Privacy notice
Last updated 10 October 2026
This notice explains what personal data esignPoint collects, why, who it is shared with, and the choices you have. esignPoint is operated by TranSecure Consulting Limited, a company registered in England and Wales (“we”, “us”), of 124 City Road, London EC1V 2NX, United Kingdom. Company number 15101385. ICO registration number ZC264471.
1. Our role
For the account and usage data described in sections 2(a), 2(d) and 2(e) we are the controller. For the documents and business records that you or your organisation put into esignPoint (section 2(b)) your organisation is the controller and we act as its processor, only on its instructions. If you are asked to sign a document, the organisation that sent it is the controller of the signing process and we process the data to run it for them.
2. What we collect
- (a) Account data. Your name, work email address, organisation name, role and permissions, and your password, which we store only in hashed form. If you sign in with your organisation’s single sign-on we receive the identifiers your identity provider sends us.
- (b) Content you add. Documents, templates, comments, tasks and the contacts, deals, employee, vendor, purchase and invoice records you create in the optional business apps. This can include personal data about other people; you are responsible for having a lawful basis to enter it.
- (c) Signing data. For each person asked to sign: name, email address, the actions they take, the date and time, the IP address and browser or device details they use, and the signature they apply. This forms the audit trail and certificate of completion. If the sender requires a one-time code, we send a code to the recipient’s email address. If the sender requires identity verification, the recipient is taken to our verification provider (section 5), which collects an identity document and a face image on our behalf and tells us the outcome; we keep the result and a reference, not the document images.
- (d) Billing data. Payments are handled by Stripe. Stripe collects your card details, billing address and, if you give one, your VAT number; we never see or store full card numbers. We keep your plan, number of seats, subscription status, billing country, and Stripe’s customer and subscription identifiers.
- (e) Technical and security data. Request logs (IP address, time, page or action) used to keep the service secure and to investigate problems. Your browser or app stores a sign-in session and your theme choice. On iPhone the app keeps your sign-in token in the system keychain. The web app may also store assets on your device so it can work offline.
- (f) Communications. Emails and notifications we send you about your account, documents waiting for you, and billing, plus anything you send to our support address.
We do not use advertising or analytics trackers, we do not sell personal data, and we do not send marketing emails without your consent.
3. Why we use it, and our lawful bases
- To provide the service — creating accounts, storing and sending documents, running signing, taking payment. Basis: contract.
- Security, fraud prevention and evidence — keeping a tamper-evident audit trail and protecting accounts. Basis: legitimate interests in running a secure service and in giving both sides of a signature reliable evidence.
- Service emails and support — one-time codes, signing requests, billing notices (including failed-payment notices) and replies to you. Basis: contract and legitimate interests.
- Improving and maintaining the service — diagnosing faults and capacity. Basis: legitimate interests.
- Legal and tax obligations — accounting records, responding to lawful requests. Basis: legal obligation.
- Identity verification, when a sender requires it. Basis: the sender’s legitimate interests or the recipient’s consent, as shown at the time; this may involve biometric data, which is used only for the verification and only with your explicit consent at that step.
4. AI features
When you use drafting, review, summarising or similar AI features, the text you submit and the relevant parts of the document are sent to our AI provider, Anthropic, to generate the result. We do not use your content to train our own models, and under our provider’s commercial terms content sent through its API is not used to train its models. AI output can be wrong; please review it before relying on it.
5. Who we share data with
We use a small number of service providers (“sub-processors”), each bound by data protection terms:
- netcup GmbH — hosting. Our servers are in a data centre in Austria.
- Stripe — payments, tax calculation, invoices and the billing portal.
- Brevo — delivery of our service emails.
- Didit — identity and business verification, where a sender asks for it.
- Anthropic — AI processing, as described in section 4.
We also share data: with the people you choose (documents and their audit trail go to the signers and to your organisation’s administrators); with professional advisers; with authorities where the law requires; and with a buyer if the business is ever sold, who must honour this notice. We will update this list when it changes.
6. International transfers
Our primary servers are in Austria. The UK recognises the European Economic Area as providing adequate protection. Some providers, including Stripe and Anthropic, may process data in the United States or elsewhere. Where personal data leaves the UK we rely on an adequacy decision (including the UK–US data bridge for certified organisations) or the UK International Data Transfer Agreement or Addendum, with additional safeguards where needed.
7. How long we keep it
- Account and content data: while your account is open and until you or your organisation delete it. When an organisation account is closed we delete or anonymise its data, apart from the records below, as soon as reasonably practicable.
- If you delete your own account (Settings on the web, Account in the app): your sign-in, name and email are erased from our records straight away and every session is ended. Agreements you created or signed, and their signature records and audit trails, are not erased: they belong to the organisation and to the other people who signed, and must not change. They no longer link to a login for you, although your name or email may still appear in the document or evidence itself where you or someone else typed it there.
- Completed signature records and audit trails: for as long as the document exists, because they are the evidence of what was signed.
- Billing and tax records: six years, as UK law requires for company accounting records.
- Security logs: for a limited period, then deleted.
- Copies in backups may persist until they are overwritten in the normal cycle.
8. Security
We use encryption in transit, hashed passwords, access controls, a tamper-evident audit log and separation between customer organisations. No system is perfectly secure; if a breach affects your data in a way the law requires us to tell you about, we will.
9. Your rights
Under UK data protection law you can ask to access your personal data, correct it, delete it, restrict or object to its use, receive it in a portable format, and withdraw consent you gave us. We do not make decisions about you that have legal or similarly significant effects by automated means alone. You can delete your own account yourself in Settings (web) or Account (app). For any other right, email privacy@esignpoint.com. If your data is in an organisation’s account, we may refer you to that organisation, which controls it. If you are unhappy with how we handle your data you can complain to the UK Information Commissioner’s Office at ico.org.uk or on 0303 123 1113, although we would like the chance to put things right first.
10. Children
esignPoint is for business use and is not intended for anyone under 18. We do not knowingly collect data from children.
11. Changes
We may update this notice. We will change the date above and, for significant changes, tell account owners by email or in the app before they take effect.
12. Contact
TranSecure Consulting Limited, 124 City Road, London EC1V 2NX, United Kingdom. Email privacy@esignpoint.com.