Privacy Policy
Back to HomeEffective date: 15 September 2026
1. Introduction
Welcome to SignToSee, operating under the commercial brand of Penserini & Vankan VOF (hereinafter referred to as "SignToSee", "us", "we", or "our").
Our Privacy Policy governs your visit to https://www.signtosee.eu, and explains how we collect, safeguard, and disclose information that results from your use of our Service. SignToSee is a document workflow and digital access terms tracking platform. Because our core function involves generating access audit logs, we handle data with strict adherence to the European General Data Protection Regulation (GDPR).
By using our Service, you agree to the collection and use of information in accordance with this policy.
2. Definitions
SERVICE means the SignToSee platform and website.
CUSTOMER (DATA CONTROLLER): The business, freelancer, or entity that creates an account with us to protect their links. For the files and links protected by the Service, the Customer is the Data Controller.
SIGNER / RECIPIENT (DATA SUBJECT): The third-party individual who clicks a SignToSee link, signs the confidentiality agreement, and accesses the protected content.
SIGNTOSEE (DATA PROCESSOR / CONTROLLER): We act as a Data Processor when facilitating the signature and access gate on behalf of our Customers. We act as a Data Controller for our Customers' account and billing information.
ACCESS LOG: The tamper-evident cryptographic log generated when a Signer accesses a protected link, containing timestamps, IP addresses, and user-agent data.
3. Information Collection and Use
We collect specific, minimized types of information to provide our Service, process billing, and generate a verifiable access and acceptance record for B2B confidentiality workflows.
4. Types of Data Collected
4.1 Customer Account Data (For Users Who Register)
To operate your account, we may ask you to provide personally identifiable information, including:
Email address
Password (cryptographically hashed)
Company name (required)
Business Name and VAT Number (for B2B billing)
Billing Address (Street & Number, City, ZIP Code, Country)
Company registration number, where you provide one
Branding you upload for use on your gates: logo image, brand text, and colour settings
A pending email address or pending company details, held only while a change you requested is awaiting confirmation
The customer and subscription identifiers issued to us by our payment provider, which let us match your account to your payments
The review status of your account, and any notes an administrator of ours records when reviewing it. You may ask us for a copy of those notes.
4.2 Access Log Data (For Signers / Recipients)
When a Signer accesses a protected link, we automatically collect data to generate the access and audit log. This includes:
The Signer's submitted Email Address
IP Address (stored encrypted at rest using envelope encryption)
Browser family, its major version number, and the operating system platform, reduced from the User-Agent header on arrival and stored in that reduced form; the full User-Agent string is not retained
Approximate geographical location, at city level where our network provider reports one and otherwise at country level, read from the connection headers supplied by that provider rather than from a third-party GeoIP lookup service, and used to enforce region-locked links and to record where an acceptance took place
Exact timestamps of link access, email verification, and digital signature execution
A keyed hash (HMAC-SHA256) of the Signer's email address, used to locate the correct decryption key. It is computed under a secret held only by our servers and kept separate from the encryption keys, so a copy of the database alone cannot be used to test whether a given email address appears in it.
Cryptographic block hashes (previous and current mathematical hashes) verifying the integrity of the audit chain
Hashed representation of the signed agreement (SHA-256 hash of the exact NDA or access terms presented at the moment of execution)
Where a gate presents NDA-style access terms, the identity details the Signer types into the acceptance form: company or trading name, the name and function of the person accepting, postal address, company registration number, and the place of signing. These are written into the text of the access terms as executed, so that the executed document identifies its parties.
These details are held exactly as the email address and IP address are: encrypted under the Data Encryption Key unique to that Signer and Customer, and destroyed with it. What we store is the frozen text of the Customer's access terms, without the Signer's particulars in it. The executed agreement is assembled from the two whenever it is displayed, emailed or exported, and is not kept in an assembled form anywhere.
To hold the email address and IP address listed above as ciphertext, we generate a Data Encryption Key unique to each Signer and Customer pair. This key is not collected from you. We create it, store it in encrypted form, and destroy it on erasure as described in Section 6.3.
The Signer's IP address (system IP routing data) is logged exclusively for fraud prevention, security, and the generation of the access log. We process user access timestamps and system IP routing data, not invasive tracking data. We do not use signer IP addresses for marketing, profiling, or unrelated analytics. Signer IP records are retained for as long as the underlying access record remains valid, and longer only where required to establish, exercise, or defend legal claims.
4.3 Hosted File Data (Sentinel, Sentinel + & Guardian Tiers Only)
For Customers on the Sentinel, Sentinel + and Guardian tiers utilizing our dedicated file hosting (1GB, 10GB, and 20GB respectively), we store the uploaded files on our servers as ciphertext. Files are encrypted client-side, in the same way as our URL routing gateway: the decryption key remains strictly client-side, is never transmitted to or held by SignToSee, and travels only in the link fragment shared with the recipient. We cannot decrypt, inspect, mine, or otherwise access the contents of these files, and cannot produce them in decrypted form in response to a legal request or a copyright takedown notice, as we do not hold the key. Note: For the Scout tier, we operate strictly as a zero-knowledge URL gateway and do not host or see the underlying destination files (e.g., your Figma or Notion workspaces).
4.4 Tracking and Cookies
We utilize minimal, privacy-first session cookies necessary to operate the Service (e.g., keeping you logged in). We do not use third-party advertising tracking cookies (such as Meta Pixel or Google Ads trackers) that sell your data to external brokers.
5. Use of Data
SignToSee uses the collected data for various purposes:
To provide and maintain our Service, including URL routing and decryption.
To generate and preserve tamper-evident access logs for our Customers.
To notify you about changes to our Service or infrastructure.
To provide customer support and technical maintenance.
To process payments via Mollie.
To detect, prevent, and address technical fraud or bot abuse.
We do not use Customer or Signer data for advertising, profiling, or sale to third parties. Where a Customer trades under their own name, we identify them publicly as a customer only if they have given us consent under Section 4.6 of the Terms, and only for as long as that consent stands; they may withdraw it at any time.
6. Retention of Data and the Right to Erasure
6.1 Customer Account Data
We retain Customer Personal Data only for as long as is necessary for the purposes set out in this policy, or to comply with European tax and accounting laws (typically 7 years for billing records).
6.2 Access Record Retention
The fundamental purpose of SignToSee is to provide our Customers with a verifiable record that a specific individual accessed protected content and accepted the access terms. The access record itself, meaning the timestamps, the hash chain linkage, and the hash of the terms that were accepted, is append-only and is retained for as long as operationally necessary to protect the Customer, which GDPR Article 17(3)(e) permits for the establishment, exercise or defence of legal claims.
6.3 Erasure of Personal Data Within an Access Record
The personal data inside that record is handled separately from the record itself. A Signer's email address and IP address are stored only as ciphertext, encrypted under an encryption key unique to that Signer and that Customer. On a valid erasure request we destroy that key. The access record remains and stays cryptographically verifiable, but the email address and IP address within it can no longer be decrypted not by us, not by the Customer, and not by anyone holding a copy of our database. This is irreversible and cannot be undone on request.
6.4 What Key Destruction Does Not Reach
Certain fields are inputs to the record's integrity hash, so they cannot be altered or removed without breaking verification of that record. These are the identifiers of the record and the gate, the timestamp of access, a coarse browser and device descriptor, the fingerprint and size of the file that was accessed, and the hash of the accepted terms. They are deliberately kept coarse for this reason: anything placed inside the hash is permanent.
The frozen text of the access terms is beyond reach, because it is held in a table that rejects updates and deletions and its hash anchors the record. That text contains the Customer's own details and the terms themselves; the Signer's particulars are not in it, and are destroyed with the key as described in Section 6.3. After erasure the agreement still renders, showing the terms that were accepted with the Signer's identity marked as erased.
Other fields are retained simply because the access log is append-only, without forming part of the hash. The location descriptor derived from the network path is one of these. Where our network provider reports a city for the connection, that descriptor is recorded at city level rather than country level for example "Amsterdam, NL" and it is stored in the log as ordinary text, not under the Signer's encryption key. Key destruction therefore does not blind it.
Signature receipts already delivered by email to the Customer or the Signer also cannot be recalled.
7. EU Data Sovereignty and Transfer of Data
SignToSee is built on the principle of European Data Sovereignty.
Your information, including Personal Data and Hosted Files, is processed and maintained on servers located entirely within the European Union (e.g., via Scaleway in France). We actively avoid hyperscalers subject to the US CLOUD Act (AWS, Google Cloud) for our core hosting to protect your intellectual property from foreign extraterritorial jurisdiction.
If we utilize third-party sub-processors located outside the EU, we ensure strict compliance with the GDPR via Standard Contractual Clauses (SCCs).
8. Disclosure of Data
We may disclose personal information under the following circumstances:
To the Customer: Access Log data belonging to a Signer is fully visible and exportable by the Customer who generated the protected link.
Law Enforcement: Under certain circumstances, we may be required to disclose data if required by Belgian or EU law, or in response to valid requests by public authorities.
Business Transaction: If SignToSee is involved in a merger or acquisition.
9. Security of Data
Traffic to and from the Service is encrypted with TLS.
Payload data, meaning the destination URL behind a gate and any file you upload, is encrypted in your browser before it reaches us, under a key we never receive. We store and serve only ciphertext.
Access log personal data is encrypted at rest under a key unique to each Signer and Customer pair. Those keys are themselves encrypted under a master key held only in the environment of the running server, and never written into a stored container image or a source repository.
Signer email addresses are indexed using a keyed hash computed under a secret separate from the encryption keys, so a copy of the database alone cannot be used to test whether a given email address appears in it.
No method of transmission or storage is completely secure, and we do not claim otherwise.
10. Your Data Protection Rights Under GDPR
If you are a resident of the European Economic Area (EEA), you have certain data protection rights. We aim to take reasonable steps to allow you to correct, amend, delete, or limit the use of your Personal Data.
If you wish to be informed what Personal Data we hold about you, email us at support@signtosee.eu.
You have the right to:
Access, update, or delete the information we hold about you. For access records specifically, deletion is carried out by destroying the encryption key for your data, and Sections 6.3 and 6.4 set out exactly what that reaches and what it does not.
Rectification of inaccurate information.
Object to or Restrict processing.
Data Portability.
Please note that we will ask you to verify your identity before responding to such requests. If you are a Signer/Recipient requesting erasure of your data from an Access Log, the Customer who created the link is the Data Controller for that record, and we will route your request to them. Where the request is valid, the mechanism is the key destruction described in Section 6.3: your email address and IP address become permanently undecryptable, while the record that an acceptance took place remains.
11. Data Processors and Service Providers
We employ specialized third-party EU-compliant companies to facilitate our Service:
Hosting & Infrastructure: Scaleway (France)
Email Automation: Brevo (France)
Payment Processing: Mollie (Netherlands)
Invoicing & Accounting: Moneybird (Netherlands)
Analytics: Privacy-first analytics (e.g., Plausible or Ghost CMS logs) that do not use invasive tracking cookies.
12. Payments and B2B Invoicing
We use third-party services for payment processing and B2B VAT invoicing. We do not store or collect your payment card details on our servers. That information is provided directly to our payment processing provider, Mollie, and our invoicing platform, Moneybird, whose use of your personal information is governed by their respective Privacy Policies and strict security standards.
13. Children's Privacy
Our Services are strictly for B2B professional use and are not intended for anyone under the age of 18. We do not knowingly collect personally identifiable information from children.
14. Changes to This Privacy Policy
We may update our Privacy Policy from time to time. We will notify you of any changes by posting the new Privacy Policy on this page and updating the "Effective date."
15. Contact Us / Company Information
If you have any questions about this Privacy Policy or your GDPR rights, please contact us:
Commercial Brand: SignToSee
Legal Entity: Penserini & Vankan VOF
Enterprise Number (KBO): BE 1036.515.175
Email: support@signtosee.eu