Skip to content

LEGAL

Privacy Notice

What is recorded about you when you upload, send or sign a file, written so a signer can read it before the first thing is collected.

01

Who this covers, and in which role

1.1 Three groups of people appear in this notice. A "Sender" is someone with an account who uploads a file and routes it for signature. A "Signer" is someone with a free account who receives and signs that file. Someone "On Copy" receives a copy of the sealed file without signing. Signers and On Copy together are the "Parties", and they are the people with the least relationship to us and the most recorded about them.

1.2 For the contents of a file and for everything recorded about a Party in the course of signing it, the Sender's organization is the controller and OctoDoc is the processor. We act on the Sender's documented instructions, and the data processing agreement published in the trust center at /trust is the instrument that says so.

1.3 For our own account records, billing, security logs and product analytics about Senders, OctoDoc is the controller. That is a genuinely different role with a different lawful basis, and the two are not merged.

1.4 The friction map — a clause-level index of where signers stall — is not offered. If a per-tenant version is introduced, a Sender's index will use only that Sender's own files, for that Sender, with OctoDoc as processor. Aggregating it across tenants would make us controller of behavioural data about people who never chose us. A cross-tenant version will not ship without its own lawful basis, its own purpose statement here, and an opt-out.

1.5 Nothing on this page is a claim that OctoDoc staff can read your documents. The single named platform operator can see platform-wide counts and operational event types, but the console excludes tenant and target identifiers, personal data, document content, payloads, hashes, IP addresses and user agents. Operator status is not a document key and grants no access to a tenant's rows. OctoDoc uses private Supabase Storage and does not use a per-file encryption key or make a WORM claim. A support need that genuinely requires a tenant's data requires a break-glass flow with recorded consent, bounded scope, an audit row per read and a notification afterwards.


03

Signing, and the record that cannot be optional

3.1 A signature is only worth anything if there is a record of who made it, when, and what they were shown. That record is collected under Article 6(1)(f) for the establishment, exercise and defense of legal claims, and it is not optional: you cannot decline it and still sign. You can read exactly what it contains before you start, which is the trade this notice is making explicit rather than burying.

3.2 The record holds the consent time, your IP address, your browser's user-agent string, whether you opened the PDF for a required disclosure, the version and hash of each consent artifact, and the geometry and value of each mark you confirmed. It is written to an append-only hash-chained ledger.

3.3 The consents are separate because they are legally distinct, and merging them into one checkbox is both a legal defect and a dark pattern. The Service separately records agreement to transact electronically, acceptance of the signer terms, and the statutory electronic-records disclosure when it applies. Optional per-page dwell and maximum scroll depth are offered behind a separate consent on the signing surface. Biometric capture is not offered and would require its own additional consent before collection.

3.4 Every page can be downloaded and printed before you sign and after, and there is a review screen before the final action so you can correct your own mistake before it becomes a signature. Both exist because the law requires them, and both are stated here so you know to expect them.

3.5 Signers are never charged. A signer account has one login email and may hold several separately verified signing addresses, plus the documents that person has signed; it does not make that person a member of any workspace or expose another organization's data. The signing route checks that the literal invited Party address is verified on the authenticated account before it exposes a file.

3.6 This document does not establish production availability. The deployed state of the signing path, the ledger and the seal must be verified from the service.


04

Identity verification and biometric data

4.1 The highest identity tier would ask for a government ID and a liveness selfie, checked by a third-party vendor. That involves a biometric identifier, which is the most sensitive thing this product would ever touch and the only category with an uncapped private right of action in a US state.

4.2 Before any such capture, and before the vendor's code loads a frame rather than after, you would be shown written notice of what is collected, the specific purpose, and the length of term of collection and storage, and asked for a separate written release. An electronic signature is a valid written release; a bundled checkbox is not, and this consent is never merged into any other.

4.3 The retention schedule and destruction guidelines would be published before we ever hold a biometric identifier, not afterwards: destruction on satisfaction of the purpose or within three years of your last interaction, whichever comes first.

4.4 This tier is not yet offered, and no biometric identifier has ever been collected by this product. Vendor selection, on-device processing, statutory possession and regional availability will be settled and disclosed before it is offered.

05

Deletion, and the one thing that cannot be deleted

5.1 You may ask for access to what is held about you, for it to be corrected, and for it to be erased. An Organization's owner can also download a manifest-backed export of classified tenant data and execute an account or organization erasure instruction that returns a written confirmation naming every deleted and retained class. The runbook covering those requests carries a 30-day service level. Where OctoDoc is processor, a request is passed to the Sender's organization as controller and we assist them; where OctoDoc is controller, we answer it ourselves.

5.2 Signed artifacts and the evidence block of the Ledger may be retained where Article 17(3)(e) applies for the establishment, exercise or defense of legal claims. Storage is administrator-removable private Supabase Storage, not Object Lock, and this notice does not claim physical undeletability.

5.3 Per-file encryption, crypto-shredding and public erased-state verification are not offered. Erasure uses deletion under the controller's instructions and applicable legal-retention limits.

5.4 No database relationship may make a person undeletable. Where a user's identity is preserved as evidence that they confirmed something, the user record is tombstoned and the two are decoupled, rather than the person being retained because a foreign key points at them.

Data classErasable on requestMechanism
Reading log with consent-conditional per-page dwell and maximum scroll depthYes, on a read link or signing surface and only where the visitor allowed the reading logPurged on the 13-month schedule in section 7; the strictly-necessary open row and 24-hour abuse log follow their own shorter limits
Margin questions and answersNot retainedProcessed in memory for the response; no transcript store
Identity-verification evidenceNot collected; the tier is not offeredVendor and deletion terms are required before collection
Account, billing and product analyticsYesStandard deletion
Sealed artifacts and the ledger evidence blockSubject to the Art. 17(3)(e) legal-claims exceptionDelete when no lawful retention ground applies; no Object Lock or crypto-shredding claim

06

Every subprocessor, and whether it sees your document

6.1 The two columns that matter are the last two. Most of this list never sees a document and never sees a party's name, and saying which is which is more useful than the list itself.

6.2 The ledger never enters a logging or analytics vendor, and neither does document content or signer personal data. No observability vendor is connected to any surface today. When one is, that boundary is enforced by an allowlist of field names in the exporter that drops everything else, rather than by a policy someone has to remember — but the exporter does not exist yet, so today the guarantee rests on there being nothing to export to.

6.3 The Service sends every model request through Vercel AI Gateway with zero-data-retention routing required for that request. Where OctoDoc cannot reliably read an uploaded page as text, the request carries a rasterised IMAGE of that page rather than text, so that its words can be transcribed; only pages routed that way are sent, and no other page of the document accompanies them. The Gateway is configured to route those requests only to providers covered by its zero-data-retention arrangements, including a prompt-training opt-out. These are application controls that the Service enforces in code. They do not establish that OctoDoc has executed and filed every required provider agreement or addendum; that paperwork remains a launch prerequisite.

6.4 At least 30 days' notice is given before a subprocessor is added or replaced, and a customer may object and terminate the affected subscription for a prorated refund if we proceed. The authoritative register is published at /trust#subprocessors with a version and an effective date; the version in force is 2026-09-05, effective 5 September 2026. The table below is that same register.

6.5 An organization may decline model processing, and 6.3 then describes something that does not happen to its uploaded pages. The owner turns it off in the organization's profile, and while it is off no page of an uploaded file is rasterised or sent to be transcribed — a page OctoDoc cannot read as text simply stays unread. The choice is reversible in the same place, it changes nothing already uploaded or sealed, and the upload control states which of the two is true for the reader's own organization before a file is chosen. PDF upload, reviewed Word conversion, reusable PDF forms, field preparation and cited questions remain available. The same choice also governs the launcher described in 6.7.

6.6 The send-policy model request is not governed by that choice, and it is named here rather than left to be discovered. Before a document may be sent, its text is classified against the published excluded-category ruleset at /trust, so that OctoDoc refuses the categories the federal E-SIGN Act removes from electronic signature. That check runs on every send, it reads the document's own text and never a page image, and it carries the same zero-data-retention routing as every other model request. It is a condition of sending rather than a feature of reading, which is why declining model processing does not switch it off. It is the only model request that choice does not govern.

6.7 The launcher — the prompt box that turns a request you type into a place inside the product — sends that typed request, and nothing else, through the same Gateway routing. It never carries document text, a file name or another party's name, and it only chooses among a closed set of destinations; it cannot create, send or sign anything. It is governed by the choice in 6.5: while model processing is declined, the launcher matches your request against that same closed set on our own servers and sends nothing to a model.

SubprocessorPurposeLocationDocument contentParty personal data
Vercel (including AI Gateway and Sandbox)Application hosting, document processing, isolated Word conversion and transport for model callsUSYes — during Word conversion, preparing, flattening or sealing, and as bounded model context under required zero-data-retention routingYes — application requests and incidental document content
SupabasePostgres, authentication and private object storageUS, us-west-2Yes — including page bytes in private StorageYes
CloudflareAuthoritative DNS, the reverse proxy in front of Supabase authentication, database and storage, and inbound email routingUSIn transit only — every Storage upload and download crosses the reverse proxy, which terminates TLS and stores nothingRequest metadata and operational inbound email may contain personal data
ResendAccount email, signature requests, reminders, sealed-copy delivery and inbound attachment intake on agents.octodoc.orgUSDocument names and email content, plus a PDF emailed to the inbound address, which Resend holds until OctoDoc fetches itYes — name and email address
StripeSubscription billingUSNoSender billing data only
AnthropicSend-policy classification, launcher intent routing, extractive CLI summaries and routed-page transcriptionUSYes — bounded document content, and a rasterised page IMAGE for a page with no readable text layer, routed by the Gateway under required zero-data-retention and prompt-training opt-out controlsIncidentally, where document content contains it
Timestamp authoritiesRFC 3161 timestamp tokens from DigiCert on every seal and on five-minute ledger anchorsUSHash onlyNo

07

Where data lives, and how long

7.1 The Service runs on Vercel in the United States: the marketing pages, the sender plane, the signer surfaces, and the document work that prepares, flattens and seals a file. Private object storage, authentication and the database are provided by Supabase in the United States. Document bytes pass through the application process while a file is prepared, flattened and sealed, and the signing identity is supplied to that process as configuration; neither is written to any location a browser can reach.

7.2 An organization's region is fixed when it is created and cannot be changed afterwards. Serving another region is a separate deployment, not a migration of your data. EU and UK residency are not offered today, and that is stated as an absence rather than left to be inferred.

7.3 Signed artifacts and the Ledger are HOSTED for the published retention period, subject to section 5. That window is the whole of what OctoDoc undertakes to keep. Separately, and without limit of time, a sealed PDF you hold checks against the digest its Sender published without an OctoDoc account and without OctoDoc taking part, so a copy you keep outlives anything we host. Reading-log data collected on consent follows the 13-month purge schedule; stronger identity-verification schedules attach only if that tier is made available.

7.4 Transfers out of the EEA or the UK would rely on the Standard Contractual Clauses carried by the data processing agreement. A transfer impact assessment will be finalised before OctoDoc accepts its first customer in either region.


08

The Margin, and what happens to what you ask it

8.1 The Margin is the assistant a signer can ask about the file in front of them. It quotes the file and cites the page it quoted. It gives no advice, it will not tell you whether to sign, and it is not a substitute for the advice of an attorney.

8.2 What it writes never enters the signed file. Nothing it produces is part of the bytes that are hashed and sealed, and every mark bound into a sealed file requires a human confirmation recorded against that exact geometry.

8.3 The signer Margin answers locally from the frozen document text and does not persist a transcript or route a question to the Sender. Escalation, private-mode controls and a separately exportable transcript store are not offered.

8.4 The Margin is available on the signing surface. Consent-conditional reading telemetry is offered on read links and signing surfaces, and the sender's per-page rollup is offered for read links. Escalation and configurable kill switches are not offered.

09

Your rights, and how to use them

9.1 Depending on where you live you have some or all of the rights below. Where OctoDoc is processor we route the request to the Sender's organization and assist; where we are controller we answer it. Either way the 30-day service level applies and you are told which of the two happened.

9.2 Privacy requests may be sent to privacy@octodoc.org. A compliant postal address for notices will be published here at the same time it is added to the legal instrument contact table.

  1. 1Access — A copy of what is held about you, and what it is used for
  2. 2Rectification — Correction of anything inaccurate, including a misspelled party name on a record
  3. 3Erasure — Deletion, subject to the single disclosed carve-out in section 5
  4. 4Portability — Your data in a machine-readable form, including a full export before you leave
  5. 5Objection — To processing based on legitimate interests, including the security and abuse logs
  6. 6Withdraw consent — For anything collected on consent, at any time, without affecting signing
  7. 7Opt-out signal — On a read link or signing surface, Sec-GPC: 1 is honored as a standing decline of consent-conditional reading telemetry, with no re-ask. It does not disable the strictly necessary signing record.
  8. 8Complain — To your supervisory authority, without going through us first

10

Business prospecting

10.1 OctoDoc may send a small number of plain-text product introductions to named people at companies that published a contact address on their own website. We do not buy lists, infer addresses from naming patterns, or use enrichment services. Each row is created when a human reads a published page, records the exact URL and the date, notes whether that page carried a no-solicitation line, and records the country and entity type before any message is composed. A message carries no image and no tracking pixel.

10.2 The lawful basis depends on where the person works. In the United States, CAN-SPAM permits opt-out marketing to business addresses when the message identifies itself as an advertisement, carries a working opt-out honored within ten business days, and includes a valid physical postal address. In the United Kingdom and the European Union, we rely on legitimate interests in introducing a document product to a named person whose address the employer published for business contact, and the first message carries the source URL and date, a separate line stating the right to object to direct marketing, and a link to this section. In Canada, New Zealand and Australia we send only where the published address, the absence of a no-solicitation line and the relevance of the message to that person's role together support implied or deemed consent; New Zealand's five-working-day unsubscribe clock is the shortest in that set and is the one we honor on those rows. We do not send to jurisdictions where counsel has not closed the outbound gate.

10.3 Two personal-data classes are created. A prospect row holds the name, the work email, the source URL, the read date, the country, the entity type, the segment key and the outcomes of each touch. A suppression row holds an opted-out or hard-bounced address and the timestamp only. Prospect rows are kept for twelve months after the last lawful send or until a valid erasure request, whichever is first. Suppression rows are kept for three years after the opt-out so the address is not contacted again on any path; they hold no message body, no signal text and no source URL.

10.4 You may object to direct marketing at any time. On United Kingdom and European Union rows the first message states this right separately from the unsubscribe link, because a footer that only says unsubscribe does not discharge Article 21(4). Objections, access requests, rectification and erasure go to privacy@octodoc.org under the same thirty-day service level as every other class in section 9.

10.5 To stop prospecting messages, reply "stop" to the message, use the signed unsubscribe link in its footer, or write to privacy@octodoc.org. An opt-out is honored the same day and writes the outreach suppression table; a hard bounce retires the address immediately. Opting out of prospecting does not affect a signature request you have already received or consented product mail you asked for separately.

11

Children, and marketing

11.1 The Service is not directed at children and is not intended for anyone under 18. We do not knowingly collect personal data from children, and where we learn we have, it is deleted.

11.2 We do not sell personal data and we do not share it for cross-context behavioural advertising. There is no advertising pixel, no third-party analytics beacon and no session-replay script on any surface where a document, a party name or a hash is visible.

11.3 Marketing email goes to people who asked for it and to named prospects reached through published-business prospecting described in section 10. A signature request is not marketing and is not a channel we will use for it.


12

Changes to this notice

12.1 Material changes are announced before they take effect, and the version of this notice a signer was shown at the moment of collection is recorded with their consent — so what you were told is a fact about the record, not a claim about a page that has since been edited.

12.2 A change that widens what is collected, or that changes who acts as controller, is not applied retroactively to data already collected under an earlier version.