Privacy and cookie notice
Version 2026-07-29 · SHA-256 f1db01c0da28f4fd…
PRIVACY NOTICE
Effective date: 29 July 2026
Last updated: 29 July 2026
This Privacy Notice explains how Pen Free Signatures handles personal information when someone creates an account, prepares or sends a document, receives a signing invitation, signs a document, contacts us, or otherwise uses the service.
The operator name, privacy contact and service address shown above form part of this notice.
1. Who is responsible for your information
The Operator is the controller of personal information used to administer accounts, operate and secure the service, communicate with users, prevent misuse, and comply with its own legal obligations.
For personal information that an account holder puts in an uploaded PDF or supplies about a recipient, the account holder will normally decide why that information is used. In that situation, the account holder is normally the controller and the Operator processes the information on the account holder's behalf. The Data Processing Schedule in our Terms of Service applies to that processing.
If you are a recipient and your request concerns the contents of a document or why you were asked to sign it, contact the sender first. You may also contact the Operator about service records, security information, or the way the platform processes your information.
2. Information we process
Depending on how you use the service, we may process:
Account and profile information
- your name, email address and Clerk account identifier;
- your organisation or workspace name and your role in it;
- authentication, session and account-security information handled through Clerk; and
- account creation and update timestamps.
We do not receive or store your Clerk password.
Document and transaction information
- PDFs, filenames, page counts, file sizes and cryptographic document hashes;
- document subjects, messages, signature-field positions and date-field positions;
- a recipient's name and email address, usually provided by the sender;
- private signing-link records and hashed signing tokens;
- typed or drawn signature representations;
- signing dates, status changes and timestamps;
- the electronic-signing consent wording and the version accepted; and
- original PDFs, completed PDFs and evidence records.
The documents uploaded by users may contain additional personal information chosen by the sender. The service is not intended for special-category information, criminal-offence information, medical information, children's information, or documents requiring a regulated, witnessed, notarised, advanced or qualified signature. Users should not upload that material.
Technical, delivery and audit information
- IP addresses and browser user-agent information associated with sending, viewing and signing events;
- event type, event time, actor type and chained audit hashes;
- email destination, message-provider identifier, delivery state and delivery errors;
- security, hosting and application logs generated when the service is accessed; and
- information needed to investigate errors, suspected misuse or security incidents.
Communications
If you contact us, we process the information in your message and any contact details you provide so that we can respond and keep an appropriate record of the request.
3. Where the information comes from
We collect information:
- directly from an account holder when they register, upload a document or prepare a signing request;
- from a sender when they provide a recipient's name and email address;
- directly from a recipient when they open a private link, review a document, consent and sign;
- automatically from the browser, device and network used to access the service; and
- from our authentication, hosting, database, storage and email providers when they report account, delivery, security or service events.
If a sender gives us someone else's personal information, the sender is responsible for having a lawful reason to do so and for giving that person any privacy information the law requires.
4. Why we process information and our lawful bases
We process account and profile information to create and administer an account, provide the requested service, and communicate about that service. For an account holder, this processing is generally necessary to perform our contract with them or to take steps they request before entering into that contract.
We process document, recipient and signing information to prepare documents, deliver private signing links, record the recipient's actions, apply the signature and signing date, produce the completed PDF, notify the sender and make the result available for download. Where the Operator acts as controller, this is based on performing our contract with the account holder and our legitimate interests, and those of the sender and recipient, in providing a reliable electronic-signing workflow. Where the Operator acts as processor, the account holder is responsible for identifying the lawful basis for the underlying document and recipient information.
We process IP addresses, browser information, timestamps, hashes and audit events for our legitimate interests in protecting accounts and documents, preventing misuse, diagnosing problems and producing proportionate evidence of the signing process.
We process information where necessary to comply with a legal obligation, respond to a lawful request, or establish, exercise or defend legal claims.
Electronic-signing consent records a recipient's intention to use an electronic signature. It is not normally the lawful basis on which all personal information in the service is processed. Where we separately rely on data-protection consent, you may withdraw that consent at any time without affecting processing already carried out lawfully.
We do not use personal information for behavioural advertising, sell it, or use it to make solely automated decisions that have legal or similarly significant effects.
5. Information you need to provide
There is no statutory requirement to provide information to Pen Free Signatures. However:
- an account cannot be created or operated without the required account and contact information;
- a signing request cannot be delivered without the recipient's name and email address;
- the document and required field information must be processed to provide the signing service; and
- a recipient who does not provide the required signature and confirmation cannot complete the document through the service.
6. Who receives the information
We disclose information only where necessary to operate the service, complete a transaction, protect the service, or comply with law.
The intended sender and recipient can receive or view transaction information and document content relevant to them. A completed PDF is made available through authenticated or private-link access and may be sent to the account holder as an email attachment.
We currently use these service providers:
- Clerk for authentication, account management and session security;
- Vercel for application hosting, networking, server execution, private Blob document storage and scheduled retention tasks;
- Neon for the PostgreSQL application database; and
- Resend for transactional invitation and completion emails.
Those providers process information under their applicable service terms, data-processing terms and subprocessor arrangements. Their own controller activities, such as administering the Operator's provider account, are governed by their privacy notices.
We may also disclose information to professional advisers, insurers, courts, regulators, law-enforcement bodies or other authorities where reasonably necessary and lawful. If operation of the service is reorganised or transferred, information may be disclosed to the proposed successor subject to appropriate confidentiality and data-protection measures.
We do not give document content or contact details to data brokers.
7. International transfers
Some providers are established outside the United Kingdom or use personnel, infrastructure or subprocessors in other countries. This means personal information may be processed outside the UK.
Where a transfer is restricted by UK data-protection law, it must be covered by a lawful transfer mechanism. Depending on the provider and destination, this may include UK adequacy regulations, the UK Extension to the EU-US Data Privacy Framework, the UK International Data Transfer Agreement, the UK Addendum to the EU Standard Contractual Clauses, or another legally permitted safeguard.
You can contact us for further information about the transfer mechanism relevant to your information. The Operator must verify the applicable provider contracts, processing regions and transfer safeguards before using the service for production documents.
8. How long we keep information
Pen Free Signatures is deliberately an ephemeral service rather than a permanent document archive.
- A draft, its uploaded PDF and its saved configuration are scheduled for deletion 30 days after upload.
- A sent but incomplete signing request, including its original PDF, recipient information, signing token, delivery records and audit events, is scheduled for deletion 30 days after sending.
- When a document is completed, its original and completed PDFs, evidence record, recipient information, delivery records, signing token and audit events are scheduled for deletion seven days after signing.
- Private signing links expire when the corresponding request expires or is completed and consumed.
The sender and recipient should download any copies they need before the displayed deletion deadline. Copies already downloaded, forwarded or delivered to an email inbox are outside our control and are not deleted by the service's retention process.
Account and workspace profile information is kept while the account remains active and for only as long afterwards as is reasonably necessary to close the account, handle a request, protect the service or meet a legal obligation. Contact us if you want the application profile associated with a deleted authentication account removed.
Deletion removes the transaction from the active application database and private object storage. Limited infrastructure logs, security records or provider backups may remain for the provider's documented security, continuity and deletion cycle, after which they are overwritten or deleted. We do not restore deleted transaction data to active use except where technically necessary to recover from a service failure.
9. Security
We use measures designed to protect personal information, including authenticated account routes, private object storage, short-lived object-specific access URLs, cryptographically random signing links, hashed signing tokens, document hashes, access controls and encrypted HTTPS connections.
No internet service can guarantee absolute security. Keep signing links private, protect your email account, use a secure device, and contact us promptly if you believe a link, account or document has been accessed improperly.
10. Cookies and similar technologies
The service uses essential authentication and security technologies provided by Clerk to keep users signed in, maintain session state and protect accounts. Hosting and security providers may also use strictly necessary technologies to route requests, prevent abuse and maintain service availability.
The application does not currently use advertising cookies, behavioural tracking cookies or optional analytics cookies. Because only necessary technologies are currently used, the application does not display an optional-cookie consent banner. If optional analytics or advertising technologies are introduced, this notice and the consent controls will be updated before they are enabled where consent is required.
Blocking essential cookies or equivalent browser storage may prevent sign-in and other secure features from working.
11. Your data-protection rights
Depending on the circumstances and the applicable law, you may have the right to:
- ask for access to your personal information;
- ask us to correct inaccurate or incomplete information;
- ask for information to be erased;
- ask us to restrict how information is used;
- receive certain information in a portable format;
- withdraw consent where consent is the lawful basis; and
- complain to a data-protection regulator.
These rights are not absolute. For information controlled by the sender, we may refer your request to the sender and assist them as their processor. We may need to verify your identity and clarify the scope of a request before acting on it.
Your right to object: You may object to processing based on legitimate interests. Tell us what processing you object to and why it affects you. We will stop unless there are compelling legitimate grounds to continue or the processing is needed for legal claims. You have an absolute right to object to direct marketing; Pen Free Signatures does not currently conduct direct marketing.
To exercise a right, use the privacy contact shown above. You can also complain to the UK Information Commissioner's Office or to the competent regulator where you live or work. We would appreciate the opportunity to address the concern first.
12. Children
Account holders must be at least 18 and use the service for business or professional purposes. The service is not directed at children, and users must not upload children's information or invite a child to sign through the service. Contact us if you believe children's information has been submitted.
13. Changes to this notice
We may update this notice when the service, providers, legal requirements or processing activities change. The latest version will be published on this page with a revised effective date. If a change materially affects how existing account information is used, we will provide an additional notice where reasonably practicable.