Privacy notice

Last updated 7 August 2026.

In plain terms. We collect what we need to run the service and nothing else. We don't sell your data, we don't advertise to you, and we don't read your documents or use them to train anything. Signing a document necessarily creates a record of who signed and from where - that's the entire point, and we explain exactly what that record contains below.

1. Who we are

GetSigning is a service operated by Goggle Software Ltd. We are the data controller for the purposes of the UK GDPR in respect of the account data described below.

Goggle Software Ltd
128 City Road
London
EC1V 2NX
United Kingdom

Registered in England and Wales, company number 11136456.
Email: hello@gogglesoftware.co.uk

We are registered with the Information Commissioner's Office, the UK's data protection regulator, under registration number ZA919631. You can verify this on the ICO's public register.

Data protection enquiries, including any request to see, correct or delete your data, go to dpo@gogglesoftware.co.uk. That address is monitored by a director; we are a small company and there is no ticket queue between you and someone who can act.

2. Two different roles

This distinction matters, because it decides who you should contact about what.

  1. We are the controller for the account data of our customers - the people who sign up and pay. That's your name, email, company and billing history.
  2. We are a processor for the documents our customers upload and the personal data of the people they send them to. If you received a document to sign and want to know why someone holds your data, ask the business that sent it - they decide what to send and to whom. We'll always help them respond.

The terms of that processor relationship are set out in our Data Processing Agreement, which applies automatically to every customer account. Questions about it go to dpo@gogglesoftware.co.uk.

3. What we collect

If you have an account

DataWhy
Name, email, company nameTo create and identify your account
Password (hashed, never stored readable)To sign you in securely
Company addressTo appear on signature certificates and invoices
Sign-in times and IP addressesSecurity, and detecting unauthorised access
Subscription and payment historyBilling, and our legal accounting duties
Support emailsTo answer you and improve the service

Card details go directly to Stripe and never reach our servers.

If you were sent a document to sign

DataWhy
Name, email, and optionally company and roleGiven to us by the sender so we can address the document to you
What you type into the document's fieldsTo complete the document as intended
Your signature - the strokes you draw, or the name you typeTo place the signature on the document
The signing record (see section 4)Evidence that the signature is genuine

4. The signing record

When you open or sign a document we record the following. We're setting it out in full because you're entitled to know precisely what evidence is attached to your signature - it appears on the certificate bound into the completed PDF, which every party receives.

RecordedPurpose
Date and time you opened and signed, to the secondEstablishes when signing took place
Your IP addressEvidence of origin, and rate limiting to prevent abuse
Approximate location derived from that IP (usually town and country)Evidence of origin. It is not precise and is not GPS.
Browser, operating system and time zoneCorroborates the session
Screen size, language and a device fingerprintCorroborates that the same device completed the whole signing session
How many times you opened the link, and whenShows the document was available to you and reviewed
Your confirmation that you agree to sign electronicallyRecords your intent, which is what makes the signature effective

The device fingerprint is deliberately coarse - it is a hash of ordinary browser properties such as screen size and language. We do not use canvas fingerprinting, font probing, tracking pixels or any other technique designed to follow you across websites. It exists only to show that one consistent device completed one signing session.

This record cannot be deleted from a completed document, because it is the evidence that makes the signature meaningful. Deleting it would undermine the legal value of an agreement that other people are relying on. See section 10 for how this affects your rights.

5. Why we're allowed to

6. Who we share it with

We do not sell personal data and we do not share it for advertising. We use the following sub-processors, and no others. Each is named, with what they do and where the data physically sits.

WhoWhat forWhat they receiveWhere
DigitalOcean
US company
Hosting the application, the database and your documents Everything, encrypted in transit and access controlled London, UK
Amazon Web Services
US company
Sending email, through Amazon SES Recipient name and email address, the email content, and any attached signed PDF London, UK
eu-west-2
Cloudflare
US company
DNS, TLS and protection against attack Connection metadata: IP address, requested URL, browser. Not document content, which is never cached Global edge network
UK and EU for UK visitors
Stripe
Stripe Payments Europe Ltd, Ireland
Taking payment for credits Billing name, email and address. Card details go to Stripe directly and never touch our servers EU and US

Your documents are stored only in the United Kingdom. They leave the UK in one circumstance: when a completed document is emailed to the parties as an attachment, it travels through Amazon SES in London and then to whatever email provider the recipient uses, which may be anywhere. We attach the signed PDF deliberately, so that everyone who signed keeps their own permanent copy even if this service ceases to exist.

Three of the four companies above are American, even where the data itself sits in the UK. That means the US CLOUD Act could in principle be used to compel disclosure. We would rather state that plainly than imply an insulation we cannot provide. Transfers outside the UK rely on the UK International Data Transfer Addendum, the UK extension to the EU-US Data Privacy Framework, or an adequacy decision, as applicable to each provider.

We will disclose data where the law requires it, but we will not hand over your documents on request without proper legal process. If we are ever compelled to, we will tell you unless we are legally prohibited from doing so.

If we add or change a sub-processor we will update this page and email account holders before the change takes effect.

7. Where it is held

Documents, signature certificates and account data are held on servers in London. They are not replicated to any other country.

Email is sent through Amazon SES in the London region, so the content of a message, including an attached signed contract, is processed in the UK before delivery. Once a message reaches the recipient it is on their own email provider's infrastructure, which is outside our control and may be anywhere.

Backups are held in the same region as the primary data.

8. How long we keep it

WhatKept for
Documents and signature certificatesWhile your account is open, and until you delete them
Audit trails for signed documentsKept with the document - deleting them would destroy the evidence
Account detailsWhile your account is open, then 30 days
Invoices and payment records7 years, as tax law requires
Email delivery records90 days for the message body, longer for the fact of sending
Security and sign-in logs12 months
Draft documents never sentDeleted whenever you delete them

9. How we protect it

No system is perfectly secure. If a breach affects your rights, we will tell you and the ICO within the timescales the law requires.

10. Your rights

Under UK GDPR you have the right to: be told how your data is used; get a copy of it; have mistakes corrected; have data deleted; restrict or object to processing; and receive your data in a portable format.

To exercise any of these, email dpo@gogglesoftware.co.uk. We'll respond within one month and won't charge you. We may ask you to confirm who you are first, so that we do not hand someone's data to the wrong person.

Two honest limits

  1. If a business sent you a document, we are only their processor. We'll pass your request to them promptly and help them answer it, but they decide the outcome.
  2. We usually cannot erase a completed signature record. Once a document is signed, other parties have a legitimate interest in evidence that the signature is genuine, and that interest doesn't disappear because one signer would prefer the record gone. We'll always explain our reasoning, and we'll still correct anything factually wrong.

11. Cookies

We use one cookie: a session cookie that keeps you signed in. It's strictly necessary, so it doesn't require consent and there's no banner to dismiss.

We do not use advertising cookies, tracking pixels or third-party analytics. We don't track whether you opened our marketing emails.

12. Children

GetSigning is for business use and not directed at children. We don't knowingly collect data about anyone under 18. If you believe we have, tell us and we'll remove it.

13. Changes

If we change this notice we'll update the date above. For changes that materially affect you we'll email account holders in advance.

14. Complaints

Please raise anything with us first. If you have an account, a support ticket is quickest: sign in and click Support. For data protection matters specifically, or if you do not have an account, email dpo@gogglesoftware.co.uk.

You also have the right to complain to the Information Commissioner's Office, the UK's data protection regulator, at ico.org.uk or on 0303 123 1113. Our ICO registration number is ZA919631.