn't disappear because one signer would prefer the record gone. We'll always explain our reasoning, and we'll still correct anything factually wrong.
11. Cookies
We use one cookie: a session cookie that keeps you signed in. It's strictly necessary, so it doesn't require consent and there's no banner to dismiss.
We do not use advertising cookies, tracking pixels or third-party analytics. We don't track whether you opened our marketing emails.
12. Children
GetSigning is for business use and not directed at children. We don't knowingly collect data about anyone under 18. If you believe we have, tell us and we'll remove it.
13. Changes
If we change this notice we'll update the date above. For changes that materially affect you we'll email account holders in advance.
14. Complaints
Please raise anything with us first. If you have an account, a support ticket is quickest: sign in and click Support. For data protection matters specifically, or if you do not have an account, email dpo@gogglesoftware.co.uk.
You also have the right to complain to the Information Commissioner's Office, the UK's data protection regulator, at ico.org.uk or on 0303 123 1113. Our ICO registration number is ZA919631.