Privacy Policy
Last updated June 29, 2026
DigiSig is operated by SoftSplit d.o.o., Trg bana Josipa Jelačića 1, 10000 Zagreb, Croatia ("we", "us"). We are the data controller for the purposes of the EU General Data Protection Regulation (GDPR). You can reach us at hello@digisig.eu.
The short version
Your document is encrypted in your browser before it ever leaves your device. We never receive the decryption key, so we cannot read your documents. We keep only the minimum data needed to make signing work and to provide a tamper-evident audit trail.
What we process
- Document contents: encrypted on your device (AES-256-GCM). Where an encrypted copy is stored to deliver a signing request, we hold only ciphertext and never the key.
- Signing metadata / audit trail: a SHA-256 hash (fingerprint) of the document, signers' email addresses, signing timestamps, and event records. The tamper-evident trail stores hashes and pseudonymous identifiers rather than document content.
- Email addresses: each signer's email is part of the signing record. It is cryptographically bound into the signature itself (so a signature can be verified against the person who made it) and is shown in the audit trail.
We do not log IP addresses in the signing record, and we use no analytics, advertising, or third-party trackers. Our infrastructure provider (Cloudflare) may process connection metadata such as IP addresses transiently at the network layer to deliver and secure the service, as our processor.
Why we process it (lawful bases)
- Performance of a contract (Art. 6(1)(b)) — to provide the signing service you request.
- Legitimate interests (Art. 6(1)(f)) — to secure the service and to produce a reliable audit trail.
- Consent (Art. 6(1)(a)) — where you opt into the paid certified copy or optional features.
Where your data is stored
All data is processed and stored within the European Union. We use Cloudflare: encrypted document blobs in R2 (EU jurisdiction) and signing metadata in D1 (EU region). No personal data is transferred outside the EU by us.
How long we keep it
We keep your data on our servers for a maximum of 30 days from when a signing request is created, after which the encrypted document and all signing metadata — including email addresses — are automatically deleted. Your durable proof is the signed PDF you download, which carries its own verifiable certificate, so we do not need to retain anything to keep your signature verifiable. You can also ask us to delete a specific request's data sooner (see Your rights); we honour this except where we must briefly retain it to complete a signature you have asked us to process (GDPR Art. 17(3)(e)).
Your rights
Under the GDPR you have the right to access, rectify, erase, restrict, and port your personal data, and to object to processing. To exercise these rights, contact hello@digisig.eu. You also have the right to lodge a complaint with your local supervisory authority (in Croatia, AZOP).
Sharing & processors
We do not sell your data. We use a small number of processors under data-processing agreements:
- Cloudflare — EU hosting, storage (R2/D1, EU), and network security.
- Stripe — payment processing for the optional certified copy. Card details are handled by Stripe; we never see or store them.
This is our current sub-processor list; we will update it here if it changes.
Changes
This policy may change as the service develops. The "last updated" date above reflects the current version.